12 ms·
Guidance to developers affected by effort to block less secure browsers, apps
- phendrenad2 6y agoGoogle is becoming increasingly user-hostile, which is the wrong business phase to be in while your competition is on the rise. Other email providers are (finally!) getting almost as good as Gmail. Bing is an okay substitute for Google Search. YouTube has been strangled by subservience to advertisers and people are moving to Twitch and other places.
- olliej 6y agoThe only reason chrome isn’t mandatory is that there are still a few hold out browsers they can’t force out of the market. Also, the requirement that the browser not lie about its identity in the UA means that the existing UA tests that google properties deploy everywhere means that those “acceptable” browsers may still be “accidentally” blocked. It would be nice if people would start to acknowledge that chrome is the new IE and Google is the new MS. Actually arguably worse: in addition to using free services subsidized by their primary advertising business. Once that business is gone they start charging. All the while they grossly destroy user privacy, and come up with new specs that just happen to accidentally make tracking users easier. Generally poorly thought out ones to help single teams at google without any thought of what the general problem is.
- devit 6y agoI fail to see how they can possibly do this in a way that isn't trivially worked around by just embedding the same code as the full browser. I guess their best bets are detecting non-fullscreen screen sizes on mobile, requiring Widevine or requiring Chrome and adding some proprietary authentication code, but all these are problematic and can be worked around. Also of course both Firefox and Chrome support automation via WebDriver and WebExtensions so not quite sure what they plan to do with "The browser must not provide automation features".
- smlckz 6y agoIf browsers which does "server-side rendering" are blocked from accessing my Google Account, I lose my access to all Google services requiring sign-in like Gmail etc. I don't have the privilege to own a desktop, laptop, or even smartphone. I am using a J2ME enabled feature phone with Opera Mini to access the internet. Most websites requiring "modern browsers" are out of reach from me. Thanks to all the people who maintain the websites that are functional without JS or upto ES5.1 (last JS version supported by Opera's server rendering powered by Presto) or less. Only Google Search and Gmail works in Opera Mini, other Google services don't. So I am out of luck! Anyone out of luck like me?
- ashneo76 6y agoIs it possible to de Google?? Google provides no value other than a few email address
- forgotmypw17 6y agoAlways welcome all browsers and configurations.
- neurostimulant 6y agoRent a vps and run WRP [0] on it. WRP is basically a proxy that use chromium and render the pages as imagemap html pages that compatible with older/simpler browsers. It should works on opera mini. Hopefully google won't block it outright. [0] https://github.com/tenox7/wrp https://github.com/tenox7/wrp
- smlckz 6y agoIf I could rent a VPS, I could buy a smartphone instead. sigh My j2me phone's screen resolution is 320x240, and Opera's server does a respectable job in transforming webpages to fit into that small screen size. It also uses a binary file format named OPML to encode the transformed page. With my 2G internet connection, it'd take much more time to load a page and cost me more to load images.
- ashneo76 6y agoBasically, fuck you too Google. For sucking the open source community
- forgotmypw17 6y agoThis only concerns auth?
- 1vuio0pswjnm7 6y ago"The browser must not proxy or alter the network communication. Your browser must not do any of the following: * Rewrite HTTP headers The browser must have a reasonably complete implementation of web standards and browser features. You must confirm that your browser does not contain any of the following: * Headless browsers * Text-based browsers" Sure, I see the "increased security" goal of protecting HTTP headers and allowing images and Javascript in the context of the "sign in" process that Google has implemented. However I also see the goal of not impeding Google's online ad services business which, at least in part, relies on images, Javascript and blocking automation after the user signs in. I fail to see the benefits of these requirements outside of Google's sign-in process. HN does not impose such restrictions. It is no less useful than Google, IMO. Imagine if HN required "a reasonably complete implementation of web standards and browser features" just to sign in. I once read that Marissa Mayer, former Google VP, still uses Pine. Bias disclosure: I am a text-only browser user; I prefer text-only software.
