Live data from Hacker News

Apple adds a tracker blocker to desktop Safari

techcrunch.com

281–290 of 301 posts

Re: Apple adds a tracker blocker to desktop Safari

#281

Earlier quoted context omitted.

So you're saying that privacy is impossible? If that's true, then I'd rather go down fighting (no matter how futile that is) than willingly give up any more private information to Google. I think the time for pragmatism when it comes to privacy is long over.

I'm saying what I said: if your browser isn't adequately secure, all the anti-tracking features don't much matter, because the people you really need to worry about will be able to own up your entire machine and quietly persist themselves into it.

> because the people you really need to worry about

I think we disagree who to really worry about. I worry more about persistent low-level corporate surveillance more than hacker attacks because while the latter is more acute and can cause great financial harm, the former is whats going to damage my freedom and right to privacy once the government decides it wants to firehose all that data.

Re: Apple adds a tracker blocker to desktop Safari

#282
post #270

Earlier quoted context omitted.

Apple Pay is a generation ahead of chip and pin. It obviates the need to enter a PIN which is more convenient and invulnerable to attacks on PIN terminals, which have defeated chip and pin in the past.[1] [1] https://en.m.wikipedia.org/wiki/EMV

What about contactless cards? I personally find contactless cards, common in the UK, much more convenient than having to faff about with my phone, which may be out of battery.

My understanding is that contactless cards have limit of £30 per transaction in the UK. Apple Pay (perhaps it's the same with Android Pay?) has a significantly higher limit.

Re: Apple adds a tracker blocker to desktop Safari

#283
post #173

Earlier quoted context omitted.

You are actually incorrect. Tracking Protection refers to an IE feature that lets you set "Tracking Protection Lists", which block traffic to specified domains and URLs. You can see a bit about them here: https://msdn.microsoft.com/en-us/library/hh273400(v=vs.85).a... The whole "Do Not Track" default thing was, of course, a huge fiasco, as Google and others chose to ignore IE's default usage of it.

I don't know why this has been downvoted. Tracking Protection Lists are one of the best and unsung features of IE. People don't realize that they're different from Do Not Track.

Do you have to set it up manually? How is this better than downloading one of the privacy-protecting extensions available for most desktop browsers?

Re: Apple adds a tracker blocker to desktop Safari

#284
post #231
post #47

Earlier quoted context omitted.

Internet Explorer has tracking protection since IE9.

Most sites don't obey the do not track header. Edge on the other hand is much more nefarious, by default it sends all data sent by POST requests to Microsoft. I was surprised to find Bing sending data from people who use Edge on my site to try and improve their search results. There are so many security and privacy issues with this it's not funny at all.

I've never heard that Edge sends absolutely all POST requests to any website to Microsoft as well. Could you share an article or something proving this?

Re: Apple adds a tracker blocker to desktop Safari

#285
post #271
post #265

Earlier quoted context omitted.

I recently realised that any company taking on Google (e.g. Apple, Mozilla, ...) that is afraid they won't be able to take them on in areas like machine learning or sheer size, is realising, rightfully so, that being pro-privacy is the one thing they can compete on with Google that Google will never be able to imitate. Pretty sweet, actually.

I think a big thing about AI with Apple is the fact that their stance on privacy makes it a bit harder to compete with the harvested data sets of Google. From what I understand though, according to the reactions on the papers they released a bit back, they're not doing so poorly. That being said, and I've never used Cortana or Alexa, but I hear they're pretty decent compared to Siri.

Exactly, I think they figure that if they have to harvest data themselves and try to beat Google at its own game, they have a larger chance of losing than if they concede on quality by not harvesting data (as much), but try to offset that by being privacy-conscious. And yeah, perhaps they'll still be able to do a pretty decent job that might not give them too much of a disadvantage compared to Google. You often see, I think, that with a few years delay many machine learning advancements can be reproduced offline.

Re: Apple adds a tracker blocker to desktop Safari

#286

Sounds like this is more in line with what they did with ApplePay vs traditional credit cards--I.e. They give you randomized IDs each time so the other party can't track you from transaction to transaction. Adds can still appear but they won't know who you are, so it's a direct shot at Google and others looking to give people "targeted" adds based on user behavior. I agree it's an issue that needs addressed. Just bec…

I've had that problem before as well. My wife was going to Mexico and looking for a new swimsuit, and so I was hitting up the SwimCo website. Cue three months of women's swimwear ads from SwimCo – and nothing else . Almost every single ad on every single page was the same ad in different shapes, all of them for SwimCo. Recently too I've noticed that Amazon is putting ads in my Instagram feed for specifically things t…

Whats worse is when colleagues at work can look over your shoulder and see everything you are considering buying. Luckily for me my purchasing habits are pretty mundane, but I can imagine this could get quite embarrassing for people shopping for more risky items.

Re: Apple adds a tracker blocker to desktop Safari

#287
post #242
post #195

Looks like this will stop (after 24 hours) some companies from doing an initial redirection to set cookies for tracking purposes... Example: 1. Search Google for hockey sticks 2. Click on search result hockeystick.com 3. hockeystick.com issues a 302 to adcompany.com which then issues a 302 back to hockeystick.com Why the 302? Because in Safari, you could only access cookies in a 3rd party context if you've seen a dom…

Won't the browser show an error about a circular redirect? Or does that take a few bounces?

