Google Chrome to remove detailed cookie and site data controls
lapcatsoftware.com
lapcatsoftware.com
It does, but it's split between two places. You can see a list of all sites that have stored data in Preferences > Privacy > Manage Website Data... (no option to view here, just delete).
You can also navigate to the site in the browser and then view the detailed data:
- Check "Show Develop menu in menu bar" in Preferences > Advanced
- Develop > Show Web Inspector
- Navigate to the Storage tab
On the left you'll see options for Cookies, Local Storage & Session Storage.
However, needing to delete those cookies without first viewing the page due to side effects - that is a very niche use case.
Manually interrupting most flows is practically impossible. Too fast, and can chain across a half dozen (sub)domains near instantly. The web hasn't been that slow or simple in a long time.
Yes, as mentioned, from atrocious engineering.
See also that Windows can break the desktop due to their own advert.
If you have to go over the settings... A safe, privacy respecting browser wouldn't resort to any shady tactics in the first place.
I'm actually not against Firefox either, but they refuse to implement a profile switcher, and I need one to be able to fully and unambiguously isolate my work and personal accounts. What's particularly grating is that they already have profile support. Just not the UX to switch the profiles without pain.
https://addons.mozilla.org/en-US/firefox/addon/profile-switc...
This is the only thing that makes FF awkward for me when not using a Mac.
If you are using GNOME desktop you can also try this to integrate the profiles into the launcher. I wrote it when still using Ubuntu but I'm on Fedora now and it's the exact same steps: https://www.tombrossman.com/blog/2020/launch-firefox-profile...
Parent is 100% correct.
Insofar as he was opposed by “the Left”, it was for his political actions in opposition to equal rights. The religious basis of that action was probably important to Eich, but it was immaterial to the opposition.
> FWIW, I voted to call it that in my state, but I have no problem with someone holding a different opinion.
Good for you.
> That’s sorta how democracy works.
In a liberal (in the classical, Enlightment-derived sense, not either of the narrower senses it is used for factional positions within the US political system) democracy, you are absolutely permitted to have a problem with, and (peacably) take action based on such a problem, with unwelcome political actions, including actual or threatened refusal to participate in economic exchanges with the perpetrator.
I much prefer to be persuaded to vote for or against something than have to state my opinions under the barrel of a proverbial gun. After a free and fair election, I accept the results and move on, even if things do not go my way. Seems more civilized and less painful than all known alternatives.
The logical conclusion of it being permitted is...that it will be done when the utility of the impact it is perceived as likely to have outweighs the perceived disutility of the protest action, including any beneficial exchange foregone. Which is, all in all, not very much, which matches pretty well with observed behavior.
> After a free and fair election, I accept the results and move on, even if things do not go my way
Well, when there is a free and fair election to strip you of fundamental liberties, and you lose, try to keep that attitude in mind.
I would love a company like DuckDuckGo or Brave to offer a paid tier where I can just subscribe to an ad-free search engine (I would love Google to offer a 'Google Premium' with this, but let's be real that's not happening!).
i.e. If you are competing with Google by releasing a free search engine with Ads, you have to provide better search results with Ads mixed in than Google which will be tough. If you found a monetisation strategy that didn't involve Ads, theoretically it should be easier to offer a better quality search result and better quality product than Google (because you are actually focussing on delivering the best quality results rather than the right mix of good-results and Ads to optimise revenue).
For companies - It doesn't sound too hard to implement and seems like it would be a good source of revenue. Plus paying subscribers will be more 'loyal' in terms of moving their searches across.
For users - you get more of a guarantee that the companies statements about privacy and impartiality are true, because there is less incentive for them to break that.
The affiliate link autocomplete for finance.{us, com} was a bug and fixed immediately.
Browsers other than Brave have a hard time surviving without being captured by a search or other big-tech power. We're the only user-first, private browser with opt-in revenue sharing.
https://www.computerworld.com/article/3284076/brave-browser-...
https://www.computerworld.com/article/3292619/the-brave-brow...
These seem pretty cut-and-dry, but if they are false they should definitely retract.
> We're the only user-first, private browser with opt-in revenue sharing.
I personally don't want revenue sharing - I just want the first browser that is user-first and private. The issue with me being advertised to isnt that I want a cut of the revenue, it's that I don't want to be advertised to. That's the whole point of my post - if you need revenue just charge me for it. Why can't we just have a search company that will just let me pay them money in a straightforward 1950's-style transaction.
