Several Major Browsers to Prevent Disabling of Click-Tracking 'Hyperlink Auditing' (bleepingcomputer.com)
x_t0ken_407 quotes BleepingComputer: A HTML standard called hyperlink auditing that allows sites to track link clicks is enabled by default on Safari, Chrome, Opera, and Microsoft Edge, but will soon have no way to disable it. As it is considered a privacy risk, browsers previously allowed you to disable this feature. Now they are going in the opposite direction.
Hyperlink auditing is an HTML standard that allows the creation of special links that ping back to a specified URL when they are clicked on. These pings are done in the form of a POST request to the specified web page that can then examine the request headers to see what page the link was clicked on.
The article concludes that "Firefox and Brave win the award" for people who want this click-tracking capability disabled -- since "only Brave and Firefox currently disable it by default, and do not appear to have any plans on enabling it in the future."
Hyperlink auditing is an HTML standard that allows the creation of special links that ping back to a specified URL when they are clicked on. These pings are done in the form of a POST request to the specified web page that can then examine the request headers to see what page the link was clicked on.
The article concludes that "Firefox and Brave win the award" for people who want this click-tracking capability disabled -- since "only Brave and Firefox currently disable it by default, and do not appear to have any plans on enabling it in the future."
Went looking for how to turn it off, article was kind enough to provide the necessary about:config setting, it's "browser.send_pings".
Firefox already has it off by default. Nice! for once.
Can't you just encase the link in Javascript and get the clicked link that way? Or do webpages not do that very often?
"First they came for the slanderers and i said nothing."
Chrome is open source, so it should be simple to patch Chromium to prevent enabling it instead, maybe even to patch Chrome.
Everybody wraps their hyperlinks with tracking code anyway.
Why ... just why....
Oh. Advertising tracking. Yeah. Blah.
"Safari, Chrome, Opera, and Microsoft Edge"?
So in other words: Safari, Chrome, Chrome and Chrome.
HTTP is worthless, total trash. It's garbage, and we can do a lot better. Maybe not with the World Wide Web, but with politicians. That's why I know Trump's going to win again in 2020. He's the only one since the conception of Bohemian Grove a hundred years ago who has been a president to not attend. That's the kind of guy I want to be president, and because he's really a non-politician, a true outsider and not just controlled opposition, a guy not willing to play the game of the purple party, he's going to win. Donald Trump is in it to win it.
d888888b d8888b. db .
~ 88 ~ 88 `8D. 88 .
. 88 . 88oobY' 88 .
. 88 . 88`8b . 88 .
. 88 . 88 `88. 88b_ d88 88. 88
. YP . 88 . YD ~Y8888P' YP. YP
VP. `8D
j88.. . `88. d8' j88.. . `88. d8'
888888D. `Y88P'. 888888D. `Y88P'
Chrome devs have removed the hidden setting while they debate promoting it into the regular settings UI. If you want this, star the bug (but don't flood the comments too much):
Issue 935978
So where was Tim Berners-Lee to protect the Web from corporate interests and control when this standard was being enshrined for their benefit? Right: he was participating in the very same standards body, W3C, that did the evil deed.
Fucking hypocrite.
Turned off by default in Pale Moon too.
(I checked...)
AC
Trump will be in prison the day he leaves office.
If avenetti becomes president will he go to bohemian grove? Will he bring stormy Daniels? I think I answered my own question when I had to look up how to spell his name.
Exactly. He will be identifying the corpse of Crooked Hillary after she has served some time and has done herself in. Personally, I'd just leave her to rot.
HTTP is worthless
No! You couldn't be more wrong!
HTTPS is worthless! In fact it's dangerous. It's a bear trap. Watch out!
Devil's advocate.... ... good.
This is exactly the motivation people need to move to different F/OSS chromium forks.
Look folks, as long as Google has control of the browser engine source code, Google has you by the short hairs. Worse, control of the binaries as in Android. Open source or not. Not only is Firefox just an all round nicer browser to use (my opinion, if you disagree then please direct your fan mail to Larry Page) it is the only browser that gives a toss about your privacy.
When all you have is a hammer, every problem starts to look like a thumb.
As a forever user of Netscape, Mozilla, FF, since forever, I give you all the 1-finger salute. I feel secure. The SJW shit needs to end soon, but I'm not switching browsers.
Trump will be in prison the day he leaves office. He'll be under it the day after he dies there. Melanie-sic will not attend.
eventually cave in.
Firefox users used to be able to check a preferences box to enable/disable Javascript. There were some sites I would only visit with JS disabled first, and others where I wanted it enabled. I assumed the Mozilla team would eventually do the user-friendly thing and allow preferences to be set for certain oft-visited websites (perhaps a user-editable file listing special websites and whether to enable audi,video,popups,JavaScript and preserve cookies when otherwise clearing them) but nope - they appear to have caved to ad sellers and disabled the disabling of JS.
They seem to currently also be ignoring the option to disable popups.
The users get the browser for free, so they are NOT the customer.
The advertizers are directly or indirectly donating money to the Mozilla Foundation, so THEY are the customer and they will get what they want as soon as enough people at Mozilla decide to relax their principles.
