Live data from Hacker News

Google’s Plan to DRM the Web Goes Against Everything Google Once Stood For

techdirt.com

421–427 of 427 posts

Re: Google’s Plan to DRM the Web Goes Against Everything Google Once Stood For

#421
post #419

Earlier quoted context omitted.

When navigator.getEnvironmentIntegrity is called the browser can get an attestation from any single atestor willing to attest to it.

I'm unable to understand this. Since the API doesn't provide a way to force a specific atestor to be invoked, doesn't it mean it will be the browser that decides which atestor can run on a given platform? Of course then substitute browser for Chrome and we'll get the obvious outcome - Google will decide.

There are seriously so many conflicting informations that this should be hanged from implementation before it its fully formulated (aside fact that it is bad idea and should be scrapped).

Firstly on Android Chrome implementation (testing) only Google Play is now implemented as attester and it does not seem that probable for it to change. (so presumably at least Chrome+Root wont work).

Second and Most Important - the mechanism does not allow for "willing to attest it" - it actually contains this phrase "The web server then checks that the token came from an attester it trusts" so it is disingenuous to say that "any single atestor" is OK - it must be attestor that server decided beforehand (so if server decide we only trust Google and Microsoft - and you have Mac, then tough luck. [more realistically Linux will be at issue]) - so we are getting system that can exclude certain OS and Browsers permanently without recourse - by server side.

@zb3 >doesn't it mean it will be the browser that decides which atestor can run on a given platform? That seems to be case in Chrome implementation* - and there is nothing about this in standard so unless other browsers would create another standard - this way seems likely.

This would be disastrous for any decentralized OS like Linux or BSD - it would be completely impossible for it to realistically work as it requires single "platform" by design - and I should remark "there is no single uniform thing in Linux".

* - note that server decides which attestors it trusts. Which means in essentia that sever decides which platforms it trusts.

Again this must be scrapped.

Re: Google’s Plan to DRM the Web Goes Against Everything Google Once Stood For

#422

Earlier quoted context omitted.

>The whole point of Android certification is that you are following Google's rules. Whole point of WEI is that you are following Google's rules. You essentially acknowledged that YOU CANNOT become manufacturer - you become subcontractor for corporation that dictates what you can and cannot do. Which from point of trust is precisely that - anticompetitive behaviour.

>Whole point of WEI is that you are following Google's rules. That would be the point of the Google Play attestor. With WEI sites can use anyone as an attestor. It is up for attestors to compete in providing a valuable signal to sites. It's not anticompetitive because you can come up with your own standard of a secure device and get sites to trust your attestor.

>It is up for attestors to compete in providing a valuable signal to sites.

right because users will chose attestor - oh wait they will not.

This system is designed (at least in Chrome) with PLATFORMS in mind not independent attestors - so you clearly didn't get the memo.

>valuable signal

rather highly intrusive signal.

>It's not anticompetitive because you can come up with your own standard of a secure device and get sites to trust your attestor.

Again it is anticompetitive when you produce a standard that benefits you (or biggest players) on market and makes nearly impossible for another competitor to emerge - it is even more anticompetitive when you create standard that "is impossible to implement" for architectural and 'branding' (ideological) reason by another competitor.

Such situation can be understood as public attempt: to form cartel at best, monopoly at worst. Both are anticompetitive by nature - and would result in dissolution of company if it is registered in any country with working and not totally corrupt government.

>secure device

about "security": https://news.ycombinator.com/item?id=36985317

Re: Google’s Plan to DRM the Web Goes Against Everything Google Once Stood For

#423

Earlier quoted context omitted.

I’m not sure what you mean by “they aren’t doing it”. WEI doesn’t exist yet, obviously nobody is blocking clients who aren’t attested. More to the point, even the author of this proposal has recognized this is an issue, identified it as so in the proposal, then failed to put forward a workable solution. That’s my problem.

> I’m not sure what you mean by “they aren’t doing it”. Making the web impossible to use if you don't fit into their specific requirements. WEI is just another signal. It won't be the only signal for the vast majority of the web. Google cannot do anything to break the web without the help of Apple. Frankly, Apple has a better chance of breaking anything open than Google does. Apple has the vertical control. Google ha…

Part 2:

> Yet a lot people seemingly know its going to do this, that, and some other bad thing

Original https://news.ycombinator.com/item?id=36935843

New

Because any other option is not sensible:

1. Authors don't understand what tech they use. (not possible as they acknowledge issues)

2. Authors don't understand that something unrealistic is unrealistic.

Idea that you can give companies or corporations tools to check "did user modify his environment" and they would not use it to exclude users is stupid or disingenuous because advocates for this did exactly comment in such way: We want this proposal to do precisely that.

