Hacker News new | ask | show | jobs
by eh78ssxv2f 2018 days ago
Exactly.

Besides privacy and obvious web-centralization issues, there are bunch of security issues associated with proxying the traffic. Apple and Mozilla brought these issues to the attention of Google during SxG spec discussions. At that time, Google's rebuttal was that SxG is a opt-in feature for sites.

Quoting from [1] (Mozilla's official position on SxG): "Sites opt-in to using this mechanism, and in doing so need to be aware that this comes with some risks, but in doing so they enable a new feature".

This time, Google really did not handle any of the previously discussed security/privacy concerns. Instead, they just went ahead and started proxying the user's traffic without the opt-in from the users or the sites.

[1] https://docs.google.com/document/d/1ha00dSGKmjoEh2mRiG8FIA5s...