Live data from Hacker News

Google’s nightmare “Web Integrity API” wants a DRM gatekeeper for the web

arstechnica.com

161–170 of 484 posts

Re: Google’s nightmare “Web Integrity API” wants a DRM gatekeeper for the web

#161

Seems like this is going to get a lot of pushback. It might not go through. But remember whether it goes through or not isn't the important thing. The fact that Google wants it to is what matters.

This feels like a reincarnation of Microsoft Halloween documents but all in the open... How corrupt our industry became that this doesn't cause the same uproar... Google truly morphed into what it fought in the beginning.

https://en.wikipedia.org/wiki/Halloween_documents

Re: Google’s nightmare “Web Integrity API” wants a DRM gatekeeper for the web

#162
post #118

They're going to prevent me from running an adblocker in this "web integrity" environment, aren't they.

That makes zero sense. If they ever did that they would lose all their market share overnight, and they know that. Google has always been good about letting people have full control over their devices, despite building incredibly locked down UX. It would be trivial for them to build a Chromebook, or Android phone, or browser that you can't flip into dev mode, but they've never done that, even though many of their com…

Chrome for Android _already_ doesn't let you use an adblocker, and it has a pretty high share in the mobile market.

Re: Google’s nightmare “Web Integrity API” wants a DRM gatekeeper for the web

#163

Earlier quoted context omitted.

I disagree. An open WiFi network that is not being advertised would be similar to leaving a door unlocked or the shades open. When that network is actively advertised it ceases to be an open blind, and moves into open house territory.

So if my front door is open, or my garage door is open, you feel you have the right to enter my home without permission?

If you are advertising that your door is unlocked, and the precedent is to enter unlocked doors - as it is to connect to open networks, then yes. Permission in such a scenario is implied.

You make these analogies attempting to equate an advertised open WiFi network to an unlocked home, while ignoring the precedent around both of those things.

It is expected that people connect to your advertised open WiFi network. It is not expected that people wiggle your doorknob to check if it's unlocked or not. If you put a sign on the door advertising, "the door is unlocked!" then I wouldn't be surprised when someone mistakes that for "come in".

Re: Google’s nightmare “Web Integrity API” wants a DRM gatekeeper for the web

#164

I've been reading HN since its birth and have been in the browser game for 25 years. HN, as a collective, shit all over Firefox and Mozilla for a decade while Google, who was never going to to anything but this, did just this. Good job.

There's not necessarily a contradiction here—both companies can be completely screwed up at the same time.

Re: Google’s nightmare “Web Integrity API” wants a DRM gatekeeper for the web

#165
"The explainer is authored by four Googlers, including at least one person on Chrome's "Privacy Sandbox" team, which is responding to the death of tracking cookies by building a user-tracking ad platform right into the browser."

Mr Amadeo does a good job succinctly explaining the explainer.

Re: Google’s nightmare “Web Integrity API” wants a DRM gatekeeper for the web

#166
post #63

Earlier quoted context omitted.

> When Google can do something that every one of it's users hates I don't think this is remotely the case. Quite a few tech-savvy people I know (some of them software developers) use Chrome and mostly don't care about whatever Google does with it. I mention "manifest v3" and get a blank stare. I talk about advertising and ad blockers, and most people don't care, with some of them not even using ad blockers. We really…

> after all, Firefox is a perfectly viable alternative to Chrome that very few people use I don't use Firefox because it's slower than Chrome and because their behavior regarding limiting which extensions are available in phones, requiring signed extensions, Firefox Pocket, ads in new tab page, etc, does not exactly give me confidence that Mozilla truly has my interests in mind. In fact I bet they'll implement the ni…

Mozilla just took position against this DRM API: https://github.com/mozilla/standards-positions/issues/852#is...

Also, Firefox just passed ahead of Chrome on some JS speed benchmark, so you should get ready to switch back!

