Live data from Hacker News

Web Environment Integrity API Proposal

github.com

171–180 of 460 posts

Re: Web Environment Integrity API Proposal

#171

This seems like a very believable parody. Particularly given the 'spec.bs' filename which looks like it's just markdown.

I don't know what ".bs" denotes, and I cannot find anything relevant on Just Solve The File Format Problem.

Most likely https://github.com/speced/bikeshed

Re: Web Environment Integrity API Proposal

#172
post #93

Earlier quoted context omitted.

No, it's similar to attestation APIs like android SafetyNet (now called Play Integrity API) that are used to check that "your ROM is valid according to Google". Secure boot can protect you eg. against malware gaining write access and modifying your system. I see it as user protection, as long as you can sign the trust chain. This is what GrapheneOS is doing as far as I know.

A trust chain beginning at the bootloader is what will ultimately enable this API, though, because that's what SafetyNet/Play Integrity API relies on. If you don't have a locked bootloader, or you're not running stock Android, you won't pass SafetyNet/Play Integrity (at least the higher tiers of it). To take your GrapheneOS example, apps wishing to support it must add GrapheneOS keys: https://grapheneos.org/articles/…

I don't disagree with you, but let's not throw away secure boot because Google found a way to ruin it!

Re: Web Environment Integrity API Proposal

#173
post #136

Earlier quoted context omitted.

You can by not using Google products. Change the search for ddg or kagi. Change your email for proton. Use Dropbox instead. Remove Chrome, live with iceweasel or Firefox. It is not like you'll be loosing much. This is the time to change, while we still have other players in the market.

No, you can't - not until you get a significant part of the world's population to join your protest. The point is that if chrome implements this, netflix, amazon, facebook etc might decide they'll use this feature and only permit browsers who implement this to use this site. Even if the only browser that does so is chrome, that's fine because chrome's market share is big enough that they can ignore the rest. Have fun…

[deleted]

Re: Web Environment Integrity API Proposal

#174
Are they trying really hard to shoot themselves in the foot?

Google needs to stop this bullshit start innovating again. First AMP, now this? Leave the web alone!

Where's the Google that makes great web applications with simple, great UX, like Maps, Gmail, Drive and Search (which has severely degraded)?

Or great tools like Go, Lighthouse and Devtools?

Disappointing!

It's like they're trying really hard to be the villain.

Re: Web Environment Integrity API Proposal

#175
post #127

Earlier quoted context omitted.

What exactly is Mozilla even competing for? Popularity? Mozilla's revenue is proportional to usage so they need enough users to cover their development costs.

If only the wikimedia foundation would fork firefox, then the open web might have a chance. Wikimedia is honestly the only organization with the right ideology, the right business model, and enough money to do something like this sustainably.

I thought Wikimedia was quite shady itself when it comes to funding and money management?

Re: Web Environment Integrity API Proposal

#176
post #31

I can't help but see this as evil. Giving more control to corporations and less control to individuals.

I highly doubt it, but I wonder if this will be the straw that breaks the camels back where general perception of Google flips to where they are viewed in the same circle as Comcast or EA.

Google is heading in that direction and their velocity is accelerating.

Re: Web Environment Integrity API Proposal

#177
post #72

It's time to break Google up. They're the AT&T and Standard Oil of our generation. Make Ads, YouTube, Search, Cloud, Chrome, etc. all independent companies. Demand that antitrust regulators do their damn jobs for a change.

Only if you throw Apple, Microsoft and Meta into the grinder as well. Our regulators are fully captured and have been for some time.

Absolutely, and more besides.

Re: Web Environment Integrity API Proposal

#178
post #59

What's strange to me is that the main author of the spec -- Ben Wiser -- seems to be against closed, wall-garden paradigms as he has written in a blog post "I just spent £700 to have my own app on my iPhone" [1]. In the post, he laments the state of the App Store monopoly on iOS and ponders returning to Android for the app installation freedom. How can he reconciliate these views with this spec, which he is the main…

And he uses a Linux laptop!

> Apple’s strategy with this is obvious, and it clearly works, but it still greatly upsets me that I couldn’t just build an app with my linux laptop.

Ben, you've thought about the impact your proposal would have on Linux laptop users, right? Surely you sometimes use your laptop for banking, right?

Re: Web Environment Integrity API Proposal

#179

Earlier quoted context omitted.

If only the wikimedia foundation would fork firefox, then the open web might have a chance. Wikimedia is honestly the only organization with the right ideology, the right business model, and enough money to do something like this sustainably.

I thought Wikimedia was quite shady itself when it comes to funding and money management?

Mozilla and Wikimedia both have a reputation for wasting money by trying to branch out beyond their main product. Wikimedia is totally overfunded so wasting money doesn't threaten their survival but they've also been criticized for begging for donations that they don't need. Personally I don't see a reason to combine them.

Re: Web Environment Integrity API Proposal

#180
How can the “attesters” verify the integrity of the user agent? Sure the attestation is signed, but why can’t we mess with the data sent to the attester and just nullify the entire point of the proposal? The “browser acceptance criteria” in the spec, that would presumably contain this info, is just “TODO”. Thanks Google for conveniently omitting that key detail.

Also interesting that its implied in the explainer that attesters are just HTTP endpoint dealing with “billion-qps” traffic. Again, point above, but also how can we trust any attester to not use the (completely unobfuscated) information the user agent is sending them?

I guarantee that big websites will host their own attesters, only allow use of their attester, and require attestation for every request, allowing them to fingerprint every single user.

Post reply on HN