10 ms·
This sounds terrible. Does it mean that browsers will begin lying to users and say that the users are visiting the website's server when they are really visitin
by 48309248302 7y ago
This sounds terrible. Does it mean that browsers will begin lying to users and say that the users are visiting the website's server when they are really visiting a restricted version of the website that is hosted in Google's cache? I don't want my content restricted or hosted in Google's cache.
AMP doesn't load in a privacy sensitive way. It's on Google's servers and it takes many seconds to load if you have JavaScript disabled.
Also, the feature only works on Google Chrome and possibly Edge, which gives another point to the article below.
https://www.zdnet.com/article/former-mozilla-exec-google-has-sabotaged-firefox-for-years/ https://www.zdnet.com/article/former-mozilla-exec-google-has...
AMP is a fundamentally bad idea that needs to disappear.
Edit: Mozilla has marked Signed HTTP Exchanges as harmful.
https://mozilla.github.io/standards-positions/ https://mozilla.github.io/standards-positions/
- chii 7y ago> I don't want my content restricted or hosted in Google's cache. how is this different than using your own domain, but pointing it to a github.io page? Or using medium, but with your own domain (but still being served from medium's servers)? Is it just google you're adverse to, or the entire idea of someone else hosting your content?
- 48309248302 7y ago1) I want full control over my servers and to not be penalized in search engines for not hosting my sites on Google. Where are the server-side logs? 2) I want full control over how I publish my sites with real web standards. AMP is not a web standard, it's a Google format that they are strong-arming people into using. 3) Mozilla considers Signed HTTP Exchanges harmful. This technology is as bad as what Microsoft was doing with IE in the old days. 4) I don't publish on Github pages, but if I did, I would still have a choice over which servers I put the sites on. 5) There shouldn't be a single company (or few companies) that dictates how we publish online. 6) Shame on the people who are splitting the web with this fake-opensource technology. There's even a Google engineer over here referring to the Web like it's a Google product. https://news.ycombinator.com/item?id=19631136 https://news.ycombinator.com/item?id=19631136
- Operyl 7y agoAs per point 6, I wouldn’t take what was said there as a statement from Google, or potentially even an employee of Google. They did it as a throwaway .. anybody wishing to kick the hornets nest could have posted that, employee or not.
- 48309248302 7y agoIt's not written like someone trying to kick a hornet's nest. It's written like someone who has been conditioned inside of a culture that has begun to view the Web as a Google product on some level.
- Operyl 7y agoAnd if somebody was wanting to kick a hornets nest, that’s exactly how you’d want to write it :). My point is, you cannot just blindly trust anonymous comments to be who they say they are, it’s an easy way to get yourself in trouble.
- laggyluke 7y agoBut if the comment was, say, digitally signed, on the other hand... ;)
- skybrian 7y agoThat's a good point! Domain owners can host their websites wherever they like, and yes that includes Google's cloud. If they go through a content network like Cloudflare, you can't even tell who's hosting the site by looking at the IP address. It drives home the point that websites are abstractions that have no necessary relationship to any particular physical hardware. Network tools may or may not tell you a bit more about the source, depending on if there are any leaks in the abstraction.
- 48309248302 7y agoThere is a difference between the web publisher controlling that abstraction and a web publisher that has been strong armed into one abstraction or another.
- skybrian 7y agoThere are incentives, but publishers still make their own decisions.
- 48309248302 7y agoBeing penalized in the search results is outright coercion, not an incentive.
- millstone 7y agoDNS is the answer to the first two questions. However the last question is a fair point - nobody complains about CloudFlare's caching of your web page as you designed it. The critique of AMP is that it receives privileged placement in search results, and that content authors are being pressured into adopting this de-facto Google-controlled spec, where they host your content and control its presentation. Anything that furthers AMP helps Google in this effort.
- sandov 7y agoI didn't even know about "HTTP Exchanges", and I'm more interested than ~98% of the population about this kind of stuff. Showing the name of the "signer" in the address bar, instead of the server where the content is actually hosted goes against decades of browser UI design. Good on Mozilla for marking it as harmful.
- jedberg 7y ago> Showing the name of the "signer" in the address bar, instead of the server where the content is actually hosted goes against decades of browser UI design Does it though? If you use Cloudflare or Akamai or Cloudfront or Netlify or etc. etc. then what shows up in the URL bar is not the server where the content is actually hosted. Well, it is the server where it is hosted, it's just one of the many domains hosted by that server.
