Live data from Hacker News

Google’s nightmare “Web Integrity API” wants a DRM gatekeeper for the web

arstechnica.com

181–190 of 484 posts

Re: Google’s nightmare “Web Integrity API” wants a DRM gatekeeper for the web

#181
post #63

Earlier quoted context omitted.

> When Google can do something that every one of it's users hates I don't think this is remotely the case. Quite a few tech-savvy people I know (some of them software developers) use Chrome and mostly don't care about whatever Google does with it. I mention "manifest v3" and get a blank stare. I talk about advertising and ad blockers, and most people don't care, with some of them not even using ad blockers. We really…

> after all, Firefox is a perfectly viable alternative to Chrome that very few people use I don't use Firefox because it's slower than Chrome and because their behavior regarding limiting which extensions are available in phones, requiring signed extensions, Firefox Pocket, ads in new tab page, etc, does not exactly give me confidence that Mozilla truly has my interests in mind. In fact I bet they'll implement the ni…

Firefox may not be _as_ fast as Chrome, but it's a fairly negligible difference nowadays. rendering speed hasn't been a limiting factor for a while, and i feel like network latency and poor application optimization has been more the culprit there. you can only squeeze so much blood from the optimizing inefficient JS stone, and no amount of rendering engine optimization will ever fix shitty backend API response times

Firefox fails because there is no actual industry pressure to build a better browser. you simply can't sell a browser alone anymore: the free offerings have been good enough since the early 2000s.

Safari only needs to be good enough for iOS users to not abandon the platform entirely, and the ecosystem wants to push you into native apps anyway (Apple wants their IAP cut).

Chredge is, well, _there_, but basically just a minimum batteries included that maybe funnels some set of users into other Microsoft offerings, but it isn't the core product.

Chrome is, well, Chrome.

Firefox is comfortably supported by Google funding as an antitrust action shield. there's no real pressure for them to try and beat Chrome in market share because they're explicitly paid to be minority market share, and aren't really going to lose that share because they already have all of the "intentionally don't want to use Chrome" market. Mozilla faffs about making also-ran internet services (idk, whatever the heck that VPN offering was, etc.) because they fundamentally can't lose their main revenue stream so long as Google wants to avoid antitrust action, and have no real pressure to offer a competitive product.

Re: Google’s nightmare “Web Integrity API” wants a DRM gatekeeper for the web

#182

The use cases for the WEI proposal are pretty clear from the explainer ( https://github.com/RupertBenWiser/Web-Environment-Integrity/ ...): Google "will be able to request a token that attests key facts about the environment their client code is running in." Google "will ultimately decide if they trust the verdict returned from the attester." "Allow" Google "to evaluate the authenticity of the device and honest repre…

“There is a tension between utility for anti-fraud use cases requiring deterministic verdicts and high coverage, and the risk of websites using this functionality to exclude specific attesters or non-attestable browsers. We look forward to discussion on this topic, and acknowledge the significant value-add even in the case where verdicts are not deterministically available (e.g. holdouts).” See, don’t worry, they’re…

We look forward to discussion on this topic

Also known as "we'll read what the opponents say, and keep trying to poke them with convincing-sounding arguments until they surrender."

Re: Google’s nightmare “Web Integrity API” wants a DRM gatekeeper for the web

#183

> Google's plan is that, during a webpage transaction, the web server could require you to pass an "environment attestation" test before you get any data. There is no value in this "attestation" for me as a user. I want to be able to do whatever I want with the browser (for example, remove ads or block access to canvas and webgl) and I want sites to be unable to know this. And probably this attestation will provide a…

Attestation is a great concept for stuff you're in control of. Employee laptops, your own servers, your own phone, you name it. You want to be able to control and verify your devices are still under your control, preferably without manually entering the data center every week to check. The concept isn't inherently bad. That said, the concept is seemingly aimed at blocking ad blockers and preventing browsers like Brav…

> In practice this will just mean "no Firefox, no Linux, no adblockers"

And no curl, no yt-dlp or youtube-dl, no alternative YouTube frontends, no scraping the web to build an alternative search engine.

