Mozilla claims Apple, Google and Microsoft force users to use default browsers
techradar.com
techradar.com
But this goes way beyond the browsers - I've never explicitly installed Keychain on my iphone and yet it shows as an option next to 1password every time I fill in a password field. Google calendar asks me to install an app every time I open a web version on my phone, my work laptop has 1 active notification in system settings for a year because I didn't enable iCloud backup.
I'm not sure what's the solution here. I stick to the apps I use because I know what I'm doing, but so many users will just click "yes" when shown a pop-up. On the other hand, the built-in integrations provide value (e.g. it's better that people use and save random passwords in Keychain than using the same one everywhere). I feel it's always a cat-and-mouse game where the big tech is punished after they've already gained a lot, so they win anyway.
- The keychain is an essential part of macOS and iOS; if an application wants to securely save data then that is the interface it uses. This is not optional because a huge proportion of applications would break if it were removed.
- iCloud Keychain is the feature of iCloud that syncs your keychain to iCloud. iCloud itself is opt-in, and this particular feature of iCloud is opt-in as well, I think, or at the very least optional even if you use iCloud.
- Safari has a built-in password manager, like every other browser these days. This saves to the keychain, whether that’s synced or not.
[ ] Show me the Windows welcome experience after updates ...
[ ] Suggest ways I can finish setting up my device ...
[ ] Get tips, tricks, ...
It happens all the time, for lots of people.
To be sure, this isn't just restricted to "please install this" dark patterns, and in certain ways it's been central to the ad-supported business model ever since the first television ad was shown on a network channel. But arguably we shouldn't give any of these examples credit for truthfully being "opt out."
Edge even has special behavior to show you the same bullshit when you try to download another browser [1] [2]. But no worries, they might get a slap on the wrist for it.
[1] https://www.xda-developers.com/microsoft-edge-chrome-2008/
- PDFs (sometimes, even if you don't have Edge set as your default PDF app) (even though Edge is actually the least unusable non-paid PDF viewer for Windows)
Besides that, Edge will randomly reset itself as the default on updates.
It's a dark pattern Apple repeats with a lot of notifications - they are not dismissible and give the appearance they are only resolvable by completing the notified request, but it actuality just starting the setup and then cancelling will resolve it.
Inside the *CONTROL PANEL* of the latest iOS.
And the acquisitions...
I've had countless minecraft sessions ruined because of microsoft account / store issues. Don't even get me started on realms and the chat policing bullshit.
Github new PR review UI is great on paper yet completely useless to review large PR because of performance issues.
It took me one month to upgrade a zoom account to pro because the checkout would just show a blank page. Oh and I can't stay signed in on zoom.us because I disable "Functional Cookies", yet that's the only website that's ever had an issue, and I'm not using a hardened setup, just vanilla FF.
So much for the modern, developer and open source-friendly narrative.
Heh, try KDE's KRunner. I type 'kt' and it matches ktorrent. But if I type 'kto' it switches to matching "Desktop 8". 'ktor' once again matches ktorrent.
I hate this behaviour, as I'm usually looking as my fingers type the last bit, and if I keep adding matching letters, please don't change?
When you enter your birthday during Windows installation (yes, you have to have a Microsoft network account to log in to your own computer, and you have to supply a birthday), the button for confirming the date is a small, grey checkmark hiding below the date picker. Clicking the big, blue “Continue” button in the lower corner will discard your date choice (since it wasn’t picked) and then fail form validation because you didn’t pick a date.
There is a certain cubicle masochism associated with this kind of system. I’m convinced that computers did not get easier to use since all of them had command prompts. But you know, it’s got windows!
"Chery"
I'm misspelling CherryTree.
Instead of getting note taking software, VLC starts playing "11 - Pulmonary Archery (Explicit).flac"
This is annoying not just because it's not what I wanted, but also because I already have music playing, music which is now abruptly cut off.
Another anecdote is that minecraft 1.19 doesn't work on Ubuntu 18, as it uses glibc 2.29. D:
[0]: https://executor.dk/
If you want to read the specifics of my transition to Linux: https://www.scottrlarson.com/publications/publication-transi...
As an engineer I feel like it's a great investment and loving my setup has a big impact on the enjoyment I get from work.
If you spend the time, can all the annoying stuff be turned off in Windows?
I can't seem to get two Windows installs to be functionally identical the same way. I also can't believe winget is a relatively new invention.
You can turn off most of the annoying stuff, for a time. I'm convinced that sometimes settings just change on their own.
This (requiring elevated privileges) is a very niche thing, though (raw access to the serial port).
Yes, for this very niche thing Windows works out the box. For other not so niche things, Linux works out the box. For the not so niche thing of "set up a LAMP stack" and similar, Windows is pretty poor at it, compared to using apt-get.
Also, for this very niche thing, I'm pretty certain that the arduino IDE I installed from the repository worked out the box for serial port access.
I'm guessing that you pretended the Linux boxes were Windows, and installed on Linux by downloading it off the arduino distribution site?
Yes, that was a mistake. But it was not as simple as saying "install from apt-get" because some where using Arch-based distros (pacman), a few were using Fedora (yum) and others Ubuntu. Even so, not always that the user is added to the right group. Also, we wanted to show the new 2.0 IDE.
Had some issues after Win10->Win11 beta Insider build updates, but that's other story.
Win + WSL gives you both Linux and Windows tools at your disposal.
my solution is to use windows for GUI things, and a remote linux instance for actual building/running/deploying services. vs code server is really nice for this, you can essentially run it as a GUI thin client locally that controls a headless remote that does all the heavy lifting. it's pretty seamless if you're willing to accept that you need a network connection to get any work done.
Not sure where powertools come in, but I’m personally agnostic wrt. shell scripting flavours.
1) find my mouse
2) search through windows titles (I tend to have 15-30 terminals with ssh)
That's exactly what it is: encouraging "developers", some of whom IMHO shouldn't even be writing software, to indulge in "coding" while completely ignoring and antagonising the user perspective. Countless users' workflows just broken with no recourse just because some selfish bastard wanted to use something "new and different" without considering the wider effects. When the culture only cares about promoting new and shiny tools/frameworks/etc. to developers and feeding their appetite for otherwise useless things, and in doing so, forsakes the original purpose of software, this is the result.
It's even worse. I want to open Notepad++ and begin to type
N -> notepad.exe
No -> notepad.exe
Not -> Notepad++
Note -> notepad.exe
Notep -> Notepad++
Notepa -> Notepad++
Notepad -> notepad.exe
The times I actually wanted to open notepad.exe is exactly 0 but the stupid algorithm sees me mistakenly opening notepad.exe because of the aforementioned stupid algorithm and recommends it even more often. It's like it's designed to create the most annoying search experience possible.
