Consider Disabling Browser Push Notifications on Family and Friends Devices
lloydatkinson.net
lloydatkinson.net
Not one time have I allowed it ever in all these years and I'm shocked anyone else allows it at all too. Not having considered it before but I'm really surprised this tech is on by default or even exists at all. It may have some neat IOT use cases but IOT has about a billion other notification options for machine/machine communications that are better. Thats the best I can do in terms of trying to argue theres a good aspect of the functionality.
But what about Gmail you say? Well, I personally don't use the web interface anyhow opting instead for a nice/superior experience from a local client but IIRC the tab starts blinking when theres new mail and the number in the title bar changes.
Even LinkedIn and its simple blue dot on the title of the tab is sufficient for me to know theres new activity there if I want to bother looking (ooooh loooook - a guy I know knows a guy that posted a virtue signaling meme regarding a supposedly socially relevant topic that companies pretend to be concerned about - I MUST KNOW ABOUT THIS IMMEDIATELY!).
Now, on to changing browser and OS notifications on all 4 home systems to my preferences this morning. I didn't realize how much the hubris of bugging me with stupid crap annoyed me until this prompted me to consider it. Thanks OP!
I was too! But then like I mentioned with UX dark patterns encouraging users to click by making them believe they have to click it, it's perhaps not as surprising. Non-technical users are already conditioned to click OK or Yes to anything that appears on their screen without reading it.
Glad you found the advice useful!
> I have never seen them used for any legitimate or useful purpose
That's definitely overblown. I've got a half-dozen enabled, and on re-reviewing that list, I still think they're legitimate. Upon checking mine, I've whitelisted Google Calendar, Gmail, Google Meet, Mattermost (work chat app), and Slack, and I want notifications enabled for all those things.
I have three enabled. One is for a past side-hustle, but the others are messages.android.com and messages.google.com . Definitely keeping both of those, even if/when I finally mostly depart the google ecosystem.
Personally I haven't had any use cases for them and they have only been a source of frustration.
I (over)use the keyboard shortcut of windows key+# (so win+1 switches the focus to the first application icon on the taskbar, win+2 the second, etc), and I've got muscle memory of which applications are pinned to each place. Plus, I've already got the muscle memory of how to get to the various websites I keep open.
[…]
> I've got a half-dozen enabled[…]
That's fine for you, a purveyor of tech news. For almost everyone else, they are a means to spam and false malware notifications.
Our company provides services to clients who rely on computers but aren't necessarily computer experts. The only instances of browser notifications that I've seen (on client machines) are those I just described. In fact, yours is the first instance of someone appreciating them that I've encountered.
No shade intended. I just don't think their benefit outweighs their abuse.
TFA said they're without purpose, I said I disagree. You're now saying their abuse outweighs their benefit, which is a separate topic, and is more subjective. I'm not sure I entirely agree, but I could definitely see a case for that.
We rely on them extensively for basic notification functionality in healthcare applications.
We literally send out alerts that save people's lives using web push notifications, so I think it's a bit cavalier to dismiss them entirely.
I do agree that it would be nice if the were restricted a bit more, perhaps to installed PWAs of some sort.
Is that HIPAA compliant? What happens when Google/Apple/whoever goes down (does happen!), do patients die?
Yes, the alert is a link to an authenticated PWA, no PHI is sent in a message.
As far as push server failure, we also have SMS notifications as fallback.
Phone, text, email, even snail mail.
What's cavalier is thinking because your business wants to use them that they then should be used.
In-app notifications, SMS and web push notifications are all important means of communicating events that clinicians need to be aware of.
This is delivered via a PWA so that it works on the wide variety of devices we see across patients and clinicians.
Many elderly patients are confused by native apps and app store experiences. Many of them refuse to use an "app". Additionally, things like accessibility are problems that have been solved effectively on the web but can be more challenging with native apps.
Many clinical devices don't support app stores or installation of native applications.
