Permission.site
permission.site
permission.site
Another cool site to check out: https://coveryourtracks.eff.org -- a great tool to see how unique your browser's 'fingerprint' is and how well it protects you from trackers and other annoyances online.
If you send a link to padenot@mozilla.com I can have a look, I'm on the media team at Mozilla (that includes WebRTC).
Thanks!
I should note that it's not a "crash" -- it's just that I get immediately disconnected from the meeting when I have my video + audio on and then someone else joins. I'll try to get some repro steps and send to you!
I have no love for Zoom but at least they have a desktop app so I can screen share without bogging down my whole machine
It should be illegal imo
There should also be a name for ostensibly public social media sites that webhostage you into signing up. Instagram comes to mind.
It’s a reprehensible dark pattern.
The industry term is "web-to-app conversion" by the way.
Appholing Appstunting Nativebaiting
Has both web and app in it, and it says what it does. Could also be webcrapping as verb.
It's so clever I think I'll start using it, and also telling people I came up with it by myself.
[1]https://www.reddit.com/r/changelog/comments/6xfyfg/an_update...
But Chromebooks are sometimes a little bit special. I'm working on a app right now which is designed for tablets and wanted to check if I could run it on my Chromebook, because of the bigger screen (13" compared to Samsung S5/S6 with ~10") and I couldn't install it from the alpha channel. The thing was, it has a camera, a front camera, but the Manifest.xml required the default camera permission which was missing and this prevented me from even finding the app in the PlayStore.
And Slack as app is basically only the website. All the "native" apps seem to just render it (Linux, MacOs and Windows are Electron apps, the Android version feels like a WebView)
Then they decided you should need the app to message people.
Then they decided you should use a completely separate app to message people versus browse Facebook.
Now I have to use mbasic.facebook.com to message people. The quality of the experience dropped so much because, but I'm glad they don't have access to my contacts, text messages, location, etc. They get enough info about me from other sources.
Some forum software allows the owners to create an app then prompts you to install their app. Not sure which it is, but it's super annoying.
Over the last couple, reddit has significantly limited their mobile website utility, requiring login (like Instagram) and nagging you to download the app.
Marketing metrics seem to have overcome usability in terms of relative importance. It's really frustrating to see what the movie computing environment has become.
No shed picture. But no compromises here either.
Also I find it totally hilarious that I'm 42 and I have never even seen WhatsApp's interface yet my 80 year old father is a social media expert in a lot of ways.
The future is just tragic.
But you can put your computer behind Pi-hole or add some of Pi-hole's lists to your hosts file, which would prevent them from communicating with tracking domains completely... unless they also bundle some sort of a proxy or a VPN.
I'd rather have a browser that cannot access these things at all. Now I've to hope that the permissions work and the implementation is bug-free (my trust in that is quite low, browsers are too large).
One particular video conferencing software asked for permission to read key strokes from any process! A very weird request. The only non-nefarious use case I can think of is that they want to allow keyboard shortcuts to work even when their app isn't in the foreground.
On the other hand, you might be able to do it with some key or combination that is less commonly used?
So if you want real data privacy, you need a native app, despite the drawbacks you point out.
And there are already encrypted media streams but I don't know if that counts as E2E?
A lot of these 'native' apps are just web browsers anyways...
So running WASM wouldn't make any difference if you're relying on a server to deliver you that WASM on every request. A compromised (or subpoenaed) server could simply ship you a compromised WASM payload for a single request and you'd be extremely unlikely to ever find out. If Signal wanted to add a backdoor, otoh, they'd need to ship it as a signed update to all their users, with all the reputation risk that entails.
Whether a native app is simply a browser underneath doesn't matter, just how the code gets delivered to the user. Even a browser extension or chrome app could work, since they are run from a signed, static bundle rather than from a server.
Encrypted media streams seem like a DRM feature? I don't think they have any relevance to end-to-end encryption.
But I'm afraid we're in its dying days, at least as far as the original ideals of the web were concerned.
In our rush to make browsers more powerful application platforms rivaling operating systems themselves, we raised the bar so high that we ensured the web's destruction: by guaranteeing that it would eventually be effectively controlled by a single browser maker.
In practice, this was probably always going to be Google, but if it wasn't Google it would simply have been some other Google-sized player.
(Oh and yeah 20 years ago I had AJAJ by just loading the target URL in a hidden/offscreen iframe and reading its contents programmatically. Never mind the fact that I could also read contents from the user's hard drives ... although I didn't use it for this)
Remember, we invented pop-up blockers because advertisers abused it, and we've been in an arms race with those assholes ever since. Tracking and ads in desktop apps came from the web ecosystem and now we're stuck with it.