N -> OneNote.app
-> Then (maybe) quickly changes to Notes
No -> Notes.app
-> Then (maybe) changes to OneNote
Not -> OneNote.app
Note -> Notes.app
etcAt least that's how it was before. I wouldn't be surprised if they broke it.
I use both of these, and it looks like Windows has remembered I select one or the other at a given point, so is saving that suggestion.
It also likely has built in associations for the default applications (notepad, camera, etc.) that you've overridden by selecting notepad++ at those points. If you select/locate notepad++ at the other positions, I wonder if it will start suggesting that instead.
[0]Honestly how? I have 32GB of ram, the name and directory of every program I've ever run probably fits in 100kB. You could even presort the list by the first two possible letters (26^2) at a tolerable memory usage.
[1]To my tastes anyway.
R -> "R, the project for statistical computing" (fair I suppose)
Ru -> Run (what is "run"? It's that little dialog box from Windows 3.1 where you can type in an executable to run)
Run -> Run
Rune -> RuneScape (not something I have installed)
Runem -> Some Hearthstone game file
Runemac -> Search results for "run amok".
Runemacs -> Hey the thing!
This makes it even more inexcusable for the default Windows behaviour to be stupid.
This is the best. It opens immediately, no animations, ads, etc. I have a .bin folder in my home dir with full off shortcuts, this folder added to the $PATH so I just need to type my shortcuts to open any app.
If you want fuzzy searching to work, add a shortcut in the start menu for runemacs by placing the shortcut in %APPDATA%\Microsoft\Windows\Start Menu
I would be completely happy if my win10 stopped deciding I really want to search the word notepad on the internet with edge/bing
I still prefer Firefox, though.
The research concluded that Microsoft Edge is the most invasive, along with Yandex.
Not to mention their new loan scams. Edge is a spyware/adware first and browser second.
It really needs to be possible to say "no means no". But somehow, continuously nagging seems to have become acceptable.
It is worth noting that KeyChain was introduced in Mac OS 8.6 in 1999, and has been part of every version of macOS since then, as well as every version of iOS ever. It's basically the user credential subsystem for Apple operating systems.
As I understand it, 1Password came out in 2006.
When I looked at it last, it seemed that 1Password didn't interoperate well with KeyChain and also required a subscription - decisions which I found unappealing.
It's a system app. You also didn't explicitly install the TV app yet here we are.
Settings -> Passwords -> Password Options -> uncheck iCloud Passwords & Keychain
Microsoft started spending dramatically more money on "lobbying" following that.
[1] - https://en.wikipedia.org/wiki/United_States_v._Microsoft_Cor....
Facebook acquired and repeatedly copied its closest competitors, no problem. Adobe buys up its competitors, no problem. Google aggressively pushes Chrome and fails to makes its own websites fully compatible with competitors, carry on. Apple refuses to give users the freedom to run their own apps on their purchased phones, no biggie.
Was there some kind of official policy shift, or did the government just give up?
https://www.history.com/topics/united-states-constitution/ci...
Again, all of this is conjecture. There's a lot of strangeness that surrounds the US intelligence agencies though, so I'm inclined to make some sense of it.
The US intelligence service is also a bureaucracy, and people seem to forget that. Just because something is "secret" doesn't mean it is romantic or Bornesque.
Context: I have not held a TS clearance or been employed with the US government nor contractor for a little over 3 years.
hunter-gatherer sounds about right on the money.
I've previously held a TS SCI clearance within an organization. I wasn't an S-2 guy, but worked with them and troubleshot stuff in the SCIF from time-to-time. I did some auditing in well-known buildings, blah blah blah.
Basically, the more secretive things get, the more bureaucratic and tedious they get. The more impossibly hard it is to do literally anything without at least 5 or 6 meetings to discuss the poteintal outcomes and risks therein. I suppose when you get to the kinds of things POTUS wants done right now, it could get weird? I don't know, never been in that position. But the amount of oversight and auditing that gets done by people that refuse to do anything that could risk their retirement? It is excessive. At more than a few points I found myself "preparing for the pre-inspection, inspection." That inspection, which would happen however often, was essentially always happening. You were either "learning from the last one" or you were "cleaning up for the next one". Just absolutely soul crushing.
I should also mention, even though some of the words I used above might sound interesting, it really comes down to carpeting. Carpeting sucks everywhere in the government. They can spend tons of cash on stupid meeting room tables for conference calls or whatever, but the thing you walk and stand on is just absolutely awful. Except in an executive officers office. The office that goes completely unused because they're out doing...whatever it is they do. Golf? Lunch? Who knows. Once you notice the little things like that, or light fixtures just looking like trash, you realize that all of the magical ideas people have about the big scary government is just kind of...quaint. Like things can be important or sensitive or whatever, but it's just not the way people imagine it being. It's too bogged down in the mud to be what people think it is.
Getting basic things like light fixtures changed out becomes a major hassle because, if it requires a dude on a ladder, now that dude on a ladder also has to have a clearance, and the room has to be sanitized. Don't forget to turn on the red light, so no one forgets that there is a guy up on that ladder! Getting one bulb changed can interrupt your work for at least an hour or two. It's insane.
Like, we had one cleaning lady. For a building of...a lot of people. Everyone loved her and treated her great. Do you know why that was? (Well, she was totally awesome and nice. But besides that.) It was because if she quit, there would be no one to replace her. That would mean every desk jockey in the building would be lugging their trash to the locked dumpster halfway across the parking lot in the hot sun. Then have to go through all of the fun stuff that goes with getting through the front door. They treated her like royalty!
Right before I left, they did actually get some young guy in there. If I had to guess, they went with him because they were hoping he would stick around for at least two to three decades.
It even comes with a handy Q&A technical FAQ like ensuring you can also get the chat of the person the target is speaking to, or why you might receive multiple copies of one message (a target that is synching on another device has all of that data forwarded onto the NSA as well, so you get repeat messages). Quite user friendly! I'd love to see the UI.
---
Incidentally, I'm not saying you're lying. The reality is that most of government is just bureaucracy. The NSA has tens of thousands of employees, a budget in the tens of billions of dollars, and their fingers in everything all the way down to World of Warcraft. [2] The guy tasked with spying on elves and death knights (which, shockingly, never turned up anything) is going to have a different view of the agency than the guy who is doing things like spying on people's Skype conversations, or the person who is producing the metadata upon which people end up being killed.
[1] - https://grid.glendon.yorku.ca/items/show/74
[2] - https://www.smithsonianmag.com/smart-news/the-nsa-was-spying...