All I'm saying is - Please don't try to beat Google Search at being Google Search with the same ads-in-search model - you have such a great opportunity, and clearly the experience, to do something different! I personally hope you choose a different path that allows you to have a better ad-free product. Maybe you will succeed going down the ad-route, but I personally want a different option to having my results stuffed with ads, rather than just a new (either better or worse) Google.
As soon as you do a paid version of search I'll be a subscriber, as long as there is a guarantee that it is privacy-preserving, will never have ads, is a sensible price and isn't linked to some weird crypto stuff.
I use Safari because of keychain and continuity. For example my Mac Mini can autofill 2FA tokens sent to my phone.
I use Firefox for web development and for sites I don’t trust and don’t want tracking me.
I only use Chrome for Gmail and YouTube.
Adblocking, background playback.
I’ve never heard about this, could you provide a source?
Unless you just mean that sending data over plain HTTP to these servers is in some sense a VPN tunnel because the resulting servers could forward it elsewhere?
Most HN comments about these topics are plain FUD, and despite mentioning a bunch of intricate networking tools, the commenter still fails to address reality.
https://librewolf-community.gitlab.io/ https://chromium.woolyss.com/
The author addresses this point (or has now addressed it) in the addendum to point out an "observer effect" shortcoming:
This information can be seen with the web inspector in both Chrome and Safari.
Yes, but the crucial difference is that you have to navigate to an individual site in a browser window in order to see the site data in the web inspector. Whereas in the Preferences, you can get to the site data, for every website, without having to load the sites. And remember, the very act of loading a site can make the site data change, so there's an "observer effect" if you try to examine or delete it in the web inspector.
You can detect developer tools being open in Chrome pretty reliably, so detect dev tools have been open then "clean up your act" before there's a chance to view anything of note
Even so, we added CSS and stuff to highlight elements and that was easily found.
What do people look for today?
1. Watching window.innerHeight/innerWidth for sudden, large decreases, indicating that the user just opened the inspector.
2. Logging objects to the console with toString methods and checking if that method gets called.
but 2. I have no idea, except the browser vendors would add a "stealth dev mode"
So your solution would require inject your code into the code that wants to hide from you ... ?
I might be off here, but I imagine console.log early exits if there's no console open, so it doesn't call toString
If that's the case you can just write to the console in a loop and immediately know if one is open
The point is to avoid calling toString when the console is open, by using some other way of displaying logged values.
Their code will call console.log(object) every X ticks.
As soon as you open the console, console.log fires instead of early exiting => object.toString is called => they know the console is open
My memory is fuzzy, but I also had a different function I would call if frameworks added it so instead of “Object {}” it was “Backbone.Model {id=1}”.
I put these in and used them in firebug extensions I wrote for frameworks.
Later I asked chrome to add something, which is why there is a “enable custom formatters” option for the console. Really needs to work in the debugger though.
Someone else is writing code that they want to have react to the console opening.
So they will intentionally force the call as soon as the console is open, as a result toString is called regardless of if you yourself have made a call to it.
The point is that you patch the console to not do that.
2. Ahhh, clever!
I mean more specifically taking advantage of the awkward UI to cover up your tracks on local storage, it's something that's just devious enough that if you get caught (which is not difficult) it'll be hard to explain what you were doing, and you'll be trying to explain it to technical people
When discord loads, it copies it out of localstorage into a js var and deletes the localstorage. So if you examine localstorage it will be empty. On page unload it copies it back into localstorage. So if you want to see the value, you have to make sure no discord tabs are open in your browser.
I believe one reason for this is to prevent self-xss. It's hard for a malicious person to write a snippet of js to steal the login cookie now that it's no longer in localstorage. Another reason might be to prevent bots. It's hard for someone to automate a discord account if there's no way to get the account's login cookie.
Like, if I have one Discord tab open (so localstorage is cleared) and I open a second one in parallel, will I be logged out in the second one?
Specifically, there have been a lot of changes to cookies lately because malicious actors (malware/adware) figured out how to access the cookie store and infer/determine cookie information from other sites.
I suspect that maybe this cookie store is kept in a more secure part of the application and only the cookies relevant to the site you visit get pulled out of it. It may even be a risk to have the information for all domains even loaded into memory for the application.
With all that said, there should be some way to manage/introspect that cookie store from outside of the browser imho.
Slow clap. Well done.
So whether your theory is true or not, no one should use Chrome.
