Live data from Hacker News

Google’s nightmare “Web Integrity API” wants a DRM gatekeeper for the web

arstechnica.com

251–260 of 484 posts

Re: Google’s nightmare “Web Integrity API” wants a DRM gatekeeper for the web

#251
The attestation need not be done by Google or web browser owner themselves. This can be done by operating systems or any third party attestation just like a simple version of certification attestation. I think even though the intention behind the idea is good, the integrity of the company that suggested this is so doomed that we are all afraid. I think such proposals will come and need to come so that gradually these proposals will mutate into something useful

Re: Google’s nightmare “Web Integrity API” wants a DRM gatekeeper for the web

#252
post #192

Earlier quoted context omitted.

iPhone users are using Manifest V3 _every single day_ in their Safari. There was never another option for them. Yet, noone cares, even on HN.

I care, and I've basically stopped using my iphone for anything because the web is an abysmal experience full of ads even with the maximum amount of ad blocking possible on iOS. I hate the iPhone and the only reason I haven't switched back to android is that it seems to manage to, somehow, still be even worse. We are well and truly on the other side of the enshitification event horizon on mobile, and it looks like Go…

Not trying to get you back on your iPhone but I can tell you that 1Blocker + NextDNS do wonders when it comes to blocking ads on the web using iphones. Granted, sometimes some sites do break for weird reasons but i'm happy to live with that if it means I get to avoid ads. Hell, it even manages to block ads on mobile youtube.

Re: Google’s nightmare “Web Integrity API” wants a DRM gatekeeper for the web

#253

Seems like this is going to get a lot of pushback. It might not go through. But remember whether it goes through or not isn't the important thing. The fact that Google wants it to is what matters.

>> Seems like this is going to get a lot of pushback. It is: https://github.com/RupertBenWiser/Web-Environment-Integrity/...

> An owner of this repository has limited the ability to open an issue to users that have contributed to this repository in the past.

It sure seems like they're silencing opposition.

Re: Google’s nightmare “Web Integrity API” wants a DRM gatekeeper for the web

#254

The attestation need not be done by Google or web browser owner themselves. This can be done by operating systems or any third party attestation just like a simple version of certification attestation. I think even though the intention behind the idea is good, the integrity of the company that suggested this is so doomed that we are all afraid. I think such proposals will come and need to come so that gradually these…

Practically speaking yes, the OS (and further down the TPM/enclave) will be the root of attestation. Google here is starting with Google Play Integrity (previously known as SafetyNet), which is an OS-level attestation authority. On Windows, this attestation would probably be done via TPM/Secureboot and Windows integrity APIs.

That's what's scary about it, because it has the potential to make large parts of the web inaccessible unless you have a signed and sealed OS layer and browser to browse it with.

Re: Google’s nightmare “Web Integrity API” wants a DRM gatekeeper for the web

#255
post #154

It's great to see this getting more attention. User-agent discrimination (i.e. "go away if you're not using the latest version of Chrome") needs to become illegal. As long as I'm not overloading your service or similar, what hardware or software I use must not be restricted. The same goes for other deliberate obstacles to accessibility and interoperability --- creating a "standard" that's so complex and churned frequ…

Why shouldn't the owner/operator of a website be able to decide who to sling bits to? How is this, conceptually, any different from sites that used to block IE out of spite?

[deleted]

Re: Google’s nightmare “Web Integrity API” wants a DRM gatekeeper for the web

#257

They're going to prevent me from running an adblocker in this "web integrity" environment, aren't they.

Not until Mozilla gives in.

Mozilla are proposing IPA[1] which is designed to track user interaction with ads and product marketing, and track any conversion that occurs (e.g. users end up purchasing something).

If you are shown a product ad whilst browsing searchengine.example and then later look up the product at reviews.example, then end up making a purchase at shop.example, your browser sends all of these events to an aggregation service that allows shop.example to understand (at least in aggregate, assuming you trust the cartel running the aggregation service) that you were exposed to their product at searchengine.example and further exposed to their product at reviews.example.

[1] https://github.com/patcg-individual-drafts/ipa/

Re: Google’s nightmare “Web Integrity API” wants a DRM gatekeeper for the web

#258
post #229
post #154

Earlier quoted context omitted.

Why shouldn't the owner/operator of a website be able to decide who to sling bits to? How is this, conceptually, any different from sites that used to block IE out of spite?

For the same reasons a shop owner must sell to all customers without discriminating on ethnicity, religion, disability, etc? Would it be acceptable for a website owner to block users from Detroit (78% African Americans)[1] or block users from El Paso (82% Hispanic)[2] because the website owner claims that fraudulent ad clicking is more prevalent from those cities? Would it be acceptable to only serve web pages to peo…

I block China and Turkey from some of my websites to reduce bots and hacking attempts, does this make me a bad person for discriminating or should I have to tolerate the script kiddies, ddosing and exploit searches?

I’m not defending google’s crap but I should be able to block anyone I want from my websites if I choose.

Re: Google’s nightmare “Web Integrity API” wants a DRM gatekeeper for the web

#260

Earlier quoted context omitted.

Any archive site (archive.org, archive.ph, etc.) can be blocked by sites requiring attestation. What will happen if such a thing actually happens is that the underground market for "trusted device" farms grows, not too different from what's currently already happening but possibly at a far larger scale. Of course, that means the financially motivated scraping services still keep going while the honest individuals wan…

This has been happening already. The market is trying really hard to price out web scraping through scraper detection technologies and it's kinda working - scraping is becoming non-existent in user-space apps. It's also extremely discriminatory. Try running a single scrape with a developing country's IP and Linux, you'll be blocked at TLS step lol

But of course search engines are fine
Post reply on HN