They (Chrome) are taking it away [0].
[0]: https://developer.chrome.com/en/docs/privacy-sandbox/user-ag...
They (Chrome) are taking it away [0].
[0]: https://developer.chrome.com/en/docs/privacy-sandbox/user-ag...
I have no doubt Google has self-serving motivations here but the result is still a win for us. I wish Firefox had enough leverage to force decisions like this down people's throats whether they like it or not but it just ain't so. Reality is imperfect so I'll take what I can get.
So sorry, until you pay with a unique individual bank account to prove identity, you can't post on future social media sites. You are a bot after all.
If it's costing you money, have your HTTP server return 402 Payment Required instead of the free page. That's how it should be.
I do not agree that every piece of the internet "should be" behind a paywall because bad actors exist. That world is the literal death of the "open" internet, putting everything behind a paywall.
Not something that should be prevented.
> false information, information manipulation
Not something any one person should be the arbiter of.
> and any other number of malicious inputs that otherwise in a forum for people require trust to maintain community quality
Trust is how you solve this. Forums shouldn't be letting randoms sign up and post. Just like we developers don't let randoms commit to our git repositories.
But they want that mass market appeal, don't they? They want everyone to have input access, to be able to comment and participate. Usually because they're pushing ads and the more eyeballs the better. They're hopelessly dependent on "engagement".
> That world is the literal death of the "open" internet.
Not really. It might mean the death of the "free" internet but not the "open" one. The open internet is the one where we get to use whatever software we want to interoperate without restriction. It's the one where we get to use a Python script to scrape your site if we wish to do so. It's the one where we get to download videos with yt-dlp.
But I do intend to arbitrate if the election information being input from multiple geographical locations is valid data or not. Otherwise I'm not doing the project and the existing system of it only being owned by the largest political parties who have their own organization doing the tabulation. Others who have attempted this work have seen active manipulation campaigns over the course of their validation and speak to the only way to counteract the manipulation was bot control.
I do not want mass market appeal. I want the thing to get adoption for a day by people that would otherwise be casual at best internet users.
> The open internet is the one where we get to use whatever software we want to interoperate without restriction. It's the one where we get to use a Python script to scrape your site if we wish to do so
Sorry, Error 402, please provide payment. You're a bot until proven otherwise.
How are you going to do that?
I live in a country whose supreme court routinely orders censorship of "fake news" and other kinds of "harmful" information, something not seen since the days of our military dictatorship. This year our government essentially created a ministry of truth. They censored "fake news" which literally turned out to be true after our current president was elected, it's comical.
How do you plan on being any different?
> Sorry, Error 402, please provide payment. You're a bot until proven otherwise.
OK. Do you accept credit cards?
The same way it's organized among the political parties. Word of mouth, social media and good will among interested parties who trust each other for a common goal of maintaining democratic principles. I don't come from a country that censors such work. Their main problem is it's all pen and paper by people that are usually schoolteachers and farmers on a normal day and they need the tech help.
> OK. Do you accept credit cards?
No I do not accept credit cards. I'm neither a business nor a payment processor. Please contact the administrator. Don't expect a reply. If you have to cold call, you're not in the existing trusted network where others vouch for additions to the network and will be two-factor geo-IP verified. Good luck with your python scraping in your world.
A good democracy will have access for whoever requests it to validate and learn about their peers more, not forced behind a paywall. Hopefully by enabling my ethos, it marginally feeds towards culturally maintaining that my country doesn't have a Ministry of Truth and other forms of democratic deficits.
A core of Democracy is indeed preventing ballot stuffing when people go to upload the vote results they see. We're just not talking about electronic means than paper ones. You say "me", why is your script different from a Russian-style nation state trying to put weight on the scales? Or trying to DDOS the site? And if you are indeed different, to make the distinction in any way, some form of meta information must be monitored and acted upon. You may be innocent, I can not know that in the technological future you propose. Without information, as per security best practices, the wire defaults to closed, not open. The cost is the loss of ease of use and access, but the data integrity is more important than your scripting convenience. The data can at least represent the historical record. Without that historical record, scripting of false data is worse than useless and actively dangerous and not worth putting into the world.
> You say "me", why is your script different from a Russian-style nation state trying to put weight on the scales?
Don't accept votes from unknown, untrusted randoms. Even in my country where the election is fully digital, they check my ID before letting me vote. There are ways it could go wrong but that isn't one of them.
> Or trying to DDOS the site?
They can't DDoS you if you have them pay for the resources required to serve them.
> The cost is the loss of ease of use and access
That's fine.
Trust can be built from metadata. You stop it from being unknown, by shock, building up knowledge through recording it.
