Live data from Hacker News

Google no longer providing original URL in AMP for image search results

twitter.com

351–360 of 566 posts

Re: Google no longer providing original URL in AMP for image search results

#351
post #292

Earlier quoted context omitted.

Yes, as you say, Integrity is preserved. However, Confidentiality is also another important aspect of Information Security. Making a 3rd party appear as a 1st party, is a privacy and confidentiality violation, which is why I do not like AMP and signed exchanges.

Yeah, as near as I can tell signed exchanges are essentially a caching proxy. With integrity checks, so that you don't have to trust the proxy all that much and its agency is much reduced. I'm reminded of apt. The calculation appears to be that given the chance, some website controllers will choose to trade confidentiality of public pages for better load times. In business terms, this seems a pretty straightfoward wi…

The publishers are not mentioning to the visitor they are adding one more third party looking at your data; one that maintains an ad exchange and will be an intermediary on every resource request.

A publisher is free to switch to AMP, but choice needs to be given to the user to agree or leave the site the same way it happens with cookies. I wouldn’t opt in and now I cannot block Google tracking at the DNS level thanks to this.

Re: Google no longer providing original URL in AMP for image search results

#352
I can kind of understand why Google wants to do AMP. Mobile web performance and all. It probably scores better at some metric that someone believes passionately in (to the exclusion of all else). I don't think it's worthwhile overall, but I can understand it.

What I can't understand is why it has to be managed so badly. Just put the damn URL there for people who want it. Allow opt out for people who want that. Super easy.

Even if the plan is to cynically use leverage to railroad through adoption of AMP, you're not going to win over the people who despise AMP. There's nothing to be be gained by twisting arms like this. You're only making enemies. Just throw a bone to the people don't like AMP, and the rest of the people will go along with AMP anyway because they don't care.

Re: Google no longer providing original URL in AMP for image search results

#353

Earlier quoted context omitted.

> Google can choose today which site (original or AMP cache) to show in their search results. Today, as an end user, I know, via the URL, when I land on a Google AMP site. Ok why is this an issue? Note that HN is a bad place for this kind of socratic method discussion, we'll both quickly run out of the ability to post replies. Assume I'm someone who doesn't share whatever values you share about the purity of the url…

Because now every asset you download from the web is a Google tracking resource. Is it really unclear what’s going on? When you perform a GET request for these assets you are being monitored. These requests end up being part of the profile built for you which is used for advertisement targeting and content recommendation. PS: You work for Google. Do you work on this project?

> When you perform a GET request for these assets you are being monitored.

You'll only ever retrieve Google AMP cache results from the Google search page, where they were already able to track if you made such a request, since the link you clicked has trackers in it.

So from that perspective, nothing changes.

> PS: You work for Google. Do you work on this project?

No, I work on mostly internal infrastructure. My interest in AMP is simply that I don't dislike the AMP "experience", it's fine. But more importantly, I legitimately don't get the HN hysteria around AMP. Returning to your concern, literally nothing changes with AMP vs non-AMP.

I don't get it. The most compelling concern I've heard is that it's annoying to have to couple parts of your infra to AMP-standard stuff. And I sort of understand that. But even that isn't different than previous SEO/ranking changes that required changes to the page.

Re: Google no longer providing original URL in AMP for image search results

#354

Earlier quoted context omitted.

The worst thing I've seen recently is amp URLs for reddit threads. It's one bad thing (new reddit UI) wrapped in a worse thing (AMP), and getting back to classic reddit takes a lot of gymnastics. The stupid part is that the amp page is indistinguishable from the (new) reddit page (the AMP page comes complete with the "download our app" popup). So I don't see how it's providing any speed/experience benefit.

I can never get the Open In Reddit app button to work. I’m on iOS and have the latest version of the official reddit app. Which btw is painfully filled with ads.

Same here, it always sends me to the App Store. I already have the app installed.

Re: Google no longer providing original URL in AMP for image search results

#355

Earlier quoted context omitted.

> Google can choose today which site (original or AMP cache) to show in their search results. Today, as an end user, I know, via the URL, when I land on a Google AMP site. Ok why is this an issue? Note that HN is a bad place for this kind of socratic method discussion, we'll both quickly run out of the ability to post replies. Assume I'm someone who doesn't share whatever values you share about the purity of the url…

Because now every asset you download from the web is a Google tracking resource. Is it really unclear what’s going on? When you perform a GET request for these assets you are being monitored. These requests end up being part of the profile built for you which is used for advertisement targeting and content recommendation. PS: You work for Google. Do you work on this project?

