24 ms·
Where Am I? NYTimes or Google?
- superasn 6y agoYes this has been a big issue for a very long time now. Google wants to push a release where it will display the hostname of the amp site even if the content is being served from google.com[1]. Mozilla (and Apple) are strictly against it and thank god for Mozilla. If Google had a bigger market share this would already be something we would have been living with. I'm sure there are better sources for this, but here is the first result: https://9to5google.com/2019/04/18/apple-mozilla-google-amp-signed-exchanges/ https://9to5google.com/2019/04/18/apple-mozilla-google-amp-s...
- Spivak 6y agoI don’t really think Google’s plan is that weird. And it would be amazing for decentralized networks, archiving, and offline web apps. Google can’t just serve nyt.com — they can serve a specific bundle of resources published and signed by nyt.com verified by your browser to be authentic and unmodified.
- pwdisswordfish2 6y agoIn what ways is this different/similar from "content centric networking"? https://m.youtube.com/watch?v=gqGEMQveoqg https://m.youtube.com/watch?v=gqGEMQveoqg (Google Tech Talk from Van Jacobsen on CCN many years ago)
- wmf 6y agoAMP is happening and CCN is not.
- pwdisswordfish2 6y agoDo you mean to say that is the only difference?
- wmf 6y agoNo, there are many differences but they don't matter. Since CCN is not economically feasible, none of the technical details matter.
- pwdisswordfish2 6y agoWhy is CCN not economically feasible?
- deleted 6y ago[deleted]
- domenicd 6y ago+1. The way I think about it is that signed exchanges are basically a way of getting the benefits of a CDN without turning over the keys to your entire kingdom to a third party. Instead you just allow distribution of a single resource (perhaps a bundle), in a crytographically verifiable way. Stated another way, with a typical CDN setup the user has to trust their browser, the CDN, and the source. With signed exchanges we're back to the minimal requirement of trusting the browser and the source; the distributor isn't able to make modifications.
- skybrian 6y agoIt seems like there is a risk that an old version of a bundle will get served instead of a new one by an arbitrary host? Maybe the bundle should have a list of trusted mirrors?
- gpm 6y agoAlternatively super short expiry times. It doesn't seem like it would be that concerning to have another site serving a bundle that was 5 minutes out of date. It doesn't seem like it should be too much load to be caching content every 5 minutes.
- deleted 6y ago[deleted]
- gregable 6y agoThere is a publisher selected expiration date as part of the signed exchange which the client inspects. The expiration also cannot be set to more than 7 days in the future on creation. This minimizes, but of course does not eliminate, this risk.
- xg15 6y agoIt also makes signed exchanges completely unusable for delivering packages offline. (E.g. the USB stick scenario) What a bummer.
- tyingq 6y agoThe AMP spec REQUIRES you include a Google controlled JavaScript URL with the AMP runtime. So technically the whole signing bit is a little moot, given that the JS could do whatever it wanted.
- gregable 6y agoThe same could be said of any CDN hosted javascript library. For example: jquery. There is an open intent to implement support for publishers self-hosting the AMP library as well.
- ComputerGuru 6y agoYou missed the required part.
- donaltroddyn 6y agoFor most JS served by CDN, you can (and should) use Subresource Integrity to verify the content. At least the last time I was involved in an AMP project, Google considered AMP to be an "evergreen" project and did not allow publishers to lock in to a specific version.
- gregable 6y agoLong term versions are now supported, so publishers can lock in a specific version. Publisher hosted copies are in the pipeline, as I referenced in the parent comment. My choice of verbiage was a bit confusing it appears.
- donaltroddyn 6y agoI don't think it's your wording that's confusing. You are contradicting the AMP documentation. AMP's documentation seems to indicate that the LTS is stable only for one month (new features released via the same URL each month), and so is not compatible with SRI (see https://github.com/ampproject/amphtml/blob/master/contributing/lts-release.md https://github.com/ampproject/amphtml/blob/master/contributi...) You can specify a version (ie, https://cdn.ampproject.org/rtv/somenum/v0.js https://cdn.ampproject.org/rtv/somenum/v0.js), but the AMP validator complains about that.
- dannyw 6y agoThe plan is bad because google currently tracks all of your activities inside AMP hosted pages site in their support article. Google controls the AMP project and the AMP library. They can start rewriting all links in AMP containers to Google’s AMP cache and track you across the entire internet, even when you are 50 clicks away from google.com.
- wmf 6y agoPublishers who use AMP were already allowing Google to track everything through either Analytics or Ads. Likewise, AMP pages are mostly accessed from Google search that's already tracked.
- robin_reala 6y agoAs a user I can choose to block GA, either through URL blocking or through legally mandated cookie choices in some regions (e.g. France). When served from Google I have no choice in the matter.
- gowld 6y agoIf you can block GA at the client, you can block google.com at the client, no?
- robin_reala 6y agoNot if I want AMP pages. (I mean, I don’t, but there are presumably people who do.)
- gregable 6y agoWhile that's theoretically possible, the library can be inspected and does not do these things.
- simion314 6y agoCould Google give specific persons different versions or is technically impossible?
- colordrops 6y agoWhy do they need a special extension though? What's wrong with DNS?
- gregable 6y agoSigned exchanges are an extension to digital certificates, such as used for TLS. This is independent of DNS.