Bush+Cheney did the PSP: https://en.wikipedia.org/wiki/President%27s_Surveillance_Pro...
The courts found that unconstitutional: https://www.aaup.org/brief/aclu-v-nsa-493-f3d-644-6th-cir-20...
Obama publicly condemned the Patriot Act, but extended it in 2015: https://en.wikipedia.org/wiki/USA_Freedom_Act
Meanwhile Obama's VP (Joseph Biden) claims to have written the Patriot Act: https://www.c-span.org/video/?c4876107/user-clip-joe-biden-w...
In '91, the FBI got Joseph Biden to introduce a bill banning encrypted cellphone calls in the United States (Subtitle B: Electronic Communications): https://www.congress.gov/bill/102nd-congress/senate-bill/266
This move by Joseph Biden was condemned by the founder of the EFF: https://www.eff.org/pages/decrypting-puzzle-palace
You can watch a gaggle of senators from both parties go to bat defending the PSP in 2013 here: https://www.intelligence.senate.gov/hearings/open-hearing-fi...
After the PSP was found to be unconstitutional, you can watch another gaggle of senators from both parties go to bat defending the PSP in 2017 here: https://www.intelligence.senate.gov/hearings/open-hearing-fi...
A notable quote from the above video from Senator Wyden suggests the 3 letter agencies are harvesting location data in mass from cellphone towers.
You see surveillance legislation move forward with support from both parties - often under the guise of protecting children or stopping terrorists. It's not a stretch to connect the dots between our 3 letter agencies working with legislators in the background to advance the surveillance state, and those legislators simultaneously working with MAANG on multiple fronts, to assume there is some level of crossover with the surveillance agenda. It would be more unreasonable to assume they keep their surveillance objectives isolated from their interactions with industry after the Snowden revelations - which showed us that they absolutely worked with industry to collect PII of U.S. citizens in mass.
Mostly think tanks, policy circles, and White House wonks over every successive Internet-age administration. All segments of the U.S. government pay close attention to, among many people, geopolitical analysis of all stripes, who can help them understand how to remain the world hegemon. The U.S. frequently commissions studies by outfits like Booz Allen Hamilton on geopolitical matters (you can browse the "DoD Reading Room" to read plenty of the these thanks to FOIA requests[0]).
"Breaking them up would hurt the U.S." isn't just a lobbyist argument, it's deeply understood at all levels of the government. The White House absolutely understands that Silicon Valley is part of the U.S.'s soft power, draws plenty of international students to the U.S., and helps the U.S.'s cultural hegemony. It's not just about the most popular social networks and search engine "belonging to them" (though that's obviously important, and an advantage no rational nation would give up); Google and Meta's R&D spending are also huge elements of the U.S.'s "artificial intelligence dominance" over China, and the U.S. will never break them up simply because it sees AI-dominance as one of the most important elements of its geopolitical strategy.
It's easy to get the impression that the government mostly deals with domestic politics; but at its root, it is deeply and overwhelmingly concerned with fundamental strategic questions. The government cares deeply about U.S. universities remaining the world's best; about immigration remaining high (Republican administrations too) so that it can attract as much skilled labor as possible, grow the economy, compete with China's 1.4B population, and avoid an aging population that would decimate the economy for decades.
Policy debates "inside the government" bear very little resemblence to the TV version the American citizenry is obsessed with.
[0]: see, for example, "The Future of Europe", a 177 page evaluation of Europe's future economic, industrial, demographic, and political trends. https://www.esd.whs.mil/Portals/54/Documents/FOID/Reading%20... After you read it, you'll understand that the "policy debates" the masses are exposed to have very little resemblence with what preoccupies decisionmakers! The government, no matter the administration, is far more rigorous and strategic than people give it credit for.
Forcing windows, android, and ios on your citizens and gifting silicon valley a constant worldwide surveillance feed is incredibly harmful to long term interests. Forcing every business to use office365 to interact with any government office is a 1% income tax gifted to the american economy.
But there's no reason for countries like India not to do it. Russia did it; it's not just massive countries that can get away with it.
Could even mandate that any inter-operation occurs over open protocols with at least two implementations (many governments even have this policy for essential systems, they just forget to enforce it around microsoft).
In this case the example document you quote is rather poorly chosen and does not really seem "rigorous" at all. Most if not all topics the document touches are basically the same that monopolize "policy debates" everywhere all 24h of the day (immigration, nationalism, welfare, and immigration. did I say immigration?), and the conclusions are defended as poorly as your average comment from Reddit. The document does not even get the names of many regions and cities correctly; the grammar is at many points terrible; many of the figures and charts look as if made with Paint, and whenever they are not, they are screen-scrapped from random websites and then poorly JPEG recompressed. Heck, at some point they even use Google Trends as source...
My humble opinion about these "think tank" reports that get "leaked" is that they use "commissioned by X government" just to advertise themselves, and it's either false or meaningless. I'm quite sure that the "serious" government analysis, if they exist, don't get leaked since that would probably immediately ruin all the predictions.
1. Parliamentarians are legislators; they focus on laws, not policy.
2. Those policies have support from every party with significant representation. Hard to publicly debate it when everyone agrees.
Like most things, its a bit of a two way street.
From an intelligence perspective, I agree w huntergatherer that everyone's not under active surveillance. IMO the problem is:
- once you are its far cheaper and more complete to surveil than it used to be, and...
- the bar to be a "party of interest" is far lower than it used to be. We can see this especially as some tech filters downwards into local police stations.
Its also tremendously useful for FAANG/MAANG to ensure their interests are adopted by elected officials and US officials are pretty cheaply bought. Honestly two senior SWE salaries for a year would do it for most congressmen. Just like Altria, or energy companies, tech companies donate to both sides of the fence, solicit tax breaks from both sides of the fence and look to keep labor cheap and competition low so that their owners/shareholders/investors are enriched.
From a federal government perspective, we need these companies to be 'American'. It doesn't matter where they pay their taxes, how much they off-shore work, etc. these companies trade on the US stock exchange, make up one of the strongest economies in the world, driving capital and human talent from every corner of the world to the US.
Why slow all that down in the name of 'fairness', user protection, competition and a lack of predictability
More than that: Google actively prevents competitors from working when competitors would work fine without any extra "help"
It's not just government - every single day I'm seeing Americans being directly hostile against free markets and choice. A lot of people (and media) expect and demand that a single corporation builds all of their things and owns all of their data. Plenty of people get outright hostile and dismissive of anything and everything that might create competition with the brand they're religiously following.
Politics is just following the people.
Do they? I am not aware of many FB, Android or google fanboys. People just use it. But surely would use something better, if avaiable.
