Earlier quoted context omitted.
I don’t really think Google’s plan is that weird. And it would be amazing for decentralized networks, archiving, and offline web apps. Google can’t just serve nyt.com — they can serve a specific bundle of resources published and signed by nyt.com verified by your browser to be authentic and unmodified.
The AMP spec REQUIRES you include a Google controlled JavaScript URL with the AMP runtime. So technically the whole signing bit is a little moot, given that the JS could do whatever it wanted.
Where Am I? NYTimes or Google?
81–90 of 381 posts
Re: Where Am I? NYTimes or Google?
#82Remember when Google's mantra was "Don't be evil" ???
"Don't be evil", using primary colors in the logo to bring that kindergarten familiarity, fun doodles, a dumb funny movie and quirky April Fools projects were a great marketing strategy to distract your average person in lowering their guard and feel safe to give all the data to an advertisement company. I wonder if they currently teach this case in marketing/PR classes.
To be clear, I don't think Google or any other large company is evil. It's just the way things turn on, how the incentives are structured.
Re: Where Am I? NYTimes or Google?
#83Earlier quoted context omitted.
Is NYTimes's use of Fastly also a cover-up?
Google by definition wants to cover-up the domain name that serves amp web pages. Over half of the article discusses that. For your question about fastly, I already answered that in the comment you replied. The fastly CDN requires that the DNS is configured to point at fastly servers. Take a look at https://docs.fastly.com/en/guides/sign-up-and-create-your-fi... under "Start serving traffic through Fastly". Once you’…
Re: Where Am I? NYTimes or Google?
#84Earlier quoted context omitted.
If Google AMP is acts like a cache of content, then cache poisoning attacks are a concern. How those cached items expire will determine how long an attacker who poisons the cache can serve malicious content.
Why does Archive.org get a pass on this one? Signed responses mean that there's a very clear way to leverage the browser's domain blacklisting technology to stop the spread of malware, which isn't presently possible for any content mirrors on the web.
Google AMP doesn't show Google on the page. Google is pushing for the URL to show the origin site's URL instead of Google[2].
If an attacker poisons a nytimes.com article served by Google AMP, how does a browser's domain blacklisting help? Block google? Block nytimes.com? Neither makes sense.
1. https://web.archive.org/web/20050401090916/http://www.google...
2. https://9to5google.com/2019/04/18/apple-mozilla-google-amp-s...
Re: Where Am I? NYTimes or Google?
#85Yes this has been a big issue for a very long time now. Google wants to push a release where it will display the hostname of the amp site even if the content is being served from google.com[1]. Mozilla (and Apple) are strictly against it and thank god for Mozilla. If Google had a bigger market share this would already be something we would have been living with. I'm sure there are better sources for this, but here is…
I don’t really think Google’s plan is that weird. And it would be amazing for decentralized networks, archiving, and offline web apps. Google can’t just serve nyt.com — they can serve a specific bundle of resources published and signed by nyt.com verified by your browser to be authentic and unmodified.
Re: Where Am I? NYTimes or Google?
#86IMO the core point of the article is false. > To be blunt, this is a really dangerous pattern: Google serves NYTimes’ controlled content on a Google domain. No, "Google serves NYTimes' controlled content" is an oxymoron. Google controls the content that is served, and that's all your browser is verifying. Google could very well make the NYTimes content on there display something else and your browser wouldn't show a…
I don't like AMP nor much of how Google has behaved with it (http://exple.tive.org/blarg/2020/05/05/the-shape-of-the-mach... largely matches my thoughts), but let's stick to what's actually happening with SXG.
Re: Where Am I? NYTimes or Google?
#87Remember when Google's mantra was "Don't be evil" ???
"Don't be evil", using primary colors in the logo to bring that kindergarten familiarity, fun doodles, a dumb funny movie and quirky April Fools projects were a great marketing strategy to distract your average person in lowering their guard and feel safe to give all the data to an advertisement company. I wonder if they currently teach this case in marketing/PR classes.
I feel like in the first few years it was not yet an advertising giant. Wikipedia says they had small text ads in 2000, but seems to imply that the advertising didn't get really huge for them until after IPO. Correct me if I am wrong, I was not following super closely in those years. But that would provide a few years of "not being evil".
Re: Where Am I? NYTimes or Google?
#88Remember when Google's mantra was "Don't be evil" ???
Meh, they preserved 2/3rds of it.
Re: Where Am I? NYTimes or Google?
#89AMP seems like a solution in search of a problem. Are people really having trouble with loading speed in 2020? I travel to remote areas in third world countries regularly for work and still don't really have problems loading pages with mobile data. Even if it didn't have all of the problems associated with it I just don't get the point. I don't need Google to repackage a website with less useability. It's frequently…
I lived in Africa and the only internet I had was cellular and by the gb. Amp is a massive improvement over the extremely large web pages we now have to endure. It's also much faster to render, which makes a huge difference on the crappy Android phones that are everywhere. Hell, I'm using a $200 Android phone right now because my iPhone broke and browsing the web is painful on it. And with the terrible hauwei $40 pho…
Re: Where Am I? NYTimes or Google?
#90Earlier quoted context omitted.
There has been no regulatory action since Microsoft (which happened as Google was being born), so the tech giants have forgotten fear and no longer self-regulate out of simple self-interest.
Another way of looking at it is: they absolutely are self-regulating . And it appears to be a problem. Another problem is, there's effectively no distinction between regulator and regulatee.
If they do that, it's not really visible, I don't see any regulation with how Google is behaving regarding search & web, if anything it looks like anti-competitive monopoly behaviours.