Live data from Hacker News

Google’s nightmare “Web Integrity API” wants a DRM gatekeeper for the web

arstechnica.com

211–220 of 484 posts

Re: Google’s nightmare “Web Integrity API” wants a DRM gatekeeper for the web

#211

Earlier quoted context omitted.

Edge and Brave are based on Chromium. While Brave would likely block this API for a while (until too many sites require it and it would hurt their market share) they don't block most changes that Google pushes into Chrome so are still largely contributing to Google's power over the Internet. So if you really want to disrupt Google's control over the web platform the only options are really Firefox and Safari.

Safari has far more weight here though people are loathe to admit it. Apple's market share is a direct check on Google's ability to push things through so easily. Firefox unfortunately does not have the numbers on their side nor will they seemingly risk their Google payout deal. At this point, if you're using it, you're doing it because it has specific features or extensions you want, or you believe that it's ethical…

> Safari has far more weight here though people are loathe to admit it.

On HN people are more likely to complain about Safari existing and demand Chrome everywhere.

Re: Google’s nightmare “Web Integrity API” wants a DRM gatekeeper for the web

#212
post #63

Earlier quoted context omitted.

> When Google can do something that every one of it's users hates I don't think this is remotely the case. Quite a few tech-savvy people I know (some of them software developers) use Chrome and mostly don't care about whatever Google does with it. I mention "manifest v3" and get a blank stare. I talk about advertising and ad blockers, and most people don't care, with some of them not even using ad blockers. We really…

>Firefox is a perfectly viable alternative to Chrome that very few people use. The problem is that it isn't. Do you know why Firefox managed to usurp IE6 in the first place? Because it won the adoption and appeal of tech enthusiasts and professionals. Mom and pop (read: the general population) switched to Firefox from IE6 because their tech nerd kids installed it for them, and the enterprise largely moved off of IE6…

Firefox did not defeat IE6. That was Chrome. Firefox has basically been a fringe browser since Netscape imploded.

The original reason Google started the Chrome project was that the stagnation of IE6 was a barrier to implementing the web software they wanted to build. At least that's what they told us.

Re: Google’s nightmare “Web Integrity API” wants a DRM gatekeeper for the web

#213

Earlier quoted context omitted.

>Firefox is a perfectly viable alternative to Chrome that very few people use. The problem is that it isn't. Do you know why Firefox managed to usurp IE6 in the first place? Because it won the adoption and appeal of tech enthusiasts and professionals. Mom and pop (read: the general population) switched to Firefox from IE6 because their tech nerd kids installed it for them, and the enterprise largely moved off of IE6…

Firefox did not defeat IE6. That was Chrome. Firefox has basically been a fringe browser since Netscape imploded. The original reason Google started the Chrome project was that the stagnation of IE6 was a barrier to implementing the web software they wanted to build. At least that's what they told us.

No, it was Firefox that defeated IE6. Chrome came and defeated Firefox; Firefox's reign was rather shortlived.

It seems this particular moment in history has been either forgotten or rewritten, judging from this thread and another one from yesterday.

Re: Google’s nightmare “Web Integrity API” wants a DRM gatekeeper for the web

#214
post #63
post #32

> Exactly how the rest of the world feels about this is not necessarily relevant, though. Google owns the world's most popular web browser, the world's largest advertising network, the world's biggest search engine, the world's most popular operating system, and some of the world's most popular websites. So really, Google can do whatever it wants. This is the point that company breakups start to make a lot of sense.…

> When Google can do something that every one of it's users hates I don't think this is remotely the case. Quite a few tech-savvy people I know (some of them software developers) use Chrome and mostly don't care about whatever Google does with it. I mention "manifest v3" and get a blank stare. I talk about advertising and ad blockers, and most people don't care, with some of them not even using ad blockers. We really…

If I don't want to be tracked, I won't use chrome. If I don't care then I'll use it.

Just like I'll have some conversations on WeChat but if I want to talk about Chinese politics maybe I'll do that on another platform.

I don't really see the erosion in the corporate space. The erosion of privacy is happening at the government level. With "forced backdoor" laws and/or just outright forking the internet backbone (ala PRISM). I've never really understood "Corporate erosion of privacy"... It's opposite, Privacy is literally a USP of Apple products. They had to back out changes that hinted at an erosion of that trust with the on-device processing of Photos for cloud-sync. People are more aware than ever.

Re: Google’s nightmare “Web Integrity API” wants a DRM gatekeeper for the web

#215
post #63

Earlier quoted context omitted.

