8 ms·
SugarCoat: Private browsing without breaking the web
- marcodiego 5y agoI actually don't care that much when sites break because of my ad blockers. If sites require my ad blockers disabled to work correctly, these sites are what is broken in the first place.
- rgrmrts 5y agoAgreed, but some sites are unavoidable. For example, I recently had a website break on me that was important for me to access (hospital network website, had to check test results). This approach potentially allows me to browse the web without having a binary switch for blocked ads and traclers.
- 1vuio0pswjnm7 5y agoGood attitude. The only thing that is "breaking" is a web developer's opinionated view of how to present information. As we all know, that view is not always a reasonable one. The web developer does not work for you, the user. She works for advertisers or advertiser-funded organisations. IME, pages that are almost wholly JSON can easily be "redesigned" on the client side by the user (me), to present the information in a format that is most pleasing to the user (me). Having a company that has chosen online ads as its "business model" sponsor researchers to "improve privacy" is inherently flawed. If this company was serious about user privacy they would not show ads. Today's online ads imply data collection and as such are are not compatible with privacy. Companies want (need) to know who looked at an ad and when. That conflicts with privacy. Solve the problem by not showing ads. Brave's customers are advertisers. Make users the customers not the targets. Forget about ads. Will not happen. When users are not willing to pay for whatever "service" the tech company can offer, privacy problem cannot be solved. This publication is a nice bit of "submarine PR" as PG would call it.
- nyanpasu64 5y ago> IME, pages that are almost wholly JSON can easily be "redesigned" on the client side by the user (me), to present the information in a format that is most pleasing to the user (me). What's a page that's made of JSON? And isn't it less semantic and more dependent on JS to convert the page into a readable representation, than a pre-rendered static site?
- 1vuio0pswjnm7 5y agoYouTube, i.e., a video page or a search results page, is one example of a page that is mostly JSON. These YT pages rely on automation. The browser runs Javascript to format the page and to make HTTP requests that send data back to Google (privacy violation, no user benefit). The browser loads thumbnail images, automatically. There are many steps that have been automated. The JS is of course not written by the user, but by Google to support its data mining and advertising business. However, it is also possible to retrieve a web page and perform the necessary steps manually, without Google's "help". Instead of letting a browser do whatever the website's Javascript programmers want it to do (to suit advertising interests, not user interests), the user controls the process, performing the steps manually. This is how I approach YouTube and other convoluted websites. I retrieve the page to memory (tmpfs), using a relatively simple TCP client + local TLS proxy (no gigantic web browser is needed for such a simple task). I do not retrieve the separate Google Javascript files (which a Js-enabled browser will automatically request. There is no need for them; they are used to manipulate the user for Google's interests. (I am not interested in commercial videos nor am I interested in Google's JS "video player"; I do not use a mouse.) As the page is mostly JSON, it is not formatted to be easily readable on the screen. I reformat it manually, using tr and sed. Then I extract the bits I want from the text, i.e., playback URLs, and various metadata such video IDs, descriptions, durations, suggestions, views, likes, channels (if any), time since upload, thumbnail URLs, continuation token, etc. Then I make a subsequent HTTP request if I want something further. By contrast, using a "modern" Javascript-enabled browser controlled by an advertising-funded organisation to retrieve a page from YouTube will result in all manner of privacy intrusion. Even just leaving a page open in the browser, without interacting with it at all, the Google JS will trigger constant HTTP requests, some empty (zero benefit to the user, the user would never intentionally make such requests). The amount of code needed for the fully automated Javascript-enabled browser is gigantic. The program is a security nightmare. The amount of code need for youtube-dl is also relatively large; IME the distributed binary can take over 7 seconds to start up. The amount of code I need is, by comparison, tiny. I only need sed, tr and a TCP client. Everything fits on a single page. Fast and reliable.
- northisup 5y agoif not ads, what type of monetization do you prefer?
- 3np 5y agoMy biggest friction is not ads but e-commerce. Anti-fraud/anti-bot detection goes red for me from time to time - presumably having somewhat successfully removed surface areas for fingerprinting makes the AIs put me in the "shady" basket, so sites with high sensitivity set will not allow me to proceed. PayPal is the absolute worst here and the process is horrendous, opaque and time-consuming. I've been blocked by Stripe as well. Sometimes I will abort a purchase when I see that the only payment option is PayPal.
- w-ll 5y agoI use ublock and some custom DNS stuff and Paypal has never broke for me. I actually use Paypal at checkout more than not.
- aembleton 5y agoAt least with Paypal, I know it will work whereas with some random payment provider I do not. By default, I block all third party scripts which means if I haven't come across the payment provider before then it'll break.
- 3np 5y agoI guess I'm just unlucky. Cursed by the algorithm or something. Maybe having moved a lot and having a very foreign name for my country of residence are factors as well.
