Live data from Hacker News

Edge sends full URLs of pages visited to Microsoft

twitter.com

81–90 of 161 posts

Re: Edge sends full URLs of pages visited to Microsoft

#81

Earlier quoted context omitted.

no, it's likely you're either on a mobile device or your cookies are set so that it's redirecting you to it. the non-mobile version works fine and is clearly different.

Not anymore, that’s the new layout.

I still see the old (superior) layout when I use an incognito window, so I guess the new version is being tested or rolled out gradually.

Re: Edge sends full URLs of pages visited to Microsoft

#83

Eric Lawrence (PM on Edge, previously on Chrome, previously author of fiddler) showing screenshots of documentation that explains all that, and saying it's been documented this way for 14 years: https://twitter.com/ericlaw/status/1152933704198758401

...and for 14 years no ordinary user has understood what those default settings do, instead assuming “their software provider wouldn’t do that...”

Re: Edge sends full URLs of pages visited to Microsoft

#84
post #45

Earlier quoted context omitted.

Not if there's an other layer of verification locally. Then you can allow a few false positives with the hash on the remote and they'll get discarded when the full hash is compared locally. That being said 32bits of information seems like quite a lot and can probably used to match the original URL fairly accurately.

You also need to consider the greater context. Suppose my history shows I sent a hash that could be one of 100 different known URLs. One of them is about model airplanes, but there is no way to know I picked that one. Chance I like model airplanes? All else being equal.. call it 1% But what if over the next hour I continue to send hashes with random subject matter sets that include model airplanes each time. Suppose…

You skipped a factor, in Safe Browsing Update API (the mode actual web browsers like Firefox use) that step where you send a 4 byte prefix only happens when the prefix already matched a local hotlist.

So if you visit 100 URLs in an hour, and using the local hotlist allows your browser to discard all but 1 of those URLs as definitely not bad, that's only one URL prefix checked against Google, not 100 so there's no triangulation.

And the actual number isn't 1-in-100, that's why they picked 4 byte prefixes. I haven't actually checked, but by eyeball from playing with this data for work I would guess 1-in-a-million.

So, you visit 100 URLs about model planes, one of them happens to be a 1-in-a-million match to a possible badware site, your browser sends the 4-byte hash prefix to Google, it gives back the 4-byte prefix of the badware site it was worried about which is different, your browser goes "Phew, good" and nothing happens.

There's just not really an opportunity for tracking here.

Re: Edge sends full URLs of pages visited to Microsoft

#86

Edge is the number one browser in the world for installing chrome.

Chrome is the number one browser in the world for installing Firefox.

Is it? Have that many people been switching that they outnumber users installing it on their new machines?

Re: Edge sends full URLs of pages visited to Microsoft

#87

Eric Lawrence (PM on Edge, previously on Chrome, previously author of fiddler) showing screenshots of documentation that explains all that, and saying it's been documented this way for 14 years: https://twitter.com/ericlaw/status/1152933704198758401

...and for 14 years no ordinary user has understood what those default settings do, instead assuming “their software provider wouldn’t do that...”

I think you're making a big assumption that ordinary users care if Microsoft knows what URLs they visit--how many of them use blockers or another technology to opt out of e.g. Facebook tracking?

Re: Edge sends full URLs of pages visited to Microsoft

#88
post #16

Every time I see people on HN campaigning for Microsoft as some kind of reformed tech company that has seen the errors of its past and turned into a force for good, something like this comes up. Same old Microsoft. Second verse same as the first.

Not sure if it's bought or organic, but no other company gets the response Microsoft gets. The smallest triviality get praised, the biggest flaws get rationalized away. Like, people here were going wild when they added UNIX line-ending support to notepad.

They employ a lot of people directly, and a lot of people are employed in their ecosystem. I'd deny that this is exclusively for MS, though. Every large company has an army of employees that come in to explain how things actually are. On HN, this happens just as often for every medium-sized company; the only companies who absolutely get bulldozed when they do something worth getting bulldozed for are tiny, because their defenses just get shouted down by the employees of competitors.

Re: Edge sends full URLs of pages visited to Microsoft

#89

Every time I see people on HN campaigning for Microsoft as some kind of reformed tech company that has seen the errors of its past and turned into a force for good, something like this comes up. Same old Microsoft. Second verse same as the first.

This is "the same verse" as what? Bundling IE with Windows? The same as making proprietary technologies on open ones? The same as strongarming Gary Kildall? No, no it isn't "the same". Anti M$ comment is just whiny. This behaviour is part of SmartScreen, it's publicly known about, documented, optional. It's explicitly called out somewhere - when you install a new Windows 10 and it takes you through the privacy settin…

It's so weird to come in with a defense of "this is no worse than this long list of horrible things other companies have done, and other horrible things this company has done before!"

I completely agree with you, this is no worse than many of those things.

Re: Edge sends full URLs of pages visited to Microsoft

#90
post #87

Earlier quoted context omitted.

...and for 14 years no ordinary user has understood what those default settings do, instead assuming “their software provider wouldn’t do that...”

I think you're making a big assumption that ordinary users care if Microsoft knows what URLs they visit--how many of them use blockers or another technology to opt out of e.g. Facebook tracking?

Agreed, the average user simply does not care about privacy to that degree. FaceApp is yet another example. On the bright side, most of the tools we need to "cover up" are available to us. You can't ask for more than freedom of choice, I suppose.
Post reply on HN