Microsoft Edge is leaking the sites you visit to Bing
theverge.com
theverge.com
A more interesting blast from the past is the practice of capturing the search phrase in your browser sent to a competing search engine, and then noting the next visited page in your browser. This essentially captured the user's preferred link from your competitor's SERP (Search Engine Results Page), which led to legal challenges about search copying.
I'm quite certain Chrome does not do that by default. There are a number of settings in Chrome that you can change to send URLs of every web page to Google, such as turning on history sync, the checkbox for "making searches better" or the "enhanced safe browsing" checkbox. None of that is enabled by default in a new installation of Chrome.
what about today, and for browsers not from Microsoft and Google, that are also offering search?
It is still unacceptable for many.
I noticed that when you searched for the company on Bing, you would actually see a bunch of these documents, despite nothing linking to it!
Of course I updated the robots.txt and yelled at leadership for the gaping security hole, but I was very surprised to see that Microsoft would send every link you crawled back to Bing to index. Distributed web crawling!
I've curious how there was a security hole when a client opted out of requiring auth? If the client wants them publically available then there was no security hole.
Secondly, I am wondering why you are yelling at leadership for something that seems like it was your responsibility.
Its possible they wanted the link to be easier to share with very specific people, but not necessarily be something found on bing.
https://www.example.com/id/0ca6ade6b2bb1eea371d0b029f552cee/... may be "public" in the sense that it is accessible if you know the URL.
Many products (Google Docs, Youtube, Office 365, Dropbox, etc) allow sharing things via unguessable URLs; it's a standard practice that was safe, until browsers and browser extensions decided it was okay to send private URLs to other parties.
I would not be surprised if the EU steps in at some point and fines them heavily for it.
If the specific people can get to it without auth, so does everyone else.
the decisions on which basis the user opted out from auth was that they believed the links where obscure/private enough to be "non discoverable" (enough)
for example let's say your link is `example.invalid/documents/samcea45pwmcwwn325ewaruvon4pepwrm8euwawuvuer8u` and there is no non-authenticated index/listing available
under normal circumstances you could argue that this long id is comparable to a "simple" shared password i.e. knowing is a very weak form of authentication, except it doesn't have the same degree of protection wrt. storage, logs etc. But good enough for non-public non-secret data.
that is until you browsers without you knowing it or explicitly agreeing to it starts creating that index which shouldn't exist _and_ pushes it to a search machine...
(or a you have a virus infection which installs a link scrapper , now that I think about it edge pretty much acts like a virus in this case, lol)
EDIT: A example for a well known user of such links: Google. E.g. drive shear links: https://drive.google.com/drive/folders/some-ver-long-id?usp=...
Similar such links are all the time used for account setup or password reset, too.
There is nothing wrong with them, and intentional mall ware would likely be able to scrap whatever you additionally add to secure a shared link without password.
There is _a lot_ wrong with what edge is doing.
If edge would be hardware it would need to be destroyed in some countries because it counts as unauthorized spying device (but that law was never updated to the digital age).
We never got to the bottom of how it happened, but our theory was that Edge would send browsing history back to MS; and MS/Bing would index based on this. So this seems to be a practice that has been going on for a long time
Some old articles about it: https://www-nrk-no.translate.goog/norge/fodselsnummer-fra-br... https://www-nrk-no.translate.goog/norge/felleskjopet-beklage...
In my head, “normal“ CAs used by browsers for example are held to a high standard of digital trust. Whereas trust in the US military as a CA sort of implies blind faith. But I honestly don’t feel that I know enough about TLS to know why I should trust, say, digicert or identrust, more or less than the US military.
Microsoft gets a pass.
On the English speaking internet, TikTok does indeed get a lot of flak.
But on the other internets, Microsoft gets lots of criticism for how the spy on users too, together with all the other big US-based companies.
It receives it on the English speaking internet as well, but nowhere near the level as what can be seen outside of that.
Although they won't give normal users this option, if you wanted the non-spyware version of Windows, you would need to pay a subscription.
Now they’re messing up where it matters. The endless promotion of Bing, making it hard to completely remove it from the browser, adding a huge fucking B button. All while ignoring glaring bugs that were making it impossible to use certain sites with Edge while working fine in its sister browsers. Now I’m swapping back to Chrome because this is purely intolerable.