Reasons don’t really matter to users though. It’s pointless arguing if we should assume innocence or guilt because irrespective of the developers motives, if a particular feature is a show stopper for you then you switch to a platform that supports said feature. Anything else added to colour the discussion is irrelevant.
In terms of end users driving decisions ultimately, I agree. That said, this is a discussion forum so I figured it was open for discussion and assumed that folks would be deciding on their own how to react to the change.
I guess this all depends on what we think we’re having a discussion about!
The tools are designed for developers who often want to manually edit cookies on pages they are debugging.
A particular feature of a web application (shopping cart) had different behaviour depending if the page was loaded as "an initial pageview on revisit", e.g. the user coming from [search engine|other link|bookmark|url bar] or from normal site browsing. By storing data in both Local Storage and Session Storage, and comparing the two on page load, I could determine if the user, who had been to the site in the past, had just come back. This all had to be developed in the dark as the major browsers have no method of viewing Local Storage and Session Storage for websites not loaded.
https://www.chromium.org/Home/chromium-security/site-isolati...
Disclosure: never used or saw safari, and i don't have a mac, nor the mac nature.
Also the amount of bugs and missing features I face in Safari as a web developer is a nightmare.
Cute animations though.
Apple doesn’t make money from web ads (yet). Although even that is changing as Apple now offer personalised Ads in Apps, they might one day offer that on the web as well.
Nobody who isn't a web developer is out there trying to guess what individual cookie names/values mean or wants to delete individual ones. At most, they just want to be able to clear them per-site (or across the entire browser).
Anyone else will use the Developer Tools UI that's better suited for the task.
Think facebook.com, fbcdn.net, etc.
I end up having to delete cookies for Cars.com every other week, because sometimes the search function would corrupt something and every page would return a blank white screen.
https://developer.chrome.com/docs/devtools/storage/cookies/
Contrary to the headline, Chrome isn't removing the ability to do anything -- they're just removing it from the preferences interface, where I'm not sure it really ever made sense to include in the first place.
Truly, editing/deleting individual cookies isn't something any regular user ever needs to do -- just clearing per-site, which continues to exist in preferences.
I disagree. A problem just recently with a gov site req'd you delete their cookies to resolve it (as an interim solution until they get around some year to fix the issue).
The settings pane gives you a cleaner ui for quick changes (debatable, but I certainly feel this way). Dev tools can break your browser if you do things wrong. They are made for development and deep changes, not routine stuff.
That is not "nothing has changed".
If your site needs users to clear cookies, then you should fix your site. Clearing cookies is not a routine thing.
They're removing the listing of individual cookies for each site. So you can still remove all cookies from, e.g. Hacker News, but will no longer be able to see the individual names of the cookies, e.g. `ph_6CDb7STpzm64A_...`.
I do have to commend you on the bold tone while being so misleading, though. Haha, good stuff. I propose a Law of Increasing Internet Indignation: indignation is a monotonically decreasing function of knowledge.
Physician heal thyself.
> If you click the disclosure triangle for one of the entries, you see… well, basically nothing about the site data. And there are no delete buttons for individual cookies. The only button is "Clear data", an all or nothing option.
Site guidelines suggest that you ought to assume good faith on the part of your conversational partners and responsd courteously to the good faith interpretation of their words.
I suggest you have simply misunderstood what people are complaining about.
That's not good faith interpretation. That's wholesale misinterpretation which is either incompetence or malice. If you want to play the whole "good faith" game, you actually need good faith.
You're all privacy groupies. You don't know anything about actual privacy. You're just an outrage squad. You know it. I know it. But you're performing for some absent audience that supposedly can't tell.
Fine, this site is yours. Keep it. I'll go play with the shellfish.
I have had locally compiled builds break my profile data once or twice, but that's a seperate issue.
So move it somewhere where it makes more sense.
> Truly, editing/deleting individual cookies isn't something any regular user ever needs to do
No true Scotsman? If the user needs to do this, they're automatically not a regular user, or what?
Anyway, hard disagree.
>> All the functionality is already built into Chrome right here: https://developer.chrome.com/docs/devtools/storage/cookies/
It can't both be redundant and be solved by moving one of the interfaces somewhere else. Either you meant to say it's not redundant and is needed but didn't list any reasons why you think this or your idea of simply moving the redundant interface elsewhere doesn't change the point made as it'd still be rudundant and not needed, just elsewhere.
> No true Scotsman? If the user needs to do this, they're automatically not a regular user, or what?
