Live data from Hacker News

Apple adds a tracker blocker to desktop Safari

techcrunch.com

41–50 of 301 posts

Re: Apple adds a tracker blocker to desktop Safari

#41
post #29

This is great, but unfortunately, until Apple ups its browser security game, Safari is a non-starter. On macOS, switching from any other browser to Chrome is in the top 3 things you can do to materially improve your security in ways that actually matter in the real world.

I am curious to know why you say this considering Safari is just as sandboxed as Chrome?

Re: Apple adds a tracker blocker to desktop Safari

#43
post #40
post #27

The big question to me is whether it's enabled by default, and whether it blocks requests to Google Analytics. If so, that's an interesting shot across the bow.

This is actually really concerning to me. If they blocked Google Analytics, it would severely damage that data. It'd be bad news for site owners who just want to quantify their traffic.

Well, back to log files. Which may no longer work with the latest and greatest JS framework :(

Re: Apple adds a tracker blocker to desktop Safari

#44
post #37
post #29

This is great, but unfortunately, until Apple ups its browser security game, Safari is a non-starter. On macOS, switching from any other browser to Chrome is in the top 3 things you can do to materially improve your security in ways that actually matter in the real world.

Can you give specific examples why Chrome is significantly better than other browsers, including Firefox, Opera? Chrome is a non starter for me because of its resource usage and battery hunger. One specific area where Safari is better than Chrome is in private browsing mode. In Safari, each tab is completely separate, and the cookies aren't shared (as far as I can tell) whereas in Chrome, it's only separate as a whol…

Me too, I only use chrome for its built-in Flash support when a site requires it.

Re: Apple adds a tracker blocker to desktop Safari

#45
post #27

The big question to me is whether it's enabled by default, and whether it blocks requests to Google Analytics. If so, that's an interesting shot across the bow.

Speaking of shots across the bow, I'm surprised they've never put an ad-blocker in Safari.

Re: Apple adds a tracker blocker to desktop Safari

#46
post #41
post #29

This is great, but unfortunately, until Apple ups its browser security game, Safari is a non-starter. On macOS, switching from any other browser to Chrome is in the top 3 things you can do to materially improve your security in ways that actually matter in the real world.

I am curious to know why you say this considering Safari is just as sandboxed as Chrome?

No, it isn't.

Re: Apple adds a tracker blocker to desktop Safari

#48
post #29

This is great, but unfortunately, until Apple ups its browser security game, Safari is a non-starter. On macOS, switching from any other browser to Chrome is in the top 3 things you can do to materially improve your security in ways that actually matter in the real world.

While I'm not sure how effective they are on OS X, I have a hard time agreeing with any suggestion that Chrome is anything but the worst possible option for browser security right now. Chrome's official extension store is full of malware which collect not just your browsing data, but the contents of every page you view, and Google has shown almost zero interest in policing it. And a large percentage of malicious websites are designed to get users to install these malicious extensions.

Chrome may be relatively decent at preventing a webpage from compromising your OS, but in the modern era, a compromised browser is as bad or worse anyways, since that's where most of your sensitive activity goes.

While many HN readers will know to avoid the perils of this crud, I don't feel Chrome can be recommended over IE6 to the wider Internet while this remains so commonplace. Safe use of Chrome requires constant vigilance.

In light of Chrome's issues, I feel like a claim that switching to Chrome is important for security to require an exceptional evidence of vulnerability in the other browser.

Re: Apple adds a tracker blocker to desktop Safari

#49
post #25

It's unclear to me how these "trackers" work? How do they track you, is it cookies, or what?

A decent overview: https://panopticlick.eff.org/about Test your browser: https://panopticlick.eff.org/

That site is interesting, and it shows you that 1 of X browsers resemble a particular fingerprint ingredient.

I found this one rather interesting, it was the most unique of the ones listed:

HTTP_ACCEPT Headers

One in several thousand have the same headers as me. But the headers themselves are quite a small little string, I'm surprised it is that unique.

Re: Apple adds a tracker blocker to desktop Safari

#50
post #9

Earlier quoted context omitted.

> Does this mean browser fingerprint is somehow scrambled before it is sent to the tracker instead of blocking? It might be homogenized instead of scrambled. Every iOS device could be given (barring IP etc.) the same fingerprint.

I don't think that's even theoretically possible. How do you block JS font enumeration without crippling the browser font API?

Browsers already treat first-party cookies differently than third-party ones. Report a homogenized fingerprint to Google Analytics, but a real one to the main site.
Post reply on HN