Sometimes software doesn’t need iteration or more features. Sometimes it just needs to work!
If MS stay true to form then give it a year and Edge will be a fetid turd, but they'll add some lock-in from the OS; maybe Office online breaks in all the other browsers. The World will be worse, some middle-manager will get a promotion, shareholders will get a few more cents, so it goes...
My condolences to everyone who has to suffer stereotypical enterprise software.
The Flash UI of VMware vSphere.
Why was everything Silverlight for a few months?
Also never fails to amaze me that if Adobe hadn’t been so lazy with making Flash performant on Mac, Steve Jobs wouldn’t have delivered the death blow. ActionScript was not a bad language!
That's exactly how it went. And since users keep allowing themselves to be exploited, that's how it'll continue to go.
Luckily, these days users seem to prefer being exploited by Google instead of Microsoft, so MS isn't able to force their shitty browser on everyone the way they did in the IE6 days.
On mobile, they broke the address bar somehow, so now I’m using Firefox everywhere, even though I never really planned to do so…
It’s a shame. It was a great browser for a while.
Edit to add: Firefox has the best “reader mode” of any browser I’ve tried. I’m actually really happy about that.
I cannot imagine Microsoft improved Chrome's speed by a noticeable degree without Google noticing and applying the same improvements.
The tl;dr is: It can now suspend tabs without killing the tabs.
I literally can run like 50 tabs on a 4gb RAM device with no problem on Edge. And no need to reload any tabs.
These tabs stay as "Efficiency mode".
That said, I disabled that creator follow nonsense the moment it landed. Not because of the URL tracking, but because it is stupid.
None attempted to load with the browser I am using. I was able to read the text of the article and follow any links on the page no problem.
One could hope that "web developers" will stop accepting money in return for putting this garbage into pages. IMHO this is unlikely to happen.
Alternatively, for recreational web use, one can stop using the browsers that auto-load the garbage by default. I did this and has worked better and better for over 20 years.
The popular browsers supplied by so-called "tech" companies have many "features" but they do not allow users to disable auto-loading.
The minute that software engineers stop working for Google and Facebook…
But the other day I used a clean browser to search for something in a store and the first search result was for a competing store! Very sneaky. It's all so fascinating.
The way internet is made, you either go onlyfans style paid only model where every "consumer" pays or like wikipedia where everything is open. Ads don't work, tracking doesn't work. What i mean by not working is that with tools like ublock origin, these "one trick pony" fail so then they make the appeal "but think about the creator".
If you are so concerned about your revenues, go do onlyfans. otherwise assume you will not get any revenue ads.
That is unacceptable. When your operating system can't be trusted, it's time to move to a different platform.
A lot of the excitement was dulled by the fact that a well designed, well engineered app needs money to pay those designers & engineers, and just like this instance, you can never really know whats being leaked or sold, unless it's a large open source project.
Yes, I know the old adage that if you're not paying for a product you are the product, and as I try and simplify my life and focus on having just a few really high-quality items in any category of life, getting screwed so often because of the need for companies to have as much information as possible updated as often as possible is really making it harder and harder to be the technology and internet enthusiast I once was.
You probably mean this one, a new kind of browser: https://thebrowser.company/
Also it's of course not a new browser. It's just the next Chrome GUI.
I've been using it for a while and it's solid.
Now it's just "You are the product". It doesn't matter how much you pay for something. You can spend hundreds on a copy of Windows, or thousands on a laptop or smart TV and still have your data collected and used against you at every opportunity.
It's free software now that's most likely to do what you want without also trying to screw you in secret, but even with open source software you have to watch it like a hawk. So much good software goes bad eventually and even well intentioned programs can have their own ideas on how much data is okay to send to third parties.
Sometimes this isn't ideal, and then I go through the process again. It's baffling. There are some good companies out there ofc, and I do hope they continue doing the right thing.
Iirc Edge “telemetry” is also used for the WebView2 runtime which affects Tauri (an Electron alternative) as well, so for the people who think that installing Firefox fixes the problem, that’s not true. The Tauri devs were rightfully pissed and harassed Microsoft, but last I checked MS didn't care. So it wouldn’t surprise me if this new “feature” is also part of WebView2, just because of the code share.