- grey-area 6y agoThat's not why Google (the corporation) wants this to happen. This is not about technical capabilities but about power. They cannot be allowed to become the gatekeeper for the web.
- jacquesm 6y agoThey already are. The question is not how we're going to stop that from happening but how we are going to roll it back.
- nxnews 6y agoWhy would it be amazing for decentralized networks and offline web apps?
- remexre 6y agoIf I publish mycoolthing.com/thing, it could be mirrored over a P2P network as peer1.com/rehosted/mycoolthing.com/thing, peer2.com/rehosted/mycoolthing.com/thing, etc., in a way that would make it evident to end-users not familiar with the protocol that the content is from mycoolthing.com.
- tgv 6y agoAMP is of course not P2P.
- tyingq 6y agoI think the point is that signed exchanges ( https://developers.google.com/web/updates/2018/11/signed-exchanges https://developers.google.com/web/updates/2018/11/signed-exc...) could potentially be useful, if separated from AMP, and made an actually secure thing. Like, for example, the spec doesn't require specific Google controlled js URLS to be in the content.
- gregable 6y agoSigned exchanges is actually separate spec from AMP. The browser implements it independently. There is no requirement for AMP pages to use signed exchanges nor for signed exchanges to be AMP.
- mulmen 6y agoHow does centralizing content on Google from multiple sources improve decentralization? The web is already decentralized. That's why it is a web. AMP is a scourge. It's a bad idea being pushed by bad actors.
- amelius 6y agoGoogle is not a single server. Think of Google as a CDN.
- deleted 6y ago[deleted]
- oblio 6y agoSo it's decentralized because Google has multiple servers? And here I was, thinking that Google runs everything from a single IBM mainframe. What you're saying would be described as distributed... Not decentralized.
- HeWhoLurksLate 6y agoSeems to me like it's easy to forget there's a difference between those two..
- deleted 6y ago[deleted]
- eternalban 6y ago> How does centralizing content on Google from multiple sources improve decentralization? It actually makes perfect sense in Doublespeak. /s
- DougBTX 6y agoThey’re suggesting a web technology which would allow any website to host content for any other website, under the original site’s URL, as long as the bundle is signed by the original site. That could be quite interesting of a site like archive.org, as the url bar could show the original url. But AMP is a much narrower technology, I’d imagine only Google would be able to impersonate other websites, essentially centralised as you say. The generic idea would just be a distraction to push AMP. Everything would be so much better if the original websites were not so overloaded with trackers, ads and banners, then there would be no need for these “accelerated” versions.
- boomlinde 6y agoHow is it not weird that I see a domain name in the URL bar that has nothing to do with the domain I actually requested content from?
- jeffdavis 6y agoIt's completely moving away from the client/server model to something else. Perhaps that's a great thing to do, but it's not something to do quietly.
- mooman219 6y agoJust hearing about this from the thread, I'm getting a IPFS vibe from this. It would be interesting to see that tech get more native integration with the browser from this idea.
- deleted 6y ago[deleted]
- xg15 6y agoI agree, if we finally got a way to have working bundles on the web, that would be extremely useful. (And would also restore some of the capabilities of browsers to work without internet connection). It seems to me, a lot of the security concerns come from the requirements to make pages served live and pages served from bundles indistinguishable to a user - a requirement that really only makes sense if you're Google and want to make people trust your AMP cache more. I'd be excited about an alternative proposal for bundles that explicitly distinguishes bundle use in the URL (and also uses a unique origin for all files of the bundle).
- gregable 6y agoI believe the issue with this is that users already largely don't understand decorations in the URL. For example, the difference between a lock and an extended verification certificate bubble. Educating a user on what a bundle URL means technically may be exceedingly challenging.
- olingern 6y agoThe problem is ownership. Google is “stealing” or caching content for what they consider a better web. I don’t support ads but I also don’t support Google serving a version of the page that steals money from content creators. So, therein lies the problem: choice. I can imagine a future where amp is ubiquitous and Google begins serving ads on amp content. Luckily, companies have to make money and amp is not in most people’s or company’s best interests. If amp was opt-in only, this would be much more ethically sound.
- gregable 6y agoSigned exchanges guarantee that the content cannot be modified by the cache, such as ad injection. Google has never injected ads into any cache served AMP document (technically if the publisher uses AdSense, this is false, but that's not the point you are making). It's difficult to follow what definition of theft is being suggested. The cache does not modify the document rendering, it's essentially a proxy. In a semantic sense, this is no different than your ISP delivering the page or your WiFi router.
- realusername 6y agoBeing completely against AMP for obvious reasons, I'm personally not against signed exchanges itself, this feature could spawn a whole new class of decentralised and harder to censor web hosting, that sounds like a great addition.
- jhhh 6y agoGoing to also spawn a whole new class of semi-persistent malicious pages (say created via XSS) that once signed and captured can be continuously replayed to clients until expiration.
- CGamesPlay 6y agoWhat? The signing allows the content to be mirrored in other locations with guarantees about consistency. It doesn't imply anything more about the content than SSL does.
- 8organicbits 6y agoIf Google AMP is acts like a cache of content, then cache poisoning attacks are a concern. How those cached items expire will determine how long an attacker who poisons the cache can serve malicious content.
