Live data from Hacker News

HTTP "Prefer:Safe" – Making Online Safety Simpler in Firefox

blog.mozilla.org

41–50 of 62 posts

Re: HTTP "Prefer:Safe" – Making Online Safety Simpler in Firefox

#41
post #36

My feeling is that most of the people talking here do not have children yet. As a father, I would be really pleased to have such header accepted by many providers to just filter out content which is clearly not for kids. A small example, I am French living abroad, if I want my kids to read a bit the news, I cannot send them on one of the 3 "major" French newspaper to read a bit. Why? Because at the bottom of the firs…

I would imagine the newspaper you refer to is not regarded as a serious newspaper, but I am not too familiar with the French publications. Surely there are other ones you could trust them to browse.

Which one were you referring to again?

Re: HTTP "Prefer:Safe" – Making Online Safety Simpler in Firefox

#42

Soooo.. This is sending "Hey, this is a kid on a restricted machine" to all servers now? I mean I fail to understand the original idea, obviously. It makes no sense to me. But I question the value of the above - basically now the server can _just as easily_ do crap with that information. You can now identify minors (using that feature). Beautiful. The server operators cannot decide what 'parental control' would mean…

I exactly had the same idea... I would also add that this thing is going to be useless anyway because not all the websites are going to implement it. So you will have this header + the traditional blocker... It's totally unrelated but something I would really like to have right now would be a header with the average connection bandwidth (or just thresholds). This could be really useful to reduce the amount of data se…

I exactly had the same idea... I would also add that this thing is going to be useless anyway because not all the websites are going to implement it. So you will have this header + the traditional blocker...

It's not useless, since it allows the site to avoid being blocked by hiding the "bad" content. Ideally blockers would be smart enough to recognize and block only the "bad" DOM elements, but they usually just block the whole page, if not the whole site.

Re: HTTP "Prefer:Safe" – Making Online Safety Simpler in Firefox

#43
post #40

Soooo.. This is sending "Hey, this is a kid on a restricted machine" to all servers now? I mean I fail to understand the original idea, obviously. It makes no sense to me. But I question the value of the above - basically now the server can _just as easily_ do crap with that information. You can now identify minors (using that feature). Beautiful. The server operators cannot decide what 'parental control' would mean…

You can't identify minors because this isn't just a feature for minors but, e.g., for companies or public terminals as well. Of course it depends on the websites to deal with it. But, e.g., most popular porn sites actually do care about stuff like this. There is no UI in Firefox because Firefox uses the operating systems parental control features to enable/disable it. And those features should have a UI within the sy…

Your last paragraph is what I can't understand. Ignoring OS X for now (wouldn't know a thing about that):

Parental control in Windows just lets me set time limits/limits on what programs/games I can run as far as I know (just double checked microsoft.com and that's what they list as well). Given that and my understanding of the Fx feature means that Fx understands that this is a machine with parental controls enabled and _shares that with the world_.

That is nonsense. It's crap. The world cannot (as I stated before) decide what is okay and what not. Going with your porn example (I .. kinda expected that): I'd be entirely fine with a 16yo kid to look at porn. I might not want that very same kid to use the computer around 2am in the night. For the latter I can use parental control features. You (and Mozilla) force your (weird, from this pov) moral/set of values on me. Enabling parental control does NOT mean that I want the world to know about it. It also doesn't imply that porn isn't okay. On the other hand, maybe I would put the NRA website on the list of things I don't want to see in my household. No one can decide what is okay or not - except for the parent/admin.

"There is no UI in Firefox, because Firefox uses the OS parental control features to enable/disable it" is missing the point. Unless I fail to understand what this does I cannot use the parental controls without Firefox/Mozilla abusing that flag and asking the YouPorn administrators for parental support.

This is a misfeature and at best useless, although I'd lean towards harmful and wrong.

Re: HTTP "Prefer:Safe" – Making Online Safety Simpler in Firefox

#44

Earlier quoted context omitted.

I exactly had the same idea... I would also add that this thing is going to be useless anyway because not all the websites are going to implement it. So you will have this header + the traditional blocker... It's totally unrelated but something I would really like to have right now would be a header with the average connection bandwidth (or just thresholds). This could be really useful to reduce the amount of data se…

I exactly had the same idea... I would also add that this thing is going to be useless anyway because not all the websites are going to implement it. So you will have this header + the traditional blocker... It's not useless, since it allows the site to avoid being blocked by hiding the "bad" content. Ideally blockers would be smart enough to recognize and block only the "bad" DOM elements, but they usually just bloc…

That is absolutely meaningless. What is bad content? The header doesn't tell what the client considers 'bad' or not 'safe', it's a bool.

Given that, I see these possible outcomes

- the client's admin might not care about this site at all (effort to hide stuff would be wasted?)

- the client's admin might consider content 'unsafe' that seems fine/okay to the site operator => Blocklist, failed to archive what you suggest

- the client's admin might consider content 'safe' that the site now refuses to share => Curse site and Mozilla, switch browsers and/or consider that site broken and the operators morons (similar to 'breaks zoom on mobile devices' today, for example)

Re: HTTP "Prefer:Safe" – Making Online Safety Simpler in Firefox

#45
post #7

"Won't someone think of the children?" comes to the HTTP standard. Seriously though, this seems totally reasonable although "safe" does seem like an odd word choice. Maybe "modest" instead?

