Mozilla says Chrome’s latest feature enables surveillance
howtogeek.com
howtogeek.com
This API is behind a permission prompt that can only be triggered in response to a user gesture, so the bar to entry is high. The example on web.dev is a chat app that would automatically set an active/away status: seems useful! IMO I ought to have the ability to cash in some of my privacy chips (so to speak) on a site that I know and trust and that I want extra functionality from.
Relatedly, I feel like Safari is heavy-handed in the opposite direction. For example, it removes all locally stored data from a site if it isn't used within 7 days. There are sites I use less frequently than that where I'd still appreciate the ability to save information, but I don't have a choice. It all but guarantees sites need logins, backend storage etc. just to store simple data, which ends up being just as big a privacy danger!
Every single feature on the web that gets misused has some useful applications too. For me, the useful applications hardly ever outweigh the downsides. The web has been getting progressively worse and worse.
That's why you have the permission prompt.
Okay, but you can already do that.
This can easily be abused for stalkerish behavior. Even read receipts in chat apps like Facebook should be able to be disabled by the user. (You can, with some JS injection, but basically that means programmers' privacy is respected and non-programmers' privacy is violated.)
Also micromanagement.
I once had a coworker who would "pounce" on me when my Slack status became active, instead of respecting the time I needed to code. I had to set my Slack status to always away.
Well, sure. Any away/active status can be used for bad things. Pretty much any form of text communication can, too. We all opt in and out of things according to our level of comfort, like with the permission prompt this API provides.
You can just opt out if you're not comfortable with it.
(besides, payment APIs are already able to request your contact information in order to bill you and ship things to you. And guess what: pretty useful!)
Somehow, we all sleep at night anyway.
Slack isn't as bothersome (it doesn't seem to try to detect "stepped away from the computer for 5 minutes", it's just "closed the app for the day" or "has the app open", which is better than Discord), but it's a feature that should totally go away.
Slack's "z" indicator for "outside of work hours" is fine. I will note the irony behind switching to Slack only to have Slackbot send them a "electronic mail" when they get back online ;) If only there was some other system that could send messages to users and have them read them when they feel like it.
It really isn't. Some time look at the permissions controls in Chrome. https://twitter.com/dmitriid/status/1434086651362430976?s=20
Most of these toggles will pop up a permissions dialog. Trigger enough of those, and the user will either dismiss them automatically or accept automatically.
https://idle-detection.glitch.me/
and click "ephemeral", it shows a prompt next to the address bar saying "idle-detection.glitch.me wants to know when you're actively using this device" and has buttons for "block" and "allow". So I don't know how "it really isn't" could be true in this case.
I have an alternative way to do this. Check if a user hasn't interacted with your text box in x period of time. If they haven't, set them to away.
I'm sure people can come up with other methods too. It just seems like there's a thousand ways to skin this cat that don't have the same potential for privacy issues.
There is always a less convenient and more manual way. Pointing that out helps no one.
Not sure I understand your special case here.
If I go out for a walk or I go watch some TV or otherwise stop using my computer, depending on the chat app I want to either automatically be 'unavailable' (for work chat app), or I want to stay 'available' but have notifications go to my phone instead of the chat tab (for friends' chat apps).
That suggests to me that this feature is more than just "did you touch that particular tab", and I'm not really sure how you're reading it differently?
Even only with public group messages, you can figure out some others sleep schedule or when is he/she mostly active if you have enough data. This api will only make things worse because it trace you 'actively' now.
Besides that, you are able to send message when other is not here is the biggest point of a text chat app. If you must chat instantly, why not just call with phone?
That's exactly how Google uses it. They will make an interesting feature, that absolutely require this to be enabled.
It's similar to how to get list of recently watched YouTube video on your phone you need to give permission to Google to log your history, because it's impossible, of course, to store that locally on your phone.
There is a bifurcation of people who want to learn about the tech they use every day, and those that don't.
Those that don't can't be saved if they won't grab around for the life raft.
Rest of us still want to build PWAs.
Similarly, there are people who don't work on websites, writing javascript, in fact they think they think those people are dumb monkeys who can't even make their stuff work on all browsers.
They don't care about latest features, in fact they prefer browser being a dumb tool to view websites not a replacement for an OS.
However this is assuming Chrome won't have a whitelist of favoured domains that can bypass permission prompts like it has for other features (audio auto-play, and I believe also some VR-functionality, probably other things on top since I last checked). I gave the linked pages a quick look but it looks like the feature is still being worked on, and...I'm too tired to look through draft spec documents right now...
There's no bar of entry whatsoever for this. Chrome will automatically update itself to Chrome 94 and voila - it tracks your idle status. Worse yet is if you try to complain, they can shift the conversation by saying the ability is there for websites behind a permission dialog, and of course they take user privacy seriously. Basically exactly what you've done!
I don't think it's paranoid to assume nefarious intent because web devs weren't asking for this functionality nor was it impossible before. You add a mouse listener to the page, you check document.hidden, etc. With so many techniques already available ask yourself: why did Google spend time building this? And why didn't they consult other web stakeholders?
>I don't think it's paranoid to assume nefarious intent because web devs weren't asking for this functionality
I use chat webapps occasionally like Discord and it would be very useful there. Right now I usually use the desktop application which is basically a wrapper around the web app with a few more abilities like idleness tracking. It would be nice if the web app could have that functionality so I don't have to run an unsandboxed executable on my computer with access to all my files just for it.
>nor was it impossible before. You add a mouse listener to the page, you check document.hidden, etc.
That only tracks idleness within the current tab, not the whole device. For chat applications that difference is important.
You could argue that Chrome was already doing this and sending that data back to Google over telemetry. (I don't know if they were.) That's where my second point comes in. Before, they had no justification for this. If they do it, it would look like creepy tracking. Now if you call attention to it they can say oh that's just there to power idleness API, nothing to worry about.
