Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
gregable
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
9 ms
·
91.
▲
by
gregable
6y ago
Certificate revocations do apply to signed exchanges.
92.
▲
by
gregable
6y ago
Not continuously. The signed content includes an expiration date, which the publisher controls. This expiration can also never be set more than 7 days in the future.
93.
▲
by
gregable
6y ago
Yes and No, mostly yes: On publisher origin, the plan-of-record does not involve any validation of the contents of the AMP javascript files. When an AMP Cache (eg: Google) crawls one of these AMP documents, the same is true - the contents o
94.
▲
by
gregable
6y ago
I want to break down this question slightly. > Can a third-party other than Google deliver an AMP page? Yes. Examples: Bing runs their own AMP cache and also delivers AMP pages. LinkedIn and Twitter also link to AMP pages, but they don&#
95.
▲
by
gregable
6y ago
All this means is that any server can choose to present any bytes, even with TLS, as a response to any request. This isn't a novel observation. If a signed exchange includes a URL, that URL must be signed for the browser to respect the
96.
▲
by
gregable
6y ago
It's more of a question of if a specific document is using AMP, the site can be a mix. Just like a site using jquery as an example. An AMP page can be identified by examining only the first few bytes of the HTML. The `<html>` tag
97.
▲
by
gregable
6y ago
Google never displays AMP documents on desktop (sans mobile emulation), this won't be an issue.
98.
▲
by
gregable
6y ago
@DevKoala, do you have an example where you encountered the "mini-site" experience? I haven't seen it, but it could be a bug that would be worth fixing.
99.
▲
by
gregable
6y ago
@freeone3000, that's incorrect, in the case of Signed Exchanges. Chrome will verify the document's signature against the publisher's public certificate. This will be `nytimes.com` for example. It is not using Google's ce
100.
▲
by
gregable
6y ago
The AMP team doesn't prefer these URLs shared either: If you click the browser share icon, or trigger the browser native share intent, the origin URL will be shared, not the AMP Cache URL. Only if you explicitly copy the URL bar will t
101.
▲
by
gregable
6y ago
Chrome does enforce the matching signature. Browsers without Signed Exchange support will not likely ever get a signed exchange as they do not advertise support for it in the `Accept` request header.
102.
▲
by
gregable
6y ago
This concern, Google controlled/hosted JS, is independent from Signed Exchanges and specific to AMP. At the same time, the AMP project is actively working to move the origin (control/host) of the AMP Javascript to the publisher&#x
103.
▲
by
gregable
6y ago
Yes. Signed Exchanges mean the publisher signs the content using their private key. A third party can provide delivery like a CDN, but they cannot modify the content, or the signature would no longer match. The useragent (browser) enforces
104.
▲
by
gregable
7y ago
Another possible solution to what you want to solve is to use a signed exchange signature: https://wicg.github.io/webpackage/draft-yasskin-http-origin-... The publisher server must support it, but this results in the d
105.
▲
by
gregable
7y ago
https://www.denverpost.com/2019/12/23/drones-mystery-colorad...
106.
▲
by
gregable
7y ago
Is that even necessary? If they sit far enough out, are sufficiently small, and are not broadcasting radio, I doubt we'd notice them.
107.
▲
by
gregable
7y ago
Without the Javascript file, the images will not load. AMP loads images using a custom element <amp-img> which has performance benefits such as lazy loading of images until they are close to the visible viewport and guaranteeing a sta
108.
▲
by
gregable
7y ago
Reasonable question. Until the javascript has loaded (a single cacheable javascript file: https://cdn.ampproject.org/v0.js ), the browser can't lay out the resources on the page (images for example). If the browser ren
109.
▲
by
gregable
7y ago
Any AMP page can be HTML5 compliant. AMP doesn't require that the page pass an HTML5 validator, but is entirely compatible with HTML5. JavaScript and Web Components are part of the HTML5 standard. This is simply the Extensible Web ( ht
110.
▲
by
gregable
7y ago
The behavior you describe occurs if the useragent blocks the URL https://cdn.ampproject.org/v0.js which does not have anything to do with ads or analytics. Certainly an ad blocker can be used to block any URL, but I don
111.
▲
by
gregable
7y ago
Every valid AMP page includes a <link rel=canonical href="..."> to the canonical URL for the document. If the aggregator (facebook in this case) parsed and linked to the canonical as the publisher recommends via this annotat
112.
▲
by
gregable
7y ago
See the list of natively supported Ad networks in AMP: https://amp.dev/documentation/components/amp-ad/#supported-a... There are about 200 in that list and any network can submit a config to be added, it'
113.
▲
by
gregable
7y ago
A few references listed in this article: https://www.cloudflare.com/learning/performance/why-site-spe... - Mobify found that decreasing their homepage's load time by 100 milliseconds resulted in a 1.11% uptic
114.
▲
by
gregable
7y ago
Publishers who implement Signed Exchanges get AMP links directly to their site with no iframe viewer on browsers that support the technology: https://amp.dev/documentation/guides-and-tutorials/optimize-... https:
115.
▲
by
gregable
7y ago
AMP pages are just HTML. Publishers can and do use AMP pages as their "regular" pages that every user sees, not just those coming from Google. Other aggregators (Bing, Twitter, LinkedIn, etc) link to AMP versions. These pages are
116.
▲
by
gregable
7y ago
Sites which optimize their pages via https://www.npmjs.com/package/@ampproject/toolbox-optimizer have the initial layout performed server-side instead of by javascript, and thus the CSS Flash-of-unstyled-content p
117.
▲
by
gregable
7y ago
You misunderstand the 8 second CSS animation in the AMP boilerplate. Here's the code (simplified): <style> body { animation:-amp-start 8s steps(1,end) 0s 1 normal both} @keyframes -amp-start{from{visibility:hidden}to{
118.
▲
by
gregable
7y ago
To ensure the entire origin had the same policy. Perhaps that's unnecessary though.
119.
▲
by
gregable
7y ago
What if: a) the origin sharing the resource must place a .well_known/static_resource file in place. b) The presence of .well_known/static_resource prevents any request on this origin to send cookies, and any set-cookie header is i
120.
▲
by
gregable
7y ago
Agreed, but keep in mind that shipping via vehicles raises the cost which potentially lowers consumption and or production. Nothing inconsistent about both fighting for a tax and fighting to keep costs higher at the same time given uncertai
More ›