Religious passion is more happening with apple, but it seems to me, they lost faith quite a bit. People use it and are entrenched in the apple universe, but fanatic worship and praise I am hearing way less nowdays, than back in the day, when Jobs was alive.
Since this was the 80s and Reagan-style free market rhetoric was in fashion, this became the new law of the land.
Problem is, very few antitrust violations actually meet this standard, because most companies aren't buying other companies purely to jack up prices. The harm is a lot more subtle. If you remember the days of "disruptive innovation", that could be looked at as monopolists getting punished for being too large and ignoring new technologies. Now, because antitrust is basically not enforced anymore, incumbents just buy their disruptors and integrate them into the whole. Startups no longer exist to create new products, but to eat up chunks of a big company's M&A budget for that year.
I'm hopeful that Lina Khan turns the ship around on this but it will take a decade, at least.
The TL;DR version is that the MS case affected things, but so do a shifting emphasis in Congress.
Fortune magazine article about it from 2002 (hosted by CNN):
> For a couple of embarrassing years in the mid-'90s, Microsoft's primary lobbying presence in D.C. was "Jack and his Jeep." As the software giant's sole in-house lobbyist, Jack Krumholtz, then 33, had to battle endless traffic jams to get from Microsoft's suburban sales office to Capitol Hill. "Early on I spent most of the day in my Jeep Grand Cherokee on my cellphone," Krumholtz says. "I hit an all-time low on the day I was parked on a Capitol Hill side street reading through my mail with the laptop on the steering wheel."
> No longer. After the Justice Department filed its antitrust suit in 1998, Microsoft--a company famous for its disdain of government--undertook the largest government affairs makeover in corporate history. The company now boasts one of the most dominating, multifaceted, and sophisticated influence machines around, one that spends tens of millions a year. It's no great surprise that one of the country's wealthiest companies can bankroll a beefed-up lobbying operation when it faces a crisis. But what few people realize is that Microsoft has reached the very highest ranks of lobbying so quickly. Says David Hart, a lobbying expert at Harvard's Kennedy School of Government: "Microsoft has joined the top tier"--with such longtime heavyweights as Philip Morris, Lockheed Martin, and AT&T.
https://money.cnn.com/magazines/fortune/fortune_archive/2002...
Bill Gates quote from 2020:
> "I was naive at Microsoft and didn't realize that our success would lead to government attention," Gates said, referring to Microsoft's antitrust challenges from more than 20 years ago. "And so I made some mistakes — you know, just saying, 'Hey, I never go to Washington, D.C.' And now I don't think, you know, that naivete is there."
https://www.cnbc.com/2020/10/14/bill-gates-i-was-naive-at-mi...
MS won the case on appeal and absolutely nothing changed in the US. Even the cited Wikipedia article says as much. There was never a time since IE was bundled with Windows that IE didn’t come with Windows in the US. There was also no browser choice mandate in the US.
> They not only lost that case, but the initial judgement was that the company was to be broken up.
That judgement was also vacated by the appeals court who concluded that the district court "failed to provide an adequate explanation for the relief it ordered".
If you look at the APIs available on MacOS/iOS at present [0], and how WebAuthn works, you need to "trust" the client-side software to correctly identify the site origin (i.e. protocol, domain, port) and pass it to a physical security key. In the case of a software token, you need to restrict which app(s) can pass this information through to the system carrying out authentication.
The end result right now, as I can see it, is that if you sign up to a website using a "passkey" via Safari (for example), there is no real supported workflow that isn't site-specific, for migrating to a new browser - you are effectively beholden to Apple's keychain for getting you back into that site.
If you want to enrol a new device (say an Android phone using its own software implementation of WebAuthn), you would need to find a way to sign into your old account (which requires your MacOS/iOS passkey to log in), then enrol your Android device (which is a separate physical device). You'll likely get stuck here.
An expert user could add a physical FIDO2 token to their account from the old device (Safari), and use that as the authenticator to log in on the new device, but this is significant friction for a non-technical user.
While moving users away from passwords might make sense, I do think we'll see these "passwordless" authentication mechanisms become the next major point of friction in user browser choice. Even if you can implement WebAuthn in your rival browser, unless you get access to the system key store, you won't be able to let users sign in. That will prevent them switching.
[0] https://developer.apple.com/documentation/xcode/supporting-a...
However, the lock-in concern remains: how can you export passkeys to another password manager the same way you can export passwords to it?
You inherently can't copy-paste a passkey, since it's an asymmetric public/private keypair authentication. These keys are (usually) decrypted by a single symmetric key that you protect well. If you allow that key to be exported, you're back to "one password for every website"!
When this is done on a hardware-protected security engine (which doesn't permit any extraction of the key), it's arguably quite secure, but you don't then have any migration path.
Does Firefox use the keychain - on macOS it does not even try
It is not possible to take anything Apple or Google do in this area to be in good faith.
This could all be mitigated with a little bit of tooling (allowing an existing passkey to enrol a new passkey from another device), which would also help users of hardware tokens to potentially create a way to auto-enrol an off-site key.
I do believe WebAuthn is a good-faith attempt to get away from the pervasive problem of "use the same useless password everywhere", but it makes a range of compromises which (intentionally or otherwise) create a level of cryptographic vendor lock-in that I don't think many people have recognised yet.
Before "cloud keychain" (i.e. software-backed, like Apple's implementation), your only "safe" option was to have 2x hardware tokens, and try to keep one off-site, but still accessible enough you could enrol it on all the sites you use.
I fear with "cloud keychain" Webauthn, we are heading for a world where getting locked out of (or banned from) your "FAMNG" account will lock you out of everything else, to an extent we've not really seen before - no access to your synced keychain secret will prevent you from logging in to everything. Physical tokens remaining interoperable should give technical users an insurance policy against this, but without some kind of portability (i.e. pairing hardware webauthn keys), I fear it won't be practical enough to keep users safe, and independent of the keychain providers.
Or any other mismatched devices ecosystem, the locked in ecosystem dream of apple is only applicable to extremely tiny amounts of people.
You shouldn't get locked in with a USB hardware token - you can enrol it in Chrome on one computer, and then authenticate via Firefox in another computer.
The issue is really the software-based "passkey" implementation. As long as you're not solely reliant on one company for login (i.e. you enrol multiple keys, one of which is portable and interoperable, AKA a hardware token) you can safely add software-based ones for convenience without getting locked in - you can always use the hardware token to get back in and enrol a new device.
If that happens it will be 100% the fault of those specific passkey implementations. There's no reason why exporting a passkey database should be any more difficult than exporting a password database.
That isn't to say I disagree with you though.
That means anyone can implement it, including a physical token (which can be entirely open source, like the solokeys dongle).
