August 2020
466 tweets
I think I would have known if it had been you 😁
♥ 1
Send a bunch of policy lawyers and have them keep sending endlessly long emails. Look at the archives. Or maybe don't!
♥ 6
Maaaaaaybe don't. Unless you want to look upon the worst of the HTML days and fondly conclude it wasn't that bad.
♥ 7
Apple do too, they have malware removal silent updates.
It's an interesting question whether they'll cooperate.
Things can get fun if TikTok tries to evade, too. A Web version, VPNs, we could be looking at the Great Firewall in reverse.
♥ 1
Oh my god this is just pure gold.
♥ 4
If you follow WebAdv, you've noticed that some of the adtech folks have what may seem like strange positions, for instance that browsers have a duty to share data with them despite user preference.
Before you take the bait, remember we've been there. Beautiful example below.
Quoting a tweet by @adrianba ↗
♥ 10↺ 5
They're not all bad 😁 But the bad ones are *really* bad!
Sorry 😁
TAG does fraud prevention? I thought all they did was take money.
♥ 2↺ 1
There's a lot more where that came from if you're short on pain.
Oh, we are much agreed. The problem is in part market incentives. If you're an adtech company and you don't track but your competitors do, you're facing an uphill battle convincing customers. Everyone thinks they have to be a small Google.
I've had voicemail from lawyers in the EU!
There's a letter begging to be written right there.
♥ 1
Yes!
France!
If openly commercial yes, but I think some will try workarounds, eg. for nonlegal conseil.
I know, it's beautiful in its own way. We should have a replies competition.
♥ 1
I don't know that it's them, I'm speculating that it could be given the current state of play and how weird that is out of the blue. Half of the message was garbled, too.
Anyway. It looks like I'll be back in the game soon!
Oh yeah!
With where the Web's at, we're gonna need them.
Ah dommage, c'était bien!
♥ 2
Rocking moves!
Excellent news! I haven't finished it yet but so far there's a lot to love.
Quoting a tweet by @laurenfklein ↗
♥ 3
No videos? Sounds like my kind of singing 😁
It's really the only kind of shirt worth having.
🤗❤️
Lol, you could pick a few things up for spec editors, but this is mostly for authors who want to publish nonfiction.
♥ 2
A book on how to do standards wouldn't be for a huge audience, but you could make it mandatory reading...
Whoa I had no idea there was such a thing!
♥ 1
Je ne sais pas qui c'est mais oh putain. Courage, tiens bon!
♥ 1
Aïe. La génétique garde encore bien des mystères.
♥ 1
Thank you. I can now confidently proceed to using that subject line for all my email.
♥ 2
I want to take a course in diplomatic phrasing from @karaswisher.
Quoting a tweet by @karaswisher ↗
♥ 1
It's almost like using Google Search 🤣
♥ 4
I'm not so sure. As written, it feels like Albiades is affectionately humouring Socrates.
Pat-pat on the forearm. Half smile. "I guess that's right. Of course. I'm wedded to stupidity."
♥ 1
Ça pourrait être intéressant de comparer les superficies desservies. À Paris le métro est ultra concentré, essentiellement sur les riches.
Tout à fait, “riche” est un raccourci. Mais aux alentours de 200km divisé par 14 lignes (je ne compte pas les bis, hein) ça nous fait du ~14km par ligne soit à la louche une diagonale titubante d’intra muros. Je pense que ça ne compte même pas le RER.
Certes, mais justement pour ceux-là: le réseau banlieue-banlieue s’est développé ces dernières années? (Ça fait ~5 ans que je suis parti.) D’expérience c’était l’enfer.
I don’t know about adtech specifically, but for cross-border transfers I would ask Madhulika Srikumar (linkedin.com/in/madhulika-s…, I don’t think she’s on the Twitter). She touches upon these issues in youtube.com/watch?v=7E-syt….
And yeah, the TikTok stuff is bullshit.
♥ 1
Which part? The code? Why someone would write that? Why this would be the documentation for a major product from a major company? What did they do with the bodies of the QA people?
♥ 3
This is well beyond redundant. Also, even if you turn it into JavaScript as people use it, you would get:
if (auth.isSignedIn) auth.signIn()
which *still* makes no sense. There is literally no level at which this works.
♥ 3
Hahahaha.
Now I “get” it :)
♥ 1
Totally! In the same way you want to check that your return value is roughly equal to a boolean before using it in a conditional. You never when JavaScript might change the semantics of `if`.
♥ 5
How does anyone get anything done!
Sure, but this level of bad is quite surprising from pretty much anyone.
I agree about tech writers, but most of these API docs read like they didn’t even get any QA.
♥ 2
Well, I guess that's Isaias in Brooklyn.
♥ 2
Hey, it could be an actual hurricane!
The season goes to, what, November?
I've totally been thinking of that. Hilarious material!
Yeah, I mean, it's almost a bit on the nose.
Do you have a reference for that paper?
♥ 1
Thanks a lot!
♥ 1
I recently learnt that Google still runs its privacy work as (apparently) a branch of security. That's how you get these screw ups: for security folks, Google isn't part of the threat model (that would make little sense), but for privacy purposes it has to be. Hard to align.
Quoting a tweet by @Independent ↗
♥ 116↺ 30
Beirut Explosion: 'I Was Bloodied and Dazed. Beirut Strangers Treated Me Like a Friend.' from @VivianHYee nyti.ms/31i3a81
I know, but "insider threat" and "you are the threat" are different problems with different mitigations. No amount of DLP, access restrictions, logging, etc. will protect you from OKRs that violate privacy!
Absolutely. I'm not saying that the tools don't overlap. You certainly want those teams talking. But Google's privacy message is often "your data is with us, so it's all good!" That's security thinking 😁
And also look at their privacy announcements: they all have huge sections about security. Part of that may be that they really need the filler, but I think mostly it's a sincere mistake.
Hahaha!
I've been almost tempted to write a manifesto. "A/B Testing: Désigner in the Loop" But I'm too old for this shit 😁
♥ 1
I think it's a blend. Yes, they make a lot of money by "not understanding" the problem, but I think there are some in there who know they need to grow out of it or face obsolescence.
I think you're imagining it as more strategised than it was. I thought it felt like "oh shit, Apple's kicking our ass on privacy again, what do we have?"
"Uh... Good security? Oh, and that AI thing, people love that crap. Oh! And we did a retention thing!"
Never ascribe to malice that which can equally well be explained by an executive team not educated on a given issue ;-)
Oh, they are SO far from privacy by design, they still think in terms of transparency and control.
This is such a waste of time and money.
If you're involved in this please reach out and we can talk about the future. Web and apps are getting better privacy; the faster you adapt, the less painful it will be. Invest your resources in the future, not in maintaining the past.
Quoting a tweet by @MediaPost ↗
♥ 164↺ 43
I don't know who they're paying yet, but a lot of adtech people in WebAdv seem to have trouble understanding the Priority of Constituencies.
♥ 4
And even computers that can often have problems detecting darker skin tones. That'll show the background instead.
♥ 2
Or, rather often, both.
♥ 1
We removed a ton of ours! But the hard trick is to remove them from ads. I think we could use web bundles for good here.
♥ 4
Regulation to force browsers to have identifiers is pretty bold, but after the CMA report they really think that's a thing.
♥ 1
It's for the publishers, man. They're all doing it for the publishers. The smaller the publisher the more they're doing it for them. Why do you hate freedom?
♥ 19
Yup, privacy is censorship!