When you've tried to implement reliable health care systems for elderly populations, clinical settings, mobile in-field settings and physicians in a HIPAA regulated space perhaps you'll be able to tell me a better way.
Your assumption that we use any technology because "we want to" indicates that you don't have much experience with this stuff, perhaps it would be better for you to reserve judgement in the future until you understand a subject a bit more thoroughly.
Most of it are native apps tho ?
The difference is that you install app explicitly for purpuse of doing that, vs "I accidentally clicked on website and now it sends crap to my feed" of average illiterate users.
I have a couple of clients I woke with so I prefer to isolate them by profile in browser…
The key idea is that enabling notification should be an explicit actions, and have more consent than a single click.
EDIT reply to: >That ad must've been injected by the proxy you were using to access LibGen.
I just went to the top search result for "libgen" from google search result. It's possible they were trying a temporary monetization trial to take advantage of the Z-Library shutdown and that push notification is now gone. The other possibility is that the search result pointed to "libgen.ee" or "libgen.il" which apparently is a clone of Libgen (they call it "Library Genesis+") and it's the clone sites that have the push notifications. It's confusing to to people not familiar with it to know which is fake and which is real. (screenshot of google results: https://imgur.com/a/65Beo8H)
On another side note, what's amazing is how that website got a push notification silently past Chrome's "Privacy and security" setting of "Sites can ask to send notifications". There was never a "Allow this site to send notification?" prompt. I wonder what Javascript trick they used to bypass Chrome's security.
Yeah, you should never use google for this.
Protip: find the wikipedia article of your site of interest and bookmark it as a source of always up to date urls. Conversely, just use alternative search engines like duckduckgo and/or brave search.
I don't recommend relying on Wikipedia as a source of up-to-date anything.
"Consider disabling push notifications on your device and on family and friends devices"
because browser vs native should make no difference, right? But when said that way, you see how absurd is the statement as a generate guide. This would be a full-time job to a) convince people not to get notifications and b) change their settings.Now personally, I have disabled all native push notifications or at best have them sent to the "Notification Center". And after seeing my GF bothered by so many notifications, I showed her how to disable them. Everyone else is on their own.
Although it can be useful for some web applications, I kind of wish that push notifications were not added to browsers. Most often they are just abused to spam users. The pop-up you get while going to pages asking you to allow push notifications is also annoying. I have started to disable notifications in all the browsers I use on mobile and desktop.
Here's a question. Can you disable web sites asking while keeping the notifications that you have already allowed?
I'm building a niche social media PWA (eschewing native apps to save time), and use browser push notifications to let my users know when someone has DM'ed them.
Browsers should've really made it an user-initiated action. Something more akin to adding a site to your browser's bookmarks than what we have currently.
I prefer running Slack in the browser, and I need to receive message notifications.
Push notifications aren't any less useful to have in browsers than in native apps.
Though I would like to see the prompt locked behind "add to home screen".
Even to use this theoretically, though, I'd want the strict ability to control who can even send me a direct message. As it stands, the only thing I currently allow push notifications for are SMS and Signal, but the SMS texts are still overwhelming election spam from people who aren't even trying to spam me but have the wrong number for my mother or grandmother and bulk property buyers who claim they want to buy one of my houses. So I hope you plan to enable user-controllable proactive origin filtering (not after the fact user-by-user blocking).
Consider food delivery services (from the reastaurants). We actively order food directly from the reastaurant where possible, because Uber Eats charge more for the food and still charge "service" fees + delivery.
I've just checked, and I have 7 (including Uber Eats) food and grocery delivery apps.
It would be my preference if I dealt with a PWA instead of having to install many apps with varying quality. A notification of the status of my order is useful, and with the grocery apps, sometimes an item that I've ordered is out of stock, and I have a small window to take some action (if I hadn't chosen one when ordering).
