Chrome is experimenting with RSS support, cleaning User-Agent strings, and automatic password changes.

Google has announced the addition of an experimental "Follow" feature in Chrome, which includes a built-in RSS client. Users will be able to subscribe to RSS feeds from their favorite sites via the Follow button in the menu and track new publications in the Following section on the new tab page. Testing of this new feature will begin in the coming weeks and will be limited to certain Chrome users in the US who are using the experimental Canary build.

Chrome is experimenting with RSS support, cleaning User-Agent strings, and automatic password changes.

Google has also published a plan to trim down the User-Agent HTTP header content. The reformation of User-Agent support was initially planned a year ago but was postponed due to the COVID-19 pandemic. It is noted that Safari and Firefox have already removed OS version details from the User-Agent.

Chrome 89 has enabled the User-Agent Client Hints mechanism by default, which is being developed as a replacement for User-Agent. Now, Google intends to start experiments to reduce User-Agent related functionality. User-Agent Client Hints allows selective delivery of data about specific browser and system parameters (version, platform, etc.) only after a request. proxy server. Users, in turn, can determine what information can be provided to site owners.

When using User-Agent Client Hints, the identifier is not sent by default without an explicit request, and only basic parameters are provided, which complicates passive identification. For sites that need detailed browser data in the first request, extensions called "Client Hints Reliability" have been developed, which include the HTTP header Critical-CH provided by the server, indicating that the site requires Client Hint parameters to be sent in a separate request for content generation, as well as the ACCEPT_CH extension in HTTP/2 and HTTP/3, which transmits information about the Client Hint parameters that need to be obtained at the connection level. server.

Until the migration to the Client Hints mechanism is complete, Google does not intend to change the behavior of the User-Agent in stable releases. At least in 2021, no changes will be made to the User-Agent. However, in the experimental branches of Chrome, experiments will begin with reducing information in the User-Agent header and the JavaScript parameters navigator.userAgent, navigator.appVersion, and navigator.platform. After this cleaning, it will still be possible to determine the browser name, significant browser version, platform, and device type (mobile phone, PC, tablet) from the User-Agent string. To obtain additional data, the User Agent Client Hints API will need to be used.

Seven stages of gradual reduction of the User-Agent have been defined:

  • In Chrome 92, a warning about the deprecation of navigator.userAgent, navigator.appVersion, and navigator.platform will begin to appear in the DevTools Issues tab.
  • In Origin Trial mode, websites will have the opportunity to enable the transmission of a reduced User-Agent. Testing in this mode will last at least six months. Based on feedback from testing participants and the community, a decision will be made about the feasibility of implementing the next stages.
  • Websites that did not manage to migrate to the Client Hints API will be provided with a reverse Origin Trial, allowing them to revert to the previous behavior for at least six months.
  • The version number of Chrome in the User-Agent will be shortened to the form MINOR.BUILD.PATCH (for example, instead of 90.0.4430.93, it will be indicated as 90.0.0).
  • Version information will be reduced in the navigator.userAgent, navigator.appVersion, and navigator.platform APIs for desktop systems.
  • The transmission of mobile platform information will be reduced in Chrome for Android (currently, the Android version and device model codename are transmitted).
  • Support for reverse Origin Trial will be discontinued, and only the reduced User-Agent will be provided for all pages.

In conclusion, it is worth noting Google's initiative to implement an automation feature in the built-in password manager in Chrome that changes passwords if there are signs of compromise. Specifically, if during a check it is found that an account has been compromised due to a site password database leak, the user will be offered a button for quickly changing the password on the site.

For supported websites, the password change process will be automated — the browser will automatically fill in and submit the necessary forms. Each step of the password change will be shown to the user, who can intervene at any moment and switch to manual mode. To automate interaction with password change forms on different websites, the Duplex machine learning system is used, which is also applied in Google Assistant. This new feature will be gradually rolled out to users, starting with Chrome for Android in the USA.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster