Earlier quoted context omitted.
As far as I can determine, Incognito mode just creates a 2nd sandbox for cookies and history that's shared across all Incognito tabs/windows, and is only deleted once you close them all. Cookies you create in one Incognito tab or window are visible to all other Incognito tabs/windows, just as cookies created in plain tabs/windows are visible to all other plain tabs/windows. So if you go into Incognito mode and browse…
> what I'd really like is a Chrome extension like Firefox's CookieSafe, where I can block all cookies by default and then whitelist them back in on a site-by-site basis, but nothing like that exists at the moment. Wait what? That functionality is built into Chrome, and you configure it in the same place that you toggle deletion of all cookies on exit. What you describe above is exactly how I browse in Chrome. No exte…
Google Removes Cookie Control from Chrome
61–70 of 70 posts
Re: Google Removes Cookie Control from Chrome
#62Earlier quoted context omitted.
...Or a different browser. Seriously, though, Google is used to web development, where they control the software and the machines running it. A new version of GMail rolls out, and everyone gets it. Like in the case of Buzz, this isn't always good, but it makes developers' lives easier. But desktop applications are a different game. Almost any time you take control away from the user, it's bad. New version of the brow…
Users of b2c software are incapable of making decisions about their security, and should not be asked to.
In either case, the Right Thing was discovered long, long ago: sensible defaults. Users who don't understand the software needn't worry, and those that know what they're doing can make the appropriate decision.
It bugs me to no end when developers take this parental tack with users, as if we were not only responsible for producing the software, but also for ensuring the user doesn't do anything to harm themselves. Put an are-you-sure dialog box in the way, but don't try to force anything on your users. Even if you know better, you're over-stepping and your second-guessing of the user is misguided.
Re: Google Removes Cookie Control from Chrome
#63Let's assume you're a very "privacy conscious" person who only accepts cookies for sites where you feel they are necessary -- say ones where you're going to login, or you really want to read articles there and you can't without the cookies, or whatever. Under Firefox (and Chrome under the old modality) your cookie setting choice was "Block but notify on new cookies."
Under the old model, when you first tried to access that site, create an account, login, register, etc., you'd get the initial pop-ups that you needed to respond to, that made it very clear that there were cookies involved now that you might want to accept. This is in fact a modal decision, because not accepting those cookies at that point will have consequences (like registration sequences that keep repeating, login prompts that won't accept your input, and so on).
Now the new model. As you browse the Web the little cookie icon is constantly popping up in the bar. Sometimes it shows clear and sometimes it shows blocked -- but after a while you're just going to ignore it as you go flying from page to page. There's nothing in that icon to alert the user that they've reached an important decision point about an initial cookie from a site. Even if they think to click that icon at the right moment on a new site, they have to do more clicking to dig down into the cookie management system to accept it if they wish to.
Old model: You're on a page where you want to login. You get a pop-up that there's a cookie. One click on Yes. Finished. Easy to do, and impossible to miss that there's a key decision point.
You really do want people to make a go/no-go decision on initial cookies from sites, and not create a situation where they can easily go winging by those initial cookies and have them fall into a default blocked state -- since the consequences of doing this are a mess and require going in and deleting cookie blocks manually.
It's really initial presentation of first cookies on a new site (when the user is defaulting to blocking cookies) that is the major concern. In that situation, the user should be presented with a modal choice so that they cannot easily miss the fact that they are at an important "exception" decision point -- that is, accepting a cookie when their default is not to accept all cookies.
And remember, by not choosing the simpler "accept all cookies" option, the user has already demonstrated that they have concerns in this area, and are likely to be very accepting of UI sequences that make it easier for them to function within that choice with a minimum of confusion or risk of not noticing new initial cookie decisions for a site.
Sorry about any formatting nasties in this response -- I copied most of it in from a text-based e-mail.
Thanks.
--Lauren-- lauren@vortex.com http://lauren.vortex.com
Re: Google Removes Cookie Control from Chrome
#64Any contradictory reports? Thanks.
Re: Google Removes Cookie Control from Chrome
#65Earlier quoted context omitted.
This is how Chrome has worked since forever, and it's a good thing. Asking the user for confirmation for security updates leads directly to users running known-insecure versions of software. If you don't want auto-updates, use Chromium.
...Or a different browser. Seriously, though, Google is used to web development, where they control the software and the machines running it. A new version of GMail rolls out, and everyone gets it. Like in the case of Buzz, this isn't always good, but it makes developers' lives easier. But desktop applications are a different game. Almost any time you take control away from the user, it's bad. New version of the brow…
Right, that's why the App Store has been a huge flop, and its closed model isn't being duplicated by everyone who's making an OS these days as fast as they can run their copy machines.
