Live data from Hacker News

Google’s nightmare “Web Integrity API” wants a DRM gatekeeper for the web

arstechnica.com

101–110 of 484 posts

Re: Google’s nightmare “Web Integrity API” wants a DRM gatekeeper for the web

#101
post #81
post #63

Earlier quoted context omitted.

> When Google can do something that every one of it's users hates I don't think this is remotely the case. Quite a few tech-savvy people I know (some of them software developers) use Chrome and mostly don't care about whatever Google does with it. I mention "manifest v3" and get a blank stare. I talk about advertising and ad blockers, and most people don't care, with some of them not even using ad blockers. We really…

I'm a tech-savvy person and I consider Manifest v3 an improvement (improves security + performance), and Firefox implements it as well as things like declarativeNetRequest[1]. [1]: https://developer.mozilla.org/en-US/docs/Mozilla/Add-ons/Web...

Manifest v3 itself is an improvement and is probably non-controversial. I can't see why anyone would think deprecating manifest v2 along with removing webRequest is a good thing. The latter is what everyone is mad about when they talk about "manifest v3". I'm not sure whether you're trying to making a nitpick point about the difference between the two, or you legitimately think the latter is a good thing.

Re: Google’s nightmare “Web Integrity API” wants a DRM gatekeeper for the web

#102
Surprising even myself, I actually like this proposal. It does two things, one which is good, and the other which is not as bad as people are saying.

The good thing is to give browsers a way to attest to their inviolability to systems on the other end. This is generally useful! In particular, it opens up a huge potential for people to run what are effectively servers in their browsers - which was TBL's vision for the web in the first place.

The not-as-bad-as-you-think thing is that Google (and others) will use this to disable ad-blockers. Ad blockers are fundamentally dishonest, and people who use them may feel guilty for doing so. The more honest approach is to simply not consume the media. And this, it turns out, is better for society at large. Anyone who gets paid to talk ekes out a living by hacking the algorithm, making a brand, and telling people what they want to hear. It's bad and it's a bad system that makes the world worse.

Re: Google’s nightmare “Web Integrity API” wants a DRM gatekeeper for the web

#103
post #23
post #6

Google seems to be escalating the speed of its efforts to restrict its user base to the completely non-technical, but Apple and Facebook already own that market. It also sounds like they're promoting yet another way to make "the internet" slower, more bloated, and have greater impediments to usage.

This proposal only impacts "the web", which has already been going downhill for years now due to unsustainable ad-reliant business models. The internet is fine.

While I agree with the other people in this thread pointing out that the web practically is the internet for the average user, I think this is an opportune moment to mention that Gemini exists, free of any kind of mass surveillance or advertising. It's like the web prior to Eternal September. I even have my own Gemini capsule[0] which has a live web mirror[1] statically generated from the former's content. Granted, Gemini is vanishingly obscure and relatively inaccessible compared to the web, but it's still cool that it exists.

[0] gemini://hackersphere.space

[1] https://hackersphere.space

Re: Google’s nightmare “Web Integrity API” wants a DRM gatekeeper for the web

#104

> The goal of the project is to learn more about the person on the other side of the web … The intro says this data would be useful to advertisers to better count ad impressions, stop social network bots, enforce intellectual property rights, stop cheating in web games Go f yourself, Google. Browser’s purpose is to serve me web pages, not to learn about me.

As long as Google is still leading in the browser market share, they do not care or give a shit and will never change.

Re: Google’s nightmare “Web Integrity API” wants a DRM gatekeeper for the web

#105
post #63
post #32

> Exactly how the rest of the world feels about this is not necessarily relevant, though. Google owns the world's most popular web browser, the world's largest advertising network, the world's biggest search engine, the world's most popular operating system, and some of the world's most popular websites. So really, Google can do whatever it wants. This is the point that company breakups start to make a lot of sense.…

> When Google can do something that every one of it's users hates I don't think this is remotely the case. Quite a few tech-savvy people I know (some of them software developers) use Chrome and mostly don't care about whatever Google does with it. I mention "manifest v3" and get a blank stare. I talk about advertising and ad blockers, and most people don't care, with some of them not even using ad blockers. We really…

> mostly don't care about whatever Google does

This is not support, this is lack of awareness or apathy.

Re: Google’s nightmare “Web Integrity API” wants a DRM gatekeeper for the web

#106

Surprising even myself, I actually like this proposal. It does two things, one which is good, and the other which is not as bad as people are saying. The good thing is to give browsers a way to attest to their inviolability to systems on the other end. This is generally useful! In particular, it opens up a huge potential for people to run what are effectively servers in their browsers - which was TBL's vision for the…

Do you know how rooting Android is basically useless nowadays? Most banking and government apps, at least in my country, don't work if Google didn't give the seal of approval for your system. I take it you see as good thing to bring this to the browser as well, because this somehow has to do "personal computer advocacy"? It literally cripples the users' devices.

Re: Google’s nightmare “Web Integrity API” wants a DRM gatekeeper for the web

#107

The use cases for the WEI proposal are pretty clear from the explainer ( https://github.com/RupertBenWiser/Web-Environment-Integrity/ ...): Google "will be able to request a token that attests key facts about the environment their client code is running in." Google "will ultimately decide if they trust the verdict returned from the attester." "Allow" Google "to evaluate the authenticity of the device and honest repre…

“There is a tension between utility for anti-fraud use cases requiring deterministic verdicts and high coverage, and the risk of websites using this functionality to exclude specific attesters or non-attestable browsers. We look forward to discussion on this topic, and acknowledge the significant value-add even in the case where verdicts are not deterministically available (e.g. holdouts).”

See, don’t worry, they’re thinking about you, holdout.

Re: Google’s nightmare “Web Integrity API” wants a DRM gatekeeper for the web

#108
post #31

While I don't love this API's idea, I understand why they're doing it, and the API it describes really just sounds like any Captcha API today. > Google's plan is that, during a webpage transaction, the web server could require you to pass an "environment attestation" test before you get any data. At this point your browser would contact a "third-party" attestation server, and you would need to pass some kind of test.…

That's how I read the proposal too.

One key difference to Captchas is that since this new system requires no user input, the "cost" of a website requesting attestation is a lot smaller. So it will probably be used more widely.

Re: Google’s nightmare “Web Integrity API” wants a DRM gatekeeper for the web

#109
There are conflicting "requirements" for the web it seems. We want freedom and anonymity but not too much because bots and because we want to use the web to buy things but not too little because dissidents, but not too much because pedos and terrorists...you get the idea.
Post reply on HN