Live data from Hacker News

Your computer should say what you tell it to say

eff.org

211–220 of 263 posts

Re: Your computer should say what you tell it to say

#211

Earlier quoted context omitted.

> I will no longer be using the bank's website That's a great temporary measure, but once this has rolled out everywhere and is part of standard commercial experiences, are you really willing to completely opt out of online banking because you're not permitted to send fake browser identification? It's a fine philosophical position, but it feels akin to refusing to use public streets because of the existence of survei…

> are you really willing to completely opt out of online banking Sure, why not? It's not like it's a huge sacrifice on my part. It's just a little reduction in convenience. No big deal. > because you're not permitted to send fake browser identification? That's not the issue for me at all. The issue is if sites require me to use specific browsers, to not use specific extensions, to not be able to modify the browsers,…

What does your banking experience look like if losing online banking is a minor inconvenience to you?

For me it would be as if my bank ceased to exist.

Re: Your computer should say what you tell it to say

#212

Earlier quoted context omitted.

I work in a bank. Until a year ago, our passwords are 8 characters max, no special characters, upper and lowercase letters are equal. We were running IE7 up until 2 years ago. A huge amount of the business is still organized around sending excel sheets to each other, with no sidechannel validation. The fact that you recieved an excel sheet from some email is treated as proof that it's valid. Last I checked we were al…

> I have no doubt they will implement WEI, but it will not bring security. This is precisely OP’s point. WEI will quickly dominate despite having nothing to do with securing anyone.

WEI sounds like another security theater play by Ad corp. When web first come out it is because it's sandbox that made it so attractive. The server doesn't need to know what client it is, as long as it is speaking http.

With intro of html5, (webgpu, webgl, web audio api), that sandbox has being slowly opened up.

Re: Your computer should say what you tell it to say

#213

> A handful of companies have established chokepoints between buyers and sellers, performers and audiences, workers and employers, as well as families and communities. When those companies refuse to deal with you, your digital life grinds to a halt This short paragraph summarizes the (ex-ante) improbably unusual situation we have drifted into. The negatively affected stakeholders being enumerated are more or less the…

See also the history of railroads and telecoms.

The difference is one of degree (comprehensiveness) and potential impact. Total control of a mobility mode is bad, total control of a certain type of communication infrastructure is worse, but the fingeprinting and tracking and exploitation of every single digital device and information exchange is just out of the scale.

Re: Your computer should say what you tell it to say

#214
post #151

Earlier quoted context omitted.

the better argument is just flipping the perspective. if your computer runs a web server this increase the control because without it other computers can connect to it and lie about their identity. that's not to say I think this is a good thing, I just don't think control over your computer is a good argument when both sides of a connection are computers, and both operators want not just control over their computer b…

>without it other computers can [...] lie about their identity That's the point, I think. I own my computer, which means I decide whether it lies. If I want to serve "This website only works in Chrome" when it's actually cross-platform, that's my right. I might want the client to open the page in Chrome automatically, and I would have more control over the connection if I could do so, but that control would be over t…

> >without it other computers can [...] lie about their identity

> Are you saying that my demand to not have a server control what my client does is an act of control over what their computer does?

Yes. The owner of that computer does not want to serve your requests and you want to prevent them from exerting that control over their computer.

>Like if I told you not to use your forklift to take my stuff, I'm asserting power over your property?

Yes that is what is being argued here. Forklift owners demanding the right to lie about using a forklift to property owners like Google who do not want to allow forklifts to take their stuff.

Re: Your computer should say what you tell it to say

#215

I read the entire thing and it’s not clear how this reduces control of your own computer. It seems the premise is that those with a computer should be able to access others servers wholesale unconditionally. This premise is obviously wrong. > It also raises the barrier to entry for new browsers, something Google employees acknowledged in an unofficial explainer for the new feature, Web Environment Integrity (WEI). Th…

> It seems the premise is that those with a computer should be able to access others servers wholesale unconditionally. This premise is obviously wrong.

