8 ms·
Google Removes Cookie Control from Chrome
- btilly 16y agoThis smells like a bug. Has he tried reporting it to http://crbug.com http://crbug.com?
- stretchwithme 16y agoThe author says google is pushing out new versions of the browser automatically now. I was pretty sure I didn't enable the automatic updating feature but when I checked "About Chrome", I was informed that the browser had been updated. Seems to be no way to disable this either. Am I missing something?
- aj 16y agoYes, that is a feature that Google has hardcoded into Chrome. You CANNOT disable auto-updates or even make it so that you are asked for confirmation.
- wazoox 16y agoFortunately, the auto-update feature doesn't work on my Linux machines.
- jan_g 16y agoSame here. Everything is managed via Synaptic update manager and Chrome gets updated only after I hit the button 'Install updates'.
- russss 16y agoChrome's auto-update feature on Debian-based distributions at least consists of it installing its apt repository in your sources.list. Which is fine by me.
- masklinn 16y agoOf course you can (disclaimer edition note: but it's not necessarily for the faint of heart, and isn't officially supported. On their updater and update policy, Google manages to be worse than Apple on Windows, which is already pretty fucking bad). 1. On Windows and OSX (at least), the actual updating is performed by a single service running in the background for all Google applications (the Google Updater). This service is installed and/or activated by all Google applications, every time you install them (or run them, in OSX, not sure for Windows). I'm sure you can find how to do the same in Windows but my know-how is not good enough, but in OSX you can disable GUS forever by uninstalling it, emptying its directory and then setting it write-only. This way, it's not possible for GUS to be reinstalled. 2. A good enough outbound firewall (I'm partial towards Little Snitch on OSX) will allow you to block connections to the update server, and make GUS unable to query it, and therefore to update Chrome without your consent.
- barrkel 16y agoOn Windows, Autoruns from SysInternals (http://technet.microsoft.com/en-us/sysinternals/bb963902.aspx http://technet.microsoft.com/en-us/sysinternals/bb963902.asp...) works fairly well for finding out about these things that happen automatically, and disabling them, as easy as unchecking a checkbox. There's at two categories relevant to googleupdate: CurrentVersion\Run, and Task Scheduler.
- barrkel 16y agoToo late to edit: there's a third one, in Services, on my machine gupdate1ca54[more hex digits] - it also links to googleupdate.exe.
- aj 16y agoUgh, of course, there are work-arounds. But if you re-read my comment, I said it is hardcoded in Chrome. I was talking about Chrome. Another point: Your method will disable all google updates (google toolbar, google talk etc) which is a good side effect imo but not necessarily desirable by all.
- 16y ago
- fauigerzigerk 16y agoThat's a very bad "feature". On some connections I pay for every MB downloaded.
- beej71 16y agoI agree it's questionable from a money standpoint, but not updating your browser is questionable from a self-preservation standpoint, as well. (But I also agree that should be your decision to make.) The compression Chrome uses on the diffs is pretty hardcore: http://www.chromium.org/developers/design-documents/software-updates-courgette http://www.chromium.org/developers/design-documents/software... So you can at least be reasonably certain that your browsing bandwidth dwarfs the Chrome updates, FWIW.
- fauigerzigerk 16y agoI don't understand why they're taking that decision away from me. They could just enable auto update by default so most users would always be up-to-date unless they have a reason for disabling it. There are some good reasons other than money as well, such as privacy and security. I don't want my computer updated in any shape or form when I'm on an airport or in an authoritarian country for instance. I don't know whether a Chrome update is dwarfed by regular browsing. The link you posted shows the size of one particular diff update they did. That's a completely worthless measure. The worst case, no doubt, is that everything has to be replaced and that would be 10MB.
- darren_ 16y agoSecurity-wise I'd be very surprised if Chrome updates weren't signed; MITMing of auto-updates isn't exactly new (see EvilGrade). So I doubt it's an issue there. That said, I agree that there should be an option (not a prominent one) to switch it off.
- DennisP 16y agoThen why is my Chrome still on version 3?
- bostonvaulter2 16y agoIf you switch to linux it won't auto-update.
- modeless 16y agoThis is how Chrome has worked since forever, and it's a good thing. Asking the user for confirmation for security updates leads directly to users running known-insecure versions of software. If you don't want auto-updates, use Chromium.
- gaius 16y agoImagine the howls if Microsoft had done this...
- edanm 16y agoIt's not about Google vs. Microsoft. The world has simply gotten smarter about such things, and most people now accept auto-update as a good idea.
- drdaeman 16y agoHowls of joy because we won't have any IE6 systems left? ;)
- rmc 16y agoIt would be brilliant! If MS did this then IE6 would have dissappeared long ago!
