Live data from Hacker News

Virtual Machine Detection in the Browser (2019)

bannedit.github.io

41–50 of 98 posts

Re: Virtual Machine Detection in the Browser (2019)

#41
post #34

Earlier quoted context omitted.

I may not have the right to have access to most of these websites but I do have the right to complain about how unethical I find it. And of course this situation has different implications if the website offers some sort of an essential service, but that's an entirely different discussion.

Is unethical the right word? Unpleasant might fit better. It doesn't break ethical rules to ensure ads are shown so income can be generated to pay for hosting.

There are many ways to pay for hosting. Ads are just one way. Since they have proven so lucrative for some well positioned businesses, those businesses have pushed the meme that the only choices are ads or paid subscription. There are other ways. I’ve run sites where I happily paid the hosting bill because I correctly suspected it would lead to me getting the job I wanted down the road. You could say that sounds like advertising, but it was not run as a business, much less an advertising business. There was no self promotion whatsoever other than bragging rights.

Many people have agendas, including sometimes very positive agendas, that lead them to support online services of various types in order to further those agendas.

None of this is to say there’s no place for advertising or for paid subscriptions. I’m just saying there are often more options.

Re: Virtual Machine Detection in the Browser (2019)

#42
post #21

Earlier quoted context omitted.

A video game installation is a conscious choice that I can make depending on whether I trust the vendor or not. Me visiting New York Times and getting 58 trackers scraping my device configuration and preferences is not a choice.

It is as much a choice as installing an .exe. Treat the web browser like the OS of old, because that's exactly what browser makers think of it.

And how do i get back to a hypertext reader?

Re: Virtual Machine Detection in the Browser (2019)

#43

Earlier quoted context omitted.

And most importantly, it should be checked by default IMO

...no, that's where I don't agree. Again, software should attempt to be truthful by default. There's a reason we allow programs to detect the hardware they're running on—it allows for all sorts of optimizations. Does the VM claim it's network driver was manufactured by Broadcom, or does it go with Cambridge Silicon Radio? Or does it decline to provide a vendor, and if it does, how long until software starts assuming…

It could report the host's hardware.

Re: Virtual Machine Detection in the Browser (2019)

#44

Earlier quoted context omitted.

Well, presumably there may be valid use cases for WebGL applications or games behaving differently according to specific vendors/drivers. It feels like something that needs to be asked permission for, however, so it can’t be used for nefarious purposes.

The web APIs seem to be filled with features that in theory could be useful but you would have to do some serious hunting to find a legitimate user while you are flooded with examples of evil uses. Firefox removed the battery API for this. In theory you could do something like show a stripped down site for low power users or something but it was only ever used for tracking. While browsers have been used for a lot now…

The problem with limiting browser features is that it makes web apps less competitive with apps on propertiary platforms. I agree not all websites should have access to battery API, but the user should decide on that, not a browser vendor. The same goes for all other limitations imposed.

Re: Virtual Machine Detection in the Browser (2019)

#45
I understand the technical challenge here, but pay a thought to students who are subjected to online proctoring software that takes a huge amount of onerous control over a student's computer [1]. This kind of software means that students running a vm to mask their computer from heavy-handed software may make it harder for a person to remain in control of their own system. I don't think this knowledge is bad to share, but a person using a virtual machine should never be penalised their degree.

1.https://www.proctoru.com/

Re: Virtual Machine Detection in the Browser (2019)

#46
post #21

Earlier quoted context omitted.

A video game installation is a conscious choice that I can make depending on whether I trust the vendor or not. Me visiting New York Times and getting 58 trackers scraping my device configuration and preferences is not a choice.

It is as much a choice as installing an .exe. Treat the web browser like the OS of old, because that's exactly what browser makers think of it.

It is not. I can open someone’s blog without knowing what trackers they have. A site has inherently a different trust boundary than an executable, and it should stay that way.

Re: Virtual Machine Detection in the Browser (2019)

#47
post #39

Earlier quoted context omitted.

True in theory but good luck explaining this to my grandma/99% of internet users. People click links freely even if they shouldn’t,

Twenty years ago they ran .exes just as freely.

And? Why should we still be adapting the security and privacy model we had 20 years ago?

To your analogy, 20 years ago this bit us all in the ass just as much because every EXE brought with it all sorts of toolbars and adware. I don’t want the web to become this.

Re: Virtual Machine Detection in the Browser (2019)

#48

Earlier quoted context omitted.

And most importantly, it should be checked by default IMO

...no, that's where I don't agree. Again, software should attempt to be truthful by default. There's a reason we allow programs to detect the hardware they're running on—it allows for all sorts of optimizations. Does the VM claim it's network driver was manufactured by Broadcom, or does it go with Cambridge Silicon Radio? Or does it decline to provide a vendor, and if it does, how long until software starts assuming…

Does the VM claim it's network driver was manufactured by Broadcom, or does it go with Cambridge Silicon Radio?

It would simply be whatever the virtual NIC is. Intel ones seem to be pretty common, likely due to wide availability of drivers and documentation.

Re: Virtual Machine Detection in the Browser (2019)

#49
post #34

Earlier quoted context omitted.

I may not have the right to have access to most of these websites but I do have the right to complain about how unethical I find it. And of course this situation has different implications if the website offers some sort of an essential service, but that's an entirely different discussion.

Is unethical the right word? Unpleasant might fit better. It doesn't break ethical rules to ensure ads are shown so income can be generated to pay for hosting.

Ads, fine. Participating into a pervasive tracking infrastructure that strips you bare of your privacy to optimize manipulation of your individual cognitive faults is entirely another thing.

Re: Virtual Machine Detection in the Browser (2019)

#50

Earlier quoted context omitted.

What websites ask for that?

I know Twitter does this. Also saw someone mention Facebook asked for the same when they tried to delete their account. It's a mad mad world out there.

That might be consequence if GDPR: they need legal proof of the legitimacy of the request and of its thorough execution.

Just as you can’t really “unsee”, you can’t fully delete data once you’re exposed to it. Something documenting its previous existence will always remain

Post reply on HN