Live data from Hacker News

Your computer should say what you tell it to say

eff.org

111–120 of 263 posts

Re: Your computer should say what you tell it to say

#111

>You can choose not to send this to the remote server, but you lose the ability to send an altered or randomized description of your device and its software if you think that's best for you. The EFF is being misleading here by conflating the attestation taken and fingerprintable information like a user agent. An attestation taken does not contain information about the device that can be used to identify since the dat…

> "End users are not the only stakeholders in the web."

Wrong. RFC 8890 clearly states that the internet is for end users.

https://www.rfc-editor.org/rfc/rfc8890.html

Re: Your computer should say what you tell it to say

#112

This is one of the most detailed and balanced articles I have read so far on the topic. However, like every other one I've read, it omits one very important clarification about 'Web Environment Integrity': It is not part of the Web. This is exclusively a Google draft for a Google Chrome feature, and whilst Google is a member of the World Wide Web Consortium (W3C), they are not doing this as a member. I don't believe…

Web standards today aren't made by the W3C; they're made by WhatWG, which is Google, Apple, and Mozilla, but mostly Google.

Some historical context: WHATWG[1], the Web Hypertext Application Technology Working Group, was originally a spin-off of the W3C[2], and was an organisation formed in 2004 by W3C members unhappy with decisions made in the W3C at that time. In 2019, a 'Memorandum of Understanding' was signed[3] agreeing to various principles for coordination between the two organisations.

The W3C is still very much active, and produces the vast majority of specifications that are implemented by 'web browsers' (in the general sense) like Chrome, Firefox and Safari, and they have their own standardisation process which is comparable in quality to organisations like ISO.

The area in which WHATWG are most active, though, is HTML, for which they produce what they call 'Living Standards' that have a different process from W3C's. CSS is done inside the W3C, and JavaScript is formalised by ECMA, an entirely different organisation still.

[1]: https://whatwg.org/

[2]: https://www.w3.org/

[3]: https://www.w3.org/2019/04/WHATWG-W3C-MOU.html

[4]: https://www.ecma-international.org

Re: Your computer should say what you tell it to say

#113
post #10

I mean, devil's advocate here, this tech already exists and the question is do we do client attestation in a browser or pretend remote attestation doesn't exist. If this gets rejected, would that mean that services that need a "trusted client" simply deprecate their web apps and rely on a iOS/Android app? I'm not trying to argue in favor of WEI, I just think this doesn't magically disappear if Google doesn't implemen…

I would suggest reading the TAG's Web Platform Design Principles document, it does a really good job laying out why the web is different from mobile and native applications and the reasons why some APIs, like client attestation, work in a mobile environment but would damage the web platform if they're implemented. For example, the WEI proposal violates the "It should be safe to visit a web page" principle ( https://w…

"In order for the web to remain vibrant"

The people pushing these things do not care about this at all. To them it's like something a child would say and marks the speaker as utterly irellevant and silly, not even a real person due any respect at all.

Re: Your computer should say what you tell it to say

#114
post #97

Earlier quoted context omitted.

> Once it exists though, you can be sure it will become a standard practice requirement Yes, this seems inevitable. At which point, I will no longer be using the bank's website. > they'll seem absurd and won't last long in that position. I'm not sure what you mean here, though. People who object to ubiquitous surveillance don't seem absurd to most (even those who aren't so upset about it), and they certainly aren't c…

> I will no longer be using the bank's website That's a great temporary measure, but once this has rolled out everywhere and is part of standard commercial experiences, are you really willing to completely opt out of online banking because you're not permitted to send fake browser identification? It's a fine philosophical position, but it feels akin to refusing to use public streets because of the existence of survei…

> are you really willing to completely opt out of online banking

Sure, why not? It's not like it's a huge sacrifice on my part. It's just a little reduction in convenience. No big deal.

> because you're not permitted to send fake browser identification?

That's not the issue for me at all. The issue is if sites require me to use specific browsers, to not use specific extensions, to not be able to modify the browsers, or to adhere to specific requirements in terms of the OS I'm using. Having to maintain a completely different environment in order to use certain websites really is a loss of convenience that I object to.

