Live data from Hacker News

RFC 35140: HTTP Do-Not-Stab (2023)

5snb.club

171–180 of 219 posts

Re: RFC 35140: HTTP Do-Not-Stab (2023)

#171
post #110
post #95

Earlier quoted context omitted.

I wonder how many web developers actually honour Do Not Track. I do, in all the websites I've made for my employer too, but I think I'm only getting away with it because my employer doesn't know. I've even made it so that browsing with Do-Not-Track enabled also skips the cookie consent banner and just assume the user wants no cookies other than the strictly necessary ones (like their session/login cookie), and doesn'…

A better option would be to just make tracking illegal, and heavily fine companies that are found to be doing it. And make it strict liability, so intent doesn't matter. I can dream...

> A better option would be to just make tracking illegal, and heavily fine companies that are found to be doing it. And make it strict liability, so intent doesn't matter.

I don't think it's that easy though. The "just" is doing a lot of work in there. Consider:

Some websites have login with third-party credentials. It doesn't matter that you choose to use these for convenience, because intent doesn't matter, and it is a fact that both the Service Provider and the Identity Provider are tracking you. IdP knows which sites you are logging in to, and SP knows and stores your third-party identity (they might say they need it to know which account you're logging in to, but like I said, intent doesn't matter).

Hacker News is currently tracking me. They might say the cookie is needed for session stuff to work, but intent doesn't matter, and it is a fact that the cookie uniquely identifies me.

My web browser is tracking my mouse position. Mozilla might say they need it for styling stuff to work, but intent doesn't matter, and it is a fact that Mozilla's software is tracking my mouse position in real time (let's not even talk about browser history).

Your browser cache might have two HN posts where my comments appear. If that's the case, then it would be a fact that you are tracking which posts I am commenting on. Intent doesn't matter, so hopefully you're not a company (tracking is fine if you're an individual though (based on the quoted text)).

/s

Hopefully this ride down the slippery slope illustrates some subtleties, at least without a very precise definition of "tracking". But then again, if the definition is too precise, there's gonna be loopholes in the letter of the law; in that case we might say that we should also consider the spirit of the law, but "intent" is part of that.

Re: RFC 35140: HTTP Do-Not-Stab (2023)

#172
post #141

Earlier quoted context omitted.

It's amusing to see this message heavily upvoted on HN when most mentions of Firefox here are welcomed with an avalanche of perfect solution fallacies. I'm dubious about people becoming militant about this when the software engineering industry gave Chrome a red carpet by using it and installing it on their relatives' computers while knowing very well it's adware and when switching to the alternative is incredibly ch…

Chrome had the advantage for a long term because their dev tools were just so much better than Firebug in both features and performance. Even today, I can't pinpoint it to specific things because it's (relatively) little and subtle differences, but Chrome's dev tools feel way more polished than Firefox's. It's almost as if Steve Ballmer and the legendary "developers developers developers" speech still rings true toda…

> Chrome had the advantage for a long term because their dev tools were just so much better than Firebug in both features and performance. Even today, I can't pinpoint it to specific things because it's (relatively) little and subtle differences, but Chrome's dev tools feel way more polished than Firefox's.

My point exactly! You're talking about which browser to use for web development. That's not relevant for engineers not touching html/js/css, and for all non tech savvy family members whose computers we set up.

Re: RFC 35140: HTTP Do-Not-Stab (2023)

#174

Earlier quoted context omitted.

You'd think there'd be some "competitive advantage" to be had, but when their entire industry is built upon tracking and profiling everyone they possibly can, they'll do anything they can, fighting tooth-and-nail to the very end against any legislation that somehow interferes with their tracking, even if it means resorting to childish and petty temper tantrums that further enshittify the web. What little "competition…

Other replier believes that competition is a system that works toward consumer needs and betterments. Advertising is extractive

Competition _is_ a system that works toward consumer needs and betterments. In advertising though, you are not the consumer.

Re: RFC 35140: HTTP Do-Not-Stab (2023)

#175

   Them: What's your LinkedIn Account?
   Me: Don't have one.
   Them: Twitter?
   Me: Nope.
   Them: InstaGram or TicToc?
   Me: Nope.
   Them: Do you use the web at all?
   Me: Only through Lynx.  I see a lot fewer ads.
   Them: No JavaScript!  How do you use YouTube?
   Me: I don't, really.
   Them: You have no social media?
   Me: Well... I *did* order a pizza from Dominos online once...

   Yeah... I don't use the web much as you would expect for someone
   who's livelihood depends on it.  I just wish USENET was still
   USEFUL.  I have a rant in me about ad-tech and crap-ware on the
   web.  I'm just enjoying my life without the web too much  to 
   write it.  And clearly, HN is my web-tech achilles heel.