Wym? It's decent feature (if you are the target for it). Ability to track your subscriptions from all of the different websites in one unified place (in this case your browser) is not a terrible product
Has Google said this? They might infer duration from time between clicks on different search results, but I've never seen evidence they are using data from Chrome and Google Analytics.
Source: used to chat with Google search engineers about web spam back in the day at conferences.
Believe what you want, but apply some basic logic - why would they not use data they already have?
For example, a search engine that made a good-faith effort to filter out SEO-optimized junk like listicles and slideshow "articles" would be extremely interesting to me. Bonus points for allowing me to permanently blacklist entire domains from search results.
Or, you know, just don’t use Edge???
I don't believe for a second that this is a bug.
Another slick trick of Edge that I have noticed is that after updates, various settings can change or new ones added, particularly those that involving privacy. So users have to always be wary and vigilant about checking all settings after any update.
Email? Works. News websites? They work. Banking sites? Yep. Google Maps in 3D? Works. Which special, golden webshit is it that breaks on Firefox? And what do people mean Firefox is slow? I've tried Chrome, and boy either we live in differen universes, or there isn't, in fact, any difference in speed.
I find this no longer the case, and I am now back on Firefox :)
Now in 2023 Firefox is fast again, but so is Edge. As soon as Edge was usable, I ditched Chrome, and will only consider Firefox again if they add native vertical tabs.
My point is, browsers are continuously updated, so any claim about a characteristic must be specified in some timeframe.
Honestly, imo for a decade or so now (since the times of the old opera), most browsers are more or less the same utility-wise, with only minor differences between them. Most of them nowadays are chrome clones anyway. And if there is a feature in one and not the other, there will certainly be some extension that adds it. So I do not see why not at least go for the best privacy option.
https://imgur.com/a/p4CVBHb "Power and privacy to the people. No need to dig into your security settings. Fierce privacy is our default."
but has Google as the default search engine and defaults to having search suggestions on.
My search suggestions are disabled and I exclusively use keyword searching like g, y, ddg, da, ...
(My experience over 20+ years: no, they don't.)
There is also a section in the Privacy and security section for the firefox suggest feature specifically. [1]
I could be wrong but I thought those were also piped to the default search provider. I havent fired up wireshark to test though either.
[1] https://support.mozilla.org/en-US/kb/search-suggestions-fire...
really the only way to be sure is to fire up wireshark. But I am on a work computer with a TON of crap running that is quite chatty. So i didnt look to verify.
But even on my browser I see this: https://imgur.com/a/odiHIzy
That said, my search provider is Kagi and I also dont see my search quota increment even with search suggestions enabled....
As long as you're doing that you might as well go all out and work through the ever-growing list of "features" that generate outbound connections you never explicitly requested, but which Firefox makes anyway.
https://support.mozilla.org/en-US/kb/how-stop-firefox-making...
Because of how profiling algorithms work, you could just as easily profile someone based on hashes alone. The URL doesn't matter.
Basically this: https://en.wikipedia.org/wiki/Federated_Learning_of_Cohorts
"Power and privacy to the people. No need to dig into your security settings. Fierce privacy is our default."
- Firefox on a recent update. You know, a browser that defaults to Google search and having search suggestions on.
I know I'd have a couple privacy settings to change.
This sort of behaviour, which Firefox had indulged in in the past, is abhorrent. It needs punishment of the company and the controlling staff; they can not be trusted at all.
More seriously, I wish there was a web browser built in a sort of cameleon fashion:
* layer 1 - the lowest layer would be some weird rotating engine that would use different browser engines to send disinformation to all websites, web apps. For example, at one moment websites see that i'm on FF, but the next moment on a version of (fake) "Chrome", etc. But, functionality, the user is unaware of what engine is actually driving the typical underlying browser processes.
* layer 2 - the middle layer would hold my personal/private data, like saved passwords, cookies that i desire, etc. This layer is in total control of the user and their data. Whatever configs and preferences are set by the user are saved in this layer, and it persists across browser upgrades, browser synching platforms (like Firefox Accounts), etc.
* layer 3 - is what the user sees as browser UI (the original term was "browser chrome" of coiurse), and interacts with the UX features...The user can use 1 of a few UI themes: 1 that "looks" like Firefox, another that looks like Chrome, another looks like Brave, Edge, etc. On top of these "browser skins", there could also be the typical browser-brand-specific themes that each native browser has available.
