And of course: we owe it to the web to use Firefox. The Chrome clones are only stalling; not counteracting the impending monoculture even one bit. It doesn't matter how fancy their marketing is.
And of course: we owe it to the web to use Firefox. The Chrome clones are only stalling; not counteracting the impending monoculture even one bit. It doesn't matter how fancy their marketing is.
There are many browsers, many apps, many everything... you can switch whenever... but the DRM and attestation pushes with browsers (and mobile devices) means, that sure, you can use a different browser, but your bank, your streaming service, your newssite might not work unless you're using chrome with drm and hardware attestation. This is already true with many banking apps, where you cannot even start the app on a rooted phone, a phone with an unlocked bootloader or even just a phone that's "not on the list".
So yeah... google is the silent killer of the "free interet" and te world happily follows... sadly.
Edit: and by switching i don't mean going to some tinfoil grayweb nonsense. Go to their direct competitor.
The banks don't need your money.
Indeed.
> If even some 10-20% of IT professionals (with salaries to match) up and leave for a less shit bank, trust me, they will care.
That's an impossible number of people to coordinate on something like this, and even if, I doubt banks would care. There exist no less shit banks, and retail is a rounding error anyway.
Banks aren't shit because of incompetence or a not-give-a-damb attitude. They're shit because it makes them more money, both directly and by reducing risks.
If your bank account gets drained and you'd made a big song and dance about how you selected that bank specifically because it had less security on its mobile app, well, nobody will have any sympathy for you.
If your bank is equally secure but uses dedicated hardware devices instead of smartcard readers, then all you did is swap one bit of secured hardware for another, making your life less convenient and in return for what?
A bank has to know it's communicating with the real human who owns the account and not a hacker. It's going to achieve that one way or another. You'd be much better off accepting the tech and finding ways to achieve your goals within it, like by setting up a project to maintain whitelists of known good/secure OS builds. You can then make libs that wrap SafetyNet and eliminate the false positives. Even if banks don't start using it anytime soon, other smaller companies might and it's a place to start. Of course the fact that virtually nobody cares about custom operating systems to begin with is the biggest hurdle you'd face, not the tech or business requirements, but that is partly on the OS developers. You can't complain nobody cares about if you're not giving anyone a reason to care.
If my phone breaks or is stolen, I can’t actually buy a replacement phone now, as that requires spending money, which requires 2FA which requires my phone.
Some banks are phasing out code cards or SMS verification for 2FA, and the only way to get the second factor for logging into the online banking website on your computer, is to use the bank’s app on your phone.
This is utterly false. Yubikey, TOTP-based solutions, there are options. It is a choice by the businesses to not implement those options.
A mobile phone app can let users "deposit paper checks from home" without ever driving to the bank branch by taking a photo of the check with the smartphone camera. Last time I looked into it, a desktop website couldn't enable check deposits with a webcam. (EDIT: I don't mean technically not possible. I meant that the banks deliberately chose not to have the websites utilize desktop/laptop webcams as an alternative to smartphone apps.)
Smartphone bank apps also have "push notifications" to immediately alert you of suspicious activity on your account.
But if one never uses the extra features that smartphones bank apps enable, then yes, desktop bank websites can be seen as perfectly equivalent.
I really want a general-membership credit union with stellar technology, but I haven't found one yet. Does your credit union by chance offer open membership?
"Suspicious activity" is such a bad strawman argument, i'm not sure how to address it. "Just thought you'd want to know your money is gone, lol." Either you do N+1 factor authentication for real, or you just shouldn't bother. Browsers have had push notifications for quite some time now too... so even if it was a worthwhile feature, it doesn't need an app.
Of course, a bank should be able to send you a text on the service of your choice. But they won't.
True, but the key word you used is "most". E.g. My home insurance refunds an annual dividend back to me and their method to pay me is paper check. Not an electronic direct deposit, nor a VISA giftcard, nor even a "credit" that can be applied as a discount off year's premium. It's a paper check.
>So of course it _can_ work just the same there.
Sure but that's talking in hypotheticals. Today, I have the reality of a paper check to deal with and Bank of America and Chase websites do not have options to upload images of checks for deposit. (Chase does have a paper check scanner option that doesn't require mobile phones but that's only for commercial accounts: https://www.chase.com/business/banking/services/quick-deposi...)
>"Suspicious activity" is such a bad strawman argument, i'm not sure how to address it. "Just thought you'd want to know your money is gone, lol."
No, you misunderstand. The better banking smartphone apps will require interactive approval from you to allow a particular suspicious transaction to happen. This prevents your money from being gone. (Example screenshot: https://www2.bac-assets.com/online-banking/spa-assets/images...)
> Browsers have had push notifications for quite some time now too...
No, web push finally came to Safari in iOS 16.4 which was just a few months ago in April 2023.
From the tone of your reply, it seems like you'd rather be argumentative instead of acknowledging that bank apps have some extra features that's convenient for some users.
Why not?
My bank only allows me to do Zelle (instant p2p money transfer) via app, not that a browser would be incapable.
My HOA started mandating Zelle as the only way they will accept payments. So now it appears that I have no choice but to use a device that supports my bank's app if I want to avoid getting a lien put on my house.
Or there should be the option of opening another account, at a less tyrannical institution, to use for those payments.
Let me tell you how that tends to go down in the real world. The HOA doesn't have a physical office or anything. It's some random address and random suite. Maybe it's a document processing company or some other third-party processor. There's some non-trivial chance that some $15/hr kid who may or may not have been raised right is opening the envelopes and feeding the contents into a scanner.