I'm thinking it's in the same category as "Safe For Work" and "Not Safe For Work". But yeah, I expected a HTTP header that would, say, redirect to an encrypted version of the webpage, sort of like HTTPS Everywhere, but on the browser-server level.

NSFW is just another undefined concept. It depends on your work, on your culture/upbringing and the society you live in.

If I stumble upon pictures of tits because someone posted a link to a yellow press newspaper site or a random celebrity scandal, I .. misclicked because that wouldn't interest me in the slightest. But it wouldn't be unsafe, not even for work. On the other hand, I wouldn't exactly want to end up on a nazi propaganda page (even if I'm merely looking at current splitter groups/facts around news reports about these sort of braindead idiots). I would feel very bad about leaving a trace like that - even if I don't think I'd have to face any sort of consequences.

Point being: Safe™ is undefined, for minors or employers. You can try to find a GCD, a common global set - and you'll fail/end up with a balance act between false positives and misses.

Re: HTTP "Prefer:Safe" – Making Online Safety Simpler in Firefox

#46
The Web is about statelessness and hyperlinking, so I'll note that:

1) Javascript breaks stateless linking.

2) Mobile versions and browser detection breaks stateless linking.

3) Censorship headers like Prefer:Safe, and censorship in general, breaks stateless linking.

And the list goes on. Some state and inability to link is inevitable, but this is not.

Mozilla: please get back on track for a strong/stateless and cite-able web. Headers are not the place to build a censorship "UX."

Also, "safety"? That's not helping. Almost no one uses NetNanny, or similar software and, while I'd like to think we've grown as a species, even if we haven't, it doesn't make sense to force something most Web surfers have already rejected back down their throats. (And it is forcing them, even if it's optional. The social implications of even "optional" headers will be with us for a very long time.)

A browser especially should strive to be neutral, unless you want to start getting requests from governments and industry to block sites directly in the browser. Google handles a million or more every day and they are just and index list... You can't expect a different fate without discarding neutrality as a core principal.

Cite-ability requires availability, and censorship - the Web-equivalent of a frontal lobotomy - contradicts the very essence of your product. I'm starting to feel ashamed to be using a browser made by an organization that doesn't understand that.

Re: HTTP "Prefer:Safe" – Making Online Safety Simpler in Firefox

#47
post #27

Just wtf is this. Mozilla now jumping on the "omigod teh childr0n" bandwagon, too? Any reasonably educated child can easily disable all of these "safety features" (e.g. boot the machine at night from USB stick...). These "features" are nothing but placebos for parents too incompetent to educate their children.

>(e.g. boot the machine at night from USB stick...) Well it does not work, if I use a transparent proxy at home which injects "Prefer: Safe" in every HTTP request header.

In which case the browser support and whole article is useless and nothing new for that kind of weird setup.

Although I'd recommend being a responsible admin/parent in that case instead and, with the _correct_ infrastructure for this scenario already in place, define filters for things you don't like or white lists for things that are okay for your network, instead of begging the internet to correctly guess your moral boundaries.

Re: HTTP "Prefer:Safe" – Making Online Safety Simpler in Firefox

#48
post #33

Earlier quoted context omitted.

It is a matter of common sense. You can't reasonably control internet usage of teenager (and probably shouldn't). While 5yo is an avid user YouTube and google and it is a good idea to filter things they can get to

I would say that the answer for the 5 year old scenario is supervision.

sure. but having several layers of "defense" is still a good idea

Re: HTTP "Prefer:Safe" – Making Online Safety Simpler in Firefox

#49

Earlier quoted context omitted.

[Citation Needed] Spec makes no mention of age groups this is supposed to be used for aside from "children".

It is a matter of common sense. You can't reasonably control internet usage of teenager (and probably shouldn't). While 5yo is an avid user YouTube and google and it is a good idea to filter things they can get to

I would freaking love it if Youtube had the sense to not serve adult adverts during obviously children's programming.

Re: HTTP "Prefer:Safe" – Making Online Safety Simpler in Firefox

#50
post #36

My feeling is that most of the people talking here do not have children yet. As a father, I would be really pleased to have such header accepted by many providers to just filter out content which is clearly not for kids. A small example, I am French living abroad, if I want my kids to read a bit the news, I cannot send them on one of the 3 "major" French newspaper to read a bit. Why? Because at the bottom of the firs…

How can the sites tell that this content isn't okay?

I posted an example elsewhere in this thread: I might want to limit a 16yo with parental controls to avoid having them use the computer the whole night, but I wouldn't mind them seeing (naked) girls on a yellow press site, if that's what they stumble upon.

I'm also reasonably sure that your particular problem could already be solved on the client site, today, and that would even make sure that your personal take on moral values is respected. Plus, as others have stated, 'parental' controls might be used for a "kiosk mode" in a hotel or elsewhere (for .. whatever reason). Would you really want these scenarios to result in the same thing ("Content filtered on a news site"), both for your personal kids and for random mature people elsewhere?

Post reply on HN