Live data from Hacker News

Google’s Plan to DRM the Web Goes Against Everything Google Once Stood For

techdirt.com

381–390 of 427 posts

Re: Google’s Plan to DRM the Web Goes Against Everything Google Once Stood For

#381
post #346

Earlier quoted context omitted.

Those methods didn't kill the open web because they could be bypassed, and that's precisely why WEI was proposed.

Really?? Mind telling me how to access Netflix, Disney+, or any other streaming service without authentication/authorization? I'll take the information on banks too.

Where did I say you could access these without authentication? Nowhere.

But I can still access them with my device being controlled by me, I can create bots/extensions to export and archive content. I can because there's no reliable method to identify whether my device acts in my interest, so they have no choice - they have to restort to methods that can be cracked. WEI is an attempt to introduce that reliable method.

Sure, there's EME with Widevine L1, but this is currently limited to providing media content, not apps themselves. That's why WEI is considered the DRM for the web.

Re: Google’s Plan to DRM the Web Goes Against Everything Google Once Stood For

#382
post #344

Earlier quoted context omitted.

The problem is that the owner of the device is considered "untrusted" here. While that sometimes makes sense (for law enforcement purposes), using this for business purposes is anticompetitive. It shouldn't be possible for companies to do whatever they want.

>using this for business purposes is anticompetitive Businesses not trusting every random person is not anticompetitive. Doing that is how businesses make bad deals, get hacked, or make bad decisions.

Of course it is anticompetitive, if a given service (which is defacto mandatory) strikes a deal with select few hardware vendors to artificially make it impossible to access the service using different hardware (for purely business reasons), then it obviously is anticompetitive.

Re: Google’s Plan to DRM the Web Goes Against Everything Google Once Stood For

#383

Earlier quoted context omitted.

Websites could choose to deny access to clients that attest to having adblocking addons installed.

Point me to anything which would give websites access to that information via WEI. There is nothing. I have seen nothing except FUD. Aside from that, this only attests for the device. Ad-blockers can be external. This does nothing for external ad-blockers. Explicit non-goals for WEI: "Enforce or interfere with browser functionality, including plugins and extensions." https://github.com/RupertBenWiser/Web-Environment-…

I guess I'm not seeing any technical barriers there to an attester providing a service that only attests to browsers that don't have adblockers installed.

Re: Google’s Plan to DRM the Web Goes Against Everything Google Once Stood For

#384
post #153

Earlier quoted context omitted.

> How about you offer a reasonable opposing viewpoint Read the proposal: https://github.com/RupertBenWiser/Web-Environment-Integrity/... >That's settled then. Full filesystem, location, camera, and microphone access should therefore come on by default without a permission dialog. Why not bring back Java and Flash while we're at it! It's not the browser vendor's fault that websites are misusing it. Now who is arguing…

"anyone can become an "attester"" - and no site has to respect that. Read between the lines - using TLS as example: I can attest that my site is my by being self-certified but no browser will accept that - as my certificate is not "attested" by browser or OS. The WEI attester is exactly same - if site decides that it trust only Google, Apple and Microsoft - you do not have any way to access the site if you don't have…

By Anyone I didn't mean end-users. The TLS analogy stands. No browser has made the decision to trust only one authority. A motivated and funded organisation can become an Authority (like Let's Encrypt did) and the same can happen in the WEI case too. Ofcourse noone can trust self-certification. At the "trust-me-bro" game bots are more convincing than real users.

Re: Google’s Plan to DRM the Web Goes Against Everything Google Once Stood For

#385
post #61

Earlier quoted context omitted.

That’s not how I remembered it. Chrome really was a good browser and I would argue is still a good browser (for now). IE got displaced by Firefox’s predecessors because MS got caught napping - they disbanded the IE team thinking they have won. Firefox simply got outcompeted by Chrome as Google went crazy making it faster and faster. Firefox fell behind often enough that Chrome managed to take almost all of its market…

> Firefox simply got outcompeted by Chrome as Google went crazy making it faster and faster. I disagree - if that was the case then people would be switching back to Firefox now. Firefox got outcompeted by chrome by Google adding a "works better in chrome" button to their home pages.

>if that was the case then people would be switching back to Firefox now

It's like sayinig people would be switching off of Facebook or Twitter. It's really hard to disengage the general audience.

With that said, I did in fact switch to Firefox in 2023. I still unfortunately need google translate on mobile, but once Firefox can get those add on features out of beta it will be a pretty seemless transition.

Re: Google’s Plan to DRM the Web Goes Against Everything Google Once Stood For

#386

Earlier quoted context omitted.

This is such a naive and for lack of a better word stupid take > YouTube - streaming content. Probably gets sold to Netflix or AT&T or Comcast. Make Netflix more powerful? In what world is that good for competition

>> YouTube - streaming content. Probably gets sold to Netflix or AT&T or Comcast. >This is such a naive and for lack of a better word stupid take What is the not naive, not stupid, clearly-more-beneficial-than-what-we-have action that should be taken with youtube?

I don't understand the downvotes. You asked a legitimate question. How do we fix this anticompetitive monopolistic behavior?

