Live data from Hacker News

So, you don't like a web platform proposal

blog.yoav.ws

21–30 of 114 posts

Re: So, you don't like a web platform proposal

#21
post #3

While I fully understand the feeling of the author being a Googler doing their job, being a cog in the machine and launching something to advance their promo case, would be visibly upset that people who actually care about the outcome are actively fighting their project, I also think from the users' perspective, dealing with a powerful corporation, it is the right thing to do to bury this type of danger as soon as po…

>The piece where the author suggests focusing on "technical arguments" when the issue at hand is fundamentally political is frankly laughable It is essentially just asking for constructive feedback. When people just say not to do it, insult the author, or make assumptions about the proposal that aren't true the comments are not actionable. Even if an issue is political you can still make a constructive argument on th…

It’s asking for feedback the author knows how to deal with (and disregard).

You know, if your government body of choice came up with a terrible idea in a draft bill and enraged the population, it would not be appropriate for them to go on TV and say “the population should offer constructive criticism in the form of legal arguments”. So what the fuck is this guy saying exactly, that you feel is a valid approach to handling public outcry?

Re: So, you don't like a web platform proposal

#22
post #12
post #7

Earlier quoted context omitted.

Google has already achieved this goal with their QUIC based HTTP/3. No implementation or use of HTTP/3 lib in any browser can connect to a webserver unless it gets the continued approval of a third party incorporated CA for TLS certs. With a 90 day renewal period that's basically just attestation of content every 90 days. If your site becomes illegal in an area (say, abortion information) then your CA TLS host can be…

Can't you sign your own certificates? Whether people trust those is a different story. WAI is different because it breaks abstraction by asserting based on details which are otherwise invisible to the server.

> Can't you sign your own certificates?

Self-signed certificates are banned in HTTP/2 onwards, which is really irritating when it is used for internal server-to-server communications.

You have to set up a Root CA certificate and use that to sign a second certificate. It's the same thing but with extra steps.

Re: So, you don't like a web platform proposal

#23
post #5

>That's great!! Getting involved in web platform discussions is essential to ensure it's built for and by everyone. Yes, because Google is known for listening to public and talking to non-organisations without posting conversation killers like "the decision has been made and we're going forward with it. Thanks for your valuable feedback."

Yes, organizations love the mealy mouthed, weak feedback on their Github issue tracker because that's easy to ignore. Just say the issue is spammy, or hostile, then close it without addressing any of the issues. What's harder to ignore (though still not impossible) is top articles on Reddit, HN, and even mainstream tech news sites, and a constant coverage on YouTube, podcasts, etc.

[dead]

Re: So, you don't like a web platform proposal

#24
This article's advice makes more sense to me if I take it as tips for diplomacy as a representative in a high-stakes industry standards forum, where you can't necessarily call it out when someone is trying to pull a fast one.

However, when reporting back to your company, you can and must privately call out Machiavellian plots, sabotage, sloppiness, bad technical directions, business conflicts, arrogance, etc., to the people who need to know that's going on.

If you're not representing a company, but rather, the public interest, then I guess what role you take might depend partly on the overall ethical temperature of the forum, and what influence you can have. Can you do more good by trying to join the cabal circles, with all the necessary diplomacy? Or can you do more good by speaking candidly in public?

Re: So, you don't like a web platform proposal

#25
post #15

Since this is here and there is a point made about discussing the technical merits of [0]... can someone explain to me how the WEI stuff isn't easily "faked" by scrapers and the like? I could see this being used in a similar way to user agents (sometimes helpful when working on bugs and fixing them on minor platforms!), but I'm really struggling to see the overall value-add here. I get the politics aspect of it (I th…

I believe the idea is that an independent third party will cryptographically sign something to attest that the client is legit.

So you can't fake that unless you have the third party's private key.

If course the question is then, how does the attestation third party ensure you are sending it real information? I've not bothered to read the proposal because I don't care, but I suspect it will require client-side plugins/libraries etc snooping on what is going on kinda like an antivirus thing snoops on things going on.

