12 ms·
Google Chrome to stop back-button hijacking
- sliken 8y agoOnly the most anti-social sites break the back button, I kill the tab of any site that does. What I hate and is much more common is the "do you want notifications". I'd love a "never ask about notifications again" option.
- MiddleEndian 8y agoI'm not sure about Chrome, but in Firefox I know I set the default permission to 'never' ask somewhere in about:config. The ideal life is one without unwanted notifications.
- girzel 8y agoIs that dom.webnotifications.enabled? God I hope so, I don't know why I didn't look there sooner to turn off this crap.
- MiddleEndian 8y agoYeah that sounds about right. The other thing to disable is the full screen notification, which I think requires two keys now for some reason.
- mikro2nd 8y agoNo need to drop to about:config... it's right there in the GUI for Privacy > Notifications -- a checkbox below the list of blacklisted sites.
- clircle 8y agoFirefox has this in about:preferences#privacy.
- Klathmon 8y agoThat's an option right in the settings. Along with all other permission requests. Just set it to "never ask" or something similar and it will auto-deny all notification permission requests. You can also enable it for specific sites if you want.
- FreakyT 8y agoI definitely recommend doing this! UX-wise, I do wish that Chrome surfaced the option a bit better. Seems that a "never ask me again" checkbox, or even a shortcut to the relevant settings page, would be a nice touch.
- Klathmon 8y agoNow I won't pretend to be within several magnitudes of the scale that Chrome runs at, but having given users the choice of "never ask for X again" in the past, it just ended up causing more issues than it ever solved. People don't read dialogs, they just don't. And giving them the option of "never ask again for any site" would most likely mean that some would hit it and it wouldn't even register that it was something they did, let alone remember they did it for the rest of their time using that browser. Then you start getting complaints about how Firefox has this notification feature but chrome doesn't, or notifications are broken on my chrome, or whatever else. That's why I'm hopeful for some new browser APIs which will manage permissions across the board, and will use things like heuristics to allow or disallow asking for permissions based on things like amount of interaction, number of times they interact with the website, and the "kind" of site it is (a PWA should be allowed to ask for notifications fairly early on in the process of using it, a news website should have to wait until the user has come back at least a few times before being able to ask). I don't envy browser vendors for having to make decisions on what is and isn't allowed there, because no matter what some well meaning sites will be caught in the crossfire, but it's by far the "least bad" solution in my opinion.
- paulie_a 8y agoThere is a bit of hubris when it comes to websites even asking to allow notifications. No site is that important. why would I ever want to enable notifications under any circumstance ever. I generally get badgered about it by a site I'll probably only visit once.
- technion 8y agoAny time I visit a non tech relative - their desktop is constantly popping up with messages they claim to know nothing about. In the old days, you needed an RCE and some malware to do desktop popups. Now it's apparently just a feature. It's becoming an increasingly abused function.
- alexis_fr 8y agoThe upside is, at least they don’t have a virus, not the kind that encrypts files or sends you CC info to China.
- TeMPOraL 8y agoNo, they just have the regular spyware conveniently bundled with almost every site they visit :). Seriously, ad&tracking blocking is the first thing I do when I have to fix up a computer for a friend or family member.
- acdha 8y agoThis is why I applauded Firefox shipping it by default. It’s so much easier to leave it in than have to install something else or figure out which ad blockers are trustworthy.
- blfr 8y agoI thought it was a great idea at first but in reality I only use it for the calendar and get annoyed by requests on every other site.
- kevin_thibedeau 8y agoFirefox has an option to disable notification prompts in about:config.
- jvzr 8y agoEven worse (and this is something that we also see on mobile): they usually implement a fake pop-up that asks for Location/Notification before showing the real one, just to be able to spam that fake pop-up while a dissent in the real one would hide forever Evil
- randallsquared 8y agoGMail breaks the back button in this way. There are intermediate "pages" in the app in some cases such that hitting the "back" button puts the browser in a state that causes a replay of the thing that brought the page from which you were clicking the "back" button. This happens a lot when searching through mail. Once you're aware of it, it's simple enough to hold the back button and then go back several entries at once, but maybe this change will remove the "when I hit back, it goes back and then forward to where I was when I hit back" behavior in the first place.
