Live data from Hacker News

Mozilla says Chrome’s latest feature enables surveillance

howtogeek.com

71–80 of 122 posts

Re: Mozilla says Chrome’s latest feature enables surveillance

#71
post #63
post #42

Earlier quoted context omitted.

> This can easily be abused for stalkerish behavior Well, sure. Any away/active status can be used for bad things. Pretty much any form of text communication can, too. We all opt in and out of things according to our level of comfort, like with the permission prompt this API provides.

Why not add an API to allow servers to request your contact information and creditworthiness? You can just opt out if you're not comfortable with it.

That API already exists, and you can't opt out of it. Every one of the credit reporting agencies provides some variant of it to banks, right now.

Somehow, we all sleep at night anyway.

Re: Mozilla says Chrome’s latest feature enables surveillance

#72
post #19

I am a privacy-conscious person but I really wish these debates could be a little more nuanced. This API is behind a permission prompt that can only be triggered in response to a user gesture, so the bar to entry is high. The example on web.dev is a chat app that would automatically set an active/away status: seems useful! IMO I ought to have the ability to cash in some of my privacy chips (so to speak) on a site tha…

Yeah, explicit confirmation is nice.

However this is assuming Chrome won't have a whitelist of favoured domains that can bypass permission prompts like it has for other features (audio auto-play, and I believe also some VR-functionality, probably other things on top since I last checked). I gave the linked pages a quick look but it looks like the feature is still being worked on, and...I'm too tired to look through draft spec documents right now...

Re: Mozilla says Chrome’s latest feature enables surveillance

#73
post #3

As long as you're asked for permission I don't see the problem

"Sorry! Looks like something went wrong. In order to use our site you'll have to enable idle tracking. This helps us improve our software for customers like you!"

Hey, if they want their app to suck, I have alternatives.

Re: Mozilla says Chrome’s latest feature enables surveillance

#74
post #58
post #54

Earlier quoted context omitted.

But this isn't adequate for the IM use case at all? I spend the bulk of my time not focused on my chat app tab(s) but I definitely want to be reported as 'available' by those chat apps, because I am if someone messages me.

That usecase could just as easily be solved through this novel concept called "manual override".

Or you could manually message each of your contacts to let them know when you are available. Or you could physically show up at people's houses to let them know that you are available to talk.

There is always a less convenient and more manual way. Pointing that out helps no one.

Re: Mozilla says Chrome’s latest feature enables surveillance

#75
post #63
post #42

Earlier quoted context omitted.

> This can easily be abused for stalkerish behavior Well, sure. Any away/active status can be used for bad things. Pretty much any form of text communication can, too. We all opt in and out of things according to our level of comfort, like with the permission prompt this API provides.

Why not add an API to allow servers to request your contact information and creditworthiness? You can just opt out if you're not comfortable with it.

The first one is just Autofill. I already have that, why should I be scared of it?

Re: Mozilla says Chrome’s latest feature enables surveillance

#76
post #59
post #21

Earlier quoted context omitted.

Usually the W3C spec for new features like this will contain a few paragraphs outlining intended use cases. In this case: > Making these distinctions is important for applications which have the option of delivering notifications across multiple devices, such as a desktop and smartphone. Users may find it frustrating when notifications are delivered to the wrong device or are disruptive. For example, if they switch f…

giving the users explicit control over where their messages are sent is a good idea. being spied on supposedly so the system can decide where to send you messages is a bad idea.

An opt-in system to allow idle detection is an explicit control. It shouldn't be the only option, but denying that it should be an option at all feels a little infantilizing.

Re: Mozilla says Chrome’s latest feature enables surveillance

#77
post #54

Earlier quoted context omitted.

> The example on web.dev is a chat app that would automatically set an active/away status: seems useful! I have an alternative way to do this. Check if a user hasn't interacted with your text box in x period of time. If they haven't, set them to away. I'm sure people can come up with other methods too. It just seems like there's a thousand ways to skin this cat that don't have the same potential for privacy issues.

But this isn't adequate for the IM use case at all? I spend the bulk of my time not focused on my chat app tab(s) but I definitely want to be reported as 'available' by those chat apps, because I am if someone messages me.

So after 20 minutes instead of logging you out the away status is set.

Not sure I understand your special case here.

Re: Mozilla says Chrome’s latest feature enables surveillance

#78
post #19

I am a privacy-conscious person but I really wish these debates could be a little more nuanced. This API is behind a permission prompt that can only be triggered in response to a user gesture, so the bar to entry is high. The example on web.dev is a chat app that would automatically set an active/away status: seems useful! IMO I ought to have the ability to cash in some of my privacy chips (so to speak) on a site tha…

No web page needs this feature. If we think they do then we’ve missed the turn off somewhere. A web page is for consumption and not being spied on.

Re: Mozilla says Chrome’s latest feature enables surveillance

#79
post #32

Earlier quoted context omitted.

You know who loves to use this feature? Recaptcha! When browsing Firefox in Incognito mode with uBlock Origin and uMatrix fully active, the Recaptcha challenges load painfully slowly. Like each picture might take upwards of five seconds to refresh. And to my delight, I have noticed that if I flip away from that tab while the panels are refreshing, they pause until I bring the tab back into active focus. It's a slap i…

I see the same thing on the chase.com web site. When I log into my account, it starts up some react or angular type bullcrap that takes literally 5-10 seconds to fully load no matter what computer I'm on or what browser I'm in. If I switch away to another tab to do something else while it's doing that, _it will never fully load_. The only option is to sit there with the tab open and stare at it until my account infor…

I actually use a dedicated browser for the likes of banks. Firefox is what I use for it only. All else I use Vivaldi.

Re: Mozilla says Chrome’s latest feature enables surveillance

#80
post #3

As long as you're asked for permission I don't see the problem

It’ll find a workaround that causes you to be asked permission constantly so you’ll give in and accept it. Web pages will do anything to manipulate APIs in nefarious utilization.
Post reply on HN