Live data from Hacker News

Gemini is Solutionism

xn--gckvb8fzb.com

181–190 of 227 posts

Re: Gemini is Solutionism

#181

Earlier quoted context omitted.

> Eh, it would be really nice to have back a Web where clicking a link couldn't result in loading a page that's tracking your mouse movements while you're on it. It's still possible if you use uBlock, or enable JS only when you need it. You don't have to throw the baby (gemtext missing inline links !) out with the bathwater.

> It's still possible if you use uBlock, or enable JS only when you need it. Possible, but painful. Take HN's official search engine, for example: https://hn.algolia.com/ I open it. "This page will only work with JavaScript enabled" sigh Accept JS from hn.algolia.net and the mangled cloudfront domain (and make sure not to accept ravenjs.com). Possibly cdn.jsdelivr.net if I want to spare a click later, because I don't…

I’m not that familiar with Gemini, but implementing search functionality via Gemtext is impossible right? Would the appropriate comparison not be pages that are similarly static to Gemtext?

I’m not convinced that an entirely new protocol is necessary. How is the Gemini experience different from just browsing all webpages with JS disabled, or if you want to go even further, using a web browser that just doesn’t implement JavaScript?

Re: Gemini is Solutionism

#182

Earlier quoted context omitted.

"If you're only hosting 1 site, isn't the privacy leak negligible because there is a 1:1 mapping from ip to domain so an attacker can easily determine it." What if it is a company serving advertisers, not an "attacker". Not sure why this myth of effortless, reliable translation from IP to domain name in "real-time" exists amongst HN commenters. Show us who is doing this for the purposes of advertising and how it is w…

> Show us who is doing this for the purposes of advertising and how it is worth the effort and can be relied on. Why would an advertiser do this? Advertisers are typically in leauge with site operators. Site operators just tell them this data (maybe with rare exceptions like superphish). Advertisers don't do this because they don't need to. Advertisers are not the adversary tls is meant to thrawt. You don't use the l…

[deleted]

Re: Gemini is Solutionism

#183

Earlier quoted context omitted.

"If you're only hosting 1 site, isn't the privacy leak negligible because there is a 1:1 mapping from ip to domain so an attacker can easily determine it." What if it is a company serving advertisers, not an "attacker". Not sure why this myth of effortless, reliable translation from IP to domain name in "real-time" exists amongst HN commenters. Show us who is doing this for the purposes of advertising and how it is w…

> Show us who is doing this for the purposes of advertising and how it is worth the effort and can be relied on. Why would an advertiser do this? Advertisers are typically in leauge with site operators. Site operators just tell them this data (maybe with rare exceptions like superphish). Advertisers don't do this because they don't need to. Advertisers are not the adversary tls is meant to thrawt. You don't use the l…

"Why would an advertiser do this?"

Not an advertiser necessarily but any entity or person that can "monetise" the data collected. The collector might use the data itself, it might license, sell or transfer the data, it might provide services that rely on the data, who knows. Some users may not want to voluntarily share this data when they derive no benefit from doing so. We do not have to guess all the possible ways, besides locating the applicable TLS certificate, that the data might be used before we can honor the user's wish that this data not be sent in plaintext where it is not needed for choosing the certificate.

AFAIK, sniffing SNI is already used for the purpose of censorship by some countries. This has been published. It would be ignorant to think that this is the only purpose for which such data might be used, or that any purpose would always be non-commercial and unconnected, directly or indirectly, to web advertising. As the use of DoH increases, sniffing SNI would seem an easy substitute for sniffing DNS.

1. A real-time list of every domain visited by a user.

"You don't use the lock on your door to thrawt the person who you invited in and opened the door for."

For some users, advertisers are not an "invited person". What is more, companies like Google have attempted to force the use of TLS for every site, even ones where, in the user's or site operator's opinion, TLS is not needed.

"It is difficult to tell if a site needs it or not at the stage where you send it."

But this is not an argument for sending SNI by default, even where it is not needed.

A TLS proxy can be configured to distinguish sites that need it from sites that do not. This is what I do. The default configuration is to not send SNI. This makes sense because the majority of sites I visit do not require it.

As such, from where I sit, the solution chosen by modern web browsers is to prioritise websites that use CDNs that depend on SNI. The side effects for users of indiscriminantly sending SNI, i.e., sharing every domain the user visits in plaintext on the wire, are not as important as reducing costs for those websites using TLS and CDNs. Arguably, SNI is for the benefit of websites and CDNs at the expense of users. (Hopefully ECH will obviate this tradeoff.)

"Otherwise (e.g. if using DoH) just create a db of popular sites you care about."

According to this answer, 1:1 mapping is not an equally easy alternative to SNI. Sniffing SNI is "trivial" and works for any https site, whereas 1:1 mapping through a database is "non-trivial" and only works for "a selection of popular sites [one] cares about". SNI makes the task of monitoring a user's web use easy. If SNI is not available to sniff, then the task becomes more difficult. This is the point.

Sniffing SNI is easy. The theoretical 1:1 mapping alternative proposed by HN commenters is more difficult. This is the point. What is easy and reliable for all www sites versus what is more difficult and unreliable for all www sites. The point is not what is possible^2 and what is impossible. That is the red herring diversionary argument tactic that HN commenters defending gratuitous SNI like to use.

2. It is possible to avoid DNS altogether and to only send SNI when it is required. I have been doing this for years. Gather bulk DNS data and load the data into a forward TLS proxy that stores domain:IP addresses mapppings in memory and does lookups in real-time as requests are received.

Re: Gemini is Solutionism

#184

Earlier quoted context omitted.