Re: Google’s Plan to DRM the Web Goes Against Everything Google Once Stood For

#387
post #168

Earlier quoted context omitted.

The problem I see with this idea is that MS doesn't really have much leverage to push Edge on people any more. People aren't just using Windows PCs for their web browsing these days; lots of people are using mobile devices, and many don't even have PCs any more. Google and Apple control the mobile device market (roughly half and half, though it depends on which country you're in too). If a bunch of websites suddenly…

I sometimes have to use Microsoft Teams at work. Microsoft Teams requires Microsoft Edge to run. I was forced to install Microsoft Edge on my Ubuntu machine. Microsoft is pushing its Microsoft Edge product even on GNU/Linux. There are indeed the end times. I just saw cats lie down with dogs.

>I sometimes have to use Microsoft Teams at work. Microsoft Teams requires Microsoft Edge to run.

Plainly wrong. I use MS Teams at work too. My machine is running Debian. No, I sure as hell don't have Edge installed on Debian; I use it in Chrome.

Re: Google’s Plan to DRM the Web Goes Against Everything Google Once Stood For

#388
post #382

Earlier quoted context omitted.

>using this for business purposes is anticompetitive Businesses not trusting every random person is not anticompetitive. Doing that is how businesses make bad deals, get hacked, or make bad decisions.

Of course it is anticompetitive, if a given service (which is defacto mandatory) strikes a deal with select few hardware vendors to artificially make it impossible to access the service using different hardware (for purely business reasons), then it obviously is anticompetitive.

>strikes a deal with select few hardware vendors

That isn't what is happening. Anyone can become a manufacturer for Windows PCs or Android certified phones.

Re: Google’s Plan to DRM the Web Goes Against Everything Google Once Stood For

#389
post #384

Earlier quoted context omitted.

"anyone can become an "attester"" - and no site has to respect that. Read between the lines - using TLS as example: I can attest that my site is my by being self-certified but no browser will accept that - as my certificate is not "attested" by browser or OS. The WEI attester is exactly same - if site decides that it trust only Google, Apple and Microsoft - you do not have any way to access the site if you don't have…

By Anyone I didn't mean end-users. The TLS analogy stands. No browser has made the decision to trust only one authority. A motivated and funded organisation can become an Authority (like Let's Encrypt did) and the same can happen in the WEI case too. Ofcourse noone can trust self-certification. At the "trust-me-bro" game bots are more convincing than real users.

> By Anyone I didn't mean end-users.

then it isn't anyone.

>and the same can happen in the WEI case too

It is impossible to happen in this case.

If client has to be certified, then as product OS must be certified out-of-the-box for non-technical user. This will make sure 97% of market is covered by Apple, Microsoft and Google - these are "Authorities" web will have - even if the remaining few percent would be unified - it still will lead to most often then not "not being included" as trustworthy from server side.

>The TLS analogy stands.

no it does not. TLS cares about connection not OS stack. Also power dynamic flows in opposite direction.

>Ofcourse noone can trust self-certification.

If you want you can - because You (user) can import any certificate. The problem for me is that:

[Free/Open] Source/Linux in their entirety can be attested only if self-certification is possible. AND Self-certification means that WEI doesn't work. AND Any proposal that excludes any OS (or Linux distribution) from web is unacceptable.

Do you see logical outcome which this reasoning leads me to?

>No browser has made the decision to trust only one authority.

But it is not the browser here who has the final power "to trust", it is the server. And companies will only care about Windows, Mac(Safari), Android and Chrome.

>A motivated and funded organisation can become an Authority (like Let's Encrypt did)

Let's Encrypt could do that because TLS works in reverse direction and it is website that must be certified not the user.

> At the "trust-me-bro" game bots are more convincing than real users.

Yes exactly which is again everyone's point - for 10001 times and again "You cannot trust the client" - it is impossible to create privacy/[freedom of use for browsers and OS]-focused 'secure' and perfect attestation about client.

One has to give - 'security'/perfection or privacy/[freedom of use for browsers and OS].

We calculated what this proposal brings and rejected it on basis that bad is bigger than potential 'good' it can bring.

And again to put it clear - you need bots: search crawlers, web archive bots, URL scanners.

So put it clear - it is clearly from my perspective a wrong proposal.

P.S. This another thing worth considering if you think WEI will create real security: https://news.ycombinator.com/item?id=36985317

Re: Google’s Plan to DRM the Web Goes Against Everything Google Once Stood For

#390

Earlier quoted context omitted.

Websites could choose to deny access to clients that attest to having adblocking addons installed.

Point me to anything which would give websites access to that information via WEI. There is nothing. I have seen nothing except FUD. Aside from that, this only attests for the device. Ad-blockers can be external. This does nothing for external ad-blockers. Explicit non-goals for WEI: "Enforce or interfere with browser functionality, including plugins and extensions." https://github.com/RupertBenWiser/Web-Environment-…

This will be hard as:

The attester verdict is an abstract concept that refers to the response from attester. It reports how much an attester trusts the web environment the user agent is executing in.

The web environment is defined as TODO [sic]

So essentially google has carte blanche for information from your browser.

And they are prototyping that into browser - so forgive me but I'm concerned even more.

Post reply on HN