The real concern here is friction for the "average end user" - passkeys IMHO are a net-good thing, as long as we don't see this result in everyone regressing towards "single factor auth" in some way. As it stands though, WebAuthn/Passkey gives you a level of phishing resistance that ought to raise the bar on compromising accounts.
The part I do fear about third party password managers is that they'll potentially end up lowering the level of security that WebAuthn heralded, by normalising pure "software" authenticators - putting TOTP seeds into bitwarden alongside passwords feels like putting all your eggs in one basket, even if it's a reasonably good basket. A physical WebAuthn key gives you a level of hardware isolation (limited attack surface, time-bounded attack surface, physical contact required per-authentication) that will be lost if everyone moves to software-based tokens.
On the other hand, if people are replacing a globally re-used password with a "passkey", it's a lot better. If they are replacing a hardware token with a software token, that's a small step backwards. If most people are still manually using the same password everywhere, it's probably a net step forwards.
I have to support some non technical people in our company once in a while. Trust me, this stuff is way too hard for normal people. People I know that own things like a ubi key are almost without exception IT professionals that know what they are doing. Outside IT professionals in IT departments, I don't know a lot of people that have much awareness of this stuff.
The trend in this space is to not have dependencies on dedicated hardware and use multi factor via phone apps and other things. It works, it's easy to explain to users. And lots of apps do this now. Google authenticator is still used but is increasingly positioned as a backup option to more user friendly alternatives.
WebAuthn is not a great success so far. It launched with a lot of fanfare a few years ago and then nothing much at all happened. In it's current form, that's not going to change any time soon.
Today there is no migration path from one MacOS WebKit browser (Safari) to another (which also has an implementation of PassKey), since the third party browser can't share the same authenticator key.
As you say, all of this is far too complicated for an end user - my suggestions to avoid the problem and migrate only work for tech savvy users that know every site they use. That's maybe 0.1% of users.
My worry if we see adoption of passkeys is that only 0.1% of the browser market becomes contestable, as everyone else is stuck locked into their incumbent browser with no way to enroll their new browser's passkey into the sites they use.
1 ) Hardware authenticators won't spit their root secret, almost by design.
2 ) Webauthn doesn't require that the authenticator store the list of accounts, also by design (for privacy). So if you want to switch from iPhone to Android, you have to remember all websites you used Passkey on, and go one by one hunting down the right security settings page.
The specific challenge here is around software webauthn for passwordless access (think using Safari to create an account on a site). In this scenario, the average user has no portable authenticator. They cannot move to a new browser - you install Chrome, but can't log in from Chrome, as only safari can do a passkey login.
Even if chrome supports an equivalent setup (their version of passkey over Google sync, for example), you can't enroll it - to enroll, you need to sign in using Safari. To enroll your new device (chrome), you need to use it. You can't get logged in on chrome to do this. The average user has no option. A tech savvy user could manually copy session cookies to steal their own session, perhaps, or use a hardware key as a "bridge".
In essence, if you sign up for something using a passkey, you won't be able to easily leave that ecosystem at all, without pretty advanced tech knowledge (using a dedicated hardware webauthn key, or stealing and porting session cookies).
My separate observation about a lack of support for hardware keys to be "paired" to support an off-site backup use-case is unrelated, but perhaps relevant for tech savvy users who want to better "own" their own identity, and link their webauthn keys together for backup use-cases. Otherwise you have to maintain a list or spreadsheet of every site you use - I have one, so I can ensure I enroll each token I have with each service!
I think people who evangelize Webauthn need to carefully convey the risks and remind everyone that end users need backups (multiple authenticators, backup codes...). Hopefully, down the road, it will force interoperability between big manufacturers so one authenticator can authorize another for all websites in one go (this probably requires websites to have a standard way to enroll new authenticators).
> My separate observation about a lack of support for hardware keys to be "paired" to support an off-site backup
This is worrying me more. Interoperability between tech giants is bad but the sovereign solution may never get there.
Say you install an app/visit a website on your phone and register an account with a passkey. My current understanding is that on iOS 16, the passkey lives in your iCloud keychain. If you want to sign in on a Mac on Safari, you can just visit the website and the discoverable credential from your phone will appear when you try to log into the site with webauthn. The website will be able to tell that you're logging in from a new device and optionally require additional authentication.
If you want to sign in on a device that doesn't have access to your keychain, you can use your phone as an authenticator over a combination of Bluetooth and a tunnel server by scanning a QR code on that device with your phone. The site is then supposed to prompt you to register the new device with whatever its local passkey solution is.
The best source I could find for how this protocol works at a technical level is an episode of "Security. Cryptography. Whatever" on passkeys. I guess the specs aren't exactly public yet (at least since I last checked) and are only available to fido alliance members.
I've been trying to work on figuring out ways to build a "passkey manager" of sorts to live up to the potential webauthn offers with hardware-backed credentials that are also synced and backed up (to an offsite key). As far as I can tell, as mentioned in another comment, this just doesn't seem to be a priority for the fido alliance, which is a real shame.
I'm cautiously waiting to see how 1Password deals with passkeys, given that they're one of the few FIDO members with a vested interest in being cross platform, but I'm betting they'll just implement a software keystore built into their current vaults without any hardware backing.
Chrome and iOS will pop up a QR code for webauthn over BLE or whatever it's called (there's also caBLE[0]) whenever you're either enrolling or trying to log in via webauthn. This means that, as long as you have access to any device with your old passkeys, you can log in on your browser/android phone.
0: https://blog.millerti.me/2021/06/18/previewing-chromes-cable...
I am a huge proponent of web engine diversity, but Mozilla is going to have to do some serious self-reflection and enact major changes internally to have a fighting chance. As things stand, even if regulation limiting MS/Google/Apple's abilities to self-promote went into place it will make precious little difference because Firefox gives few reasons for non-technical users to switch to it. As big of a splash as Manifest V3 has been, it's ultimately a storm in a teacup that only a portion of technical users know and care about.
Mozilla doesn't make this argument because their browser share is lower than it used to be, but because diversity, not domination, is the goal.
Somehow though, that is the worst for you, while Apple simply blocking any competition on iOS (everything is Safari under the hood) is fine.
The amazing thing is that you say you are a huge fan of engine diversity - exactly what Apple is totally blocking.
Not much Firefox can do with their engine when iOS is their most important platform by far (note the countries they are strong in). Unless Apple changes policy they isn't much point in FF investing in their engine.
I'm saying to go ahead and put those regulations in place to force browser choice, but that alone won't save Mozilla. People will switch browsers on iOS in large numbers, but it won't be to Firefox because as I mentioned, to average users it offers nothing that Chrome doesn't. A handful of technically inclined users will start using Firefox on iOS while everybody else switches to Chrome or keeps using Safari.