The "No true Scotsman" fallacy comes after redefining the group once a valid counterexample from the original group is defined. It's not a fallacy in itself just to claim a group has an attribute, the claim is still falsifiable and testable by bringing forth the counter case to why a non-developer needs or wants to use a separate settings UI for it. "non-devoloper" wording chosen instead of "regular user" particularly because the ability is still in the developer UI and maybe that'll make the claim about "regular users" a little more defined.
If this were disabling the ability for users to clear cookies for a single site I'd hard disagree but I'm wracking my brain to find a realistic case a non-developer user needs/wants to view and clear individual cookies instead of site based cookies or all cached objects for that specific page. It's seemingly by definition only useful when identifying and fixing bugs from reviewing the source/dev console logs and "clear the cookies for the specific site" is already seemingly rare enough for a user to be told to do by generic troubleshooting. If being told to do it by a developer or support agent the console is still there and again I think it's fair to say we are veering far from typical things that user cares to have in a settings UI vs where it is in the dev console.
I never said it was redundant. Perhaps you mixed me with someone else?
Regardless of how you call the fallacy, I think there still is one since the vagueness of the term "regular user" seems to implicitly define out the users that would need to access the cookie dialogue.
If the wording is switched to "non-developer", then I once again disagree with this conclusion. Non-developers should definitely retain the ability to view, edit and delete their cookies.
I view this mostly as a matter of power. Yes, non-developers won't be editing or deleting individual cookies most of the time. However, if a website starts misbehaving and attempts to seize control of some part of experience from the end user, the end user must have the ability to counter that.
Having the ability to delete and edit pieces of information stored by websites on the user agent is a crucial part of that. If you take this ability away, then you ever so slightly took control out of the hands of the end user. In the end, you are making the user powerless and submitting them under your control.
I believe this is how iOS development works.
Admittedly we are very far away from this scenario, but let us not delude ourselves into thinking (a) that it's impossible, or (b) that it's not in Google's interest to do this once they are confident enough in their market power.
This will be harder, especially where you need to clear cookies on different domains like a login page, saml page, account page, etc.
If I remember right, clearing it for one site didn't help because clearing "login.paypal.com" cookies didn't clear "some-other-thing.paypal.com" or "www.paypal.com". They seem to use www.paypal.com for everything now.
Google for: "paypal Your browser sent a request that this server could not understand" for one example
Or "paypal your last action could not be completed" for another.
> If I remember right, clearing it for one site didn't help because clearing "login.paypal.com" cookies didn't clear "some-other-thing.paypal.com" or "www.paypal.com". They seem to use www.paypal.com for everything now.
Right, but that's not a problem that this particular change is going to do anything about. Previously, you had to find all the different paypal domains and whack their cookies and now you have to do the same. The functionality you can't do in the Preferences window now (but you can in DevTools) is find a single cookie in a single site and whack that one. That's the one that would be Daily WTFy.
One could imagine a browser vendor who made this workflow easy because they thought it was in the users' best interest. Obviously, that browser vendor is not Google.
How many people do you really think would ever need this feature in day to day use, even if it were extremely easy to find? The number is probably vanishingly small.
Also it just so happens that there are extensions that allow you detailed (read: raw and editable) cookie data for each website you visit!
... this, despite the fact that all the APIs are there, and internally, FF is essentially a bunch of "chrome extensions" on top of the C++ core. That is, the only thing that was removed was the ability to _load_ extensions.
FYI.
Now, as you say, you can download an extension (and indeed, I do!), but I think there is some merit to it being in the base app. (E.g., not having to trust an extension. But also, it's part of Firefox's data, and FF should provide decent tooling for itself.)
Hmm, are you sure about that? IIRC, Firefox 90 had ability to remove cookies per exact subdomain in that view (i.e. account.google.com), since version 91 there's only an option to remove cookies for whole google.com domain...
Or is that defective hardware?
Non-developer hat: PlayStation Network store also had a bug where you'd be logged in, but unable to buy anything. Instead of deleting all data you could delete one cookie and it would temporarily resolve the issue.
While I very much agree with the point you're making, I can count on one hand (with fingers to spare) the number of family members I have who know what the developer tools even are, and that's because I showed them when troubleshooting an issue they were having. They aren't going to learn or remember how to access the dev tools to manage cookies, but they do know what it means to delete individual cookies and the current process to do so, and if they forget the exact steps they could certainly figure it out in settings/preferences.
