Live data from Hacker News

Where Am I? NYTimes or Google?

theinternetbytes.com

231–240 of 381 posts

Re: Where Am I? NYTimes or Google?

#231

With the utmost respect to you and the other commenters here, when I see positivity about the abstract, hypothetical technical merits of something with a long history of, in practice, being part of an extremely controversial power play it reminds me a lot of the comments I see promoting a widely installed piece of process management software — one which a lot of people don’t really want, whose subtle changes to layer…

You might want to work on reducing the length of your sentences- it's very hard to get the meaning behind them.

Re: Where Am I? NYTimes or Google?

#232
post #152

Earlier quoted context omitted.

URLs haven't been associated with legitimate content for a long time now, since most of the things come from giant CDN companies like CloudFlare anyway. What you're seeing in URL bar has very little to do with where the JS code executed on your computer is coming from.

Does it matter if it comes from a CDN rented by the NYT or a computer owned by DigitalOcean but rented by the NYT? What matters is that the domain points to where the NYT considers is the correct source of their content.

With signed exchanges, the NYT is cryptographically opting into allowing Google (or other cache providers) to represent specific articles as being the NYT. It doesn't seem much different.

Re: Where Am I? NYTimes or Google?

#233
post #215

Earlier quoted context omitted.

Perhaps they instead see the “solution” to be problematic.

Yes, but not acknowledging the problem and that AMP is a solution, even if it's the wrong solution, defeats any meaningful discussions. We need something like AMP but outside of Google's control. My point is that it's so easy to just see the drawbacks and none of the benefits when you're sitting on a good connection. All threads on HN becomes completely one-sided where everyone is just backslapping each other's compl…

like a moth to a flame eh googler?

Re: Where Am I? NYTimes or Google?

#234

Earlier quoted context omitted.

> WeChat (The Chinese equivalent of Medium) TIL

Well, it’s more like WhatsApp, Medium, Venmo, and Facebook all combined into one giant app.

Also food ordering, travel reservations, health care appointments, banking, government services, and a whole lot of other things that would take too long to list. It's not an exaggeration to say the entire Chinese consumer experience runs through WeChat.

Re: Where Am I? NYTimes or Google?

#235
post #74

IMO the core point of the article is false. > To be blunt, this is a really dangerous pattern: Google serves NYTimes’ controlled content on a Google domain. No, "Google serves NYTimes' controlled content" is an oxymoron. Google controls the content that is served, and that's all your browser is verifying. Google could very well make the NYTimes content on there display something else and your browser wouldn't show a…

The pattern is dangerous because it trains the user to dissociate URL and legitimate content, and the best tool at our disposal against phishing is still the ability to use the URL to ascertain the legitimacy of a content.

It's the current amp status quo that trains users that legitimate content is sometimes on other domains.

This change would restore the idea that the URL indicates the provenance of the content,

Re: Where Am I? NYTimes or Google?

#236
post #5

Earlier quoted context omitted.

I don’t really think Google’s plan is that weird. And it would be amazing for decentralized networks, archiving, and offline web apps. Google can’t just serve nyt.com — they can serve a specific bundle of resources published and signed by nyt.com verified by your browser to be authentic and unmodified.

That's not why Google (the corporation) wants this to happen. This is not about technical capabilities but about power. They cannot be allowed to become the gatekeeper for the web.

They already are. The question is not how we're going to stop that from happening but how we are going to roll it back.

Re: Where Am I? NYTimes or Google?

#237
post #173

Earlier quoted context omitted.

Google is not a single server. Think of Google as a CDN.

So it's decentralized because Google has multiple servers? And here I was, thinking that Google runs everything from a single IBM mainframe. What you're saying would be described as distributed... Not decentralized.

Seems to me like it's easy to forget there's a difference between those two..

Re: Where Am I? NYTimes or Google?

#238

People have been railing against Google's Amp on HN for years, and I think I finally figured out what it's for. It's Google way of combatting phone apps. If all of the world's information — especially current news and similar information — moves from the open web into apps, then Google can no longer crawl, index, or scrape that information for its own use. The rise of the mobile phone app is a threat to Google on so…

That's long been Google's stated reason for Chrome and much else, that pushing the web forward as a platform aligns with their interests as well.

Re: Where Am I? NYTimes or Google?

#239

Earlier quoted context omitted.

> How does centralizing content on Google from multiple sources improve decentralization? It actually makes perfect sense in Doublespeak. /s

They’re suggesting a web technology which would allow any website to host content for any other website, under the original site’s URL, as long as the bundle is signed by the original site. That could be quite interesting of a site like archive.org, as the url bar could show the original url. But AMP is a much narrower technology, I’d imagine only Google would be able to impersonate other websites, essentially centra…

I think this is possible already, but should not override the displayed URL for the content.

Create a new “original URL” field or something.

Re: Where Am I? NYTimes or Google?

#240
post #211

Earlier quoted context omitted.

There is a publisher selected expiration date as part of the signed exchange which the client inspects. The expiration also cannot be set to more than 7 days in the future on creation. This minimizes, but of course does not eliminate, this risk.

It also makes signed exchanges completely unusable for delivering packages offline. (E.g. the USB stick scenario) What a bummer.

Browsers could have a setting to optionally display the content anyway, along with a warning to the effect of "site X is trying to show an archive of site Y", similar to how we currently handle expired or self-signed SSL certificates.
Post reply on HN