Live data from Hacker News

Web Environment Integrity API Proposal

github.com

241–250 of 460 posts

Re: Web Environment Integrity API Proposal

#241
post #158

Earlier quoted context omitted.

I was there too, in the 1.0 days, and still am. But these days are gone, Firefox is not coming back. Back then Firefox was immensely better than IE. As long as the other alternatives are just as good, there is no reason for the mythical "average user" to change over. Why bother if you can do everything in Chrome? We may understand the differences, ideological or technical, but good luck explaining that out there. The…

"You can use adblock" is a pretty chunky benefit over Chrome

but "Netflix and my bank actually work in Chrome" is Google's endgame.

Re: Web Environment Integrity API Proposal

#242

Earlier quoted context omitted.

>What this is proposing is basically to turn websites into mobile apps The web is an app platform which competes against other app platforms. >device controlled, unmodifiable, broken on any non-approved hardware That's already true of the web without this API. It doesn't change anything in regards to that. >at least I'd still be able to use my adblocker when I browse the web Please read the proposal. It has nothing t…

> That's already true of the web without this API. It doesn't change anything in regards to that. I fully disagree, I don't see how anyone could credibly make this claim. The web is open and customizable and neutral in a way that native platforms are not. Part of that is full device and OS neutrality where customizations and forks of browser engines do not generally[0] signal untrustworthiness to website operators. A…

>I don't see how anyone could credibly make this claim

>device controlled

A website is limited in what it can do by the browser it runs in.

>unmodifiable

Since responses are generated server side you can not modify what they send you.

>broken on nonaproved hardware

There are existing sites which don't support Linux or don't support mobile devices.

>true neutrality of OS and hardware is incompatible with attestation

Attestation doesn't mean that HTML now renders differently. The User Agent string already allows servers to block OSs.

>There is a zero percent chance that detecting bot traffic for advertisers will not turn into adblocking/automation restrictions over time

Sites can already detect adblocking without attestation. There is no evidence that the precense of an adblocker will be a signal to whether an environment is trustworthy. That is not the purpose of the API.

>given Google's history around adblockers

They have worked to support ad blocker extentions and they have provided a platform to ad blocker extentions. They have banned a malicous adblocker which also committed clickfraud. They have had some anti adblock experiments on YouTube such as limiting the resolution.

>We are far, far past the point where Google deserves the benefit of the doubt on this

I disagree.

>Chromium is already less effective at adblocking than Firefox is today

It works fine for me.

>Manifest V3 is still set to make adblocking worse

No, it won't. You just have to use a different API.

>despite employee claims that these efforts were not intended to harm adblockers

They care about improving the experience of the entire chrome user base. Getting rid of poorly designed APIs is a part of making Chrome better for everyone.

>We're not jumping to conclusions

Yes. You are. Google is trying to make the web more private and secure from the current state the web is in. Look at the reponse to FLOC. Despite increasing user's privacy many people forgot upset because they greedily want the web to cater to only them and not to people who rely on advertising. Similarly with Web DRM people panicked because they didn't want DRM because they only care about themselves and do not care about people who want their content to be protected. There is a theme where people get outraged because they don't understand that there are more people who use the web and have different needs than just them.

Giving people the option to protect their content or the option to use attestation as a signal doesn't prevent some idealized open web from existing. Sites that would like extra security can opt into it.

Re: Web Environment Integrity API Proposal

#243

Earlier quoted context omitted.

> how do we protest this? You do not and you cannot. It was written in stone once Chrome dominated the browser market. What Chrome (Google) wants, Chrome (Google) gets. Despite all the good engineering Google wants to sell ads, that's all there is to it. And the result is this proposal. > The saving grace here might be that Firefox won't implement the proposal. It's irrelevant and we are an irrelevant minority. Unles…

You can by not using Google products. Change the search for ddg or kagi. Change your email for proton. Use Dropbox instead. Remove Chrome, live with iceweasel or Firefox. It is not like you'll be loosing much. This is the time to change, while we still have other players in the market.