- 1337p337 16y ago...Or a different browser. Seriously, though, Google is used to web development, where they control the software and the machines running it. A new version of GMail rolls out, and everyone gets it. Like in the case of Buzz, this isn't always good, but it makes developers' lives easier. But desktop applications are a different game. Almost any time you take control away from the user, it's bad. New version of the browser introduces a security flaw? Sorry, you've been automatically upgraded. Hate a new feature? See previous answer. Security hole found in the Google Updater daemon? Oops, we gave it admin privileges and ran it without telling you. Has Google created so much good will over the years that people don't scream about this the way they would about similar behavior from Microsoft/Apple/DemonizedCompanyOfYourChoice?
- thezilch 16y agoTitle here and there are a bit misleading. My hope is Lauren has simply missed the cookie icon, in his location bar. Running 7.0.536.2 (dev), in the cookie settings, I can set Chrome to "Block sites from setting any data." Now, upon browsing to a site attempting to set, in the URL (location) bar is a cookie with an "X" overlaid -- similar in style to the padlock with an "X" when an HTTPS URI is using an unsigned SSL cert. Clicking on the cookie presents me with the list of "cookies and other site data." Each can be selected and "Allowed" or "Allowed for session only." The claim that one needs to allow "willy-nilly" or only having the option of "manually entering cookie exceptions into tables," these are just hand-waving. I'm not sure what more is needed; I certainly don't want popups for every cookie without my taking action.
- ck2 16y agoWhat about third party cookie control which is important? I barely use chrome but I know firefox has a toggle for this.
- thezilch 16y agoWhile I'm not familiar with which Firefox controls you are referencing, the following is a shot of the cookie+"X" and the impending modal for selecting 0..n cookies and site data to be allowed indefinitely or for this session alone: http://i.imgur.com/va1xW.png http://i.imgur.com/va1xW.png
- ck2 16y agoFirefox (3.6.11) default without plugin modification: http://i.imgur.com/TUgZU.png http://i.imgur.com/TUgZU.png "accept third-party cookies" (which no web developer should ever rely on) and also available via an extension (but should be built in) http://i.imgur.com/dZxFG.png http://i.imgur.com/dZxFG.png (hmm, why is imgur setting a 9-month long tracking cookie)
- Tichy 16y agoKey thing is really to disallow third party cookies, as that (among other things) is what is being used to track you by all the advertisers, spammers, Facebookers and so on out there.
- mtigas 16y agotldr: Author is referring to the ability to enable the "ask me every time a site wants to set a cookie" prompt (a la Firefox). Looks like this has been disabled in the latest Chrome nightly. FUD, etc. However: In general, cookie controls are still entirely there, so I'm positive that specific feature is what they're referring to. I use an extensive cookie domain blocklist and that's all there and functional. (I've never used said "ask me every time" feature in Chrome, but I went through a phase of using that on Firefox.) ----- UPDATE: Found the relevant checkin: https://code.google.com/p/chromium/issues/detail?id=51375 https://code.google.com/p/chromium/issues/detail?id=51375 Looks like the previous behavior can be re-enabled via the "--enable-cookie-prompt" command line argument. Perhaps support for re-enabling that by default should go in that bug (or a new one that references it)?
- lionhearted 16y ago> I use an extensive cookie domain blocklist and that's all there and functional. Care to share a rough overview of sites you're blocking, and a little of your reasoning? I tried putting fairly restrictive settings on Firefox one time to see how browsing differed - I noted a lot of sites didn't work without explicit permissions, so that's sort of a hassle. Beyond that, is it privacy considerations? Do you work in a field that you wouldn't want your browsing habits logged and cross-referenced? Vagueness on answer is ok, I'm just kind of curious what your reasoning is, and if there's any utility to me building some kind of blocklist for myself.
- stanleydrew 16y agoI know you weren't asking me, but I have a similar setup. I block everything by default and only enable specific cookies when necessary for functionality. Same with javascript, which Chrome makes pretty easy. I don't have any specific reason except that it feels cleaner not to send a bunch of data over the wire that isn't really necessary.
- joey_bananas 16y agoSo, how do you do that then? Some extension I assume?
- jrockway 16y agoSummary: "I noticed a bug in the latest Beta version of Chrome. I know Beta versions are 100% stable and never have bugs, though, so I assume this is some conspiracy by Google to ruin my life or something. Two more pages of whining about this." I wish everyone contributed to open source projects, so they would know when to blog and when to file a bug report.
- kelnos 16y agoThere's actually an issue on Chromium's tracker that suggested removing this feature (which was then closed as implemented). See link somewhere in the comments.
- barrkel 16y agoI'm starting to get the impression that Chrome is the browser for inept people, and that if you want good control over the browser behaviour, it's not a good choice. Chrome's responsiveness to public feedback is similar to Google's responsiveness, i.e. not responsive at all, and tends to authoritarianism. My worry is that Firefox may take too much of a lead from it, and similarly start removing features.
