Live data from Hacker News

Chrome is entrenching third-party cookies that will mislead users

brave.com

271–280 of 329 posts

Re: Chrome is entrenching third-party cookies that will mislead users

#271

Earlier quoted context omitted.

> Regarding analytics, I believe browsers should take user's side and do not cooperate with marketing companies Browsers were supposed to act as agents working for the user. User-agents. These days it's getting harder and harder to find a browser that doesn't work for an ad company at the expense of the user. Chrome's entire reason for existing is data collection. Firefox can, for now at least, be hardened to work fo…

> Mozilla is an ad-tech company too now. I'm sorry, this seems egregious. I agree that it should've been off by default but I challenge anyone to read how the implementation works (not just the blog post and the FUD responses to it) before calling it a giveaway to the ad industry: https://github.com/mozilla/explainers/tree/main/ppa-experime... FF is currently a key tool in the fight to avoid a Google-top-to-bottom fu…

Ultimately, the problem is that entire premise is deeply offensive. I do not want my browsing history being monitored, collected, sent to third parties, and sold to marketers in any form period. I do not want a browser using my data in any way to support surveillance capitalism.

The implementation is just FLoC/Topics API all over again and it's still not compelling. The first kick in the teeth comes right at the start where the entire thing is predicated on data gathered from having an ad shoved in your face.

> At impression time, information about an advertisement is saved by the browser in a write-only store. This includes an identifier for the ad and whether this was an ad view or an ad click.

I do not want ads. Ever. Like many (likely most) firefox users, I go to some lengths to prevent them from showing up in any form. Now that firefox is going to be profiting directly off of firefox users seeing and clicking on ads they will certainly degrade our ability to prevent them.

It then involves sending my data to third parties so that it can be aggregated. Then my browsing has to be monitored to identify conversion events. None of this is acceptable.

Here's what their Cookie Monster paper says:

> User perspective. Ann browses various publisher sites that provide content she is interested in, such as nytimes.com and facebook.com. Ann does not mind seeing relevant advertising, understanding that it funds the free content she enjoys.

I am not Ann. I very much mind seeing advertising, relevant or not. I do not understand that if funds "free content" I enjoy. If I need to be exploited to pay for something, that thing it isn't "free" and if it's infested with ads I do not enjoy it. The entire thing is based on a fantasy where users find this acceptable. We don't and it isn't. If we did, we'd probably all just be using chrome.

> FF is currently a key tool in the fight to avoid a Google-top-to-bottom future

Why should we care if Firefox isn't Google if both are just going to exploit us?

Re: Chrome is entrenching third-party cookies that will mislead users

#272

Earlier quoted context omitted.

Kind of wondering what you’re talking about here? Firefox still works great for me, did I miss something in the news? Is there some sort of big change coming down the pipeline?

Not OP, but Firefox didn't have to lose nearly all its market share to Chrome. Mozilla could have course corrected and righted the ship, but instead they got distracted on dozens of unrelated and often controversial projects and ended up burning most of their credibility. Mozilla is a husk of what it could have been, and that's hurt Firefox.

What, specifically, should they have done differently that would have made Firefox not lose most of its market share to Chrome, and how do you know it would have worked?

Re: Chrome is entrenching third-party cookies that will mislead users

#273
post #65

Earlier quoted context omitted.

> or your favorite websites won't work If my favorite websites stop working with Firefox, they won't be my favorite websites anymore. I'll just stop using them instead.

I'll just stop using them instead. Easily said, until it's your bank, or a government entity, or the electric company, or any of the thousands of other entities that have started blocking Firefox. Firefox should really camouflage its user agent, or make it trivial to do so.

I already need to camouflage my user agent because some websites broke on a Linux host running chromium or Firefox. Switching UA to windows fixed this.

I believe it was an analytic bug in Disney+, where they didn't except Linux to be an acceptable OS.

Re: Chrome is entrenching third-party cookies that will mislead users

#274
post #86

Earlier quoted context omitted.

Not to disagree with you specifically, but this seems a good context to make this point: Maybe I missed the memo that we stopped hating monopolies? Every browser worth considering, except Firefox and Safari, is based on Chromium. Firefox and Safari make up about 20% global market share, meaning Chromium in about 80% [0]. A bug in Chromium is a bug in all of them. A backdoor in Chromium is a backdoor in all of them. A…

Because it doesn't matter that much, as Chromium is open source, not to mention it did a fine job thus far in advancing the open web. I'd like Firefox to stick around, but as far as I'm concerned, if Safari goes away, I couldn't care less.