> When Google can do something that every one of it's users hates I don't think this is remotely the case. Quite a few tech-savvy people I know (some of them software developers) use Chrome and mostly don't care about whatever Google does with it. I mention "manifest v3" and get a blank stare. I talk about advertising and ad blockers, and most people don't care, with some of them not even using ad blockers. We really…

> after all, Firefox is a perfectly viable alternative to Chrome that very few people use I don't use Firefox because it's slower than Chrome and because their behavior regarding limiting which extensions are available in phones, requiring signed extensions, Firefox Pocket, ads in new tab page, etc, does not exactly give me confidence that Mozilla truly has my interests in mind. In fact I bet they'll implement the ni…

> limiting which extensions are available in phones

As opposed to chrome, which doesn't allow any extensions on mobile

> requiring signed extensions,

So does chrome

> ads in new tab page

Chrome is made by a company whose main business is selling ads ...

> clearly express support for adblockers

Mozilla has long shown support for ad blockers for example, uBlock origin was the first extension aupported on mobile, Mozilla has no plans to drop the blocking WebRequest API, largely because it is needed for sophisticated ad blockers like uBlock origin, etc.

I don't agree with everything Mozilla has done, but I still think Firefox is better than the alternatives.

Re: Google’s nightmare “Web Integrity API” wants a DRM gatekeeper for the web

#216

Earlier quoted context omitted.

Edge and Brave are based on Chromium. While Brave would likely block this API for a while (until too many sites require it and it would hurt their market share) they don't block most changes that Google pushes into Chrome so are still largely contributing to Google's power over the Internet. So if you really want to disrupt Google's control over the web platform the only options are really Firefox and Safari.

Safari has far more weight here though people are loathe to admit it. Apple's market share is a direct check on Google's ability to push things through so easily. Firefox unfortunately does not have the numbers on their side nor will they seemingly risk their Google payout deal. At this point, if you're using it, you're doing it because it has specific features or extensions you want, or you believe that it's ethical…

I don't like strict Apple AppStore policy to ban other browser engines, but I admit that it contributes web diversity much.

Re: Google’s nightmare “Web Integrity API” wants a DRM gatekeeper for the web

#217

Earlier quoted context omitted.

That is because without https, there is no guarantee that the site requested is bring delivered as the site intends. For example, an ISP could insert data or scripts into the page.

And monkeys could fly out of my butt. Not everyone has the same threat model. Faced with a choice between a vague future threat that might happen (an adversarial ISP or other MIM attack) and a certain future threat that will happen if we let it (incumbent gatekeepers locking down the Web), I'll take my chances with the former, and opt for less gatekeeping rather than more.

It's not a "might happen." ISPs, especially in places like hotels and other public WiFi spots, were replacing ads on sites with their own ads. I don't know if they did anything more nefarious but they were probably also snooping and logging to at least some degree.

Re: Google’s nightmare “Web Integrity API” wants a DRM gatekeeper for the web

#218
post #192

Earlier quoted context omitted.

iPhone users are using Manifest V3 _every single day_ in their Safari. There was never another option for them. Yet, noone cares, even on HN.

I care, and I've basically stopped using my iphone for anything because the web is an abysmal experience full of ads even with the maximum amount of ad blocking possible on iOS. I hate the iPhone and the only reason I haven't switched back to android is that it seems to manage to, somehow, still be even worse. We are well and truly on the other side of the enshitification event horizon on mobile, and it looks like Go…

You could use Brave or Orion and get adblocking on iOS

Re: Google’s nightmare “Web Integrity API” wants a DRM gatekeeper for the web

#219
post #31

While I don't love this API's idea, I understand why they're doing it, and the API it describes really just sounds like any Captcha API today. > Google's plan is that, during a webpage transaction, the web server could require you to pass an "environment attestation" test before you get any data. At this point your browser would contact a "third-party" attestation server, and you would need to pass some kind of test.…

Captchas only let you verify that the user is human, this API lets you do more: it lets you verify that your web application is going to run unmodified and that the user is going to see what you want him to see, _everything_ that you want him to see and nothing else.

Unlike captchas with this you can remove adblockers, greasemonkey/stylus edits, extensions adding download links to your youtube videos, etc, from the picture.

Re: Google’s nightmare “Web Integrity API” wants a DRM gatekeeper for the web

#220

Earlier quoted context omitted.

That is because without https, there is no guarantee that the site requested is bring delivered as the site intends. For example, an ISP could insert data or scripts into the page.

Let's rephrase that... "That is because without Web Integrity, there is no guarantee that the site requested is being delivered as the site intends. For example, a browser extension could remove ads or modify content on the page." See where this slippery slope is heading? We DO NOT want what "the site intends". We want to be in control of the content we consume.

Well, as you note, user control is exactly the difference; a user can still modify a page with HTTPS, but not with this proposal.
Post reply on HN