What they're not going to do is think "well, I can't find the thing I used to use to deal with cookies, I'd better go muck around in the developer tools." I'd imagine a very large percentage of non-technical people who have heard about cookies fall into the same category as my relatives, but that's my own bias talking and YMMV of course.
If a non-developer is in a situation where they need to delete a single cookie by name but deleting _all_ of that site's cookies would be ruinous for some reason, then something's horribly wrong.
(And when the need truly does arise, there's a perfectly-good tool for that which is no harder to find than the sub-menu being deprecated.)
Only time I have (probably ever) deleted an individual cookie was for testing during development, and in those cases I already use the dev tools to do so.
(90% or more of most sites' organic web traffic is mobile.)
No? Didn’t think so.
If this individual-cookies-manager settings page didn’t already exist, would you think it worth it to introduce one? More worth it than an individual-localStorage-keys-manager (which clearly nobody is scrabbling for)? If so, why?
When dealing with cookies I don’t want to just wipe all of them! Sometimes I just want to deal with some of them. Not as a developer but as a user of the SSO multidomain 20-redirect hellscape
There are just as many weird problems with websites that cannot currently be fixed in this "pick and choose" manner, because the corrupted state is a single key in the site's localStorage. Instead, the current solution is "blow away the site's localStorage as a whole." (And, in fact, it's usually even less granular than this; you'd usually hit "clear Storage" in the Devtools, blowing away localStorage, AppCache, and a number of other things, all at once.)
Sites' localStorage is thought of as a kind of opaque per-site database—not something to be picked through by users, but rather something that's either in a valid state, or in a corrupt state where it should be purged.
And, as far as I know, that paradigm has been working just fine for everyone! Nobody knows enough about a site they didn't develop themselves to make a change to a single key in a site's localStorage that will take it from a corrupt state to a valid state. The average user—even the average developer—is only likely to corrupt the state further, by making changes roughly at random. We all just "purge localStorage" as one of the "the site is doing weird shit" debugging steps, and never ask for a finer scalpel than that—because that fine scalpel would essentially be akin to picking through the site's memory one raw address-value pair at a time. There'd be no context. It'd be useless, unless-and-until you went through a laborious brute-forcing process.
It's great that you've figured out how to delete particular individual cookies for a site, but you must realize that you learned what worked in each case by brute-force trial and error, in ways that likely corrupted the site's state innumerable times before you created a new valid state. That what you were doing was essentially akin to creating a Game Genie code for the website, poking and prodding at its (opaque!) memory in the hopes that you'll get a useful result, rather than a program crash.
And the argument being put forward in this comments section, is that the mindset required to create a Game Genie code or something like it, automatically implies that the right "home" for said process is the Devtools UX anyway. The Devtools UX gives you the tools needed for iteration and experimentation (a REPL; a live view of the site as you poke at it; etc); while the Settings UX is for knobs and switches where you know what button you want to press from the start, and just need an efficient navigation hierarchy that will let you find it and press it.
By deleting individual cookies within a site's cookie jar, you're debugging that site—poking and prodding at it iteratively—whether you call it that or not. So why expose a secondary, non-iterative interface for doing so? You'd just be encouraging people to do an inherently-iterative process more painfully by using a non-iterative interface.
1. Product management decides which audiences should get special attention.
2. UX researchers get hold of a number of users matching those audiences. Interview them what are their pain points with the product and observe them stumble through a bunch of critical journeys.
3. UX designers design how that should go instead.
4. Eng (including UI) design how to make that happen.
5. The design doc goes through approvals from all the above, but also legal, security, privacy and other stakeholders.
After that, it's a simple matter of programming.
If you use any Google app on iOS, it makes you sign in through a web view, which sets some system-wide cookies.
Meaning if you just want to sign into YouTube, and later search something in Safari etc., you will find yourself signed into Google Search!
I always have to go into the cookies settings and filter by “Google” and remove all of them to get that scummy tracking off my ass.
Same thing with any Google service on desktop browsers.
Seriously, Fuck Google.
I also try to make using a private browser tab or page as my normal way to do web browsing.
I use FireFox for everything personal and Chrome for development. I'd encourage others to do the same. Apart from expressing a "vote" for web standards and interoperability, it also ensures that by default you are separating personal from work / dev which makes things a lot easier when you want to nuke all your browser settings / cache / cookies etc.
Email your reps.
Tell them this is dangerous and that Google shouldn't be allowed to run the entire web. Take chrome away!
The only reason Firefox is even able to exist is Google propping them up with lots of extra money.