- CGamesPlay 6y agoWhy does Archive.org get a pass on this one? Signed responses mean that there's a very clear way to leverage the browser's domain blacklisting technology to stop the spread of malware, which isn't presently possible for any content mirrors on the web.
- 8organicbits 6y agoArchive.org makes it clear you are on archive.org. The URL shows archive.org. The page content shows archive.org at the top. [1] Google AMP doesn't show Google on the page. Google is pushing for the URL to show the origin site's URL instead of Google[2]. If an attacker poisons a nytimes.com article served by Google AMP, how does a browser's domain blacklisting help? Block google? Block nytimes.com? Neither makes sense. 1. https://web.archive.org/web/20050401090916/http://www.google.com/ https://web.archive.org/web/20050401090916/http://www.google... 2. https://9to5google.com/2019/04/18/apple-mozilla-google-amp-signed-exchanges/ https://9to5google.com/2019/04/18/apple-mozilla-google-amp-s...
- jeffbee 6y agoWell, it's the going opinion of HN for years that the main problem with AMP is it shows the actual origin instead of the proxied origin. Lying about the URL is something hundreds of HN comments have angrily demanded.
- nojs 6y agoWhy do you say that? I don’t think people want it to show the “proxied origin”, they want AMP to get out of the way and google to link to the real website.
- ori_b 6y agoNo. The complaint is that Google is redirecting the content to servers that they control.
- jeffbee 6y agoThis is not correct. Anyone can host AMP. See, for example, amp.cnn.com. Google hosts AMP content for its customers who elect to use that service. It’s not a nefarious plot.
- dqpb 6y agoIsn't this basically like a CDN or a PoP cache?
- IncRnd 6y agoNot exactly. For a CDN to work, the DNS is repointed towards the CDN's servers. In this case, Google is trying to cover-up that Google and not NYTimes is serving the page.
- wmf 6y agoIs NYTimes's use of Fastly also a cover-up?
- IncRnd 6y agoGoogle by definition wants to cover-up the domain name that serves amp web pages. Over half of the article discusses that. For your question about fastly, I already answered that in the comment you replied. The fastly CDN requires that the DNS is configured to point at fastly servers. Take a look at https://docs.fastly.com/en/guides/sign-up-and-create-your-first-service https://docs.fastly.com/en/guides/sign-up-and-create-your-fi... under "Start serving traffic through Fastly". Once you’re ready, all you need to do to complete your service setup and start serving traffic through Fastly is set your domain's CNAME DNS record to point to Fastly. For more information, see the instructions in our Adding CNAME records guide." A CNAME record is a dns mechanism that aliases an alternate domain for a canonical domain.
- esafwan 6y agoHave a look at this: https://blog.cloudflare.com/announcing-amp-real-url/ https://blog.cloudflare.com/announcing-amp-real-url/ Cloudflare allow using of same domain to use AMP. In this case, content is served from Cloudflare CDN.
- archon810 6y agoIt's called Signed Exchange and it's the same thing the comment you replied to is about.
- tyingq 6y agoNote the Cloudflare hosted AMP pages still mandate AMP requirements, like including a Google controlled JS uri in your content. Signing is moot if you allow Google to run arbitrary JS on your content. They haven't abused it yet, but it's allowed by spec. Subresource integrity isn't mandated, explained, or recommended.
- m-p-3 6y agoI'm still waiting for general support of addons for the next version of Firefox on mobile just so that I can have the Redirect AMP to HTML[1] addon. [1]: https://addons.mozilla.org/firefox/addon/amp2html/ https://addons.mozilla.org/firefox/addon/amp2html/
- henriquemaia 6y agoI'm on Firefox on a mobile device. That addon has a redirection link [1] specifically for Firefox' mobile version. As I didn't know about this addon, thanks for sharing it. [1] https://addons.mozilla.org/en-US/android/addon/amp2html/ https://addons.mozilla.org/en-US/android/addon/amp2html/
- deadelvis 6y agoHere's a user script to get rid of AMP (I use it with adguard): https://userscripts.adtidy.org/release/disable-amp/1.0/disable-amp.meta.js https://userscripts.adtidy.org/release/disable-amp/1.0/disab...
- rpastuszak 6y agoRemember when Google was telling us that third-party cookies are there to protect us, and Safari/Firefox/Edge are just reckless and pose a risk to users by blocking them?
- Jabbles 6y agoPlease provide a link, I could only find this, which suggests Google has reversed course: https://www.techradar.com/uk/news/google-is-phasing-out-third-party-cookies-in-chrome-to-protect-your-privacy https://www.techradar.com/uk/news/google-is-phasing-out-thir...
- rpastuszak 6y ago> By undermining the business model of many ad-supported websites, blunt approaches to cookies encourage the use of opaque techniques such as fingerprinting (an invasive workaround to replace cookies), which can actually reduce user privacy and control. https://blog.chromium.org/2020/01/building-more-private-web-path-towards.html https://blog.chromium.org/2020/01/building-more-private-web-... I'm going to copy paste my older comment on this: I find their "removing 3rd party cookies will incentivise businesses to rely on fingerprinting" discourse dangerous. It implies that other browser vendors (Mozilla, Safari/WebKit, new Edge) are in fact making the Web a more dangerous place. I believe it's dangerous because it creates a harmful, unproductive PR narrative—people might just assume this is a true statement, without learning about both sides of the problem. I'm not trying to strip anyone of agency, I just don't think most of my friends would have time to research this topic and might decide to follow the main opinion instead. The answer I'd like to hear: Yes, it does push some actors towards fingerprinting, but preventing fingerprinting should be dealt with regardless. Changes should happen both on legislative and browser-vendor level.
