Live data from Hacker News

Google’s nightmare “Web Integrity API” wants a DRM gatekeeper for the web

arstechnica.com

111–120 of 484 posts

Re: Google’s nightmare “Web Integrity API” wants a DRM gatekeeper for the web

#111
post #58

Earlier quoted context omitted.

Why is that?

> Google's plan is that, during a webpage transaction, the web server could require you to pass an "environment attestation" test before you get any data. At this point your browser would contact a "third-party" attestation server, and you would need to pass some kind of test. If you passed, you would get a signed "IntegrityToken" that verifies your environment is unmodified and points to the content you wanted unloc…

Why is that? Who is forcing the free web to use this mechanism, since it is the server that requests the confirmation. Why can't it just... not?

Re: Google’s nightmare “Web Integrity API” wants a DRM gatekeeper for the web

#112

They're going to prevent me from running an adblocker in this "web integrity" environment, aren't they.

Not until Mozilla gives in.

Even if they don't, a lot of websites are just breaking on Firefox. The development community decided they want a Chrome monoculture.

Re: Google’s nightmare “Web Integrity API” wants a DRM gatekeeper for the web

#113

Well, I think this move by google will divide the chromium project in 2 versions: one with and one without this "feature".

Yes, just like you can still use Android phones that don't pass SafetyNet. But good luck doing anything useful with them.

Re: Google’s nightmare “Web Integrity API” wants a DRM gatekeeper for the web

#114

The Chrome team have used "the Open Web" as a euphemism for what is to all intents and purposes Google's great ad supported walled garden. That so few people see this for what it is is amazing, and then they get all surprised when Google act to preserve it and close the capability gap with native platforms.

When Microsoft did this with IE, they did it with proprietary and undocumented APIs. The fact that this is an open spec, discussed in an open forum, using well established and standard technologies is what ensures it can never be positioned against users in any meaningful way.

To me it looks like SGX for the web. Maybe it will introduce some neat and weird capabilities, but at the end of the day, it will be trivial to bypass at scale if it ever positions itself as being harmful to users.

Re: Google’s nightmare “Web Integrity API” wants a DRM gatekeeper for the web

#117

I've been thinking about this for a few days but just realized that this is a complete end run around all web scraping in general. All 'adversarial compatibility' from projects like Nitter, Teddit, Invidious, and youtube-dl go out the window. Any archive site (archive.org, archive.ph, etc.) can be blocked by sites requiring attestation. And just like the book industry was terrified of piracy and were 'rescued' by Kin…

[deleted]

Re: Google’s nightmare “Web Integrity API” wants a DRM gatekeeper for the web

#118

They're going to prevent me from running an adblocker in this "web integrity" environment, aren't they.

That makes zero sense. If they ever did that they would lose all their market share overnight, and they know that. Google has always been good about letting people have full control over their devices, despite building incredibly locked down UX.

It would be trivial for them to build a Chromebook, or Android phone, or browser that you can't flip into dev mode, but they've never done that, even though many of their competitors in the space regularly lock users out of their devices.

Re: Google’s nightmare “Web Integrity API” wants a DRM gatekeeper for the web

#119

I've been thinking about this for a few days but just realized that this is a complete end run around all web scraping in general. All 'adversarial compatibility' from projects like Nitter, Teddit, Invidious, and youtube-dl go out the window. Any archive site (archive.org, archive.ph, etc.) can be blocked by sites requiring attestation. And just like the book industry was terrified of piracy and were 'rescued' by Kin…

Any archive site (archive.org, archive.ph, etc.) can be blocked by sites requiring attestation.

What will happen if such a thing actually happens is that the underground market for "trusted device" farms grows, not too different from what's currently already happening but possibly at a far larger scale. Of course, that means the financially motivated scraping services still keep going while the honest individuals wanting user-agent freedom get screwed, just like with many other forms of DRM...

Re: Google’s nightmare “Web Integrity API” wants a DRM gatekeeper for the web

#120
post #70
post #68

Earlier quoted context omitted.

But that's the catch, company breakups are extremely hard to perform especially when you're talking about such a giant company being tackled by an organization that only has ~400m in funding. Especially when they can point to the other giant companies as defense against claims of monopolist behavior. See Google using Microsoft, Apple, and Amazon as a reason for why their ad business should not be broken up in the Jan…

As hard as it may be, to paraphrase the ancient parable: The best time to break up Google was 10 years ago. The second-best time to break up Google is today.

You'll be very pleased to hear that it is going to happen soon with two antitrust cases against Google, one for search dominance [0] and the other for their ad business [1] with the former going to happen this year in September. So there is a start on that.

So get a front row seat and get ready for what is to come in September this year to witness the beginning of the end of a company once adored by hundreds of techies finally getting broken up to pieces.

[0] https://www.cnbc.com/2020/10/20/doj-antitrust-lawsuit-agains...

[1] https://www.cnbc.com/2023/01/24/doj-files-second-antitrust-l...

Post reply on HN