Some popular browsers are supposedly "open source" yet it appears no browser user longing for saner times has ever tried reversed this change and recompiling the browser for their own use. No third party cookies by default.
The most fascinating thing IMO about so-called "modern" browsers is that even when their vendors publish source code, "99.9%" of people will not even attempt to make changes, even something as simple as changing a default from "on" to "off". It's like the software is stamped with "Read Only" or "Do Not Touch" and "99.9%" of people dutifully obey. The "0.1%" appear to be very conservative with the changes they make.
For example, if it was possible to disable auto-loading of resources, I might actually use these "modern" graphical browsers for tasks other than commercially-oriented transactions. Cookies are only one problem with these browsers.
This sort of argument in defense of so-called "tech" company "default settings" shenanigans has been called out in recent litigation. Courts are becoming aware of the power and significance of "default settings".
It's this idea of "overkill", or other simialr rationales, that I am referring to in the original comment. Just enough "friction" to stop people from changing things. Not worth the trouble, people may think. And this works year after year. Amazing. Browser vendors were not the first in the computer industry to utilise this type of tactic, but it's a fine example.
Not sure who "you" refers to in the parent comment: me or a hypothetical person. If it's the former, I use a text-only browser that neither auto-load resources nor runs Javascript, along a localhost-bound proxy that strips or adds cookies. This is perfect for me. Both software I can change and quickly re-compile at any time. If it's the later, and "you" refers to a hypothetical person, then I cannot comment on behalf of such persons.
What I do know is that most users do not change default settings.
When the user types or clicks on https://hostx.com/1.htm, the user knows she has sent a request for filepath "/1.htm" at hostx.com. That's straightforward and easy to understand. Her intent is clear. She wants the file named "1.htm" from hostx.com.
However, what if she uses a browser that auto-loads remote files and auto-runs JS, and, e.g., the file 1.htm instricts the browser to auto-load the file "1.js", the browser automatically runs 1.js without any input from the user, and then 1.js makes more HTTP requests. Has the user "authorised" that information to be sent. Imagine she does not know the contents of file 1.js. How can she authorise sending information, i.e., an HTTP request, if she does not know what is the information, i.e., the request, and where it is being sent.
> Some popular browsers are supposedly "open source" yet it appears no browser user longing for saner times has ever tried reversed this change and recompiling the browser for their own use. No third party cookies by default.
And my response was simply it's way easier for the vast majority of people to change a setting once, than compiling the source (and remember to stay up to date with new releases)
> What I do know is that most users do not change default settings.
And they don't install alternative privacy respecting browsers either.
(edit for layout)
They are not interested in computers and they certainly do not read and comment on HN.
When I use the term "browser user" in the quoted comment it can be assumed I am referring to browser users who can write/edit and compile source code. If I wanted to address or comment about a larger audience, including people who are not interested in computers, who do not read HN, i.e., "the vast majority of people", then I would not be commenting here.
https://blog.mozilla.org/en/mozilla/firefox-rolls-out-total-...
Finally, just last month.
There's lots of stuff I'd like to change, but I am not wading through the nightmare pile of code to add mdns browsing and SyncThing bookmark sync.
It's too bad most apps are getting rid of true scriptability. Browsers would be way better if you could just drop a python file in a folder and change stuff.
Overall I think "browsers" are overextended and overrated. I use them as HTML readers. I prefer separate programs for different tasks instead of one program for every task.
The so-called "modern" web browser, a "nightmare pile of code" indeed.
One project I was responsible for was the development of a distributed file system for AIX. The goal was a distributed file system that addressed some of the weaknesses found in other distributed file systems at the time. Our chief competitor was Sun's NFS distributed file system. NFS was a really nice design. It was well integrated into the operating system and quite reliable because it utilized a (mostly) stateless server. This had a number of performance and security implications along with some file system semantics over NFS that didn't match local file system semantics. We wanted to introduce state for the server to address these issues and thought of a number of complex protocols to manage it in the presence of unreliable clients. That's when I thought up the idea of making the clients keep their own state to be restored when they reconnected to the server. I protected this state from manipulation by the client by encrypting it. I didn't call them cookies, I called them tokens.
This design was patented by IBM and I was one of the two inventors on the patent. This patent was owned by IBM and years later they gave a special award for this patent because it decided that it was one of IBM's most important patents. (They wouldn't have done this unless the patent had held up to scrutiny or legal challenges). Unfortunately, by that time I had already left IBM to start my own company--I was at the top of my game and had confidence that I could create a software product of some kind that would be successful--so I missed out on the financial award for the patent. By then, I was at my new company and already in competition with IBM.
By now, the patent should be long expired. Interestingly, IBM ended up buying my company around seven years after I and a partner started it.
I was very aware of the academic literature and industrial practice during this time so I do believe that my invention does reflect original work that ended up with a very significant impact.
From a more personal perspective, the invention didn't financially benefit me. The work that I did at my company own was more creative, inventive, technically impactful, and financially important to me. For example, Austin Ventures has indicated that my company was the start of Austin becoming an important high-tech location, but none of that was related to the cookie.
In the end, it's definitely been used in excessive and somewhat intrusive ways. I also wish that browsers had better controls over second and third party cookies and tracking (similar for nested iframe) in order to bubble some of it closer to the surface. In the end, pihole, ublock origin and privacy badger goes a long way to limiting this.
You did good and there's no problems with what you did.
That's the entire point of coming from the future to the past with information unavailable. It's pretty much Time Travel 101 sci-fi trope. Rather than going back in time with sports scores and stock picks, I was putting it towards nerdy tech dev. Sheesh
I mean, it depends. If you build a atomic bomb during a war (with unrestrained city bombing from all sides going on), don't act surprised if cities indeed will be nuked with it and people point the finger also towards you.
But a general purpose lightweight distributed storage technology? Seriously no, then you can also blame hard drive producers for enabling tracking.
We all want some websites to store temporary information on out computers. Otherwise we could not log in to anything for example. And that the default of the browsers is to allow any random website to store literally GBs of data on your computer without asking (https://developer.mozilla.org/en-US/docs/Web/API/Storage_API...) - then this is really the choice of ad financed browser developers - and the choice of the users to just accept that behavior (ignorance can also be a choice).
> I mean, it depends. If you build a atomic bomb during a war , don't act surprised if cities indeed will be nuked with it and people point the finger also towards you.
You forgot the first part of the sentence you quoted.
>> We should, of course, think long (and sometimes evil)
My intention is to say that you can't do an exhaustive search and it shouldn't be expected. What's obvious to some isn't to others. This doesn't mean we can just go along without concern for morals. As scientists/researchers/inventors/developers we must think ahead (and evil). But it is like viewing history from a modern lens. We have knowledge we didn't back then and judgement about intent should come from the view of the time. (This also doesn't mean we can't look back at history and see "normal" things that people did as horrific. These are different things)
- Why didn’t you have the foresight to predict that it could be used for what it is used for now?
- Whoah there. Kind of out of left field. I had nothing to do with WWW cookies.
?
Seems like you can just tell those friends that you invented the great-grandfather or the fifth cousin once removed on the uncle’s side to the modern cookie and be done with the conversation a lot quicker.