Live data from Hacker News

HTTP "Prefer:Safe" – Making Online Safety Simpler in Firefox

blog.mozilla.org

11–20 of 62 posts

Re: HTTP "Prefer:Safe" – Making Online Safety Simpler in Firefox

#11
post #3

"Strengthen the online trust and safety model" is a weird way to say "no porn."

It has many other uses, IMO. - Disable signup/require COPPA form to be mailed & signed - Filter out explicit content from user-generated content - Disable vulgar sections from a blog - Prohibit downloading software etc

Most of these are horrible suggestions for the same reason Do Not Track is useless - no enforcement or guarantees make it pointless. Especially that last one. LOL. The notion of a webpage blocking me from downloading because of a header that my platform's client browser sent? Pfft.

Re: HTTP "Prefer:Safe" – Making Online Safety Simpler in Firefox

#13

A header Id rather see is Cookies: I-know-what-they-are-for "don't show me information about cookie usage".. )

Agreed. Can't believe the alert has to be implemented on all the websites, instead of requiring browser vendors to provide an alert (that can be globally disabled.

Re: HTTP "Prefer:Safe" – Making Online Safety Simpler in Firefox

#14
I was with them until they mentioned "one less thing for kids to try to circumvent to disable this control". If a kid is actively trying to circumvent the parental controls, this is no longer about "protection" but about control.

In other news, the Feynman lectures on QED are blocked in "safe" mode. https://www.youtube.com/watch?v=yvl6TBGEoO0

Re: HTTP "Prefer:Safe" – Making Online Safety Simpler in Firefox

#15
post #3

"Strengthen the online trust and safety model" is a weird way to say "no porn."

It has many other uses, IMO. - Disable signup/require COPPA form to be mailed & signed - Filter out explicit content from user-generated content - Disable vulgar sections from a blog - Prohibit downloading software etc

> - Disable signup/require COPPA form to be mailed & signed

Somewhat off topic, but I think 13 is considerably above the age where kids have a reasonable interest in being able to actually use the web. When I was a few years younger than 13 (10 years ago...), I once accidentally put my true birthday into AIM, and was subsequently banned from the service I used to communicate with friends from school. Recently, the same happened with one of my sister's friends and Gmail. Does anyone actually think these forms are a good thing?

Re: HTTP "Prefer:Safe" – Making Online Safety Simpler in Firefox

#17
Just wtf is this. Mozilla now jumping on the "omigod teh childr0n" bandwagon, too?

Any reasonably educated child can easily disable all of these "safety features" (e.g. boot the machine at night from USB stick...). These "features" are nothing but placebos for parents too incompetent to educate their children.

Re: HTTP "Prefer:Safe" – Making Online Safety Simpler in Firefox

#18

Just wtf is this. Mozilla now jumping on the "omigod teh childr0n" bandwagon, too? Any reasonably educated child can easily disable all of these "safety features" (e.g. boot the machine at night from USB stick...). These "features" are nothing but placebos for parents too incompetent to educate their children.

I think you misunderstand. This is a feature for 5-6yo, not for 11-12yo

Re: HTTP "Prefer:Safe" – Making Online Safety Simpler in Firefox

#19

Just wtf is this. Mozilla now jumping on the "omigod teh childr0n" bandwagon, too? Any reasonably educated child can easily disable all of these "safety features" (e.g. boot the machine at night from USB stick...). These "features" are nothing but placebos for parents too incompetent to educate their children.

I think you misunderstand. This is a feature for 5-6yo, not for 11-12yo

[Citation Needed]

Spec makes no mention of age groups this is supposed to be used for aside from "children".

Re: HTTP "Prefer:Safe" – Making Online Safety Simpler in Firefox

#20
I wonder how they're going to implement the "no circumvention" part.

Surely there's an option in about:config that affects the new behavior? Is about:config disabled too?

There are also dozens of add-ons that lets you control every single header. Are add-ons disabled too, or is there going to be a blacklist of header-modifying add-ons?

It will take less than a week for point-and-click circumvention tools to become available all over the place. Just download this little .EXE that makes a small change to your Firefox profile and might or might not also contain malware! Should Google block searches like "how to disable Prefer:Safe" if such searches come from a browser that already has "Prefer:Safe" enabled?

Post reply on HN