Live data from Hacker News

Google’s Plan to DRM the Web Goes Against Everything Google Once Stood For

techdirt.com

341–350 of 427 posts

Re: Google’s Plan to DRM the Web Goes Against Everything Google Once Stood For

#341
post #328

Earlier quoted context omitted.

I'm sorry, but the idea that it's about allowing me to attest to the security of my device is not correct. I can make all the attestations I like about the security of my device, but if they're not backed by a confirmation from Google then it's quite likely that nobody will care. The issue is that making modifications to anything in the chain of trust requires approval from a trusted third party.

>the idea that it's about allowing me to attest to the security of my device is not correct I was oversimplifying. A service doesn't have to trust every attestation and a service does not need to do anything with the attestation if it doesn't want to. >The issue is that making modifications to anything in the chain of trust requires approval from a trusted third party. That is by design because it means untrusted peo…

Yes, you are correct that preventing users from making modifications to anything in the chain of trust without being approved by an already-trusted third party, likely the company who certified the device, is by design.

Re: Google’s Plan to DRM the Web Goes Against Everything Google Once Stood For

#342

Earlier quoted context omitted.

Yep - weakening Big Tech in the US will strengthen China's Big Tech, which no one wants.

So we have to accept control through Google or Apple or otherwise we will be controlled by Alibaba or Huawei? I don't want my devices to be controlled by neither company.

One wants profits; another wants to influence you. Take your pick.

Re: Google’s Plan to DRM the Web Goes Against Everything Google Once Stood For

#343
post #25

Google might have pretended to stood for something, but they have been an evil corporation since they have been a corporation. That's what corporations do by design. One relevant example is that they've been doing the "only for ie5+" with their services for 10+ years now. They killed most of their browser competition not by having a good product, but by having or buying up good services that they used to force chrome…

Good/bad is too simple to explain these things. Corporations try to make money or build leverage. Of course some of them don’t execute or compete very well. In the early days it was doing good and building the leverage, now it is time for them to use that leverage to continue to milk the cash cow for as long as possible.

Re: Google’s Plan to DRM the Web Goes Against Everything Google Once Stood For

#344
post #328

Earlier quoted context omitted.

I'm sorry, but the idea that it's about allowing me to attest to the security of my device is not correct. I can make all the attestations I like about the security of my device, but if they're not backed by a confirmation from Google then it's quite likely that nobody will care. The issue is that making modifications to anything in the chain of trust requires approval from a trusted third party.

>the idea that it's about allowing me to attest to the security of my device is not correct I was oversimplifying. A service doesn't have to trust every attestation and a service does not need to do anything with the attestation if it doesn't want to. >The issue is that making modifications to anything in the chain of trust requires approval from a trusted third party. That is by design because it means untrusted peo…

The problem is that the owner of the device is considered "untrusted" here. While that sometimes makes sense (for law enforcement purposes), using this for business purposes is anticompetitive. It shouldn't be possible for companies to do whatever they want.

Re: Google’s Plan to DRM the Web Goes Against Everything Google Once Stood For

#345
post #191

google never stood for anything, do no evil was mostly marketing. 2010s https://nakedsecurity.sophos.com/2011/08/26/real-canadian-ph... "we don't collet private data" https://europe.googleblog.com/2010/04/data-collected-by-goog... "ops we do" https://googleblog.blogspot.com/2010/05/wifi-data-collection... google wage fixing, all the way back from 2001 https://www.cnet.com/tech/tech-industry/apple-google-seek-ap... be…

Storing data from open networks is like recording people who are yelling.

If I were to yell my name at the wind and you happened to be near and were to write it down, you'd still be in violation of privacy regulations.

Re: Google’s Plan to DRM the Web Goes Against Everything Google Once Stood For

#346

Earlier quoted context omitted.

> if you for example would trust let's say Opera as the attester, Opera would need to trust windows or Linux or Android as the OS attester. But it's not the user ("you") deciding which attesters to trust - it's website operators. And they will choose to trust only attesters that meaningfully (cryptographically) verify the user's client environment, including the secure boot chain, OS, and browser. Otherwise the attes…

> But it's not the user ("you") deciding which attesters to trust - it's website operators. You know what? They are already doing it. This just gives them another option. > And they will choose to trust only attesters that meaningfully (cryptographically) verify the user's client environment, including the secure boot chain, OS, and browser. Otherwise the attestation can be spoofed, in why case why would they bother…

Those methods didn't kill the open web because they could be bypassed, and that's precisely why WEI was proposed.

Re: Google’s Plan to DRM the Web Goes Against Everything Google Once Stood For

#347

Earlier quoted context omitted.

> it's clear that they are being careful and are upfront about the some potential misuses and the proposed handing of them. On the contrary, my main issue is that they identify one of the primary issues and fail to address it. The biggest issue is that web designers will design around WEI such that the web is unusable without it. For example, while the current use case might be “captcha without WEI, no captcha with W…

> The biggest issue is that web designers will design around WEI such that the web is unusable without it. For example, while the current use case might be “captcha without WEI, no captcha with WEI”, a future use case might be “captcha with WEI, 401 without WEI” You know they can do that right now, right? They aren't doing it. Will more do it because it is simpler now? Sure. Will it put "an end to the open web"? Nope…

How can they verify it now with hardware-based security? They can't, that's why WEI is proposed, to bridge device attestation API.

While trivial fingerprinting methods can be bypassed, TEE-based methods are pretty much impossible to bypass ($500K reward for that)

Re: Google’s Plan to DRM the Web Goes Against Everything Google Once Stood For

#348
post #115

Earlier quoted context omitted.

> what does Google have to do with how websites choose to treat their users or what solution they would propose Google owns YouTube. Is it so hard to imagine that some product manager at YouTube counted the losses due to adblockers and asked a team in Chrome to prevent them?

Youtube can and in some measure is already doing it without this new API. If google wanted to be sneaky they can provide whatever data they want to Youtube alone without making it a public standard. you see how all of these fears are contorted reasoning because you want to try to find something wrong with the proposal because all fo your fears do not require this proposals and would be easier and with much less backl…

How can they get hardware attestation right now? They can't, that's why WEI is proposed.

Re: Google’s Plan to DRM the Web Goes Against Everything Google Once Stood For

#349

I've been wary of Google for a while now, and this is further proof my wariness is justified. However, one thing I can't seem to kick is using Google search as a fallback. I use DuckDuckGo or Brave search for most of my searches, but half the time I have to add "!g" to the search to switch to Google to get actually useful results. Does anyone have any tips or tricks (or search engines I'm unfamiliar with) so I can br…

> Does anyone have any tips or tricks (or search engines I'm unfamiliar with) so I can break free?

https://seirdy.one/posts/2021/03/10/search-engines-with-own-...

Re: Google’s Plan to DRM the Web Goes Against Everything Google Once Stood For

#350
post #327
post #309

Earlier quoted context omitted.

Why? As a supplier of an API to search engine "customers" their entire job would just be to service that demand and provide new query options. The intra-engine competition, meanwhile, would drive up results quality. Search engines would rise and fall on their own merits rather than on the basis that theyve got access to the biggest index.

But part of the competition is the index quality. For example, it's a lot easier to provide a keyword index than a phrase index. There's code search which is almost orthogonal to what ordinary search wants separators wise etc

I dont doubt that. The point of regulating it as a utility isnt that theres nothing to compete over but that the barrier to entry is so high that you can't simply rely on the market to provide competition.
Post reply on HN