4 ms·
If I have not understood the post then it is probably their communication style. They lay out a bunch of things to fix about a system that could bring down you
by smorgusofborg 5y ago
If I have not understood the post then it is probably their communication style.
They lay out a bunch of things to fix about a system that could bring down your browser. What if that system that communication with Google about GCP messed up for them isn't even the IPs you are contacting during unrest in Khazakhstan or an election in Uganda? What if it is a semi-intentionally confused transparent proxy?
Testing a few more things that a friendly proxy may do as it improves your connection is hardly the same as assuming the worst about your network in proper paranoia mode.
- tjoff 5y agoThey lay out one thing that can bring down your browser if a bunch of circumstances are true. They are fixing that thing and all those circumstances and try to make sure that circumstances of that characteristic won't happen again. The what-ifs you are talking about could just as well be any homepage on the internet. ... and that page could also be MITMed. So your point is to not have bugs?
- smorgusofborg 5y agoYou expect bugs, I expect bugs, they expect bugs.. This explains why they lead with a discussion of defenses they were taking like certificate pinning or encrypting this tracking that caused them to discount risks of putting this service in a new system and letting it run on startup and contact a 3rd party? Except that isn't what they lead with, they have done nothing to reiterate a position that's appropriate for a browser maker.
- tjoff 5y agoNot sure what your main point is? Telemetry is inexcusable? I'm the first to agree that it absolutely should be OPT IN and not OPT OUT as it is now, but even so my biggest concerns would not be trying to evade hostile countries. If that is your bar you can't just install a mainstream OS and mainstream software and assume that it is a good idea.