You deranged idiots are incredible. You clearly want a police state where any person can be locked up on a whim if the "right people" disagree with them, and you think of yourselves as the "right people".
History is littered with the corpses of the victims of tyranny who themselves enabled that tyranny in the dreams of using it to oppress their political opponents.
At least the Trumpsters chanting "Lock her up!" had a list of actual violations of actual laws for which they wanter her locked up. The FBI even admitted to that list when James Comey infamously stated that "no reasonable" prosecutor would prosecuter her for her crimes, and then moments later announced that if anybody else did the same thing, that person WOULD be prosecuted. You people who've been snorting some sort of drug from Rachel Maddow or Chris Hayes or Chris Cuomo, or Don Lemon, etc have no flipping idea of what laws you imagine Trump has violated.
Morons.
And if drumpf ever gets out , he will be skull fucked with APKs dick with the Muller report wrapped around his teeny member.
Editor David and msmash will give a reach around while beauhd will felch the drumpf asshole with a drinking
straw
Kenn doll will be left in the corner, beating off alone as usual
At least you can see where you are going. Plus you can block ping with browser extensions. Redirects not so much.
This is why Firefox is doomed if it remains a hold-out. Money from the internet comes from advertising so the major platforms are going to find a way to sideline companies the size of Mozilla that spoil the party. The surprise here is that Safari has recently disabled this feature since Apple is much less beholden to advertising interests. There's a chance that the Safari change was inadvertent, or at least wan't considered very high up the corporate ladder. With luck Apple will put the feature back.
The reason they're doing this is not to track people more. They're doing this so more developers use the ping attribute for this functionality instead of hacky JavaScript or redirects (which prevent the user from seeing what URL the link goes to, increase navigation latency since everything ends up serialized, make it hard to copy the real URL or open the URL in a new window, etc.).
If things go as they typically do, browsers will start blocking the old behavior from working or otherwise disincentivising that behavior once enough of the internet has migrated.
You clearly want a police state where any person can be locked up on a whim if the "right people" disagree with them
Isn't that every country ever? A small group of people get together and tell a larger group of people how things are going to be ... or else.
Why does a user need to download and install optional stuff to make the basic functionality safe?
Script blocking used to be intgrated, and frankly it is to a certain extent a vulnerability to build into Firefox the ability for a script/plugin to make changes to a basic security function like this. By all means, allow addons to automate the loading of certain pages, or filter certain content or help manage bookmarks or the way things look on screen but allowing plugins to monkey with security issues like whether remote code will be allowed to auto-execute on the desktop is a baddie.
Also, why should only the more-advanced users get these important options? They're the ones less likely to be victimized by malware.
Oh, and another thing: with JS blocking made optional in a plugin that is vulnerable to breaking in every new release, what's to prevent click tracking to eventually be migrated to a plugin at some point and making that option also unavailable to most users (Most Firefox users do not even know what a plugin is, let alone to even look for something called NoScript and even if they knew they needed it, knew what it was called, knew where to find it, and trusted the download, the odds are insanely low that they would know all that for a click tracker.
Again, my basic question: Why was a basic security function moved into a plugin? It doesn't make things better for a user and it doesn't even make the code simpler. I'm rather big on the "Why" question - I find it often elicits very interesting things.
I wonder what would come from misleading the advertisement industry targeting their own practices.
First off this was never a major feature even some power users would have known of.
Secondly link tracking is used by web masters / site owners to know what links you click on their site.
Web masters / site owners track visitors so they can better understand them *and* improve their site.
Does Firefox Focus normally stop a majority of these? The Android version is based on webview/blink, but it has an integrated adblocker.
Tor Browser will present you with many more warnings and generally provide far more security information than Firefox. The most common are: don't maximize the browser window on a desktop, and beware of fingerprinting with the canvas element, and noscript redirect warnings.
That lying bitch of a Daniels that first has consensual sex with someone, then blackmails him for money and when she is paid off she still goes public because she thinks the other side pays more should be ass-raped by a horse.
w3c publishes recommendations not specifications.
"And thirdly, it is more what you'd call guidelines than actual rules." — Captain Hector Barbossa
why is this an HTML standard?
the standard mentions that it will increase transparancy for the user, but sure looks like a heavy price to pay.
On a long enough timeline, the survival rate for everyone drops to zero.
Maybe this is a reaction to the GDPR's proposed Link Tax? Did that even make it into the GDPR?
So much freedumbs!
Browsers were also known as "User Agents", but ever since broadband reached the mainstream consumer, there has been less and less of the "User" represented by the user agent.
The original role of the browser as a computerized representative of the visitor's choices in the exchange between the consumer and the producer is all but gone now. With the most popular sites being from conglomerates and giants who lobby or buy seats at the browser standards body now, how could this ever have been expected to ended differently?
A normal linux distro from 2003 could easily have 5 browsers if you installed various Desktop Environments from the full 4GB DVD (none of the browsers were Internet Explorer even at the hight of its imperial dominance). They were ALL open source and would have easily allowed someone to compile all this stuff out of the way. Where did they all go off to die? Complexity killed them. Low mom & pop percentages killed them. Firefox killed them (just like Chromium killed Edge)
I understood that https was supposed to be more secure, what pray tell what makes it a bear trap?