8 ms·
AMP really has to go away, its a MITM attack on the internet. Google discontinues so many services, why is AMP not one of them yet?
by 0x006A 6y ago
AMP really has to go away, its a MITM attack on the internet. Google discontinues so many services, why is AMP not one of them yet?
- chadlavi 6y agobecause it's a useful MITM attack on the internet
- ryanianian 6y agouseful to whom?
- oblio 6y agoTo Google, of course :-)
- zo1 6y agoAfter they took away peoples' ability to MITM their own stuff by forcing HTTPS everywhere under the guise of privacy.
- wolco 6y agoNot everyone joined the https party. The additional overhead on sites isn't justified for sites you don't even log into.
- tgv 6y agoVia http you expose the GET headers, i.e. everyone can see the urls you're browsing, even if you don't login to pornhub.
- AlexandrB 6y agoThis gets trotted out a lot, but who is "everyone"? At worst it's a bunch of random people in the cafe whose WiFi you're using - but these people don't have the resources to track your activity once you leave the cafe. Otherwise it's just the same rogue's gallery of large corporations interested in adtech/surveillance money: ISPs, device makers, other online service providers. The thing is, none of them have the reach, data collection, and analytics capability of Google. And Google almost certainly gets all this information too, whether you use HTTPS or not (see reCaptcha, Google Analytics). To me, this rationale looks an awful lot like a moat to stifle Google's competition. If collecting "the urls you're browsing" is wrong, why is it ok for Google to do it? And if it's not wrong, why is it somehow better that only Google gets to do it?
- JoshTriplett 6y ago> At worst it's a bunch of random people in the cafe whose WiFi you're using - but these people don't have the resources to track your activity once you leave the cafe. Depending on what you're doing, one-time collection may be enough. Also, many captive portals are provided to businesses by companies whose own business interest is in tracking people, and they'll absolutely correlate the data. Rather than having to worry about whether the service you're getting internet access from will track you, make it impossible for them to do so.
- AlexandrB 6y agoIsn't this just imparting a false sense of security? The one party who I'm most worried about getting my data, Google, will still get it. I think you've still failed to answer my basic point - how is this not just a competitive moat that benefits Google? If we care about privacy and data collection, legislation is required because Google and Facebook have no reservations about sucking up everything they can. If it's ok for them to do it, why not $RANDOM_CANADIAN_ISP?
- JoshTriplett 6y agoIt's not an argument against HTTPS. If you use HTTPS, you know you're talking to the site you think you're talking to. If that site itself is sharing data in a way you don't want, including by pulling in third-party scripts, you have a problem with the site. That's not an argument against HTTPS; communicating in cleartext doesn't solve that problem, it just means that other people the site doesn't trust can also access that data. Let's not let the perfect be the enemy of the good here. Universal HTTPS is an improvement.
- wolco 6y agoEveryone on your private network basically. Pornhub should offer https if it doesn't already. A good example of a site where this would be a feature. Local recipe blog.. maybe Btw.. Pornhub has it's own google version of ad tracking they sell/share espically when you login.
- zbrozek 6y agoI disagree. There's no reason to leak things to everyone on the planet, even if what's leaked isn't the most-damaging-to -leak-thing possible. As an example, it annoys me that the Texas Instruments site isn't encrypted, leaking my interest in parts to anybody listening.
- wolco 6y agoI don't understand this point of view. You are either using a vpn or tor if you don't want the planet to leak your info to the world or you are leaking already. If you are not then sure browsing in an internet cafe or an unsafe network will allow rogue entities to see your interest in parts. Your browser is fingerprinting you on chrome with an id. You are being fingerprinted with your unique fonts on other browsers. If you have javascript on that opens the floodgates. Logged into facebook still? Browser extension gone rogue? Andriod OS?
- pixl97 6y agoI dont think they meant leaking into to TI, they meant leaking more into to ISPs than necessary. Http connections are like a post card, anyone in route can read it. At least with https they have to jump thru more hoops.
