4 ms·
I’ve been using this for a couple years now, and absolutely love it. Thanks, team! I also love that it’s owned by the University of Aarhus, as I am more willin
by pcl 2y ago
I’ve been using this for a couple years now, and absolutely love it. Thanks, team!
I also love that it’s owned by the University of Aarhus, as I am more willing to trust academia with something that has a disturbing level of (client-side) access to my browsing data.
I really wish the browser vendors would develop better permission models to guarantee my data can’t be exfiltrated by a malicious plugin (aka a once-good plugin that got bought out by a bad actor).
For example, I’d love to see the browser impose a policy of “no outbound network requests except to pre-registered endpoints with pre-defined headers and data payloads”, so that plugins could fetch allow lists but could not exhilarate my browsing history.
- sciolistse 2y agowhile we're wishing for impossible things i'd also love if the consent dialogs were an actual standard. if sites could describe a list of what they needed consent for and the browser supplied the actual dialog, so i could just configure it to always allow all if i wanted to, that would be fantastic.
- paulryanrogers 2y agoOr even better a header to signal the wish to not be tracked. We could call it "Do Not Track", and enforce with laws.
- junto 2y ago[flagged]
- joshuaissac 2y ago> if the consent dialogs were an actual standard. if sites could describe a list of what they needed consent for and the browser supplied the actual dialog There is a standard for this called P3P, which was implemented by Netscape, Firefox, Internet Explorer and Microsoft Edge before eventually dropping support for it. But there was nothing requiring website owners to use it. Various data protection regulations across the world require them to obtain consent for collecting data, but they are not required to recognise consent or non-consent expressed via P3P settings. These standards will only get used if the website owners are forced to use them, either by regulators or by monopolistic/oligopolistic market forces. https://en.wikipedia.org/wiki/P3P https://en.wikipedia.org/wiki/P3P
- buzer 2y agoAs far as I understand at least some businesses in California are required to honor GPC. https://oag.ca.gov/privacy/ccpa#collapse8b https://oag.ca.gov/privacy/ccpa#collapse8b > Under law, it must be honored by covered businesses as a valid consumer request to stop the sale or sharing of personal information.
- jitl 2y agoIt is very hard to prevent exfiltration by code that is allowed to write to the DOM in today’s browsers. There is Content Security Policy (csp) which applies to the whole page and sometimes governs scripts injected by extensions but not the extensions themselves. I would love to see browsers add a chain-of-custody to scripts and DOM nodes, so it is easy to tell which nodes were added/touched by a script, and if a script adds a script tag, that newly loaded script would show up as branches in the custody tree. Then we could say, “no nodes or scripts in this tree may trigger requests to unauthorized domains”. It would be sort of like CSP, but with a runtime-tracked implicit capability/taint for extensions.
- jraph 2y agoAdd some sort of signing process and call this Secure DOM.
- ronsor 2y agoNo, then people will mistakenly think it is 100% secure.
- whereismyacc 2y agoSecurer DOM.
- aristus 2y agoBrowser DOM Security Mechanism.
- xelamonster 2y agoI'd like to see a separation between read and write permissions to the DOM for plugins personally. I would feel much better if I didn't have to give any plugin that might need to modify parts of a limited set of pages the ability to silently manipulate anything and everything I see in the browser. Read-only access could be granted by default, then only when a plugin sees something it wants to act on it could pop up and request my approval before doing so. The current approximation of that by disabling the plugin globally and enabling it on specific pages is so clunky and adds so much extra friction that I don't ever bother with it.