So I stuff my HOA dues in cash in an envelope and then go down to the post office to stand in line and get it delivered certified with a return receipt. I get the return receipt. Then the HOA puts a lien on my house. I say, "But I made the payment on time!" Then they say, "Naw-uh." Then I say, "Sure I did, I sent it in cash and I have a return receipt." They say, "We have no idea what you're talking about."
<sad trombone>
> Or there should be the option of opening another account, at a less tyrannical institution, to use for those payments.
How can I find out which ones let me use Zelle through their website? I don't trust anyone I can find at a branch or on the phone to give me the correct answer, because chances are they all personally use the phone app and really have no idea. I guess I can start opening up random accounts with random banks until I find one that works. For now.
I think we're missing the point entirely by talking about cash and hopping around banks and all that. The point many people are trying to make here is that life is already being made unreasonably difficult for those of us choosing to use Libre computing platforms, and there's a plausible reality in the future where choices go from inconvenient to scant to nonexistent.
No message, no nothing, just close the socket.
But this bank routinely violates EU directives so I'm sure if there's a rule they don't care about it.
You’ll end up with a fork of Chromium/Blink that doesn’t have WEI. And it will be used to surf web sites. While the official browser from Google would be used to access sites that require WEI attestations. Just like the Bank of America app would.
Corporate power in pushing Chrome for everything can be limited if we have open source alternatives. Look at Firefox and what it did to M$IE, which had the full power of Micro$oft behind it. That only happened because Netscape chose to OPEN SOURCE their code base. They couldn’t beat IE on their own, but the open source community could.
Well, that and WebKit, which was basically adopted by Apple (Microsoft’s competitor) from another open source browser, Konqueror! And that led to Chrome, Chromium and Blink etc.
In short — open source is the best way we can check corporate power on the software side.
On the hardware side, it’s far more difficult, and if the vendors choose to ban any “unapproved” apps (eg requiring Safari WebView rendering engine in all apps on non-jailbroken iPhones) then the best tool we have is government antitrust laws. Maybe one day, in that area too, open source hardware will be the people’s best weapon. But not today :-/
I mean sure, you can just not-use those services and not chat with everyone else, but that's a bad solution.
And the rest of the web can be accessed using the fork of Chrome
What’s the big deal? People have been using Popcorn Time to view movies that they couldn’t access, and so on.
Which means that every service in countries where Huawei has major market share definitely can't require Google anything.
Not if one doesn’t want to end up supporting Chromium in any way. Which one shouldn’t if they believe “chrome and google in general are the first in line to cause problems”.
On macOS, that leaves essentially Firefox and Safari. Except Firefox has no support for AppleScript so it’s excluded from a ton of useful automations and is thus not suitable as a daily driver for many people. So Safari remains. And Orion, which is also based on WebKit. Both are closed-source.
There are indeed many browsers if all you want to do is display webpages. But as soon as you have any hard requirement, be it ideological or technical, the choices drop dramatically. Unless you don’t mind supporting Google, that is.
Which is why we should shame every one of us that does do it.
I don't tend to have the issues people are describing using Firefox for banking, paying bills, etc. And when I'm shopping for something at random and looking for the best price, if one site I've never heard of doesn't work (typically Cloudflare) I just go somewhere else. But Verizon reworked their back end within the last month, causing UBlock Origin to SCREAM (over 2000 blocked scripts and counting when all was done), although the real trick was spoofing as Chrome because until then only the page headers and footers would appear, not the body with the "Pay my bill" button. Opera was even worse, so somebody screwed up something badly! I was chatting with support all this time and they logged at least one ticket.
Thinking through the "public shaming" bit, if the issue reoccurs next month, I'm going to the Better Business Bureau. While they can't guarantee a resolution, it is a very simple way to publicly shame a company doing wrong.
Long term, I'm thinking we need to add "user agent" to the list of "protected classes", i.e. gender, race, sexual preference, etc. to really hammer the point home. While it's just a piece of software, there is a real person behind it. Bots need not apply. And from there perhaps a law or FTC rule to state that public web sites must be accessible by the public.
I do wish the EFF would take up this cause.
Just forget about that. If you don't, I'll take the google software engineer salary and build it.
The issue is not technological, it's a natural outcome of how people work on and individual, and on a societal level. Regulation is the closest that can affect this situation, but as it turns out, no large entity has the same goals as "the people" - hence, I'm not holding my breath. I am using Firefox and other FOSS software though, and contribute back what I can, donations, bug reports. It's a nice privilege.
Mozilla is hanging tightly on the Google's tit though. It won't be shocking to see Firefox deteriorate rapidly should it start gaining ground on Chrome. He who pays the piper calls the tune.
It is actually Google's Blink that split off of WebKit, not the other way around.
they have 25% of the mobile browser market share.
The web lost. Now it's just a transport layer for mobile app API requests.
It seems they have gotten inside your head. If services are no longer that, but "apps", then of course people lose sight of the problem.
And as you are already on to, not all web apps are cloud. What can be on-device webpages (e.g. routers) should be.
If a company is going to be gating their API behind some proprietary shovelware anyway, I would rather they write it in a plaintext scripting language (JavaScript) that runs inside a free software virtual machine (Firefox) which lets me intercept and control it.
*Yes, "program". How I hate "apps". Perverse term.
Companies continue to encroach on what should be basic freedom to do network management. It's entirely intentional; to the point that I've about accepted there's a high-level of society push to enact as many barriers to reasonable liberty as humanly possible, all in the name of "Public safety" or some other transparent on further examination excuse.