Here I am deliberately designing apps that track no user interaction data at all. Maybe that's why Google doesn't even list my app even though it's one of the longest running "web apps" alive and used to be listed #1 when it first came out. Now they have more ads for similar apps than search results on a search results page.
Is your hypothesis that Google would have some incentive that you collect user interaction data? Why would that be?
> used to be listed #1 when it first came out
Back in 2002. A lot has happened since then. Your app [1] is not comparable to what competitors like Zoho offer. There's plenty of potential reasons for not being ranked higher: from the landing page, to the increase in SaaS competition, to not keeping up with UX trends etc.
That's not what ezInvoice does. There is a lot of crossover in the features we offer, but they're not really the same.
As to keeping up, the ezInvoice app is a Cloud app, and it's also a "Single Page", Offline-First, and Local-First app, so you're either missing that or ignoring it.
>> Is your hypothesis that Google would have some incentive that you collect user interaction data? Why would that be?
Goggle is in the business of collecting as much data on users as they can, and that includes the users of the products advertised on their platform and those companies that place them. They offer services specifically for that purpose and as far as I know Google sells data to other corporations.
https://cloud.google.com/solutions/financial-services/datash...
you're right! at least before it was somewhat mitigated I think?, you can measure timing Chrome used to slow down inactive tabs with rounded ms I believe I'd have to check the fingerprinting JS i wrote a few years ago.
Mouse movement is a good one too.
I'm sure there are other hacks maybe onfocus the entire window and poll it.
IntersectionObserver sounds like a good thread, there is a good polyfill library too.
When browsing Firefox in Incognito mode with uBlock Origin and uMatrix fully active, the Recaptcha challenges load painfully slowly. Like each picture might take upwards of five seconds to refresh.
And to my delight, I have noticed that if I flip away from that tab while the panels are refreshing, they pause until I bring the tab back into active focus.
It's a slap in the face that this kind of user-hostile design is allowed.
When I log into my account, it starts up some react or angular type bullcrap that takes literally 5-10 seconds to fully load no matter what computer I'm on or what browser I'm in. If I switch away to another tab to do something else while it's doing that, _it will never fully load_. The only option is to sit there with the tab open and stare at it until my account information appears.
In 2021, I guess I should just be happy that they're not showing me ad while wasting my time.
https://developer.mozilla.org/en-US/docs/Web/API/Page_Visibi...
It's obvious when you the Page Visibility API original editors/authors: https://www.w3.org/TR/page-visibility-2/
Both of which you could argue 'allow for surveillance'
What user-oriented use-cases does this enable which couldn’t have been done otherwise?
I really thinks this is apples vs oranges.
In this case:
> Making these distinctions is important for applications which have the option of delivering notifications across multiple devices, such as a desktop and smartphone. Users may find it frustrating when notifications are delivered to the wrong device or are disruptive. For example, if they switch from a tab containing a messaging application to one for a document they are editing, the messaging application, not being able to observe that the user is still interacting with their device, may assume that they have left to grab a coffee and start delivering notifications to their phone, causing it to buzz distractingly, instead of displaying notifications on their desktop or incrementing a badge count.
Is any webapp doing this? To me it sounds like multiple steps into the future:
- First a webapp has to have the capability to notify just one device, so in this case your browser and not also your phone. I cant think of an app where you dont receive double notifications on web+mobile (or triple with a smartwatch).
- The webapp then needs to be smart enough to dynamically select the "most active" device to send the notification to.
- The new feature can then be used as a workaround for "incorrectly" classifying your computer as an inactive device, because you are not interacting with the webpage anymore.
being spied on supposedly so the system can decide where to send you messages is a bad idea.
An opt-in system to allow GPS (or idle detection) is an explicit control, but it is not toggling the usage of this low level feature, which is the important part that I want to approve. Approvals should not be blanket.
Unless the feature is designed to fake data and make permission status opaque to the remote, it's a privacy reduction that will happen, the only question is when.
1. Most people aren't engineers and don't understand the privacy implications of this, and these types of metadata collections. Browsers aren't just developer tools, they are made for the general public.
2. I already get spammed by too many permission popups; rarely are they for purposes that benefit the user. It would be interested to see some stats on how many users simply accept these popups to dismiss them without regard for the consequences.
ISTR the motion sensing web APIs worked on Mac laptops when they were originally added (then later stopped working, either intentionally or through neglect).
Gee whiz! I guess we'll just have to wait and see if G ends up being evil or not
To move this sort of paradigm back into OS would require a wholesale re-write of APIs and how they're accessed.
Surprise! Both Apple and Microsoft did that, but neither of their new APIs caught on, because the benefit of being a native app was outshined by losing the easy access to the user data. So from the dev's stand point they may as well get the benefits of cross platform that web-apps afford if they're gonna have to deal with the gate-keeping anyways; native performance be damned.
Is it watching my camera?
Or just no mouse or keyboard activity for a while — because if the latter, my website could already know that.
We built an app for distance learning which put something a lot more invasive (but with permission)… namely eye tracking and facial recognition to see whether the kids are paying attention. It’s actually LESS invasive than the current alternative — requiring the kid to keep their camera on. Now the teacher jusy knows when the kid is present and when not.
Frankly, USA public schooling is about as invasive and controlling for kids as schooling can get. Every minute of their lives inside the school is regimented. So distance learning can be a respite.
Instead of designing a system that allows third parties to offer alternative browsers they decided to be selfish and do everything by themselves for themselves, and wonder why their market share continues to plummet.
Where is the GeckoView alernative for desktops that would allow their technology further reach?
More likely their share is smaller because they're competing against one of the largest companies in the world.