Firefox needs a differentiator that Joe Q. Public cares about, and I sincerely hope they can come up with something once enforcements have been put in place because otherwise its course will remain unchanged.
This has not been my experience. I even did a Google search for something random and could not find any "Download Chrome!" message anywhere (I'm using Firefox). I do remember some years back there was such a message somewhere on Google search, though. I wonder if maybe one of my uBlock Origin lists has it blocked.
On iOS in a private tab, Google doesn't try to push Chrome but instead the Google app, which functions as a browser.
[0]: https://i.ibb.co/Htk645k/Screenshot-2022-09-23-183455.png [1]: https://i.ibb.co/thnRN7P/Screenshot-2022-09-23-at-6-42-14-PM...
I see people using Chrome on iOS - they use it not because they think they're running Blink/V8, they use it because Google brings their own password syncing and UI to it. Same for something like Firefox Focus.
Is it really anticompetitive if allowing a different rendering engine would result in less than (maybe) 0.01% of users actually switching due to the change?
I'm writing this from Firefox, having used it ever since the days when Firefox releases used to have launch parties, and tabs was the revolutionary killer feature.
Let me rephrase the question: does Gecko/Spidermonkey have a future?
I think it's clear the Firefox branding will live on, since it is Mozilla's crown jewel.
But in today's landscape, you can target WebKit (Apple) and V8/Blink (Chrome) and you've surely covered 98% of all use cases.
Surely these competing engines have far, far more resources pouring into them than Mozilla can afford.
Since the balance of power has shifted towards the owners of these huge players, how can Mozilla keep its browser engine competitive, given that all these new features (such as wasm) surely require massive investment?
I know these questions have been asked already a million times, but it keeps me wondering. Will Firefox eventually need to become a fork of Chromium like everyone else, just to keep pace? Can Mozilla keep its entire browser stack afloat in these shifting currents? (pardon the gross metaphor)
Firefox moving to Blink means I'm just hopping over to whoever has the slickest Chromium clone right now.
Well, mobile is the future of computing. Does Firefox have a future on mobile? I think the answer is clearly no.
Firefox will be relevant only until the Desktop PC paradigm fades into obscurity.
Eventually Chrome and Safari will join Firefox in obscurity, as more content moves behind apps and walled gardens, and as the desktop paradigm falls into disuse.
Give it 10 years.
If anything, it is an albatross around the necks of the groups and management that care more about the 'mission' of an open web and the advocacy and other programs that are largely unrelated to the Firefox browser, and certainly don't require the browser to be its own thing rather than a chromium fork.
For the short and medium term goals, a browser is just another tool and vehicle for pushing their vision for the future of the web... But it's an extremely expensive and difficult tool with comparatively little short and medium term importance. So why keep it? You don't need a 'real' browser to put up surveys or blog posts, or to attend or run conferences, or to join web working groups or participate in RFCs. Not having to pay for almost any engineers or teams for something the rest of the foundation could categorize as a pyrrhic project? That would be simply wonderful, I'm sure.
Vasselization simply makes more sense in the foreseeable future.
Some of whom they are naming in these allegations.
It will relieve a lot of resources to be spent on other things like user experience, and they will benefit from all the development resources devoted to chromium, while being able to remove anything they don't like, like MV3 limitations on adblockers.
I really like what brave is doing, I switched because I lost hope Mozilla is going to do anything, they are funded by google, and therefore afraid to do anything impactful.
While brave has privacy by default, has an independent search engine, an independent ad network(that is privacy friendly and isn't enabled by default), and they aren't afraid to do anything against big tech, like banning AMP, removing social trackers and other things.
Brave is almost what Mozilla should've been.
… which might actually not be as easy as it sounds. Sure, as long as Chrome/Blink internally retains MV2 compatibility behind a configuration setting for enterprise customers you job is easy – just hard-code that setting back to enabled for everybody instead of just enterprise users and you're done.
However once Google starts ripping out the MV2-related code from the Chrome/Blink code base, all that code suddenly becomes your responsibility to maintain – and from that point on there's always the risk that Google suddenly decides do to some large scale refactoring or internal architectural change that radically conflicts with your attempts to maintain those old features alive.
Once you reach that point, you've then got the choice to either spend ever increasing amounts of effort on maintaining those features on top of the current code base, doing a hard fork and therefore having to suddenly maintain the whole shebang, which would be an even larger effort, or instead giving up and dropping those features after all.
Mozilla seems to do fine keeping up. Wasm and Rust originated in Mozilla even and they are still very active on that front as well.
I seriously doubt Mozilla will kill their company by switching to Chrome. It would be suicidal for them. Users would revolt and fork the code base probably. Mozilla developers especially and without their developers Mozilla is nothing. Just look at what happened to Opera after they switched to Chrome. They technically still exist. But they are a footnote in web server statistics at this point. A rounding error basically. I've not seen anyone using it in many years now.
So, I doubt a move to Chrome would end well for Mozilla if they ever were to float such an idea. The history of Mozilla is that they bootstrapped out of AOL's Netscape division which was being mismanaged by AOL. Once the code base was OSS, people just left and created mozilla.org to cut loose from the failed corporate entity. AOL ended up with nothing. That can and will happen again if it needs to.
In short, users and developers would abandon a Chrome based Firefox in a hurry and it wouldn't take long for them to get organized with a new foundation. Wikimedia manages fine based on donations. Millions of Firefox users would be able to keep the project going pretty much indefinitely. Mozilla would lose control over most of its key people, users, and assets. Which is why they will never do this. It would be corporate suicide.
Instead we're dealing with the "diversity" of the web (HTML,CSS,JS) engines and endless arguments around Manifest v3, etc. So many precious man hours are going to waste.
I'm not following your question. How does Firefox branding live on without Gecko/Spidermonkey?
Many Firefox users would not notice the difference, as long as the things they care about keep working.
Of course, many apps don't properly do this and end up hardcoding references to Chrome...
I think what OP is referring to is this: https://news.ycombinator.com/item?id=32415470
It's not quite the same as running actual Firefox Focus, but there's a drop-down menu option to let you switch to launching the in-app page in proper Firefox Focus. That's almost instant and appears to preserve the page state. So between that and the way cookies always seem to be reset in in-app sessions, which is great, that's why I think the in-app sessions are using Firefox Focus.
Maybe Mozilla can knock off the grandstanding, the money wasting, the back patting, and just work on making a competitive browser. Also completely remove Pocket and anything else like it.
I think the issue here is that Mazilla feels that they do. The problem for the average user is not “Do I want to use a Porsche (Chrome) or a Mercedes (Firefox)?”. It’s “Which icon is the one that makes The Internet open up and show me all the things I want to see?” They don’t care beyond that.