- Jabbles 6y agoThank you for the additional background.
- 6y ago
- xg15 6y agoAren't we essentially reinventing http proxies with this?
- nokya 6y agoJust having this idea already tells how important it is to actively resist Google. One should never forget that at a certain point, Google will likely invoke the looser's argument ("protect you from terrorists and pedophiles") to require proof of identity prior to granting access to any resource or service it controls. Anything that helps them advance in that direction must be fought fiercely.
- priyaranjan 6y agoThis has been discussed over & over again and there is no representation from amp team to make it any better. I was surprised to realise how much my life changed when I started using firefox + duckduckgo. Full time, at work & home, on macOS & android.
- agumonkey 6y agohas the mainstream web jumped the shark ?
- smpetrey 6y agoHoly mackerel
- deleted 6y ago[deleted]
- w-ll 6y agoThe shenanigans Google been doing to the url bar is super hostile. Trying to copy the domain of a url without the protocol just infuriates me.
- marvindanig 6y agoHm. There's room for a new good browser to pick up the beans and run with it now…
- trishmapow2 6y agoNot defending that change, but when do you ever need to copy just the domain instead of the full URL?
- nemothekid 6y agoThe times that bit me the most is when I need to copy an IP address.
- jeffbee 6y agoAlways. Main reason I cut something is I want to paste the hostname into a terminal so it can be an argument of whois or dig or traceroute or whatever, in no case have I ever been glad of the scheme prefix.
- waheoo 6y agoIt's a solution in search of a problem.
- p1mrx 6y agoI've lost count of how many times I've done: $ ping http://whatever.com [furious line editing ensues] But thankfully it's fixed now, with the "Always show full URLs" option.
- smabie 6y agoIsn't more common to paste to a utility that uses the prefix like curl or wget? Or pasting into a chat? Besides all of those tools could just strip out the prefix, while there's no way to add the protocol to a domain name. More information is strictly superior.
- abraham 6y agoOne of the main reasons sites use AMP (listed in top sites in serps) will not require AMP soon. https://www.theverge.com/2020/5/28/21272543/google-search-results-page-experience-load-time-contentfu-paint-layout-shift-top-stories-amp https://www.theverge.com/2020/5/28/21272543/google-search-re...
- IgorPartola 6y agoI truly hope whoever keeps pushing AMP such as it is has to birth a hedgehog backwards. I mean, at least add some way to opt out of this shit. This is why I don’t use Google as my mobile search engine. I honestly still would if my browser allowed me to disable or bypass it, but nope. No extensions for me because Apple won’t allow for anything like that. /rant
- plplok 6y agoI'm wondering about this as well? Who was it? I'm pretty sure there were many internal discussions as to why/how to push this change. I'm surprised that those haven't been leaked.
- deleted 6y ago[deleted]
- toastal 6y agoThe beta of Firefox on Android still hasn't allowed any add-ons to auto-redirect away from AMP-enabled sites. I was excited to see Privacy Badger enabled 2 releases ago, but even its tracking-token-stripping capabilities seems missing on mobile.
- bitsoda 6y agoFor real. For the most part I love all things Google, but AMP makes my blood boil. How does it save me any time when I have to tap that little ‘i’ to get to the original website through all that janky scrolling? Ugh, infuriating. I feel like a walrus on a tar floor maneuvering through AMP pages. What an awful piece of technology. /rant
- fizwhiz 6y ago> has to birth a hedgehog backwards You have every right to be indignant, but I could have really done without that imagery.
- anonu 6y agoRemember when Google's mantra was "Don't be evil" ???
- lalos 6y ago"Don't be evil", using primary colors in the logo to bring that kindergarten familiarity, fun doodles, a dumb funny movie and quirky April Fools projects were a great marketing strategy to distract your average person in lowering their guard and feel safe to give all the data to an advertisement company. I wonder if they currently teach this case in marketing/PR classes.
- smabie 6y agoI mean, I don't think that was the intention. I'm sure Page and Brin really wanted to be different when they started. But as a company grows, the vision of the founders is excised and replaced with the same shit found in all large corporations. To be clear, I don't think Google or any other large company is evil. It's just the way things turn on, how the incentives are structured.
- S_A_P 6y agoI think that’s a great way to put it. Each decision to grow the business is not necessarily bad or evil. As google has grown and acquired market share they leveraged that to spur more growth and market share. They act in their own best interest. It’s not necessarily evil, but selfish motives and evil sometimes look a lot alike.
- asveikau 6y agoI am sure tons of people here know Google history better than I. What was the year they fully turned on the advertising spigot? I feel like in the first few years it was not yet an advertising giant. Wikipedia says they had small text ads in 2000, but seems to imply that the advertising didn't get really huge for them until after IPO. Correct me if I am wrong, I was not following super closely in those years. But that would provide a few years of "not being evil".
