8 ms·
Google proposed Web Bundles could threaten the Web as we know it
- maproot 6y agoGoogle = evil!!! They sleep and dream only about how to spy! Teach your users at every place, at each of your site not to use there spyware & "search engine". Instead of this use privacy search engines, browsers and tools. eg. privacytoolslist.com
- mtmail 6y agoThree of three comments where you add the URL. It can quickly look like you only comment to self-advertise.
- maproot 6y agoI just only want that people to take care of their privacy and help them start using open source software. It's a good starting point. What I can really recommend. Absolutely free, no ads, no profit to show them alternatives of proprietary software. And I'm not native. It's very hard to participate in discussions. Much more easy to show/link information that I found useful. Sorry.
- dimitrios1 6y agoInterestingly the main quotation in the article is from a Brave team member -- what does Brave do when this is rolled out? Fork Chromium?
- tmd83 6y agoI am really curious what's the general opinion on Googler's as a web developer. I have seen a long while ago some nice articles from Google about site optimization. Do they even follow any of their original advice or Google basically keep doing over engineered stuff fixed by adding another set of over engineered staff? Let's talk gmail. I just refreshed the window and it did close to 400 request, ~8MB download which translates to nearly 40MB resource. And it keeps making more requests even when I'm not doing anything. And a refresh of Google.com the search page did 33 request and nearly a MB download. And they are preaching the world about optimizing the web?
- return1 6y agoYes because heavy pages clog their crawlers. Of course they are not following their advice (neither does FB)
- tormeh 6y agoThis is great: https://developers.google.com/speed/pagespeed/insights/?url=mail.google.com https://developers.google.com/speed/pagespeed/insights/?url=... I mean, kudos to Google for (probably) not cheating here, but that's a low score.
- GuB-42 6y agoAnd I don't really understand why they don't follow their advise. Saving a single byte on Google front page can potentially save terabytes of bandwidth. I know the idea of "developers are expensive, hardware is cheap" but when you serve trillions of search queries, hardware is worth considering. The 8 MB you get don't come from nowhere, there is a server somewhere sending them to you. And improving user experience for billions of users is not a negligible advantage either. Maybe it is a sign that Google is ready to be taken over by a less bloated company. It is, after all, how Google came to power, by being efficient and to the point. Just look at to original Google home page compared to its competitors.
- bryan_w 6y agoThis actually gets back to the issue of web bundles. Google doesn't have to worry about the 8 MB because they have an extensive CDN, but smaller sites have to save every bit because they are being charged for it. If Google can leverage its CDN to serve the smaller sites, everyone wins.
- samsquire 6y agoThis is an idea I had, an alternative to web bundles and solves the same issues. Inside a HTML file, we introduce an attribute for embedded resources called cache=”identifier”. Script tags, style tags will have this attribute defined. There would also need to be an embedded image introduced. Inline all your resources. The browser will fetch the HTML and add whatever has the cache=”identifier” to its cache. Then when the browser fetches a page, it will send a Cache-Got header, this is a bloom filter serialized of identifiers cached. The server will check the bloomfilter to see if an item needs to be sent to the client and exclude the contents of those embedded resources with an empty script tag or empty style tag. EDIT: Why is this being downvoted?
- TekMol 6y agoI think their idea is to combine that with signing the bundles, so a page from www.someserver.com can be served by anyone, aka Google. I guess this would mean Google can serve all content on the web. There seems to be a strong urge in Google to cut the connection between then endpoints of the web and become the central authority. Make all traffic flow through their machines. Let no information arrive at the endpoints. Right now, requests on the web are kind of p2p. A user requests a website, the publisher serves it any way they see fit. Directly via their servers or via a CDN of their choice. Google seems to have a strong focus on ending this. Turning the web into Googlebook / AOLoogle. I wonder why. Do they see their business model threatened on the open web? Or do they see a chance to increase their profit with a closed web?
- laurent123456 6y agoThe article seems to give some clue. The format would allow serving unblockable ads using random urls, or urls that look legitimate. Google’s goal is to have full control over the user experience so that they can serve more ads.
- TekMol 6y agoKind of. It is already be possible today to put ads into a page directly. But the benefit for Google would be that if they deliver the bundle, they would know that their ads are in there. Heck, they would know everything that is in there. So they would have full information about all ads and everything that is taking place on this new "web". Of course, they could also use the opportunity to hinder ad blockers further. For example by not allowing plugins to get between reading the bundle and rendering it. They already weakened plugins a lot over the recent years.
