Earlier quoted context omitted.
What browser do you use?
Until they pulled this recent spying stuff I was a firefox user, but now I'm testing librewolf, zen browser, and brave. I might give Basilisk a try too. I'm also keeping an eye on ladybird but it looks like it isn't really ready yet. Ultimately on the desktop I'll need something based on firefox because it can be hardened better than anything else I've seen and my work has me regularly dealing with some nasty website…
Chrome is entrenching third-party cookies that will mislead users
301–310 of 329 posts
Re: Chrome is entrenching third-party cookies that will mislead users
#302Earlier quoted context omitted.
> FWIW, it's practically impossible to provide that guarantee because the API necessarily provides at least the data point of, "Did they select an option in the permission notification?" ("If yes, what option was selected?" etc.) Wrong. The status of permissions should not be visible to the page in most cases. Instead, fake data should be returned from them. That would be practical.
It's always better to give no data (aside from leaving them with "we couldn't collect that data") than it is to give fake data because that fake data will be used against you just as often as real data would. Don't hand companies extra ammo to use against you, or think that you're safe just because they've written an incorrect assumption about you on the bullet. You're still going to be taking the hit.
To your point, unfocused fake data can be harmful to the faker but it seems focused fake data can work against the collectors.
Re: Chrome is entrenching third-party cookies that will mislead users
#303This is a tough situation. Yes, this can, and will, be abused for tracking users across domains that they don't expect to be related. But there are also legitimate use cases for this. For example, consider the stackexchange family of sites. They are clearly related, have a unified branding, etc. but are on separate domains. On Firefox, which blocks third party cookies, I have to log in to each of those domains separa…
However they could solve this "problem" in a number of ways, the most straightforward being to use subdomains instead of individual domains.
I put "problem" in quotes as it's not even a problem; it's browsers working as intended. When you visit different domain names, you should expect that your browser won't be aware of data (cookies) stored by other domains.
Re: Chrome is entrenching third-party cookies that will mislead users
#304Earlier quoted context omitted.
> Regarding analytics, I believe browsers should take user's side and do not cooperate with marketing companies Browsers were supposed to act as agents working for the user. User-agents. These days it's getting harder and harder to find a browser that doesn't work for an ad company at the expense of the user. Chrome's entire reason for existing is data collection. Firefox can, for now at least, be hardened to work fo…
> Mozilla is an ad-tech company too now. I'm sorry, this seems egregious. I agree that it should've been off by default but I challenge anyone to read how the implementation works (not just the blog post and the FUD responses to it) before calling it a giveaway to the ad industry: https://github.com/mozilla/explainers/tree/main/ppa-experime... FF is currently a key tool in the fight to avoid a Google-top-to-bottom fu…
Right now is actually Safari that prevents it, like it or not. Especially iOS one where users have to use it. Firefox is rounding error in this fight.
Re: Chrome is entrenching third-party cookies that will mislead users
#305Earlier quoted context omitted.
> As someone who worked both on advertiser and publisher sides (incl. content monetisation): advertisers like to say that they support publishers and the open web, but in fact, they are keeping it hostage. I know what you're saying, I agree, as I worked (in the past) on advertising platforms as well, but both of those statements can be true at the same time. The open web was built on advertising, but the perverse inc…
> micro-transactions are not possible given the huge banking fees Cryptocurrencies like Litecoin have low transaction fees (currently less than a cent). Apple somehow manages to sell apps that cost just several bucks. Also, in Russia, a Fast Payment System allows transfers up to $1000/months without commission, however these terms are available only to personal transfers and not for business. But it shows that low-co…
Apple (literally the single wealthiest company on the planet) "somehow" manages to sell inexpensive licenses to primarily ad- and surveillance-financed agents that infest end-user hardware through a marketplace that probably acts as a loss-leader for them to sell said hardware to begin with.
And "transfers of up to $1k/mo without commission"? (Why is that quoted in USD instead of Rubles?) Venmo, Zelle, Paypal, and countless other services in the US allow you to transfer $1k/mo and more without fees to other people using the same system and with a lot of friction to get money back out of said system. And the fees are still "only free to friends/family" specifically because you only need chargeback protection when paying to a business.
Re: Chrome is entrenching third-party cookies that will mislead users
#306Earlier quoted context omitted.
Firefox doesn't have ECH support (atleast not turned on by default) https://privacytests.org/ (Scroll down to Misc tests)
I observed Firefox sending ECH extension in ClientHello, maybe I just enabled it in the settings, so Firefox supports ECH (on by default since version 119). However, virtually no servers support ECH now. Not Google, not Hackernews, not Cloudflare etc. This seems to be a not very good comparison, and it looks like it cherry-picks convenient for a certain browser points and ignores others. Look at "fingerprint protecti…
FWIW the about section says this: "Each privacy test examines whether the browser, on default settings, protects against a specific kind of data leak."
The maintainer is a Brave employee and this is a project they were already doing before joining Brave. I'm hoping that they aren't manipulating it in favor of Brave.
I sent those three options as a feature request. Do you think the site is still useful in some capacity?
Re: Chrome is entrenching third-party cookies that will mislead users
#307Earlier quoted context omitted.
ISPs seeing the domains of user traffic is not a given. And DoH is a step toward mitigating that. People were setting their DNS resolver to custom values before DoH. I agree that DoH would ideally be enabled at the OS level, or that the browser flow would default to still checking host file before sending out the query.
Unless you are using an VPN, your ISP can see the IPs you are communicating with regardless of the hostnames associated with them and in turn resolve those back to hostnames or at least netblock owners.
Re: Chrome is entrenching third-party cookies that will mislead users
#308Earlier quoted context omitted.
> Easily said, until it's your bank, or a government entity, or the electric company Still easily said, since I don't use the websites for any of those things anyway. If it's really important, or involves very sensitive personal information, I'm not doing it on the web. > or make it trivial to do so. There are extensions that make this very trivial.
> If it's really important, or involves very sensitive personal information, I'm not doing it on the web. It's definitely a position you can take, but that's a very minority position among web users these days. For the rest of us, "Just stop doing it on the web" would be a pretty substantial lifestyle change and, practically speaking, not worth it.
> For the rest of us, "Just stop doing it on the web" would be a pretty substantial lifestyle change
It really isn't, though, at least not for most people I know who aren't into tech. It would certainly mean changing some habits, which is often hard, but (at least in the US) it means giving up a relatively small amount of convenience, not a substantial lifestyle change.
Re: Chrome is entrenching third-party cookies that will mislead users
#309Earlier quoted context omitted.
BAT was what kept me from trying Brave for a very long time, but I eventually tried it nonetheless (I'm back on Firefox now). In fairness to Brave, you can disable the BAT stuff and never have to see it.
The BAT stuff is entirely opt-in, not opt-out.
Re: Chrome is entrenching third-party cookies that will mislead users
#310Most people here seem to forget that ads is what pays for the free internet services. The main issue with them is not making the consent more explicit to the user. I think the business model: you either get this for free with ads and targeting, or otherwise you have to pay X, should be more common. I bet most people would pick the free option with ads and targeting.
Nobody forgets that, and the issue (at least for me) isn't the ads, it's the spying. It's entirely possible to have a financially healthy ad ecosystem without the spying. It used to be the norm, even.