- hedora 6y ago> The browser must not provide automation features. This includes scripts that automate keystrokes or clicks, especially to perform automatic sign-ins. So... banning password managers? I’m not seeing how that’ll improve security. Also, I wonder how they plan to enforce this. Presumably impacted browsers will just spoof the user agent, etc.
- mleonhard 6y ago> You must confirm that your browser does not contain any of the following: Headless browsers Won't this exclude automated testing? How will app developers test their "Sign-In with Google" integrations? > Your browser must not do any of the following: Server-side rendering Won't this exclude Kindle users and folks in poor countries that have underpowered phones?
- 0xy 6y ago>Rewrite HTTP headers Unless you're Google and you need to bolt on X-Client-Data headers in all requests made to DoubleClick, of course.
- heavyset_go 6y agoAnti-trust action can't come fast enough.
- austincheney 6y agoMost of these controls are a blessing. They are blocking gross incompetence from front-end developers who don't know ow to do their jobs. I say this as a front-end developer.
- dageshi 6y agoOnce upon a time Google would've been applauded for forcing people to improve their security. Like when they made https a ranking factor for sites and overnight forced all the laggards to move off http. Now, people just scream "monopoly" at everything google does, good or bad and boy is it getting tedious.
- gostsamo 6y agoOnce upon a time Google had "don't be evil" in their corporate mission and people trusted them to act in good faith. Good old times.
- Ygg2 6y agoNow it's "Do the right thing (for corporate)"™. How times have changed.
- tester756 6y agoThey still do >And remember… don’t be evil, and if you see something that you think isn’t right – speak up! >Last updated September 25, 2020 src: https://abc.xyz/investor/other/google-code-of-conduct/ https://abc.xyz/investor/other/google-code-of-conduct/
- gostsamo 6y agoBefore, it stated that the company must not be evil. Now, it is for the employees not to be evil somewhere in the end. In the meantime, if you are high up the management ladder, you can fuck the subordinates and get away with millions.
- Denvercoder9 6y agoPreviously on HN: https://news.ycombinator.com/item?id=25155451 https://news.ycombinator.com/item?id=25155451
- ivanche 6y agoNext step: The browser must not be anything but Chrome.
- bxk1 6y agoThis is pretty much the current step already, not the next step, with broad ban on anything that isn't a lot like Chrome and anything that they simply don't want to allow. In the last thread the narrative was hijacked with bullshit "security" justification, while in the blog post they ban much more broadly, any automation, text-based browsers, etc.
- bpodgursky 6y agoNo way. (Theoretically on Android, but let's be real, they won't). No way they are giving up marketshare on Safari or on corporate boxes with IE. They've paid so much to get onto iPhones, there's not a chance they'd risk any marketshare erosion.
- gtirloni 6y agoPlease stop spreading FUD on HN.
- userbinator 6y agoFUD? You still do not see the frog boiling after years of pushing Chrome and mindwashing developers into creating sites that only work in Chrome? Google is the one "spreading FUD". Just look at the downvoting going on in the discussion and you'll see some pretty obvious attempts to silence anti-Google criticism.
- maest 6y agoThey need non-Chrome browsers to exist, to avoid accusations of a monopoly. Chromium is arguably a strategy around this, where you can have a bunch of browsers using the same (Google controlled) infrastructure. Safari is an exception, since Apple won't accept giving that up in their products.
- 6y ago
- jhasse 6y agoWhat does this mean for IMAP?
- d99kris 6y agoIt was recently (Oct 8) announced that that Google would provide a 12-month heads-up for stopping less secure app access, so it's my understanding that IMAP is not affected at this point. https://workspaceupdates.googleblog.com/2020/03/less-secure-app-turn-off-suspended.html https://workspaceupdates.googleblog.com/2020/03/less-secure-...
- duskwuff 6y agoNothing. IMAP doesn't use the web signin form that these changes apply to.
- gtirloni 6y agoNot much. If you're not using app passwords and your client wants to authenticate using Google auth (e.g. Thunderbird), it has to open the user's browser and setup the oauth flows instead of embedding the browser directly in the app.
