Live data from Hacker News

Google’s Plan to DRM the Web Goes Against Everything Google Once Stood For

techdirt.com

411–420 of 427 posts

Re: Google’s Plan to DRM the Web Goes Against Everything Google Once Stood For

#411
post #409
post #408

Earlier quoted context omitted.

In what universe do you live that Google or anyone else should device this complicated scheme to just capture 2-3 people. Linux has only 3% share of the users. of those maybe 0.1% could write a kernel module (or even install one) and of those maybe 1% would be maniac enough to dedicate time and effort to it just to "stick it to the Pawaaa" Google could accomplish all of their supposedly nefarirous goals by just ignor…

> Google could accomplish all of their supposedly nefarirous goals by just ignoring the linux users. No, because in order to ignore linux users you'd need to know that the device in question is actually running linux. But then again, I can run a windows VM inside (sure, this might require effort to patch the windows inside), with no need to write a kernel module because this time I can introduce custom logic in the V…

> except that the 0.01% case is precisely what causes the damage (bots, fraud, piracy and so on).

Thankyou, that's precisly my point. All this trouble is worth only for fighting fraud and bots and not for making sure that that 0.1% can't use a adblocker like anyone is crying about.

Re: Google’s Plan to DRM the Web Goes Against Everything Google Once Stood For

#412
post #411
post #409

Earlier quoted context omitted.

> Google could accomplish all of their supposedly nefarirous goals by just ignoring the linux users. No, because in order to ignore linux users you'd need to know that the device in question is actually running linux. But then again, I can run a windows VM inside (sure, this might require effort to patch the windows inside), with no need to write a kernel module because this time I can introduce custom logic in the V…

> except that the 0.01% case is precisely what causes the damage (bots, fraud, piracy and so on). Thankyou, that's precisly my point. All this trouble is worth only for fighting fraud and bots and not for making sure that that 0.1% can't use a adblocker like anyone is crying about.

But:

1) I meant damage to them, bots are beneficial for users (scrapping services) just like piracy (but this is a political point)

2) Even if the reason for these changes it to fight that "fraud", it does NOT mean it won't be used to further restrict the user freedom.

On Android, banking apps require hardware attestation and this can be seen as reasonable from the security perspective.

But Google abuses it to insert their Adware and Spyware into the system, just like other vendors. Now if you root your device to remove that crap, then poof - you're no longer considered secure. With WEI this is about the same thing.

Re: Google’s Plan to DRM the Web Goes Against Everything Google Once Stood For

#413

Earlier quoted context omitted.

The whole point of Android certification is that you are following Google's rules. If you make something that is not certified you can not get play services.

>The whole point of Android certification is that you are following Google's rules. Whole point of WEI is that you are following Google's rules. You essentially acknowledged that YOU CANNOT become manufacturer - you become subcontractor for corporation that dictates what you can and cannot do. Which from point of trust is precisely that - anticompetitive behaviour.

>Whole point of WEI is that you are following Google's rules.

That would be the point of the Google Play attestor. With WEI sites can use anyone as an attestor. It is up for attestors to compete in providing a valuable signal to sites.

It's not anticompetitive because you can come up with your own standard of a secure device and get sites to trust your attestor.

Re: Google’s Plan to DRM the Web Goes Against Everything Google Once Stood For

#414
post #404

Earlier quoted context omitted.

>strikes a deal with select few hardware vendors That isn't what is happening. Anyone can become a manufacturer for Windows PCs or Android certified phones.

That's not the competition I really meant, replace hardware vendors with OS vendors / Google. "Android certified" means it follows Google's rules, so there's no way to compete by creating alternative security model (for example where the user has more power). So the anticompetitive part is the attestation part, which artificially makes it impossible to run an app that'd otherwise work on the system that doesn't follo…

>so there's no way to compete by creating alternative security model (for example where the user has more power).

There is a way, by creating a new attestor service that provides less guarantees than what Google Play's attestor provides.

Re: Google’s Plan to DRM the Web Goes Against Everything Google Once Stood For

#415

Earlier quoted context omitted.

>The whole point of Android certification is that you are following Google's rules. Whole point of WEI is that you are following Google's rules. You essentially acknowledged that YOU CANNOT become manufacturer - you become subcontractor for corporation that dictates what you can and cannot do. Which from point of trust is precisely that - anticompetitive behaviour.

