Live data from Hacker News

Google’s nightmare “Web Integrity API” wants a DRM gatekeeper for the web

arstechnica.com

41–50 of 484 posts

Re: Google’s nightmare “Web Integrity API” wants a DRM gatekeeper for the web

#41
post #23
post #6

Google seems to be escalating the speed of its efforts to restrict its user base to the completely non-technical, but Apple and Facebook already own that market. It also sounds like they're promoting yet another way to make "the internet" slower, more bloated, and have greater impediments to usage.

This proposal only impacts "the web", which has already been going downhill for years now due to unsustainable ad-reliant business models. The internet is fine.

That distinction made me feel better about the whole thing. Thank you.

Re: Google’s nightmare “Web Integrity API” wants a DRM gatekeeper for the web

#42

Well, I think this move by google will divide the chromium project in 2 versions: one with and one without this "feature".

That doesn't make any difference. There will be websites that will only allow people using approved browsers to access them. Instead of whatever you expect, you'll get a link to download Chrome (or whatever), and possibly install $COMPANY's attestation software.

Then, people will DDOS the attestation endpoints because why not.

Re: Google’s nightmare “Web Integrity API” wants a DRM gatekeeper for the web

#43

See also previous discussion on https://news.ycombinator.com/item?id=36817305 (the same link mentioned in the article) It's honestly good for this to get a lot of attention though, I'm happy to see additional commentary on it getting shared.

It's good that it's happening strong & still semi-early-ish. I'd be curious to know how or if Chrome actually manages the PR around their work. Chrome lead fired off a blog post So you don't like a web proposal which effectively says it's purely a technical decision, and that only constructive technical criticism is regarded at all. https://news.ycombinator.com/item?id=36818409 https://blog.yoav.ws/posts/web_platform…

More importantly, a company of the size, scope and sophistication of Google trying to hide its fundamental redefinition of how people access the web, behind “it’s only a technical change” is unacceptable.

As if something with multiple downstream non-technical effects, is only a technical change

As if you can minimize and dismiss everyone’s fears and concerns as hollow, invalid and irrelevant by waving the magic wand of tis only a wee technical change, to be sure, to be sure

As if everyone’s protests and arguments against can be instantly hosed down, because aye, you guessed it laddie, it’s only a technical change

It’s almost as if the folks at Google think people are so stupid that not only do people not know what they’re talking about, but they’ll actually believe the lie and fall for that deception…

It’s almost as if Google was trying to gaslight the public about this…

If they end up groveling about this, I don’t think “in retrospect, we could have communicated this better” is going to cut it. This is a company the size, scope and sophistication of Google. This is not their first rodeo. They know exactly what they’re doing, and they mean to do it…

Re: Google’s nightmare “Web Integrity API” wants a DRM gatekeeper for the web

#44
> Google's plan is that, during a webpage transaction, the web server could require you to pass an "environment attestation" test before you get any data. At this point your browser would contact a "third-party" attestation server, and you would need to pass some kind of test. If you passed, you would get a signed "IntegrityToken" that verifies your environment is unmodified and points to the content you wanted unlocked.

Would you rather a capitalist dystopia, where large corporations get to approve everything you see & hear, or a socialist dystopia, where the government gets to determine what you're allowed to view?

[Answer: Neither]

Re: Google’s nightmare “Web Integrity API” wants a DRM gatekeeper for the web

#45

They're going to prevent me from running an adblocker in this "web integrity" environment, aren't they.

Stopping anything that modifies a page on behalf of the user (rather than the creator or Google) will be step 0.

Re: Google’s nightmare “Web Integrity API” wants a DRM gatekeeper for the web

#47
> Google's plan is that, during a webpage transaction, the web server could require you to pass an "environment attestation" test before you get any data.

There is no value in this "attestation" for me as a user. I want to be able to do whatever I want with the browser (for example, remove ads or block access to canvas and webgl) and I want sites to be unable to know this. And probably this attestation will provide additional fingerprinting signals which is what I don't want.

Re: Google’s nightmare “Web Integrity API” wants a DRM gatekeeper for the web

#48
post #39

Well, I think this move by google will divide the chromium project in 2 versions: one with and one without this "feature".

Google will degrade their services for non-DRM browsers. They have a long history of "oops" with UA sniffs and serving slow buggy alternatives to Chrome-only JS. You'll be filling in captchas 10 times a day, getting randomly locked out of your Google account in the name of security, and whatever new feature they add to their services, they'll find an excuse to require the DRM for it.

Cloudflare will happily help Google with displaying captchas to everyone not using Chrome.

Re: Google’s nightmare “Web Integrity API” wants a DRM gatekeeper for the web

#49

They're going to prevent me from running an adblocker in this "web integrity" environment, aren't they.

Not until Mozilla gives in.

Where do you think Mozilla gets its funding from?

Re: Google’s nightmare “Web Integrity API” wants a DRM gatekeeper for the web

#50

They're going to prevent me from running an adblocker in this "web integrity" environment, aren't they.

Not until Mozilla gives in.

As I recall, Mozilla caved last time with EME so I would not count on it.
Post reply on HN