Live data from Hacker News

Google’s nightmare “Web Integrity API” wants a DRM gatekeeper for the web

arstechnica.com

131–140 of 484 posts

Re: Google’s nightmare “Web Integrity API” wants a DRM gatekeeper for the web

#131
It's great to see this getting more attention. User-agent discrimination (i.e. "go away if you're not using the latest version of Chrome") needs to become illegal. As long as I'm not overloading your service or similar, what hardware or software I use must not be restricted. The same goes for other deliberate obstacles to accessibility and interoperability --- creating a "standard" that's so complex and churned frequently enough that only Google can implement it and keep up with changes, and then spreading propaganda to encourage all sites to essentially become Chrome-only regardless of their actual utility, is something that needs to be stopped.

I recommend finding everyone responsible for this and exercising your right to free speech on them. It works for politicians, and it should work on this other flavour of bastard too.

Once again, Stallman was very prescient: https://www.gnu.org/philosophy/right-to-read.html

Re: Google’s nightmare “Web Integrity API” wants a DRM gatekeeper for the web

#132
post #39

Earlier quoted context omitted.

Google will degrade their services for non-DRM browsers. They have a long history of "oops" with UA sniffs and serving slow buggy alternatives to Chrome-only JS. You'll be filling in captchas 10 times a day, getting randomly locked out of your Google account in the name of security, and whatever new feature they add to their services, they'll find an excuse to require the DRM for it.

Cloudflare will happily help Google with displaying captchas to everyone not using Chrome.

endless captcha loops

Re: Google’s nightmare “Web Integrity API” wants a DRM gatekeeper for the web

#133

I'll add to this, notably, issues are still closed after the weekend: https://github.com/RupertBenWiser/Web-Environment-Integrity/... If this proposal gets rejected it'll be because of feedback in the press that is impossible to ignore. My experience watching how Google has handled contentious issues in the past makes me personally feel that Google will not be receptive to concerns about whether this spec should exis…

Note to readers of this comment in the future. This is the smartest post in the thread, and should be at the top.

Re: Google’s nightmare “Web Integrity API” wants a DRM gatekeeper for the web

#134

Earlier quoted context omitted.

Why did Google select someone unknown to announce this?* It's also the second time I've noticed Google had someone the UK introduce an unpopular proposal to Chrome. The other one was removing the URL from the address bar (accusing the author of You Don't Know JS of being "Trump-like" for how he disagreed with him in the process). https://www.youtube.com/watch?v=0-wB1VY3Nrc https://twitter.com/jaffathecake/status/1272…

Plausible deniability

Google must love Brexit. I guess that in the UK people feel distance from the devs in the US complaining about this. And the company is more comfortable with the legal situation in the UK than in the EU.

Re: Google’s nightmare “Web Integrity API” wants a DRM gatekeeper for the web

#135
post #64

Earlier quoted context omitted.

Yeah, that was when I realized that Mozilla wasn't really able to stand up to the bad guys as much as we'd hope.

thats because mozilla simply stopped having any interest in browsing whatsoever. They now have an interest in limited edition color drops and with their bespoke charactaristic allowing users to select color that best resonates with them. You and I, as mere mortals, may not know what this means, but rest assured, mozilla does.

to whomever downvoted this, you clearly need some more independent voices in your life, but fear not, Mozilla got you covered: https://blog.mozilla.org/en/products/firefox/firefox-news/in...

Re: Google’s nightmare “Web Integrity API” wants a DRM gatekeeper for the web

#137
post #53

Earlier quoted context omitted.

Care to share some examples?

Just talking about subcultures/communities that I've been a part of. Several of them only have a minimal presence on the public web, having moved to a network of private sites. A couple of them have assembled what amounts to a "shadow internet" that uses the internet for an encrypted communications channel but provides its own mailservers, IM servers etc. that don't interact with the internet proper. And, locally, th…

Are there people writing about this?

edit: I'm studying ways to facilitate decentralized decisionmaking in small permissioned networks.

Re: Google’s nightmare “Web Integrity API” wants a DRM gatekeeper for the web

#138

Earlier quoted context omitted.

I have never understood why Google has remained the esteemed vendor for a subset of technical users. They lost me more than a decade ago when they hoovered clear text passwords from their wifi scanning and blamed it on a single engineer.

Are you referring to Google Maps automobiles connecting to open WiFi networks? Because to be fair, those networks were wide open, and they were being advertised. I don't see how advertising an open WiFi network is much different from advertising an open house. In both cases you should expect visitors.

Ah yes, the “they were asking for it” defense.

Re: Google’s nightmare “Web Integrity API” wants a DRM gatekeeper for the web

#139

Earlier quoted context omitted.

I have never understood why Google has remained the esteemed vendor for a subset of technical users. They lost me more than a decade ago when they hoovered clear text passwords from their wifi scanning and blamed it on a single engineer.

Are you referring to Google Maps automobiles connecting to open WiFi networks? Because to be fair, those networks were wide open, and they were being advertised. I don't see how advertising an open WiFi network is much different from advertising an open house. In both cases you should expect visitors.

An open wifi network is akin to having the shades open or your door unlocked.

You can take advantage of it, but almost everyone is going to feel like it's not right unless they have consent.

An open house would be akin to have an open wifi network labeled "PleaseUseMe".

Re: Google’s nightmare “Web Integrity API” wants a DRM gatekeeper for the web

#140
post #91

> Google's plan is that, during a webpage transaction, the web server could require you to pass an "environment attestation" test before you get any data. There is no value in this "attestation" for me as a user. I want to be able to do whatever I want with the browser (for example, remove ads or block access to canvas and webgl) and I want sites to be unable to know this. And probably this attestation will provide a…

Ehhh, it depends. In theory one could imagine a scenario like a bank website refusing to be accessed unless the entire OS & browser stack pass attestation - as that would rule out things like keyloggers, malicious browser extensions, and session hijacking. In practice it'll just be used to lock down content and force unskippable ads on users, of course.

But that's not a direct value. I'm aware that reducing fraud for banks will potentially (bank behavior makes me doubt this) increase interest rates/decrease fees since they'll have less stolen money. I'm also aware that the current internet is built on free-as-in-beer services due to ads typically covering costs.

I'm not interested in being hobbled for either of those problems. I remember when banks used to reject my browser because it wasn't IE in Windows. I remember when I had to look at webpages that were 50% advertising.

Screw that.

Post reply on HN