It was something that came back when Microsoft was still convinced the internet would be a fad. Those activeX things could do all sorts of fun exciting things on your computer.
But this? This comment is absolutely special.
ActiveX controls were native code, with full system access by design. Possibly even worse, it was an absolutely blatant attempt by Microsoft to monopolize the web and maintain Windows' and Internet Explorer's dominance, as the controls were of course (in practice) intimately tied to IE on Windows on x86.
Flash was an abonimation, yet you could disable it with barely any consequences. Same with ActiveX.
The damage to individuals and the economy in terms of lost productivity and compromised personal information directly attributable to ActiveX's "compromise my system by design" nature is incalculable.
To compare that to Javascript is rather spectacular.
If you want to argue that Javascript has been able to wreak more damage over time precisely because it's not as objectively insane and immediately destructive as ActiveX, well fine. It could be said that Javascript is Covid-19 to ActiveX's ebolavirus. Ebola is so wantonly destructive that it kills many of its victims before they have a chance to infect others, whereas Covid's less-awful nature has actually allowed it to harm more people over time and is now probably here to stay, like influenza.
Flash was an abonimation, yet you could disable it with barely any consequences. Same with ActiveX.
This was very nearly not the case.IE/Win had close to 100% market share at one point. We were a hair's breadth away from a future where you could, in fact, not disable ActiveX without shutting yourself off from much of the web, like Javascript today.
South Korea was actually there for a time. If you wanted to spend money online, various regulations meant running ActiveX was a requirement.
The power consumption alone of JavaScript easily shadows that. Pretty much no desktop computer in the world can go in lower sleep states because of javascript "idling" in the background. And a decent percentage of CPU cores are constantly pegged at 100%. Imagine the number of batteries that has prematurely died because of the stress of javascript - when all the user wanted was to read static text.
Enabling ActiveX for your bank site is hardly the same. The real issue was running it on another OS than windows. Happily trade it for what we have today though.
Online commerce, content delivery, and advertising are what, multiple trillions of dollars' worth of business?
Once the web/internet became established and began trending toward ubiquity, companies were clearly always going to invest a lot into vying for our dollars and eyeballs. Without viable competition in the form of web standards, Javascript, and operating systems besides Windows it's almost certain that the evolving web would have leaned into ActiveX and/or Flash and made them essentially a requirement in much the way that Javascript is currently a requirement today.
The timeline we're living in is not ideal, and I really dislike Javascript for a number of reasons, but it's also one of the primary reasons we're not living in an even worse timeline.
There was always going to be something like Facebook. Now imagine Facebook... except powered by ActiveX instead of Javascript. Apologies if you just vomited as violently as I did while typing that. But when you talk about gladly trading Javascript for ActiveX, that's the sort of absolutely ruined world you're pining for.
For sure things would have been different if Microsoft had really tried to exploit their monopoly. But they just left it there as if waiting for the competition to catch up and surpass.
Flash could have been it, not that flash was much better but at least you could read text without it.
It could be that anything would be made to suck. But it doesn't really follow that money means tracking to this extent and come with such poor user experience. With trillions of dollars on the line we make it so slow it is barely usable. Oftentimes there are many layers of popups and checkboxes just to get at the content. And somehow that is worth it? The incentives are insane. Tragedy of the commons is putting it kindly.
Dark patterns are at an all time high. The techniques in the nineties used by criminals to trick you into running that attached executable in outlook express are now finessed by the largest corporations to trick you into allowing them to track you even more. On top of that the monoculture situation is pretty terrifying.
I wouldn't bet on humanity not being able to make it worse but it is hard to accept the state that we are in.
This playbook is happening again in China now. Not with ActiveX but with WeChat and AliPay. It's increasingly difficult to live there without either of the two apps and I think it does not bode well for the future for society to be reliant on two private corporation apps for basic needs, in the same way that it was not a good idea for the world to be dependent on ActiveX 20 years ago.
Sure you could disable activeX but in practice it would have been rare.
People bitch that sites don’t support people who disable JavaScript but it really isn’t worth catering to that type of person. I’ve been in multiple shops where we had the debate about how to handle non-JavaScript clients and every single time all the developers agreed it wasn’t worth the hassle.
This includes companies who had blind developers using screen readers and companies that had major legal liability if the site wasn’t accessible. The “screen readers don’t support JavaScript” argument has been dead for years now. The only people without JavaScript are those who intentionally disable it.