Re: Google’s nightmare “Web Integrity API” wants a DRM gatekeeper for the web

#167
post #58

Earlier quoted context omitted.

Why is that?

> Google's plan is that, during a webpage transaction, the web server could require you to pass an "environment attestation" test before you get any data. At this point your browser would contact a "third-party" attestation server, and you would need to pass some kind of test. If you passed, you would get a signed "IntegrityToken" that verifies your environment is unmodified and points to the content you wanted unloc…

> If we're at the point where you need to get permisssion and approval to verify that the platform you're using is acceptable

I guess it has been the case from the good old CGI era? I do remember all those private forums that required me to wait for several days until they can "verify" my identity and "approve" my registration. The control always has been at the hand of platform. The difference is that now attacks are much more sophisticated (GPT-4 powered!), while defense line is left at a pretty miserable state.

Re: Google’s nightmare “Web Integrity API” wants a DRM gatekeeper for the web

#168
post #35
post #31

While I don't love this API's idea, I understand why they're doing it, and the API it describes really just sounds like any Captcha API today. > Google's plan is that, during a webpage transaction, the web server could require you to pass an "environment attestation" test before you get any data. At this point your browser would contact a "third-party" attestation server, and you would need to pass some kind of test.…

If you liked that idea, you may love "Privacy Pass" by Cloudflare: https://chrome.google.com/webstore/detail/privacy-pass/ajhmf...

This deserves it's own post.

Re: Google’s nightmare “Web Integrity API” wants a DRM gatekeeper for the web

#169
post #86
post #63

Earlier quoted context omitted.

> When Google can do something that every one of it's users hates I don't think this is remotely the case. Quite a few tech-savvy people I know (some of them software developers) use Chrome and mostly don't care about whatever Google does with it. I mention "manifest v3" and get a blank stare. I talk about advertising and ad blockers, and most people don't care, with some of them not even using ad blockers. We really…

> We really live in a bubble, here on HN. Multiple bubbles on HN. Obviously, most of us are complicit in some techbro business conventions today that, 30 years ago, would've gotten us shunned by our peers, and reported to the authorities. (Not that current phenomena weren't foreseen. SF writers had already been all over it. Anecdotally, Internet-savvy techies were often informed by various forward-looking thinking an…

Even in 1985, there was the RISKS list... and it's still around.

Archive: https://catless.ncl.ac.uk/Risks/

So much of our current hellscape was foretold long ago.

Re: Google’s nightmare “Web Integrity API” wants a DRM gatekeeper for the web

#170
post #63

Earlier quoted context omitted.

> When Google can do something that every one of it's users hates I don't think this is remotely the case. Quite a few tech-savvy people I know (some of them software developers) use Chrome and mostly don't care about whatever Google does with it. I mention "manifest v3" and get a blank stare. I talk about advertising and ad blockers, and most people don't care, with some of them not even using ad blockers. We really…

I don't buy this. I'm sure most iphone users don't care when you ask them about privacy or manifest v3 as an abstract concept, but remember what happened when Apple tried to push a U2 album to them? They lost their collective shit. They may not write blog posts about privacy or donate to the EFF, but they have deeply personal relationships with "their" phone and they absolutely hate being reminded that it isn't reall…

>when Apple tried to push a U2 album to them? They lost their collective shit

and that's exactly it. putting something in your music library is a hugely more visible and tangible thing than all the nebulous privacy concerns the internet wants me to be afraid of. nobody gives a shit if google or apple or facebook or whoever else introduces some techical measure that could be used for nefarious things. they only care if that api is actually used for nefarious things. as long as the argument is "well if google implements X, then it would potentially allow them to do Y*, that's a failing argument.

like it or not, people actually do trust the big tech companies. as long as they aren't actively abusing that trust in ways that people care about, things like "google wants to know if you're a real person or a bot" aren't going to cause a whole lot of outrage. most people can understand that letting fake people pretend to be real is bad, and that preventing that is probably a good thing.

Post reply on HN