Live data from Hacker News

Google’s Plan to DRM the Web Goes Against Everything Google Once Stood For

techdirt.com

321–330 of 427 posts

Re: Google’s Plan to DRM the Web Goes Against Everything Google Once Stood For

#321
post #17

It's time to start lobbying hard for an antitrust breakup of Google. This DRM plan, as abuse of a monopoly position, provides more political coverage for a forced breakup. It's pretty clear how to break up Alphabet, because it grew mostly by acquisition. - Google - search, ads on search pages and nothing more. - DoubleClick - third party ads on other sites. - Analytics - services to web sites. - Cloud - the money-los…

No one pays for web browsers, I doubt Chrome would be a viable separate company.

Re: Google’s Plan to DRM the Web Goes Against Everything Google Once Stood For

#322
post #160
post #92

It seems Everyone is taking for granted the claim that this is about DRM. The claim is that websites (not Google) will use this signal to allow or deny access but this is already possible with various means. Google or any other Browser vendor do not have a say on how websites use or misuse features. > There is a tension between utility for anti-fraud use cases requiring deterministic verdicts and high coverage, and t…

The difference is that currently you can lie. You can identify the fingerprinting techniques being used, and work around them. yt-dlp already does something like this, for example. In Android, there was a lot of support for making your rooted / custom ROM system look like stock Android so you could still do banking. Now, depending on the level of Safetynet the app is using, you literally can't. I'm not arguing in fav…

>In summary, this is fundamentally different because it takes away your control of your own device.

No, it allows a business to deny to you if you can't attest to the security of your device. You are still free to do whatever you want on your own device.

If a business had an office that required you to unlock a door, but it also had a pickable lock that wouldn't be great security. It allows people to lie about having a badge by letting them pick the lock to get in. If a business increased security by making the lock no longer printable that seems like a good thing to me.

>LineageOS is a good example of this; they have their own Safetynet implementation which has very little buy-in.

Have they actually approached apps and offered compensation for them to implemented it? Or are they hoping apps just randomly decide to adopt it?

Re: Google’s Plan to DRM the Web Goes Against Everything Google Once Stood For

#323
post #225
post #121

Earlier quoted context omitted.

This is also how I remember it. "getfirefox.com" is burned into memory from ages ago, the first real competitor to IE. Everyone wanted to switch to it. Then chrome came along and people reluctantly switched at first, then enthusiastically. Firefox had the reputation of eating RAM like candy.

>Firefox had the reputation of eating RAM like candy. It wasn't unwarranted. They were dealing with a great deal of memory leak issues in the early Chrome vs FF era. The most important thing is that even when Chrome ended up taking more ram than FF for an equal amount of tab and equal websites loaded, closing tabs on Chrome was far more likely to let you free ram usage than on Firefox, and nobody likes to have to clo…

The other thing which was a problem were popular extensions which leaked memory. A lot of people went on this cycle where they’d install extensions until their browser was slow / unstable, switch to a different browser, say it was much faster, and then lard it up with extensions before repeating the process.

Re: Google’s Plan to DRM the Web Goes Against Everything Google Once Stood For

#324
post #160

Earlier quoted context omitted.

The difference is that currently you can lie. You can identify the fingerprinting techniques being used, and work around them. yt-dlp already does something like this, for example. In Android, there was a lot of support for making your rooted / custom ROM system look like stock Android so you could still do banking. Now, depending on the level of Safetynet the app is using, you literally can't. I'm not arguing in fav…

I mean, you can still lie, it's just made more difficult. Unless i'm missing something, running your OS under a hypervisor with a virtual TPM (or a forked browser with TPM access stubs and custom kernel drivers) still allows you to do whatever you want. It's certainly more difficult, and unreasonably so, but it's still quite possible. While i'm not familiar with Safteynet, i'm sure it's also possible to bypass it tha…

My understanding is that the vendor installs keys in the TPM which can't be retrieved. So no, a virtual TPM wouldn't work, because you don't have the vendor's keys. Or rather, you would be in the same situation as before, because you can install your own keys and then have the challenge of getting third parties to trust you.

