3 ms·
Mitigated how? Websites are going to force users to click "allow."
by waon 6y ago
Mitigated how? Websites are going to force users to click "allow."
- onion2k 6y agoWebsites are going to force users to click "allow." That's a bit strong. A website can't force a user to anything. The point is that to use the feature nefariously without the user knowing it's happening is relatively easy to prevent by putting the feature behind a permissions flag. If the user actively wants a website to be able to make connections they can say yes. If the user doesn't know then they ought to be saying no, but really they won't and they'll say yes if the warning isn't scary enough. The browser vendors could also do things like throttling connections or asking for permission again if things look too weird.
- ResidentSleeper 6y agoMost people I know just click "yes" on all popups until the website starts working. In between every other website asking for notification/location permissions and a huge pile of GDPR popups (which are actively hostile towards users that attempt to opt-out), we've managed to condition web users into routinely agreeing to give up their privacy and security. Hooray.
- nuker 6y ago> Most people I know just click "yes" on all popups until the website starts working This. Defaults matter. You cannot introduce a privacy sensitive feature just with a permission dialog box. You must expect that most users just click through, and continue to protect those "dumb" users.
- zeroimpl 6y agoThe only websites which would force you are: - legitimate websites using this feature for valid purposes, such as to control devices on your local network - targeted malware attacks trying to hack devices on your local network I’m certain we will not start getting popups for this on any mainstream website. So as long as this permissions thing is more than a simple yes/no dialog, I’m not worried.
- waon 6y agoI’m not convinced because many of those “legitimate websites” don’t have a very good track record of respecting user security and privacy. Given past events, I find it hard to believe that the ad industry or the entertainment industry or any other industry won’t abuse access to these APIs. To make it worse, if popular websites wants permission to use these highly-invasive APIs, users would have no choice but to cave in. This worries me a lot. Even if you don’t consider bad intentions, the security implications are huge. Imagine if Zoom had used this feature. The security fiasco a few months back would’ve been made a whole lot worse.
- zeroimpl 6y agoThe “legitimate websites” that disrespect privacy and security almost always do that in a way transparent to the user (ignoring the cookie prompts, but I don’t think that’s a fair comparison). For example, news websites could try and access my location info, but they don’t because there’s a permission prompt which would appear.
- waon 6y agoFor this particular feature, there can be no meaningful transparency whatsoever. Permission to use TCP or UDP is very, very different from permission to access location info. Any user can easily imagine the possible consequences of allowing the latter, but the definitely not the former. Heck, no one can possibly know the actual consequences unless someone goes through the effort to reverse engineer websites using this feature.