- twhitmore 6y agoThe whole AMP thing seems anti-competitive and hostile to the open web. It's a really bad look on Google's part to be pushing this.
- earthboundkid 6y agoThere has been no regulatory action since Microsoft (which happened as Google was being born), so the tech giants have forgotten fear and no longer self-regulate out of simple self-interest.
- TheSpiceIsLife 6y agoAnother way of looking at it is: they absolutely are self-regulating. And it appears to be a problem. Another problem is, there's effectively no distinction between regulator and regulatee.
- realusername 6y ago> Another way of looking at it is: they absolutely are self-regulating. If they do that, it's not really visible, I don't see any regulation with how Google is behaving regarding search & web, if anything it looks like anti-competitive monopoly behaviours.
- TheSpiceIsLife 6y agoYa'll misunderstood. Self-regulating in the same way an alcoholic meth addict self-regulates.
- Ensorceled 6y agoMost of us understand, it's just that your "word play" is not helpful.
- raverbashing 6y agoI am conflicted Yes, AMP is an anti-competitive move by Google At the same time AMP is "faster" because it gets rid of all the nagware and JS crap that the original page has. So yeah, I don't like what Google is doing but I don't like what NYT is doing neither
- twirlock 6y agoMeanwhile google spent ten years making sure I have to jump through a certificate authority's hoops because running a website without tls gives users the wrong idea about domain validation even when encryption is unneeded, which as we heard from PR dweebs on this very website all day every day, is just completely unacceptable for a whole litany of reasons.
- rdiddly 6y agoA: You are on Google. There's no confusion.
- young_unixer 6y agoI don't get the point of article. I know Google wants browsers to lie to the user about the website they're visiting. But the article screenshot is a case where that's not happening, it's displaying the real URL.
- princevegeta89 6y agoThis is the question I always had and confused myself over. In addition to this, I previously stumbled upon a few situations where I visited an AMP site to read an article and I noted down the site name in my mind. A few days later I tried to visit that site and when I put the site name in the address bar in hopes of getting helped by autocomplete, guess what?! It was nowhere to be found.
- vipulved 6y agoGrabby and wrong, and most of the value created is for Google.
- rammy1234 6y agoInternet before shows the real URL. Plain and simple.
- quadrifoliate 6y agoIMO the core point of the article is false. > To be blunt, this is a really dangerous pattern: Google serves NYTimes’ controlled content on a Google domain. No, "Google serves NYTimes' controlled content" is an oxymoron. Google controls the content that is served, and that's all your browser is verifying. Google could very well make the NYTimes content on there display something else and your browser wouldn't show a warning. NYTimes could do nothing about that. I disagree that this pattern is dangerous. While Google taking over serving the world's content is hardly a thing to celebrate, at least we're seeing that it's doing so here.
- rtsil 6y agoThe pattern is dangerous because it trains the user to dissociate URL and legitimate content, and the best tool at our disposal against phishing is still the ability to use the URL to ascertain the legitimacy of a content.
- izacus 6y agoURLs haven't been associated with legitimate content for a long time now, since most of the things come from giant CDN companies like CloudFlare anyway. What you're seeing in URL bar has very little to do with where the JS code executed on your computer is coming from.
- sudoit 6y agoYes, but users at least know the js code loaded was done so on behalf of the webpage the url points too
- icebraining 6y agoDoes it matter if it comes from a CDN rented by the NYT or a computer owned by DigitalOcean but rented by the NYT? What matters is that the domain points to where the NYT considers is the correct source of their content.
- 6y ago
- jacob019 6y agoNew York Times and all the other publishers don't have to participate in this crap. It's shameful that they cede authority over their content so easily in exchange for a vuage promise of more visibility. There are so many better ways.
- untog 6y agoIt’s not a vague promise, it’s an extremely explicit one. Search results for news contain a “top carousel”, a horizontally scrolling box that shows cards for different articles. On most phones it takes up most of the screen. If you want to be in the carousel (i.e. if you want your site to be visible near the top of search results) you must use AMP. No ifs and buts about it. If NYTimes and every other news organisation refused to participate then yes, Google would be in trouble. But they can rely on good old divide and conquer: these news organisations all compete with each other. All it would take is for one to starting producing AMP content again and they’d vacuum up all the search traffic, and all the other sites would follow them immediately.
- lazyjones 6y ago> don't have to participate in this crap It's a tempting Ponzi scheme.
- dewey 6y agoIn an ideal world where they would not rely on ad revenue and page views but are supported by the readers that assumption would be correct. But right now we are not living in that ideal world and because all other publications are doing that they have to follow if they don't want to risk losing visibility against the competition. So of course they don't "have to" but they also kinda do.
- Abishek_Muthian 6y agoI think the main issue is limited AMPCache providers and inability for the publisher to choose their own AMPCache providers. Which is being exploited the two search engines. AMP project by itself is open-source and it explicitly states 'Other companies may build their own AMP cache as well'.[1] There are only 2 AMP Cache providers - Google, Bing. Further, 'As a publisher, you don't choose an AMP Cache, it's actually the platform that links to your content that chooses the AMP Cache (if any) to use.'[2] Say, if Cloudflare provides a AMPCache and if the site publisher can choose their own Cache provider this can be resolved effectively as AMP by design itself is easy for a laymen to create high performance websites; of course there is no excuse for hiding URLs. [1]https://amp.dev/support/faq/overview/ https://amp.dev/support/faq/overview/ [2]https://amp.dev/documentation/guides-and-tutorials/learn/amp-caches-and-cors/how_amp_pages_are_cached/ https://amp.dev/documentation/guides-and-tutorials/learn/amp...