> They can't DDoS you if you have them pay for the resources required to serve them.
Not a payment processor. Not a business. Nobody is going to pay for membership. This is not on the table.
> That's fine.
I deeply disagree and you're not changing my position on that nor am I likely to change yours. But I'm the implementer, so guess which way it's going. See: Not accepting your money.
What I have though gotten out of this conversation is that I'm now aware of how much more complex feature set I need to put into the first party tracking to get it right in a shifting tech environment. So food for thought.
You're an implementer operating in a deeply adversarial environment where everyone is your enemy. Everything you do can and will be circumvented, especially by the Russia-style attackers you mentioned. See the copyright industry's fruitless attempts to curb copyright infringement. If it actually looks like you succeeded, it's only because people didn't care enough.
Unless the free computing we enjoy today is completely destroyed to the point we can only run government signed software, there's little you can do to defend against these things. To stop this, you will need tyranny the likes of which will destroy everything the word "hacker" stands for. I presumed you cared at least a little about that since you're posting on Hacker News.
Yeah, I grew up and realized that there's more to the world than mere developer convenience above all else. If Hacking means siding with the developer over everyone else in humanity and societal benefit, let it burn. Luckily, that's not my definition.
I'm fine with what my side project is and it's scope. It's secondarily a tech demonstration for the bigger thing that comes later. If that means the early stage is only viewed by 2000 people and improved the lives of some election nerds for no monetary gain plus a news article after submissions close, good, the plan is on track. I'm not trying to be big in this project.
This sort of thing always feels like it's going against the grain, with someone always asking "why wouldn't you do this properly. You know, build an allow list of user agents and match against them". I fully support people being forced into detecting the features they want and doing away with this nonsense,
The web platform gave web developers way too much freedom and they're abusing it. God giveth and god taketh away.
Or for more useful stuff, "X gets you data from URL Y". Either you get that data or you don't. Voila, data about the browser.
The only alternative is that you never ever release any new features or fix any bugs.
If I remember correctly, Firefox's fingerprinting resistance will actually slow down functionality to achieve that. Reduces the precision of performance timers or something. Makes CAPTCHAs exponentially more obnoxious.
So... yes, you could build a "browser" like that. It would effectively have no scripting at all though, nor could it ever introduce new semantics that send data to another site, directly or transitively. You can do some stuff with that kind of system, but it's limited enough that most people don't choose it.
Gopher exists I guess? Lynx too, though lynx supports css, and that largely can't be allowed either.
The web should be fully declarative and permissions/capabilities based. If they can't do something that way, they shouldn't get to do it at all.
I'm not deeply familiar with it, but it's a similar "extremely minimal is best" approach, also in part for privacy reasons.
- People on HN.
Do you think otherwise?
B. Check if a link is visited.
Whether these two even remotely fall into the same category is left as an exercise for readers.
B. Provides bits of identifying information.
To me it seems they're in the exact same category.
Knowing the user's mouse position? Provides bits of identifying information.
Knowing which subdomain the user is visiting? Provides bits of identifying information.
Reading URL query string? Provides bits of identifying information.
If this is a category, it's a quite big one!
Maybe the ultimate conclusion is Javascript should not actually exist at all. The web should be declarative, not executable. Developers tell the browser what they want and the browser does it. If it can't be done that way, it isn't done.
Just like Chrome's Manifest V3 making extensions more declarative and limited. My only problem with it is the fact it cripples uBlock Origin. I actually do want those restrictions applied to 100% of all the other extensions, it's just that uBlock Origin is too important and trusted and should be an exception. Honestly, uBlock Origin should be literally built into the browsers at this point. The only reason we can't have that is the massive conflicts of interest involved: can't trust an advertising company to maintain an adblocker.
Road to hell is paved with good intentions. When you propose a law, you must also think about the numberless ways it could be abused and misused to cause harm. Same principle applies here. The code shouldn't just fail, it should fail in ways that prevent the developer from even knowing it failed much less why. Simply because that would leak information.
The best user agent is the one that offers them the fewest identifying bits. In other words, the user agent of the most popular version of Chrome. The ability to set it to "anything we want" is actually a trap. What we really want is for everyone to use the exact same user agent so they can't tell us apart.
If everyone has the same user agent, it's nothing but a waste of bandwidth and it should be removed. Google is actually achieving our objective here.
https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Re...
"Origin" means no path, so the referer might tell me which search engine the user used, but not what search query was done. It's much better than in the old days, where I might even see someone's session ID in the referer.
A lot of sites will break for people as a result, though. Maybe that's what The Google wants, though.
Yeah, it's even spelled wrong!
I would appreciate it if someone explain what other things people do to tackle this, or if I'm completely wrong?