The URLS would be different. Companies also rewrite internal links as you're navigating a site to accomplish the same thing. Example: https://baycloud.com/thirdparty-redirect

Re: Apple adds a tracker blocker to desktop Safari

#288
post #270

Earlier quoted context omitted.

What about contactless cards? I personally find contactless cards, common in the UK, much more convenient than having to faff about with my phone, which may be out of battery.

My understanding is that contactless cards have limit of £30 per transaction in the UK. Apple Pay (perhaps it's the same with Android Pay?) has a significantly higher limit.

25 € in Austria. But for higher amounts you can still just hover the card above the terminal and then enter your PIN instead of sticking the card in (at least at some stores).

Re: Apple adds a tracker blocker to desktop Safari

#289
post #286

Earlier quoted context omitted.

I've had that problem before as well. My wife was going to Mexico and looking for a new swimsuit, and so I was hitting up the SwimCo website. Cue three months of women's swimwear ads from SwimCo – and nothing else . Almost every single ad on every single page was the same ad in different shapes, all of them for SwimCo. Recently too I've noticed that Amazon is putting ads in my Instagram feed for specifically things t…

Whats worse is when colleagues at work can look over your shoulder and see everything you are considering buying. Luckily for me my purchasing habits are pretty mundane, but I can imagine this could get quite embarrassing for people shopping for more risky items.

Indeed. It was especially awkward after I searched for "Willy Wonka costume", which prompted Amazon to also show me the results for "Willy costume". Some of those items were then clearly visible in almost every Amazon ad and recommendation I received during the next couple of months.

Re: Apple adds a tracker blocker to desktop Safari

#290
post #175

Earlier quoted context omitted.

My contention was that Safari is less safe than Chrome, not that Safari's sandbox was in particular worse than Chrome's. Nevertheless, on balance, Safari's sandbox is significantly worse than Chrome's. I think --- but you'd know better than I would --- that this is because browser security is a platform problem for Apple, and an application problem at Google. Apple's platform-level mitigations are very powerful on iO…

You actually did make a claim that Safari's sandbox was in particular worse than Chrome's, in the post I directly replied to. That is what got my dander up. Elsewhere you implied that the Safari sandbox comparable to the Java sandbox. I hope you will now agree that the Safari sandbox is closer to Chrome's than to Java's. I don't know enough about the full spectrum of security technologies in all the browsers to have…

Sorry for the delayed response. Also: I have to be terse about some of these things for work reasons.

First, regarding isolation: using the same OS facility to block system calls is a superficial similarity between Chromium and Safari. Chromium and Safari are divided into process components differently, and block different system calls. Chromium exposes much less to its renderer process than Safari does to WebProcess. Not only that, but Chromium has finer-grained components; the GPU isn't exposed to Chromium renderers the way it is to Safari WebProcesses. This isn't a theoretical difference, as you know (but readers here don't): IOKit has been a source of WebProcess sandbox escapes for Safari. Safari isolates the network process and Chrome doesn't, but the network process is a low-priority attack surface. The highest priority attack surface is the one reachable directly from content-controlled Javascript. You say Chromium's edge over Safari is "small overall". We agree that the edge exists, but I strongly disagree that the delta is small.

We agree on anti-exploitation. In fact, if Safari got better here, I'd be less nervous about people running Safari. What are the plans here? The combination of (1) general purpose operating system, (2) rich attack surface exposed to WebProcess, and (3) lack of serious runtime hardening is most of my argument against using Safari. The rest of this list is "nice to have" stuff.

Regarding UX: Chromium has a well-regarded security UX team. Does Apple staff a dedicated security UX team for Safari? Chromium supports U2F natively. When will Safari? I think Chromium, Safari, and Firefox are closer together here than the browsers are on other facets of this list; I don't think Safari does a bad job here, just not as good of a job as Chromium.

Regarding TLS: Adopting Google's BoringSSL library is a fine start and I know Apple has strong crypto people on the Secure Transport team. But does Safari support HPKP? (If so, when did that happen?) Why is it virtually always Google's TLS team detecting and punishing rogue CAs? What CA BR violations were detected by the Safari team, or any other team at Apple? Has Safari done anything like the Google PQ handshake experiment? It feels a little unfair holding Apple to the standard of what is basically the most sophisticated Web PKI team on the planet, but that's a real part of browser security.

Regarding "Library Security": I don't know what to call this item and so I'm not surprised that you're confused, but: how does Apple's work fuzzing and doing vulnerability research in the underlying libraries that the browser depends on compare to Google's work doing the same thing? I think we both know the answer: nothing Apple is doing is close to what Google's in-house offensive researchers are doing. Apple benefits from the work Google does here and so can draft off Google's team here, but Google prioritizes their in-house offensive work to help Chromium.

I could make a similar scorecard for iOS versus Android and I think you'd see the reverse on these rankings, with Apple in the lead on basically everything. But browser security isn't hardware security, and on macOS, I don't think Safari and Chrome are close. I think Chrome is significantly more secure.

Post reply on HN