Live data from Hacker News

So, you don't like a web platform proposal

blog.yoav.ws

101–110 of 114 posts

Re: So, you don't like a web platform proposal

#101
post #48

Earlier quoted context omitted.

> I am not a contributor to the repo, and stepped in as chair on the repo after writing this Nobody is missing this; you're defending this work. You can't both defend the work itself and place yourself outside of the process as a "chair." > If you're objecting to the goals of the proposal [1], it'd serve you better to outline which goals are objectionable and why Many technologists don't have the clout or sometimes t…

> Nobody is missing this; you're defending this work. You can't both defend the work itself and place yourself outside of the process as a "chair." I'm not defending the work. I'm defending the venue, to enable standard proposal work to happen in public (and get feedback from the community). > But it is DRM because it can be used, in effect, like DRM. You are missing the point that most of the community sees this as…

> I'm not defending the work. I'm defending the venue, to enable standard proposal work to happen in public (and get feedback from the community).

You mean the repo which is closed for new issues, on which Google has shut down commentary, past the weekend deadline it promised for re-opening commentary? This is the open work process under examination?

> OK, maybe I'm missing something then. Can you explain to me in what ways this is DRM?

I would be glad to take a crack at this, but smarter people have spent their whole lives advancing humankind's understanding on this topic. They should speak on it, not me. I have my own private suspicions about what they will say though.

Re: So, you don't like a web platform proposal

#102
I'm sorry for the Chrome devs to be on the receiving end of the shitstorm. I've met quite a few of them and I know they do care about the Web.

But I'm not sure if they realize, being on the inside of Google, just how much goodwill this company has lost on numerous botched UA sniffs, AMP, EME, manifest V3. We've had "we're listening, but we're doing it anyway" before.

Re: So, you don't like a web platform proposal

#103
post #48

Blog post author here. A few clarifications: * I am not a contributor to the repo, and stepped in as chair on the repo after writing this, to help the engineers contributing to it deal with clear spam & abuse cases. I wrote this post with WEI in mind, but nothing about it is specific to this proposal, and could've been applied to multiple past proposals (and probably future ones), either from Google or from other sta…

> I am not a contributor to the repo, and stepped in as chair on the repo after writing this Nobody is missing this; you're defending this work. You can't both defend the work itself and place yourself outside of the process as a "chair." > If you're objecting to the goals of the proposal [1], it'd serve you better to outline which goals are objectionable and why Many technologists don't have the clout or sometimes t…

Yeah, the author has to resort to tone-policing because they have no good rebuttals for the criticism being received so they are trying to invalidate and dismiss said criticism due to its 'tone'.

What a lazy rhetorical device.

Re: So, you don't like a web platform proposal

#104

Blog post author here. A few clarifications: * I am not a contributor to the repo, and stepped in as chair on the repo after writing this, to help the engineers contributing to it deal with clear spam & abuse cases. I wrote this post with WEI in mind, but nothing about it is specific to this proposal, and could've been applied to multiple past proposals (and probably future ones), either from Google or from other sta…

Your P.S. really shows that you are not really acting in good faith here. It might be good to take a step back and think about the reaction people are having. Consider the possibility that the problem might not be that the whole rest of the world is acting like toddlers , but rather that there is something fundamentally and objectively problematic with WEI and that the community is having a very strong negative react…

Writing "the whole rest of the world" shows you have lost perspective. Most of the world has never heard of this proposal. The people arguing against it don't represent them. (Nor do the people proposing it.)

Re: So, you don't like a web platform proposal

#105

Earlier quoted context omitted.

Even if the client is legit someone can just use a web extention or the devtool protocol to navigate to pages and extract text.

I think the point is that the server won't send the content if attestation fails So the data isn't there at all - it's not just hidden away behind some JavaScript

I'm saying that extentions and developer tools still exist in browsers that will be attested.

Re: So, you don't like a web platform proposal

#106
post #12

Earlier quoted context omitted.

Can't you sign your own certificates? Whether people trust those is a different story. WAI is different because it breaks abstraction by asserting based on details which are otherwise invisible to the server.

You can. It's just that no browser that supports HTTP/3 will accept it as a legit endpoint with a valid root. So they won't connect to the HTTP/3 endpoint at all and you won't be able to access the HTTP/3 self-signed website. And before anyone goes there, no, setting up your own root CA is not an option. Unless you get can Google/Apple/Mozilla/etc to include your root CA in their browser trust stores it doesn't help…

That's still self-signing. So the extra steps are immaterial to the point.

Re: So, you don't like a web platform proposal

#107

Earlier quoted context omitted.