- edoceo 6y agoIf you have "less secure apps" you can still use password. Going forward G is pushing use of XOAUTH2 for IMAP auth. There was some noise from the PHP group because the imap_* functions don't do XOAUTH2 (but Net_IMAP and Zend IMAP libs do the trick)
- kwijibob 6y agoI hate the smartphone app trend of having embedded browsers. Just launch me to my preferred real browser. Stop trying to trap us in your ecosystem.
- athenot 6y agoEven worse when the embedded web view is not properly detecting the user-agent and puts up a banner... prompting you to download the app (looking at you, NHL).
- tinus_hn 6y agoNever mind carrying around 6 copies of Chrome on your phone
- pitaj 6y agoWhat are you talking about? Embedded browsers use the system webview, provided by Chrome, Firefox, or whatever is configured.
- tinus_hn 6y agoSure, Chrome on iOS is ‘only’ a 118 mb application! And much of that is also in Google Maps, the Google Docs apps etc.
- marcan_42 6y agoChrome on iOS isn't even a real thing, it's just an app embedding Safari like every other app with a webview (because Apple's draconian policies forbid alternate browser engines). All the other Google apps also have to use Safari for any web stuff.
- trickstra 6y agoI'm surprised such draconian policies still haven't been challenged in court like Microsoft or Google have.
- dleslie 6y agoThis has nothing to do with security and everything to do with banning tools like youtube-dl, wget and others; from the post: > The browser must identify itself clearly in the User-Agent. The browser must not try to impersonate another browser like Chrome or Firefox. > The browser must not provide automation features. This includes scripts that automate keystrokes or clicks, especially to perform automatic sign-ins. Edit: I feel like mentioning youtube-dl was a mistake. It's not just about youtube-dl. This policy bars the use of all text-based browsers, headless browsers, browsers without javascript, and browsers with automation when accessing Google's services. It bans browsers that contain Node.js, even.
- austincheney 6y ago> The browser must not provide automation features. This includes scripts that automate keystrokes or clicks, especially to perform automatic sign-ins. If a web developer knows what they are doing they are using the standard web APIs supplied by the browser in an efficient way, designed to be invisible to accessibility for accessibility test automation, and thus this control from Google is largely unenforceable. As such I believe this is just a block against incompetent forms of automation that probably shouldn't be there in the first place.
- InfiniteRand 6y agoThis is kind-of funny requirement given the history of user-agent strings being incredibly convoluted. I mean Chrome doesn't clearly identify itself as Chrome, it still identifies itself as Apple Webkit
- trickstra 6y agoAlso given Google's history of sending corrupted version of pages to Firefox useragents. https://www.reddit.com/r/firefox/comments/7whdv4/googlecom_in_firefox_for_android_normal_vs_w/ https://www.reddit.com/r/firefox/comments/7whdv4/googlecom_i... https://androidforums.com/threads/problems-with-firefox-user-agent-override-and-google-images.1039531/ https://androidforums.com/threads/problems-with-firefox-user... https://www.ghacks.net/2018/07/25/google-making-youtube-slower-for-non-chromium-browsers/ https://www.ghacks.net/2018/07/25/google-making-youtube-slow... ... and many more
- haunter 6y agoHope that doesn't kill ungoogled-chromium
- skee0083 6y agoWill iOS mail app still work?
- IshKebab 6y agoThis presumably means they are banning Chrome Lite?
- swiley 6y agoDear god I'm glad I got my crap off of google.
- uniqueid 6y agoSame here. It's like I made a sharp, long-term investment. As the months pass, I enjoy the payoff: watching Google get worse and worse without it touching my life.
- throwawayay02 6y agoI really dislike this notion of many internet companies of their own self-importance. To me the obvious example is a website that requires you to set up a very strong password and link a phone number. A user account is a two way street, the website should give you the tools for good protection, and you should use them if it matters. If it doesn't matter to me let me use a weak password. If it doesn't matter to me let someone hack my account, what do I care. And if the user doesn't care why does the website owner? Why should hackernews care more about my user account than myself for example? It could be argued this position of security maximalism is due to cutting costs on customer support, for account recovery, but as I understand it Google doesn't have customer support already.