♥ 4
I mean, they did call it PRAM.
♥ 2
I'm disappointed they haven't figured out how to make it about the children or the troups. Or both.
♥ 2
I appreciate the mention (and the quality summary thread) but I don't think we've ditched "most" yet. We dropped programmatic in Europe and apps, but it's still in Web elsewhere for now. In the meantime, we've fixed what other things we could: open.nytimes.com/how-the-new-yo…
♥ 5↺ 3
Recommending bookshop.org/books/the-pric… (or the French original if you prefer).
♥ 1
Are you angry that this actually does matter in picking your president? You may wish to read @CageJulia's book: bookshop.org/books/the-pric…
Quoting a tweet by @ShaneGoldmacher ↗
♥ 2↺ 1
I'm an immigrant too, but frankly I think this is mad no matter what!
I can't vote here, but I can still vote in a number of French elections (presidential, and for my local representative who covers North America as a district).
♥ 2
Actually, I’d like to think that desperate times call for creative thinking, reinvention, and reckoning with mistakes made!
♥ 6
There are many different things we can get involved in and only so much time. Given the IAB’s track record the onus is on Rearc to prove itself. If the people in Rearc are competent on this, why did they fight to do nothing for two decades?
♥ 5
Working towards the future doesn’t mean forgetting the past. My priors are informed from two decades of lying, lobbying against privacy, derailing DNT, creating the TCF, “transparency & choice”, working against publishers, etc.
But I’d sincerely love for good things to happen!
♥ 4
I would take that one step further: one of the major next pieces of work is identity that is guaranteed to be unique to an origin, with no hook for email, phone, or even from billing. There has been some promising progress in that space.
♥ 2
As an engineer, I agree but only up to a point. Some things are hard to solve with tech alone, or sometimes tech exists that is hard to transition to for non-tech reasons. I think we need to articulate tech and policy together much more effectively.
One of the tricky bits is you need a messaging channel. Ideally you would get your origin-specific ID (eg. de4db33f) and you could push messages (sealed web bundles, so you can’t pixel them) to it. How the user receives that (email, push, voice, /dev/null…) would be their call.
♥ 1
I’m not sure that’s common ground, no. Sure enough transparency and choice should exist, but they’re the last fallback when everything else has failed. The defaults should be such that people rarely have to care, ideally never.
♥ 1
Whenever the first answer to privacy issues is “transparency and choice” that’s code for screwing over users. eg. AdChoices, Google privacy settings, etc.
A bit more on that in open.nytimes.com/how-the-new-yo…
♥ 1↺ 1
I’d love to see that happen. It’s all yours if you want it!
♥ 1
It's hard to dress for video. I used to have a collection of shirts with relatively small motifs but they don't work there. I've started switching to bigger/bolder designs.
♥ 1
NYS has about 650 cases / 10 deaths per day. Considering the country it's embedded in and how brutally it was hit that's remarkably low. Hence the light of hope depicted above!
♥ 1
Yeah, I loved the joke about how Australia was now the Spice Girls: doing great until Victoria ruined it 😂😘
Seriously though, going hard against it is worth it, you need to crush it. NYC isn't under tough rules but newyorkers learnt their lesson the hard way.
♥ 1
Wow, beautiful!
♥ 1
Awww, you're too kind! 😊
It took a long time to write this one, but I'm working with my team for them to write other pieces on some details. I'll keep you posted!
♥ 1↺ 1
WebIDL folks: is there documentation for the decision to make [Unforgeable] legacy? I can’t seem to find much in the issue tracker.
♥ 2
🤫🤭
♥ 3↺ 1
This reminds me of the time the IAB came to the HTML WG to ask for the iframe security model to be decreased. Good times!
♥ 1
Believe it or not, it was actually a thing almost twenty years ago!
♥ 1
I want to read about this
♥ 2
If you are that's two of us! An investigation is warranted, maybe even urgently.
♥ 2
Maybe if you wear leather pants commando style?
♥ 1
I could also see a "Wait-" instalment 😁
♥ 1
Ah.
Would you go on the record for my call-out about Sticky Scrotum Syndrome?
♥ 1
In practice, the ads.txt specification has no processing model, no threat model and assessment thereof, and no conformance criteria, so at the end of the day you can blame pretty much whoever for whatever 🤭
♥ 4
I'd love to see that!
♥ 2
7yo: I'm made out of objects, like bones and stuff, but I'm not an object myself.
Me:
♥ 10
This is the best Soundcloud.
♥ 2
Ha! I'm just waiting for you all to reach consensus on something 😁
♥ 1
What does "Predictable Privacy" even mean? Is that just a rebranding of the transparency & choice gimmicks?
Do you mind explaining where this newfound passion for accountability comes from and why it's been absent over the past two decades? What changed?
♥ 7↺ 1
"Consumers' privacy choices" is largely an oxymoron. If you're forcing people who want privacy to make choices, you're not respecting their privacy.
♥ 9↺ 2
Few people mind ads that much, but users are just forced to care because there is no privacy and little quality control. And the more they understand what is done with their data, the more they want to block.
Those sites will die if adtech isn’t reformed.
♥ 2
You just defined privacy as choice. That’s a very old trick to pretend you care about privacy but then put all of the onus on the user.
When users have to opt out of something in order to get privacy, they are being forced.
♥ 14↺ 2
Again, it’s a track record question. You say you’ve changed, that you and the rest of the IAB now care about privacy.
Great if true! I want to believe you. If you want to be credible, show us a vision of privacy that doesn’t require “transparency & choice”. We’ve seen that lie.
♥ 3
Yes, that’s what adtech people call “transparency and choice”. It’s a small subset of what people thought privacy should be… in the 1970s. It’s a great way to pretend you care and do nothing.
♥ 5
Note that that's a step towards PbD, but not the whole story.
♥ 1
I didn't say "without" I said "that doesn't require it". Compliance is a separate issue. Assuming you're honest in caring about privacy, changing your frame might help.
♥ 2
I see why you include "troll" in your bio.
♥ 1
The "choice is great for people, consent sucks!" is an interesting new take!
Consent is... choice.
♥ 2
I don't think that's weird! A great example is the TLS error dialog browsers have. You can circumvent if you know what you're doing, but you won't default to that.
Having your data broadcasted over RTB should have a similar user experience.
♥ 1
That returns to the initial question: the IAB has zero credibility in accountability or understanding privacy. I can't even get an answer that's anything other than "transparency and choice". There are indeed projects to make this work, but why pay attention to Rearc?
♥ 4
Being trustworthy custodians of user data is a huge part of accountability. You can't have people accountable for what happens to the data and no one in charge of protecting it at the same time, that makes no sense.
↺ 1
There are much better ways to do contextual. Buyers are excited when they see them. There's nothing backwards about contextual research today, quite the contrary.
♥ 4
Ah, so you think it means "predictably bad"? 😁
♥ 1
We could do scanning much better. Once you stop basing the system on reactions to personal data broadcasting, the need to run it real-time is much lesser, arguably gone. We could rebuild to support preflight scanning in programmatic.
♥ 3
Only if you allow creatives to change at runtime. There’s no good reason to allow that either. Have the browser control the limited channels they need to work, block all other requests.
♥ 3
Actually, the changes to the browser security model wouldn’t be that hard. And they can drive positive change in the ad stack.
Yes, it’s work, but that’s not a reason not to do it. The best time to fix this was twenty years ago, the second best time is now.
♥ 2
Absolutely. I’m not saying that it’s a silver bullet, but it helps.
