3 ms·
Just ask the user if its okay, like with geo data, translate web site, etc. "Allow example.com to track your location?" [Yes] [No] "Allow a1.example.com to st
by yaix 14y ago
Just ask the user if its okay, like with geo data, translate web site, etc.
"Allow example.com to track your location?" [Yes] [No]
"Allow a1.example.com to store x MB of data locally?" [Yes] [No]
Also
> The HTML5 Web Storage standard was developed to allow sites to store larger amounts of data (like 5-10 MB) than was previously allowed by cookies (like 4KB).
Main difference is that cookies are uploaded to the server with each request, while localStorage is not.
- afhof 14y agoThat is a good way to never ever ever use a feature again. "Frightening Message: This website wants to do something scary. Do you want to allow some bad thing to happen to your computer?" That is how lay people, i.e. the people needed to mass adoption, read browser requests for Geo, storage, and other permissions. It would be better to have sane and safe defaults in the browser, rather than pester the user. Would cookies have worked if the browser asked for permission on every website?
- JoachimSchipper 14y agoWould cookies be used for tracking you everywhere if the browser asked for permission on every use? Would this be a good or bad thing? (It's not like keeping state in the URL is hard - using cookies just looks marginally better.)
- im3w1l 14y agoThen, if you were logged in to a site, you would only be logged in, in that particular tab.
- yaix 14y agoBrowsers like Chrome do it with geolocation for example. If it is required for the user to get a certain service they want, what's the "scary" part? You can say no and use the parts of the site that work with it, or yes and get the extra functionality. Like with geolocation.
- okamiueru 14y agoIt could be done as in Opera, where there is a initial limit, and a request to exceed it when maxed. http://i.imgur.com/SOoadOB.png http://i.imgur.com/SOoadOB.png
- yaix 14y agoIt should not be blocking though!
- tripzilch 14y agoHeh, that may possibly be one of the final features for other browsers to copy from Opera, before they join the herd and switch to webkit :) I'm actually not sure how much that'll change Opera, and affect their way of innovating new features to include.
- rplnt 14y agoThis is what Opera does (you are prompted to raise limit) and it does not prevent this kind of attack. You still would have to have separate TLD limit.