Live data from Hacker News

Google’s nightmare “Web Integrity API” wants a DRM gatekeeper for the web

arstechnica.com

51–60 of 484 posts

Re: Google’s nightmare “Web Integrity API” wants a DRM gatekeeper for the web

#53
post #21

Earlier quoted context omitted.

> Those few who care will turn to more esoteric, incomplete, user-unfriendly but open systems. A lot of that has been happening for a long time now.

Care to share some examples?

Just talking about subcultures/communities that I've been a part of. Several of them only have a minimal presence on the public web, having moved to a network of private sites. A couple of them have assembled what amounts to a "shadow internet" that uses the internet for an encrypted communications channel but provides its own mailservers, IM servers etc. that don't interact with the internet proper.

And, locally, there have been two ISPs set up (one by me and my friends) that aren't meant for public use, but to supply service to smaller groups. The one I set up was to supply internet service to a remote neighborhood that isn't likely to get reasonable commercial internet in the near or medium future.

Those two ISPs supply internet access, but they also operate an intranet that is mostly decoupled from the public internet.

All baby steps, and nobody is 100% "off the grid", so to speak, but it's a trend that started long ago and seems to be gaining a bit of momentum.

My prediction is that the web will ultimately be just for commercial use (it's already 90% there), and there will be a whole bunch of tiny networks -- that may or may not portal to the internet -- that will fill the needs that the internet is increasingly unable to fill.

Re: Google’s nightmare “Web Integrity API” wants a DRM gatekeeper for the web

#54
One thing from the blink-dev discussion caught my eye:

> Anything we might decide would ultimately be influenced by the larger societal debate around privacy (regulations etc.) since perfect privacy means perfect immunity for criminals.

Ensuring that your devices don't spy on you on behalf of a government or company does not imply "perfect immunity for criminals".

Putting aside attestation for the moment, consider this: Modern enclave driven device encryption (and the self-destructive passcode limitations that often accompany it), for example, could be likened to designing a very good safe that can automatically destroy its contents if it is breached. Do we require governments to have their own keys to all such safes sold?

Re: Google’s nightmare “Web Integrity API” wants a DRM gatekeeper for the web

#55

Earlier quoted context omitted.

One day Google may well flag your sure as lower security, refuse to let you show ads, or disappear you from search results.

You already get flagged as hazardous and uncool for not using https, even on a perfectly-static site. Some of us called that out as a slippery slope leading to ubiquitous gatekeeping, but we were shouted down in the name of (as usual) "security."

That is because without https, there is no guarantee that the site requested is bring delivered as the site intends. For example, an ISP could insert data or scripts into the page.

Re: Google’s nightmare “Web Integrity API” wants a DRM gatekeeper for the web

#56

They're going to prevent me from running an adblocker in this "web integrity" environment, aren't they.

Not until Mozilla gives in.

no web attestation for them then

youtube, prime video, netflix, banking, github

none of that for firefox users

Re: Google’s nightmare “Web Integrity API” wants a DRM gatekeeper for the web

#57
post #6

Google seems to be escalating the speed of its efforts to restrict its user base to the completely non-technical, but Apple and Facebook already own that market. It also sounds like they're promoting yet another way to make "the internet" slower, more bloated, and have greater impediments to usage.

I have never understood why Google has remained the esteemed vendor for a subset of technical users.

They lost me more than a decade ago when they hoovered clear text passwords from their wifi scanning and blamed it on a single engineer.

Re: Google’s nightmare “Web Integrity API” wants a DRM gatekeeper for the web

#58
post #3

This sounds like the final death blow to the web as a useful platform for anyone who isn't a corporation.

Why is that?

> Google's plan is that, during a webpage transaction, the web server could require you to pass an "environment attestation" test before you get any data. At this point your browser would contact a "third-party" attestation server, and you would need to pass some kind of test. If you passed, you would get a signed "IntegrityToken" that verifies your environment is unmodified and points to the content you wanted unlocked.

Because of this. If we're at the point where you need to get permisssion and approval to verify that the platform you're using is acceptable, then the gates are up and the free web is no longer free at all.

Re: Google’s nightmare “Web Integrity API” wants a DRM gatekeeper for the web

#59
Remember they already added DRM to browsers once. There was a big outcry at the time, and they still went ahead and implemented it. Now even Firefox supports Widevine.

If they believe that it's in their best interest, I'm not really sure what we can do against this...

Re: Google’s nightmare “Web Integrity API” wants a DRM gatekeeper for the web

#60
> Exactly how the rest of the world feels about this is not necessarily relevant, though. Google owns the world's most popular web browser, the world's largest advertising network, the world's biggest search engine, the world's most popular operating system, and some of the world's most popular websites. So really, Google can do whatever it wants.

On one hand, I think this is wrong, because the world is full of tech companies who thought they could do whatever they want because they're big enough. "Nobody would dare switch away from Facebook! Err, I mean Twitter. No wait, I meant Chrome!" But that's a bet, not a fact. Sometimes it works out, and sometimes everyone leaves and goes somewhere else. You think you have a moat, and you do, it's just you don't always realize it's ankle deep.

On the other hand, Google can do what it wants with Chrome, because it's their product. I use Firefox, and it won't affect me. All the people who don't care about this are free to use Chrome. Likewise, anyone who wants to listen to a man in his forties tell them about why some browsers are better than others can ask me about my thoughts. Nobody has done that yet, but the offer is on the table.

Post reply on HN