Also, by making creatives safer we can make the stack more powerful since it mitigates risk.
♥ 1
I know the challenges, I think you underestimate what we’re allowed to change ;)
One neat trick we can use is bundling.
That’s a fair point Alex, but I’m not sure if you meant this comment to be against the specific tweet you are responding to, or in general. I’ll address it both ways if that’s okay.
♥ 1
For the specific tweet, I’m not attacking anyone, only pointing out that you can’t have it both ways: saying the system will have accountability and also saying that companies shouldn’t protect their users. Saying accountability and data red in tooth and claw is contradictory.
♥ 1
For the thread in general, it’s not about attacking anyone but credibility matters. I have limited resources, there’s a lot going on, I need to decide where to dedicate time.
I’m absolutely sincere when I say that it would be great if the IAB were sincere and competent here.
But I also have to look at the past to decide where to invest my resources. I don’t think it’s outrageously invidious to say that the IAB has an appalling track record on privacy and accountability. It seems fair that I would ask for proof of change before spending time on it?
♥ 2
Forgetting all the other back and forth on this thread, so far the only thing I’ve heard about the IAB’s new approach is that privacy is somehow “transparency and choice”.
If that’s the case, I don’t at all intend this in a mean way, but looking at Rearc is a waste of my time.
♥ 2
I don’t think there was ever any consensus on an email standard. 😂
Again, as I’ve said several times above: I do not have foregone conclusions and I do not ascribe intent. But I don’t think you’d dispute that the IAB has a terrible track record here. Is it really that unfair that I’d say “show me *something*” before I commit some time?
♥ 1
I mean, learning from observing the past twenty years isn’t a “cognitive bias”, it’s just experience. I recall the promises about 3P cookies of the late 90s. I recall DNT. I’ve seen some IAB’s lobbyists at work.
C’mon, let’s not pretend there isn’t history.
♥ 2
And I genuinely look forward to reading your proposals. One thing that worries me (for you) is that if the IAB lacks a resident understanding of privacy then a perfectly well-meaning approach could still go wrong from lacking the right feedback.
♥ 2
Can you share that proposal or is it confidential to the group? If you can email it, happy to look at it and chat, my team is digging through piles of ideas so it would be timely.
Mozilla is laying off 250 people and is basically on life support. Their primary competitors:
* Bundle their browser in a leading operating system.
* Forbid alternative browser engines on their platform.
* Use their massive Web properties to drive downloads of their own browser.
♥ 2,772↺ 978
Are there any regulators who aren't asleep at the wheel right now? Do you need some help identifying consumer harm here?
♥ 605↺ 72
This blew up! Here's my proverbial Soundcloud: open.nytimes.com/how-the-new-yo…
♥ 83↺ 8
To my friends at Apple and Google: you make your own choices and it's not my place to judge. But next time you think of yourself as working for the open Web, I hope you have the self-awareness to remember that this is on you.
Mozilla is laying off 250 people and is basically on life support. Their primary competitors: * Bundle their browser in a leading operating system. * Forbid alternative browser engines on their platform. * Use their massive Web properties to drive downloads of their own browser.♥ 2,772↺ 978
♥ 57↺ 31
They could have had a supplemental commercial strategy, but the game for browsers is search royalties and that's about marketshare.
All of the browsers have flaws and make mistakes and are imperfect, the differentiating factor is who's cheating.
♥ 9
Second round of layoffs this year.
♥ 8
No one is saying they're perfect, but are you really trying to make the case that bundling Chrome with Android doesn't have a major impact? Or that pestering users on almost all your Web properties to switch to Chrome did nothing? Care to release the conversion numbers there?
♥ 5
I think what's going on is that they're playing fair in an unfair fight.
♥ 32↺ 1
Here's how I honestly read your point and you can tell me where I misunderstood. You think that Mozilla's situation is due more to mismanagement than to anticompetitive practices from Apple and your employer. So much so that mentioning your responsibility amounts to...
♥ 1
..."diverting blame".
Mozilla management sure owns a load of blame, that's plenty clear. But you folks are using multiple unfair tactics to bleed them from the jugular.
Tell why that's not true.
♥ 3
?
It goes without saying, but if you come from Mozilla, you'll like the ethics and tech challenges at @nytimes. There's a bunch of open positions just for you to look at: nytimes.wd5.myworkdayjobs.com/NYT. Come over! #MozillaLifeboat
♥ 55↺ 11
It's Congress, Kevin, that's not just a problem for QAnon folks.
♥ 11
Sure. But none of that comes anywhere near the effect of having two of history's largest corporations using unfair tricks to beat you.
♥ 10↺ 1
Ok.
♥ 1
Yeah. It's pretty okay.
♥ 1
Yes, cross-market is easier to do in digital but this doesn't seem to be taken into consideration.
♥ 3
Ha! I think pretty hard, browsers are quite difficult.
Lots of bad choices, but nothing as bad as having two monster corporations coming for you!
♥ 1
Search royalties are a normal form of payment, not a transfusion. Do you know how much Apple gets?
♥ 1
I don't know that I am the person most qualified to write that ethnography! I meant more specifically the focus on ethical outcomes.
♥ 1
The hybrid/corp model isn't 100% new, I think it might predate B Corps. I think that part is written up somewhere.
♥ 1
That's also true of Safari.
They tried!
♥ 4
Search royalties is a business model.
♥ 1
Look up how much Apple gets in search royalties.
Search royalties are income, they're not "support"!
♥ 62
Yes! It actually really does.
♥ 19↺ 1
Not anywhere near enough.
Sure, but I doubt that teams costs $12+bn a year.
Yup, I'd say not even six months.
♥ 1
That doesn't make it a bad revenue stream. There's enough competition left in search for it to remain a fine source of revenue. But that requires marketshare.
I don't have numbers specific to tech positions for either org, but here it's more than 0.
Ah, gotcha. I don't work in an engineering position and I'm not part of the tech org. In my work, depending on project, it's about 1-3.
♥ 1
Non sequitur? Do you have an idea of how much Google's campaign to drive downloads across their Web properties would have cost if they'd had to pay for it?
♥ 4↺ 1
I'm sorry but that makes no sense. There's a difference between growing in the market you're already in and abusing dominance in one market to dominate another.
♥ 1
Do you mind sharing more details on this? As far as I know search royalties are still a thing.
Oh sure — the manner in which the deals are set up is a problem, but I don’t think that’s inherent to royalties. It would be good to have a more organised system, based on actual royalties from ads, with a lottery in the browser, etc.
Somehow it stopped for me a while ago, but it used to be insane.
♥ 2
I didn't say all three tactics were used by both! Google uses bundling with dominant OS and a ceaseless blitz of "You're using Firefox, click here to get Chrome it's so much better" across its dominant web properties, worth tens of millions in equivalent ad spend.
♥ 1
That's a nice sentiment but did you push for a choice screen in Android? Did you ask Maps and Docs and Search and Translate to stop pushing Firefox users to switch? Did you try to get the Docs extension standardised?
I'm sorry but the power of defaults is very well documented, that's why using dominance in the OS space to gain dominance in the browser space is an anticompetitive tactic. It's not like it's not a solved problem, too!
♥ 1
It stopped for me not long ago, after years of badgering. Others in replies were saying they still got it though.
I'd be interested in seeing numbers on how many downloads it drove, how many impressions were made, and what the equivalent marketing budget would be.
