4 ms·
The solution proposed doesn't match the problems stated, or take much of the technical realities into consideration. Which is fine - maps are complicated, and h
by tmcw 9y ago
The solution proposed doesn't match the problems stated, or take much of the technical realities into consideration. Which is fine - maps are complicated, and hard to understand.
- As a user, I don't want to share my location with a website.
The proposed element doesn't seem to address this at all, or suggest how it might address the problem down the line. Even if there was some sort of opaque position-in-the-browser-but-not-sent, how would, say, nearby businesses show up?
- As a user, I want access to my devices' mapping features when I view a map on the web.
You already do, with the W3 and WHATWG standard protocols in every browser.
- As a developer of a website, I want to take advantage of any in-built mapping software the user has, rather than use a 3rd party library.
Like what? People don't have built-in mapping software installed on their computers.
The 'zoom as width of map' proposal is, um, well - as I said, maps are complicated. It's not a very good idea.
Anyway, the state of the art is pretty much:
- Use Leaflet and you can have your choice of mapping providers.
- There are good standards like GeoJSON and navigator.geolocation to move data around.
This concern has come up before - like there was, long ago, the mapstraction project that 'abstracted' away mapping providers. It's abandoned, for pretty good reason.
- mcphage 9y ago> Even if there was some sort of opaque position-in-the-browser-but-not-sent, how would, say, nearby businesses show up? The tag would contain (or link to) a listing of locations, and the map could choose to display nearby ones. > People don't have built-in mapping software installed on their computers. Some do (Macs, for instance), but I think the author was proposing that the browsers themselves would implement the mapping component—Google would use Google Maps, Safari would use Apple Maps, Microsoft could use Bing Maps, Opera could use OpenStreetMap or work something out with another map provider. > 'zoom as width of map' proposal is, um, well - as I said, maps are complicated. It's not a very good idea. What's the issue with this one?
- ubernostrum 9y agoThere is no way to have a web-document-embedded map that can usefully show a user things near their device's location without leaking that location to any entity with access to execute JavaScript in the context of that document. Browsers have had to learn the hard way that getComputedStyle and even the animation timing APIs are essentially un-close-able privacy leaks (hell, even HSTS is abusable as a way to set and check "supercookies"). Any useful map would have similar problems.
- LordDragonfang 9y ago>getComputedStyle It looks like Firefox actually closed those security holes a while ago[1], and WC3 changed the standard to reflect this. [1] http://www.h-online.com/security/news/item/Firefox-developers-block-old-CSS-leak-968670.html http://www.h-online.com/security/news/item/Firefox-developer...
- ubernostrum 9y agoSimple use of :visited has been closed off, yes, but that actually took multiple attempts. See this bug, for example: https://bugzilla.mozilla.org/show_bug.cgi?id=557287 https://bugzilla.mozilla.org/show_bug.cgi?id=557287 And about a year ago it was discovered that in Microsoft Edge the :visited hack was alive and well again. And that's still very far from fixing the problem. There are still occasionally properties which pop up that are accessible and can reveal visited/unvisited state. There were a whole bunch of background-image tricks where observing what image was requested from the server side would tell you visited/unvisited. There have been timing attacks which could reveal recently-visited sites based on load times (faster when coming from browser cache). Then there are the the techniques which use animation APIs and still work today. The core of the trick there is to 1) get a link in the page which you know will use unvisited style, 2) register a callback for the next repaint with requestAnimationFrame(), 3) change the link to point at the URL you want to test, and 4) see if your callback executes (which indicates the link was repainted to a different style due to now pointing at a visited URL). The ability to do visited/unvisited styles differently, along with the style-inspection and timing APIs, while useful, are basically always going to provide ways to do this. If you poke around you'll find that aside from the most basic variants there's a tendency for these reports to end up closed out or just left in limbo forever because there's no practical way to close off the privacy leaks they create.
- mcphage 9y agoRight now everything with maps is completely wide open. So if they added a feature which provided security most of the time, but which sometimes leaks information if you jump through the right hoops, that’s still 100x better than where we are today. You’ll note that nobody is using the existence of requestAnimationFrame() exploits to argue we should just give sites whatever browsing history they want—yet that’s what you’re arguing here for location history.
- chrismorgan 9y ago> People don't have built-in mapping software installed on their computers. Actually, I think the substantial majority of users do now; recent macOS, Windows 10, iOS, most Android—and having browsers fall back to using an existing mapping website (similar to its being an iframe) would not be terribly difficult.