It’s just not worth building what is almost a second website for incredibly tiny amount of non-JavaScript viewers out there.
Perhaps the question should have been, why make a special version for the ones with javascript?
It's still very useful, but don't take every single number it reports as gospel. It's tracking how unique you are among people who purposefully visit a fingerprint testing site.
But 1 in 11 people on the web are not disabling Javascript.
Like web push notifications and popups are two really useful features but the amount of abuse they have had to endure is amazing. Every shitty site from newspapers to reddit to facebook must show a dark screen and ask me to subscribe to web notifications before i can see anything.
Then there are hidden APIs for which no permission is needed, like trapping of the back button (where a site gains access to my browser's back button and won't let you go back) and page close button (where it shows a popup asking you to confirm you want to leave).
What I want since forever is a tipjar that works well. I put a bit of credit into my tipjar. I read an article and at the halfway point it allows me to tip an amount. Should be anonymous if I want and a one or two clicks affair.
The browser should never let a website interrupt unless allowed by the user. Place a bell icon in the address bar and make it translucently balloon up when triggered for visibility.
Side note: Browser interface should stay outside the untrusted zone of web content. Whenever it can't, interface could have an unobtrusive unimitable background pattern extending from the trusted zone into the untrusted zone. The user should always know what is browser or website.
Of all the sites on Earth that I could learn this existed in the browser, it was rolling stone, with some generic static article on something I can't even remember.
Why exactly does a magazine need access to my gyroscope, magnetometer and acceleration sensors? Especially considering that I'm on a desktop that thankfully doesn't have such things.
I'm stunned how often I get the permission prompt on completely unrelated websites.
I guess it allows tracking scripts to do even more fingerprinting.
I have the same problem and found that the embedded Vimeo player assumes all videos could be played in VR, although the video is a normal, flat video, so any webpage embedding a Vimeo video, prompts that permission notification for me, although the actual video could be on a different page but still initialized on page load.
Also new to me is 'pointer locking'. I wonder/wish if/when browsers would be able to transparently pass key bindings that'd otherwise be captured by the OS, like Alt+Tab. Then, just by visiting a website, I could use, for example, Citrix desktop remote login through my browser as if it were a native app.
For the confused: Check the address bar, clicking it actually changes the URL of the site (to flip you into/out of secure mode)
(The former applies to me, and clicking the toggle does nothing for me either.)
Delayed popups have very few, if any, legitimate uses.
There are a few Web APIs which work this way — for example, you can’t make a page fullscreen unless you do so in response to user input/interaction [0].
[0]: https://developer.mozilla.org/en-US/docs/Web/API/Element/req...
https://developer.mozilla.org/en-US/docs/Web/API/Event/isTru...
Because if I was a developer doing development, I'd test browsers with what I developed.
Was also interesting to see webauthn ask if I wanted to allow a site to use faceid which I didn’t know was even possible
1) Turn bluetooth off.
2) Click the "bluetooth" button, then deny it.
3) Chrome crashes.
They will probably fix it
I'm always so happy with this addon and the first thing I install on a new machine.
I think (but never really researched and enabled it) you can also have it run in whitelist mode by default, so that you can disable JS for specific sites.
Best to give it a try though.
I enabled JS for just eff.org, and coveryourtracks tells me I'm still spewing 17.12 bits of fingerprint all over the internet. I suppose it'd be possible for a browser to randomly rotate stuff like user-agent through multiple common values to mitigate that.
Just by coincidence when I opened the site in Safari on iOS I got a pop-up message that my SIM card had sent a text message.
https://web.dev/async-clipboard/#security-and-permissions:~:...
Theoretically, a bad actor could have a site or even inject code onto a site with an innocuous looking bash command, but upon copy injects say, rm -rf ~ \n
- Copied from https://news.ycombinator.com/item?id=26590437
https://i.judge.sh/sentimental/Lotus/WindowsTerminal_fyi7k86...
With iOS14 at least we can tell when apps are reading the clipboard.
https://developer.mozilla.org/en-US/docs/Web/API/Screen_Capt...
Why not have a "Do you want to allow this site to take control of your pointer?" prompt, same as when a site first wants to use your microphone or camera?
(click one of the Windows apps once it boots)
"You could label that button anything" sadly applies to a significant number of dangerous things a website can do, pointer lock is not near the top of the list.
Screen recording:
https://b-cdn.s3.maddison.io/99Q967Cnvz--2021-03-26_02-58-20...