4 ms·
For a user to correctly answer a permissions dialog, they need to learn programming and read all the source code of the application. To say nothing of the negat
by merlish 3y ago
For a user to correctly answer a permissions dialog, they need to learn programming and read all the source code of the application. To say nothing of the negative effects of permission dialog fatigue.
In practice, no-one who answers a web permissions dialog truly knows if they have made the correct answer.
Asking the user a question they realistically can't answer correctly is not a solution. It's giving up on the problem.
- codedokode 3y agoThey don't need to learn programming. Just write that this technology can be used for displaying 3D graphics and fingerprinting and let user decide whether they take the risk.
- pmontra 3y agoMost of them will say, "I need to see this site, who cares about fingerprints." Some will notice that they're on their screen anyway, a few will know what it's all about. Maybe "it can be used to display 3D graphics and to track you", but I expect that most people will shrug and go on.
- bcrosby95 3y agoYou could maybe display the request in the canvas instead of a popup. If the user can't see it, they'll never say yes.
- kevingadd 3y agoThey're going to be confused if you say "display 3D graphics", because canvas and WebGL will still work. The website will just be laggier and burn their battery faster. That's not going to make sense to them. "Fingerprinting" is a better approach to the messaging, but is also going to be confusing since if you take that approach, almost all modern permissions are fingerprinting permissions, so now you have the problem of "okay, this website requires fingerprinting class A but not fingerprinting class B" and we expect an ordinary user to understand that somehow?
- deelly 3y ago> In practice, no-one who answers a web permissions dialog truly knows if they have made the correct answer. Counterpoint: if webpage with latest news (for example) immediately asks me to allow notification, access to webcamera and location I definitely know what is correct answer to these dialogs.
- kevingadd 3y ago"Do you want to allow example.com to send you notifications" is way more understandable to a layperson than "do you want to allow access to WebGPU" or "do you want to allow access to your graphics card". Especially because they would still have access to canvas and WebGL. Permission prompts are a HUGE user education issue and also a fatigue issue. Rendering is widely used on websites so if users get the prompt constantly they're going to tune it out.
- account42 3y agoYou can always word things in a way that the user understands. > Especially because they would still have access to canvas and WebGL. Those should also be behind a (or the same) permission prompt.
- tgsovlerkhgsel 3y agoI think browsers should distinguish more aggressively between "web application", "web site", and "user hostile web site". Many APIs should be gated behind being a web application. This itself could be a permission dialog already, with a big warning that this enables tracking and "no reputable web site will ask for it unless it is clear why this permission is needed - in doubt, choose no". Collect opt-in telemetry. Web sites that claim to be a web application but keep getting denied can then be reclassified as hostile web sites, at which point they not only lose the ability to annoy users with web app permission prompts, but also other privileges that web sites don't need.
- beebeepka 3y agoDo you have something specific in mind with your opening paragraph? Because defining what is a web site and what's an app, strikes me as particularly impractical idea. You correctly point out that yes, there are a number of powerful APIs that should be behind permissions. But there are a number of permissions already, so we need to start bundling them and also figure out how to present all this to the regular user. Frankly, I wouldn't know where to begin with all this.
- tgsovlerkhgsel 3y agoNews sites are a particular category that I expect to spam people with permission prompts, as they did when notifications became a thing. Without the deterrent of possibly landing in the naughty box, they'd all do it. With it, I still expect some of them to try until they land in the box.
- bagacrap 3y agoClearly if we knew how to perfectly identify user hostile websites we'd not need permissions dialogs at all. Distinguishing between site and app, e.g. via an installation process, is equivalent to a permissions dialog, except that you're now advocating for one giant permission dialog instead of fine-grained ones, which seems like a step backwards.
- 3y ago