I should state that i know nothing about how browsers are developed...And I acknowledge from my armchair that the above would make developing a new browser crazy complex...but, wow, such flexibility i think would be pretty neat!
> Depending on your settings, this browsing history is sent to Microsoft, which helps us find and fix problems and improve our products and services for all users.
So is the news that they're doing this even when the "Help improve Microsoft products by sending optional diagnostic data about how you use the browser, websites you visit, and crash reports" option is off? That'd be unfortunate. Or is the news that it's sent to a Bing domain rather than a Microsoft domain? That is just stupid reporting.
[0] https://support.microsoft.com/en-us/windows/microsoft-edge-b...
Specfically, the following request is sent:
GET /api/v7/followweb/isfollowable?appId=F1E45C4A7B95B48AC3F411C6214F6B861D0C276B&mediaUrl=https://www.domain.com/&edgechannel=stable HTTP/1.1
The endpoint then responds with a bit of JSON: { ..., "status": "UnFollowable" }If the option is being ignored, it's the kind of thing that'll result in fines in multiple countries. If the option is being respected, it's not even a story. I assume you're the person quoted in the story and know the details, so thanks for clarifying. Sounds like it's the former then.
IIRC one of Sysinternals tools allows to pull list of accessed files, folders and sites regardless of the browser. In such case Edge wouldn't need to report history because OS does that already.
Just offer a simple clean interface to Bing + ChatGPT.
Without all the visual clutter and dark patterns.
Why do they keep the foot on the break by adding all that nonsense to their search engine?
Google is bringing in $160 Billion a year with their clean search result pages.
Why does Microsoft think they need to play clumsy tricks and add stuff on top of the search results to make a buck?
I see more users coming to my sites via DuckDuckGo - which searches via Bing - than via Bing itself. And that while Bing is the default search engine on the majority of new desktops and laptops out there. And the default search engine on many new tablets. Plus they have ChatGPT integration. It's just ming boggling how Microsoft wastes all that power with a bad UI.
No, Google brings in $X billion a year with all the ads and garbage they stuff in between those clean search results.
The same is true for Microsoft. There's no money to be made to run the service (let alone justify an American company's lust for growth and profit) without stuffing it full of ads to hopefully sell you something.
But visit this site:
And then visit this site:
And now tell me with a straight face that you don't see a difference.
Bing ads a ton of stuff to the "results+ads" concept that works so well for Google.
e: Oh woah if I zoom out to 90% then I see what you are talking about.
The layout of the results page for two sample search are almost identical.
Actually for "what is a barnacle" I think Bing wins for clarity of results.
When searching for "what dog food is the best", both Bing and Google give me an entire page full of ads before any actual results pop up.
On desktop, Google's "sponsored" marker is more obvious than Bing's, but no wheres near as obvious as it used to be when Google's motto was don't be evil.
Mobile search result ads are aggressively bad with Google, frequently I have to scroll down past a page and a half of ads before I get to actual results.
All in all, users are losing out.
Hamburger menu > Customize my homepage > uncheck the 3 boxes
Same clutter as google.
Yes, you can complain about the default, but Bing makes this pretty darn easy.
What worked for Google in a crowded search market in the year 2000 is not necessarily going to work for Microsoft Bing in 2023.
In any case, if Google's clean design was such a differentiator, they wouldn't need to pay Apple $15bn to make it the default search engine on Safari.
Also crazy that they wont let me use their new AI without downloading Edge. I'm not going to change my browser just to try a search feature. Do you want to get me using your service or not? Presumably my using Edge + Bing is only a minor improvement in conversion versus me using Chrome + Bing, relative to me not using Bing at all.
They are not conventional keyboards, they have slightly-updated interfaces including larger meta keys, a split hand layout, tenting and reverse tilting, integrated palm rest, and some other niceties. Yes, Microsoft is capable of shipping a decent user interface. Just not in software. ))
The decent part was inherited from 20 years ago. The new UI changes have generally been detrimental.
It got to a point where I'm contemplating (but too lazy) to switch my gaming PC to Linux
And I've been through a lot of operating systems, starting on the PcJr and DOS in the 80s, and every Windows version ever released.
