HTTP "Prefer:Safe" – Making Online Safety Simpler in Firefox
blog.mozilla.org
blog.mozilla.org
I mean I fail to understand the original idea, obviously. It makes no sense to me. But I question the value of the above - basically now the server can _just as easily_ do crap with that information. You can now identify minors (using that feature). Beautiful.
The server operators cannot decide what 'parental control' would mean for parents, they cannot decide what is ~okay~ or what isn't. Referencing a random US regulation/law (COPPA?) in a discussion about international traffic, international browser products seems crazy.
If you want to prevent your kids from accessing 'stuff', make sure that 'stuff' is filtered on their machine or better on the edge of your network. Don't believe that random guys on the net will correctly guess what you find questionable content for kids and hide it, because .. your kid's browser sent a friendly "My parents didn't allow me to see unspecified things" header.
Edit: I reread that thing over and over again. Something else that utterly blows my mind is this:
Users won’t find any UI in Firefox to enable or disable Prefer:Safe, which becomes one less thing for kids to try to circumvent to disable this control.
Newsflash: That includes the parents. Unless that is utterly misleading (or my English as a second language parser fails) this means that I, as a parent [1], can NOT
- activate parental control features that are somehow detected by Fx
- opt out of that idiotic header that announces decisions from my private household to each and every server, starting with Google for example
1: Hypothetical example. While I've got two kids, but both are too young to operate a computer yet and I probably won't buy into standard 'parental control' solutions anyway.
There are as many definitions of "what is appropriate for kids to see" as there are parents.
The decision belongs with the parents, not with the 3rd party sites who, let's not forget, are the ones supplying the content in the first place.
This just seems like an utterly naive and vague idea.
It's totally unrelated but something I would really like to have right now would be a header with the average connection bandwidth (or just thresholds). This could be really useful to reduce the amount of data sent if the connection is really bad.
It's not useless, since it allows the site to avoid being blocked by hiding the "bad" content. Ideally blockers would be smart enough to recognize and block only the "bad" DOM elements, but they usually just block the whole page, if not the whole site.
Given that, I see these possible outcomes
- the client's admin might not care about this site at all (effort to hide stuff would be wasted?)
- the client's admin might consider content 'unsafe' that seems fine/okay to the site operator => Blocklist, failed to archive what you suggest
- the client's admin might consider content 'safe' that the site now refuses to share => Curse site and Mozilla, switch browsers and/or consider that site broken and the operators morons (similar to 'breaks zoom on mobile devices' today, for example)
That said, I think the implementation should have an admin-controlled site whitelist and even a way to disable the header even if parental controls are enabled, to prevent (3).
http://en.wikipedia.org/wiki/Motion_picture_rating_system
However, this got me thinking that across cultural lines there are a lot of shades to what is "safe". So a website based in Austria might want to restrict different content than a website based in Australia, and who knows where the "browser" is based.
Of course your comments about the site actually implementing anything/correctly still apply.
There is no UI in Firefox because Firefox uses the operating systems parental control features to enable/disable it. And those features should have a UI within the system. That's why it is only implemented for OS X and Windows at the moment.
Parental control in Windows just lets me set time limits/limits on what programs/games I can run as far as I know (just double checked microsoft.com and that's what they list as well). Given that and my understanding of the Fx feature means that Fx understands that this is a machine with parental controls enabled and _shares that with the world_.
That is nonsense. It's crap. The world cannot (as I stated before) decide what is okay and what not. Going with your porn example (I .. kinda expected that): I'd be entirely fine with a 16yo kid to look at porn. I might not want that very same kid to use the computer around 2am in the night. For the latter I can use parental control features. You (and Mozilla) force your (weird, from this pov) moral/set of values on me. Enabling parental control does NOT mean that I want the world to know about it. It also doesn't imply that porn isn't okay. On the other hand, maybe I would put the NRA website on the list of things I don't want to see in my household. No one can decide what is okay or not - except for the parent/admin.
"There is no UI in Firefox, because Firefox uses the OS parental control features to enable/disable it" is missing the point. Unless I fail to understand what this does I cannot use the parental controls without Firefox/Mozilla abusing that flag and asking the YouPorn administrators for parental support.
This is a misfeature and at best useless, although I'd lean towards harmful and wrong.
If you want to block specific websites or specific content then you obviously need to use a different tool as well.