- luckylion 7y agoThat has never been different. Cloudflare & co are reverse proxies, for all intents and purposes from a user agent view, they are where the content is coming from. They are the ones pointed to in DNS, and they have valid SSL certs.
- jedberg 7y agoAnd how is this all that much different? In fact I would say it's more secure. DNS can be spoofed pretty easily. This is a cryptographically signed package. If anything, I'd have more faith in this changing my URL than a proxy via DNS. Just because Google invented it doesn't make it bad.
- luckylion 7y ago> And how is this all that much different? It changes the meaning of the address bar from "this is who I'm talking to" to "this is who (at some point in time) signed this content".
- gregable 7y agoThe browser displays the URL from the origin that digitally signed the unmodified content. A browser already doesn't show you what server delivered the content. That would be your wifi AP, cell phone tower, or ISP node. The internet has already long established that we can trust content without trusting intermediaries. There are two elements that are important: integrity and privacy. The content integrity is protected via a digital signature, the "signed" part of "signed http exchanges". The signature proves that the document hasn't been tampered with. Regarding privacy: The intermediary (a search engine in this case) already has the content being delivered as a result of crawling it. It also knows the user clicked on a link to get that content, and knows the user's ip address. Even without AMP or Signed Exchanges, the privacy situation is the same. Once the page is loaded, all further interactions with the origin are normal https traffic, so later requests are not different in privacy either. What this enables, for search results, is the ability to load the bytes of the content before the user clicks a search result. If the browser prefetched those bytes with the origin's awareness, then the user's privacy with respect to the search query would be violated, making prefetch problematic. With this setup, documents can be prefetched while preserving user privacy and after the user clicks all browser behavior continues as normal from that point forward.
- UweSchmidt 7y agoIt is clear that the current developments on the web are worrysome and we need real privacy. We need to be able to find a website and visit it completely anonymous, unless we actively submit information to said website or a court order is issued. A cell phone tower or ISP node is ideally just infrastructure, "plumbing". Google seems to be trying to advance their strategic position in that direction. Rather than just being one search engine among several, they are trying to become part of the infrastructure. This could prevent future privacy solutions (and even prevent competitions between search engines).
- 48309248302 7y agoGoogle can't tell if a link has been clicked if JavaScript is off and the `ping` attribute is removed, so AMP removes privacy there. By forcing web publishers to host their content on a Google cache, they lose their server-side logging and the ability to determine how they set up they way they serve their own sites. Also, why do you artificially slow page loads on AMP pages to 8 seconds when JavaScript is disabled? That is a privacy issue.
- lern_too_spel 7y ago> AMP doesn't load in a privacy sensitive way. It's on Google's servers Only if you load the page from a Google SERP, in which case, Google would already know if you visit the page. If it's loaded from a Bing SERP, it's served from a Bing server, and the same for Baidu and other AMP caches. This is far more privacy preserving than preloading a page from some third party web server that the user might never visit.
- sebazzz 7y agoSigned HTTP exchanges may be harmful, but Google is beginning to get enough dominance so they implement it and browsers with a minor market share must follow or are left behind.
- millstone 7y agoWhat happens if other browsers don't implement it? It seems like they'll just show CloudFlare or Google's domains, instead of the signing domain?
- gregable 7y agoThe behavior for browsers without support is to show the google.com/amp URL as before, along with a small html-based bar with additional information about the original domain and share intents.
- mthoms 7y agoWith a button to disable AMP results entirely if that's the wish of the user? Yeah, I didn't think so.
- username223 7y ago> share intents Does that mean that the Google+ button is coming back? Seriously? Why not just serve the content and leave it at that? Is the tiny bit of extra data you get from a unique "share on Facebook" URL worth it?
- gregable 7y agoThe share button simply calls the browser's share API, for example: https://developer.mozilla.org/en-US/docs/Web/API/Navigator/share https://developer.mozilla.org/en-US/docs/Web/API/Navigator/s... > The Navigator.share() method invokes the native sharing mechanism of the device as part of the Web Share API.
- 7y ago
- jazoom 7y agoI decided it's time to give DuckDuckGo another shot. I just realised it's a lot nicer to scroll through its results than Google is now.
- kelnos 7y agoI've been using DDG for at least a year now. On some occasions I can't find what I need and end up checking Google, but in those cases, Google usually can't find what I need either.