I'm a software engineer and occasional gamer. I use Windows every day for both my job and for everything else, and I have no issues with it.
That's why I find all of the nostalgia a little weird. Some think Windows 95 was the "peak" Windows, others point to 7 and want their "aero glass" back, others say 10 is the best and refuse to upgrade to 11, some install the old start menus in the new versions, etc.
It's the same every time a new version comes out. Eventually people years from now will look back and want to try to make their desktops the way they remember their Windows 11 desktop looking.
But this is veering off topic.
This is an often repeated excuse. It certainly isn't nostalgia. There need to be adaptations, mainly for decent scaling for higher resolution devices. But that doesn't mean the latest iterations are good. Windows 7 wasn't good either, but it was better provided you have your standard hardware setup.
Same with the start menu. I don't install the old one, but I certainly don't use the new one either. My start menu is now win + e & win + r. Because the rest ist plainly useless. Granted, this was the case since Win7 too.
It isn't that people like the new version, they just have to use it and find a way to manage. And yes, people also said that the Win95 UI was crap too.
There were some geniune improvements over time, but they are rare. I couldn't name a single one for Win11 yet. There are a lot of negatives though that even surpass the negatives past updates might have brought about.
But not solely with Bing. DDG aggregates from many different sources, including what their own spider finds.
Show me a query for which DDG has different results than Bing.
All this modern corporate bullshit is just unbearable.
What clean result pages? You posting from 15 years ago?
I see nothing clean like “10 blue links” when I search for “bicycles”
Is Microsoft still doing stack ranking?
That's almost every modern Microsoft product, in my experience.
Let me ask this: Would you be surprised to learn that Google Chrome sends data to Google when you enter something in the task bar to give you auto complete predictions? I wouldn't. The same is also true for Microsoft Edge sending data to Microsoft Bing to enable a feature of the Webbrowser.
In this age of AI scraping every shred of data I suspect anything connected to the internet will be compromised in a back room deals, through lack of security, or through sub-contractors sharing what they can get their hands on.
I think reactions to this are more along the lines of horrified, but it is our accepted trade off in the name of cheap products.
Is there a production-ready library for this? I do see the code in the article but I'm not sure I'm ready to venture into these deep waters myself.
https://addons.mozilla.org/en-GB/firefox/addon/firefox-trans...
Any way to verify this as end user and raise it to our IT folk
It's annoying that they force you to use Edge. Otherwise it would see no use from me.
Which, I know ... that's exactly why they're doing it.
It says that microsoft answered that it is "investigating the issue" which is a pretty much standard response, but it does not confirm that microsoft did not implement this. But seeing that [they even have a master filter for which urls to send to the bingapis and which not](https://www.bingapis.com/api/v7/followweb/getdomainfilter?ap...) it seems definitely a feature.
It is potentially an invasion of privacy, but also is excellent to get good search results.
Not everything is black and white. Search results have been abysmally bad for a decade now. Anything that can help fix them is welcome.
The feature they're referring to is configured remotely [1] with a set of domain filters that demonstrate the intent was to only capture a subset of sites. I think this is where I'm now supposed to refer to Hanlon's razor--Never attribute to malice that which is adequately explained by stupidity.
[1] https://www.bingapis.com/api/v7/followweb/getdomainfilter?ap...
If microsoft really wanted to scan ALL urls that badly, they can... always just do exactly that? But when they actually implement fairly decent feature that has a bug in it... it's probably a bug yes. They really have no reason to be sneaky about it
I haven't used Firefox in ages but AFAIK it has very little bloatware. The problem, from the perspective of a web dev, is that it has quite a few rendering quirks/bugs. These days chromium sets the standard for the "correct" way to render things.
Though I have noticed some issues in Teams but that’s about it
I apologize if you are already well aware of this and that the problem is that is more complex than that.
Actually I did some Googling around, and found that it was fixed recently - after 4+ years lol. https://www.ghacks.net/2022/02/28/bitwarden-firefox-private-...
Hamburger Menu > Settings
Privacy & Security tab on the left
Scroll down to the Firefox Data Collection and Use section (2nd section from bottom)
Uncheck all of the boxes in this section
What's weird is that some of your comments aren't dead, and typically shadowbanned users have all of their comments auto-marked as dead. It's possible those got vouches though.