I don’t expect you to have them, but you can speak to people who do. This kind of anticompetitive tactic is antithetical to the open Web, getting Google to repair the damage done would help the Web more than all of our tech contributions put together.
At no point did I say that Chrome was a bad browser. It certainly deserves substantial marketshare. But that marketshare would be smaller if Google didn’t very actively cheat, and that would make a huge difference to the health of the Web.
Also, I don’t dispute speed and such, but UX? I tried it on mobile for quite a while but I gave up because it regularly lost half my tabs. On desktop isn’t it just yet another Opera clone? :)
I know that's a common theory, but I actually have some doubts about user desire for the cross-device browser experience. If people really want it that much I don't understand why Chrome has such obnoxious dark patterns to force people to log in.
I of course don't have numbers to back this but IMHO dark patterns are like a code smell: if it worked they wouldn't be there.
I'm happy to sync my history across devices (it's the only bit that I care about), but I don't think users care that much about browsers?
Making that possible and making it happen are two different things though! Controlling identity on the Web is a major battleground right now, particularly with strengthening privacy. It's the battle after cookies.
I doubt Google will give up its advantage, ill-begotten or not!
I'd definitely be interested in hearing a lot more about that, it's a topic I'm likely to be focusing on a fair bit in the near future.
♥ 1
Un truc qui m'inquiète est que les jeux de données officiels français sont vraiment pourris. Si on découvrait un problèmes avec ces chiffres ça ne me choquerait pas. (J'ai contribué au code pour ce bout de notre scraper et 😱.)
♥ 2
Remember Wuhan?
♥ 2
Cotegory theorists.
Sorry, I'll... I'll see myself out.
♥ 1
Yes, there was a good piece from @matthewstoller (which I can't seem to find again) about how Russia swiftly, effectively, and decisively curtailed anticompetitive behaviour from Google.
The EU and US seem to be less interested in maintaining a free market.
♥ 2
This provides some further context about how Google’s Chrome “oops” strategy has long been to cheat its way to the top.
Googlers love to point fingers at Apple’s iOS strategy, but in terms of playing dirty Chrome is the bigger threat to the open web.
Quoting a tweet by @bougakov ↗
♥ 20↺ 2
Of course! I should’ve recalled it was your newsletter and not an op-ed. Thanks!
♥ 1
They’ve stood up, at times, just late and not very effectively. It’s more than I could say of the FTC.
It’s a thorny problem but I don’t think it’s that simple. The browsers do contribute some to feature pressure, but there are plenty of other constituencies asking for their own piece too.
I wish browsers were more modular, but that’s a problem almost as old as computing itself, and Mozilla tried.
I’ve joked before that reimplementing a browser in JS could be the solution, but it might be less of a joke the more time passes…
I can’t speak for all of WE but in France there’s very much an engineering approach to products in which if you build something of good quality — which they do — then users will happen. It’s adorable.
♥ 1
Well, but then accessibility is hard, i18n is hard, you need access to the device capabilities with the right security model, you need to be able to make some privacy guarantees. I'm not saying it's impossible but it gets tricky fast!
♥ 1
Frankly, it's not so bad these days. When you see something that only works on Chrome it's usually that Google wrote that code.
♥ 1↺ 1
I think they need a bit more money than that would likely carry.
Oh, interesting, I don't get that from LinkedIn, I only get constant badgering to install their app. Not much better, but still.
I think this mostly shows that you haven't used it in years!
Also, there are good reasons why the law distinguishes between fair competition and anticompetitive practices.
♥ 6
I wonder if this is something that could have been predicted when everyone dropped the web and rushed to a closed, inferior platform?
I guess not.
Quoting a tweet by @kottke ↗
♥ 24↺ 1
Hahaha!
There isn't an emoji that's laughing hard enough.
♥ 3
So users get screwed the same across the board? Are you under the impression that's legal?
♥ 1↺ 1
Those should really be combining chars.
Oh, this is quite rich. You're all about accountability but when there's a problem it's someone else's fault. Publishers have a choice between going out of business or cheating, and your proposed solution is to cover your own ass.
You're such a caricature it's painful to watch.
The consent dialog *is* built into the browser. It's exactly what Brave or Safari are doing, they are conveying exactly and precisely their users' consent.
♥ 2
IDs can be legitimate when there is governance. That is how pseudonymous systems work: there are strong rules and cultures to ensure that reidentification only happens in the user's interest.
Your idea of governance is to abuse choice and to blame others. You don't deserve data.
So... Who else do you think should be offering a purchase or subscription directly in their app without paying the App Store Tax? #FreeFornite
Quoting a tweet by @jacknicas ↗
♥ 6
It's simple: the TCF is a failure, through and through. I know the spec. I'll tell you exactly what I told Mathias at the time: you can't make open programmatic legal with a consent layer. CMPs are useless for this, no matter how much crypto you add.
♥ 2
The TCF is a typical IAB failure: screw over the user and shift liability to publishers. We walked away from programmatic because it can't be made legal as it exists today. Others don't have that luxury.
The faster you get that, the less you'll waste your time.
♥ 3
There are several aspects to why publishers were unhappy.
One is that third parties have no business being data controllers. The data observed about the publisher’s audience should only be used in the publisher’s service and not elsewhere. That’s how it used to be.
♥ 2
Google wasn’t the only one to do that, if it had been limited to that (serious) issue it might have been chalked up to the usual story of intermediary capture and adtech being publisher-hostile.
But Google managed to make it worse.
♥ 1
What they did was that they required publishers to gain consent for their processing while also refusing to provide an exhaustive description of their processing and putting unlimited liability on publishers if that consent were found to be invalid.
♥ 1
But… you can’t obtain valid consent without an exhaustive description of the processing. So Google’s position was that publishers *must* act illegally to serve personalised ads and that, should regulators enforce, publishers would serve as the liability shield for them.
♥ 1
So yeah, you could say people were mad :)
I think the protocols are the wrong fix, or perhaps more clearly they’re a fix in the wrong direction. Making representations that the publisher obtained legally valid consent to a system that users can’t possibly comprehend, certainly not in a popup, is a fiction.
What would work would be the reverse: making representations that there are no third-party data controllers involved, that none of the data leaves the first party and its known processors, and that various guarantees about the safety of its processing are enforced.
That seems at best difficult in open programmatic, but not impossible and I know some people are working on promising solutions to that.
♥ 1
People are mad at one another because our incentives are out of line. My take is that we start with the user and work our way down the stack weeding out everything that doesn’t align with that. I outline some of that in open.nytimes.com/how-the-new-yo….
♥ 3
It’s work though! Starting with users means not offloading the work of guaranteeing their privacy to them, which means privacy by default.
In turn that means you can’t rely on transparency and control since those assume user action (to read, to chose) and so aren’t “by default”.
♥ 3
I don’t think this is ripping it all out though? It’s fixing in a different direction.
♥ 1
This all goes back to the same problem: if breaking the law is the only way for a group to make money (because if they don’t, others will outcompete them by doing it) then they’ll break the law.
As Pat says, what’s needed is enforcement.
♥ 2
Right, but they also haven’t been enforcing. It looks a lot like CYA theatre to tell regulators they’re accountable.
Indeed, I don't think they want to break the law, but they also don't want to go out of business. So if others are doing it and their business partners are doing it... You have to be really solid to ditch open and go full NPA like we did, even if it's the only lawful option.
I meant to add: I completely agree that it shouldn’t be everyone person for themselves, and I would further say that it shouldn’t be every industry for itself!
