Live data from Hacker News

Google’s nightmare “Web Integrity API” wants a DRM gatekeeper for the web

arstechnica.com

201–210 of 484 posts

Re: Google’s nightmare “Web Integrity API” wants a DRM gatekeeper for the web

#201

Earlier quoted context omitted.

> after all, Firefox is a perfectly viable alternative to Chrome that very few people use I don't use Firefox because it's slower than Chrome and because their behavior regarding limiting which extensions are available in phones, requiring signed extensions, Firefox Pocket, ads in new tab page, etc, does not exactly give me confidence that Mozilla truly has my interests in mind. In fact I bet they'll implement the ni…

uBlock Origin doesn't work on mobile Chrome. I don't understand this perspective. At the very least you would want to use an alternative Chromium browser on Android, even if you weren't willing to install Firefox. You're upset about not being able to run every extension and so you're running none of them? Look, I will absolutely criticize Mozilla for some of its policies. Pretty much every issue you've raised there i…

> uBlock Origin doesn't work on mobile Chrome.

That's true, I was talking about desktop, I probably should have not mentioned the phone extension thing.

In Android I use Bromite (a Chromium fork) which I should probably replace since it's fairly outdated at this point.

But you're wrong about me not using Firefox out of spite, the real reason I don't use it is because it is (or apparently was according to the other replies) slower to the point it is noticeable, at least on my desktop (and even more so on my old phone). The rest is just why I don't support them despite being worse.

Re: Google’s nightmare “Web Integrity API” wants a DRM gatekeeper for the web

#202

Earlier quoted context omitted.

> after all, Firefox is a perfectly viable alternative to Chrome that very few people use I don't use Firefox because it's slower than Chrome and because their behavior regarding limiting which extensions are available in phones, requiring signed extensions, Firefox Pocket, ads in new tab page, etc, does not exactly give me confidence that Mozilla truly has my interests in mind. In fact I bet they'll implement the ni…

Mozilla just took position against this DRM API: https://github.com/mozilla/standards-positions/issues/852#is... Also, Firefox just passed ahead of Chrome on some JS speed benchmark, so you should get ready to switch back!

That's nice to know, I'll give it a try soon then!

Re: Google’s nightmare “Web Integrity API” wants a DRM gatekeeper for the web

#203

I've been thinking about this for a few days but just realized that this is a complete end run around all web scraping in general. All 'adversarial compatibility' from projects like Nitter, Teddit, Invidious, and youtube-dl go out the window. Any archive site (archive.org, archive.ph, etc.) can be blocked by sites requiring attestation. And just like the book industry was terrified of piracy and were 'rescued' by Kin…

Any archive site (archive.org, archive.ph, etc.) can be blocked by sites requiring attestation. What will happen if such a thing actually happens is that the underground market for "trusted device" farms grows, not too different from what's currently already happening but possibly at a far larger scale. Of course, that means the financially motivated scraping services still keep going while the honest individuals wan…

This has been happening already. The market is trying really hard to price out web scraping through scraper detection technologies and it's kinda working - scraping is becoming non-existent in user-space apps. It's also extremely discriminatory. Try running a single scrape with a developing country's IP and Linux, you'll be blocked at TLS step lol

Re: Google’s nightmare “Web Integrity API” wants a DRM gatekeeper for the web

#204

Earlier quoted context omitted.

More importantly, a company of the size, scope and sophistication of Google trying to hide its fundamental redefinition of how people access the web, behind “it’s only a technical change” is unacceptable. As if something with multiple downstream non-technical effects, is only a technical change As if you can minimize and dismiss everyone’s fears and concerns as hollow, invalid and irrelevant by waving the magic wand…

This defies my Occam's Razor view. You seem to be assuming Google is an extremely well connected organism with vast coherency: each limb knows what the others are doing, they are working together in close fashion, & doing things for ulterior motives. This is such a horrific & bastardly case - of creating unparalleld rank awfulness hither-to-fore unimaginable - that I am tempted to agree. And I do think there probably…

No, I’m using Google rhetorically. Sure you could be more specific and say the Google Chrome team, or whoever is actually discretionary responsible for this, and the chain of command that authorizes them with that power within the org… but I think, bothering with such specifics would make the message less effective so I didn’t.

Also, I don’t think it’s necessary. Google is responsible for whatever its parts are doing; a corporate entity. And people are right to expect that if they get something from Google then it’s caused by Google.

Also, I think it’s wrong and too early to be diluting or shielding Google behind the pedantic hairsplitting that, “oh you see it’s not actually google at fault here, um, it was probably some guy that works in a basement somewhere, you know, his views not reflected by ours and so on…” it’s not necessary to provide them that shield or confusion at this stage.

He may work at google, you may work at Google, I may work at google; we don’t know. And it’s not important. What’s important is that Google is at fault here. (I don’t btw)

Magnitude of the malfeasance is so great they deserve to be held to account for it, and a simple label of Google is sufficient.

Also, Occam’s razor? I think it’s unnecessary to invoke the preposterously exaggerated strawman of some ghastly and convoluted conspiracy here, when their actions directly align with, and can be efficiently implemented by, their business. It’s a simple thesis: Google is at fault and they meant to do it. They know it’s bad and therefore are selling it deceptively.

