Safari 4's Messy Trail
Signum Ignitum writes "Safari 4 comes with a slew of cool new features, but extensive data generation combined with poor cleanup make for a data trail that's a privacy nightmare. Hidden files with screenshots of your history, files that point back to Web pages you've visited and cleared from your history, and thousands of XML files that track the changes in the pages in your Top Sites can add up to gigabytes of information you didn't know was kept about you." Some of Safari's bloat is kept in quite obscure locations; it takes a fairly knowledgeable user to find it and clean it up. You can avoid some of the worst of it by disabling Top Sites.
The big value-proposition of the Mac has been that it is easy for the non-geeky user to use. Unfortunately, things like these make those very users vulnerable. Without exposing easy ways to flush potentially sensitive and private information, it is the same users Apple attempts to serve that will be exposed. And, this will probably be the default browser for most new systems, so unless this is patched, expect the problem to proliferate...
Keep in mind this is a beta, folks; if you're using it, you're presumably volunteering to help inform Apple about stuff like this. So in addition to letting everyone else know safari is doing this, it might be a good idea to let Apple know that it is unacceptable in a web browser. Presumably the company released the beta in order to solicit just this kind of information from its users; hopefully enough concern from users will lead them to take these "features" out of the final release candidate.
The real scary part of this for me is not the government, more on that in a sec, but your girlfriend/boyfriend/housemate. Anyone who feels like he/she wants to do some snooping now has a treasure chest of stuff to take out of context.
If you are seriously worried about those people snooping around in your computer like that, you have serious problems. You're supposed to be able to trust your girlfriend. If you can't, you may consider getting a new one, because she's going to cheat/breakup before long.
Can't always do as much for your housemate, but if you are seriously worried about them snooping around in your computer, you ought to password protect your computer. And get a lock for your bedroom.
Getting back to the government, most cases are not high profile law&order style procedural deals. I could easily see local lawyers taking porn sites as evidence you killed her, technology sites as evidence you were researching bombs, map sites that you were researching crimes, and I can see local judges allowing it, and local jury's believing it.
What exactly are you planning on doing that you will end up in such a situation? Judges typically don't allow evidence that is not directly related to the case, so if you're worried about being framed for killing your girlfriend with a pipebomb at a popular geocaching site I can see why you're worried, but most people don't have that problem. Oh, maybe this goes back to your weird housemate thing again?
Qxe4
Use "Private Browsing" mode and this junk won't get in your history in the first place for you to need to delete it. The end. Meanwhile, fulltext searching of your history is hella convenient.
Here's why I use and love Safari 4 on OS X. And yes, I am a huge geek who hacks code for a living.
For me, Safari provides the best web experience. For you, Firefox 3 is the sweet spot. Why can't you just accept that people have differing priorities and requirements, instead of smugly deriding others for using a "miserable little browser"? If you want to hate on a browser, hate on IE. At least there's demonstrable evidence of how IE has damaged the web. Us Safari users are doing just fine.
For internet settings (for IE at least), it's Options > delete offline content (exact location varies based on version). You get a warning about cache and cookies, you hit OK and it is gone. Deleted. ALL of the internet temp files.
To get of -all- temp files, just run disk cleanup. It will empty all standard temp directories. A program uses windows temp, disk cleanup removes it. None of this hiding BS, at least not in XP.
Dunno about Vista personally.
Security is mostly a superstition... Avoiding danger is no safer in the long run than outright exposure. - Helen Keller
Everybody on here needs to grow up. You're whining and crying about your browser keeping a history of your browsing. That's been an accepted feature for over a decade. Only now, you've got a porn mode so it doesn't keep a history. That's new. Why are you wanking fools whining about a browser cache now? Are you seriously crying that a file on your computer might have a screenshot of where you've been on the web? Really? I've got a hint for you: NOBODY CARES ABOUT YOUR DONKEY PORN.
Don't bother responding, I've already answered your objections:
"Oh, but Geekboy, I live in a totalitarian regime, and I'm a freedom activist! They monitor everything I do!" Your browser history is the absolute last place the KGB is gonna look for information. They'll talk to your neighbors, your boss, your parents, and probably drag you in for interrogation before they even consider looking in your history.
"Oh, but Geekboy, I just love looking at little kids! It's not sexual at all, it just makes me happy!" Do like pedophiles have done since the middle ages: become a priest. Get it off the internet, those parents' groups and TV shows are really annoying. Also, same thing as in the KGB. Even if they don't catch you in an actual sting, they'll grab your stacks of CDs and piles of imported manga way before they give a rats ass about your browser.
Now mod me down, and prove you're all pathologically paranoid morons.
Just another "DOJ fascist authoritarian totalitarian bootlicker" -- Zeio
Why is it that everyone's response to any sort of problem is "Windows is worse"? If someone described a serious flaw in say, a Prius, would your response be, "Yeah, but Honda sucks."
I'm not trying to excuse crappy design problems in Windows, but when is Apple going to lose this untouchable luster and take it's lumps along with everyone else?
You're not seriously considering Chrome over Safari for privacy reasons?
I'm not sure even Private Browsing works fully. Adobe stores a cache of all flash ads and components that are seen on sites that you visit.
So if you are browsing porn, (possibly even on Private Browsing mode... I'm not sure), even with resetting and clearing your history and cache, you can still get some idea of the websites visited by looking in the user's Library/Preferences/Macromedia/Flash Player/ folder and looking in the subfolders there (eg. follow through the #SharedObjects folder, and the macromedia.com folder and they have folders naming the sites visited in each).
Even when most people think they've cleaned up traces of where they've been, it's trivial on a Mac to get a list of sites that they've visited.
Jeeze, seriously, I didn't even RTFA but I noticed TFS said Safari 4 was generating potentially gigabytes of cached info, which it did -not- delete when you "cleaned" the cache.
Yeah, slashdot summaries are known for being highly accurate and reliable, and not at all sensationalistic. Of course, anything could potentially generate gigabytes of data. My text editor could do it if I had enough monkeys. But is the average Safari user's cache weighing in at several gigabytes? I don't think so. That was just put there to cause alarm for attention-getting reasons.
... and then they built the supercollider.
Call me a crotchity old unix head but I'm very happy that Apple is using /var for cache information and not /Users/username/Library/Caches.... in fact i think that whole directory should point to /var.
I'd love to be able to partition my /var stuff off like I do in Linux. So if Apple is moving in this direction and keeps it up, good.
Not any more. If you're a good boy, you get to disable ads on /. while you're logged in. I now just get a little box saying "Ads disabled [tick] Thanks again for helping make Slashdot great!".
Dear Slashdot policy makers,
The feature introduced to allow active participants the option of disabling advertisements on the site has to be one of the most awesome things I've seen implemented re: ads on community driven sites.
Keep the great ideas coming.