Re: So, you don't like a web platform proposal

#26
I feel like I have to repeat this, since so much is at stake here, where it is about the preservation of the web as we know it today, at the peril of having it turned into yet another walled garden:

The only way around the dystopia this will lead to is to constantly and relentlessly shame and even harass all those involved in helping create it. The scolding in the issue tracker of that wretched "project" shall flow like a river, until the spirit of those pursuing it breaks, and the effort is disbanded.

And once the corporate hydra has regrown its head, repeat. Hopefully, enough practise makes those fighting the dystopia effective enough to one day topple over sponsoring and enabling organisations as a whole, instead of only their little initiatives leading down that path.

Not a pretty thing, but necessary.

Re: So, you don't like a web platform proposal

#27
The section, "Don't assume a hidden agenda", is a rather irrelevant response to the outrage, because the agenda we don't like is written out in the proposal. It's not hidden, it's rather transparent and it's the dystopian nightmare we want to avoid.

From the proposal:

> Users often depend on websites trusting the client environment they run in. This trust may assume that the client environment is honest about certain aspects of itself, keeps user data and intellectual property secure, and is transparent about whether or not a human is using it. This trust is the backbone of the open internet, critical for the safety of user data and for the sustainability of the website’s business.

> Some examples of scenarios where users depend on client trust include:

> Users like visiting websites that are expensive to create and maintain, but they often want or need to do it without paying directly. These websites fund themselves with ads, but the advertisers can only afford to pay for humans to see the ads, rather than robots. This creates a need for human users to prove to websites that they're human, sometimes through tasks like challenges or logins.

> Users want to know they are interacting with real people on social websites but bad actors often want to promote posts with fake engagement (for example, to promote products, or make a news story seem more important). Websites can only show users what content is popular with real people if websites are able to know the difference between a trusted and untrusted environment.

> Users playing a game on a website want to know whether other players are using software that enforces the game's rules.

> Users sometimes get tricked into installing malicious software that imitates software like their banking apps, to steal from those users. The bank's internet interface could protect those users if it could establish that the requests it's getting actually come from the bank's or other trustworthy software.

Re: So, you don't like a web platform proposal

#29

Earlier quoted context omitted.

>The piece where the author suggests focusing on "technical arguments" when the issue at hand is fundamentally political is frankly laughable It is essentially just asking for constructive feedback. When people just say not to do it, insult the author, or make assumptions about the proposal that aren't true the comments are not actionable. Even if an issue is political you can still make a constructive argument on th…

It’s asking for feedback the author knows how to deal with (and disregard). You know, if your government body of choice came up with a terrible idea in a draft bill and enraged the population, it would not be appropriate for them to go on TV and say “the population should offer constructive criticism in the form of legal arguments”. So what the fuck is this guy saying exactly, that you feel is a valid approach to han…

>It’s asking for feedback the author knows how to deal with (and disregard).

Yes, and you can see how many people are being ignored. The article is a guide on how you can avoid being ignored and actually contribute to the process of standardization.

>So what the fuck is this guy saying exactly, that you feel is a valid approach to handling public outcry?

For example, people may think coming up with legal arguments may be an effective way to engage in the proposal and try to shut it down. The article describes that legal arguments will not be productive.

Re: So, you don't like a web platform proposal

#30
post #15

Since this is here and there is a point made about discussing the technical merits of [0]... can someone explain to me how the WEI stuff isn't easily "faked" by scrapers and the like? I could see this being used in a similar way to user agents (sometimes helpful when working on bugs and fixing them on minor platforms!), but I'm really struggling to see the overall value-add here. I get the politics aspect of it (I th…

I believe the idea is that an independent third party will cryptographically sign something to attest that the client is legit. So you can't fake that unless you have the third party's private key. If course the question is then, how does the attestation third party ensure you are sending it real information? I've not bothered to read the proposal because I don't care, but I suspect it will require client-side plugin…

Even if the client is legit someone can just use a web extention or the devtool protocol to navigate to pages and extract text.
Post reply on HN