Live data from Hacker News

Web Environment Integrity API Proposal

github.com

221–230 of 460 posts

Re: Web Environment Integrity API Proposal

#221
post #158

Earlier quoted context omitted.

I was there too, in the 1.0 days, and still am. But these days are gone, Firefox is not coming back. Back then Firefox was immensely better than IE. As long as the other alternatives are just as good, there is no reason for the mythical "average user" to change over. Why bother if you can do everything in Chrome? We may understand the differences, ideological or technical, but good luck explaining that out there. The…

"You can use adblock" is a pretty chunky benefit over Chrome

[dead]

Re: Web Environment Integrity API Proposal

#222
post #70
post #43

Earlier quoted context omitted.

I was there too. People always say this, but just because a thing changed once does not mean it will happen again. In this case, the population scale alone has changed by over an order of magnitude. Just doing some quick searching - the first numbers that come up when you search for "how many people used the internet in the year 2000" are on the order of 350 million or so. Comparatively, now, in 2023, Reddit alone ha…

Yes. The solution is very simple: uninstall Chrome and Chromium. We are the people with the most influence on the tech. We are prescriptors. We are legion. – Yes but Chrome is a tad faster and I have my bookmarks and my favorites extension and blablablabla… — Then you are the root cause of the problem. If you are not ready to sacrifice an ounce of comfort to save the web, then you are the one killing the web. Simple:…

>Simple: install Firefox. Now.

No.

Re: Web Environment Integrity API Proposal

#223
At DOSYAGO, we're definitely concerned about this. We see concerns of Alphabet’s Web Environment Integrity API Proposal, we see a potential threat to the very democracy of the web. The danger isn't merely about preserving the ad business model, but the potential for market monopolization by Google Chrome. Yet, the beauty of open source presents us with hope and solutions.

As creators of a competing open-source browser, we're stirred by this. We're concerned about the future integrity of browsing - whether run remotely, headlessly, or semi-automated, we see all these threatened by such attestations. But we believe in the power of the collective, and the spirit of innovation that thrives in the open-source community.

The conundrum is real for Alphabet, but leveraging control over such a global, ubiquitous means of access cannot be the answer. However, we don't advocate a future where Google cannot derive value from its creations. The economic balance may be hard to find, but technically, solutions will emerge. We're committed to standing up for the future of the web, because we believe in its open, democratic potential.

Now, more than ever, we need you to join us in safeguarding the web's future. Come, contribute, and be part of the change. Visit https://github.com/dosyago/BrowserBoxPro today. Stand up for an open, fair, and free web.

Re: Web Environment Integrity API Proposal

#224

Oh by "Web Environment" you mean "my machine" lol! I already got caught by this kind of thing - a https://github.com/nativefier/nativefier app wrapping Youtube Music doesn't work, because Google detects somehow that you are not using a trusted browser and refuses to serve. This is sort of moving in the "zero trust" (as in let's use ML etc. to detect if we trust something. username/password is not enough), which I fea…

The thing is with existing fingerprinting you can patch against it, with this it would be very difficult.

Re: Web Environment Integrity API Proposal

#225

Earlier quoted context omitted.

> You can't just fork Chromium and add a feature Of course you can. Microsoft's Edge and Brave already add proprietary features like AI and reader mode, tab groups, video calling, crypto wallet etc. Brave could add a custom CSS or HTML feature. Hell that was the status quo we came from ten years ago when each vendor had their own feature flags and implementation for WebRTC and proprietary video codecs, etc. Brave alr…

I think you missed the point of the comment you’re replying to. Without market share, the custom feature will never be respected by the web. At best if web developers don’t have to do any work for it you might get something that you can maintain for a while.

In fact, Edge is a perfect example of "nobody caring about your tiny fork": No matter what Microsoft tried, the internet no longer cared about Trident and IE/Edge. The only way Microsoft could regain some semblance of existing was to turn IE/Edge into Chrome and play the internet game as Google dictates.

Nowadays Edge has some superfluous features that differentiate it from Chrome, but they are still superfluous. Underneath it's still Chrome, because the internet demands Chrome.

Re: Web Environment Integrity API Proposal

#226

Earlier quoted context omitted.

> who is finally putting their foot down and deciding that we are all going to be forced to either used fully-locked down devices The person who wrote the proposal[0] is from Google. All the authors of the proposal are from Google[1]. I've been thinking carefully about this comment, but I really don't know what to say. It's absolutely heartbreaking watching something I really care about die by a thousand cuts; how do…

> how do we protest this? You do not and you cannot. It was written in stone once Chrome dominated the browser market. What Chrome (Google) wants, Chrome (Google) gets. Despite all the good engineering Google wants to sell ads, that's all there is to it. And the result is this proposal. > The saving grace here might be that Firefox won't implement the proposal. It's irrelevant and we are an irrelevant minority. Unles…

We could at least get everyone here to use Firefox. There's really no excuse for a technically minded person to still be using Chrome for their day to day browsing.

If you do eventually run into a poorly crafted webpage that doesn't work on Firefox you have the wherewithal to decide if you are simply not going to use that site or hop over to chrome just this once.

But the important thing is checking in automatically as a Firefox user in the logs of every other site online. Push Firefox marketshare up and at least some places will be hesitant to write off Firefox as irrelevant.

Re: Web Environment Integrity API Proposal

#227

If this isn't added to the web you will see things like banking websites go away and require a mobile app. Features like this keep the web relevant.

I don't care if the web is relevant if it's not the web anymore. Ruining a platform to keep it relevant isn't in my interest as a user. If we shoot this down and every bank requires me to download a mobile app, then fine. What this is proposing is basically to turn websites into mobile apps: device controlled, unmodifiable, broken on any non-approved hardware. If that's going to be the case regardless, I'd rather jus…

>What this is proposing is basically to turn websites into mobile apps

The web is an app platform which competes against other app platforms.

>device controlled, unmodifiable, broken on any non-approved hardware

That's already true of the web without this API. It doesn't change anything in regards to that.

>at least I'd still be able to use my adblocker when I browse the web

Please read the proposal. It has nothing to do with preventing adblocking or detecting people with adblockers.

Re: Web Environment Integrity API Proposal

#228
post #163

This seems like a step closer to killing the open web. "Sorry, you can only access this website using this specific device with a browser compiled by Big Tech, it's for your own good." Not surprising that this is all coming from Google, the world's biggest adtech company.

This is already happening. It’s just mildly harder now. Try opening Teams in Firefox or Safari.

Good luck getting online banking to work outside Chrome and Edge.

If you call their support line to say something isn't working, they'll ask if you're using Chrome or Edge. If you aren't, they'll tell you to just use Chrome or Edge.

Re: Web Environment Integrity API Proposal

#229

Earlier quoted context omitted.

When P(fraud|request from browser) increases and P(fraud|request from mobile app) decreases and P(customer has mobile device) approaches 1 it starts making less and less sense to support running a web interface.

A good way to drive fraud to zero is to make it so that nobody uses your service.

okay?
Post reply on HN