- miohtama 5y agoHere is Brave’s announcement with technical details: https://brave.com/privacy-updates/12-sugarcoat/ https://brave.com/privacy-updates/12-sugarcoat/ The actual paper: https://brave.com/wp-content/uploads/2021/06/sugarcoat-ccs-2021.pdf https://brave.com/wp-content/uploads/2021/06/sugarcoat-ccs-2...
- jakecopp 5y agoAre there any plans for this to be implemented in Firefox? I don't feel like jumping over to Brave.
- Gualdrapo 5y ago> SugarCoat is designed to be integrated into existing privacy-focused browsers like Brave, Firefox, and Tor, and browser extensions like uBlock Origin. SugarCoat is open source and is currently being integrated into the Brave browser. Though does not mention any plans about integration with Firefox, it seems like it would be a matter of time
- michaelsbradley 5y agoFor what it's worth: I used Firefox (rel/dev/nightly, it varied over weeks and years) from 2011 to mid 2020. From mid 2020, I switched to Brave as my daily driver and I won't be switching back, based on daily UX and DX. (Brendan, thank you for getting Brave off the ground, and best of luck!)
- gruez 5y agoOn firefox you're probably better off using container tabs + temporary containers. With that, you can basically have a separate browsing session (cookies/website data) per tab, which allows for isolation and doesn't require a whitelist to work (unlike the approach described in the OP).
- wisniewskit 5y ago
- r00fus 5y agoAlright - so if the example they provide illustrates the jist of their approach, it's essentially "sandboxing" the scripts so that calls to localstorage succeed but are then effectively non-persistent. Can scripts be written to bypass such sandboxing?
- c4m 5y agoThat's right, it's essentially sandboxing the scripts. But I think the real innovation is an automated system they've created for writing the sandboxing code based on tracing the execution of the malicious/ad scripts in the browser. Otherwise, what you're saying would be true, and this could be easy to break/bypass. They discuss the details of this in the paper: https://brave.com/wp-content/uploads/2021/06/sugarcoat-ccs-2021.pdf https://brave.com/wp-content/uploads/2021/06/sugarcoat-ccs-2...
- sneak 5y agoI block a bunch of trackers both via uBlock, NoScript, and NextDNS. I don't notice much breakage; I'm not sure what this tool is trying to solve.
- zamadatix 5y agoAs the article describes the lists in e.g. uBlock consider allowing a site to work with a privacy harming script preferable to blocking the script and having a broken site. The only time you notice breakage now is when the an the block list is not up to date with the changes on the site. This tool aims to run the functional part of such scripts without compromising by allowing the privacy impacting part of the script to run instead of an all or nothing.
- dirtyv 5y agoI really like the sound of this but I don't trust Brave. I used Brave on iPhone as soon as it came out, always in private mode so as to not save any history or open tabs. A while back, after an update, I opened the app and it immediately opened dozens and dozens of tabs, all of which I recognized as being tabs I had opened in the past. It almost seemed be opening pages back to when I first used the app. I obviously left a complaint in the reviews. The developers quickly pushed another update but never addressed how or why this was even possible.
- michaelsbradley 5y agoGaslighting at its… not so finest.
- aembleton 5y agoHow is this gaslighting? To be fair, I may just not be fully up to speed on the term but I thought it meant telling someone that their experience didn't happen.
- james-redwood 5y agoYou can turn this off in settings somewhere. I remember having the exact same problem as you did. A terribly strange feature
- a-dub 5y agohm. interesting. could be an interesting feature for the mozilla vpn. rather than just redirecting all traffic to a clean pipe, redirect it into a special networking environment where tracking endpoints are mocked up to be benign. even better would be if users could also analyze their own traffic, block suspicious things and contribute to the mock environment for firewalling personal data. maybe the future of firewalls will be more about keeping user data in, rather than keeping malicious actors out...
- userbinator 5y agoeven better would be if users could also analyze their own traffic, block suspicious things and contribute to the mock environment for firewalling personal data. That's basically a MITM proxy --- and I've been running one for decades now, to adjust pages and block (as well as inject) content. But if Mozilla tries to do that with its VPN, the paranoia-spreading "security" industry (and we all know whose interests they really protect...) is going to roast them for it.
- a-dub 5y agowhy? because it would cut into sales for local firewall style products? i always assumed most of the money in that world was in enterprise software, services and labor. i don't think the personal tools for this are all that great anyhow and tools that would allow consumers to monitor their own devices and use oss tools for defeating software that doesn't serve them could very well be a hit. what's the alternative? a closed platform like apple? there's gotta be a middle ground between having to run your own monitoring infra and handing the reins over for everything to a company like apple.
- gruez 5y agoIn section 3.2.2 they mention being able to handle obfuscated/minified scripts, but based on the description it doesn't look very robust. Any sort of anti-debug/tampering would break this, eg. storing the value of window.localstorage somewhere, then comparing it against the value of window.localstorage when you try to access it. If the values differ, there's probably some debugging/tampering going on, and the site can hold the content hostage and demand you turn off the protections. I'm not sure why they don't just patch the javascript runtime environment (ie. the implementation of window.localstorage itself). That would be much more robust and harder to detect. Plus, you don't have to mess around with rewriting scripts.
- NiekvdMaas 5y agoLooking at the source code [1], I have to agree with you. This is very easily detectable by anti-tampering scripts. Using JS Proxies would have been a better approach, although that is detectable as well (see e.g. [2]). To be really undetectable, the mocks should have been done on V8-level. 1. https://github.com/brave-experiments/sugarcoat/blob/master/mocks/navigator.js https://github.com/brave-experiments/sugarcoat/blob/master/m... 2. https://github.com/abrahamjuliot/creepjs https://github.com/abrahamjuliot/creepjs
- mintplant 5y agoYou can't turn existing global objects into proxies, unfortunately.
- mintplant 5y agoHey, author here! Kinda shocked to see this on HN. Regarding anti-tampering: this work is in a "taking the Web as we found it" kind of model. We focused on improving the existing state of the art for content blocking and resource replacements rather than adversarial environments deliberately trying to get around SugarCoat. There are already other ways that sites try and circumvent URL-based blocking anyway—bypassing SugarCoat won't be the low-hanging fruit. We touch on this in the discussion section of the paper, but if a script is making itself too much of a problem, filter list authors can always opt to block it entirely. Regarding patching the runtime environment: other systems have done this, but they haven't been adopted. Deep engine modifications are hard to get upstreamed and, absent an actual standard, don't give you cross-browser compatibility. SugarCoat-generated scripts can be (and are!) deployed in existing content blocking systems today, and aren't locked to one particular browser.
- newscracker 5y agoI’d really love to see this in Firefox, even though I already use uBlock Origin, Privacy Badger and Container Tabs. Even if this is added, I’d still not give up on these extensions. Though Brave has been involved in (controversial?) work that’s tangential or unrelated from the core web, such as a substitute for advertising based income for sites, a crypto wallet, etc., I do admire the relentless focus on creating features that help and protect users. It also seems to have a higher velocity of feature releases, perhaps because it can still rely a lot on the open source Chromium project (which it customizes) as opposed to the Firefox team that has to maintain and improve Gecko/Servo as well as handle end user facing features.
- donclark 5y agoI saw several container tabs extensions. Is this the one you use? And if not, which one do you use? https://addons.mozilla.org/en-US/firefox/addon/container-tabs-sidebar/?utm_source=addons.mozilla.org&utm_medium=referral&utm_content=search https://addons.mozilla.org/en-US/firefox/addon/container-tab...
- newscracker 5y agoNo, it's not that one, but I'll check it out. I use Firefox Multi-Account Containers by Mozilla [1], which is what many other container related extensions depend on. I also use Temporary Containers [2], Facebook Container by Mozilla [3], and Google Container [3]. There are also container extensions for Twitter, YouTube, etc. [1]: https://addons.mozilla.org/firefox/addon/multi-account-containers/ https://addons.mozilla.org/firefox/addon/multi-account-conta... [2]: https://addons.mozilla.org/firefox/addon/temporary-containers/ https://addons.mozilla.org/firefox/addon/temporary-container... [3]: https://addons.mozilla.org/firefox/addon/facebook-container/ https://addons.mozilla.org/firefox/addon/facebook-container/ [4]: https://addons.mozilla.org/firefox/addon/google-container/ https://addons.mozilla.org/firefox/addon/google-container/
- wisniewskit 5y agoJust FYI, Firefox is working on Total Cookie Protection and other features like SmartBlock to keep third party storage access blocked while not breaking web pages. It's definitely nice to see the anti-tracking space getting so active over the past couple of years.
- jessaustin 5y agoThe actual title at this time is "This Tool Protects Your Private Data While You Browse".
- Sephr 5y ago> SugarCoat replaces these scripts with scripts that have the same properties, minus the privacy-harming features Depending on the scope of these replacement scripts, this may run into API patent & copyright issues. Additionally, the trackers can simply start using different tracker script URLs to avoid this type of implementation. A better solution is to allow these scripts to load (without cookies) and patch all of their actual network emissions and storage access to follow consent rules.
- 3np 5y ago> this may run into API patent issues Google vs Oracle says otherwise.
- crhutchins 5y agoBrave browser combined with Sugarcoat, I wonder how this combination will turn out. Also, it would be great if Sugarcoat could be integrated with other browsers that don't want to jump the Brave train.
- m9731526 5y agoThere's a browser plugin named Decentraleyes does this.