It’s neither convoluted nor complex in any way. In fact, if they’d tried to engage with this technically in a way that accounted for acknowledged and respected the fears and concerns people raised in response, then I think they would’ve ended up with a solution that is more convoluted, and complex. In this we have the curse of simple evil.

I think it’s drinking the gaslit Kool-Aid to pretend “oh no, it’s an accident, it’s incompetence, they didn’t mean to.” This is directly (if harmfully and unethically) supporting their business interests. They meant to do it. That’s the simplest explanation. That’s Occam’s razor.

Re: Google’s nightmare “Web Integrity API” wants a DRM gatekeeper for the web

#205
post #32

> Exactly how the rest of the world feels about this is not necessarily relevant, though. Google owns the world's most popular web browser, the world's largest advertising network, the world's biggest search engine, the world's most popular operating system, and some of the world's most popular websites. So really, Google can do whatever it wants. This is the point that company breakups start to make a lot of sense.…

Google owns the world's most popular web browser, the world's largest advertising network, the world's biggest search engine, the world's most popular operating system, and some of the world's most popular websites.

Their hold on these claims are extremely tenuous. No one would be surprised if Firefox, Bing, or iOS resurged and killed Google’s offering, for example.

Re: Google’s nightmare “Web Integrity API” wants a DRM gatekeeper for the web

#206

The people involved in this concept/idea/proposal should be shamed into retirement. They should never work in the tech sector again. They should be afraid to use their names before first knowing their audience (an agricultural audience would likely be OK).

It's really perplexing how people in such privilidged positions would put their name on this. Either their not as smart as they appear or somehow manipulated/corrupted.

Re: Google’s nightmare “Web Integrity API” wants a DRM gatekeeper for the web

#207

I've been thinking about this for a few days but just realized that this is a complete end run around all web scraping in general. All 'adversarial compatibility' from projects like Nitter, Teddit, Invidious, and youtube-dl go out the window. Any archive site (archive.org, archive.ph, etc.) can be blocked by sites requiring attestation. And just like the book industry was terrified of piracy and were 'rescued' by Kin…

Any archive site (archive.org, archive.ph, etc.) can be blocked by sites requiring attestation. What will happen if such a thing actually happens is that the underground market for "trusted device" farms grows, not too different from what's currently already happening but possibly at a far larger scale. Of course, that means the financially motivated scraping services still keep going while the honest individuals wan…

Basically the captcha solving industry.

Re: Google’s nightmare “Web Integrity API” wants a DRM gatekeeper for the web

#208

Earlier quoted context omitted.

uBlock Origin doesn't work on mobile Chrome. I don't understand this perspective. At the very least you would want to use an alternative Chromium browser on Android, even if you weren't willing to install Firefox. You're upset about not being able to run every extension and so you're running none of them? Look, I will absolutely criticize Mozilla for some of its policies. Pretty much every issue you've raised there i…

> uBlock Origin doesn't work on mobile Chrome. That's true, I was talking about desktop, I probably should have not mentioned the phone extension thing. In Android I use Bromite (a Chromium fork) which I should probably replace since it's fairly outdated at this point. But you're wrong about me not using Firefox out of spite, the real reason I don't use it is because it is (or apparently was according to the other re…

Will you at least consider switching to a DeGoogled Chromium fork? Yes, it would still be the same browser engine, but there are a lot of features in Chrome proper that Google uses to help contribute to its ad network and data collection.

Re: Google’s nightmare “Web Integrity API” wants a DRM gatekeeper for the web

#209

I'll add to this, notably, issues are still closed after the weekend: https://github.com/RupertBenWiser/Web-Environment-Integrity/... If this proposal gets rejected it'll be because of feedback in the press that is impossible to ignore. My experience watching how Google has handled contentious issues in the past makes me personally feel that Google will not be receptive to concerns about whether this spec should exis…

Why did Google select someone unknown to announce this?* It's also the second time I've noticed Google had someone the UK introduce an unpopular proposal to Chrome. The other one was removing the URL from the address bar (accusing the author of You Don't Know JS of being "Trump-like" for how he disagreed with him in the process). https://www.youtube.com/watch?v=0-wB1VY3Nrc https://twitter.com/jaffathecake/status/1272…

Be careful with having a Fav with FAAMGs: they’re all mega corporations too big to care and immune to dissent.

Skepticism is a survival skill.

Re: Google’s nightmare “Web Integrity API” wants a DRM gatekeeper for the web

#210
post #104

> The goal of the project is to learn more about the person on the other side of the web … The intro says this data would be useful to advertisers to better count ad impressions, stop social network bots, enforce intellectual property rights, stop cheating in web games Go f yourself, Google. Browser’s purpose is to serve me web pages, not to learn about me.

As long as Google is still leading in the browser market share, they do not care or give a shit and will never change.

Google are a monopoly, near-monopoly, or duopoly on the browser, search, maps, advertising, mobile, and mail.

The only regulatory action we've seen - supported on HN - is to go after their competitors.

Post reply on HN