- Latty 6y agoFrankly, this is just wrong. Maybe for some circumstances, but in Google's case, they provide email. When it comes to things like email, your account being compromised doesn't just affect you. Google let people send out emails from those accounts, so if a compromised account is used for spam, it hurts them reputationally as they are actively facilitating harm. You might not care if that account is compromised, but they should.
- bobbyi_settv 6y agoEven if you don't care if someone hacks your Google account, the rest of care when we start getting deluged with spam from that Gmail address.
- brokencode 6y ago1. Many uses are not computer experts and don’t realize they’re at risk. They won’t adopt extra security measures unless they need to. 2. No company wants to announce that a bunch of accounts were hacked. The excuse that “our users don’t care” would be widely criticized. 3. Well yes, of course companies want to reduce customer support costs, but guess who else benefits from not needing customer support? The customers. It’s better to avoid a problem in the first place than to have great mechanisms for resolving it.
- 6y ago
- jlokier 6y agoMake sense for security. However, if just to login in some application, it would be awful UX if going to the login step in an application triggers an unwanted load of 3 desktops full of 20 browser windows and a few hundred tabs, and some minutes delay while they all start up. So if I'm not already running the "full browser" required for auth, ideally for authentication I'm going to want it to launch an "alternate profile" instance of my full browser which doesn't include all the other tabs or normal user info. I.e. the browser should somehow be able to load just one special window for this application, and remember that it hasn't actually loaded my regular profile and saved state yet. Clicking on any links for info that is logically "outside the application", that's what should probably lead to a regular full browser being started. In the end, this ideal browser behaviour in response to an application requesting Google auth is much the same as using an embedded web view - except running separately from the application for security purposes so that it's UI isn't subject to application interference. Given that's just a web view with security properties, why not instead allow auth to launch a "security instance" version of an embedded web view, one that is subject to guarantees from the OS/GUI security systems that it is running independently from the application which triggered its launch?
- izacus 6y agoOn Android, there's a feature called Chrome Custom Tabs (despite the name, it works with other browsers as well) which basically opens the default browser window in a restricted UI without most of the chrome and tabs. It shares the state and extensions though and it's meant as a replacement for these exact banned flows (on Android, webview logins are banned for years now). I wonder if such interface could be exposed for desktop browsers.
- hedora 6y agoI briefly hoped this would apply to search and ad serving as well. Sadly, no. I’d happily set my user agent string to Mozilla 1.0 if it stopped all that stuff from working.
- unixsheikh 6y agoI'm glad I neither use Google nor YouTube! Security.. riiight!
- etaioinshrdlu 6y agoHow does this mesh with their plans to deprecate User-Agent? https://9to5google.com/2020/01/14/google-deprecate-chrome-user-agent-string-privacy/ https://9to5google.com/2020/01/14/google-deprecate-chrome-us...
- heavyset_go 6y agoIt meshes nicely for Google, because they want to use feature detection to detect whether you're using a Google-approved browser and not a competitor's unapproved browser. This is why they state that JavaScript must be enabled, because that's how they do feature detection: > The browser must have JavaScript enabled.
- indymike 6y agoThis reads like Google is trying to eliminate browsers that don't have a user attached to them. Good luck with that.
- LockAndLol 6y agoIf you don't like that google does this: stop using their products. Make the effort to choose, use and promote a service you think is doing a better job. If you so deem it necessary, tell Google why you're switching. If people actually did something instead of just complain, companies like this would think pretty hard about their actions since it would harm their bottom line.