- SquareWheel 6y agoDid Cloudflare end their Amp Cache? They hosted one previously.
- Abishek_Muthian 6y agoI didn't know about it, AMP site lists only Google, Bing. But I know for a fact that cloudflare has no issues caching AMP sites like any other sites though.
- SquareWheel 6y agoIt looks like they killed it last year. The codename was Ampersand. Creation: https://www.cloudflare.com/press-releases/2017/cloudflare-announces-ampersand-the-first-open-amp-cache-to-give-publishers-more-control-of-their-mobile-optimized-content/ https://www.cloudflare.com/press-releases/2017/cloudflare-an... Death: https://blog.cloudflare.com/announcing-amp-real-url/ https://blog.cloudflare.com/announcing-amp-real-url/ I agree with you that users should be able to choose their Amp Cache.
- snowwrestler 6y ago
- bobbydroptables 6y agoAMP seems like a solution in search of a problem. Are people really having trouble with loading speed in 2020? I travel to remote areas in third world countries regularly for work and still don't really have problems loading pages with mobile data. Even if it didn't have all of the problems associated with it I just don't get the point. I don't need Google to repackage a website with less useability. It's frequently not even faster.
- ocdtrekkie 6y agoAMP solves a problem, it just doesn't solve a problem for users. It's an anticompetitive play and it's helping exactly who it is supposed to help.
- smabie 6y agoI lived in Africa and the only internet I had was cellular and by the gb. Amp is a massive improvement over the extremely large web pages we now have to endure. It's also much faster to render, which makes a huge difference on the crappy Android phones that are everywhere. Hell, I'm using a $200 Android phone right now because my iPhone broke and browsing the web is painful on it. And with the terrible hauwei $40 phones that have taken over Africa, most of the web is unusable. I don't like Google's control of Amp, but it exists because of the original sin of html and js. Everything about html is terrible: bloated, pointlessly verbose, etc. I have a dream that we all just start using Gopher and dump the www, but it's never going to happen. Maybe even browser vendors could get to together and design a super light weight markup based on S-exps or something, but that's probably not going to happen either. Amp is the best we got and it solves a real problem. And it solves the problem well.
- pnako 6y agoYou're on Google, the 21st century version of AOL
- killjoywashere 6y agoIf you think this is creepy, wait until you see Menlo Security. That's security for everyone except the user.
- didip 6y agoI remembered long time ago when Digg tried to do this and the internet revolted. I guess times have changed.
- ridiculous_fish 6y agoIt's wrong to trust the URL bar. For example, this search [1] has as top link an ad that boasts "google.com", and it really is! And if you click on it, you'll end up on a google.com site, which nominally helps with printers, but in reality it's a tech support scam. So much of the distrust here is that google wants to be everything: to host their content and publisher content and user content; to broker ads and recommend links; to run their software on your computer and phone, to store your data on their servers. They serve too many masters. 1: https://i.imgur.com/HalErpIr.png https://i.imgur.com/HalErpIr.png
- tommek4077 6y agoAs an advertiser, you can write whatever you want into the url displayed there. This does not need to match the real target.
- ridiculous_fish 6y agoBut the real target is google.com. I just made https://sites.google.com/view/whalefacts https://sites.google.com/view/whalefacts, took me literally ten seconds, confirmed it was accessible from multiple IPs and multiple browsers. Google wants to be a content host and an ad broker and a search engine. Each of these is reasonable in isolation. Yet you can search on google, and Google will serve you an ad linking to a google.com site, and that site scams you out of money. This isn't theoretical, I know because my family was hit. Screenshot if it gets taken down: https://i.imgur.com/T6hVHr5.png https://i.imgur.com/T6hVHr5.png
- pvg 6y agoQuis hic locus, quae regio, quae mundi plaga?
- satyrnein 6y agoDoes it actually matter where you are, or is that just an implementation detail? One interpretation is that Google is changing the URL bar from "where" to "who", which may be the more relevant information for most users. Signed exchanges are an interesting way to achieve that.
- deleted 6y ago[deleted]
- graiz 6y agoAMP is the consequence of HTML and CSS being awful at performance. I'm not sure why the underlying problem hasn't been addressed. Rending text and images on a page shouldn't require a secondary cache and an amp rendering framework on top of ton of css and layers of javascript. It's text and images.
- deleted 6y ago[deleted]
- nwsm 6y agoThis has been all over HN since amp was released, and this is a two paragraph article with no new info or opinion. https://hn.algolia.com/?q=google+amp https://hn.algolia.com/?q=google+amp
- mindfulhack 6y agoI suppose 328 votes so far show the usefulness of repeat discussions. This article is a catalyst to keep this one going. The votes prove that it's an important enough issue to continue talking about.
- kebman 6y agoHaven't news sites pushed law suits over this?
- lazyjones 6y agoWhat will all those submissive publishers do once Google decides to monetize AMP by injecting their own ads with 0 revenue for the publisher?