> Nobody is missing this; you're defending this work. You can't both defend the work itself and place yourself outside of the process as a "chair." I'm not defending the work. I'm defending the venue, to enable standard proposal work to happen in public (and get feedback from the community). > But it is DRM because it can be used, in effect, like DRM. You are missing the point that most of the community sees this as…

> I'm not defending the work. I'm defending the venue, to enable standard proposal work to happen in public (and get feedback from the community). You mean the repo which is closed for new issues, on which Google has shut down commentary, past the weekend deadline it promised for re-opening commentary? This is the open work process under examination? > OK, maybe I'm missing something then. Can you explain to me in wh…

https://en.wikisource.org/wiki/The_Coming_War_on_General_Com...

Re: So, you don't like a web platform proposal

#108
post #52

Earlier quoted context omitted.

I don't believe in attacking individuals for what is a systemic issue. > It's important to actually read and understand the proposal before objecting to it. How do you assume that the people who criticize it didn't read it? I saw many arguments based on the proposal text. I myself read it thrice before making my first post. > For example, WEI has nothing to do with ad-blockers or DRM (in the sense that the content it…

> I don't believe in attacking individuals for what is a systemic issue. I appreciate that! > From what I can see, the webpage needs to return the token to the server before it decides to respond [1]. True that proposal doesn't say if the server should respond or not. But the mere possibility that the server can deny a response based on the token (or its absence) means that it will be used. How is this not DRM? And h…

The proposal creates a mechanism by which digital rights could be enforced, so it could be used as DRM.

Arguably, any ability to deny particular user agents is discrimination. Doing that in a cryptographically verifiable way is DRM or at least a primitive which can be used to build DRM.

> This could definitely be risky for the open web

Then it should not be done.

> At the same time, I perceive DRM as a way to control access and ability to copy copyrighted material. I couldn't find anything in this proposal that enabled any of that.

Whether the proposal specifically mentions copyrights or DRM is immaterial; I don't even know why you would make this point.

> In my book this is not a blocker for being able to discuss any of this

First of all, respectfully, "your book" is not relevant; you are acting in your capacity as a chair, are you not? Second of all, yes, if something is morally abhorrent, it is not even worth discussion. You are still not understanding why people are reacting this way. Please, again, I implore you to reconsider your interpretation of these responses; people are trying to tell you that this proposal is SO dangerous, and SO bad, that it should be deleted from existence and never discussed again.

Re: So, you don't like a web platform proposal

#109
post #48

Earlier quoted context omitted.

> I am not a contributor to the repo, and stepped in as chair on the repo after writing this Nobody is missing this; you're defending this work. You can't both defend the work itself and place yourself outside of the process as a "chair." > If you're objecting to the goals of the proposal [1], it'd serve you better to outline which goals are objectionable and why Many technologists don't have the clout or sometimes t…

> Nobody is missing this; you're defending this work. You can't both defend the work itself and place yourself outside of the process as a "chair." I'm not defending the work. I'm defending the venue, to enable standard proposal work to happen in public (and get feedback from the community). > But it is DRM because it can be used, in effect, like DRM. You are missing the point that most of the community sees this as…

Have you heard of the paradox of tolerance?

There is no reason to expect the community to be “tolerant” and “kind” to an intolerant proposal.

Get off your high horse of neutrality, because it’s not neutral. Proposals like this will be treated like a hostile attack because that is what they are. If you’re unable to see that then that problem is on you not _everyone else_.

This is extremely similar to the same arguments leftists give of _not giving a platform to fascists_. Giving that platform is legitimizing them.

This proposal is being seen as a technological fascist attack on the web, and you’re getting that signal. Except you’re categorizing that signal as noise.

Re: So, you don't like a web platform proposal

#110
post #12

Earlier quoted context omitted.

Can't you sign your own certificates? Whether people trust those is a different story. WAI is different because it breaks abstraction by asserting based on details which are otherwise invisible to the server.

You can. It's just that no browser that supports HTTP/3 will accept it as a legit endpoint with a valid root. So they won't connect to the HTTP/3 endpoint at all and you won't be able to access the HTTP/3 self-signed website. And before anyone goes there, no, setting up your own root CA is not an option. Unless you get can Google/Apple/Mozilla/etc to include your root CA in their browser trust stores it doesn't help…

>You can. It's just that no browser that supports HTTP/3 will accept it as a legit endpoint with a valid root. So they won't connect to the HTTP/3 endpoint at all and you won't be able to access the HTTP/3 self-signed website.

So long as there's a way to bypass verification or configure the trust store I'm okay with it. Is there official policy stating that this won't be possible or is this prediction?

As I understand it the primary reason for this push is that non-technical users too often skip security warnings, but I'm of the position there MUST at least be a way to bypass verification no matter what (through keyboard combos or a configurable trust store).

Post reply on HN