- Aldipower 6y agoThis is a campaign against Lynx! > The browser must have JavaScript enabled. > You must confirm that your browser does not contain any of the following: > * Text-based browsers Once upon a time the internet was TCP with things like FTP, Email, Newsgroups, IRC and yes also HTTP (aka WWW). Now, the internet seems to be Google, Apple, Facebook aaand SEO. Hey, wait! There is a small shiny place!! Hackernews! :)
- forgotmypw17 6y agoMy site still works in Lynx, nojs, and Netscape. Google is leaving the web behind, doing its own thing. That is fine.
- Enginerrrd 6y agoMan, that's deeply aggravating.
- gitweb 6y agoThis is regarding man-in-the-middle attacks. There is not attack on Lynx. Many sites do not functionin without JavaScript. Sad, but that's the way it is.
- trickstra 6y agoGoogle is actually misrepresenting the danger in their blogpost, because they write "One form of phishing, known as man-in-the-middle,..." - this statement is clearly false because MITM is not phishing. Not in any stretch of the definition. So who knows what is the real justification.
- kilburn 6y agoI agree that the post is not very well written, but if you are a bit generous you can read them saying "phishing sites are doing MITM attacks that we have a very hard time distinguishing from CEF logins, so we are axing CEF logins altogether". I'm appalled of the general direction Google is pushing the web to (an AD haven), but some of their points make sense.
- vaccinator 6y agoSomewhat unrelated, but Google already blocks me from my account all the time because they don't recognize my device because of privacy settings in my browser... they need a lesson about fingerprinting I guess.
- wwwigham 6y agoI feel like detecting these environments is directly at odds with user privacy and anti-tracking; but I guess google has never been anti-tracking, so that's not too surprising. Still, I'm incredibly disappointed that they'd essentially require clients be fingerprintable to auth. I feel like this is just codifying an arms race between strengthening requirements and JS environment checks, and hostile embedders ability to emulate a real runtime, and taking legitimate embedders with less incentive to participate in the race down as collateral damage.
- Sniffnoy 6y agoSo, uh, does this mean I won't be able to use IMAP with Gmail anymore...? It already complains at me about this for being less secure than webmail, but that doesn't seem to be covered in this announcement.
- mekkkkkk 6y agoHaven't heard of any large scale phishing operations on CEF/Electron/whatever apps. Then again I'm not keeping up with infosec news. Are they a big problem?
- cannedslime 6y ago"less secure" more like you are not allowed to scrape the almighty scraper. What pathetic double standards.
- lxe 6y ago> The browser must have a reasonably complete implementation of web standards and browser features. You must confirm that your browser does not contain any of the following: - Headless browsers - Node.js - Text-based browsers Yeah... This has nothing to do with "standards or security".
- ForHackernews 6y agoThis link breaks the back button in Firefox. Is that also supposed to improve security?
- akersten 6y ago"The browser must not provide automation features." in authentication workflows. Ok, so no password managers that auto-fill your password (like the one built-in to Chrome)? This guidance is not well-thought-out.
- jka 6y agoIs all of this an arms race around the question "is that a human at the other end of the connection?" And if so, can that be solved by the proposed approach of gradually narrowing the requirements for supported clients?
- ratiolat 6y agoI wonder what is the plan for MFP to email scanning. There's a potential of bricking hardware in this case (or not using Google Workspace, formerly knows as G Suite). Disabling less secure apps has been postponed though because of covid.
- ogurechny 6y agoWelcome to Google's private World Wide Web. Please ensure that you use the one and only official Google WWW client (others exist, but they are just for show). Unauthorized alteration of its configured operation will result in user termination. One might wonder how that can accompany all the talk about open standards, and multitude of devices implementing different subsets, and responsive/adaptive/semantic design, etc. Then you realize that you don't really need, say, user-agent sniffing if you are already in position to dictate what browsers will and will not do, so into the trash it goes. You don't need interoperability hacks if you've stopped having interoperability problems.
- ashneo76 6y agoPrecisely
- cookiengineer 6y ago"optimized for IE6 and Microsoft ActiveX" We've been there before, haven't we?
- tinus_hn 6y agoHaving a separate app for these insecure devices would be an improvement.