Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
gregable
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
9 ms
·
151.
▲
by
gregable
7y ago
You could prove the document was signed using the source's private key. That does prove the document was signed by the source if you can prove that only the source had access to the key.
152.
▲
by
gregable
7y ago
Good question. Conceptually, you can think of a signed exchange as a 301 redirect to a new URL which has already been cached by the browser (so there is no 2nd network event). The cache was populated by the contents of the signed exchange,
153.
▲
by
gregable
7y ago
There is a little confusion here, understandable. Google search will not show these signed exchanges in an iframe, the pages are full frame. Try it for yourself. Using Chrome 73 or later (you probably already have this), and a mobile browse
154.
▲
by
gregable
7y ago
The problem with prefetching the publisher URL from a search results page is that it leaks the user's query intent to an origin they have not visited, which violates the user's privacy. By prefetching a signed exchange from the sa
155.
▲
by
gregable
7y ago
Good question. The signing is done by the publisher, using the same digital signature infrastructure that is used for TLS (https). So, the publisher alone has the signing key, and any browser can verify the signature by comparing to the pub
156.
▲
by
gregable
7y ago
The javascript is heavily cached, so will not give a request on every page load. That is not the intention. If javascript is disabled entirely, Google Search won't even load AMP pages. The scenario you describe of a user loading an AMP
157.
▲
by
gregable
7y ago
In general, this sounds like an interesting use case. One thing to note is that the specification currently limits the lifetime of a signed exchange to 7 days. It's possible that by exploring some of these use cases, especially offline
158.
▲
by
gregable
7y ago
If you have a round-trip-time of 1 second, it will take you 1 second to load a text file with 1 byte in it. However, an amp page will have loaded before you clicked, so it will take only the handful of millis in CPU time to swap frames and
159.
▲
by
gregable
7y ago
The linker (google in this case) could rewrite the link to use a redirector if they choose. If Javascript is off, AMP and thus Signed Exchanges are disabled on Google search results anyway. You misunderstand the 8 second CSS animation in th
160.
▲
by
gregable
7y ago
Let me see if I can explain this a little better. Anyone can cache a signed exchange from anyone else. So, for example if you went and fetched a signed exchange from https://amppackageexample.com/ (or any other site that su
161.
▲
by
gregable
7y ago
This is an application of the W3C's Extensible Web Manifesto ( https://www.w3.org/community/nextweb/2013/06/11/the-extensib... )
162.
▲
by
gregable
7y ago
The behavior for browsers without support is to show the google.com/amp URL as before, along with a small html-based bar with additional information about the original domain and share intents.
163.
▲
by
gregable
7y ago
The publisher's cookie-based analytics will operate on the origin in the URL bar in this case. The document (though not the delivery server) will have access to publisher origin cookies. Conceptually, you can think of a signed exchange
164.
▲
by
gregable
7y ago
You may be thinking of this use cases section here: https://wicg.github.io/webpackage/draft-yasskin-webpackage-u...
165.
▲
by
gregable
7y ago
The browser displays the URL from the origin that digitally signed the unmodified content. A browser already doesn't show you what server delivered the content. That would be your wifi AP, cell phone tower, or ISP node. The internet ha
166.
▲
by
gregable
7y ago
This, and in particular, the network has much higher _latency_ over mobile. AMP is aggressive about reducing the number of round trips between browser and server.
167.
▲
by
gregable
7y ago
Yes, though in the use case here, the party linking to the content has already read the content anyway by crawling it. This would be true if your entire session were delivered this way, but instead it's only the first click from a page
168.
▲
by
gregable
7y ago
Good questions: > Who's javascript/cookies run in a real URL amp page, if any? The document operates as the signed origin, so cookies, CORS etc all operate as the signed origin (the one in the URL bar). The HTTP request is made
169.
▲
by
gregable
7y ago
I wouldn't interpret this as the browser lying any more than the fact that your wifi router delivered the AMP document to your browser and your browser didn't show your wifi router in the URL bar. The document is digitally signed
170.
▲
AMP Email
(gregable.com)
1 points
by
gregable
8y ago
|
0 comments
171.
▲
by
gregable
8y ago
Actually, the spec accepts both `<html emoji-4email>` and just `<html amp4email>`. You can see what the spec accepts here: https://validator.ampproject.org/#htmlFormat=AMP4EMAIL
172.
▲
by
gregable
8y ago
I'm with you, but it's the reality. I just searched for "NASA" on google news, clicked the first thing not from JPL ( https://www.fool.com/investing/2019/01/12/whos-who-in-nasas-... ) a
173.
▲
by
gregable
8y ago
Precisely. The exact code is here: https://www.ampproject.org/docs/fundamentals/spec/amp-boiler... Here it is pretty-printed and simplified to not have the vendor-specific stuff: <style amp-boilerplate
174.
▲
by
gregable
8y ago
The open question is would it be better or worse without AMP? It's likely that reddit (for example) would have just deployed an equally frustrating "mobile" page that loads even slower. I just tried fetching http://
175.
▲
by
gregable
8y ago
This CSS animation is just the backup in case the javascript doesn't load at all, really. After 8 seconds, the page gives up trying to prevent the flash of unstyled content and just renders, regardless of how bad the styling is. It als
176.
▲
by
gregable
8y ago
As a different example: A company dumps toxic chemicals into the air/water, and it results in horrible deaths and destruction to the environment which makes everyone's lives worse. However, they've managed to do this in a com
177.
▲
by
gregable
8y ago
I don't have numbers, and it very much depends on which grid we are talking about. It's likely that some of the electricity came from renewables and little from coal. Even if from oil, the big power plants are more efficient than
178.
▲
by
gregable
8y ago
These are currently drafts and are evolving with feedback, but Google is working with standards bodies and feedback from the web community.
179.
▲
by
gregable
8y ago
> experimental feature with no standardization Web Packaging was originally proposed in 2015 as a W3C draft ( https://www.w3.org/TR/2015/WD-web-packaging-20150115/ ) and the Signed Exchanges spec as an IETF
180.
▲
by
gregable
8y ago
Good points, but mostly just confusion on the specification, I think. > - the original server will not see your download request. This will skew their logs/statistics. True in the strictest case if that site owner is strictly using
More ›