♥ 1
During the TCF v1 timeline, when I pointed out that this didn’t seem to provide a lawful basis (and the IAB counsel appeared to be completely aware of this) I was told that this was “a publisher problem”. That’s not exactly constructive (or reassuring).
♥ 1
Party hard, party safe Fort Greene!
♥ 8↺ 2
Hang in there Luis!
♥ 1
I wish! But I have no openings right now. Hopefully next year!
♥ 1
Articles on @nytopen are only from NYT people!
♥ 1
We've all seen bad ways to verify someone's identity, but I have to say that @Experian *really* impressed me today. I love the hint that you can use your mark's date of birth, which you have since you're stealing their identity -- really helpful!
♥ 225↺ 52
They do, you get five minutes to look up the zodiac sign for a given date. I guess it filters out people who really suck at the Internet?
♥ 6
The Markup had started crediting everyone and I think we should all do that. I'm not sure what you mean by "adding", hopefully everyone adds some value. It also shows that these artefacts are built by teams instead of a lone blogger.
♥ 1
In part, but I think you can go deeper and build the whole thing in JS 😁
♥ 1
Frankly, this is so cynical and shameless from Google it made me literally laugh out loud.
I love the bit about how your data might end up with some big business! Coming from the world's foremost privacy violator, it's quite adorable. ❤️
Quoting a tweet by @manjusrii ↗
♥ 17↺ 8
Not that fast and not that reliably. And I'm full of sympathy for the USPS and the people who work there, but their offices are often places of hopelessness.
♥ 8
How do you mean? Lost mail has been a normal occurrence for me since moving here, and while it's anecdotal I find it unlikely that I'd be particularly unlucky?
♥ 1
I've looked before (from the same kind of puzzling as started this thread) and looked again right now, and I'm not finding great data. There are comparisons showing it to be better than UPS/FedEx that are easy to believe, and their own timeliness numbers that aren't great.
♥ 1
Yes, that's why I said that I find it easy to believe that USPS is better than those. And even if you're not in the Alaskan Bush, they tend to suck.
♥ 1
By "they suck" in that tweet I meant UPS and FedEx. Rereading I see that wasn't clear.
I've lived here twice, once two years in the late 90s, and since five years ago. From memory I lost at least three pieces last year, and postcards seem to have a success rate of 50%. I've lived in a few other countries and here's the first time I've worried about this.
My bias is in general very much pro public service, but from a data standpoint it's pretty unlikely that I'd be this unlucky, and I can't see confounders. But I'm happy to see it's not universal, in fact I'm happy if there's less to fix than I thought!
My experience is the exact opposite. And the redesigned Poste, if they sold alcohol I'd actually hang out there.
No, those are the ones I remember and noticed, from 2019. I don't keep running stats, but it's in line with experience. I've had several people angry with me for not answering their letters.
I'm only discussing the local ones. Hardly fair otherwise!
Lol I don't think so! We usually wave or nod at each other.
There's this one time I asked if we could return their rubber bands because I don't know what to do with them but the guy just seemed to think I wasn't making much sense. Maybe that was it!
Oh, definitely with the not destroying. I liked the @jacobinmag plan to do more than bring it back to prefascist levels, and even more if I'm an outlier for unreliability.
♥ 1
I love this classic: appliedabstractions.com/2010/02/04/eng…
♥ 3
This takes sliding into your DMs to a whole new level.
♥ 1
Firefox is definitely underrepresented in Google Analytics.
♥ 1
We definitely use the `timbl` as a speech rate unit, but I don’t remember seeing it in a draft. I think @glazou would know?
♥ 2
The word you want might be ototypical?
This is probably one of the best quotes: “speech at more than 1 timble is difficult to understand; speech below 1 timble is simply boring.”
♥ 2↺ 1
Just build an awesome alternative to gcal and Google will right away add a link to gcal in Gmail. Gotta work the shameless self-preferencing to your advantage!
In the account-specific settings, because it's better if you have to do it several times.
♥ 2
John...
♥ 1
So much proconsumerness.
♥ 1
Isn't that what Instagram is about?
♥ 6
Well, that's... Twitter?
♥ 4
Same! As a non-journalist maybe I could go peek over there and report.
Am I doing this right?
#WorkingInStyle #BestPilsner #NoFilter #YOLO
♥ 3
Damn, there go my thoughtfluencer dollars.
♥ 3
Cruelty is enjoyable, you don't delegate that. Indifference, however, is hard work because the peasants can never quite believe that you really don't care and it's tedious to constantly prove it.
The algorithm is a delegation of indifference.
♥ 2
I don’t know, in general the way in which the DNT requirement is expressed in the regs doesn’t work very well.
DNT is attached to every HTTP request. You don’t want to treat every HTTP request as a *request* to opt out, that’s pretty much nonsense.
♥ 1
What you want is to treat DNT interactions as if the user had *already* made a previous request to opt out previously, and you’re in a state of honouring it.
Otherwise this means dozens of requests for every page load.
♥ 1
In general the regs assume a much clunkier experience than is ideal for users. Eg. we initially had the DNS button built so that you hit it and you’re immediately opted out. Processing time: maybe ~15ms. But the regs forced us to also show a notice, which is painful and useless.
♥ 2
It’s actually much more wasteful than you think. For instance, there’s a DNT header attached to every single static file that’s requested, including every image or font or bit of CSS… So now we’re taking a highly optimised process that’s serving from a CDN and…
♥ 1
…instead we’re now calling an API, hitting a DB, and flipping a bit thousands of times a second?
Doing this makes things slower and expensive for zero added privacy to users.
It’s much more sensible to treat it as “already having opted out”.
♥ 1
The truth is essential. Journalism can help.
nytimes.com/subscription/t…
♥ 2↺ 2
Thank you!
I would recommend Beaufort with some Côtes du Rhône. Strong, subtle, flavourful, but not overpowering. You know, a cheese pairing that’s loyal to you.
♥ 4
Please share when done?
♥ 1
At the end of the day, so long as it only works in your best interest…
♥ 1
I was *just* thinking: I really hope we can do this together in not too long!
♥ 3
I think you handily win at privacy/wine pairings ;-) Bonus points for “extra brut”!
♥ 2
♥ 2
Yes! Not confirmed yet, but looking into it, thanks for the details.
If there's ever a way to change the regs on this point we'd certainly provide support. Beyond those acrobatics, implementing DNT for DNS is pretty cool!
♥ 2
I’m glad they finally found out.
♥ 1
That quote is from this excellent article about @MarietjeSchaake.
Big Tech is an existential threat to democracy, and judging from the sheer level of denial those who work there are in, change can only come from thinkers on the outside.
newyorker.com/tech/annals-of…
♥ 8↺ 4
I think you mean that privacy is in their NDA.
♥ 14↺ 2
It was a joke, Pat ;)
♥ 2
No worries, I think we're all tired for the same reasons :)
Hahaha ça sent tellement le vécu!
It's... tempting to point out that this is not the same measurement since the Dems' doesn't inscribe in a circle. But somehow I don't think that I would make much of a difference there.
When they tell you who they are and what they support: believe them.
Quoting a tweet by @Pinboard ↗
♥ 15↺ 7
Please pay attention to bundles. They could be used for good (packaging ads) but they are a massive architectural change that has the potential to turn the whole Web into AMP.
It would be a scandalous imperialist landgrab for Google to introduce them on their own.
Quoting a tweet by @brave ↗
♥ 97↺ 32
There are ways to get this ball rolling safely.
