Live data from Hacker News

Web Environment Integrity API Proposal

github.com

181–190 of 460 posts

Re: Web Environment Integrity API Proposal

#181
post #136

Earlier quoted context omitted.

You can by not using Google products. Change the search for ddg or kagi. Change your email for proton. Use Dropbox instead. Remove Chrome, live with iceweasel or Firefox. It is not like you'll be loosing much. This is the time to change, while we still have other players in the market.

No, you can't - not until you get a significant part of the world's population to join your protest. The point is that if chrome implements this, netflix, amazon, facebook etc might decide they'll use this feature and only permit browsers who implement this to use this site. Even if the only browser that does so is chrome, that's fine because chrome's market share is big enough that they can ignore the rest. Have fun…

Protests aren't convenient, that's the entire point of them.

What, you think taking down the ad industry on the web is going to be painless?

Re: Web Environment Integrity API Proposal

#183

Earlier quoted context omitted.

> who is finally putting their foot down and deciding that we are all going to be forced to either used fully-locked down devices The person who wrote the proposal[0] is from Google. All the authors of the proposal are from Google[1]. I've been thinking carefully about this comment, but I really don't know what to say. It's absolutely heartbreaking watching something I really care about die by a thousand cuts; how do…

> how do we protest this? You do not and you cannot. It was written in stone once Chrome dominated the browser market. What Chrome (Google) wants, Chrome (Google) gets. Despite all the good engineering Google wants to sell ads, that's all there is to it. And the result is this proposal. > The saving grace here might be that Firefox won't implement the proposal. It's irrelevant and we are an irrelevant minority. Unles…

Defeatism is not necessarily realism.

There's a degree of saying no and opting out and controlling your own shit that you can do.

Some, like owning a phone and getting tracked to many degrees is inevitable but others, like software on a computer, is quite easy to think about.

You don't need to be a majority to go a different path. Linux users everywhere know this. We never needed the "year of the Linux desktop".

There's usually ways around the designated box. Obviously, get ready to be called names for not bowing down to authority... But you can ignore them and move on.

Re: Web Environment Integrity API Proposal

#184
post #92

Earlier quoted context omitted.

I doubt Apple will be our savior here. Apple is in a great position to implement this spec: their secure enclave and the systems they've developed around it are practically the state of the art. Also Apple is in bed w/ traditional media. (Apple News, Apple TV, iTunes, etc.) Microsoft has been doing the same[1] for years w/ Pluton on the Xbox to protect their IP. Google has been doing this on Android using, dm-verity,…

> Also Apple is in bed w/ traditional media. True. Try to screenshot anything from Apple TV+ content. You'll get a black image.

Screenshotting Apple TV+ works fine for me on desktop Chrome, even with hardware acceleration enabled. I don't recall doing anything to circumvent normal behavior (not really in the habit of screenshotting things I'm watching).

Re: Web Environment Integrity API Proposal

#185
Okay, the proposal is what it is but it doesn’t explain how the attestation is generated. So this would look into the underlying OS and decide if my computer is a real computer? And when it has doubts it displays some pictures and asks me which ones show bicycles?

Re: Web Environment Integrity API Proposal

#186

How can the “attesters” verify the integrity of the user agent? Sure the attestation is signed, but why can’t we mess with the data sent to the attester and just nullify the entire point of the proposal? The “browser acceptance criteria” in the spec, that would presumably contain this info, is just “TODO”. Thanks Google for conveniently omitting that key detail. Also interesting that its implied in the explainer that…

You don't send any data to the attester. It runs locally on your device, or rather is part of its core functionality. Building a chain of trust from the TPM hardware module, validating secure boot is enabled, validating the kernel and drivers have not been tampered with, eventually validating the browser has not been tampered with.

You can't run your own attester - these are implemented by the companies who provide the hardware, such as Microsoft or Apple.

Re: Web Environment Integrity API Proposal

#187
post #59

What's strange to me is that the main author of the spec -- Ben Wiser -- seems to be against closed, wall-garden paradigms as he has written in a blog post "I just spent £700 to have my own app on my iPhone" [1]. In the post, he laments the state of the App Store monopoly on iOS and ponders returning to Android for the app installation freedom. How can he reconciliate these views with this spec, which he is the main…

A good explanation of how he would reconcile his proposal and the ideas he's previously expressed: https://github.com/RupertBenWiser/Web-Environment-Integrity/...

Re: Web Environment Integrity API Proposal

#188
post #134
post #125

Earlier quoted context omitted.

But the chance of a web page actually needing that functionality to render at all is rare for hopefully-obvious reasons. The status quo is that progressive enhancement is dead: a few-year old copy of Safari can now simply not browse much of the web anymore because it is missing some corner case of CSS or web components or whatever: I often am stuck at loading spinners or are simply thrown into a blank page... the bes…

> But the chance of a web page actually needing that functionality to render at all is rare for hopefully-obvious reasons. The chance of a page using something has no bearing on how dificault something is to implement. > People get upset about WebUSB... but that's not the API surface that is causing us issues. It's one of the hundreds of APIs, and yes, it causes issues, too. Because it also needs to be implemented, a…

No: it doesn't need to be implemented unless you actually want to do something with USB. Random websites aren't not working because you don't support USB. My iPhone doesn't support WebUSB even if I updated its firmware.

Re: Web Environment Integrity API Proposal

#189
post #5

This is pretty much the inevitable end-game of the web, in no small part funded by ad-based business models (as the analog gap pretty much destroys most attempts to use this stuff to do copy protection) and enabled by developers who have insisted we shove as much difficult-to-implement functionality (by which I am talking about CSS complex stuff, not powerful-but-easy-to-code APIs for OS-level access) into the browse…

> who is finally putting their foot down and deciding that we are all going to be forced to either used fully-locked down devices The person who wrote the proposal[0] is from Google. All the authors of the proposal are from Google[1]. I've been thinking carefully about this comment, but I really don't know what to say. It's absolutely heartbreaking watching something I really care about die by a thousand cuts; how do…

Protest is easy and involves the ADA and COPPA.

1) You cannot all of a sudden provision content differently to a user who has an unapproved device with their preferred accessibility stack and/or hardware.

2) Even if attestation does not involve tracking, effectively forcing children into an ecosystem that tracks them can be deemed unlawful by the FTC. Providers cannot foreclose all means of access to content that are not in a tracking ecosystem, because it violates the rights of children.

The proposal is probably legally negligent because it does not exercise the ordinary standard of care expected of senior technologists. Providing a tool that affects hundreds of million of children and people with disabilities is not a joke.

Re: Web Environment Integrity API Proposal

#190
post #7

The literal attempt to censor web usage of Linux and BSD desktops, other FOSS clients, custom Android ROMs, etc with an open reasoning "to sell you ads". They don't even try to masquerade it.

I mean, to be fair, that's their entire modus operandi. You don't berate a kitchen for serving food, why would you look at any Google contraption from HTTP/3 to Chrome as anything but a vehicle for selling ads and/or mining data?

Google are clearly trying to add levels of indirection here to pretend it’s some kind of standards forming, instead of a dictatorship. There’s nothing “to be fair” about.
Post reply on HN