- willcipriano 6y agoEven if Texas Instruments implemented SSL the fact that you went there would not be a secret to anyone who can see your packets due to SNI[0]. HTTPS is really only useful when you want to hide the contents of a message, not the recipient. [0]https://en.wikipedia.org/wiki/Server_Name_Indication https://en.wikipedia.org/wiki/Server_Name_Indication
- arbitrage 6y agoThe "additional overhead" argument against SSL hasn't held water for well over ten years, now.
- tekromancr 6y agoEspecially when you can just sit behind cloudflare and gett for free with very little work on your part. Granted, you then have to trust cloudflare; but it seems like they have been good actors so far considering their privileged position delivering tons of content across the web.
- tekromancr 6y agoThis is a common misconception. Https also prevents bad actors from injecting content into the page.
- viraptor 6y agoIf you want to mitm yourself, nobody takes it away from you. Create your own CA, add it to the trusted list, setup your proxy with the keys, and mitm all you want. You do get the benefit of https even on static sites though. Do you want every network you join to be able to inject any JS they want into pages you're viewing? Https solves that.
- pirocks 6y agoThis is significantly harder on android which is probably what OP was referring to.
- rblatz 6y agoIt slows down doing anything that involves it. I end up landing on some jank AMP page, and have to then navigate to the top, and pop up the original link, click it, then wait for the real site to load. Total UX fail
- tyingq 6y agoAMP keeps people on Google owned properties longer[1], so it's a revenue driver. [1] Via things like taking over swipe motions and the back button on carousel launched pages, for example.
- nojito 6y agoIt also allows for very easy tracking across the internet which is the real long term play. They will also be able to release "unblockable" advertising to amp pages eventually.
- chipperyman573 6y agoWhy would Amp allow the ads to be less blockable? Extensions still run
- monadic2 6y agoThey can package the ads in band with the content, although DOM based blocking might still work—at some point we’re going to have to write an ad detection AI just to use the internet. The long term solution is stigmatizing ads—you can never ad block someone in the ear of a newspaper editor.
- gtf21 6y agoI agree that AMP is a major attack on the internet, not to mention the fact that it makes it way slower [1] and hard to understand what you're browsing. The worst part is that my friends send me AMP links all the time even though I use DDG to avoid this stuff. [1]: https://news.ycombinator.com/item?id=18893808 https://news.ycombinator.com/item?id=18893808
- glenstein 6y agoFor me, this is a new and helpful way of thinking about the relative value of DDG over Google.
- AlexandrB 6y agoThe worst thing I've seen recently is amp URLs for reddit threads. It's one bad thing (new reddit UI) wrapped in a worse thing (AMP), and getting back to classic reddit takes a lot of gymnastics. The stupid part is that the amp page is indistinguishable from the (new) reddit page (the AMP page comes complete with the "download our app" popup). So I don't see how it's providing any speed/experience benefit.
- jereees 6y agoI can never get the Open In Reddit app button to work. I’m on iOS and have the latest version of the official reddit app. Which btw is painfully filled with ads.
- mattwad 6y agoOn Android I have a similar problem; I use Reddit is fun, and so it doesn't open that app; it always wants to download the main app.
- dmccaff 6y agoIt never works for me either, but there is a workaround. If you click on the 'x comments' link at the bottom of a post, it will open up in reddit is fun.
- dorkinspace 6y agoMay I recommend using any 3rd party app for reddit instead of the official app. I use relay on Android and it is great. There are many other options, all of them are better than the official app.
- afterburner 6y agoMake sure to try i.reddit.com in a browser, that's also a good option.
- a-wu 6y agoUse the Apollo app. Much better than the official Reddit app. It's more like what Alien Blue was before Reddit killed that.
- jgalt212 6y agoAMP is MITM attack on the internet. best and most succinct description that I've heard.
- CobrastanJorji 6y agoWikipedia says that Amp first started appearing in search results in February of 2016. Some random websites tell me the average Google product death happens about 4 years after it launches (not counting anything that hasn't been killed at all and with some huge error bars). So we should expect AMP to be abandoned sometime between now and never.
- a1369209993 6y ago> Google discontinues so many services, why is AMP not one of them yet? Because Google only discontinues useful services, and AMP is actively harmful (aka of negative usefulness)?