If you look at the code [1], you'll notice that it exists _today_. There is no feature in Windows that says 'I want to restrict this account to a "safe" internet experience' and that wouldn't make a tiny bit of sense as I expressed elsewhere. Again, if you look at the code it seems (Disclaimer: I'm neither familiar with the Fx codebase nor really a C++ guy) easy enough:
DWORD settings = 0;
wpcs->GetRestrictions(&settings);
if (settings) { // WPCFLAG_NO_RESTRICTION = 0
gAdvAPIDLLInst = ::LoadLibrary("Advapi32.dll");
if(gAdvAPIDLLInst)
{
gEventWrite = (decltype(EventWrite)*)GetProcAddress(gAdvAPIDLLInst, "EventWrite");
gEventRegister = (decltype(EventRegister)*) GetProcAddress(gAdvAPIDLLInst, "EventRegister");
gEventUnregister = (decltype(EventUnregister)*) GetProcAddress(gAdvAPIDLLInst, "EventUnregister");
}
mEnabled = true;
}
While I admit that I argued based on 'assumptions' (more .. based on what I know about these parental controls and what the article states), these are the facts.If I translate that into prose (correct me..) that reads as "If the OS supports parental controls and ANY restrictions are active, then set this boolean flag to true". Now, before you argue that these still are just assumptions about how this flag is used ... let me present [2]:
// add the "Send Hint" header
if (mSafeHintEnabled || mParentalControlEnabled) {
rv = request->SetHeader(nsHttp::Prefer, NS_LITERAL_CSTRING("safe"));
if (NS_FAILED(rv)) return rv;
}
Ignoring the weird comment: That translates into "If the user _opts in_ to use this header via a setting OR if we detected random parental control restrictions from [1], add the crappy header to the request"The documentation of the Windows parental control API can be found here [3]. Note that there isn't a feature that says 'add a random useless header' or somesuch nonsense. Glancing over the docs it seems to be possible to register extensions to the parental control environment, and _those_ might offer a 'Get a random different version of the internet, maybe' option in theory. But that doesn't seem to be the case and the check at [1] and [2] seems rather broad.
IF this whole thing would be a configurable (by the responsible admin) feature (and .. ideally opt-in, not a crazy default), THEN I'd just laugh at the people that want that, but wouldn't complain. Based on every fact I can get my hands on that is NOT what they do.
Do you still disagree, at least with the implementation?
1: http://mxr.mozilla.org/mozilla-central/source/toolkit/compon...
2: http://mxr.mozilla.org/mozilla-central/source/netwerk/protoc...
3: http://msdn.microsoft.com/en-us/library/windows/desktop/ms71...
"Prefer:Safe" is rather vague-sounding. I was expecting something about incorporating something like "HTTPS Everywhere" into Firefox.
I understand the appeal of something to prevent kids from stumbling across porn or violence online, but let's not muddy words like "trust" (which mean something very different when talking about security and privacy) with the concept of age-appropriate content.
I do agree "prefer safe" is a very poor way of expressing that desire, though. Maybe "child-safe", but not just "safe", which implies a related but different idea.
"Cool, an under-10 browsing. Let's push all the autoplay toy videos we have in rotation."
I already get the creeps from the toy ads squeezed between and in the middle of children's TV shows.
"parental-control:enabled" header would make more sense, right?
Seriously though, this seems totally reasonable although "safe" does seem like an odd word choice. Maybe "modest" instead?
But yeah, I expected a HTTP header that would, say, redirect to an encrypted version of the webpage, sort of like HTTPS Everywhere, but on the browser-server level.
If I stumble upon pictures of tits because someone posted a link to a yellow press newspaper site or a random celebrity scandal, I .. misclicked because that wouldn't interest me in the slightest. But it wouldn't be unsafe, not even for work. On the other hand, I wouldn't exactly want to end up on a nazi propaganda page (even if I'm merely looking at current splitter groups/facts around news reports about these sort of braindead idiots). I would feel very bad about leaving a trace like that - even if I don't think I'd have to face any sort of consequences.
Point being: Safe™ is undefined, for minors or employers. You can try to find a GCD, a common global set - and you'll fail/end up with a balance act between false positives and misses.
In other news, the Feynman lectures on QED are blocked in "safe" mode. https://www.youtube.com/watch?v=yvl6TBGEoO0
"don't show me information about cookie usage".. )
Do it badly -> annoy users -> no more laws that protect users.
