Live data from Hacker News

Never connect to ProtonMail using Chrome

old.reddit.com

31–40 of 289 posts

Re: Never connect to ProtonMail using Chrome

#31
post #24

Earlier quoted context omitted.

It sorta is, via ad targeting.

No it isn't. It's the difference between "Here's some money, please show this to young Democrats" and "Here's some money, please give me a list of young Democrats." That's a pretty damn big difference.

Right. Google does the first, Facebook did the second

Re: Never connect to ProtonMail using Chrome

#32

Earlier quoted context omitted.

"It's a sign that web standards are getting too complicated." Is there precedent for standards significantly simplifying over time, or do they always tend to get more and more complex?

What frequently happens is that a simplified alternative appears. HTML5 rather than XHTML, Markdown vs. HTML or LaTeX, HTML, originally, vs. SGML or Sun's ... proprietary hypertext system (Vue?). Arguably, replacement of much office suite software with Web technologies. Multics -> Unix.

Moreover, we have gone from Microsoft pushing complexities to Google.

Like the latest two HTTP protocols are both based of tech that google has already made. However, IETF is like that sounds good. It's got it's advantages, but there is very little push back saying well that makes things more complicated.

For instance with HTTP/2 it has support for pushing files to the client. Most back end web stacks are still trying to think of good ways to make that easy to use. Mainly since what files to send depend on what the page contains. So either you have to specify a custom list or the web-server now needs to understand HTML to get a list of required resources. This also gets more complicated since a push will be useless if the resource is already cached. This means your webserver has to have some kinda of awareness of how clients will cache data. Again this starts to mean your web server needs more client knowledge.

This is does not even take into account how the browser should handle these things.

Additionally, while cryptography is a good thing, the standard for HTTP/2 does not require it. However, pretty much all the browsers ignore that un-encrypted HTTP/2 is allowed. So if you wanted to run HTTP/2 without TLS the browsers act like site does not exist. This gets into the problem since there are so few browsers they can basically make defacto standards. So if you went through the effort and followed the standards what you encounter may not follow those standards at all.

Re: Never connect to ProtonMail using Chrome

#33
post #24

Earlier quoted context omitted.

It sorta is, via ad targeting.

No it isn't. It's the difference between "Here's some money, please show this to young Democrats" and "Here's some money, please give me a list of young Democrats." That's a pretty damn big difference.

> That's a pretty damn big difference.

There's certainly a difference. I'm not sure it's a very big one though.

The latter is an extra problem in a few specific areas:

1. your foremost fear is a bad actor getting your private details (e.g. identity fraud / doxing). These are legitimate fears, but certainly not a primary likelihood in the majority of cases.

2. discrimination based on background checks (jobs/loans/etc.). Also completely legitimate, though background checks tend to be plenty invasive in isolation these days anyway, so I'm not sure how much of a negative impact Google's data would potentially add here.

Other than these specific threats, the two seem exactly equivalent for most reasons people are concerned about privacy.

Re: Never connect to ProtonMail using Chrome

#35
post #24

Earlier quoted context omitted.

No it isn't. It's the difference between "Here's some money, please show this to young Democrats" and "Here's some money, please give me a list of young Democrats." That's a pretty damn big difference.

> That's a pretty damn big difference. There's certainly a difference. I'm not sure it's a very big one though. The latter is an extra problem in a few specific areas: 1. your foremost fear is a bad actor getting your private details (e.g. identity fraud / doxing). These are legitimate fears, but certainly not a primary likelihood in the majority of cases. 2. discrimination based on background checks (jobs/loans/etc.…

Can you name some of those reasons? Because they seem very non-equivalent for almost any reason I can think of.

Re: Never connect to ProtonMail using Chrome

#36

This is a really awesome project: https://github.com/Eloston/ungoogled-chromium I've really tried to use Firefox... Chrome just runs so much smoother, especially for media.

Vivaldi is a nice de-Googled project, a Chromium fork with all (?) Chrome plugins working on it.

Re: Never connect to ProtonMail using Chrome

#38
post #5

Earlier quoted context omitted.

I have been using Firefox since version 1.0. I don't understand the desire to use google's browser. However, why would even trying view secure data in your web-browser... Not even just Chrome. Things may get cached ect... Although, Mozilla has been doing things that I find annoying at times. Like adding pocket ect... Little Rant Although, I have looked at some of the other forks. What I find more depressing is how fe…

Maybe over-complicating things is a way of eliminating competition from Google. If it wasn't so complicated, someone could easily offer a competing, privacy-oriented browser; which Google would not like-- so make it so hideously complex no one can do it without $50 mil? There would be more innovation if things were simple, because anyone with a good idea could contribute.

Precisely that has been observed across many markets. Teachers unions being an example where adding on requirements to entry enshrine current members.

Re: Never connect to ProtonMail using Chrome

#39
post #24

Earlier quoted context omitted.

No it isn't. It's the difference between "Here's some money, please show this to young Democrats" and "Here's some money, please give me a list of young Democrats." That's a pretty damn big difference.

Right. Google does the first, Facebook did the second

If you're referring to Cambridge Analytica with your Facebook example, Google have provided APIs for 3rd-parties to access private user data for many of it's services, just as Facebook did with Cambridge Analytica. For example, the G Suite Marketplace lets many companies read all of your emails.

Both require an auth consent screen with permissions listed, where it may or may not be clear to the user what's being shared.

Re: Never connect to ProtonMail using Chrome

#40
post #19
post #6

This reminds me that I have private email threads with JoshMnem regarding my essay/overview.

You've been doing this for months and months and we already asked you to stop, so we've banned the account. We'd like to unban you, so please email hn@ycombinator.com and let us know that you'll stop with the essay!

[deleted]
Post reply on HN