First, introduce them only without SXG. No URL replacement, no serving from other origins. Google has no business serving other people's content. It's hard to imagine opposing the open Web so much you'd want this.
♥ 13
Second, introduce them in a limited, reasonably controlled context, where there is a strong use case: ads.
This would make it possible to have ads with tons of advantages for users and publishers, like archiving, better scanning, controlling connections outside the package.
♥ 6
It's hard to see how such a major change could be carried out so carelessly, with the Search carousel as its only driver. Anyone working towards a more open Web should be trying to *prevent* the carousel.
No, origin testing doesn't count as careful enough on this one.
♥ 11
Are you saying that bundles don't enable Google to serve other people's content from your servers? What part of this isn't just a replay of AMP with a spec to pretend it's a standard?
♥ 17↺ 1
Oh. My bad. An opt-in basis! That must be neat!
Is this the same opt-in basis that AMP used?
♥ 9
Are you telling me that the party serving the bundle cannot observe the bundle being served?
♥ 1
Answer my question about how your opt-in model differs from AMP and we can talk about whether that matters.
♥ 5
You're not answering the question. I'll take that as agreement that you'll be using the AMP opt-in model. So:
1. Publishers are forced to use bundles on penalty of losing traffic.
2. All this traffic is monitored by Google because there's no "confidentiality".
What a surprise!
♥ 16↺ 1
You know what makes me sincerely very sad here? It's to watch powerless as smart, good people like you contort themselves through inane levels of denial to stick to the belief you're doing anything other than privatise the web.
♥ 6↺ 1
There are several problems. One is that this is just AMP v2, if you think it's unAMPing then you missed the problem with AMP.
I don't speak for the NYT but the way I see it, it's in the business of maintaining its independence and being worthy of the trust of its readers.
♥ 2
Technology that flows yet more power to the already too powerful, but less visibly, contributes to harming the former. That enables third-party tracking at this scale harms the latter.
♥ 4
There's plenty good to be done with packaging. If you want that to happen then ship *just* packaging. If you're on the record saying you should strongarm the web to be served from Google with zero privacy then show us the record.
♥ 2
You seem to be saying that AMP isn't proprietary, but it is so I'm not sure what the point is?
There are all kinds of ways to address aggregation.
How is "oh shit, this destroys privacy" not an immediate showstopper in your book?
♥ 2
Again, you're not answering the question.
The only argument you have is "we have always been at war with native".
♥ 2
It's not just AMP that burnt the goodwill (to me). Everyone can screw up even if that was a very long one. But it's proposing to do the same thing without understanding what the problems were. And deciding to ship because everyone not Google has to be wrong.
You said somehow ensuring the web be relevant in a world of proprietary aggregators, but AMP is just that as used by Google, as would be bundles.
If I read news in my RSS then I am interacting with that client, and what it sees of that is fine. If I load content that claims to be from nytimes.com but Google observes that load, that's a violation of privacy.
♥ 3
Of course, in the context of removing 3P cookies it's also a massive self-preferencing play. This isn't like a CDN. It's abusive to publishers because it forces their hand, and abusive to users because it violates their expectations of privacy.
♥ 3
Are you offering to stop forcing publishers to do that?
♥ 7
Clearly, you missed the Eastasia reference. Not that this surprises me now. It would have, a while back.
♥ 1
Except that bundle will never just be in the SERP. It will also be "opted in" to show on every other surface.
How is it offensive? Literally your only argument is that you want to compete with a threat, and it's the exact same threat in every single one of your arguments?
You want the web to win? Play to its strengths and stop centralising it.
Otherwise: same shit, different people.
♥ 5
Agreed! I think there are ways to deliver packaging progressively and safely. I wish they'd listen.
A Google-only spec with a Google-only implementation is proprietary!
As I've said before, this can be rolled out in workable increments instead of as a diktat. Why not do that if you mean to do this well?
There are ways to get this ball rolling safely. First, introduce them only without SXG. No URL replacement, no serving from other origins. Google has no business serving other people's content. It's hard to imagine opposing the open Web so much you'd want this.♥ 13
♥ 3
Actually, returning to this idyllic vision of frictionlessness and fruitful content all around, might I earnestly recommend a book? bookshop.org/books/seeing-l…
You're not introducing SXG at all?
And no, I'm not taking jabs for fun, it's incredibly frustrating to have to treat the Chrome team as adversarial.
Exactly. And the goal is to keep those people separate so that we can have good governance of the web. So that we have checks and balances against bad, or simply wrong, actors.
What you propose instead is to leverage your dominance in two of these to lock up the third.
This is... completely besides the point. What matters is the mechanism.
You leveraged your dominance to force people to use AMP. It sounds like you plan to leverage your dominance to force people into bundles. So I repeat: how is that opt-in?
♥ 17
Removing friction while ignoring the power dynamics does nothing but strengthen the existing power. Removing friction is how you leverage dominance in one market over an adjacent one with which friction was removed.
♥ 1
An incremental approach would be to have just bundles, no sig, served only from their origin.
I've been working on a requirements document. It should ship when I'm back from vacation.
♥ 1
And no, it doesn't propose to leave the mess you made as is. It hints at better governance for the Web. The current model is "Google is right, everyone else is wrong, so it'll get imposed anyway. Oops that broke something! Let's do that again!" We need better.
♥ 1
Unless it games itself by structurally preferencing content it could prefetch because it is served from Google.
♥ 4
That means that sites that collaborate to speed up the Google experience will get better crux. Even a fraction of a third is a huge difference in a tense market.
♥ 4
You jest, Andrew, but following the current trajectory the web is likely gone within 5 years, just a Google strip mall as gated as native, if less bluntly. Rebooting from offline tech could be our best bet. It's certainly a contingency I'm thinking about.
That's a fine idea, but if the performance characteristics of SXG mean that those who participate rank better it can not be a requirement and still be necessary to compete.
♥ 1
You're 100% right. There are many hypothetical ways in which this could be good. The problem is that based on empirical reality, it won't be. It's a lot to detail over Twitter, but I'll try to summarise some notes.
♥ 12
Platforms in two-sided markets like this can create a lot of value. That certainly used to be true of Search. But they also get a lot of power from gating, lock-in effects inherent in two-sided markets.
♥ 8
This needs checks and balances, but here there is no CPNI or separation of banking & commerce. Google has massive leverage from this. Rarely, it can be used for good (HTTPS), but mostly it's used to tilt the balance unfairly in Google's favour.
♥ 7
I appreciate the ping but I'm on vacation so long lag should be expected.
The number of deeply experienced Web people reaching out after the threads on Google's WebBundle saying they think the Web is dead, just hasn't stopped moving yet…
The worst part is how hard it is to disagree. Things have been grim before, but never this grim.
♥ 56↺ 16
"Never bet against the Open Web," we used to say. I'm not even sure who came up with that first.
But what do you bet on when the Web isn't open any more?
You're 100% right. There are many hypothetical ways in which this could be good. The problem is that based on empirical reality, it won't be. It's a lot to detail over Twitter, but I'll try to summarise some notes.♥ 12
♥ 20↺ 4
I keep thinking about what to do after the Web is gone. So many of us wanted this to be good, for everyone. Losing it is certainly bad for civil society.
There's plenty more worth standing for, but none of it with so much promise, none of it the medium for all humankind.
♥ 19↺ 3
We should go out in style though. Not with a whimper.
♥ 9↺ 2
The stated plan says performance affects the ranking. Bundles affect performance, if preloaded from Google almost certainly in ways that cannot be matched in other ways.
