I think a realistic description/story from real experience I've had as a security engineer might help some people understand why this will end up so bad. I've worked with banks, who are among the most security-minded of organizations. It's not because they're security nerds, it's because the cost of getting hacked is astronomical, and because regulations require them to be "as secure as possible." Banks won't be chom…
I work in a bank. Until a year ago, our passwords are 8 characters max, no special characters, upper and lowercase letters are equal. We were running IE7 up until 2 years ago. A huge amount of the business is still organized around sending excel sheets to each other, with no sidechannel validation. The fact that you recieved an excel sheet from some email is treated as proof that it's valid. Last I checked we were al…
Your computer should say what you tell it to say
231–240 of 263 posts
Re: Your computer should say what you tell it to say
#232Earlier quoted context omitted.
The actual goal is probably that Google and others prevent ad-blocking. WEI itself is not meant as a fingerprint, but with unblockable ads comes unblockable tracking (not that I personally care about tracking). Like, look at YouTube on iPhones, they blocked background playback in the app and even got Apple to block it in Safari in iOS update 10. They don't need WEI to keep the vast majority of users away from obscure…
YouTube contractually must pay extra when people play music in the background. It's why it's a premium only feature.
Re: Your computer should say what you tell it to say
#233Earlier quoted context omitted.
> as if they already operate effective mind control at systemic scale. If the logical conclusion of your reasoning is a mass mind control conspiracy, you should revisit your assumptions. > somehow they can bully into submission basically the entire universe I don't think anyone is bullying all of society. I think most people just don't care. It's really not that crazy, no mind control involved. Just good old fashione…
If they can kick the former president off his platform they can bully joe schmo off there platform. Whether you agree with the former president, he was in theory the most powerful person on the planet and had to submit to the powers of large tech companies. I think the idea that most people don't care is not a supported or found assumption either rather you just asserted it.
Re: Your computer should say what you tell it to say
#234Earlier quoted context omitted.
Yes, because ads are beneficial to the web. So is account security, spam detection, anticheat, etc. The current implementation of the web is not set in stone and we should take steps to improve it.
> Yes, because ads are beneficial to the web. Citation needed. Ads are not beneficial to users of the web. There does not exist a website that is better WITH ads. Users do not care about ad fraud. Ads are beneficial to adtech and companies with ad spend. We should not destroy the entire internet to protect/increase adtech profits.
Ads can fund the development of the site, the services of the site, and the content on the site. The amount of additional value that the site is able to provide users is much more than the value that gets taken away by including ads. I haven't even mentioned how the ability of users to advertise things on the web is also very useful.
>Ads are beneficial to adtech and companies with ad spend.
Who are both users of the web too.
Re: Your computer should say what you tell it to say
#235I mean, devil's advocate here, this tech already exists and the question is do we do client attestation in a browser or pretend remote attestation doesn't exist. If this gets rejected, would that mean that services that need a "trusted client" simply deprecate their web apps and rely on a iOS/Android app? I'm not trying to argue in favor of WEI, I just think this doesn't magically disappear if Google doesn't implemen…
Good. The point here is to shrink the space where client attestation is used, not to expand it. Every time it shrinks a little bit more is a victory. Let's get it out of the browser and then we can tackle native attestation for apps next.
> If this gets rejected, would that mean that services that need a "trusted client" simply deprecate their web apps and rely on a iOS/Android app?
This is verbatum the argument that was brought up for EME. But now we have the benefit of looking back at EME and seeing what the impact was. It didn't stop the movement towards native apps, businesses like Netflix implemented EME and kept many of the same restrictions they were going to implement anyway. It did end up harming browser diversity.
I understand that it sounds scary to say "we're just not going to do this" on the web when sites might be pushing a scare tactic of "we're just going to go native then." But... we've been through this, caving doesn't work. The sites that want to go native will go native, WEI on its own will not be a business justification for websites to stay on the web or to leave the web. The sites that do want to go native-only will not suddenly make a website just because WEI exists. They'll do the same stuff they wanted to do anyway, and if WEI is available, they will simply add that to their toolkit as a way to limit user agency alongside everything else they're doing.
It's good if businesses that want to rely on client attestation are "punished" by being forced to abandon their web presence. And frankly, people underestimate how much power the web has. Refusing to support WEI will not kill the web.
Re: Your computer should say what you tell it to say
#236Earlier quoted context omitted.
The problem is, this is very open (or even designed) to be abused by their implementers. It's akin to having only Microsoft as the Secure Boot key authority. Mobile devices already has tons of attestation features. Secure enclaves, security processors, cryptographic capabilities of SIM cards (e.g. I carry my private key inside my SIM card, and use it as a wet signature, legally). We do not need this tech which can an…
Based on what you're saying though, it's already been forced on users through mobile devices. This is the next step in a series of steps which weren't argued against. It's not that we don't need this tech, is that we didn't need this tech and are making noise and it now.
Re: Your computer should say what you tell it to say
#237Earlier quoted context omitted.
I work in a bank. Until a year ago, our passwords are 8 characters max, no special characters, upper and lowercase letters are equal. We were running IE7 up until 2 years ago. A huge amount of the business is still organized around sending excel sheets to each other, with no sidechannel validation. The fact that you recieved an excel sheet from some email is treated as proof that it's valid. Last I checked we were al…
> I have no doubt they will implement WEI, but it will not bring security. This is precisely OP’s point. WEI will quickly dominate despite having nothing to do with securing anyone.
Who will have some trouble with this new concept on the web? Smaller browser maker, software developers and crawlers from competitors
Not a single scammer or ad fraud will be affected, same as on mobile.
Easy to see why Google wants that, its attacking the competition
Re: Your computer should say what you tell it to say
#238I mean, devil's advocate here, this tech already exists and the question is do we do client attestation in a browser or pretend remote attestation doesn't exist. If this gets rejected, would that mean that services that need a "trusted client" simply deprecate their web apps and rely on a iOS/Android app? I'm not trying to argue in favor of WEI, I just think this doesn't magically disappear if Google doesn't implemen…
True that TPM shouldn't be embraced either, it will just create ambitions.
Re: Your computer should say what you tell it to say
#239>You can choose not to send this to the remote server, but you lose the ability to send an altered or randomized description of your device and its software if you think that's best for you. The EFF is being misleading here by conflating the attestation taken and fingerprintable information like a user agent. An attestation taken does not contain information about the device that can be used to identify since the dat…
Not true at all in the slightest, even with the sorry explanation Google employees tried to conjure.
> To prevent ad fraud either you need to increase the fingerprintablity of users on the web, violating people's privacy, or implemented a form of remote attestation, which protects people's privacy.
Not true either, you don't have to do any of that. And why exactly should the client be responsible for ad fraud? These suckers, advertisers, try to track me without consent for years and abuse every legal gray area there is. Boot me from a service if you don't like my client for all I care, just be transparent about it.
> You can even make an attestation service for your own browser.
I don't want that. I do indeed vet clients connecting to my service to defend against attacks, but WEI comes with a cost I would never be willing to pay.