Again Google tries to defend it by saying "we will return invalid 'false' for some of the users/times of Chrome users" [to make sure that website will not do that] which for me is not only bad because it then creates "when google revokes this policy we are in even worse situation" but then leaves the issue how google decides "who" to give back this 'false':

I will reject times immediately not only because this can be easily circumvented by website [check n-times] to detriment of user but it would also contradict official documentation of WEI (same token for same input from user).

And this leads us to another point - if Google wants to return false negatives it would need to either keep information that is supposed to return 'false' - EU will not be very happy with that (also it does contradict this "chrome users"); or more likely it will be implemented in chrome.

Now when we established that implementation in chrome is most probable - we can also establish that:

A) Implement this on profile basis - companies will ask you to reset profile if you are this false negative.

B) Implement on connection basis - companies will ask you to refresh.

C) Implement on device age / os version / type - Google can even make the manufacturers happy with this one.

… as you can see at most this will be nuisance and if by some weird way:

Z) Implement on Super-complicated basis - this will be still possible because…

3. Google plays disingenuous word game with us here by saying - We won't destroy open web

Other Chromium browsers may ignore that Google X% false negative (Google may loose few % of users before it scrapes this policy). And there is 0 need for Google to actually do something when companies will misuse this API.

In simple words the part that should worry you is not that "Google will destroy web by using this API on Chrome and it services", what must worry you is that other companies will do that for Google and Google will wash their hands from this by saying "We wanted good but didn't work". You can see that tone from the Google - We don't want that so we created these "holdouts".

They are proposing thing that any sensible person see as clear cut attack (or stupid idea that can only work this way) on Privacy and Your Right to use Your Device (and for some people Your OS and/or Your Browser) as You want to use. They are at fault here.

Re: Google’s Plan to DRM the Web Goes Against Everything Google Once Stood For

#424

Earlier quoted context omitted.

I’m not sure what you mean by “they aren’t doing it”. WEI doesn’t exist yet, obviously nobody is blocking clients who aren’t attested. More to the point, even the author of this proposal has recognized this is an issue, identified it as so in the proposal, then failed to put forward a workable solution. That’s my problem.

> I’m not sure what you mean by “they aren’t doing it”. Making the web impossible to use if you don't fit into their specific requirements. WEI is just another signal. It won't be the only signal for the vast majority of the web. Google cannot do anything to break the web without the help of Apple. Frankly, Apple has a better chance of breaking anything open than Google does. Apple has the vertical control. Google ha…

Part 1:

> They cannot prevent websites from requiring X to access their sites.

They can by lowering amount of signals site gets - so to make it impossible to guess what client is running.

> There is no workable solution to force someone to accept traffic against their wishes.

Not give someone way to disallow traffic based on OS or Browser.

> If they only accept requests with some custom header, that's their prerogative.

And it is users prerogative to not give you any custom header which they do not want - or if you force them to do so give you not real one.

>Many features of browsers have been (ab)used for "nefarious" purposes. Should we get rid of those?

Yes we should. Or at least we should do risk assesment on those to check if they should be part of standards and Browsers. We should do more risk assessment of any new feature and standard.

>Anything Google does is automatically bad.

If they start championing privacy and less pro-corpo bs - I will applaud them for that.

> This whole thing feels like since Trump is not president in the US any more, certain people need a boogeyman and are using Google in his place.

Don't bring your (USA) bs politics to this - if anything it is your fault to not make proper regulations on your market.

> even though there is no proof

If you understand even tiny bit of tech - you will see the definite proof - the proposal.

> "and stated goals which are the opposite."

PR is irrelevant.

Re: Google’s Plan to DRM the Web Goes Against Everything Google Once Stood For

#425
post #216

Earlier quoted context omitted.

Google Maps (and even more so Waze which they own) already had partnerships with various brands - for example, type McDonalds into Google Maps (at least in the UK) and it has the M logo next to "see locations" as soon as you've typed Mc - so it's not such a huge stretch as you think it would be.

I'm grateful they started doing this sort of thing. It was what got me to finally stop using Google Maps.

What’s the alternative?

Re: Google’s Plan to DRM the Web Goes Against Everything Google Once Stood For

#426
post #23

Earlier quoted context omitted.

No need to proxy, you can just use https://brave.com/ . Add a pihole to strip it from other devices and non-browser web traffic.

Using a browser powered by Google’s technology stack is hardly deGoogling.

You can view the brave browser repository yourself and see how they strip out a bunch of google crap: https://github.com/brave/brave-browser

If you don't trust them, you can compile it on your own.

Post reply on HN