And don’t get me started on Firefox nagging people to use Mozilla VPN, and their push towards DNS over HTTPS, as in “Trust me dude, I want your logins, your passwords, your DNS and your VPN, and pinky swear I’m just a charity with benevolent intentions, Google just gives us money for… stuff.”
I think the "opens tabs all the time telling you how much Big Browser care about your privacy" is primarily referring to the tabs that are sometimes opened when you restart the browser for the first time since a new update has been installed, telling you the sort of stuff that is in the new update, or sometimes talking about other projects they have.
Or like, "hey, try colors" or whatever.
I disagree with their insinuation that the push of their VPN etc. is for a nefarious purpose due to their receiving some funding from Google.
We’re in the paradox that it is possible to claim there is no ad on a browser because you don’t look at them when they appear. Similarly, people who are satisfied with a government stance will see no problem in violently repressing opposition. Defects only appear when you are on the other side.
But they do appear, and they educate the users such as my parents into creating a Firefox account or assuming that Firefox equals privacy, which is clearly not the case.
I didn't make that claim. I just said I immediately close them and don't mind them much because I basically only restart the browser when I reboot the PC (so about once a month because after that all kinds of bugs start to appear).
Of course I see them as problem, I assumed that was obvious from the rest of my comment.
Agree that Mozilla building independent sources of revenue is a good thing.
You don’t have to name names if that’s a problem, but there should at least be something credible we can look into.
Pretty explosive allegation imo.
It also makes my blood boil that Safari both hides the full path of the URL you're currently visiting and doesn't implement the standard practice of giving you a preview of the full URL you're about to visit when you hover over a link. These are horrible choices for usability and security, especially at a time when phishing is so productive.
Safari has both of these. Safari > Settings > Advanced > Show full website address, and View > Show status bar.
Moreover, I don't think either of them help out with phishing. The intention behind not showing the full website address is specifically to stop phishing, since it puts the emphasis on the domain name. (Is there a phishing situation where someone could spoof the domain name? Maybe, but I imagine in that case, they could spoof the rest of the URL as well). As for the status bar, I don't think anyone would look at it even if it was enabled by default.
In regards to the https problem specifically, while safari will say you are browsing an insecure page if using http, they do it in a horrible way - by adding text to the beginning of the url bar. Certainly if you were trying to reduce url confusion, you would add a separate symbol and label! I can click insecure icon on chrome and other browsers to read more about how, but I cannot do so on safari -- so much for trying to reduce confusion.
What's the problem with this?
> Certainly if you were trying to reduce url confusion, you would add a separate symbol and label!
Why? I'm not following what's wrong with Safari's approach. You're stating your conclusions but not your reasoning.
> I can click insecure icon on chrome and other browsers to read more about how, but I cannot do so on safari
Read more about what?
In the second, Safari inlines the "not secure" to the URL but not in a visually clear way. It looks like "not secure" is part of the domain.
Read more about what the "not secure" and the padlock actually means.
The move to hide the full URL is to make the URL readable for the average user. People on this site might know how to parse URL components in their head, but the average user does not inherently understand the DNS hierarchy nor do many completely understand URI delimiters.
https://secure.bankofamerica.com.0-0.pw/login/securelogin.aspx
might look okay to a lot of people 0-0.pw
would be a little better indicator that it isn't their bank.The padlock is mostly useless in today's world. It was useful in a time when ecommerce was young and otherwise legitimate sites were collecting information via http. There was an attempt to make it more useful with extended validation certs, but that solution didn't really end up being effective. Phishers could still register EV certs that spoofed other names, and adoption was too low to change user behavior.
Criminals today phish people, use HTTPS, and people have a false sense of security because of those who told them “padlock = good”. The padlock served a purpose to drive http adoption. It does more harm than good today.
Browsers should instead upgrade to https automatically on all connections.
And frankly, the Settings window and the View menu are not obscure places to put these options. Those are the first places you should look if you're in a Mac app and want to configure the UI.
If Safari was a 1:1 clone of Chrome but without (probably) sending my stuff to Google, I'd be all over it. Millions of other Mac users too. Instead I'm using Chrome on Mac just to get many websites to even work.