Re: RFC 35140: HTTP Do-Not-Stab (2023)

#176
post #141

It’s great satire, but it really does mirror a larger societal shift where the burden of safeguarding personal autonomy has shifted from institutions/regulators to individual users. Do-Not-Stab, Do-Not-Track, whatever it might be, any sort of “voluntary compliance” is a non-starter in the face of financial pressures IMO we need to start normalizing being militant about this stuff again, to aggressively and adversaria…

It's amusing to see this message heavily upvoted on HN when most mentions of Firefox here are welcomed with an avalanche of perfect solution fallacies. I'm dubious about people becoming militant about this when the software engineering industry gave Chrome a red carpet by using it and installing it on their relatives' computers while knowing very well it's adware and when switching to the alternative is incredibly ch…

I think we shouldn't minimize the harm Chrome does by calling it adware. It monitors all your activity for Google to tie it to your identity, who then publish your demographics, preferences, history, and mental state on the global markets. Let's call it what it is: a brain tap.

Re: RFC 35140: HTTP Do-Not-Stab (2023)

#177
post #172

Earlier quoted context omitted.

Chrome had the advantage for a long term because their dev tools were just so much better than Firebug in both features and performance. Even today, I can't pinpoint it to specific things because it's (relatively) little and subtle differences, but Chrome's dev tools feel way more polished than Firefox's. It's almost as if Steve Ballmer and the legendary "developers developers developers" speech still rings true toda…

> Chrome had the advantage for a long term because their dev tools were just so much better than Firebug in both features and performance. Even today, I can't pinpoint it to specific things because it's (relatively) little and subtle differences, but Chrome's dev tools feel way more polished than Firefox's. My point exactly! You're talking about which browser to use for web development. That's not relevant for engine…

Interesting, in my murky memory Chrome's developer tools were at most "quite decent" but for a long period of time could hardly compete with Firefox's, maybe even with mere Firebug. It it true that in total "feature count" Chrome most probably leads now, and especially recently they seem to adapt features that used to be Firefox exclusive in remarkably increasing rate. But I really do not remember being blown away by Chrome's devtools, like, ever, actually. Even today I pretty much prefer Firefox Developer Tools over Chrome's, because they mostly has more features I actually need and also feel way less cluttered. Most of the times I need to do anything with Chrome's devtools it takes me just a little moment to stumble upon some missing detail I am used to (for example overflow/layout/event listeners badges directly in the DOM inspector tree) or to be mildly offended by unfamiliar (or missing) keybinding, or confusing layout. There are quite a few features In Chrome that I'd like to see in Firefox (command palette for example), but still prefer "living" in Fx albeit without them.

Yes, al subjective, biased and anecdotal, but wanted to leave one real (yet still virtual) vote in favour of Firefox's Developer Tools here.

Re: RFC 35140: HTTP Do-Not-Stab (2023)

#178
I find it funny that the authors are from Google, of Google Analytics, where the recommended way to opt out of tracking is to install a "do not track" browser plugin (not available on mobile).

> Google has also released a browser plug-in that turns off data about a page visit being sent to Google, however, this browser extension is not available for mobile browsers.

source: https://en.wikipedia.org/wiki/Google_Analytics#Privacy

Re: RFC 35140: HTTP Do-Not-Stab (2023)

#179
Don't care too much about do-not-stab since I deployed a pi-bulldog on my network that catches all the back alley NSRs (network stab requests). I was thinking about using SDoH (self-defense over https) or AoT (AR15 over TLS) to be protected outside my network as well, but honestly the little stabbings here and there cause sufficiently little blood to be drew that its not worth the hassle.

Re: RFC 35140: HTTP Do-Not-Stab (2023)

#180
post #141

It’s great satire, but it really does mirror a larger societal shift where the burden of safeguarding personal autonomy has shifted from institutions/regulators to individual users. Do-Not-Stab, Do-Not-Track, whatever it might be, any sort of “voluntary compliance” is a non-starter in the face of financial pressures IMO we need to start normalizing being militant about this stuff again, to aggressively and adversaria…

It's amusing to see this message heavily upvoted on HN when most mentions of Firefox here are welcomed with an avalanche of perfect solution fallacies. I'm dubious about people becoming militant about this when the software engineering industry gave Chrome a red carpet by using it and installing it on their relatives' computers while knowing very well it's adware and when switching to the alternative is incredibly ch…

Mozilla would be the first to request permission to stab you so that they can then analyze the blood of the knife in order to make future product decisions.
Post reply on HN