DevKoala,

I don't think you may realize how much of your online activity is already tracked by google / facebook / instagram.

Google's javascript is everywhere, including explicit tracking with analytics, and lots of CDN loads for endless lists of things (js libraries, fonts etc).

Their properties also track you, google search, youtube, email. They also make software you might use (chome / android / google maps / google play store).

If you think something about signed exchanges let's google track you, and they can't now... please examine these assumptions.

Folks who come up with these super complex schemes (google will use javascript loaded into AMP to take over and track you) ignore that google ALREADY tracks them.

And folks who say they don't use any google products (no android / google maps/ play services / chrome etc etc) are often either lying or don't understand how many third parties load google analytics into websites, or load recaptcha bot protection etc.

Re: Google no longer providing original URL in AMP for image search results

#356

Earlier quoted context omitted.

This gets trotted out a lot, but who is "everyone"? At worst it's a bunch of random people in the cafe whose WiFi you're using - but these people don't have the resources to track your activity once you leave the cafe. Otherwise it's just the same rogue's gallery of large corporations interested in adtech/surveillance money: ISPs, device makers, other online service providers. The thing is, none of them have the reac…

> At worst it's a bunch of random people in the cafe whose WiFi you're using - but these people don't have the resources to track your activity once you leave the cafe. Depending on what you're doing, one-time collection may be enough. Also, many captive portals are provided to businesses by companies whose own business interest is in tracking people, and they'll absolutely correlate the data. Rather than having to w…

Isn't this just imparting a false sense of security? The one party who I'm most worried about getting my data, Google, will still get it.

I think you've still failed to answer my basic point - how is this not just a competitive moat that benefits Google? If we care about privacy and data collection, legislation is required because Google and Facebook have no reservations about sucking up everything they can. If it's ok for them to do it, why not $RANDOM_CANADIAN_ISP?

Re: Google no longer providing original URL in AMP for image search results

#357

Earlier quoted context omitted.

I don't think so. I personally don't use sites that don't have HTTPS. I don't have any interest whatsoever in making it easy for third parties to see my traffic.

I personally don't use sites that don't have HTTPS. Then you have chosen to exclude yourself from knowing a large chunk of interesting information that was posted on web sites before the web went fully corporate.

Another problem is that you can't even find those websites anymore. They're at the absolute bottom of search-engine rankings for whatever reason.

Re: Google no longer providing original URL in AMP for image search results

#358
It is a huge shame that the AMP AC seems to have completely dropped any work on the following focus card on their Github - https://github.com/ampproject/meta-ac/projects/1#card-194203...

Overwhelmingly that's the main user request for AMP. The lack of progress and the fact that it disappeared from the 2020 priorities with no progress speaks volumes.

Re: Google no longer providing original URL in AMP for image search results

#359
post #300

Earlier quoted context omitted.

Combined with that second thing I mentioned (required Google hosted JS), it is total control by Google with no straightforward way for me to detect it, block it or go around it, as I can today.

So if I understand correctly, your threat model is "Google will inject unwanted JS into a JS blob they host (like the amp.js from Google's CDN) and this will do nefarious (for some definition of nefarious) things to me without me knowing." How is this different than today, where many sites use js from google, either as a cdn or part of the ads infrastructure? I guess you can block some of those, but blocking the jque…

>>what kind of nefarious thing do you fear Google will do

Well, the headline is one good example. That google controlled JS is EXACTLY how they removed access to the original URL...on somebody else's page that isn't theirs. "Signed exchanges" doesn't fix that either. It's also how they hijack the back button and swipe events for carousel navigated pages.

Re: Google no longer providing original URL in AMP for image search results

#360

Earlier quoted context omitted.

> a net improvement for security that allows sites to put less trust in third-party servers and scripts. Third parties like Google, right?

Yes. Signed Exchanges mean the publisher signs the content using their private key. A third party can provide delivery like a CDN, but they cannot modify the content, or the signature would no longer match. The useragent (browser) enforces this. This gives the secure control of the content back to the publisher, unlike the trust model of CDNs or the AMP Cache.

> The useragent (browser) enforces this.

This assumes the user agent is actually an agent of the user, and not the AMP provider, which is demonstrably [1] not the case.

[1] https://github.com/w3ctag/design-reviews/issues/467#issuecom...

Post reply on HN