>Whole point of WEI is that you are following Google's rules. That would be the point of the Google Play attestor. With WEI sites can use anyone as an attestor. It is up for attestors to compete in providing a valuable signal to sites. It's not anticompetitive because you can come up with your own standard of a secure device and get sites to trust your attestor.

Even if that'd be the case I'd still consider this API nothing more than a framework for enabling anticompetitive behaviour.

But let's go back to the "anyone as attestor" argument. I don't see it in the API at all - I see only content binding..

Re: Google’s Plan to DRM the Web Goes Against Everything Google Once Stood For

#416
post #404

Earlier quoted context omitted.

That's not the competition I really meant, replace hardware vendors with OS vendors / Google. "Android certified" means it follows Google's rules, so there's no way to compete by creating alternative security model (for example where the user has more power). So the anticompetitive part is the attestation part, which artificially makes it impossible to run an app that'd otherwise work on the system that doesn't follo…

>so there's no way to compete by creating alternative security model (for example where the user has more power). There is a way, by creating a new attestor service that provides less guarantees than what Google Play's attestor provides.

Compete in anticompetitiveness? Attestation is the problem itself, it makes it harder to compete, by definition excluding any newly created environment.

But this isn't really my problem as I'm not a business. As an user, I'd be happy to have a secure OS with hardware attestation and app security but without Google Adware and Spyware.

Re: Google’s Plan to DRM the Web Goes Against Everything Google Once Stood For

#417
post #415

Earlier quoted context omitted.

>Whole point of WEI is that you are following Google's rules. That would be the point of the Google Play attestor. With WEI sites can use anyone as an attestor. It is up for attestors to compete in providing a valuable signal to sites. It's not anticompetitive because you can come up with your own standard of a secure device and get sites to trust your attestor.

Even if that'd be the case I'd still consider this API nothing more than a framework for enabling anticompetitive behaviour. But let's go back to the "anyone as attestor" argument. I don't see it in the API at all - I see only content binding..

When navigator.getEnvironmentIntegrity is called the browser can get an attestation from any single atestor willing to attest to it.

Re: Google’s Plan to DRM the Web Goes Against Everything Google Once Stood For

#418
post #416

Earlier quoted context omitted.

>so there's no way to compete by creating alternative security model (for example where the user has more power). There is a way, by creating a new attestor service that provides less guarantees than what Google Play's attestor provides.

Compete in anticompetitiveness? Attestation is the problem itself, it makes it harder to compete, by definition excluding any newly created environment. But this isn't really my problem as I'm not a business. As an user, I'd be happy to have a secure OS with hardware attestation and app security but without Google Adware and Spyware.

>Compete in anticompetitiveness?

Trust isn't anticompetitive.

Re: Google’s Plan to DRM the Web Goes Against Everything Google Once Stood For

#419
post #415

Earlier quoted context omitted.

Even if that'd be the case I'd still consider this API nothing more than a framework for enabling anticompetitive behaviour. But let's go back to the "anyone as attestor" argument. I don't see it in the API at all - I see only content binding..

When navigator.getEnvironmentIntegrity is called the browser can get an attestation from any single atestor willing to attest to it.

I'm unable to understand this. Since the API doesn't provide a way to force a specific atestor to be invoked, doesn't it mean it will be the browser that decides which atestor can run on a given platform?

Of course then substitute browser for Chrome and we'll get the obvious outcome - Google will decide.

Re: Google’s Plan to DRM the Web Goes Against Everything Google Once Stood For

#420
post #416

Earlier quoted context omitted.

Compete in anticompetitiveness? Attestation is the problem itself, it makes it harder to compete, by definition excluding any newly created environment. But this isn't really my problem as I'm not a business. As an user, I'd be happy to have a secure OS with hardware attestation and app security but without Google Adware and Spyware.

>Compete in anticompetitiveness? Trust isn't anticompetitive.

In this context it clearly is - if the server assumes the request sent by the client is always untrusted, then any capable device / app can use the service and it's possible to manufacture that device / app without permission from some company that has a dominant market position..

I acknowledge though, that this is incompatible with many practical scenarios, and CPC advertisements are one of those.

It's hard for me to argue here theoretically without taking context into account, as it turns out what I'm arguing for depends on it heavily..

It could be possible for Google to make changes where while theoretically possible to compete, it's not practical, and when it gets practical, Google could make another change and so on..

Post reply on HN