Live data from Hacker News

So, you don't like a web platform proposal

blog.yoav.ws

111–114 of 114 posts

Re: So, you don't like a web platform proposal

#111
post #40

Earlier quoted context omitted.

Can you provide an example of feedback that hasn't been ignored?

https://github.com/RupertBenWiser/Web-Environment-Integrity/...

1. This isn't external, it's internal

2. It's not feedback, it's a bug report on something being broken

You don't get a gold star for being like "See, they're listening!" when they allow people internally involved in the project the privilege of having their bug reports heard.

The proposal is de-facto bad. The goals it wants to achieve are bad. There is no "technical argument", just like there's no "technical argument" to being against a proposal that says you must share all your passwords with me. Stop the sealioning.

Re: So, you don't like a web platform proposal

#112
> It also doesn't mean that the proposal is "done" and the proposal authors won't appreciate constructive suggestions for improvement. Different proposals may be in different stages of their development, and early stage proposals are often extremely malleable.

It's important to note that this is, as of now, much less "malleable" due to it being implemented in Chromium[0]. Personally, it looks like it's just been implemented and then someone has thrown together a standard later.

The same person behind the specification has also published a testing suite[1] for the API, too. Pretty damning, if you ask me.

[0]: https://source.chromium.org/search?q=getEnvironmentIntegrity... [1]: https://rupertbenwiser.github.io/wei-wpt/

Re: So, you don't like a web platform proposal

#113

Earlier quoted context omitted.

> I don't believe in attacking individuals for what is a systemic issue. I appreciate that! > From what I can see, the webpage needs to return the token to the server before it decides to respond [1]. True that proposal doesn't say if the server should respond or not. But the mere possibility that the server can deny a response based on the token (or its absence) means that it will be used. How is this not DRM? And h…

The proposal creates a mechanism by which digital rights could be enforced, so it could be used as DRM. Arguably, any ability to deny particular user agents is discrimination. Doing that in a cryptographically verifiable way is DRM or at least a primitive which can be used to build DRM. > This could definitely be risky for the open web Then it should not be done. > At the same time, I perceive DRM as a way to control…

If we delete it for existence it'll just come up again; the benefits for web developers are extremely compelling.

Re: So, you don't like a web platform proposal

#114
post #54

Blog post author here. A few clarifications: * I am not a contributor to the repo, and stepped in as chair on the repo after writing this, to help the engineers contributing to it deal with clear spam & abuse cases. I wrote this post with WEI in mind, but nothing about it is specific to this proposal, and could've been applied to multiple past proposals (and probably future ones), either from Google or from other sta…

Pretty deceptive to present yourself eager to discuss when you aggressively locked and closed issues where people present legitimate and well thought out concerns. If you don’t want to take responsibility for the proposal, withdraw your name from it. > Political/ecosystem arguments are technical arguments. No they are not. You don’t get to retcon a term just because people spotted a flaw in your argument. Edit: I not…

Software serves people. Underneath the question of what the technology does is always the question of what benefits who and why.

Is it technically correct for Hacker News to require login to upvote a story or comment? Mu; it's technically correct because it supports the ability to tie actions to actors, and that's correct because commenter history matters for the kind of forum Hacker News strives to be. Technical decisions are inextricable from what serves people.

And in that vein, the WEI team has been squelching comment channels because they've become low-value noise channels and dogpile opportunities. This isn't a design that the team in charge of it is choosing to do or not do by the number of angry GitHub posts they get, so that channel is now noise because they don't have someone to perch on the channel and filter novel information from me-too "Don't do" repeats.

Post reply on HN