That's good, make them hackers instead by making them implement their own HTTP-proxy :)
- Disable signup/require COPPA form to be mailed & signed
- Filter out explicit content from user-generated content
- Disable vulgar sections from a blog
- Prohibit downloading software
etc
Somewhat off topic, but I think 13 is considerably above the age where kids have a reasonable interest in being able to actually use the web. When I was a few years younger than 13 (10 years ago...), I once accidentally put my true birthday into AIM, and was subsequently banned from the service I used to communicate with friends from school. Recently, the same happened with one of my sister's friends and Gmail. Does anyone actually think these forms are a good thing?
Any reasonably educated child can easily disable all of these "safety features" (e.g. boot the machine at night from USB stick...). These "features" are nothing but placebos for parents too incompetent to educate their children.
Spec makes no mention of age groups this is supposed to be used for aside from "children".
Although I'd recommend being a responsible admin/parent in that case instead and, with the _correct_ infrastructure for this scenario already in place, define filters for things you don't like or white lists for things that are okay for your network, instead of begging the internet to correctly guess your moral boundaries.
Is this intended for the publisher to implement filtering, or for the publisher to declare semantic labels which can be filtered by 3rd-party sites with consistent editoral viewpoints?
1) Javascript breaks stateless linking.
2) Mobile versions and browser detection breaks stateless linking.
3) Censorship headers like Prefer:Safe, and censorship in general, breaks stateless linking.
And the list goes on. Some state and inability to link is inevitable, but this is not.
Mozilla: please get back on track for a strong/stateless and cite-able web. Headers are not the place to build a censorship "UX."
Also, "safety"? That's not helping. Almost no one uses NetNanny, or similar software and, while I'd like to think we've grown as a species, even if we haven't, it doesn't make sense to force something most Web surfers have already rejected back down their throats. (And it is forcing them, even if it's optional. The social implications of even "optional" headers will be with us for a very long time.)
A browser especially should strive to be neutral, unless you want to start getting requests from governments and industry to block sites directly in the browser. Google handles a million or more every day and they are just and index list... You can't expect a different fate without discarding neutrality as a core principal.
Cite-ability requires availability, and censorship - the Web-equivalent of a frontal lobotomy - contradicts the very essence of your product. I'm starting to feel ashamed to be using a browser made by an organization that doesn't understand that.
A small example, I am French living abroad, if I want my kids to read a bit the news, I cannot send them on one of the 3 "major" French newspaper to read a bit. Why? Because at the bottom of the first page, they put a lot of sexual content like fully naked women wresting. If this header could remove such content, together with videos where people are beheaded. I would be pleased. Really.
If you start to think that this is censoring content, it is not, it is journalist work, that is, providing adapted content to the visitor.
Which one were you referring to again?
I posted an example elsewhere in this thread: I might want to limit a 16yo with parental controls to avoid having them use the computer the whole night, but I wouldn't mind them seeing (naked) girls on a yellow press site, if that's what they stumble upon.
I'm also reasonably sure that your particular problem could already be solved on the client site, today, and that would even make sure that your personal take on moral values is respected. Plus, as others have stated, 'parental' controls might be used for a "kiosk mode" in a hotel or elsewhere (for .. whatever reason). Would you really want these scenarios to result in the same thing ("Content filtered on a news site"), both for your personal kids and for random mature people elsewhere?
"Yet"? You mean, everyone will eventually have children, and only people who have children can discuss such things?
Surely there's an option in about:config that affects the new behavior? Is about:config disabled too?
There are also dozens of add-ons that lets you control every single header. Are add-ons disabled too, or is there going to be a blacklist of header-modifying add-ons?
It will take less than a week for point-and-click circumvention tools to become available all over the place. Just download this little .EXE that makes a small change to your Firefox profile and might or might not also contain malware! Should Google block searches like "how to disable Prefer:Safe" if such searches come from a browser that already has "Prefer:Safe" enabled?
This is supposed be activated by Windows Parental Controls, which already allow you to block the user from running unknown .exe files.
Why not? Porn sites aren't interested in appearing to kids, which are unlikely to pay for their stay.
The field value MAY be preceded by any amount of LWS, though a single SP is preferred.
For the definition of SP and LWS, see: http://www.w3.org/Protocols/rfc2616/rfc2616-sec2.html#sec2.2
For the definition of MAY, see: https://www.ietf.org/rfc/rfc2119.txt