Where's the stretch?
I haven't said anything bad about web vitals? The whole time that AMP has existed we've all asked for web vitals and the shut down of AMP. Google promised it so many times it's a common joke. Even people on the AMP AC laugh at it.
♥ 4
But instead we're getting web vitals and something that renders them useless. So who cares about intent? This is just the usual Google hurting the web and patting itself on the back that it meant well.
♥ 4
OK. Well then there really is no use case for bundles is there?
You can't say ranking isn't affected for stuff that doesn't carousel. The carousel is a hell of a piece of ranking!
♥ 3
Sure. But then who needs signing? Bundles without signing don't muck around with origins, don't upset the Web's architecture just to replace a technology that shouldn't have existed in the first place, have better market dynamics, good perf.
So why sigs?
♥ 1
I still don't know what your point was unless it was that we don't need to sign bundles at all. Good night to you too!
♥ 2
And as I pointed out, that stated plan has a lot of gaps.
♥ 1
That's an interesting take. I'm not sure where it leads but I can sense that it could help. Need to chew on it. Thanks!
♥ 1
Yeah, I'm not giving up, not just yet. I've lived through those too. But the previous assaults were frontal, this one feels different. Google has gamed the web from the inside. We're in a more complicated situation, at least it feels that way.
♥ 6
If we make it through I'm tired of having to wait for antitrust or other regulatory intervention to step in every decade. We need to fix that for good.
♥ 1
Haha, the SVG working group debated that twenty years ago, for pretty much the same reasons 😁
That doesn't make it a bad idea though. I need rest too, but it's true that we may be stretching the architecture of being all things to all in a single mode.
What? I can get the whole world's music in Spotify, as just fungible commodity. You're doing the same for the Web. I'm not making a metaphor, I'm just stating fact.
This is... a complete nonsequitur?
♥ 1
Absolutely, even though that might involve some uncomfortable cuts because it's all a bit tangled up in a way that makes keeping just the good stuff awkward. But there's a lot to keep.
♥ 2
I'd like to rebuild with power guaranteed to stay at the edges. The impossibility to match identity across two contexts. Content contracts (in support of IP but not DRM). Strong, legally binding fiduciary duties for user agents.
♥ 3
What snark? I've taken time out of my vacation for nothing other than to show with argument and fact that you are working against the web, but that there are ways for you not to.
If it's more comfortable for you to ignore that, that's entirely your right. The open Web is an opinion, you don't have to agree it's right.
But this many tweets in, without a single rejoinder from you about your market dominance tactics, you don't get to dismiss this as snark.
The Internet was disruptive! That's a good point on gating access. You know who used that to unfairly dominate markets? Newspapers! Damn good at it, too. But then the regulators intervened and that's how we have quality news instead of a cartel.
The problem today is not at all about preserving any business model. It's about eliminating abuse from dominant players. Not to keep old things, but on the contrary so that we can have new ones.
With Spotify, there can be very little innovation in music beyond what Spotify thinks music should be. If tomorrow I make a revolutionary olfactory synesthetic album, I'm fucked. Spotify can't run it because they took the business of pumping out the bytes from me.
It's the same with the strip mall web you want. We can't "shine through" with content if we can't run our tech. Tech isn't neutral. It shapes the how, what, who of communication.
I'm fine with disruption. But Google isn't disruptive. That was a long time ago! It's just a cheating incumbent.
I mean, are you saying that this is right: themarkup.org/google-the-gia…
Innovation in advertising has been stalled for years. Are you saying that we should keep this: papers.ssrn.com/sol3/papers.cf…
Packaging is fine. Serving other people's content while pretending you aren't isn't.
♥ 6
How is "strip mall web" snark? You're literally turning the web into a list of businesses that have to follow your rules. Kenji literally said we should leave the serving to you.
And motives? Who's motives have I ascribed?
♥ 2
As I've said before, I'd love to be wrong. The Chrome team used to be a hell of an ally!
Tell me, do you think this is conspiracy: themarkup.org/google-the-gia…
What about this: papers.ssrn.com/sol3/papers.cf…
I've asked simple, honest questions time and time again in this thread about what you are doing about the distorted market dynamics you can see just as well as we all can. So far, I've heard nothing but a lot of silence.
Same, except I never moved to SV in the first place 🤭
♥ 3
I was just trying to show that there's history, and that people have been in your position before. Is that what you felt is unhelpful? Or are you denying that Google is massively leveraging market dominance in anticompetitive ways?
If by ill intentions you mean that publishers are forced into it, that's just a fact. I don't know what the intentions were. Have you looked at the license you impose for it? Is that necessary to ward off those threats?
Again, privatise the web is a fact, and it's an effect. I don't say that it's an intent. You're making the web run on Google instead of independently, and we have no say in the matter.
What stunts the development of the web is precisely the fact that we can't build anything without having to defend against you as part of the technology. Isn't that a problem you would want to solve? I think it's a problem.
♥ 2
You said we shouldn't be in the business of pumping out the bytes. Implicit there was that you serving our content à la Spotify is fine.
OK, I get that you can't talk about some things. But there's a problem there: whether the web has a future depends more than anything else on whether we can stop Google from cheating at this scale. I really am not saying this to point fingers, it's just where we are.
And I mean it when I say "at this scale". Cheat a little bit if you want! I honestly don't fucking care so long as you stop harming the web and pretending it's not happening.
Again, I completely get that you can't talk about it. But is it that insulting to ask that you think about it a bit more seriously, and stop claiming native is the more serious threat?
Because if that's the web we get it really is no better than native.
♥ 2
Just don't ship the sigs then! I believe you mean this. This is a good thing to fix. It just doesn't require screwing around with origins.
Yeah, exhausted too. Checking out of this thread. Let's reconvene when I ship requirements.
I still don't understand why anyone needs to screw up origins!
♥ 2
Fair! It matters a lot that you stop forcing people to hand that business over to you though. If you don't understand that you are forcing people, I get that, but you need to look more closely.
♥ 1
I didn't say it was because of where you work.
A Web in which distribution, identity, advertising, and a few other things are dictated by a single player, what's more one that will cheat to put itself first, isn't worth having.
♥ 2
A CDN we choose. They work for us. This we don't, and it doesn't.
♥ 1
And I would love to live in that world. But there's plenty of evidence, which alas you can't discuss, that you are abusing the power dynamics of the existing Web. And bundles make that worse. Give me 1 reason we would trust that this time it's different from what you already do?
♥ 1
And I'm not arguing for inertia, on the contrary I'm arguing to *change* the way we do things so we can have the nice things you talk about without you molding the web to your unique vision.
♥ 1
What? No. It's that no one should be forced into bundles, and if TS or ranking depend on it even a little bit that will hurt.
♥ 1
Actually, not so clearly. The explainer does not distinguish between what is gating and what is ranking.
Cloudflare is a service provider. Bundles enable serving by a third party.
♥ 4
I'm only proposing to eliminate any advantage, direct or indirect, from having your content served by Google. All other pure UX rankings are fine.
I don't understand how this is so controversial.
♥ 1
As I've said plenty of times in this thread (which technically I said I left to return to my vacation 😛) I'm happy with any solution that does not involve a third party serving other people's content. That's a violation of the trust structure of origins.
I have plenty of use to bundle things on my own site, so long as it's origin only.
I literally said that bundling should ship without sigs, I think that was, like, my second tweet.