Re: Google’s Plan to DRM the Web Goes Against Everything Google Once Stood For

#325
post #172

Earlier quoted context omitted.

"Chrome - browsers" And the money is coming from where? Chrome exists mostly, so the ad buisness gets more data and they can influence the direction of the web. Seperate that and there will be no more chrome as there is no other source of income. (Except maybe a little bit from ChromeOS). Otherwise I get it, it is mostly politics to threaten google to reach this.: "It's quite likely to make Google dump this proposal,…

Call me old skool, but how about charging for it?

When every other browser is free, that sounds like a death sentence

Re: Google’s Plan to DRM the Web Goes Against Everything Google Once Stood For

#326

one “side effect” of this would be enabling Google to effectively block ad-blocking. And, of course, plenty of people will insist that that’s not a side-effect, that’s the end goal.

How would this block ad-blocking?

Google could stop certifying configurations with an ad-blocker. Of course they are the ones that want to be established as infrastructure to certify your client being "genuine" or not.

Re: Google’s Plan to DRM the Web Goes Against Everything Google Once Stood For

#327
post #309
post #256

Earlier quoted context omitted.

I doubt this is feasible, there's a lot that goes into the index which determines which kinds of queries you can even run.

Why? As a supplier of an API to search engine "customers" their entire job would just be to service that demand and provide new query options. The intra-engine competition, meanwhile, would drive up results quality. Search engines would rise and fall on their own merits rather than on the basis that theyve got access to the biggest index.

But part of the competition is the index quality. For example, it's a lot easier to provide a keyword index than a phrase index. There's code search which is almost orthogonal to what ordinary search wants separators wise etc

Re: Google’s Plan to DRM the Web Goes Against Everything Google Once Stood For

#328
post #160

Earlier quoted context omitted.

The difference is that currently you can lie. You can identify the fingerprinting techniques being used, and work around them. yt-dlp already does something like this, for example. In Android, there was a lot of support for making your rooted / custom ROM system look like stock Android so you could still do banking. Now, depending on the level of Safetynet the app is using, you literally can't. I'm not arguing in fav…

>In summary, this is fundamentally different because it takes away your control of your own device. No, it allows a business to deny to you if you can't attest to the security of your device. You are still free to do whatever you want on your own device. If a business had an office that required you to unlock a door, but it also had a pickable lock that wouldn't be great security. It allows people to lie about having…

I'm sorry, but the idea that it's about allowing me to attest to the security of my device is not correct. I can make all the attestations I like about the security of my device, but if they're not backed by a confirmation from Google then it's quite likely that nobody will care.

The issue is that making modifications to anything in the chain of trust requires approval from a trusted third party.

Re: Google’s Plan to DRM the Web Goes Against Everything Google Once Stood For

#329
post #274

Earlier quoted context omitted.

How would Chrome make money? Right now they get a blank check from Google because dominance on the web is their business model. But if they're not supposed to sell out users interests to the ad-company, how are they supposed to earn any revenue? Sell Chrome licenses?

Just like how Firefox earns money, sell default search engine rights to highest bidder (google, bing) etc , Chrome itself can become billions of dollar business.

So in other words, sell user interests to the highest bidder.

Firefox is not comparable because it's not a stock company. They don't have the obligation to maximize profit for shareholders.

Re: Google’s Plan to DRM the Web Goes Against Everything Google Once Stood For

#330
post #185

Earlier quoted context omitted.

Nit: Google Cloud has been profitable this year: https://techcrunch.com/2023/04/25/google-cloud-turns-profit-... It's actually perfectly fine to lose money; you have to invest before you can start making a profit, and services like Google Cloud can be money printers once they're established. But all the cloud providers are competing hard, pumping money into 3rd parties / partners that will then sell it and set it up…

> It's actually perfectly fine to lose money; you have to invest before you can start making a profit, and services like Google Cloud can be money printers once they're established. It's not fine if you use a monopoly in one area to buy your way into another. That's one of the core tenets in antitrust (back when it was being enforced, at least).

Google Cloud is quite far from a monopoly...
Post reply on HN