5 ms·
"The answer to the AMP URL problem are "signed exchanges", which allow a publisher's domain to be displayed in the browser address bar, even though the content
by davidu 7y ago
"The answer to the AMP URL problem are "signed exchanges", which allow a publisher's domain to be displayed in the browser address bar, even though the content is loaded from Google's cache when a user clicks on an AMP link in Google Search results."
Someone smart thought this was a good idea.
"This allows you to use first-party cookies and storage to customize content and simplify analytics integration. Your page appears under your URL instead of the google.com/amp URL."
Creating opacity in security and misdirection in trust is unwise for users. Making the address bar lie is dangerous.
I just don't get how the smart people at Google allow this to happen. The developers of Chrome and AMP can try to rationalize bad behavior but I'm surprised how all their coworkers let it stand. There was once a Google that would have been displeased with this kind of action.
- ec109685 7y agoHow is the signed exchange materially different than just having the browser make the request when you click on a link? Google hits the page beforehand, gets a cryptographically signed package of assets, verifies its contents and returns that to the user when the user clicks a link versus having the browser make the request itself at that time.
- londons_explore 7y agoAgreed. As long as it's crypto-signed byte-for byte and matches exactly what the original website published, then the actual TCP connection used to deliver the data is irrelevant.
- username444 7y agoThen why have Google deliver it at all, instead of encouraging publishers to simply cache their pages and serve via CDN? Amp is a solution that creates more problems than it helps. But it's a strategic move for Google to exert more control over publishers.
- ec109685 7y agoGoogle needs to deliver it or the browser wouldn’t be able to pre-cache the content for the user since it would leak to the publisher that the content was shown in a search result.
- username444 7y agoAgain, this is a made up problem. We don't need to pre-cache results. We just need faster loading websites without the bullshit JavaScript that does... Nothing. Google can, and has since inception, shown a 2-sentence description plus a title. If I as a searcher find that useful, I click through to the publisher site. This is a good system. AMP simply steals the entirety of the content from the publisher and serves it for them. That's not Google's job. And that's absolutely terrible for publishers. The solution is to provide tools and guidelines for publishers to follow for a better user experience, not cut them out completely. Fix the problem at the root.
- ec109685 7y agoHow is showing a page in < 100ms versus 2+ seconds a made up problem? There is no way without pre-fetching to deliver an instant experience. Also, what do you mean that google steals content from publishers? Publishers are in control of the ads running on amp pages (and receive the revenue), with over 100 ad networks supported by it.
- username444 7y agoI don't need a page to show up in 100ms. 2 seconds isn't a problem. 5 seconds is, but I'll wait it out for something I'm really interested in. Regardless, this stuff can all be done externally with current tech. Fairly easily. Serving up cached pages and lazy loading images resolves 90% of pagespeed issues. Removing JavaScript where it's not needed (almost everywhere) is another huge step. There is no legitimate reason - zero - for Google to go so hamfisted with this. The only reason it's being shoved down everyone's throat is because it gives them more control over publishers.
- politelemon 7y ago> I just don't get how the smart people at Google allow this to happen. We'll probably never get a true answer to this, can only speculate. This appears to be group(s)think in action, where the involved parties feel justified, even entitled, to make this change for the 'betterment of the web'. Think back to when the Chrome/ium team decided to hide 'www' and 'm' from URLs and had to roll back that decision pretty quickly. I cannot find the post where an engineer indicated that in their internal discussions this seemed like a good idea. Given the massive browser share that Chrome/ium commands, the decisions being made around tampering with the address bar and making it behave in a way that does not reflect the underlying protocols, would not occur in a team with healthy debate around the merits and dangers of such actions - so I believe that debate is either not happening or simply being suppressed at multiple levels within the organisation.
- lokedhs 7y ago> Think back to when the Chrome/ium team decided to hide > 'www' and 'm' from URLs and had to roll back that decision > pretty quickly. I cannot find the post where an engineer > indicated that in their internal discussions this seemed > like a good idea. Wasn't it Apple who started with this? I seem to recall seeing their web browser only showing the main domain of the website.
- sys_64738 7y ago> Making the address bar lie is dangerous This x1000. The only positive constant users have had since 1994 is that the URL doesn't lie. You can look at it and figure out if you're safe or not. Now Google wants to hide that from users by this masquerading going on. That is simply terrible and doomed to be exploited in the years to come. The only people who win here are the scammers who will defraud users.
- username444 7y agoNot entirely true: https://en.m.wikipedia.org/wiki/IDN_homograph_attack https://en.m.wikipedia.org/wiki/IDN_homograph_attack
- v7p1Qbt1im 7y agoYou can‘t really, though. Many people have been fooled by fake URL‘s. Nobody checks the cert. To say nothing of the non-human-readable token URL‘s in emails. Password managers and hardware tokens (Android phones too now) are actually a much better defense against phishing.
- ec109685 7y agoCan you explain how scamming is possible? The page shown to user is cryptographically verified to have been fetched from the url shown to the user in chrome’s url bar.
- keiru 7y agoMaybe not directly scamming exploiting this mechanism, but it might destroy the healthy habit of URL checking and being aware of what is going on. Instead people are given a false "seamless" experience. In the future similar white lies might be adopted by other companies, and eventually exploited. Just like the endless bombardment of cookies warnings trained people to just click through "OK"s and "Accept"s. Paired with introduction of the new Google portals, people might get used to opening a site within a site, or a site that is not the site. Now you can scam people by making them believe your shady website has a seamless Paypal/Visa portal, but it's just a css copycat and a private database of fools. I don't know why I'm always weary of increased levels of abstraction in interfaces.
- loudtieblahblah 7y ago>I just don't get how the smart people at Google allow this to happen B/c people at Google have the delusion that they are the internet.