Earlier quoted context omitted.
Then why not fix the horrendous browser performance of Chrome? It's not like people's complaints about how much energy it uses relative to Safari are new. People have been complaining for YEARS. According to another comment you work on the Chrome team. So unlike most everyone here, you're actually in a position to fix one of the two options.
(a) I do not work for Google or on Chrome. (b) I do not disagree about Chrome's energy usage. It sucks.
Apple adds a tracker blocker to desktop Safari
151–160 of 301 posts
Re: Apple adds a tracker blocker to desktop Safari
#152Earlier quoted context omitted.
There's a huge difference between being asked if it's ok to share your data and just sharing it by default. Additionally, Apple doesn't offer any kind of way for anyone but you to decrypt your data.
So you've never actually installed Windows 10 then? Because from the beginning it's asked for permission to share your data for things like Cortona, the touch keyboard, ink, voice, etc. Based on user response they've evolved the interface and made it clearer removing anti-patterns. This is the same stuff Apple asks for permissions on. Microsoft doesn't let you turn off telemetry data entirely. Things like hardware co…
Re: Apple adds a tracker blocker to desktop Safari
#153Sounds like this is more in line with what they did with ApplePay vs traditional credit cards--I.e. They give you randomized IDs each time so the other party can't track you from transaction to transaction. Adds can still appear but they won't know who you are, so it's a direct shot at Google and others looking to give people "targeted" adds based on user behavior. I agree it's an issue that needs addressed. Just bec…
That's actually not how ApplePay works. You get a new randomized credit card number, but only once. Shops can still track you by checking for the number. You can check that yourself by looking at receipts when you pay with ApplePay - each receipt features the same numbers (most receipt only show the last 4 digits, but they are always the same when you pay with ApplePay).
It would be really cool if it generated new numbers each time and had an amount coded to that number. So when I wave my Apple Pay device over the reader it would display the amount on the device, I would approve, and then a number would be handed back that's only good for that amount.
Re: Apple adds a tracker blocker to desktop Safari
#154Earlier quoted context omitted.
Safari's sandbox is weaker in some ways and stronger in others. Saying which is overall stronger would be a judgment call. I wouldn't make a claim like that without spelling out at least some of the details. This subthread is about the sandbox so I'm not sure why you threw in "and anti-exploit features". I'd probably say without qualification that Chrome has better memory corruption mitigations. I hoped you might hav…
In what ways would you say the Safari sandbox is stronger than Chrome's, on macOS? How would you compare Safari's anti-exploit technology (allocator hardening, Javascript engine hardening, &c) to that of Chrome? Do you think you do anything better than Chrome does on that front?
It would be easy to get the impression that you're trying to shift the burden of proof and move the goal posts. Despite this, I will try to assume good faith.
I think you original post gave the impression that Safari either has no sandbox, or has a wildly ineffective sandbox. You didn't directly state it, but at least some users understandably took away that implication. I think this is inaccurate and unfair.
One piece of evidence we have is grey market prices for end-to-end Safari exploits (with full sandbox escape). By this metric, breaking out of our sandbox on Mac or iOS is not trivial, and is at least comparable in difficulty to Chrome or Edge on Mac, Windows or Android. On the flip side, it seems to be significantly easier to get inside-the-sandbox remote code execution in Safari if you go by market prices, hacking contests, etc. That's something we're working on. Chrome and Edge definitely have materially better mitigations here (as I said in my earlier post).
And finally, to answer your question: One small way Safari has better sandboxing is the we sandbox our network process (something that Chrome is still working on).
Re: Apple adds a tracker blocker to desktop Safari
#155Sounds like this is more in line with what they did with ApplePay vs traditional credit cards--I.e. They give you randomized IDs each time so the other party can't track you from transaction to transaction. Adds can still appear but they won't know who you are, so it's a direct shot at Google and others looking to give people "targeted" adds based on user behavior. I agree it's an issue that needs addressed. Just bec…
That's actually not how ApplePay works. You get a new randomized credit card number, but only once. Shops can still track you by checking for the number. You can check that yourself by looking at receipts when you pay with ApplePay - each receipt features the same numbers (most receipt only show the last 4 digits, but they are always the same when you pay with ApplePay).
Re: Apple adds a tracker blocker to desktop Safari
#156Re: Apple adds a tracker blocker to desktop Safari
#157Earlier quoted context omitted.
In what ways would you say the Safari sandbox is stronger than Chrome's, on macOS? How would you compare Safari's anti-exploit technology (allocator hardening, Javascript engine hardening, &c) to that of Chrome? Do you think you do anything better than Chrome does on that front?
Your original post here made a bold claim with no qualification and no supporting details. You're not providing any backing to your claim but at the same time you're asking me to give details. Plus you've repeatedly thrown in anti-exploit tech which wasn't the original point of contention. It would be easy to get the impression that you're trying to shift the burden of proof and move the goal posts. Despite this, I w…
I think if you create a breakdown of all the facets of browser security, it will look something like this:
Isolation: Chrome > Edge | Safari > Firefox
Anti-Exploit: Edge > Chrome > Firefox > Safari
UX: Chrome > Firefox > Safari > Edge (U2F, password manager)
TLS: Chrome > Firefox > Safari | Edge
Library Security: Chrome > Edge > Firefox > Safari
If you want to add privacy controls here, you'll get an easy win for Safari, but privacy isn't security.
You're close to this stuff though, so if you disagree with any of these informal rankings, or think I've got the rankings wrong, please correct me.
Re: Apple adds a tracker blocker to desktop Safari
#158Earlier quoted context omitted.
There's a huge difference between being asked if it's ok to share your data and just sharing it by default. Additionally, Apple doesn't offer any kind of way for anyone but you to decrypt your data.
So you've never actually installed Windows 10 then? Because from the beginning it's asked for permission to share your data for things like Cortona, the touch keyboard, ink, voice, etc. Based on user response they've evolved the interface and made it clearer removing anti-patterns. This is the same stuff Apple asks for permissions on. Microsoft doesn't let you turn off telemetry data entirely. Things like hardware co…
Spotlight and Safari send anonymous data back that is parsed and separated so that it can't be used to identify the machine, user, or account that they came from. That's wildly different from the MS approach even after all the changes made on MS's end.
Re: Apple adds a tracker blocker to desktop Safari
#159This is great, but unfortunately, until Apple ups its browser security game, Safari is a non-starter. On macOS, switching from any other browser to Chrome is in the top 3 things you can do to materially improve your security in ways that actually matter in the real world.
Just to add some context, on macOS you can look at the seat-belt policy as a rough analog of for basic sandboxing guarantees, where the fewer exceptions you have the stronger your sandbox is. From that perspective, Chrome's policy has around 1/10th the exceptions of Safari. * Safari SB policy: https://trac.webkit.org/browser/webkit/trunk/Source/WebKit2/... * Chrome SB policy: https://cs.chromium.org/chromium/src/cont…
If you add these things up, the difference in practical effectiveness is not as wide as one might think.
Re: Apple adds a tracker blocker to desktop Safari
#160Earlier quoted context omitted.
I know he is, but that's not the same thing as what he's implying and, even then, Apple's solution is opt-in while Microsoft's was on by default.
If Apples solution is opt-in, Microsofts is in. For many things there just is no opting out.