At one previous job, that supported vehicle registration for county clerks, there were enough situations where multiple users would "work" on the same vehicle registration that we had to let users know if some other user updated that particular record - rather than fail/error if that user presses submit "too late".
The thing is, many non-technical users don't even know where or how notifications really show, much less how to edit/remove them.
Push notifs in a PWA get us about 90% of the functionality of a native app on Android and (finally) iOS.
The other big positive is that the closer PWAs are to native apps in functionality, the less of a stranglehold Apple and Google will have over app distribution.
I completely agree with the author about how hostile the "modern web" is. At least push notifications are dubious in value from the start, but unfortunatelY JS seems to be trying to replace built-in functionality of the browser like rendering static content.
I like to disable JS, but these days virtual no site works without it (except HN, kudos!)
As the famous proverb says "give a man a fish and you feed him for a day; teach a man to fish and you feed him for a lifetime". The best way to "fix" phishing attacks and malware is by making people more "technical". The only way to eliminate these phenomena is by educating people about what a Push Notification really is and that you simply don't have to click it.
The Web needs to be a competitive platform for apps next to the closed and "gated" App Stores. I think that we should not dumb down web browsers to simple page viewers.
Any plan now and going forward has to take this reality into account. Not blame the victim.
I continue to try to educate, but nowadays I make sure they always have ad blockers installed (I believe most of the tricks they fall for stem from malicious ads) and I try to lock things down and disable features where it makes sense. I dislike the locked down world of iOS and what has become of MacOS, but I appreciate having it for devices they use. This is part of my job, I think about this stuff every day and I still worry I can't keep up, so I can't really expect the same from them.
I've been trying to do this for 25 years. It has yet to be successful. Especially since the vectors of attack change constantly.
> The Web needs to be a competitive platform for apps next to the closed and "gated" App Stores. I think that we should not dumb down web browsers to simple page viewers.
Disagree 100%. With native(ish) apps at least I can do things like block internet access if I don't want them to "phone home". I can also downgrade (or not upgrade) them if they push regressive "updates". Web apps take all control away from the user. We need ways of running whatever we want on mobile. But using web apps as a workaround is a cure that's worse than the disease.
I always “poll” data mentally, I find this to be crucial to me maintaining control over my devices and not allowing them to control me.
Most people are not ok with missing incoming calls.
You just described why millennials consider phone calls incredibly disruptive and rude (and I entirely agree with them despite being a Gen-Xer).
She's been spammed by all sorts of nonsense from tabloids and scams.
> In the same way that e-mail spam filtering works, so should browser push notification spam filtering. If you don’t implement this, you are complicit in the continued abuse of your users.
I can't remember as I haven't worked on notifications in years, are the notifications not meant to be encrypted? Such that the browser vendor can't see the contents?
With e-mail I understand and accept the message processing needed to identify if it's spam, but I'm wondering whether browser vendors (or more specifically, push servers) would today be able to intercept messages.
Numerous services will allow messages to be sent via push notifications, wouldn't it cause issues if your browser vendor is now "reading your messages"?
> If needing to filter browser push notifications for spam seems like a lot of work, then questions need answering about the value of the feature in the first place. Seriously, what is the value of this feature?
I understood the feature as part of making PWAs able to replace the need for native apps. When browsers started supporting push notifications, I used the service to send public transit alerts to users who opted into them.
> Were you pressured into it by ad companies? Why is the feature so open to abuse?
Native apps can be removed from stores, and Google/Apple would (I assume) drive the lion share of notifications thorugh their servers, and can probably detect abusive behaviour more readily.
With browsers, I'd again assume that it's harder, as one can use any service they'd like.
Then what about Chromium where all the tracking stuff has been stripped out? Who would police that?
Two possible solutions:
1. A blocklist is maintained, similarly to malicious websites. Don't know if flagging a website abusing notification marks it as malicious overall, but at least with malicious websites the user wouldn't even see the website.