- MertsA 8y agoI would love it if Google would identify sites that ask for notification permissions without any request from the user while crawling sites. Then just make a blacklist of those sites ala the safe browsing lists. There's no good usage for sites requesting notification permission without the user opting into it first.
- otikik 8y agoOn Firefox at least, you can: Preferences / Permissions / Notifications / [x] Block new requests asking to allow notifications
- adtac 8y ago>I kill the tab of any site that does I believe this is one of the intended effects. For example, when you click on a link after a Google search, and then click the back button to go back to the search results, I imagine Google records this to downrank that page for that query in a small way. When you kill the tab, you forfeit this opportunity.
- raxxorrax 8y agoYou will get more problems like these if the largest advertising company develops browsers. No excuse for the other browsers though...
- Tsubasachan 8y agoI don't use Chrome but FF lets you block requests to allow notifications. Its in settings>privacy&security>permissions.
- lichenwarp 8y agoThe full page email popups/page dimming are the worst, I hate that it has caught on so much.
- kurtisc 8y agoAt least they have a nice big div to hit with your element blocker.
- seanwilson 8y agoHow does this work with single page apps where it's not uncommon to modify the history?
- Gaelan 8y agoSounds like it's only counting history entries in reaction to a user interaction, so if history is modified when the user clicks a link nothing will change.
- huntermeyer 8y agoI have the same concern.
- sincerely 8y agoI mean, aren't SPAs kind of a hijacking of how browsers are intended to be used?
- evrydayhustling 8y agoI get what you're saying, but browsers haven't been stateless url-loaders since the late 90s. JavaScript in general, cookies, local storage, and plug-ins are all compromises with "pure" http navigation that (a) can be abused but (b) offer some much needed client-side cooperation in maintaining continuity and reducing repetitive traffic with the server.
- kurtisc 8y agoThere are ways of doing SPAs without polluting the history. In fact, I find them less frustrating to use. If your design relies on cues taken from malware pages, that's on you.
- SquareWheel 8y agoWhy do you think the history push API was introduced? For websites that work like SPAs.
- SECProto 8y agoFunny, one of the things that convinced me to switch away from chrome (back to Firefox) was when chrome got rid of the backspace-key-navigates-back. Sure, I could use an addon to restore the feature but .... why should I live with a browser that subverts decades of standard keyboard shortcuts?
- SquareWheel 8y agoIt was a horrible keyboard shortcut that caused countless lost form entries. Just because something is standard doesn't mean it is good.
- SECProto 8y agoGoogle had several possible solutions: - warn before navigating - give options for the keyboard shortcut - change shortcut unilaterally They chose the third, which some (likely the overwhelming majority) preferred. I didn't, so I switched to Firefox. We're both happy this way I guess.
- SquareWheel 8y ago>warn before navigating This requires too much page context. A search field being partially filled is very different than a long registration form being worked on. >give options for the keyboard shortcut You said yourself, they released an extension for this.
- SECProto 8y ago> You said yourself, they released an extension for this. Oh was there an official one? At the time, the only extension I could find was some slightly-sketchy third party one that allowed you to set hot keys for many things. > This requires too much page context. A search field being partially filled is very different than a long registration form being worked on. Fair enough.
- 8y ago
- yalogin 8y agoThis is very much needed. Every site I visit through google news hijacks the back button. They only show their news letter signup page for the most part but still very annoying.
- catmanjan 8y agoDoes this mean they no longer support history.pushState?
- denormalfloat 8y agoPlease also fix the back button on the PDF reader built into Chrome; pressing the back button on my mouse seems to go nowhere.
