Live data from Hacker News

Your computer should say what you tell it to say

eff.org

101–110 of 263 posts

Re: Your computer should say what you tell it to say

#101

I read the entire thing and it’s not clear how this reduces control of your own computer. It seems the premise is that those with a computer should be able to access others servers wholesale unconditionally. This premise is obviously wrong. > It also raises the barrier to entry for new browsers, something Google employees acknowledged in an unofficial explainer for the new feature, Web Environment Integrity (WEI). Th…

> It seems the premise is that those with a computer should be able to access others servers wholesale unconditionally

No, the preimise is that a server that offers an HTTP endpoint should provide the same behavior at the endpoint regardless of the nature of the device or software that is accessing it.

Obviously, we have some exceptions already, hence robots.txt

But the idea is that if I am a user pointing something with a reasonable functional distance of "a web browser" at an HTTP server, the server should not alter its behavior based on an attempt to verify the internals of my browser.

Re: Your computer should say what you tell it to say

#102

I read the entire thing and it’s not clear how this reduces control of your own computer. It seems the premise is that those with a computer should be able to access others servers wholesale unconditionally. This premise is obviously wrong. > It also raises the barrier to entry for new browsers, something Google employees acknowledged in an unofficial explainer for the new feature, Web Environment Integrity (WEI). Th…

> It seems the premise is that those with a computer should be able to access others servers wholesale unconditionally. This premise is obviously wrong.

Yes, that is obviously wrong. Accessing a website doesn't give you anything like the ability "to access other servers wholesale unconditionally". Requesting files over HTTPS isn't a gorram root ssh session.

All a user-agent does is ask "Can I have file `/x` please?", "Can I have file `/y` please?", "Here is the data `foo=bar` for `/quux`" etc., etc., etc...

The server is free to say "200 OK" or "400 Fuck off" to any request it receives, at its own discretion, based on whatever rules the server administrator wants to put in place. Which they have the absolute capability to do. That is nothing like "unconditional wholesale access" to a server.

Re: Your computer should say what you tell it to say

#103

This is one of the most detailed and balanced articles I have read so far on the topic. However, like every other one I've read, it omits one very important clarification about 'Web Environment Integrity': It is not part of the Web. This is exclusively a Google draft for a Google Chrome feature, and whilst Google is a member of the World Wide Web Consortium (W3C), they are not doing this as a member. I don't believe…

Web standards today aren't made by the W3C; they're made by WhatWG, which is Google, Apple, and Mozilla, but mostly Google.

Re: Your computer should say what you tell it to say

#104

I read the entire thing and it’s not clear how this reduces control of your own computer. It seems the premise is that those with a computer should be able to access others servers wholesale unconditionally. This premise is obviously wrong. > It also raises the barrier to entry for new browsers, something Google employees acknowledged in an unofficial explainer for the new feature, Web Environment Integrity (WEI). Th…

> It seems the premise is that those with a computer should be able to access others servers wholesale unconditionally. This premise is obviously wrong.

"Obviously" is a very strong word for what is pretty much your opinion.

As the system was designed browsers are an agent of the user, not of the web servers or the ad businesses. If you want guaranteed ad impressions and control go make iPhone apps. Taking an open system such as the web and forcefully closing it up using overwhelming monopoly power like Google is doing is not only disgusting but also incredibly anti-competitive.

> At the end of the day, even if WEI is implemented it wouldn’t necessarily get rid of an open web as it’s entirely optional.

For now. "Entirely optional" can be stretched very far. If you were banned from AdSense revenue and from appearing in search unless you enforced this, it would still be "entirely optional" but also pretty much trash your site unless you complied.

Re: Your computer should say what you tell it to say

#105
post #97

Earlier quoted context omitted.

> Once it exists though, you can be sure it will become a standard practice requirement Yes, this seems inevitable. At which point, I will no longer be using the bank's website. > they'll seem absurd and won't last long in that position. I'm not sure what you mean here, though. People who object to ubiquitous surveillance don't seem absurd to most (even those who aren't so upset about it), and they certainly aren't c…

Hey John, I love that we are in the same threads on HN so much :-D > I'm not sure what you mean here, though. People who object to ubiquitous surveillance don't seem absurd to most (even those who aren't so upset about it), and they certainly aren't changing their position. Yeah good question/clarification, I'm referring to the CCTV cameras in the bank itself (such as in the vault, in the lobby, etc).

Hooray for shared interests! :)

> I'm referring to the CCTV cameras in the bank itself

Ahh, I see what you mean. I do know people who hate even those cameras, but they do also understand why they're there and just silently put up with them while minimizing the amount of time they spend on-premises.

I think there's a bit of a difference, though. If I'm in a bank branch, it's effectively "their house, their rules", so CCTV cameras don't offend me there.