(Yes, I know that the App Store does prompt users for updates, but in all other respects it's a much more tightly controlled system than PCs, and users love it.)
Re: Google Removes Cookie Control from Chrome
#66Earlier quoted context omitted.
As far as I can determine, Incognito mode just creates a 2nd sandbox for cookies and history that's shared across all Incognito tabs/windows, and is only deleted once you close them all. Cookies you create in one Incognito tab or window are visible to all other Incognito tabs/windows, just as cookies created in plain tabs/windows are visible to all other plain tabs/windows. So if you go into Incognito mode and browse…
> what I'd really like is a Chrome extension like Firefox's CookieSafe, where I can block all cookies by default and then whitelist them back in on a site-by-site basis, but nothing like that exists at the moment. Wait what? That functionality is built into Chrome, and you configure it in the same place that you toggle deletion of all cookies on exit. What you describe above is exactly how I browse in Chrome. No exte…
Re: Google Removes Cookie Control from Chrome
#67Earlier quoted context omitted.
As far as I can determine, Incognito mode just creates a 2nd sandbox for cookies and history that's shared across all Incognito tabs/windows, and is only deleted once you close them all. Cookies you create in one Incognito tab or window are visible to all other Incognito tabs/windows, just as cookies created in plain tabs/windows are visible to all other plain tabs/windows. So if you go into Incognito mode and browse…
As far as I can determine, Incognito mode just creates a 2nd sandbox for cookies and history that's shared across all Incognito tabs/windows, and is only deleted once you close them all. Cookies you create in one Incognito tab or window are visible to all other Incognito tabs/windows, just as cookies created in plain tabs/windows are visible to all other plain tabs/windows. Not entirely. The basic test I performed in…
Right, I can reproduce this behavior. This much works.
If I was to open a link in a new tab from the logged in Incognito tab, that new tab would inherit the session from the parent tab, but opening a new window or tab and manually navigating to that site forces the site to create a new session.
This behavior I cannot reproduce. Here is what I see:
* Open Chrome. My configuration removes cookies at exit, so I'm in a fresh session with no cookies yet defined.
* Open a new Incognito window with Command-Shift-N. Login to Gmail in this new Incognito tab.
* With the Incognito window as the focus, create a new tab with Command-T.
* In the new Incognito tab, navigate manually to http://google.com/. In this new tab, I'm still signed in to Google with same account I used to login to Gmail.
* Make the standard/plain (non-Incognito) window my focus. Create a new Incognito window with Command-Shift-N.
* In the tab in the new Incognito window, navigate to http://google.com/. In this tab, I'm still signed in to Google with the same account I used to login to Gmail.
So I'm only seeing 2 cookie contexts: one for standard tabs and one for Incognito tabs, regardless of how they're created.. For the record, I'm using the beta channel (currently on 6.0.472.63, Chrome wants me to restart so I'll be on 7).
Re: Google Removes Cookie Control from Chrome
#68Earlier quoted context omitted.
...Or a different browser. Seriously, though, Google is used to web development, where they control the software and the machines running it. A new version of GMail rolls out, and everyone gets it. Like in the case of Buzz, this isn't always good, but it makes developers' lives easier. But desktop applications are a different game. Almost any time you take control away from the user, it's bad. New version of the brow…
> Almost any time you take control away from the user, it's bad. Right, that's why the App Store has been a huge flop, and its closed model isn't being duplicated by everyone who's making an OS these days as fast as they can run their copy machines. (Yes, I know that the App Store does prompt users for updates, but in all other respects it's a much more tightly controlled system than PCs, and users love it.)
Re: Google Removes Cookie Control from Chrome
#69Earlier quoted context omitted.
> what I'd really like is a Chrome extension like Firefox's CookieSafe, where I can block all cookies by default and then whitelist them back in on a site-by-site basis, but nothing like that exists at the moment. Wait what? That functionality is built into Chrome, and you configure it in the same place that you toggle deletion of all cookies on exit. What you describe above is exactly how I browse in Chrome. No exte…
There's really a night and day difference between CookieSafe style cookie management and what Chrome offers in terms of usability. CookieSafe is much nicer and no Chrome extensions seem to offer anything similar.
Re: Google Removes Cookie Control from Chrome
#70Earlier quoted context omitted.
I know you weren't asking me, but I have a similar setup. I block everything by default and only enable specific cookies when necessary for functionality. Same with javascript, which Chrome makes pretty easy. I don't have any specific reason except that it feels cleaner not to send a bunch of data over the wire that isn't really necessary.
So, how do you do that then? Some extension I assume?