- TACIXAT 8y agoRight now you can't close a tab with ctrl+w if the "Would you like to see desktop notifications?" dialog is up. For a second I thought this was a fix for that.
- jlebar 8y agoI implemented the history.pushState API in Firefox many moons ago. Dunno why I didn't add this protection then, other than, it was a simpler time. It was around then that we added the API for vibrating a phone and we all sort of said "eh, someone could abuse this, but why would they?" (In my defense on that one I was on the side arguing that they would do it specifically for ads and we needed to lock it down.) Anyway, I approve of this change.
- aerovistae 8y agoCan you explain how this change stops abusers while still allowing front-end routing? I’m a bit confused because they seem mutually exclusive to me, or should I say they come together or not at all.
- dfabulich 8y agoThe commit comment explains, "Entries that are added to the back/forward list without the user's intention are marked to be skipped on subsequent back button invocations." The commit doesn't include a mechanism for marking the should_skip_on_back_forward_ui flag, but the normal way Chrome verifies "user's intention" is waiting for a gesture/click in the page. So if you're doing front-end routing in response to a user clicking on a link or button in your UI, or swiping the page or what have you, that will allow you to pushState and then intercept the back button, as you can today. But if you attempt to pushState on load, that's not enough to establish intention; the back button will then skip your pushed states and leave the page.
- cronix 8y agoI quit using chrome, but it would be nice if they alerted you to the fact that the site is hijacking the button. Personally, when sites do that, I immediately add them to a block list because they are shit and I don't want to visit them ever again. Now you'll never know.
- tylerhou 8y agoHow do you define "hijacking the button?" There are many valid uses of pushing state to history, and it's very difficult to distinguish a malicious use from a non-malicious use in the general case.
- thefounder 8y agoThis is bad for my Electron app. I wish there would be a flag to disable all the web "security"(i.e isTrusted field requirements).
- xg15 8y agoMore in-depth discussion about the rationale and design process behind the intervention: https://github.com/WICG/interventions/issues/21 https://github.com/WICG/interventions/issues/21
- baybal2 8y agoI know why Google has reacted now, I noticed few month ago that "clickfarm" websites began visually spoofing popular websites. You accidentally click "clickfarm.com" from, say, google.com; then you press back button, it seems that you are "back," by the moment you click on another link, you realise that google.com page was fake, and is stuffed with invisible ads.
- fooker 8y agoWhat purpose does invisible ads serve?
- happppy 8y agoI think opacity set to 0, you didn't knew but you saw the ad and this will count as view?
- baybal2 8y agoGoogle looks for obscured ads, but there are new ways of tricking both the bot and the ads code coming out almost monthly. What they look above all else are the organic clicks from clear IP ranges.
- jwilk 8y agoThis works with JS disabled: https://bugs.chromium.org/p/chromium/issues/detail?id=907167 https://bugs.chromium.org/p/chromium/issues/detail?id=907167
- acdha 8y agoThanks - the mountain of JS on the other page failed on iOS
- justkez 8y agoI've recently noticed Chrome (71) on Mac is now hijacking the `Command + Q` shortcut and asking if I really want to quit. I appreciate people will occasionally shut down a Chrome session by mistake, but it seems a little ironic that they're clamping down on behaviour hijacking in one space whilst implementing it in another. (Caveat: I'm not sure if this change is being committed by a Google Chrome dev or non-Google Chromium dev)
- AbacusAvenger 8y agoI saw that too. There's a menu option to disable it.
- tushar-r 8y agoAFAIK, this has been the case for quite some time now. There is a menu option to disable this - Chrome > Warn before quitting (cmd+q) I've disabled cmd+q on my system, so I haven't run into this recently.
- slig 8y agoWhen using Command + W to close a tab, it's only a fat finger away to close the entire browser. Years ago that happened and it was a huge hassle since it wasn't easy to reopen all the tabs you had.