I wholeheartedly think it’s a good idea to split browsers between work and personal just so to get familiar with other browsers.
MAYBE, if you want a browsing engine / "webview".
Bad phrasing from my part too, sorry.
https://en.wikipedia.org/wiki/Gecko_(software)#Quantum
I remember it clearly because Firefox got a big performance boost in it's renderer when quantum was released, often it's faster than Chrome.
Swapping your VW Beetle's wheels for a Ferrari's doesn't make it a Ferrari! Even if it improves handling (or whatever I'm not a car person, it's just an accessible analogy)
If you compile servo and point it at the homepage of google, I doubt it renders right now. It was constantly broken even when it had a full-time staff.
Servo still exists and has been spun out of Mozilla's org (https://github.com/servo/servo/). Certainly development will be slower without a dedicated, paid team behind it, but it's still alive (last merge to master was 9 days ago). And perhaps without Mozilla's direct control, it will actually end up becoming the browser you hoped it would be.
I do feel like most of the arguments against Firefox boil down to either website compatibility or performance issues. Using Blink as their rendering engine would kill the first concern completely. I'm not sure if Firefox's current performance issues (real or imagined) are due to the rendering engine or UI, so not sure where that would land.
Very frequent and large feature updates, deepening ecosystem integration that uncharacteristically doesn't get the way if you don't use it.
I always get a bit anxious when one of these massive enterprises suddenly gets up and starts moving with newfound focus, and MS is pretty much sprinting on Adderall at this point.
Unfortunately on Mac, I have to run some JS heavy apps and Firefox's performance on those is dismal. Jetstream benchmark for Chrome is 102 vs Firefox at 65.
I really wish more people would look at and help develop NetSurf[0] or other lightweight browsers with their own layout engines More importantly, I wish that regular users would stop going with the 900 pound Chromium/Blink gorilla, and instead use a greater variety of browsers/engines. This browser monoculture is just pure death.
Last time I looked, only one person had used firefox in the trailing 3 months.
Companies do not want this, this makes it possible to reverse engineer their process, to view what they are doing, and basically takes away control.
They want a future where your browser is instead a portal to the web where various companies just deliver black boxes of bytes to your machine and you don't have visibility into the code that is running, the actions they are performing or what is going on. In such a world they control the platform the content and the delivery mechanism.
Openness is contrary to the goals of these large companies because that causes them to lose control.
Google is rebuilding their Docs for using canvas only[1]. You have no control over it.
Similar things are happening. Web assembly is getting more popular, and in more cases browser is just a sandbox running arbitrary code. E.g Microsoft has huge interest[2].
[1]: https://workspaceupdates.googleblog.com/2021/05/Google-Docs-...
[2]: https://www.infoworld.com/article/3613873/microsoft-gets-ser...
But with the competition as good as dead they can do whatever they want: the bulk of the audience is now captive and has lost either the willpower or the means to attempt to escape.
It's about time we reboot this web thing.
And they don't know it for the most part. People not into computers don't realize what is going on. Sadly, many people into computers don't really care neither.
I still try to speak about privacy and why I think we should care when natural in the conversation with people who are likely to be interested. Often, people actually show interest, especially if you take their perspective in account.
You cannot care if you are not aware. It is a complicated matter which looks very abstract when you haven't had a chance to look into it and think.
And then, some are aware and really don't care. But at least it is a conscious choice.
Firefox works well enough for me.
People complained, Mozilla ignored the complaints and somehow this all just blew over because of browser extensions against tracking cookies.
There's still no replacement for the "ask me every time" cookie dialog.
Same for Chrome.
Linking here to a previous discussion on Firefox containers: https://news.ycombinator.com/item?id=28353876
Most google chrome users aren't techincal users; they aren't familiar with cookie data controls and won't care if they're gone.
Google consistently drops technical features in the name of improving or simplifying UX for most of their userbase (in a way that's aligned with google's interests). This happens since the beginning of Chrome (merging the address bar and search bar seems like that to me); This approach is present in other google products too (e.g. it's harder than ever to override defaults in google search).
There are constant changes to Chrome and these get pushed out in "updates" to selected groups of users, aka "Field Trials". I have never seen any public discussion of any of these changes prior to including them in automatic updates. What makes this change to user control over site data any different. In fact, I can recall years ago Chrome used to let users change Javascript and Cookies settings on a global or per site basis, and from the Address Bar not only a "Settings" page. Then, without any discussion or debate amongst end users, Google changed Chrome. (Note Javascript is needed to store site data via "LocalStorage".) Today, in "Guest mode" on a Chromebook, it's impossible for the user to disable Javascript or Cookies globally in Chrome. Being logged in to the Chromebook is a prerequisite for globally disabling Javascript or Cookies. There is never debate on these design decisions. These are dark patterns. How effective are user complaints at influencing Chrome development. Please cite evidence. Perhaps what we need are user-controlled solutions.
