11 ms·
Safari 17 Link Tracking Protection
- exabrial 3y agoFTA: Why does the StopTheMadness extension want to disable input field max length? That’s a very useful feature for developers to give instant feedback to the users. I get it: a minority of people have 64+ char email addresses, but if you know the server is going to reject the POST, why not stop it before the submit?
- X-Istence 3y agoFun fact, I bank with a bank I won’t name, who has a change password flow that allows for up to 32 character passwords. Their login page only allows for 16 character passwords using the max length. This would truncate my password on login. Backend handles the longer password just fine though.
- deleted 3y ago[deleted]
- mywittyname 3y agoWe might bank with the same bank!
- chrisoverzero 3y agoTo paste a value that’s too long, then remove some part in the middle. Otherwise, it’s truncated.
- lapcat 3y ago> Why does the StopTheMadness extension want to disable input field max length? That’s a very useful feature for developers to give instant feedback to the users. I'm the developer of StopTheMadness, and it doesn't disable input field max length. Rather, it warns you when you paste something longer than the max length; otherwise, without the warning, your paste gets silently truncated, and you wouldn't know it.
- noja 3y agoIn Safari for iOS 17, I am seeing a gray inline box appearing on some websites asking about "disabling tracking detection" (or something like that). It looks suspicious as if it is part of the webpage, and not part of Safari. Anyone know if it's legit?
- ezfe 3y agoDo you use Private browsing and then refresh the page? That box appears because private browsing protections are much stricter than regular browsing and can break websites.
- noja 3y agoYes! I find the UI confusing because I can't tell if it's really from the website or from the browser (it's part of the screen the website has control of).
- lapcat 3y agoDo you mean "If this page is not displaying as expected, you can reduce advanced privacy protections which may resolve issues"? That's legit, and also annoying. I've filed a bug with Apple to get an option to permanently suppress it.
- noja 3y agoThat's the one!
- mark_l_watson 3y agoI have doubled down on using Apple’s privacy and security capabilities but I also don’t feel so great about living in a walled garden and it is not totally clear to me how they might use my data. I use it all: I run all of my Apple devices in Lockdown Mode, and I try to use private browsing tabs as much as I can.
- hospitalJail 3y ago>it is not totally clear to me how they might use my data. Well they have given it to the US government, they give data on people from China to the Chinese government, and the same for Russia. That is likely out of necessity, but the bigger concern will be when Apple stops growing and stockholders will demand more.
- bunga-bunga 3y ago> I try to use private browsing tabs as much as I can. I regularly open websites and searches in private mode, but cookie notices are killing me. iOS Safari doesn't even share cookies between private tabs, so there's one notice per tab, even if you already accepted/denied it.
- deergomoo 3y agoGiven you use private browsing a lot it might not be something you’re willing to trust, but I find Consent-o-Matic[0] to be fantastic and indispensable. I have it set to blanket deny all non-essential cookies and the mobile web is a far less miserable place now. [0] https://apps.apple.com/gb/app/consent-o-matic/id1606897889 https://apps.apple.com/gb/app/consent-o-matic/id1606897889
- bunga-bunga 3y agoI tried it for a couple of days and found that it clicks the wrong button, landing me on a secondary “cookie page” where I have to still manually tap. This happened on Google.com and I think YouTube and Yahoo (or some of its properties). I tried several cookie extensions and often either they don’t work or break the website (hiding the notice, but leave an invisible wrapper that causes the website to be completely unclickable)
- captainmuon 3y agoIt seems like the tracking protection looks for specific parameter names. Won't people just start using randomized names? Already now I have to rename my stats script from 'track' to 'res', otherwise I only see about a quarter of users. (I'm just using it to count how many views each page has, not for tracking.) The endgame is to move all ad and tracking code to 'first-party', i.e. the website delivers the code in its source. (Un?)fortunately that is not happening quickly since advertizers distrust the publishers.
- hadrien01 3y agoIf you just want to count page views you can use your HTTP server logs, no need to have Javascript.
