Live data from Hacker News

RFC 35140: HTTP Do-Not-Stab (2023)

5snb.club

151–160 of 219 posts

Re: RFC 35140: HTTP Do-Not-Stab (2023)

#151
post #141

It’s great satire, but it really does mirror a larger societal shift where the burden of safeguarding personal autonomy has shifted from institutions/regulators to individual users. Do-Not-Stab, Do-Not-Track, whatever it might be, any sort of “voluntary compliance” is a non-starter in the face of financial pressures IMO we need to start normalizing being militant about this stuff again, to aggressively and adversaria…

It's amusing to see this message heavily upvoted on HN when most mentions of Firefox here are welcomed with an avalanche of perfect solution fallacies. I'm dubious about people becoming militant about this when the software engineering industry gave Chrome a red carpet by using it and installing it on their relatives' computers while knowing very well it's adware and when switching to the alternative is incredibly ch…

Chrome had the advantage for a long term because their dev tools were just so much better than Firebug in both features and performance. Even today, I can't pinpoint it to specific things because it's (relatively) little and subtle differences, but Chrome's dev tools feel way more polished than Firefox's.

It's almost as if Steve Ballmer and the legendary "developers developers developers" speech still rings true today - the key to getting people to use your software is to make life as easy for the power users as possible, let them spread the word. And it's ironic how Microsoft lost its ways there... a lot of people I know have gone from Windows to Mac and convinced their close relationships (aka those whose computers they fix) to do the same. It's just so much more relaxing to boot into an OS that doesn't try to shove advertising down your throat at every turn.

Re: RFC 35140: HTTP Do-Not-Stab (2023)

#152
post #124

It’s great satire, but it really does mirror a larger societal shift where the burden of safeguarding personal autonomy has shifted from institutions/regulators to individual users. Do-Not-Stab, Do-Not-Track, whatever it might be, any sort of “voluntary compliance” is a non-starter in the face of financial pressures IMO we need to start normalizing being militant about this stuff again, to aggressively and adversaria…

> IMO we need to start normalizing being militant about this stuff again, to aggressively and adversarially defend the freedom to use your computer the way you choose to use it Yes. As a millennial the times of civil disobedience was better. Not only did we get a better internet for consumers, but better companies were rewarded and won. Rose tinted glasses? Possibly, but there’s another reason for disobedience: the o…

Use ublock origin with the "Cookie notices" custom lists. Not explicitely accepting cookies is legally the same as refusing them (now, whether websites actually respect that is the opening keynote of the Naiveté conference)

Re: RFC 35140: HTTP Do-Not-Stab (2023)

#153

It's important to note that the Do-Not-Stab header has been deprecated because one browser engine switched it on by default and requiring users to opt into stabbing hurt the bottom line of the stabbing industry, so it's no longer respected. Luckily someone came up with General Assault Control, a non-standard alternative, which also only has one value, so you can set Sec-GAC to 1 to request websites not to assault you…

It's now customary, in order to comply with European regulations, to present users with a list of possible violent crimes against their person that they can opt out of before using a website. This ensures that non-consent to stabbing is always an active choice, so that users who want to be stabbed or otherwise maimed won't accidentally miss out on the opportunity.

We value your body integrity. We and our 1492 partners would like to stab you.

Re: RFC 35140: HTTP Do-Not-Stab (2023)

#154

It's important to note that the Do-Not-Stab header has been deprecated because one browser engine switched it on by default and requiring users to opt into stabbing hurt the bottom line of the stabbing industry, so it's no longer respected. Luckily someone came up with General Assault Control, a non-standard alternative, which also only has one value, so you can set Sec-GAC to 1 to request websites not to assault you…

Why is it a binary value? What about masochists, or people who lost a bet and want to be stabbed just a little? Or strangled?

Re: RFC 35140: HTTP Do-Not-Stab (2023)

#155
post #138
post #124

Earlier quoted context omitted.