2. If a user dismisses notifications and never opens them, perhaps the browser can take initiative and block them permanently.
----
I'm responding mainly with experience of spam on family's phones, I fortunately don't have elderly family who use PCs.
No, the Windows API's for showing the notification (or for any OS) are going to need to know the text to render and the image to display, which is information the browser will have to tell those API's.
> send public transit alerts
Probably the only legitimate use case I've heard but I've personally used apps from the transit companies for this.
This doesn't make sense. The browser sees everything that passes through the browser, by definition.
If you set up an extension that blocks notifications with the word "vanilla", what the extension would be doing to act on that notification is what I regard as "reading your messages".
Off topic: I don't know if the situation is better on Android but my biggest pet peeve currently is being bounced into an app instead of the web version of the same page. Like clicking on an IMDB link in google results or a Steam link (often comments, like when I'm trying to figure out if something is a bug while playing on a console). I know the workaround for this (long-press link, open in new tab, or delete the app) but on the other side of that coin sometimes I get sent to the Amazon webpage but I want to bounce to the app where I'm logged in and the UI is better (IMHO) but I've yet to find a good way to do that (maybe "share" the page to the Amazon app? I've never tried).
According to Apple it'll finally arrive on iOS 16.x on Mobile Safari in 2023.
It would be a shame if the feature becomes unusable for other reasons after being delayed for so long.
I am wondering what the limitations are going to be.
As I understand Apple used to be the gatekeeper of all push notifications (App Store, APNS) but with enabling push notifications on the em web it might open the floodgates. Could be a thing, could be problematic.
1. easier to install. Users are not used to PWAs and may not manage to install them.
2. easier tracking - you can't delete cookies inside an app.
3. can unlock the full potential of the device (almost, some private APIs are only for Apple/Google).
PWAs have these advantages:
- no censorship from Apple, Google, Amazon, other app stores
- no fees paid to Apple and Google.
- might be easier to develop in some cases - will run on both iOS and Android
Android supposedly has great PWA support obviating the need to write native apps yet no one has ever stepped up to the challenge of finding popular examples where a company was forced to write an app for iOS . But decided that a PWA was good enough for Android.
And despite the whining about fees, most (80% it came out during the Epic trial) App Store revenue is from games. And most other companies are either in the B2B space where the customers sign contracts outside of the App Store, B2C companies that are advertising supported, sell physical goods and services that are not effected by the policy (Uber, Amazon, etc) or have the option to bypass the App Store in app purchases like Netflix and Spotify.
Otherwise, completely agree. I've already had to clean out notification permissions from multiple people who were getting insidious amounts of web push spam. Nobody knows how to manage their notification permissions on Chrome, and web push popups themselves aren't great at telling you how to disable unwanted ones. I suppose this is why every hostile ad site begs you for web push permissions nowadays.
Related gripe: websites that ask for location before you even have a chance to know why they need it.
The feature had potential, but the fact that websites can ask you to enable push notifications unprompted renders it far more irritating than useful.
On a related note, I wish Chrome had an easy way to permanently say "don't ask again" (on a site-by-site basis) to the "Do you want to login with a google account?" popup that so many sites have nowadays.
But I prefer my browser to act as a sandbox. Push notifications are disabled and I don't get any requests to allow on any device I use.
But then I don't like notifications in general even from apps and only have f exceptions for Telegram direct messages/sms and calendars.
If I want to know if I have an email or some app has she news for me, it can wait until I make time to go have a look.
I use devices to work and the last thing I want is distractions from notifications as much as possible. I also feel less overwhelmed and freer when exposed to less notifications.
The problem is the rampant spamming of the permissions prompt itself and ensuing inadvertent acceptance. So the practical solution is to close that vector. Instead of the active popup, use only a passive menu entry or an unobtrusive icon, like how it already works for mailto handler registration.
“Your computer is infected with dangerous viruses.” “Your bank account has been compromised.” “System Is At Risk” "Your might loose your data!”