- dewey 3y agoThere's a reason we don't do that anymore and it's that there's too much noise and it's easier to filter it out if you aggregate the data somewhere (bot traffic, scraping etc.). Sometimes you also don't really have access to HTTP server lots depending on where you deploy your frontend.
- maple3142 3y agoI don't think that would play well with cdn caching.
- captainmuon 3y agoI used to do that almost 20 years ago with a little script. This time I looked into my log file, said nope, too complicated, and just installed a WordPress plugin (or Matomo in another case).
- veave 3y ago>The endgame is to move all ad and tracking code to 'first-party', i.e. the website delivers the code in its source. I don't know why this hasn't been happening. I can think of a thousand ways of making sure that users see my ads. The fact that you can block ads via /etc/hosts is... pathetic.
- simonw 3y agoIf anyone from the Safari team is reading this: please, please document this stuff at a technical level. As a web engineer I need to know the full details of how this works at the browser API level - the end-user targeted terminology really doesn't help me. I want to understand things like how I can implement SSO across two different domains.
- jonhohle 3y agoThere are several standards for cross domain authentication - oauth, oidc, etc.
- bgorman 3y agoI don’t want these features. This will inevitably break certain experiences. Some features like query parameters are part of HTTP and shouldn’t be tampered with.
- lapcat 3y agoYou can disable it in Safari Settings.
- mrweasel 3y agoWhat greatly fascinates me is that apparently no one in the advertising industry looks at all the effort that goes into subverting their rather invasive tracking and comes to the conclusion that maybe, just maybe, they've turned the tracking dials just a tad to far to the right. There seems to be zero self-reflection from the advertising industry. They'll try to find ways around these new measures in Safari, rather than wonder why the hell someone is going to great lengths to prevent their tracking. You see this on places like LinkedIn as well. People in the ad business have zero reflections on why companies like Apple do this or why the EU is trying to regulate their industry. It's always whining about how their right to do business is infringed. The entire online ad business just seems to be completely morally bankrupt.
- doe88 3y agoIt is difficult to get a man to understand something, when his salary depends on his not understanding it.
- notaustinpowers 3y agoThat revenue chart always has to go up and to the right! /s I work in SEO so I work with advertisers quite a bit, and they absolutely do not care about privacy. I had one who thought that when a user clicks on our site from Google that we can grab their email since "they're logged into their Google account anyway, why not just get their email so we can do some email marketing?" When I said we can't do that, he thought it was a bug, not a privacy feature. If they could install cameras in your home, they would, and they have.
- azinman2 3y agoWhat are you expecting to happen, exactly?
- mrweasel 3y agoAssuming that people are generally as good as I chose to believe I expect the advertising industry to realize that they are in the wrong and revert to content based advertising. Realistically I expect that they'll find a way around the link tracking protection and not give a shit. It's just that I fail to see how a group of people can be so insensitive, so fixated on profit that they ignore everything related to moral. How can an entire industry be so detached from everything from any concept of right or wrong.
- tolmasky 3y agoCan't trackers change to using a credit-card-scheme-style "dynamic" tracking ID system (you know, the same way you can tell if a credit card is Visa or MasterCard)? For example, if instead of looking for "gclid", a site looks for "f(query-key) == 39", where "f(query-key) = char1 + char2 + ... + charN % 64". Under this system, each advertising provider simply needs to own a mod number instead of a query-key (Google would look for 39, Microsoft for 23, etc.). You can then have infinitely many tracking keys, that don't even need to be consistent within the same session. At this point, you would probably feel a lot less confident about arbitrarily removing these from the URL, since it becomes increasingly difficult to know for sure that you aren't breaking a legitimate use-case query parameter.
- joshstrange 3y agoThey could, in the same way ads/analytics can be served from your own domain (or more likely subdomain) to avoid various adblock/analytics-block tools. It's a cat and mouse game.
- SoKamil 3y agoTikTok already does this similar way. If you share a link to a video, tracking data is encoded in the URL