- noisy_boy 6y agoGoogle has already effectively become the address bar - people go to google.com to go to any other website. Now they are just solidifying it so that you don't even remember the url of a website after a while.
- markosaric 6y agoTime to share this post one more time: How to fight back against Google AMP https://markosaric.com/google-amp/ https://markosaric.com/google-amp/ And the original thread https://news.ycombinator.com/item?id=21712733 https://news.ycombinator.com/item?id=21712733
- reaperducer 6y agoPeople have been railing against Google's Amp on HN for years, and I think I finally figured out what it's for. It's Google way of combatting phone apps. If all of the world's information — especially current news and similar information — moves from the open web into apps, then Google can no longer crawl, index, or scrape that information for its own use. The rise of the mobile phone app is a threat to Google on so many levels from ad revenue to data for training its AIs. So Google comes up with Amp to convince publishers to keep their content on the open web, where it can be collated, indexed, and otherwise used by Google for Google's services like search and those search result cards that keep people from visiting the content creators. Google's explicit carrot in all this is the user benefit of page loading speed. Google's implicit carrot in all of this is page rank. But Google's real motivation is to have all of that information available to itself. Can you imagine what would happen if content from even one of the big providers was no longer visible to Google? New York Times, WaPo, or even Medium? It would create a huge hole in a number of Google products and services, make its search results look even weaker than they already are, and cause people to look for search alternatives. That's my theory, anyway.
- ffritz 6y agoInteresting, though the barrier for users to install a new app seems to be very high these days. Most people only install a few necessary apps and thats it. In addition, we are talking about publishers here. There are thousands of news sites, no user has more than a couple of news apps. That’s why they have to keep up their website anyway, with or without amp.
- Kevin605 6y agoThis has already happened in China, where Baidu (The Chinese equivalent of Google) can’t crawl any articles from WeChat (The Chinese equivalent of Medium), as a result, the usefulness of its search result has deteriorated significantly. Recently, Baidu has been trying to start its own publishing platform with little success.
- saagarjha 6y ago> WeChat (The Chinese equivalent of Medium) TIL
- jakeogh 6y agoUsers executing their code are the product. Giving those people the independence of knowing who they are talking to is contrary to their business model. Image AMP? No URL for You! https://news.ycombinator.com/item?id=23322730 https://news.ycombinator.com/item?id=23322730 Tangental: https://news.ycombinator.com/item?id=20930270 https://news.ycombinator.com/item?id=20930270
- Mikeakogu 6y agoThanks for this educative post
- causality0 6y agoI despise AMP for the entirely selfish and pedestrian reason that it hijacks my phone's browser bar and won't let me access tab management until I scroll all the way back up to the top of the page.
- chvid 6y agoI think the author has got it all wrong. You are supposed to trust Google. And when your browser says 'Google' - you know it is all good.
- Kiro 6y agoAMP is disliked by privileged people who have never experienced how truly awful browsing the web with a bad internet connection can be.
- saagarjha 6y agoPerhaps they instead see the “solution” to be problematic.
- Kiro 6y agoYes, but not acknowledging the problem and that AMP is a solution, even if it's the wrong solution, defeats any meaningful discussions. We need something like AMP but outside of Google's control. My point is that it's so easy to just see the drawbacks and none of the benefits when you're sitting on a good connection. All threads on HN becomes completely one-sided where everyone is just backslapping each other's complaints.
- theduder99 6y agolike a moth to a flame eh googler?
- mikro2nd 6y agoCan you elucidate what you'd consider a "bad" internet connection? I live Out In The Styx, in a Shithole country, at the end of an allegedly 2MB/s piece of wet string masquerading as an internet connection that seldom lives up to its adverted performance. AMP has never once made any significant difference to my web experience.
- paxys 6y agoRegardless of your feelings on AMP, the premise of this article is wrong. Security standards and expectations are still exactly the same in this model. You see "google.com" in the address bar and trust that Google is serving you the right content.
- aronpye 6y agoAMP is the main reason I switched to DuckDuckGo from Google. Webpage rendering often used to break on iOS, in particular scrolling where the page would just go blank.
- collinmanderson 6y agoYeah AMP is one of many reasons I switched to DuckDuckGo. “Why am I giving Google this much power? Why am I contributing to them being a monopoly?” were the general reasons. Hearing people mention low quality search results was what kept me off, but I’ve actually only needed to do a google search about once a week, far less than I was expecting.
- gorgoiler 6y agoWith the utmost respect to you and the other commenters here, when I see positivity about the abstract, hypothetical technical merits of something with a long history of, in practice, being part of an extremely controversial power play it reminds me a lot of the comments I see promoting a widely installed piece of process management software — one which a lot of people don’t really want, whose subtle changes to layers of abstraction introduce new and unexpected bugs that can only be fixed by further coupling, and which can also be reasonably described as a single entity politically maneuvering itself to bring order to the chaos at the expense of living in, for want of a better term, a dictatorship. Well at least under Google AMP, the pages loaded on time.
- Clausinho 6y agoI'm out of the loop, care to elaborate which PM software you are referring to?
- gorgoiler 6y agoEdit: it’s too controversial I think to introduce it by name. Googling “RedHat’s replacement for Linux init” would be a good start.
- deleted 6y ago[deleted]
- izzagilani 6y agoSo systemd, right?