We have endpoint protection of course, but they do not react to this of course as it is not real.
But you can turn it off in Chrome, Edge and Firefox over GPO or Intune policy. And/or push out ublock origin too :) if customer allows/wants.
>I have never seen them used for any legitimate or useful purpose
At work.
If you use web-based email like office.com/outlook.com/gmail.com
If you use MS Teams and/or Slack in a browser
you want to have notifications on :)
Let's be honest here, they are only getting those notifications because they visited some random shady website and clicked on "allow" notifications as they would click the "accept" cookies button; to hide the nag.
Installing uBlock or setting up ad-blocking DNS for your friends should cut out 99.9% of phishing and spam.
Though ironically even if we are to take your example, I would consider advertising in this scenario to be harmless compared to receiving malicious phishing links in your notifications. I believe those 2 websites would never stoop that low.
And they may not purposefully stoop that low. But there are most likely using a third party ad network.
Anyway people never click allow on those so they might as well be useless. I prefer to make my own notification system. If the user wants it , they leave the tab in the background , much like how i leave gmail.
Aren't they already a privacy nightmare being so centralized?
They do, by accident. And then wonder why the fuck they keep getting spam push messages and how to turn it off. Which is why the right thing to do is turn them off completely for non-technical friends and family. Likelihood of harm is near-zero (as you note, basically no-one wants these) and, at the very least, it saves them from distracting, useless pop-up dialogs.
there's legitimate uses for browser notifications. messaging apps like slack and discord, calendars, email clients, etc. some browser games. some buy/sell platforms. notifications serve a purpose. if you understand the consequences and want to turn them off on your computer, then go ahead.
but in my experience well-meaning young folks turning things off on other people's computers is a big part of why some people don't trust their computers, or think they're bad at computers. they're talking to a friend and find out that their friend's computer gives them a little notification every time they get an email, and they don't understand why their computer doesn't do that. and the first conclusion they come it is that they just don't know how to use the computer properly. meanwhile they know how to use their computer perfectly fine, but some grandson has gone through the settings and turned off half the things their computer does.
I wish you could completely block URLs and phone numbers from SMS -- it's by far the most dangerous vector. People get a text from their bank, the tax agency, their medical fund, fedex. It warns them of a problem on their accounts and they leap into action like Pavlov's dog, clicking the link, calling the number. The nice man on the other end listens and says "we need to secure your accounts, but before we continue I need to do a full ID check. Can we start with the current balance of your account? Very good. And your full name and DOB? Okay, just waiting for the system, a bit slow today ha ha. Now we will be sending you a security prompt by SMS to verify you. We take security very seriously here...".
Though I agree that it would be good to not turn it on by ok-clicking like our parents always do. “aA -> turn on” would be enough, popups definitely banned.
I love how people here are simultaneously for pushing the web platform forward and also for holding it back.
Now about how to fix that is an interesting question...
If pushing the web forward is whatever the hell that assortment of notifications is at the top of the article, I'm all for holding it back.
Browser push is probably close to 100% malicious or ads at this point. It's directly enabled scammers to steal 10s of millions of dollars.
If Google came out with a feature that just stole $50 of iTunes gift cards from your granny no one would want it. That was browser push is at this point.
The feature is needed for browser based mail, chat, calendar, meetings etc like office.com, Teams, Slack
Yes, they all have native apps but some like to use web versions or being logged in to different accounts
Of course, short of just getting rid of it, we could make it like RSS where there's just a little icon and you have to choose to engage with it to use it, otherwise you won't even realize it's there. But I expect that amounts to the same thing, and the feature'd be dead before long, being too much effort to keep up for something that nearly no-one would both know is there and want to use. Probably usage levels similar to FTP in the browser, and that got axed.
I don't understand why some people seem to believe anything that adds complexity is positive. Removing bad features is a good thing!