[1] https://bugzilla.mozilla.org/show_bug.cgi?id=1369357
[2] https://addons.mozilla.org/en-US/firefox/addon/zoom-page-we
[1] https://bugzilla.mozilla.org/show_bug.cgi?id=1369357
[2] https://addons.mozilla.org/en-US/firefox/addon/zoom-page-we
It would be very interesting to develop a modern web based purely on declarative content (modern HTML/CSS). HTMX is an interesting take on this, although it's currently implemented as server-provided JS: i don't see a reason why such patterns couldn't be implemented by the browser itself.
For sure. I think some scripting could also potentially be implementable without massive fingerprinting / privacy implications. E.g. pure compute scripts, form validation, etc. that has no practical way to smuggle any data out of your browser. Anything that sends a request would have to be statically derived (or explicit user input as into form).
EDIT: Just for the sake of mentioning, simple/obvious computations for interactivity was the promise of GNU's libreJS project. I'm unaware of the current state of it, though.
Is not that the subset of the web that would work when javascript is disabled? Some already develop it in that direction - what is not declarative shall be unnecessary. Or are you suggesting something different?
I don't understand why we need to have dozens of CSS frameworks for "components" that have become common practice across the ecosystem. Pagination, "Hero" elements, intra-page tabs, breadcrumbs (and many others) should be HTML standard so that it's more accessible and users can come up with their own stylesheets. The breadcrumbs for example would enable your browser UI to show a "go up" button like your file browser does. Another interesting example would be element filtering: why can't a <form> with a local action property (like "#data") be used to filter a list of elements without JS?
As long as most UI of a page is dictated by dozens of piled-upon CSS hacks, user stylesheets will remain a wild dream. But given how little variety there is on the web these days, many things could be standardized part of the HTML spec so that CSS is only needed for customization (eg. colors, spacing) on simpler pages, while retaining the possibility for the server to suggest more complex CSS UIs as we currently do if you absolutely want to do that.
There is something like that, the Gemini protocol.
I understand the appeal of simplicity but if you ask me that's a huge step backwards compared to HTML5. No <form>, no <section>/<article... It's like markdown but with another syntax :-/
it wouldn't be much work
Also, is there some good venues to discuss the semantic/declarative web with you htmx folks and hopefully people from other like-minded projects? IRC? XMPP? Matrix?
We use discord for chat right now:
Do you maybe have a gateway/bridge to a libre network such as IRC/XMPP/Matrix? I find HTMX pretty interesting but i wouldn't touch discord with a 10-foot pole, if only because my limited computing resources won't allow for such a resource-hungry app to run in the background.
It seems like matterbridge supports discord backend but i don't have a discord account to try it with. If you're not willing to host matterbridge, i'm already hosting one and i would just need credentials to try and connect it to Discord. If you're willing to give that a try, feel free to mail me at my username @ thunix.net.
I wrote more but I sound like old man shouts at cloud. I've got ad and JavaScript blockers, but so much of the web is created sitting upon a mesh of invasive bullshit that it breaks easily.
Shakes fist at cloud anyway.
IE, web component where you can set a format string and then the browser renders it substituting the info it has?
Then sites that need to know the date can ask for it.
There's a lot we could do by splitting stuff into permissions and some sort of standard templates.
I use a site that only does UTC, and time zone related complaints are the most common issue asked about on the forums
you can easily detect this
- please display this localdatetime as a string
- read it back and parse it
- are they (almost) exactly multiples of 60 minutes apart?
- if yes it's most probably your timezoneAnd displaying time/date locally would leak that information anyway if you wanted to do it in a way that works in various contexts it would need to in a website (e.g. canvas based apps)
even if you just let the user stylize the font of the date (which you clearly would need to), you tell your magic date input to only show the current hour, then use a font that has a certain width for each number, allowing you to then based on the width of that element figure out the hour, same for other things, obviously. It's easy to imagine some thing like that without thinking about all the details, but it's not really feasible once you think about how this would be implemented and how it could be circumvented. And that's in addition to not working in contexts where you schedule a blog post, zoom meeting, or whatever else might require the server to account for user time zone
We could question if that’s really necessary as well but the ship has kind of sailed on that one.
People should be trained to allow script execution only when they trust the site, and there should be levels: Zero, Fully Isolated, Trusted.
OK now time to wait for someone to tell me this will be too much to ask from users. It wouldn't be an invalid point either, we can't even train people to have some common sense when in control of tons of steel going fast loaded with highly flammable liquids... So, there's that.
I don't know.
I don't think it would work when there's a state across views or server though, but maybe that's something you avoid when using Tor anyway?
One could use element.getBoundingClientRect and similar APIs to measure what size certain elements are rendered at and compare that with their default size for instance.
The resulting zoom level can then be used as a signal for fingerprinting.
Seeing that a user has a site's zoom set to 90% seems to be close to worthless in terms of narrowing down what cohort they're in, let alone identifying them individually. What am I missing here?
It's just another bit of information. Collect enough bits and eventually you'll have a likely-unique id. It doesn't matter what that information is as long as it somehow is about you (and not e.g. random). If you want to fingerprint, you just try to grab every bit of information you can, no matter how irrelevant it is taken on its own.
It doesn't need to say anything about a cohort to be useful, it just needs to enable identifying so that they can track you around and eventually combine other information they discover about you in a profile. And it doesn't even need to be 100% accurate; "that person coming from a Telia-owned IP visiting this site again at 2 AM GMT+2 using Firefox Nightly on Linux, with 1440p display and 120% zoom level and no fonts installed" could be two or three guys if I'm lucky but it's probably close enough to not matter for someone who just wants to sell me garbage.
If your zoom level were the only thing, then indeed it would be useless. Problem is, browsers leak lots of bits. It's better to try plug all leaks you can than it is to ask whether that particular leak alone is harmful enough.
How so? 90% is by far not the normal zoom level people browser with, so it is a perfectly valid data point to use for fingerprinting. Every single bit of data they can get makes your whole fingerprint more unique.
You can see the informational content of various fingerprints here: https://coveryourtracks.eff.org/
Another thing that has less than a bit of content is having cookies enabled. Nearly everyone has cookies enabled, for better or worse, so having them on doesn't add much to a fingerprint. Having them off adds far more. But both add something.
Differential calculus. One negligibility times by a huge amount equals one discreet amount. One bit here, one bit there, you get a fingerprint of a thoundred bits.