- wutbrodo 6y agoWhy would providing an unambiguous pointer to the name be any more controversial than just saying it? The only extra purpose doing it this way serves is being annoying. (Its systemd, for anyone who doesn't feel like googling it)
- xg15 6y agoI guess he was referring to systemd.
- thierryzoller 6y agoYou are at home in front of you screen. Thank me later.
- bamboozled 6y agoWhat happened to The Internet? Honestly. Google should can do this stuff if they like...on their own network in their own ecosystem. Insane that they got rich from hyperlinks and now want to fiddle with the so others can't.
- TLightful 6y agoF-"£$U£$%"£$%$C££R$£^%^K GOOGLE.
- cannedslime 6y agoThe only one who wins when media outlets integrate AMP, is google. Stop the madness, for the love of an open internet. You gain nothing, you are just giving google control over content as the new norm.
- surajs 6y agoGoogle sucks, i'm going golfing.
- Angostura 6y agoThis is absolutely the reason that Google is no longer my default search engine on mobile.
- Kiro 6y ago> Accelerated Mobile Pages (AMP) are lightweight pages designed to load quickly on mobile devices. AMP-compliant pages use a subset of HTML with a few extensions. Accelerated Mobile Pages (AMP), is a very accessible framework for creating fast-loading mobile web pages. That itself sounds awesome and something we should promote. The other part of AMP is of course that it's served through Google's servers. While their global edge caches probably bring the speed up I think that's less important. I other words: AMP as a framework to force users to build light-weight pages without bloat is a good thing. Google's control is a bad thing. I think many of the comments here make it a borderline topic where there's either all or nothing. I want to see a more nuanced discussion on what the possible alternatives and solutions are instead of just "Google bad, AMP bad".
- 7leafer 6y ago"Does google rig the system to squash its rivals and hurt us?" Well, this is one kind of modern skepticism I particularly like: Does gravity kill if one jumps off a cliff? Is a sphere round? Is it really bad if we give up our freedom? Who are we to think for ourselves? When questions like this are asked, the damage is already done. And it seems like it's already beyond repair.
- nokya 6y agoI have my own proxy filtering all my desktop and mobile traffic, anything 'AMP' is filtered spot on. Sometimes nothing shows up, sometimes the original server responds after a few seconds. I'd rather not see the page at all than play this game.
- hjek 6y agoTry the Redirect AMP to HTML[0] browser add-on to get out of the game without getting blank pages. There's also Privacy Redirect[1] for getting out of the Youtube / Twitter / Instagram / Google Maps game. [0]: https://addons.mozilla.org/en-GB/firefox/addon/amp2html https://addons.mozilla.org/en-GB/firefox/addon/amp2html [1]: https://addons.mozilla.org/en-GB/firefox/addon/privacy-redirect/ https://addons.mozilla.org/en-GB/firefox/addon/privacy-redir...
- geertj 6y agoI noticed this two days ago and it was the final straw that made me switch to DuckDuckGo on all my devices.
- user764743 6y agoYou're on a website stealing content from NYT.
- anonymousDan 6y agoGoogle amp links are so annoying too when you want to send a link to other people of something you've searched for. One of the main reasoms Inuse duckduckgo.
- anonymousDan 6y agoIs anyone aware of any Firefox/brave plugins that strip Google amp links?
- metalliqaz 6y agoI don't like AMP and I wish we just fixed the problems it is designed to handle at the root cause.
- jacquesm 6y agoGet rid of Google?
- buboard 6y agoI wonder how many phishing sites are masquerading as google from google
- vincentmarle 6y agoAMP is a lot like how I was browsing the web on my phone before the iPhone came out. Opera Mini’s servers would proxy every single page I visited and fetch and pre-compile it before sending it compressed to my phone. It was way more performant than trying to render the page natively on my crappy phone. (That’s why the iPhone was so unique, it was the first phone that could natively render websites really well). Sure, there were a lot less security and privacy concerns back then, but I think the majority of users simply don’t care as long as it works.
- stuff4ben 6y agoit's 2020 and ya'll are still using Google?!?! DDG all the way!
- SpeakForMyself 6y agoTotally disagree with this drama whoever is putting on for the sake of being in the group of 'anti-google so I am looked as if I am so smart and so know it all and google is trying to control everyone and nobody sees it except me now I am writing a post to tell the world how different I am' As a user, before learning computer knowledge, I am so thankful and amazed by those AMP pages, because they are really fast! And I barely look at this URL thing to care for security which is huge deal to those conspiracy queens, because as non-tech user I don't know a heck about URL, all I care is how fast a page is presented to me. So, no, the problem is only you, yes, you can just use a dramatic title just because you are so bored with your life to cause a scene, you are only embracing yourself and bring some noise to this already chaotic world, please, go find yourself something to do instead of trying so hard to be internet famous. Thank you.
- grey_earthling 6y agoIf The New York Times is unhappy with this use of their branding, it seems to me that they could easily claim trademark infringement. They could argue that Google is using The New York Times's branding and domain name to make it look like this content is controlled and provided by The New York Times, when in fact it isn't, and that an average person (“idiot in a hurry”) could be deceived. If The New York Times willingly gives Google permission (or The New York Times willingly abets Google's monopoly position), then I guess Google can do whatever they like.