> IMO we need to start normalizing being militant about this stuff again, to aggressively and adversarially defend the freedom to use your computer the way you choose to use it Yes. As a millennial the times of civil disobedience was better. Not only did we get a better internet for consumers, but better companies were rewarded and won. Rose tinted glasses? Possibly, but there’s another reason for disobedience: the o…

> Concretely, is there something like Adblock that can be done for cookies? I use a combination of two browser extensions: Cookie AutoDelete [0] and I don't care about cookies [1]. The second hides any GDPR 'compliance' popup; the first deletes any cookies set by a website when you close the last tab with it open. Both extensions have whitelist functionality. [0] https://github.com/Cookie-AutoDelete/Cookie-AutoDelete…

> I don't care about cookies[1]. The second hides any GDPR 'compliance' popup > [1] https://www.i-dont-care-about-cookies.eu/

I like to use Consent-o-Matic[1] for this. IDCAC accepts tracking when ignoring the request doesn't work. CoM rejects all tracking on those popups. I like the slight Fuck Off that that sends.

[1] https://consentomatic.au.dk/

Re: RFC 35140: HTTP Do-Not-Stab (2023)

#156
post #3

I’ve always wondered, since an RFC is a request for comment, how does one leave a comment? And who?

RFC's operate under the IETF. RFC's are developed under some specific group, and you can join that group, the business is generally conducted on email. There are (well, were back when I participated) in-person meetings, but attendance there was not mandatory.

RFC:s are published by the RFC Editor https://www.rfc-editor.org/>. While it’s true that most RFC:s are written and published through the IETF, this is not an actual rule.

Re: RFC 35140: HTTP Do-Not-Stab (2023)

#158
post #9
post #5

For the low price of $20/1000 clicks, I will provide you with a stabbing consent banner, fully compliant with upcoming EU and CA regulations on web-based stabbing.

I'm sold, the distinctions between "necessary", "targeting", "performance" and "functional" stabbings are such a minefield. Not to mention how I'm supposed to properly disclose the 846 different stabbing brokers I work with. How's a man supposed to make a living stabbing people with all of this red tape in the way?

At least people will be able to differentiate between legitimate interest to stab you and consent to be stabbed for 247 of those 846 partners.

Re: RFC 35140: HTTP Do-Not-Stab (2023)

#159
post #141

Earlier quoted context omitted.

It's amusing to see this message heavily upvoted on HN when most mentions of Firefox here are welcomed with an avalanche of perfect solution fallacies. I'm dubious about people becoming militant about this when the software engineering industry gave Chrome a red carpet by using it and installing it on their relatives' computers while knowing very well it's adware and when switching to the alternative is incredibly ch…

Chrome had the advantage for a long term because their dev tools were just so much better than Firebug in both features and performance. Even today, I can't pinpoint it to specific things because it's (relatively) little and subtle differences, but Chrome's dev tools feel way more polished than Firefox's. It's almost as if Steve Ballmer and the legendary "developers developers developers" speech still rings true toda…

Personally I disagree. IMO, devtools were better when competing with firebug, but I haven't experienced much of a difference in the past... 8? years. Something like that.

Re: RFC 35140: HTTP Do-Not-Stab (2023)

#160
post #153

Earlier quoted context omitted.

It's now customary, in order to comply with European regulations, to present users with a list of possible violent crimes against their person that they can opt out of before using a website. This ensures that non-consent to stabbing is always an active choice, so that users who want to be stabbed or otherwise maimed won't accidentally miss out on the opportunity.

We value your body integrity. We and our 1492 partners would like to stab you.

Please use this outlandishly convoluted form to opt out of every single one individually.

You might also want to read our ToS in order to stay informed about the multiple ways, some of them illegal under EU law, you still will get stabbed.

(Approximate reading time: 4h53m, assuming a law degree and multiple years of experience in data protection law practice)

Post reply on HN