- geofft 6y ago> But the benefit for Google would be that if they deliver the bundle, they would know that their ads are in there. Heck, they would know everything that is in there. Is this a problem for Google currently? 1. They already get loaded/notified for the ads themselves. Do they have a problem with sites claiming they're serving ads and not doing so? (Wouldn't those sites just not get paid?) 2. They'd be serving this in response to web searches. They've already crawled the web page, or at least some version of it. (Yes, it could be a different version, but given the increasing unpopularity of what's now called "server-side rendering" aka the normal thing back in the CGI days, there's no guarantee even with a bundle that the site as seen by a human matches the same site as seen by Googlebot.) 3. If you are running Google Ads or even Google Analytics, you're evaling JavaScript controlled by Google in the context of your web page. They already have access to every detail of what's happening with your site, down to (if they want) where the user's mouse pointer is. What more information would they have access to by seeing the bundle? > For example by not allowing plugins to get between reading the bundle and rendering it. Why could they not do this with normal web pages? Define a Content-Security-Policy: no-extension-modifications header and make up some story about protecting high-value sites from buggy extensions....
- tormeh 6y agoSo it's a signed executable, running in a sandbox, served from a federated app store... Isn't the whole JS/CSS/HTML web crap a bit overcomplicated for this purpose?
- jakelazaroff 6y agoI was hoping this would be more than a rehash of the article on the Brave blog about the same topic, but alas. Link to that discussion: https://news.ycombinator.com/item?id=24274968 https://news.ycombinator.com/item?id=24274968
- rektide 6y agoI for one believe in the specified use cases of Web Bundles, & believe they are worthy. https://wicg.github.io/webpackage/draft-yasskin-wpack-use-cases.html https://wicg.github.io/webpackage/draft-yasskin-wpack-use-ca... What we have here is a budding conspiracy theory, not even a theory, just gesticulation. Consensual Delusion, a belief that we are persecuted by secret forces that must be held off, held at bay. This started months ago with an incoherent rambling ticket by the Brave author that is being cited. He spent months going back & forth with wild accusations & unspecified concerns. After dozens and dozens of exchanges, he finally named one single scenario, that people might "hide" their tracking malware by renaming files as they put them into the bundle. Color me extremely unimpressed & unscared. Enormous sound & fury, for a capability that is in no way different from the web we already have today. It's not hard to setup a.webserver to randomize asset names. Nothing about webbundles is new or changes that. Consensual Delusions like this hacked up hoax of a story threaten reality as we know it. As the old civic videos say: DONT BE A SUCKER. Anyone selling fear, uncertainty, & doubt is to be met with skepticism. Increasingly, FUD is how Apple/Mozilla/Brave are selling their anti-feature policy. "Trust us, we won't let the web work with midi" doesn't sound that great, but is much more honest than what we get, which is "these engineers & standards groups working on these specs are secretly trying to undermine this treasured web which we must protect & keep as is at all costs". the involved engineer's histories indicates they obviously care enormously about bettering the web, & in this case are combatting sizable transpiling tool bloat for devs, & enabling offline sharing & offline capable web, and literally fighting censorship, which are truly worthy goals all that will vastly help the web. This is all super hard to work through. Yes, google used the web to reap enormous profit by means of enormous information control & inventory systems for ads & eyeballs. But Google also would not exist without the web, & historically the web was a small toy that couldn't do much compared to apps. The tables have turned, & the web is clearly ascendant, much safer, & increasingly we understand that the limitations of ux were largely from lack of will to explore & test what limits there really were, so the situation is no longer so obviously tense. But Google Chrome & Chromium & the spec work Google does are, imo, designed to improve a communal shared resource for all humanity, designed to greaten the web, not subvert it. We can see that here, as the engineers working on webbundle have shown a thousand times over their commitment to honest above board clear integrity as they have tried & tried & tried to work with Peter Snyder as he fumbled & plodded his way to a scenario where WebBundles pose any real danger, & Peter has imo failed at presenting anything. We can see the engineers take Peter seriously, try to work with him. And so I feel it is in general. It is intimating as hell that the web is so big, has so many capabilities, that so much keeps getting added, and so much of that comes from gigantic unimaginably huge pools of capital derived from eyeballs-on-screen. But somehow it has been working out, the engineers have genuinely cared about doing the right thing, & usually the standards bodies & TAG can eventually come to harmony & agree, & the web improves. Peters dissent thread: https://github.com/WICG/webpackage/issues/551 https://github.com/WICG/webpackage/issues/551 Personally I greatly look forward to WebBundles. It will radically improve the JS module situation, yay, a thousand times yay, & giving people the ability to share content directly with one another, without relying on centralized infrastructure, is one of the most genuine pure & true new expanses for the web & one I am greatly looking forward to.
- azangru 6y agoThe missing hyphen in the title is really confusing.
- jasode 6y agoFyi... Web Bundles and Signed HTTP Exchanges are confusing topics so I think it's worth reading 2 previous threads with comments from 2 Google employees (spankalee, jefftk) [1]. One may still choose to discount their explanations because they may be biased sources but I still think everyone should try to understand what they're saying. Hopefully, being familiar with the technical details will elevate the discussion so people who disagree can point out specific and concrete technical flaws of those explanations rather than just restating a generalized version of "Google is trying to take over the whole web." [1] previous threads: https://news.ycombinator.com/item?id=24275752 https://news.ycombinator.com/item?id=24275752 https://news.ycombinator.com/item?id=24278068 https://news.ycombinator.com/item?id=24278068 https://news.ycombinator.com/item?id=24324120 https://news.ycombinator.com/item?id=24324120
- drewbug01 6y ago> Hopefully, being familiar with the technical details will elevate the discussion so people who disagree can point out specific and concrete technical flaws Asserting that an elevated discussion should center only on technical flaws and disagreements is a myopic way to look at a topic. There’s more to the web than the technology used to power it. How a technology is used, and what it enables (good or bad) is an appropriate topic for this forum and constitutes elevated discussion.
