Google Chrome Proposal – Web Environment Integrity
21–30 of 99 posts
Re: Google Chrome Proposal – Web Environment Integrity
#22Lots of people doom and gloom here about threats to user privacy and freedom. This is the one I'd be worried about. Thought it was annoying to not be able to use banking apps on a rooted Android? Think about how annoying it will be when you can't do much of anything, even on the Web, unless it's from a sealed, signed Apple/Google/Microsoft image-based OS... I realize the way Firefox's user share is going, it might no…
Wouldn't it be great if you never had to deal with another captcha?
Re: Google Chrome Proposal – Web Environment Integrity
#23Re: Google Chrome Proposal – Web Environment Integrity
#24Earlier quoted context omitted.
Bot traffic? Anyone using Linux will get blocked because "they can't be trusted". Only people running an "approved" operating system from a billion dollar corporation will be allowed to access. This is already what is happening with SafetyNet on Android. For now most applications don't require hardware attestation so you can pass by spoofing an old device that didn't support hardware attestation but I'm sure that wil…
You don't have to be a billion dollar corporation to become Play Protect certified. Being able to trust the security of a client can protect against many attacks and it is up to web sites to evaluate what to do with into information that a client is proven to be secure.
SafetyNet means the app checks to make sure you're not rooted or running a custom ROM because those are considered a security risk. If you are not running a locked-down OEM ROM, you can't run many apps including banking apps.
Microsoft's Pluton on-CPU attestation technology means this is coming to PCs.
Re: Google Chrome Proposal – Web Environment Integrity
#25Lots of people doom and gloom here about threats to user privacy and freedom. This is the one I'd be worried about. Thought it was annoying to not be able to use banking apps on a rooted Android? Think about how annoying it will be when you can't do much of anything, even on the Web, unless it's from a sealed, signed Apple/Google/Microsoft image-based OS... I realize the way Firefox's user share is going, it might no…
Re: Google Chrome Proposal – Web Environment Integrity
#26Lots of people doom and gloom here about threats to user privacy and freedom. This is the one I'd be worried about. Thought it was annoying to not be able to use banking apps on a rooted Android? Think about how annoying it will be when you can't do much of anything, even on the Web, unless it's from a sealed, signed Apple/Google/Microsoft image-based OS... I realize the way Firefox's user share is going, it might no…
Safari, rather than Firefox, might be only actor with the market share and motivation to drag out the implementation and adoption of this proposal.
Re: Google Chrome Proposal – Web Environment Integrity
#27Earlier quoted context omitted.
Bot traffic? Anyone using Linux will get blocked because "they can't be trusted". Only people running an "approved" operating system from a billion dollar corporation will be allowed to access. This is already what is happening with SafetyNet on Android. For now most applications don't require hardware attestation so you can pass by spoofing an old device that didn't support hardware attestation but I'm sure that wil…
You don't have to be a billion dollar corporation to become Play Protect certified. Being able to trust the security of a client can protect against many attacks and it is up to web sites to evaluate what to do with into information that a client is proven to be secure.
- What is the least expensive device that can be certified like that? The least expensive process?
- What is the highest level of openness such a device can offer to the user, and why?
To my mind, it would be best to have an option of a completely locked down and certified hardware token, a device like a Yubikey, that could talk to my laptop, desktop, phone, or any other computing device using a standard protocol. As long as it's unforgeable, the rest of the system can be much. much less secure, without compromising the overall security.
Re: Google Chrome Proposal – Web Environment Integrity
#28Lots of people doom and gloom here about threats to user privacy and freedom. This is the one I'd be worried about. Thought it was annoying to not be able to use banking apps on a rooted Android? Think about how annoying it will be when you can't do much of anything, even on the Web, unless it's from a sealed, signed Apple/Google/Microsoft image-based OS... I realize the way Firefox's user share is going, it might no…
Do you realize the amount of work that Google has put in over the years to provide Linux support for Google Chrome? Why would they suddenly about face on that? Wouldn't it be great if you never had to deal with another captcha?
Re: Google Chrome Proposal – Web Environment Integrity
#29Earlier quoted context omitted.
You don't have to be a billion dollar corporation to become Play Protect certified. Being able to trust the security of a client can protect against many attacks and it is up to web sites to evaluate what to do with into information that a client is proven to be secure.
Play Protect is different from SafetyNet. SafetyNet means the app checks to make sure you're not rooted or running a custom ROM because those are considered a security risk. If you are not running a locked-down OEM ROM, you can't run many apps including banking apps. Microsoft's Pluton on-CPU attestation technology means this is coming to PCs.
Keep it powered down when not needed for extra security.
Idealy, it could be smaller than a smartphone, and use smartphone's or laptop's hardware for UI and networking.
Re: Google Chrome Proposal – Web Environment Integrity
#30"Don't be evil" has really turned into "Google is evil"