Sure, it's open source, but it's controlled entirely by Google. No work has been done on Chromium that Google hasn't wanted done.

Said another way, Chromium can not be updated to risk Google's business or profit.

Re: Chrome is entrenching third-party cookies that will mislead users

#275

Earlier quoted context omitted.

Firefox really has been going downhill for a long time. Forcing Pocket into the browser, the ad infested new tab page, telemetry, making user accounts a thing, force installing TV show promotions, etc. What they haven't done before is spend a fortune buying up an ad-tech start up. They barely even bother to maintain a pretense that they care about Firefox users. They basically came right out and said "We know that us…

> Forcing Pocket into the browser Fun fact: by subscribing to Pocket, you're directly contributing to Firefox's development. Mozilla found itself in a situation of damned if they do, damned if they don't . People scream at them for depending on Google, and then they scream at them for trying to diversify their revenue. Nobody wants to pay for a browser, browsers are essentially incredibly complex nowadays, and I have…

> Fun fact: by subscribing to Pocket, you're directly contributing to Firefox's development.

That's not true. It isn't directly supporting anything except surveillance capitalism. Allowing yourself to be exploited in that way may indirectly support Firefox, but it's not the same thing as direct support.

Firefox users have literally begged Mozilla to let them actually directly support Firefox's development in the form of donations explicitly for that purpose alone, but Mozilla has always refused to allow it.

> Mozilla found itself in a situation of damned if they do, damned if they don't. People scream at them for depending on Google, and then they scream at them for trying to diversify their revenue.

People scream at them when they involve themselves in surveillance capitalism so yeah, spending a ton of money that could have gone into firefox development to instead buy an ad company so they can start spying on us while we use the internet isn't helping.

> Nobody wants to pay for a browser, browsers are essentially incredibly complex nowadays, and I have yet to hear how in the world are browsers supposed to get funding.

Are web browsers more "incredibly complex" than linux? I don't understand how people assume that web browsers are impossible to develop without selling users to the marketing industry while somehow linux and countless other open source projects have never once needed to do that.

Mozilla could at the very least try letting users pay for firefox development like users have been asking them to before they jump to selling firefox users out to the ad industry.

> And of course they want to cater to advertisers because it is advertising that maintains the open web

Advertising doesn't maintain the open web, it poisons it.

> And the open web is also dying, because people have been moving to mobile apps,

That's because many people don't own even computers anymore. Even where computers haven't been entirely replaced by devices that are designed for data collection and mindless content consumption, the cell phone is the computer that people have with them at all times. The dire situation around computing in general wouldn't be so bleak if we could get some decent and affordable mobile devices that weren't designed to spy on us, but I guess you might see it as that spying being what maintains the computer industry.

Re: Chrome is entrenching third-party cookies that will mislead users

#276
post #154

Earlier quoted context omitted.

> Google analytics? Check. Add this to /etc/hosts 0.0.0.0 www.google-analytics.com 0.0.0.0 google-analytics.com 0.0.0.0 ssl.google-analytics.com

Firefox doesn't respect hosts by default. An about:config option needs to be toggled for this to work.

Fascinating. I wonder what the history is of Firefox deciding to ignore hosts? Hosts has been standard since the early days of the Internet.

Re: Chrome is entrenching third-party cookies that will mislead users

#277
post #81

Earlier quoted context omitted.

> Brave has received negative press for diverting ad revenue from websites to itself,[30] collecting unsolicited donations for content creators without their consent,[43] suggesting affiliate links in the address bar[49] and installing a paid VPN service without the user's consent.[58] These are the primary issues I hear about regarding Brave on this forum. It's also founded by Brendan Eich who was forced out of Mozi…

> "collecting unsolicited donations for content creators without their consent" Those "donations" were from handouts of BAT. What they "collected" was their own BAT that they've donated to users of Brave. And it wasn't long lived. At least they've been trying to create a business model that's privacy preserving and that benefits content creators. Firefox has been selling their users to Google for years. > "suggesting…

> when Mozilla engages in political activism, promoting Marxism?

The link you provide in support of this (https://blog.mozilla.org/en/internet-culture/chris-smalls-ri...) is an interview with Chris Smalls, a union organizer. It does not in any way promote Marxism.

(Smalls does at one point talk about "class struggle". He makes it explicit what he means: he thinks there is an opposition between "99.9% of us" and "the billionaires". This is not Marxism even though it uses one phrase that Marxists also use.)

> Or when they promote cancel culture?