Re: Google’s nightmare “Web Integrity API” wants a DRM gatekeeper for the web

#184

Earlier quoted context omitted.

So if my front door is open, or my garage door is open, you feel you have the right to enter my home without permission?

If you are advertising that your door is unlocked, and the precedent is to enter unlocked doors - as it is to connect to open networks, then yes. Permission in such a scenario is implied. You make these analogies attempting to equate an advertised open WiFi network to an unlocked home, while ignoring the precedent around both of those things. It is expected that people connect to your advertised open WiFi network. It…

[deleted]

Re: Google’s nightmare “Web Integrity API” wants a DRM gatekeeper for the web

#185
post #58

Earlier quoted context omitted.

> Google's plan is that, during a webpage transaction, the web server could require you to pass an "environment attestation" test before you get any data. At this point your browser would contact a "third-party" attestation server, and you would need to pass some kind of test. If you passed, you would get a signed "IntegrityToken" that verifies your environment is unmodified and points to the content you wanted unloc…

Why is that? Who is forcing the free web to use this mechanism, since it is the server that requests the confirmation. Why can't it just... not?

All the websites demanding that I disable my adblocker say that they definitely will.

Re: Google’s nightmare “Web Integrity API” wants a DRM gatekeeper for the web

#186
post #120
post #70

Earlier quoted context omitted.

As hard as it may be, to paraphrase the ancient parable: The best time to break up Google was 10 years ago. The second-best time to break up Google is today.

You'll be very pleased to hear that it is going to happen soon with two antitrust cases against Google, one for search dominance [0] and the other for their ad business [1] with the former going to happen this year in September. So there is a start on that. So get a front row seat and get ready for what is to come in September this year to witness the beginning of the end of a company once adored by hundreds of techi…

I'll believe it when I see it.

Re: Google’s nightmare “Web Integrity API” wants a DRM gatekeeper for the web

#187

Earlier quoted context omitted.

You already get flagged as hazardous and uncool for not using https, even on a perfectly-static site. Some of us called that out as a slippery slope leading to ubiquitous gatekeeping, but we were shouted down in the name of (as usual) "security."

That is because without https, there is no guarantee that the site requested is bring delivered as the site intends. For example, an ISP could insert data or scripts into the page.

Let's rephrase that...

"That is because without Web Integrity, there is no guarantee that the site requested is being delivered as the site intends. For example, a browser extension could remove ads or modify content on the page."

See where this slippery slope is heading? We DO NOT want what "the site intends". We want to be in control of the content we consume.

Re: Google’s nightmare “Web Integrity API” wants a DRM gatekeeper for the web

#188

It honestly boggles the mind that the same company I used to respect twenty years ago has morphed into the evil monster that is modern Google. A tragic fall from grace.

These companies are merging with government. It's not about the ads.

Google has almost become a government, and one that we didn't explicitly vote for.

Re: Google’s nightmare “Web Integrity API” wants a DRM gatekeeper for the web

#189

Earlier quoted context omitted.

It doesn't matter. It's a DRM. If your version of the software doesn't contain the right keys none of this will work correctly. Kinda like how Widevine works. No keys means lower quality.

Don't you think people will inevitably crack the software side of things (as has been done with the lower levels of Widevine)? The end game is probably integration with a TPM that produces the token, or at least whatever part of it verifies that the chrome binary is genuine and that there is no forbidden software running on the client machine.

The end game is probably integration with a TPM that produces the token, or at least whatever part of it verifies that the chrome binary is genuine and that there is no forbidden software running on the client machine.

That is exactly the goal of this, and why it needs to be opposed fiercely.

Re: Google’s nightmare “Web Integrity API” wants a DRM gatekeeper for the web

#190

Seems like this is going to get a lot of pushback. It might not go through. But remember whether it goes through or not isn't the important thing. The fact that Google wants it to is what matters.

This feels like a reincarnation of Microsoft Halloween documents but all in the open... How corrupt our industry became that this doesn't cause the same uproar... Google truly morphed into what it fought in the beginning. https://en.wikipedia.org/wiki/Halloween_documents

It's literally a page from the Trusted Computing Platform. Even the names of the things are the same.
Post reply on HN