Side note: I can remember a time when it was considered a monumental task to get the entire web-using population to download a new/updated web browser. Almost like a flag day. Today, there is no need for a campaign to get users to "install the latest version of [web browser]." The concept of automating updates is great, but I am not a fan of today's software using "automatic updates" because the way in which developers are using it is user-hostile.
"In my opinion, this change is very unwelcome. It takes away a lot of information and control from the user. For what benefit?"
BEGIN Devil's advocate/"Google's advocate"
Since this is "the orange site", usually it begins with something like, "Googler here. Opinions are my own not Google's."
Our confidential studies show that individuals like the blog author comprise a minority of Chrome users. The majority of users are not aware of such "issues"; they do not publish blogs or give feedback to Google. By all accounts the majority remain satisfied with Chrome as they are not switching to alternatives. We have dominant market share. Our focus is on delivering the best experience for users. Lucky for us, this also happens to be the best experience for our customers, advertisers, and therefore the best outcome for Google. Its win-win-win. It would not be an efficient use of our limited resources to offer a version of the Chrome browser (e.g., field trial) that met the requirements of this blog author, but failed to meet the evolving requirements of Google. Altough we provide free services to our users, we are a business not a charity. If we fail, then the entire world suffers. However we are continually experimenting with improvements to the browser, e.g., based on lawsuits that governments file against us, and we are testing them on various segments of our user base, without needing the user's prior approval for every update. We believe this is the best use of Google's limited resources.
END Devil's advocate/Google's advocate
The orange site commenter's task should be to refute the Google advocate (or defend it). Or even better, give us a more entertaining/thought-provoking Devil's advocate. A fundamental rule of negotiation is that if one can understand the other side's arguments, then she will be far more effective at advancing her own arguments. ("It's difficult to determine Google's motivation for this change." Maybe that's intentional. Maybe Google does not want to open these decisions up for "debate" or negotiation with those affected, i.e., end users.)
"I hope to spur a public debate about it and give some pushback to Google before they make too much "progress" on the change in Chrome."
Good luck. Can someone remind us when that has ever worked before in bringing about changes by Google for the sole benefit of users.
With Privacy Sandbox/FLOC, it appears that debate did stop other browsers from adopting it, but it did not stop Chrome from adopting it.
The more interesting question IMO is what are the possible solutions and how well do they work in practice. For example,
1. Stop using Chrome
2. Use some Chrome extension that "solves" the problem
3. Complain about Chrome on a blog or in a forum and hope for the best
Personally, I have chosen to control site data outside the browser, using a forward proxy. The proxy software does not automatically update itself, it does not run "field trials", and it is not being sued by dozens of goverments. I do not have to make complaints on a blog to try to influence its development. Unlike a web browser from an online advertising funded entity, I have reasonable control over the operation of the software. Through the proxy I can control browsers like Chrome, including headers such as cookies and clear-site-data (https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Cl...). Nonetheless, I fully subscribe to #1 as the current best solution.
google is shit spyware
Their customers being the ones who are buying services from Google.
Not you.
You're the product.
If the audience is the product, Google still has an interest in selling a quality product. That means not running off more and more of the most tech savvy "product" segment.
When it stops being true, it will stop being trotted out as the explanation for why Google keeps making their browser better for their ad revenue business.
> If the audience is the product, Google still has an interest in selling a quality product. That means not running off more and more of the most tech savvy "product" segment.
Why do you think the most tech savvy segment is the target audience? Do you have any idea how many advertising dollars there are in the 12-17 and 18-24 brackets?
Tech savvy doesn't equal hn users.
You think teenagers and college kids aren't using ad blockers or selectively clearing browser history?
There are tech savvy users across all marketing demographics.
>When it stops being true, it will stop being trotted out as the explanation
It's not really an explanation, though. It's a half-baked observation.
Movie theaters make money on concessions, but need the good movies to draw a crowd.
Dealerships make their money on service, but still need to sell cars to get that customer base.
Even if it's true by some skewed definition, it's mostly irrelevant.