Changing away from Gmail would lose me access to an uncounted number of sites where my login is Oauth of some flavor or other.

Re: Web Environment Integrity API Proposal

#244
post #136

Earlier quoted context omitted.

No, you can't - not until you get a significant part of the world's population to join your protest. The point is that if chrome implements this, netflix, amazon, facebook etc might decide they'll use this feature and only permit browsers who implement this to use this site. Even if the only browser that does so is chrome, that's fine because chrome's market share is big enough that they can ignore the rest. Have fun…

> netflix, amazon, facebook etc might ... lock you out Is this supposed to be a bad thing? It's almost made to sound like surviving without them would be tantamount to starving, but frankly we might be better served without them.

Best of luck with that plan.

Almost no users want to be digital hermits. This protest approach has nobody following you up that mountain to the hermitage.

Re: Web Environment Integrity API Proposal

#246
post #136

Earlier quoted context omitted.

No, you can't - not until you get a significant part of the world's population to join your protest. The point is that if chrome implements this, netflix, amazon, facebook etc might decide they'll use this feature and only permit browsers who implement this to use this site. Even if the only browser that does so is chrome, that's fine because chrome's market share is big enough that they can ignore the rest. Have fun…

It might be time to abandon that half of the web. Radical software freedom ideology is looking less radical and more rational by the day.

It'll be radical and minority.

Most users are more comfortable with computers that are toasters, not (hackable) general purpose machines.

The flexibility to hack implies the flexibility to be owned. Users don't want to get owned. They hate that so much they'd voluntary choose an owner

Re: Web Environment Integrity API Proposal

#247
post #25

Earlier quoted context omitted.

It's signed? Sure you can fake the results of an attestation in your fork, but your fork would be using your own key to sign the response, a key that the site can reject.

Ah, we’ll also have to extract the key from chrome. It’s no worse than WideVine.

No, you'll need to extract the TPM secureboot keys from Microsoft headquarters. Good luck with that

Re: Web Environment Integrity API Proposal

#248
Add "integrity" to the list of adjectives used for obfuscating the rise of authoritarian dystopia...

It all started with "trusted computing", where "trusted" means "not under the owner's control". Then they tried to spin it as a "security" thing with TPMs, and created the impression that those speaking out against them were either malicious actors or insane conspiracy theorists.

Now it is actually happening. They want to control exactly what hardware and software you use, and they're doing it by ostracisation, which makes this even more sinister: you're still technically allowed to use software and hardware of your choosing, but you'll be blocked from participating.

I still remember when Intel was forced to revert adding a unique serial number to its processors because of widespread outrage, so it is possible for the public to make a difference; they just need to be educated about the coming dystopia and agitated enough to care and act upon it.

Perhaps we can start by spreading instructions on how to disable TPMs and "secure" boot along with all the advantages that come with doing so (custom drivers, running whatever OS you want, hardware you actually own, etc.) Of course the corporate-owned "security" lobby is going to start screaming that it's "insecure", but we need to make it clear that this is not the "security" we want because it is inherently hostile to freedom.

"Those who give up freedom for security deserve neither."

https://www.gnu.org/philosophy/right-to-read.html

Re: Web Environment Integrity API Proposal

#249

If this isn't added to the web you will see things like banking websites go away and require a mobile app. Features like this keep the web relevant.

Why aren't banking sites gone already? Because users expect to be able to use their desktop to do their banking. But if they can simply require you to use Chrome, suddenly you can get both birds with one stone! This is a bad thing for the web.

Re: Web Environment Integrity API Proposal

#250

The chess pieces for the end-to-end unblockable ad machine are in place. You'll have the cynically named "Privacy sandbox" that builds tracking directly into the browser. You curtail ad blockers by capping browser extensions. And then you allow access only to "attested" clients. Inescapable tracking and unblockable ads. And you'll get to see ever more of them over time. If this isn't evil enough in itself, the way Go…

The clockwork of the web is tainted more orange by the minute
Post reply on HN