Live data from Hacker News

Google’s nightmare “Web Integrity API” wants a DRM gatekeeper for the web

arstechnica.com

141–150 of 484 posts

Re: Google’s nightmare “Web Integrity API” wants a DRM gatekeeper for the web

#141

Earlier quoted context omitted.

Are you referring to Google Maps automobiles connecting to open WiFi networks? Because to be fair, those networks were wide open, and they were being advertised. I don't see how advertising an open WiFi network is much different from advertising an open house. In both cases you should expect visitors.

An open wifi network is akin to having the shades open or your door unlocked. You can take advantage of it, but almost everyone is going to feel like it's not right unless they have consent. An open house would be akin to have an open wifi network labeled "PleaseUseMe".

I disagree. An open WiFi network that is not being advertised would be similar to leaving a door unlocked or the shades open. When that network is actively advertised it ceases to be an open blind, and moves into open house territory.

Re: Google’s nightmare “Web Integrity API” wants a DRM gatekeeper for the web

#142

Surprising even myself, I actually like this proposal. It does two things, one which is good, and the other which is not as bad as people are saying. The good thing is to give browsers a way to attest to their inviolability to systems on the other end. This is generally useful! In particular, it opens up a huge potential for people to run what are effectively servers in their browsers - which was TBL's vision for the…

Yeah. And good luck with figuring out what went wrong with your attestation when it does not work. Famous google support.

Re: Google’s nightmare “Web Integrity API” wants a DRM gatekeeper for the web

#143
post #63

Earlier quoted context omitted.

> When Google can do something that every one of it's users hates I don't think this is remotely the case. Quite a few tech-savvy people I know (some of them software developers) use Chrome and mostly don't care about whatever Google does with it. I mention "manifest v3" and get a blank stare. I talk about advertising and ad blockers, and most people don't care, with some of them not even using ad blockers. We really…

I don't see a huge difference between Firefox and Chrome these days, as they implement everything Google tells them to (and pays them to)

I can still block content in any way I see fit on Gecko-based applications, not so much on Blink-based things. There are many things about Firefox-the-browser and Mozilla-the-organisation which could do with an overhaul but as it stands it is still my go-to browser. I only use Blink-based things to test and for those (annoying) sites which insist on it in which case I first try Bromite, then Ungoogled Chromium. If it still does not work it is not worth visiting. I do not have Chrome installed on any device and have never felt I was missing out.

Re: Google’s nightmare “Web Integrity API” wants a DRM gatekeeper for the web

#144

Surprising even myself, I actually like this proposal. It does two things, one which is good, and the other which is not as bad as people are saying. The good thing is to give browsers a way to attest to their inviolability to systems on the other end. This is generally useful! In particular, it opens up a huge potential for people to run what are effectively servers in their browsers - which was TBL's vision for the…

Do you know how rooting Android is basically useless nowadays? Most banking and government apps, at least in my country, don't work if Google didn't give the seal of approval for your system. I take it you see as good thing to bring this to the browser as well, because this somehow has to do "personal computer advocacy"? It literally cripples the users' devices.

I don't see the connection between Chrome attestation and Android attestation. A computer has only one operating system (in general) but many browsers. I see some value in attesting to a "pristine" browser environment to any application developer, as it removes a wide array of error modes (particularly useful if you have a weak or underfunded team).

Now, if the application provider chooses not to support the alternatives, I'd argue that's on the app provider (the bank and gov apps). And again, perhaps the best thing is to NOT USE THOSE KINDS OF APPS ON A PHONE. I am very concerned that people are essentially locked out of essential services if they don't have a smartphone and a working SIM card. After all "the best way to repeal an imperfect law is to enforce it perfectly."

I'm not Nostradamus; but I'm hopeful that if Google goes down this path that it will hasten the end of a wide variety of error modes in the world. Of course that may be putting a little too much faith in neoliberal capitalism, to come up with alternatives that aren't smothered in the cradle.

Re: Google’s nightmare “Web Integrity API” wants a DRM gatekeeper for the web

#146
post #32

> Exactly how the rest of the world feels about this is not necessarily relevant, though. Google owns the world's most popular web browser, the world's largest advertising network, the world's biggest search engine, the world's most popular operating system, and some of the world's most popular websites. So really, Google can do whatever it wants. This is the point that company breakups start to make a lot of sense.…

This line is what makes me roll my eyes whenever I hear someone say "Safari is the new IE". Safari missing a couple of features few websites use is far less of an issue than the dominant browser company can just invent new "standards" that make the web actively worse for everyone. (Sorry, I should say "everyone except for the scummy advertisers".)

Re: Google’s nightmare “Web Integrity API” wants a DRM gatekeeper for the web

#148
post #118

They're going to prevent me from running an adblocker in this "web integrity" environment, aren't they.

That makes zero sense. If they ever did that they would lose all their market share overnight, and they know that. Google has always been good about letting people have full control over their devices, despite building incredibly locked down UX. It would be trivial for them to build a Chromebook, or Android phone, or browser that you can't flip into dev mode, but they've never done that, even though many of their com…

That is what would happen if they made adblocking impossible in chrome today, minus all the people who don't use AdBlock and happen to be numerous enough to be Google's entire business.

In a world with attestation, you can't browse any website unless you are using Chrome or another attested browser. The New York Times would refuse to serve content to unattested user agents. That is what would make everyone use Chrome.

Re: Google’s nightmare “Web Integrity API” wants a DRM gatekeeper for the web

#149

Earlier quoted context omitted.

An open wifi network is akin to having the shades open or your door unlocked. You can take advantage of it, but almost everyone is going to feel like it's not right unless they have consent. An open house would be akin to have an open wifi network labeled "PleaseUseMe".

I disagree. An open WiFi network that is not being advertised would be similar to leaving a door unlocked or the shades open. When that network is actively advertised it ceases to be an open blind, and moves into open house territory.

So if my front door is open, or my garage door is open, you feel you have the right to enter my home without permission?

Re: Google’s nightmare “Web Integrity API” wants a DRM gatekeeper for the web

#150
post #71

Earlier quoted context omitted.

For the vast majority of people, the internet is the web, as well as mobile apps. The latter are already out of the control of users. Today, we at least have browsers that we can mostly force to do what we want (like stop downloading and displaying ads), but WEI will end up restricting portions of the web to users running browsers that do what the web servers want, not what their users want. And for most people in th…

The current browser stack is a lost cause. There's just no way for anyone who cares to compete with Google. But we still have TCP and HTTP. We will rebuild this place.

HTTP is terrible though. It's a big part of the problem with the web.
Post reply on HN