Live data from Hacker News

Google Removed ClearURLs Extension from Chrome Web Store

github.com

221–230 of 369 posts

Re: Google Removed ClearURLs Extension from Chrome Web Store

#221
post #209

Earlier quoted context omitted.

My web site has no comments or other user-generated content, runs no CMS, uses no cookies, collects no data except standard web server logs, hosts no executables, and has no secret nor security sensitive content.

At Starbucks I can inject arbitrary content into the browser of anyone who visits your site over HTTP and take control of their browser. Furthermore, congrats on your site but you’re 0.01% of sites like that. Should we keep an insecure web because your hosting provider is ripping you off? TLS is easy and free in 2021.

So what. We’ve all done this stuff and it’s fun for like 5 minutes.

It’s been possible for decades and doesn’t end up being a common problem. And even if it was the risk is just crap injected into someone’s blog.

Re: Google Removed ClearURLs Extension from Chrome Web Store

#222
post #209

Earlier quoted context omitted.

My web site has no comments or other user-generated content, runs no CMS, uses no cookies, collects no data except standard web server logs, hosts no executables, and has no secret nor security sensitive content.

At Starbucks I can inject arbitrary content into the browser of anyone who visits your site over HTTP and take control of their browser. Furthermore, congrats on your site but you’re 0.01% of sites like that. Should we keep an insecure web because your hosting provider is ripping you off? TLS is easy and free in 2021.

I don't like when Google, or anyone at all really, tries to globally police the internets.

It's up to web site owners to decide whether to implement encryption, and up to users to decide whether to use these web sites or not.

Re: Google Removed ClearURLs Extension from Chrome Web Store

#223
post #201
post #58

Earlier quoted context omitted.

I tried, but I find each and every Google Search alternative lacking. I frequently have to hunt down some bug descriptions or other stuff related to coding and Google Search is really hard to beat. Even tried Bing, lol

If alternatives to Google were better than Google, we wouldn’t have to tell people to use them. The whole point is to use alternatives even though they are not as good , because to aid Google is not acceptable.

In my experience, ddg is often better, but many people have a hard time changing their entrenched habits.

Re: Google Removed ClearURLs Extension from Chrome Web Store

#224

Earlier quoted context omitted.

We need a regulation that will automatically deal with such monopolies by ordering companies to split after reaching certain thresholds. This way we would never get companies too big to fail.

Then what is the incentive to start a company, grow it within the legal and regulatory framework and when it gets to an arbitrary, non-defined size have the legal and regulatory bodies systematically dismantle it by forcing you to sell it off?

The ability to walk away with enough money to fund multiple lifetimes of obscene gluttony long before that point?

Re: Google Removed ClearURLs Extension from Chrome Web Store

#225

What I don't get is why Google is allowed to provide a browser and be a major content provider at the same time. If this is allowed to continue then it seems inevitable than an unhealthy monopoly will form where Chrome and its derivatives are the only browsers that can consume the modern web, and where opting out of tracking is not a possibility for anyone but the most technically inclined (although that's almost alr…

I don't understand this logic. You can use the same argument against any Vertical integration.

Re: Google Removed ClearURLs Extension from Chrome Web Store

#227
post #53

Earlier quoted context omitted.

I thought the accepted solution to these problems was "disrupt!", not regulation. Edit: It seems that not even Silicon Valley likes the monsters it has created.

The general solution is to do a little of both. The job of the regulators isn't to just kill off specific companies that got too powerful - it's to create conditions where disruption is possible. An important way to do this is to prevent big players from abusing their power to make themselves nearly-impossible to disrupt.

> The job of the regulators isn't to just kill off specific companies that got too powerful - it's to create conditions where disruption is possible.

Broadly speaking, the big regulations tend to create conditions where disruption is harder. Regulatory compliance is often a substantial investment, and a rather big one, thus a barrier to entry; it's a lot easier for big, profitable Google to hire a team of regulatory compliance officers and GDPR architects and the like than it is for a small startup.

Re: Google Removed ClearURLs Extension from Chrome Web Store

#228

Earlier quoted context omitted.

I don't disagree with what you're saying, but I feel HTTPS everywhere does not belong in that list. Secure by default doesn't sound evil to me, and Let's Encrypt made it easy enough to get free HTTPS certificates (and for non technical people, almost all hosting services I've seen offer it out of the box)

A static blog that takes no user input/data doesn't need HTTPS. Here's a good lecture about why HTTPS everywhere isn't as important as people think. http://n-gate.com/software/2017/07/12/0/

A static blog that takes no user input/data will still leak the pages on that blog you visit, and the times you visited them. Knowing that you went to a particular page on a particular blog is a lot more information than knowing if you went to a domain. If I know you read about Conan the Barbarian on three different blogs, I know to send you ads about Conan the Barbarian (as a trivial example.)

Re: Google Removed ClearURLs Extension from Chrome Web Store

#229
post #204

Earlier quoted context omitted.

Without encryption active attacker could redirect users to different website, which would collect more data than your website does normally. They could also inject ads and javascript into users' sessions through your website.

If an active attacker has sufficient motivation, hacking user's computer is way more profitable than messing with their home router in the middle.

Redirecting an unencrypted webpage could be the first step a hacker uses to take over a user's computer. It's best to minimize attack vectors as much as possible

Re: Google Removed ClearURLs Extension from Chrome Web Store

#230
post #168

Earlier quoted context omitted.

If it is for AWS resources it is not equivalent.

AWS don’t owe non AWS customers free certificates, though. It is possible to host LetsEncrypt alternatives, though. The viability is another matter, though.

LetsEncrypt doesn't owe anyone free certificates, either. The point is that AWS isn't an alternative unless you're spending money with AWS. Nobody is wondering whether you can get a certificate by paying someone.
Post reply on HN