The link you provide in support of this (https://blog.mozilla.org/en/mozilla/we-need-more-than-deplat...) is to a blog post titled "We need more than deplatforming". It mentions deplatforming but doesn't advocate it (though it doesn't condemn it either), and the actual things it calls for are all Not Cancel Culture: "reveal who is paying for advertisements", "commit to meaningful transparency of platform algorithms", "turn on by default the tools to amplify factual voices over disinformation", "work ... to facilitate in-depth studies of the platforms' impact on people and our societies".

You might reasonably disagree with those proposals; for instance, the next-to-last one could be anywhere from "excellent" to "dystopian" depending on what exactly "amplify X over Y" means and how "factual" versus "disinformation" is decided. But none of it is advocating cancel culture.

As for the "deplatforming" in the title: the specific case it's talking about is the idea that a social media platform should ban a particular user who had for some time plainly been breaking the platform's rules, and who (according to some) had used the platform to attempt to organize an antidemocratic coup. "Social media platforms should be encouraged to ban users who blatantly break their rules, even when those users bring them a lot of traffic" and "Social media platforms should not let themselves be tools for antidemocratic insurrection" are positions one can take without being a fan of "cancel culture".

(Not necessarily correct positions. E.g., if you hold that the insurrection in question was not antidemocratic, that it was a response to blatant election-rigging, then you will likely take a quite different view of how a social media platform should respond to it. I don't myself think that's a credible position, and I doubt the good faith of most of the high-profile people who endorse it, but I know it is something many people believe. Anyway, my point isn't that those positions are right, it's that they're positions many reasonable people take, and that getting from those to "Twitter was right to kick Donald Trump off" doesn't require any sort of endorsement of "cancel culture", and that therefore the fact that an article mentions the possibility of doing that in a not-obviously-disapproving way does not amount to "promoting cancel culture".)

Re: Chrome is entrenching third-party cookies that will mislead users

#278
post #75

Earlier quoted context omitted.

I'll just stop using them instead. Easily said, until it's your bank, or a government entity, or the electric company, or any of the thousands of other entities that have started blocking Firefox. Firefox should really camouflage its user agent, or make it trivial to do so.

> Easily said, until it's your bank, or a government entity, or the electric company Still easily said, since I don't use the websites for any of those things anyway. If it's really important, or involves very sensitive personal information, I'm not doing it on the web. > or make it trivial to do so. There are extensions that make this very trivial.

> If it's really important, or involves very sensitive personal information, I'm not doing it on the web.

It's definitely a position you can take, but that's a very minority position among web users these days.

For the rest of us, "Just stop doing it on the web" would be a pretty substantial lifestyle change and, practically speaking, not worth it.

Re: Chrome is entrenching third-party cookies that will mislead users

#279
post #215

Earlier quoted context omitted.

No, that is not the entire point of DoH. That’s like saying the entire point of TLS is to prevent users from looking at the traffic being sent to a website. DNS without DoH, DoT, or DoQ, is wide open to anyone snooping traffic in the raw, that’s not necessarily information you want to share with the world.

DoH is pushed by goggle et al to ensure you continue to provide your data to them. The browser should respect the OS. The OS should respect the network (dhcp/slacc). If you want to override this then that should be an active choice by the user. I am quite happy with my OS using normal dns (via WireGuard when out) to my dns server which blocks bad domains before they even reach my firewall, I don’t need DoH, although…

DoH is necessary because ISPs snoop on DNS traffic and meddle with it. DNS is sendig everything in clear text and has no protection from modification.

As for DoH, you can choose not to use it, or use your own DoH server. I see no problems with it.

Re: Chrome is entrenching third-party cookies that will mislead users

#280

Earlier quoted context omitted.

Excluding leaks, the ISP does not see the hostnames, what it sees are the IPs you're connecting to. 20% of internet traffic goes through Cloudflare, so at least for those, the IPs are meaningless. Both privacy and security are layered, and perfect is the enemy of good. Securing the DNS is an obvious first step, forcing the Internet to HTTPS by default was another. Google and Mozilla have contributed to better privacy…

> Excluding leaks, the ISP does not see the hostnames Unfortunately they can, either through the unencrypted hostname passed in SNI or in the cert returned by the server .

In TLS 1.3 server certs are encrypted. And while browsers support ECH (Encrypted Client Hello) to encrypt SNI, almost no server supports it. Cloudflare has ECH disabled globally for some "issues" they do not disclose [1].

[1] https://developers.cloudflare.com/ssl/edge-certificates/ech/

Post reply on HN