The premise is that I shouldn't have to give that server control over locally-running code on my PC as a prereq for access. They can enforce whatever conditions they want server-side.

Re: Your computer should say what you tell it to say

#216

Here is an idea: If WEI is available use it to block chrome otherwise allow access disregarding WEI. XD

Ok but seriously, this might be the only way to combat WEI. Don't even preach to the user about the evils of WEI (ain't nobody gonna read that wall of text), just say it is not supported and tell them succinctly how to turn it off / get a different browser.

I agree; this may well be an effective last-resort action if Google Chrome does implement Google's WEI proposal. However, I sincerely hope that it won't come to that, because it's not a foregone conclusion that Chrome wouldn't win :(

Re: Your computer should say what you tell it to say

#217

Earlier quoted context omitted.

You are essentially saying that we should have to ask permission from large corporations to be able to effectively run a website. For all practical purposes that means no free speech on the internet.

Freedom of speech meaning freedom from consequences has never existed, and will never exist. Infringing on a company's freedom of association does not eliminate consequences for speech. This is about freedom of association and the right (or lack thereof) to other people's broadcast equipment.

As a society we have held that in most cases corporations do not have freedom of association when providing vital services. e.g. your electric company has to offer you access to its services as long as you pay. This clearly needs to be extended to preserve freedom of speech on the internet. I care a lot about individual rights to free speech and very little about freedom of association for large corporations.

Re: Your computer should say what you tell it to say

#218

Earlier quoted context omitted.

The best part is when the frontend input and backend validation get out of sync, so your password works sometimes depending on where you come in from.

My health insurance portal (Aetna, no I am not above naming and shaming) did something annoying. When I signed up I used a randomly generated three-word passphrase from my password manager. It was around 32 characters or something. They have the fun pattern of logging you out of your account whenever you are inactive. A bit excessive for a health insurance provider imo, but whatever. So I tried to login and guess wha…

Heh, I had a health insurance portal that when you changed your password with their mobile app, it would let you use all the special characters. However the web app blocked (or stripped) those characters out, meaning you couldn't log in to the web app because it literally wouldn't let you type your password. Every so often the mobile app forced re-auth, and it redirected you to the web version where putting in your password wouldn't work... I likewise had a nightmare process to get it reset.

Re: Your computer should say what you tell it to say

#219

Earlier quoted context omitted.

Based on what you're saying though, it's already been forced on users through mobile devices. This is the next step in a series of steps which weren't argued against. It's not that we don't need this tech, is that we didn't need this tech and are making noise and it now.

Putting boot signing and “OS integrity control” aside, current iteration of TPM devices are not this intrusive. They allow me to generate and/or store keys and do cryptographic things with these keys securely. They store my information locally, and if implemented right, this data can’t leave that chip. Even OS integrity check is done locally. You can’t ask arbitrary measurements out of it. WEI is different. Rules com…

Treating end-users as a threat is galling, given the crappy security all over the web - IOT, infrastructure (BGP,DNS), leaky S3 buckets, misconfigured government sites, etc.

Re: Your computer should say what you tell it to say

#220

I think a realistic description/story from real experience I've had as a security engineer might help some people understand why this will end up so bad. I've worked with banks, who are among the most security-minded of organizations. It's not because they're security nerds, it's because the cost of getting hacked is astronomical, and because regulations require them to be "as secure as possible." Banks won't be chom…

While I'm willing to believe banks are very security minded in terms of their core infrastructure, banks do not appear to be with regards to their customer access and usually seem to move very slowly to secure that end of things. Hell, many/most of these large institutions seem to still only support SMS for 2FA and even that's a relatively recent introduction to actually mandate. Which is to say, I expect banks to be…

If banks were security minded for their customers they would have enabled read only app passwords 15 years ago. Instead, they made it unsafe to use third party software with their online banking front ends to deter you from owning your data.
Post reply on HN