5 ms·
This seems insane and malicious as hell and I can't believe it's being sold as a feature. It's essentially just lying to users about which website they are curr
by 37 4y ago
This seems insane and malicious as hell and I can't believe it's being sold as a feature. It's essentially just lying to users about which website they are currently visiting, or maybe I'm missing something.
- nybble41 4y agoThe original version where the content was served from Google's cache without any cryptographic verification but displayed as if it came from the original site was… misguided at best. It meant that you were trusting Google's servers to only cache the content and not modify it. The new system adds verification that the content is exactly what was intended by the original site, despite being served through a cache, so the user agent is no longer lying about which website the user is visiting. Sure, the data was fetched from Google, but that's not the important part. It's been verified to have originated from the server shown in the address bar.
- jabbany 4y agoGoogle modifying the content is not really the threat model most people care that much about though (similar concerns exist with other caches/cdns)... Google redirecting traffic to servers they control to mine interaction and interest data on the other hand...
- nybble41 4y agoThat was Mozilla's objection to the Signed Exchange standard: you lose some privacy because the cache server can see the page data in the clear, even if they can't modify it. But IMHO resisting Signed Exchange doesn't help here at all, since you gave up that data to Google when you followed the link (which is not obfuscated). It makes no difference at that point what is shown in the address bar, as the page has already been served. Also, since Signed Exchange means you don't have to trust the cache, it implies that Google's cache could be replaced with a different (but still not fully trusted) server behind the scenes without changing the result.
- thomasahle 4y ago> you gave up that data to Google when you followed the link I gave up information on what site I was visiting, but if I enter any information on the page, won't that still go to Google? It's going to look like I have an https end-to-end channel with the site I'm visiting, but really Google is Man-In-The-Middleing the whole thing?
- nybble41 4y ago> I gave up information on what site I was visiting, but if I enter any information on the page, won't that still go to Google? So far as I can tell the user agent uses the original (non-Google) URL for the purpose of same-origin tests when it's returned from Google's cache using the Signed Exchanges standard, so the risk is effectively the same as if the page were served from the original server and Google were not involved. The page could send anything you enter to Google, but it would need to be coded that way to begin with. It wouldn't do so just because it was served through their cache.
- jabbany 4y ago> It makes no difference at that point what is shown in the address bar, as the page has already been served. If this were truly the case (that it didn't matter), the argument can be made that there is no reason to change the host -- just show it as google.com like it does now. The only reason that you'd want the address bar to show a different domain (i.e. the "author" rather than "publisher") is exactly because it _does matter_ to the user!
- nybble41 4y agoIt makes no difference for privacy in that you already told Google which page you were going to by following the link. Naturally the address shown in the URL bar matters to the user or we wouldn't be discussing this at all. With Signed Exchanges it can correctly reflect the origin of the content rather than being cluttered with irrelevant details about the cache server.
- 4y ago
- autoexec 4y ago> Google modifying the content is not really the threat model most people care that much about You're right that's not the concern held by the people accessing the content, but the target here seems to be the websites who partner with Google. If I publish something on the web and another company wants to host my content (including caches and CDNs) and I expect many of my readers will access my content without ever touching my servers directly, I would absolutely be concerned about my content being modified where it's outside of my control. Seems it'd be a lot of trouble to track down and verify that it were happening at all since google could change content any number of ways or not at all depending on the individual making the request.
- alanh 4y agoThe charitable explanation (steel man) is that this is simply the web catching up to email. You can use DMARC, SPF, and/or DKIM behind the scenes to validate any third party you’d like to send (cryptographically verified) email on your behalf. Is it so insane to allow a third party to serve web pages for you? I am pretty skeptical, however, given the way Google will (ab)use this.
- freyr 4y agoNot a fan of AMP in general, but if the data is signed, is this much different than, say, static assets being cached and served by Cloudflare?