I mean, Europe used to mandate a selection screen on first boot that would just ask the user what browser to install; that seems pretty reasonable. Failing that, they could let the user actually change their default browser without harassing them or resetting it constantly (Windows) or allow people to actually use other browser engines at all (iOS).
> just work on making a competitive browser
They did. But it's hard to get people to switch when the OS vendor makes it artificially hard to switch.
I doubt your regular Firefox user falls for it but your parent's computer that you installed Firefox on will
Yeah - hard agree. Pocket feels like a sheer gimmick. It cheapens the experience, and it hurts the trust people have for Firefox when they jam it in your face.
I remember the original Firefox ethos where it was just a browser, and that was awesome.
Now it's more like "You can disable that new change by installing an extension and trusting its developer and whoever they might sell it to at a date TBD."
I feel like Mozilla is having an identity crisis - but then again... when were they not.
You can have the best product in the market but if the deck is unfairly stacked against you it doesn't matter how good your product is.
Back when Firefox actually was the best product, it stole ~30% (or even more?) marketshare from Internet Explorer, despite the latter being bundled with the OS.
Firefox can be the best browser with third-party add-ons (such as uBlock Origin) and a custom configuration, but Mozilla would rather puff more hot air like this (and their other commitments to "privacy", despite their telemetry implementation not even being GDPR compliant) rather than actually making Firefox the best product.
1. I admire the irony of calling Firefox a Chrome clone when Firefox far predates Chrome.
2. That's purely your opinion. I personally find Firefox to be more performant and customizable than Chrome but to each their own. I'm not going to fanboy browsers here.
3. Where exactly did I claim Firefox was the "best" product? I made a generic statement saying that you can have the best product in the market but when the market discriminates towards you so that it's impossible to get users it doesn't matter how good your product is.
You are right about the technical details, but my intention was to compare it from a non-technical user's perspective. For the non-technical user, modern Firefox is a Chrome clone (and strives to be that) with a very similar UI. The browser engine being different is a technical detail that isn't relevant to the average user who doesn't even know what a browser engine is, and they are not aware (and don't care) about Firefox's history. Stock Firefox is very similar to Chrome and Mozilla wants it to be that way, having removed many features that differentiated it in the past.
> but when the market discriminates towards you so that it's impossible to get users it doesn't matter how good your product is
Potentially, but you can't say for sure that market discrimination and anti-competitive practices are what is holding Firefox back when there are no compelling reasons for a non-technical user to use Firefox over Chrome, so I disagree with the argument that anti-competitive practices are what is holding Firefox back - Mozilla is holding Firefox back by not actually making it a better product to the eyes of a non-technical user (ignore the fact that FF can be a better product with enough customization & add-ons - people competent enough to do so already use Firefox and are its only remaining users).
When stock Firefox is good enough to appeal to and impress non-technical users out of the box (such as by having good, built-in ad-blocking), I will believe in the anti-competitiveness argument. Until then, my opinion is that it's yet another excuse for Mozilla to waste time & resources on anything but actually building a good browser.
This is software comedy gold. If Firefox is a clone of Chrome then what isn't a clone? Is Safari a clone of Chrome because it has the tabs that Chrome took from Firefox?
Probably true, as long as it depends on the same big tech for revenue.
I don't think it has achieved its original goal and gracefully disbanded, unless I see any strong evidence that the decision was primarily and independently driven by the Servo/Rust engineering leaders.
For example Formula 1 TV doesn't work on my SmartTV or on some of my browsers despite them being forks of Chrome, where it works just fine.
Not only that, it used to work there in the past, what happened is now it actively detects if the browser is a real Google Chrome from Google (not a recompiled version), and refuse to work otherwise, even if technically it could work just fine.
In australia, you are forced to purchase a streaming package from Foxtel (Australian version of sky).
Furthermore, the only real way to make a difference by actually blocking malicious domains and resources - uBlock Origin - still isn't bundled by default despite being permissively licensed and Firefox having a way to install extensions at first run (that's how Pocket is distributed - it's not built into the browser, instead it's an extension automatically downloaded on first run).
https://analytics.wikimedia.org/dashboards/browsers/#all-sit...
Relevant xkcd: https://xkcd.com/1102/
* Got years of free advertising real estate on the most visited website on the internet, but hid the ads if you were using Chrome already
* Payed the likes of AVG, Avast, Adobe, Oracle and others to have their own software installers automatically install Chrome and make it the default browser unless you uncheck the boxes
* Repeatedly leveraged nonstandard and Chrome-specific APIs (Polymer v0) on their websites which caused other browsers to need slow and clunky polyfills.
Did you just update Java? Looks like a new browser you've never used is your default now.
It had to compete against the default interenet icon on both major operating systems and the OSes themselves were marketing themselves loudly as well.
Once exposed to it, many people chose to continue using Chrome because Chrome offered a better experience than browsers like Firefox and IE did at the time.
Early on, Chrome felt faster and sleeker than its competitors, without sacrificing functionality.
Chrome, for a long time, was simply _better_. It's bizarre how you want to erase history when we installed Chrome originally because of how much darn faster it was than Mozilla (not to mention IE7 and that crap).
However, it has a slew of useful features tailored for its audience (perhaps reminding of "big apps" of Asia) while also leveraging all kinds of ways to get installs such as bundling, etc.
I'm just not sure what are the selling points of Mozilla Firefox in 2022. They discontinued their plugins to be like Google Chrome and enforce the same censorship as Google Chrome without being Google.
10-12 years ago, when Chrome appeared, HN was full of posts like "I switched my parents computer to Chrome", "I convinced my company to switch to Chrome", ...
Back when Firefox did actually bring much to the table compared to the incumbent, it gained respectable marketshare: https://news.ycombinator.com/item?id=32959277
https://news.ycombinator.com/item?id=28510490
https://news.ycombinator.com/item?id=29579994
They'll always use "security" as an excuse to force you into doing what they want, and this is just another instance of that tactic. Don't be fooled into giving up your freedom. I wish more people would be aware of that.
This is just something that has slowly/linearly been moving in that direction. Many, many years ago it started with bank's declaring "unsupported" when I'd connect with seamonkey et al.
The initial lever was security, now it's purely client/server features that only google engineers can deliver in the next quarter.
Chrome™: The way it's meant to be played.
We should treat it like a fact, and talk about what we want to do about it. If we do nothing then these megacorps will use their power to unfairly outcompete or plain buy up all competition but the other megacorps.
We can either have a world with maybe 50 gigantic corporations or thousands of smaller, but still large businesses. I personally think the latter would be much better for democracy and distribution of wealth.
