Live data from Hacker News

Chrome breaks the Web

tonsky.me

451–460 of 473 posts

Re: Chrome breaks the Web

#451

Earlier quoted context omitted.

> It's not protecting your interests, it's protecting Google's interests. But you can always install (or develop) another browser that might do this job better for you . > If it was protecting your interests, it would be a toggleable setting that defaults to normalized behavior. The problem with this view is that the vast majority of end users do not want, and in fact will never know about or use a new setting, and s…

> The problem with this view is that the vast majority of end users do not want I'm a user. I want that. I'm probably not "a majority" but I fail to see how being assimilated to the majority without my consent, without even knowing it is happening, is "protecting my interests" What would you think of a restaurant that charges you 50% of the bill as tip because "the majority of the customers does that"?

> What would you think of a restaurant that charges you 50% of the bill as tip because "the majority of the customers does that"?

I don't know about you but when I go to the restaurant, I can't change the price of the items. If they set the tip for you, that's pretty much setting the price, isn't it?

Re: Chrome breaks the Web

#452
post #188

Earlier quoted context omitted.

Chrome is a program that I run on my computer. It protects my interests, not the interests of random crappy website developers doing horrible things like hijacking clipboard events. I'm all for the defaults being whatever is best for me. The browser is the agent of the user.

In this case, the browser is the agent of those advertising to the user. It's not protecting your interests, it's protecting Google's interests. If it was protecting your interests, it would be a toggleable setting that defaults to normalized behavior.

I don't really use that auto filling thing that much but the few time I did, Chrome asked me if I wanted to use it on that website. Isn't that what you consider a toggleable setting? I chose to use autofill my user account information on that website.

Re: Chrome breaks the Web

#453
post #415

Earlier quoted context omitted.

That's certainly one view of the world. Come work tech support for a company/product with a web-based form that has a password field in it (like a CRM or other administrative system). Now explain to users why we can't stop their browser filling in their password in the field that's asking for the other user's password. I've had situations where I'm configuring a VPN connection on the web interface for a router... the…

I suppose you could tell them to go back to a previous version of the browser. Of course that would be a terrible idea for a number of other reasons, but if enough people specifically avoid more recent versions of Chrome for this reason, maybe Google will finally do what's actually best for users and make this behaviour configurable.

> I suppose you could tell them to go back to a previous version of the browser.

No, you can't do that.

Instead you have to tell them to stop saving passwords in the browser.

Re: Chrome breaks the Web

#454
post #149

Earlier quoted context omitted.

Most of those are rebranded chromium. The only big ones that are independent are Safari (since Google forked Webkit to create Blink), Firefox, and IE/Edge. And the impression i have is that Safari is lagging, Mozilla is directionless and struggling to keep Firefox relevant, and MS is, well, MS. Ever since Opera folded and made their browser a Chromium clone, only Mozilla have been carrying the banner for standard cor…

Quantum is a great improvement to Firefox. I'm running 57.0b14 ATM (normally I'm quite conservative with anything except Emacs) and quite pleased. The performance improvements are quite noticable. Though I do wish they created a more user-extensible browser, a bit a la Emacs.

> Though I do wish they created a more user-extensible browser, a bit a la Emacs.

That's what Firefox used to be, and one of the main things that got it to where it is now. But 57 is also the one that drops that flexibility with removal of the XUL.

Supposedly there'll be new API calls for WebExtension-converted add-ons, but it seems to be really slow going. Between this and the Electrolysis update that also broke a lot of add-ons, I've seen a few get abandoned by their devs, who are fed up with Mozilla breaking what works.

Re: Chrome breaks the Web

#455

Earlier quoted context omitted.

> Regulatory compliance. > there are plenty of regulations in certain setting that require us to disallow client applications from auto-filling form fields. And which regulations would those be, specifically?

If I recall in Part 11 compliance (which is how the FDA regulates software in the US) one is required to ensure that "Passwords are not remembered by [browsers] and applications." From an ISO/IEC/IEEE 29148 perspective the language might be "shall not remember passwords" which would imply a legally binding requirement for compliance purposes. This doesn't preclude applications from using autocomplete on form entry fr…

If you want the browser to conform, you do control the browser. It isn't hard to set it up so it doesn't do autocomplete.

Re: Chrome breaks the Web

#456
post #292

Earlier quoted context omitted.

Maybe that's the key, and why they don't care. I tend to stay away from that kind of service though.

I was a little skeptical too but it seems to be encrypted locally before going anywhere, so it seems like it's alright to use. Anyway, if the deletion's compromising security as much as you say it might be an acceptable trade-off.

Fortunately firefox also keeps them, so that's my workaround.

Re: Chrome breaks the Web

#457
post #443

Earlier quoted context omitted.

Disabling autofill seems like the wrong way to handle the problem, though. Autofill does not necessarily mean that passwords are being shared; it just means that the user isn't typing them in. Strong policies on the machines in question and ensuring that users aren't sharing each others environments seems like a considerably more complete solution to me. This can be facilitated by tools like https://www.imprivata.com…

While I agree that autofill on its own is not a complete solution to GP's scenario, it's certainly a potential point-of-failure, and I understand their need to eliminate as much risk as possible. While the most significant aspect to be improved is the security habits of the clients themselves, that doesn't mean that GP and their company should be prevented from doing what little they can just because Google wanted th…

That's why there are profiles. Even in Chrome. But too in Windows.

Or that's why then the SysAdmin should disable the password manager.

It's not up to the website.

If you have an internal site, you already control the browser, then why do you want to fight the browser from the inside instead of from the outside? :o

Re: Chrome breaks the Web

#459

Earlier quoted context omitted.

While I dislike this behavior of chrome, you should never be able to set a users password.

It is arrogant to assume this is true of every single use case.

I really can't think of a scenario where the end-user not being in full control of their credentials is good.

Are there situations in which it is easier if the admin can just reset it, sure. Is that a good idea, no.

Post reply on HN