But if the bank required me to be searched when entering the place, I'd be strongly offended by that. To me, WEI is more like being frisked than being surveilled (although neither analogy is great).

Re: Your computer should say what you tell it to say

#106
post #97

I think a realistic description/story from real experience I've had as a security engineer might help some people understand why this will end up so bad. I've worked with banks, who are among the most security-minded of organizations. It's not because they're security nerds, it's because the cost of getting hacked is astronomical, and because regulations require them to be "as secure as possible." Banks won't be chom…

> Once it exists though, you can be sure it will become a standard practice requirement Yes, this seems inevitable. At which point, I will no longer be using the bank's website. > they'll seem absurd and won't last long in that position. I'm not sure what you mean here, though. People who object to ubiquitous surveillance don't seem absurd to most (even those who aren't so upset about it), and they certainly aren't c…

You'll likely be ushered to their mobile app instead.

Re: Your computer should say what you tell it to say

#107

>You can choose not to send this to the remote server, but you lose the ability to send an altered or randomized description of your device and its software if you think that's best for you. The EFF is being misleading here by conflating the attestation taken and fingerprintable information like a user agent. An attestation taken does not contain information about the device that can be used to identify since the dat…

> An attestation taken does not contain information about the device that can be used to identify since the data the site gets is low entropy.

Citation needed, how does WEI make it _impossible_ for attesters to return higher entropy information? Pinkie promises are insufficient.

> WEI doesn't stop you from changing your user agent

False, this is an explicit design goal: "Allow web servers to evaluate the authenticity of the device and honest representation of the software stack and the traffic from the device."

> nor does it prevent you from using your privacy web extentions

Not an explicit goal, but a very obvious next step with strong economic incentives.

> Physical handcuffs would be very intrusive, but that isn't what is happening here.

Seeing a message that says "Sorry, this website is only accessible by browsers that support WEI" is very intrusive.

> WEI doesn't prevent you from participating in the web or needing to meet someone else's specification. You can even make an attestation service for your own browser.

Categorically false, no website is going to trust your attestation service. This is equivalent to saying "Just create your own CA".

> I disagree that beivg a to lie about what your device is running in a building block of all civil rights because the physical analog, fraud, is illegal, and the world seems better without people commuting fraud to one another.

No, the physical analog is "lying", which isn't illegal in most situations, and required in some - such as when a stalker asks you where you live.

Re: Your computer should say what you tell it to say

#108
post #97

Earlier quoted context omitted.

> Once it exists though, you can be sure it will become a standard practice requirement Yes, this seems inevitable. At which point, I will no longer be using the bank's website. > they'll seem absurd and won't last long in that position. I'm not sure what you mean here, though. People who object to ubiquitous surveillance don't seem absurd to most (even those who aren't so upset about it), and they certainly aren't c…

You'll likely be ushered to their mobile app instead.

I don't do mobile apps.

What I'll do instead (and, honestly, this is what I already mostly do anyhow so it's not really a sacrifice) is physically go to the bank branch to conduct my business.

Re: Your computer should say what you tell it to say

#109
post #97

I think a realistic description/story from real experience I've had as a security engineer might help some people understand why this will end up so bad. I've worked with banks, who are among the most security-minded of organizations. It's not because they're security nerds, it's because the cost of getting hacked is astronomical, and because regulations require them to be "as secure as possible." Banks won't be chom…

> Once it exists though, you can be sure it will become a standard practice requirement Yes, this seems inevitable. At which point, I will no longer be using the bank's website. > they'll seem absurd and won't last long in that position. I'm not sure what you mean here, though. People who object to ubiquitous surveillance don't seem absurd to most (even those who aren't so upset about it), and they certainly aren't c…

> I will no longer be using the bank's website

That's a great temporary measure, but once this has rolled out everywhere and is part of standard commercial experiences, are you really willing to completely opt out of online banking because you're not permitted to send fake browser identification?

It's a fine philosophical position, but it feels akin to refusing to use public streets because of the existence of surveillance cameras.

Re: Your computer should say what you tell it to say

#110

I think a realistic description/story from real experience I've had as a security engineer might help some people understand why this will end up so bad. I've worked with banks, who are among the most security-minded of organizations. It's not because they're security nerds, it's because the cost of getting hacked is astronomical, and because regulations require them to be "as secure as possible." Banks won't be chom…

While I'm willing to believe banks are very security minded in terms of their core infrastructure, banks do not appear to be with regards to their customer access and usually seem to move very slowly to secure that end of things.

Hell, many/most of these large institutions seem to still only support SMS for 2FA and even that's a relatively recent introduction to actually mandate.

Which is to say, I expect banks to be about the very last significant account you use to mandate this technology (if it takes off), not the first.

Post reply on HN