"If you're only hosting 1 site, isn't the privacy leak negligible because there is a 1:1 mapping from ip to domain so an attacker can easily determine it." What if it is a company serving advertisers, not an "attacker". Not sure why this myth of effortless, reliable translation from IP to domain name in "real-time" exists amongst HN commenters. Show us who is doing this for the purposes of advertising and how it is w…

> Show us who is doing this for the purposes of advertising and how it is worth the effort and can be relied on. Why would an advertiser do this? Advertisers are typically in leauge with site operators. Site operators just tell them this data (maybe with rare exceptions like superphish). Advertisers don't do this because they don't need to. Advertisers are not the adversary tls is meant to thrawt. You don't use the l…

[deleted]

Re: Gemini is Solutionism

#185
post #179

Earlier quoted context omitted.

No, you could only do that if the basis of my comment were about generic, FOMO-driven hand-wringing, where A is unbound, so substitute any A and the criticism remains true. That's not what we're talking about. The criticism involves the observation that Gemini, specifically, is bad.

If Gemini specifically is bad, you should be able to argue that without making these other arguments that apply to any new project. Convince people they shouldn't care about it. So far I haven't found that side compelling. If you concentrate your energies there, I might.

They can't be applied to any new project. I don't know why you're ignoring this, even with the clarification using the well-understood concept of free vs bound variables. "These other arguments" are a direct response to the question you posed https://news.ycombinator.com/item?id=30068014>.

My position is something that I know you already agree with. You can't write, "Surely anything Gemini does or doesn't isn't as damaging as status quo" and think that my argument is unsound—because it's the same concept.

> If you concentrate your energies there

The last thing that we need is _more_ energy being lost to the Gemini sinkhole. That's the whole point!

Re: Gemini is Solutionism

#186

Earlier quoted context omitted.

"If you're only hosting 1 site, isn't the privacy leak negligible because there is a 1:1 mapping from ip to domain so an attacker can easily determine it." What if it is a company serving advertisers, not an "attacker". Not sure why this myth of effortless, reliable translation from IP to domain name in "real-time" exists amongst HN commenters. Show us who is doing this for the purposes of advertising and how it is w…

> Show us who is doing this for the purposes of advertising and how it is worth the effort and can be relied on. Why would an advertiser do this? Advertisers are typically in leauge with site operators. Site operators just tell them this data (maybe with rare exceptions like superphish). Advertisers don't do this because they don't need to. Advertisers are not the adversary tls is meant to thrawt. You don't use the l…

[deleted]

Re: Gemini is Solutionism

#187

Earlier quoted context omitted.

Congratulations, you've invented Gemini with HTTP syntax. Since it's incompatible anyway, why does it need to be HTTP syntax?

It wouldn’t be incompatible if it took advantage of the Accept header.

It pretty much would. You couldn't link to the HTTP-Markdown-Web from the HTTP-HTML-Web (normal browsers don't and won't support Markdown) and you couldn't link to the HTTP-HTML-Web from the HTTP-Markdown-Web (the Markdown browser doesn't and won't support HTML)

(Almost nobody would vary the response based on the Accept header. Besides, if they did, you might as well just set an X-No-Ads-Please header and send HTML in both versions)

Re: Gemini is Solutionism

#188
post #185

Earlier quoted context omitted.

If Gemini specifically is bad, you should be able to argue that without making these other arguments that apply to any new project. Convince people they shouldn't care about it. So far I haven't found that side compelling. If you concentrate your energies there, I might.

They can't be applied to any new project. I don't know why you're ignoring this, even with the clarification using the well-understood concept of free vs bound variables. "These other arguments" are a direct response to the question you posed https://news.ycombinator.com/item?id=30068014 >. My position is something that I know you already agree with. You can't write, "Surely anything Gemini does or doesn't isn't as d…

I don't understand. What clarification? I don't see any mention of free vs bound variables anywhere in this thread or your links. I meant energies in describing the technical shortcomings of Gemini, and concentrating all the energy you're already willing to expend, not adding more. If you're tired of arguing, so am I. I'll step away now.

Re: Gemini is Solutionism

#189
post #80

I find it ironic to read an English blog post deriding something for being inaccessible hosted on a domain containing Katakana, something most English keyboards would not be able to type. I cannot tell if the author is Japanese, but I am not sure it matters since the content appears to be exclusively English.

> something most English keyboards would not be able to type English language keyboards are how you type Japanese. Those keyboards you see with Katakana or Hiragana are rarely used in Japan, pretty much everyone uses romaji. And it's easy to set up on Windows. I can toggle English and Japanese input with Windows Key + Space. ナイス!

I think my comment still stands. Without extra configuration, there is no way to type the characters directly from an English Keyboard. And most users don't have that configuration setup. Even if you can type in romaji, it still requires the knowledge of what combination of latin characters correspond to to a Katakana character. I don't think you should have to enable international keyboards to access a domain.

Re: Gemini is Solutionism

#190

> Bottom line is, if you agree that the modern web has become an awful place, let’s work on changing that for everyone, instead of abandoning it like a bunch of billionaires trying to escape to a different place, before this one collapses. The implication being that the web can be changed? I don't believe that, I believe the web is broken and it's only getting worse by the day. I'm not going to discourage you from tr…

> Sorry, these are not answers for me as a user. Sure, but there are plenty of users that are out there with different needs than you. Plenty of people out there don't deal with text well. One of the best parts of the web has been the ability to share images and simulations. Gemini space has no 3Blue1Brown and no Khan Academy. You can't watch a master cabinetmaker hand carve some dovetails. Gemini can't display textu…

Gemini doesn’t aim to replace the web.
Post reply on HN