♥ 2
I want all of the perf (crazy not to!) but none of the forklifting content to Google. Otherwise it's just AMP! Thank you 🤗
♥ 1
I've actually been thinking about similar things! I've been wondering about telemetry standards. My goal is to render UAs auditable so we can have strong fiduciary commitments, but shared telemetry datasets would be really useful for the Web.
♥ 1
We could put them in a data trust and run them as a commons. It's not sexy (that's what you and I are here to bring 😉) but it could be very useful.
I wish I'd said it as well.
♥ 3
See the discussion with Yoav about perf data from multiple engines. That's solvable.
That's a bit short for me to figure out what your argument may be?
♥ 1
What's frustrating is pretending these are separate problems. The web only has a future if we can build it in a way that is Google-resistant. If Google were less of a threat these properties would be less important in a file format's threat model.
♥ 2
IIRC @jyasskin is the one who said it best: you have to include Google in the threat model.
♥ 2
He didn't say people weren't thinking about it. He said they failed to see.
♥ 3
Just my theories and probably not exhaustive, but:
• Googlers don't include Google in the threat model. That's understandable, but given how bad things have become with Google's effects on the Web, it doesn't work.
♥ 53↺ 8
Fixing that would probably include an internal review system that focuses on how technical decisions play into the existing massive self-preferencing system, and favour options that prevent it. Yes, that's hard, but scale doesn't come cheap :)
♥ 6
• Dismissing feedback about AMP. It doesn't matter that the intent was to compete with native. For pubs the effect was disastrous: extra work, lower CPM, lower conversion, broken paywall, and yet more centralisation to Google.
♥ 14↺ 5
• Maybe acknowledge that publishers were forced into AMP, and that fixing that should be a priority?
• When we provide feedback that the new things has aspects that look way too much like the previous failed thing, maybe don't get defensive about it?
♥ 8↺ 1
At the end of the day all we're saying is: we don't want you serving our content and we don't want to be forced into rules that advantage only you. Not much!
♥ 7↺ 1
I'm just here for the chaos.
♥ 6
Mozilla has done some interesting work on privacy in telemetry, it might be an option?
♥ 1
I read it exactly that way 😁 I remember the same. If Buffy taught us anything, it's that there's a plural to "apocalypse".
♥ 1
One thing that saddens me is that we were supposed to build cool stuff, not fight our friends who went to work for a megacorp.
I agree that's not completely enough but it's a great approach! You're entirely right that the first step is to assume you're the potential problem and take steps to mitigate, instead of assuming you're good. We use similar thinking. ♥
Hiding the fact that the content was served from a different origin than advertised makes the problem worse, not better. Same violation of user expectation, even less visible.
♥ 5
More than a "lived experience" AMP harms publishers across pretty much every metric we might care about. And you force us into it. What part of the feelings this produces do you find hard to understand?
♥ 9↺ 1
OK. And how can I stop you from forcing me into letting you rehost, like you do with AMP?
♥ 8
Again, they're only orthogonal if you don't include Google in your threat model. But for those of us trying to stay independent and keep the web open, that's not an option.
CWV only matter if rehosting by Google carries no advantage over vanilla Web, in threshold or ranking.
♥ 10
OK, but the expectation is that of an improvement over AMP. Otherwise you've just invented more complicated AMP. And baked it into a browser. And tried to make it look like a standard. And made the violation from 3P delivery less visible.
♥ 5
I mean, maybe we're talking entirely at cross purposes and your goal is to entrench AMP problems even more. In that case we completely agree that you're on the right track!
♥ 9
Yes!
I don't think it's dead yet either, but it hasn't been in this shitty a position in a long while.
♥ 1
I don't think that the idea is that no one inside Google looks at Google as a potential problem, we know you do. But there are plenty of cases in which it's obvious that Google was simply a blind spot in the threat model.
Identity in the browser, many of the privacy things (I've had conversations with Googlers who sincerely struggle to understand that them getting data could be a problem), AMP are a few good examples.
♥ 1
Of course. This is essentially a comment on observed outcomes more than on mental states. I think it might also trace back to company organisation. It's likely imperfect info (from a Google recruiter) but the User Trust org seemed built more around making users trust...
♥ 1
... Google than about Google trustworthiness. Again, it may be imperfect (though it wasn't the only red flag) but it jumped at me because it's the literal opposite of the approach I've been pursuing. You can see how that could add up, with the best intent of smart folks?
♥ 1
I didn't say you mentioned User Trust, I did, as an example!
And I know there's organising, I'm just saying that it doesn't show in much of the tech and products we have to deal with.
On military tech, maybe, but on AMP, privacy, identity people always seem shocked to find out that someone who understands how things work (as opposed to clueless haters) would actually see any problem. Just look at the AMP discussions here!
♥ 1
In general web packaging makes things better. There's a ton I love about the idea of packaging in general, a lot I want to do with it. If only it didn't involve content forklifting I think we might be good?
This looks like an amazing job. I'd apply if I didn't already have a pretty neat job 😁
Quoting a tweet by @sarahdrinkwater ↗
♥ 9↺ 1
I need to look at some details but I think I'll be more than fine with those, I can't wait to put them to use for a few cool things.
You think there won't be adoption without signing?
I was thinking exactly that and look forward to it!
♥ 3
I think a lot of offline can work without signing. I mean, how often are PDF sigs used? I know it's a bit different, but people only care so much about authenticity.
I mostly want to kill PDF and bring ads under control. If we can get that it'll be a pretty nice day.
♥ 1
I hear you! At the end of the day I don't know that we can make people care, though. The thing with authenticity is that social signals beat technical ones. People will believe a screenshot of an article sent over WhatsApp by a trusted friend over the original with green padlock!
♥ 2
Yup. What remains unclear is whether it's a threshold (anything "good enough" can be in, then ranked on other aspects) or a ranking. If the latter the effect will just be AMP.
Is there a way to bring back search shortcut keywords in the latest Firefox for Android? Pretty much everything about the latest is great, but this bit is a big loss. I can't seem to find info about restoring it.
♥ 5
I like it at the bottom, it takes getting used to but it's in reach of my thumb which is cool.
♥ 1
More the former, basically I'm looking for support.mozilla.org/en-US/kb/assig…. On mobile it's particularly nice given the higher interaction cost. My keyboard is contextual and has learnt to offer shortcuts for @Bookshop_Org or Wikipedia first.
Of course that's my default 😁 But it's necessarily slower. A bang for @Bookshop_Org which I search several times a day would be nice though!
♥ 2
Thanks a lot! I'm sure other book junkies will appreciate it!
♥ 1
"Google is pitting itself against “big media companies” and appealing to the Australian public to oppose the proposal."
🤣😂🎻
Quoting a tweet by @manjusrii ↗
♥ 12↺ 4
Yeah that is really good stuff. I think Google massively overplayed their hand with their crazy intervention. They made people care about the @acccgovau who had never heard of it before.
♥ 1
Got to love the part where the @acccgovau flat out calls Google's insane letter to all Australians "misinformation" right in the first paragraph, and clearly has the facts to back it.
Quoting a tweet by @montezumachavez ↗
♥ 2↺ 1
Funny that. I can't quite think of a reason why. Clearly you must be biased in favour of Big Democracy or something.
♥ 1
How can they hope to stay a trillion dollar business if they have to pay for other people's content that they use to drive traffic to themselves?
♥ 1
The font size progression, the weird blend of font families, the 80s haircut... It's a whole vibe.
Ow.
♥ 2