But in the same time, brave seem to be growing quickly, pushing privacy by default, and doing more impactful things for Digital Privacy, on probably a much smaller budget...
https://news.ycombinator.com/item?id=32809126
https://news.ycombinator.com/item?id=30853392
In other words, I don't think Mozilla is making good use of that money at all.
What's the problem again?
And I suppose Meta doesn't produce a social network?
Also the fundamental analysis of the article is that we need to have centralized control over decentralized networks (which they refer to as networks of trust and abuse audits), making the decentralized part inept. If you can no longer run a decentralized service without getting permission from a centralized authority, it's not really a decentralized service
https://bugzilla.mozilla.org/show_bug.cgi?id=505521
Note: The spiciest comments are labelled "admin reviewed" and collapsed by default.
- https://www.howtogeek.com/744102/windows-11-makes-it-hard-to...
- https://www.howtogeek.com/768727/microsoft-calls-firefoxs-br...
On macOS it's easy to change this, but things like the "tips" notification it displays after a major update still opens on Safari, ignoring your setting.
[1] E.g. I've only really encountered them in one place so far, and it's easily possible to avoid that place, too.
[2] That one place I certainly know of is the lock screen in case you've kept the default "Show random pretty pictures" setting turned on.
Save a file with the extension .htm. It defaults to Edge, no matter what.
Is it not odd that that Mozilla is taking a stand against tech giants abusing their position when the giant with largest share of the browser market is the same company that pays them hundreds of millions a dollar a year to be the default search engine on Firefox.[1] Don't they basically survive on this Google money? Don't they basically promote Google with this arrangement?
[1] https://www.theregister.com/2020/08/14/mozilla_google_search...
What. That must be the most ridiculous excuse I've heard so far.
Antitrust regulations "would impose rules that are bad for our bottom line, and would offer consumers choice."
"We got so big because of lax regulations and mergers like the Doubleclick merger that weren't stopped, and we still want to keep buying out any potential competitors."
(And Microsoft actively reinforced it by saying that if you sell other OSes on a “PC” they won't let you sell Windows.)
And of course everyone does the same on Windows. Only Edge has started to slightly change that trend, and that's with some very aggressive tactics by MS.
The main problem with including Chrome/Chromium/Ungoogled Chromium is the license. Mozilla's MPL is straightforward and compatible with most FOSS licenses. As I understand it, Chromium's codebase is still a melange of different licenses (and some proprietary code) that is generally unfit for packaging with other free software. Most repositories will still have it on-hand though, since it would be pretty silly to prevent you from using the browser you want.
If you'd rather avoid Firefox altogether, run archinstall and add chromium to your extra packages field. Many build-it-yourself distros like NixOS exclude browsers altogether.
So much for the web as the "OS agnostic" interface for the 21st century.
https://www.ghacks.net/2022/07/10/apples-business-website-is...
This, they're right you know.
Mozilla has being whining for years despite living off of Google's money and even with that they are still complaining and more websites are continuing to require Chromium browsers over using Firefox for their sites as they know the site breaks with Firefox.
That's why little to no one is using it. Like when you have the choice of Linux distros, you have the many choices of Chromium browsers and it seems that Brave is the recommended one.
Am sure Mozilla bundles its own nagware into its browser.
It loads 10x more information 10x faster
Why wouldn't Msoft NOT force Edge as the default browser; a company could fill their coffers hugely if they had a lot of browser market share.
Keep the sheeple dumb and dumber, and two generations later they'll be even more subservient and docile, pleading to be milked incessantly for $$$ all of their life instead of actually learning and exercising critical thinking, and thus possibly turning on your efforts to milk them.
You can only learn if you make mistakes. They want to "protect" you so they try to stop you from making mistakes, and in the process, take away your ability and will to have individual agency. Fortunately, people are starting to realise the truth.
Given that the other Linux kernel powered mainstream OSes are also using virtualization and sandboxing.
Are we in browser-whining season again? (Typing this from Firefox on macOS.)
But asking from a web based OS to be able to run a different web runtime is a bit like expecting that you can provide your own SurfaceFlinger on Android or the equivalent on iOS; there are reasonable limits to what can be swapped out by a 3rd party app.
Neither "forces" their respective browser in the same way that Microsoft does. Putting iOS aside for a minute to be addressed later, on an Apple device, the number of times you will get a pop-up telling you how insecure and slow and bad other browsers are is practically 0. Apple has the MacOS spam banner, but either they've toned it down or walked it back completely based on my experience purchasing an M1 this year. Never did Apple try to make you use Safari as your PDF reader, it doesn't change or add shortcuts for Safari on updates, it doesn't insert a banner on other apps or locations to tell you to use Safari, changing your default browser is as simple as opening System Preference and searching "default browser", then picking another one, and MacOS doesn't say a word about it. Spotlight is the one place that might surprise people but even it respects changing the default browser and will search on your set one.
Google, as annoying as it is, also doesn't seem to care much which browser you use on Android; I don't own a ChromeOS device so no idea what it's like on that, but you're free to install just about anything and set it as default without so much as a hiccup, and similar to Apple, I have not seen it try to set itself via other common OS features. Granted, Google is a dick with Chrome in many other ways (other commenters have already noted how they use their control of the web to force Chrome), but I don't quite put it in the same way.
iOS is special I guess in that you can install any browser "skin" you want, but it's webkit underneath. I'm mixed on this as I understand the arguments against this and it's definitely not good on Apple, but at the same time, if you're talking about what browser to use to get the features like sync, iOS lets you do it without a peep from iOS about it and for the grand majority of users, the rendering engine isn't what they care about, it's the other features of the browser which you can happily use. Still not good you can't use another engine, but I would still put it in the "okay, but needs improvement" area.
All of this compared to how Microsoft handles Edge on Windows is a pittance. They really want you using Edge for everything, and there are so many system hooks that open Edge without you wanting it to. Changing the default is much more daunting, and it's far too easy to let it get set back (in general I've noticed Windows has some weird stuff about default applications in Win11. It might just be the release we use for our lab environments, but it refuses to let me set notepad++ as default text editor without resorting to the command line, but it could be just a strange situation).
I have a hard time seeing this as anything but Microsoft muddying the waters with such arguments and I definitely don't see them as good faith. I suppose it's just good business sense that they don't try to tie Azure features/performance to "best viewed in Edge" as I imagine an exodus towards AWS/GCP, but for the mythical average user, they do a lot to get you onto Edge no matter what you actually want.
Incredibly frustrating end user experience when I have everything in FireFox, and Adblock too.
I have the Google news feed disabled, but links from gmail and the search window all open Brave as expected.