Uh, which part of my comment do you agree with? Clearly you disagree with something, because that's the opposite conclusion I came to.
Reference?
If it is “near impossible to turn that off” it means it is possible. How?
At the end of the day, only legal requirements are going to curtail this type of behavior.
> Even paid products do this kind of stuff these days.
Yes, if you pay for the product, then not only are you still the product, but you're a sucker as well.
It's not quite that stark, but I don't see why a company would truly change its business model just because they charge a fee. It's too tempting to "do something with all this data," i.e. treat all consumer software as spyware.
"You're always the product and willingness and ability to pay for a nonessential service makes your disposable income an even juicer target to advertisers."
Zero-telemetry, with built in adblocker.
Business model: pay for the browser.
Your turn!
Yes, OEMs pay for Windows; probably businesses pay for Windows. It's pretty clear they've gone to an ad-supported model whether they're honest about it or not. And of course, paying for the product doesn't mean they won't suplement invoice revenue with advertising revenue.
Last time I checked you could still just set the wallpaper via the context menu. It only locks the appearance settings.
He wasn't the nicest guy much earlier than that.[0]
So yeah, MS is being paid for their browser. But a trillion dollar valuation is simply not enough.
Not on Android. AOSP is free, but if you want to ship the play store then you have to also include the other Google apps. It is the Google data harvesting and advertising that pays for Android.
Maybe those goals align at some point, but corporations' alignment drift makes AI look downright peachy.
[1] - I'm presuming HN people, not moms & dads.
That's literally the only reason I use Edge. I want someone to release an "Edgium" like vscodium or, alternately, implement Edge's vertical tabs in Chromium.
[0] https://blog.google/technology/ads/helping-publishers-recove...
Google helping with “Adblock” is a farce considering research has shown a key reason people use as blockers is to protect their privacy…from Google.
Like Apple, Microsoft and Mozilla did for a long time.
Nothing good is viable with the current tech "economy", where software is an endless death-march of feature-bloat to justify the unlimited (also known as cancerous) growth required by venture capital or public markets.
But I bet a couple guys could pull off an Opera 2.0 and make a nice living for themselves. You only need a couple thousand paying users at a very modest subscription fee to cover a couple of developers' salaries
Re: Windows, if we're not paying for it anymore are we still the customer? Even if that's a yes, it represents a cost for msft, so they seem to be looking to extract any amount of value out of it that they can. I doubt I'll use it past Win10, the downsides just keep piling up.
https://www.microsoft.com/en-us/d/windows-11-pro/dg7gmgf0d8h...
https://gemini.circumlunar.space/
Pick your browser, I like Lagrange.
https://gemini.circumlunar.space/software/
Now we just need content.
As if the trend was not clearly visible by windows 10 and carved in stone by windows 11.
Just assume that all sites you visit is a publicly available data.
As others have commented, it's like being upset that Google Search is aware of websites you visited in Chrome. Is it unethical for that to be the case?
For me, this particular issue isn't about privacy, it's that these companies get to make their products better using my data and I get nothing out of it. Sort of how they train their AIs.
Privacy has been popularly re-defined to be "any data." Remember when people's name, address, and phone number was published in a big yellow and white book and delivered to everyone's driveway?
What we should want is compensation for the use of our non-PII data and a restriction on information about us that can be used to harm us, financial, medical, etc. to be restricted.
Chrome not telling Google I went to Amazon.com would be great, but Amazon knows I went there and if I use 8.8.8.8 so does Google anyway.
In both cases, because of these factors, yes.. I consider it to be unethical.
Yes. It's unethical in both cases.
Imagine you buy some shoes and learn that they share location information with their manufacturer. Now you think "well they do have this feature warning me if you walk in a dangerous area, so i kind of knew they do", but then your health insurance changes your policy because "you haven't been walking enough".
Does it become more ethical when the shoe producer and the insurance company happen to belong to the some corporate group, because they are not sharing with a third party?
The primary ethical problem is about using the data for purposes the users did not know about and did not agree to.
People use Edge to browse the web. Microsoft adds a new feature called "Follow Creator" and enables it by default, without asking for consent, and then fails to disclose why exactly that feature needs to collect all urls their users browse to and what that data is used for. These are highly unethical business practices.