- bradgessler 16y agoCookie management is kind of a tin-foil hat feature that is already served by Incognito mode. For the more technically inclined that really care, there are switches to turn on cookie management (and no doubt third party extensions)
- barrkel 16y agoI don't think it's well served by Incognito mode. You want to keep login cookies, but not J. Random Site's tracking cookies. Similarly, I need to install an extension (No History) into Chrome to disable history logging without disabling login cookies; but it isn't able to clear the "Most Visited" list that shows up in new tabs, owing to limitations in the API.
- dhess 16y agoAs far as I can determine, Incognito mode just creates a 2nd sandbox for cookies and history that's shared across all Incognito tabs/windows, and is only deleted once you close them all. Cookies you create in one Incognito tab or window are visible to all other Incognito tabs/windows, just as cookies created in plain tabs/windows are visible to all other plain tabs/windows. So if you go into Incognito mode and browse there for a few hours, soon you've got a bunch of cookies that are following you around the Internet until you close all your Incognito tabs. In my case, I have Chrome set up to delete all cookies on exit, so Incognito doesn't buy me much: I might as well just quit the browser and restart. If Incognito mode worked in such a way that each tab were its own cookie sandbox, then I'd be reasonably satisfied with it as a cookie management solution, but as it stands, it's not good enough. (Because each tab is a separate process in Chrome, one would think that it would be reasonably easy to support that behavior.) In lieu of that, what I'd really like is a Chrome extension like Firefox's CookieSafe, where I can block all cookies by default and then whitelist them back in on a site-by-site basis, but nothing like that exists at the moment. For now, the best I can do is the Tab Cookies extension, which removes a domain's cookies once you close the last tab that's browsing the domain. For my purposes, it's inferior to both of the other solutions I mentioned (per-tab sandboxing and whitelisting), but at least I can keep my footprint reasonably small, as long as I'm diligent about closing tabs.
- wooptoo 16y agoIs it me or Google is slowly turning evil?
- TylerBrock 16y agoWho cares... if you don't like it, don't use chrome.
- js2 16y agoRelatedly: Ultimately, the problem is that blocking third-party cookies doesn't really buy you much (if any) privacy from folks who are motivated to track you. On the other hand, blocking third-party cookies does break some real use cases about federated identity and web sites that span more than one host name. We decided to keep the option because it make some of our users happy, but we decided not to make it the default because we don't think the trade-off is advantageous for the majority of users. If you'd like more information about this topic, you might be interested in reading this paper: http://crypto.stanford.edu/safecache/sameorigin.pdf http://crypto.stanford.edu/safecache/sameorigin.pdf From http://code.google.com/p/chromium/issues/detail?id=51031 http://code.google.com/p/chromium/issues/detail?id=51031
- LaurenWeinstein 16y agoHi all. The original blog post on this topic is mine. Let's assume you're a very "privacy conscious" person who only accepts cookies for sites where you feel they are necessary -- say ones where you're going to login, or you really want to read articles there and you can't without the cookies, or whatever. Under Firefox (and Chrome under the old modality) your cookie setting choice was "Block but notify on new cookies." Under the old model, when you first tried to access that site, create an account, login, register, etc., you'd get the initial pop-ups that you needed to respond to, that made it very clear that there were cookies involved now that you might want to accept. This is in fact a modal decision, because not accepting those cookies at that point will have consequences (like registration sequences that keep repeating, login prompts that won't accept your input, and so on). Now the new model. As you browse the Web the little cookie icon is constantly popping up in the bar. Sometimes it shows clear and sometimes it shows blocked -- but after a while you're just going to ignore it as you go flying from page to page. There's nothing in that icon to alert the user that they've reached an important decision point about an initial cookie from a site. Even if they think to click that icon at the right moment on a new site, they have to do more clicking to dig down into the cookie management system to accept it if they wish to. Old model: You're on a page where you want to login. You get a pop-up that there's a cookie. One click on Yes. Finished. Easy to do, and impossible to miss that there's a key decision point. You really do want people to make a go/no-go decision on initial cookies from sites, and not create a situation where they can easily go winging by those initial cookies and have them fall into a default blocked state -- since the consequences of doing this are a mess and require going in and deleting cookie blocks manually. It's really initial presentation of first cookies on a new site (when the user is defaulting to blocking cookies) that is the major concern. In that situation, the user should be presented with a modal choice so that they cannot easily miss the fact that they are at an important "exception" decision point -- that is, accepting a cookie when their default is not to accept all cookies. And remember, by not choosing the simpler "accept all cookies" option, the user has already demonstrated that they have concerns in this area, and are likely to be very accepting of UI sequences that make it easier for them to function within that choice with a minimum of confusion or risk of not noticing new initial cookie decisions for a site. Sorry about any formatting nasties in this response -- I copied most of it in from a text-based e-mail. Thanks. --Lauren-- lauren@vortex.com http://lauren.vortex.com http://lauren.vortex.com
- LaurenWeinstein 16y agoAddendum -- I was unable to see any change from adding the specified command line argument, at least with 7.0.517.24 Any contradictory reports? Thanks.