- woodrowbarlow 8y agowasn't "reopen recent tabs" a launch-day feature for chrome?
- slig 8y agoI'm not sure. I remember hitting Command+Q a few times by mistake and losing whatever tabs I had open. Maybe I didn't know about that feature at that time.
- skohan 8y agoI came here to say this. It should really be an opt-in behavior rather than opt-out. It's not the only reason chrome has become a not-so-good citizen on macOS: the memory/CPU footprint is bad enough, but it also does things like give system-like popups when a new printer is detected on my network. I'm not sure when I permitted chrome to do this, and it seems like it's trying to subsume more and more of my system's function without asking. I find the command + q thing to be a particularly annoying version of this.
- nbevans 8y agoHow about stopping right-click hijacking and smooth-scroll hijacking too?
- skohan 8y agoRight-click is very useful in some cases. I have some productivity apps I have built for myself using web technologies, and it's extremely useful to be able to have custom context menus. Since web applications are doing more of the work that native apps used to, I'm ok with some level of annexation of the browser's UX territory when a site can really justify it. That said, I would be in favor of an option to disable it globally, or for certain domains.
- feross 8y agoOne by one, the Chrome engineers continue to chip away at the techniques in The Annoying Site https://theannoyingsite.com https://theannoyingsite.com (warning: open in a secondary browser). Talk video here: https://www.youtube.com/watch?v=QFZ-pwErSl4 https://www.youtube.com/watch?v=QFZ-pwErSl4 Source code here: https://theannoyingsite.com/index.js https://theannoyingsite.com/index.js Well done.
- amaccuish 8y agoI shouldn't have done that. Though my downloads are now filled with cats which is nice :)
- singularity2001 8y agoWow, Firefox failed the chaos monkeyt test miserably! Felt like IE in 2001! Don't open this site with 'reopen tabs after crash' option activated!! How can they even popup so much and how can the print dialog disable closing buttons?? Looking at the video, Chrome and Safari are in no way better off. Still, I thought popups were fixed 2008.
- quietbritishjim 8y agoBy the "choas monkey test" do you mean the annoying site in the parent comment? I'm using FireFox and it didn't do much for me. As I mentioned in another comment, I have set popups to appear in tabs, and that seems to mostly neuter the site. It still managed to go full screen and play audio in the form of Nyein cat and some text to speech, which admittedly was annoying. But I managed to close the site and any "popup" tabs it made with two actions: Alt+F4 (I'm on Windows) followed by clicking "leave page". I had opened the site in its own window so my existing tabs were unaffected, but I wouldn't have been much worse off if I hadn't. I believe Safari has an option to send all popups to tabs rather than new windows, so it is probably affected to a similar (low) level as FireFox. But I don't believe that Chrome has this option.
- tzfld 8y ago>https://theannoyingsite.com https://theannoyingsite.com This is worse than I thought.
- ivanhoe 8y agoWill this affect SPA routers? How is "without the user's intention" defined, does it mean programmatically added items or something else?
- shortercode 8y agoIf the current event loop task ( you may need to read up on the JS event loop ) was spawned by something like a click event then it is marked as a "user interaction". These tasks can do things like opening a popup window, start audio playback etc. whereas normal tasks are normally blocked from doing this. It's a clever mechanism but malicious sites tend to just attach a click listener to the page and trigger everything when the user clicks for the first time. On the other hand it can also be a pain to program around this if you need it. Say you have a webapp that allowed you render an image then display it in a popup. But the rendering is time consuming, so you do asynchronously in the background. The user clicks the button and you start the render. When the render is complete you try and open the popup, but your now in a different task where the popup is blocked. The best way to work around this is to display a modal dialog, saying that the render is complete. Then when the user hits "ok" you can use the task that the event created to display the popup. But it might confuse the user why they need to confirm the render is complete.
- mikewhy 8y agoCouldn't you open the popup immediately while keeping a reference, do the proceeding, then just manipulate the reference to the window you just opened?