It implies that it doesn't matter what they do to users, and have no interest in keeping them satisfied, and that's false. They might want to increase ad business, but that don't do that by allowing users to slowly trickle to alternatives. Look at firefox's fall from the top. There wasn't a breaking point, but a constant trickle due to usability and performance.
The 'you are the product' adage is true, but there isn't a single quality you can have that makes you stand out from thousands if not millions of others. Advertising is a numbers game for them.
Who does grandma or cousin Bob call to "fix" their computer? Who's controlling what browsers get installed on corporate networks and at elementary schools? Or picking the online class systems (and compatible browsers) at universities?
They run off more than the one segment they piss off.
Not if they are the only ones left in the game.
Under Google’s tutelage, the scope and complexity of the web has grown to where it’s near impossible to create an alternative from scratch.
I'd say there's an argument to be made for pushing out the tech savvy from using Chrome.
Compared to the total user base, those folks are a tiny minority who often cause problems by complaining about privacy invasions and develop/use privacy focused extensions.
Why would Google want the small group of folks who draw attention to and sometimes (gasp!) create extensions that limit the ability of Google and Chrome to track/monitor the product herds?
If the folks who actually have a clue as to what Google is up to and how they're implementing it are driven away from Chrome, there will be fewer folks implementing privacy and related extensions for Chrome.
Anheuser-Busch doesn't care that a professional brewer is unlikely to buy cases of Bud Light. In fact, I'm sure they'd prefer they didn't, as that would likely invite negative feedback from those folks.
Having a docile, uninformed pool of "product" to be sold to advertisers gives Google the opportunity to implement more and more tracking/advertising features into Chrome with less pushback from the "product" is likely seen as an unmitigated good by the rapacious and unethical scum who want ever more tracking/monitoring in browser-based interactions.
To extend your analogy, it's not Anheuser-Busch pissing off the brewers. It's Anheuser-Bush pissing off all the hops farmers.
Google's in the same position Microsoft was in the 00s. They don't make most of the stuff people actually want to use. You piss off the people making the stuff, eventually they start making stuff elsewhere.
I hope you're correct about that. That said, I won't hold my breath.
Googs: Fine, where are you going to go instead?
FB: Fine, where are you going to go instead?
Insta: see above
Twit: see above
These people are just fine without the 10 devs that might throw a hissy. (technically 9, because I have to count myself)
Wu-Tang is forever.
The argument that no one uses it is just a front. Real reason is it serves in Google's interest to remove these and that is why they are doing it. Just like GTalk and RSS.
And so it goes....
If you don't trust a site, delete its content or block it. It's not an invasion of your privacy because the UI doesn't let you pick apart the individual bits of encoded gobbledygook in the cookies.
You need Dev Tools to make sense of cookies, and Chief provides that.
I’m not so sure if grass is greener on this site, as the money always decides in the end.
he he he...almost forgot about them saying that. -posted from Firefox.
I can see some users delete cookies to prevent tracking, but should those users really be deciding which cookies to keep and which to delete when nearly all cookies have very user unfriendly names and data contents?
Given that, I agree with the Chrome team here. There shouldn't be a general-public UI to manipulate individual cookies, since making a mistake is very likely and leaks the user's private info. Power users can use the F12 tools.
Um, I'm pretty sure deleting a cookie or too isn't going to leak my private data. If it does, it is because some third party website defaults to doing the stupidest thing possible.
I can only think of one high-quality browser that belongs to a non profit. Mozilla Firefox. All money earned with it goes back to the browser. Sure, I’ve heard that executive may have been paid a subjectively “too high” salary and however true that may be: So far, no Executive who would actively question the mission and the core privacy principles has been able to stay for long.
The web is the most open, most unowned application platform out there. It’s too important for single-vendor control.
In addition to Chrome, I'm using six other browsers which work well with HN, my own sites, fb, gmail, ...
I think in today's Web we've achieved an incredible level of compatibility, interoperability, and accessibility.
Are there many sites which don't work across 25 years or 15 years or even 5 years worth of client software? Sure, but...
There are also restaurants I don't go to, roads I don't walk down, and people I don't associate with...
When a site tells me my browser is not good enough, I just turn around and stop visiting, e.g. twitter, reddit, imgur...
The Web is better than ever for me, thanks to this strategy. I've heard it called boundaries and self-respect.
--
Written on a 2012 iPad mini with iOS 9.x Safari.
Most of the sites I visit are normal ones like HN. The ones that are not, there's only so much malware an advertising network can stuff in when ublock is present.