- jhall1468 6y agoI think you misunderstood the point you were replying to. The idea is that you can’t really have a discussion about what it enables or how it’s used unless you already understand the technical details. And that shows as a lot of the comments/blog posts about this topic are using underlying technical assumptions that are entirely incorrect.
- drewbug01 6y agoThe plain language of the comment doesn’t say that: > so people who disagree can point out specific and concrete technical flaws That’s the basis of my reply. I think you have a good point; but it isn’t what the parent said.
- ffpip 6y agoYet another thing Google wants to fix by serving everything through their servers instead of asking devs to fix their owns sites. Same problem with AMP. Instead of asking news sites to fix their slow pages, it forced them through AMP by promising better result ranking. Ask them to make their sites faster within a month or say they'll get booted off search. You'll be surprised at how fast they comply
- deleted 6y ago[deleted]
- jmull 6y agoI think this line of criticism of web bundles misses the mark. It looks to me like the issues raised are perfectly possible and just as easy without web bundles -- that is, these may be legitimate issues, but are independent of web bundles. My issue with web bundles is that it's yet another pile of complexity with very little incremental value over things that already exist. A poor tradeoff. There's a substantial on-going cost to each web standard added so each one needs to "pay" for itself with broad or deep usefulness. Web bundles are just another way to skin a cat.
- cflat 6y agoLet’s call a spade a spade. The only real world problem that WebBundles (and Signed Exchanges) really solve is to allow AMP to impersonate your website. Google wants all the click data and the click through navigation data about users (by way of passive logs) so they can sell more ads. There are no other real world problems that web bundles solve.
- judge2020 6y agoLinks on the page are the same as before signed, so the only actual problem with them is not being able to change/delete the documents hosted elsewhere immediately.
- cflat 6y agoYea, but the web server delivering them is now google. Google now gets the access logs and using the persistent tls socket can follow the users activity. Sure the content is signed, but the delivery is no longer private.
- Spivak 6y agoBecause of CDNs the delivery was never all that private to begin with.
- cflat 6y agoCDNs are a known commodity with business relationships. You can’t have an unknown CDN in the mix. They are an extension of your infrastructure and you can control if they are or aren’t in the path of control. They key here is that there is also a legal and business relationship.
- deleted 6y ago[deleted]
- dlubarov 6y ago> Google now gets the access logs It doesn't seem like this would materially change the information Google receives. The status quo is that Google knows (via redirect links) what search results I click and when. It doesn't technically know what data the website will send me, but normally it's the same as Google's cached copy. It doesn't know what resources my browser will block, but in a bundle scenario, my browser is free to ignore resources even if they must be transmitted as part of a bundle. > using the persistent tls socket can follow the users activity Even if this caused browsers to keep idle sockets to Google alive more often, what information is there to be gained from an idle socket?
- jimbobimbo 6y agoWeb bundles look like a great thing for Electron and PWA like scenarios, specifically due to signature support. We had to drop service workers and reinvent the wheel with APPX (basically a signed ZIP file) in one of our apps, to ensure code integrity.
- jeroenhd 6y agoIs there anything in the web bundle standard that forces outdated pages to be refreshed? The spec seems to say little more than "detecting stolen keys is not our problem". I can imagine this being a problem when news stories turn out to be false alarm and Google happily keeps serving the original content instead of the corrected content. There's also a risk of vulnerability here, as getting a signed package might very well be used to host phishing pages on web caches.
- noisy_boy 6y agoThe only answer is to not click on ads. Do your research via review videos/amazon etc (I know that they are/could be indirect advertisements but atleast the creators get some sponsorship money). Then go to the brick and mortar shop, check it out and then, here is the kicker, pay the extra $5 bucks to buy from them.
- maple3142 6y agoI don't understand why can't this be blocked by content blockers. I tried open a .wbn in the original article, and tried to inspect the resources using devtool, it still have files listed there. So content blockers can still block something like xxx.wbn:/js/ads.js if browser have such api. Also, I think web bundle can be a Electron replacement too for some use cases, so that some totally offline JavaScript webapp don't have to use Electron.
- bogwog 6y agoGoogle should just fork the web already. Let them create their own private platform and do whatever they want. The massive control Chrome and Android gives them means they can do whatever they want already, but at least with a private platform they won’t have to fight people and deal with the negative PR of doing evil stuff. And then the rest of us who like privacy and competition and ad blockers can use the “legacy” web.
- fartcannon 6y agoThen they'll just pay a few journalists to run a couple hit pieces on the open web, saying it's a place where people who kick puppies reside.