Don't get me wrong -- I don't see this as a huge moral issue. Sites can do what they want, and if I don't like what they want, I don't have to use them. Opting not to use them strikes me as a reasonable and proportional response.

The only thing that makes me a little sad is that it's just another thing that makes the web worse and less useful.

Re: Your computer should say what you tell it to say

#115
post #10

I mean, devil's advocate here, this tech already exists and the question is do we do client attestation in a browser or pretend remote attestation doesn't exist. If this gets rejected, would that mean that services that need a "trusted client" simply deprecate their web apps and rely on a iOS/Android app? I'm not trying to argue in favor of WEI, I just think this doesn't magically disappear if Google doesn't implemen…

On my machine, it wouldn't be pretending that remote attestation doesn't exist. It does not exist, and if e.g. banks decided to require it, that'd just be locking me out. I have no attestation daemon, and if I did, it wouldn't be trusted by them. It doesn't matter if Firefox adds it too; it straight up won't work on my computer. People keep talking about browsers, but I'd prefer to continue running an operating system that doesn't have adware and spyware built in. My computer that I own is under my control, which is what these remote attestation features are meant to prevent. That is the fundamental problem.

If this kind of thing gets implemented by my bank/brokerage, I have to either buy a new computer just for them, or do all my banking over the phone or in person. It's incredibly wasteful and doesn't even help with security, but once it exists, it will get added to a checklist that banks will adhere to.

Re: Your computer should say what you tell it to say

#116

Remember: upvoting the EFF's articles is good, but you (yes, you!) can also donate to them to help with these campaigns!

I had donated to the EFF in the past, but their stance[1] that CDNs/hosted services shouldn't be allowed to choose the customers they are willing work with is not only wrong, it's causes harm[2]. [1] https://www.eff.org/press/releases/international-coalition-r... [2] https://blog.cloudflare.com/kiwifarms-blocked/

I'm more on the side of the EFF on this one. I don't think that infrastructure (and banking) companies should be able to deny lawful access as a default. What is able to be done in China in terms of cutting people off based on social credit scores should be terrifying and the only way around this is to expressly make certain markets open to anyone, even if you don't like them.

Re: Your computer should say what you tell it to say

#118

Would it be possible for attackers/fraudsters to just set up "proxy farms" of real hardware that provide the device details for attestation? It would make bots less efficient but surely the incentive for ad fraud would still exist and adaptations would be made.

Yes, but in theory if suspicious behavior was detected those devices could be permanently blacklisted from a website, making the investment challenging. If WEI goes through we'll probably see cheap PCs popping up on eBay that are unable to access certain websites.

You thought having your google account banned was bad now, wait until they ban all associated hardware with a heuristic routine and most of the web doesn't work for you anymore. That should really cut down on the account support requests they didn't want to deal with.

Re: Your computer should say what you tell it to say

#119

Earlier quoted context omitted.

that's all great but you realize a lot of readers here are not USA, eh? "web-TPM" needs to be named-and-shamed among literate people in all nations IMHO. It is clearly political -- there are private winners and public losers in the change to locked and enforced access to digital content on the Internet. Any commercial company in any country that can successfully block the roads and check ID will make money, and they…

It's not a "web-TPM", far from it conceptually.

It is totally web-tpm. The differences are irellevant to the essence.

Re: Your computer should say what you tell it to say

#120

Earlier quoted context omitted.

You'll likely be ushered to their mobile app instead.

I don't do mobile apps. What I'll do instead (and, honestly, this is what I already mostly do anyhow so it's not really a sacrifice) is physically go to the bank branch to conduct my business.

At my bank, they will then send you to the online banking, or the phone (with it's 20 min plus waits).

The Mobile app is required to use the debit card anywhere but card present, because 2fa. The Mobile app is required to do interesting things on the website, because of their 2fa. The iPad can't use their website (because reasons, they think it's mobile) and can't use the mobile app because it's not the configured phone with the account.

Credit cards really aren't a thing in this country, and if they are, they will generally have a phone based mobile app for 2fa/strong auth.

Post reply on HN