Live data from Hacker News

Web Environment Integrity API Proposal

github.com

261–270 of 460 posts

Re: Web Environment Integrity API Proposal

#261
post #136

Earlier quoted context omitted.

No, you can't - not until you get a significant part of the world's population to join your protest. The point is that if chrome implements this, netflix, amazon, facebook etc might decide they'll use this feature and only permit browsers who implement this to use this site. Even if the only browser that does so is chrome, that's fine because chrome's market share is big enough that they can ignore the rest. Have fun…

> netflix, amazon, facebook etc might ... lock you out Is this supposed to be a bad thing? It's almost made to sound like surviving without them would be tantamount to starving, but frankly we might be better served without them.

I see Facebook locking you out (no great loss there) but I'm less convinced about Amazon or Netflix. They're not advertising-based businesses, so are not suffering with bots-consuming-ads problem.

Put another way, my site is unappealing to bots, and frankly I don't care about bot traffic, because I don't have ads. So I don't feel the need to support this server-side.

Equally Amazon makes money selling goods, not ads. They don't need to know if its human or bot, they just need a credit card. [1] Netflix is subscription based, again doesn't care if its a "trusted device" or not. They want you make sure their content is available not blocked because my TV is "untrusted".

Sure, you'll end up using Chrome to use Google properties. But I don't really see the incentive for the non-ad-based Web to bother implementing this.

[1] it won't move the needle for fraud, fraud is easily done via trusted devices.

Re: Web Environment Integrity API Proposal

#262
post #177

Earlier quoted context omitted.

Only if you throw Apple, Microsoft and Meta into the grinder as well. Our regulators are fully captured and have been for some time.

Absolutely, and more besides.

Antitrust them all, and let G̶o̶d̶ the market sort them out.

Re: Web Environment Integrity API Proposal

#263

> Attesters will be required to offer their service under the same conditions to any browser who wishes to use it and meets certain baseline requirements. This leads to any browser running on the given OS platform having the same access to the technology, but we still have the risks that 1) some websites might exclude some operating systems, and 2) if the platform identity of the application that requested the attest…

> and meets certain baseline requirements

I also wonder what those certain baseline requirements are going to be? Weird that they're left ambiguous.

It's probably nothing to worry about. We have a ton of precedent with Widevine that "it's okay, we'll license to anyone who meets requirements" wouldn't ever be abused[0]. It's fine, you just meet the baseline requirements that aren't spelled out yet and that might be subject to change and that certainly won't include headless or highly scriptable or experimental browsers. Nothing to worry about.

[0]: https://blog.samuelmaddock.com/posts/google-widevine-blocked...

Re: Web Environment Integrity API Proposal

#264
post #30
post #7

The literal attempt to censor web usage of Linux and BSD desktops, other FOSS clients, custom Android ROMs, etc with an open reasoning "to sell you ads". They don't even try to masquerade it.

Yeah I mean the first of their examples is literally: > Users like visiting websites that are expensive to create and maintain, but they often want or need to do it without paying directly. These websites fund themselves with ads, but the advertisers can only afford to pay for humans to see the ads, rather than robots. This creates a need for human users to prove to websites that they're human, sometimes through task…

It’s not impossible that google people who work there long enough are under a corporate delusion that users need something ads related that is aligned with business model of their paycheck issuer. They may sincerely believe it’s the only way forward, because otherwise it’s ruined for everyone.

As someone who lived in a city fully controlled by organized crime, I can tell you that eventually some people become fanboys of gang-law and start to unironically teach everyone how it’s better and more moral than actual law.

Re: Web Environment Integrity API Proposal

#265
post #158

Earlier quoted context omitted.

"You can use adblock" is a pretty chunky benefit over Chrome

but "Netflix and my bank actually work in Chrome" is Google's endgame.

the adblock "endgame" will be a self-hosted DNS system that blocks requests to ad-server urls (or return benign responses).

Then the game will switch to encrypted proxied traffic that you cannot block.

Then the adblocking software will switch to the GPU layer, and use machine learning and AI to wipe the region of memory in the GPU containing the ads (and replace it with something benign).

Then the next logical step from likes of google is a fully trusted computing environment - aka, you as an end user no longer control your own machine.

This is entirely predicted by Richard Stallman.

Re: Web Environment Integrity API Proposal

#266

Earlier quoted context omitted.

> how do we protest this? You do not and you cannot. It was written in stone once Chrome dominated the browser market. What Chrome (Google) wants, Chrome (Google) gets. Despite all the good engineering Google wants to sell ads, that's all there is to it. And the result is this proposal. > The saving grace here might be that Firefox won't implement the proposal. It's irrelevant and we are an irrelevant minority. Unles…

We could at least get everyone here to use Firefox. There's really no excuse for a technically minded person to still be using Chrome for their day to day browsing. If you do eventually run into a poorly crafted webpage that doesn't work on Firefox you have the wherewithal to decide if you are simply not going to use that site or hop over to chrome just this once. But the important thing is checking in automatically…

> There's really no excuse for a technically minded person to still be using Chrome for their day to day browsing.

Sadly, Chrome is substantially more secure than Firefox.

Re: Web Environment Integrity API Proposal

#267
post #136

Earlier quoted context omitted.

You can by not using Google products. Change the search for ddg or kagi. Change your email for proton. Use Dropbox instead. Remove Chrome, live with iceweasel or Firefox. It is not like you'll be loosing much. This is the time to change, while we still have other players in the market.

No, you can't - not until you get a significant part of the world's population to join your protest. The point is that if chrome implements this, netflix, amazon, facebook etc might decide they'll use this feature and only permit browsers who implement this to use this site. Even if the only browser that does so is chrome, that's fine because chrome's market share is big enough that they can ignore the rest. Have fun…

> they'll use this feature and only permit browsers who implement this to use this site

we as tech early adopters and "leaders" in this space, we need to be telling family and friends to complain to those sites about such required support. If enough people complain to amazon that they don't want to use this google branded browser, i think there will be some pushback and the companies would be hesitant to drop support for firefox.

Re: Web Environment Integrity API Proposal

#268
post #92

Earlier quoted context omitted.

I doubt Apple will be our savior here. Apple is in a great position to implement this spec: their secure enclave and the systems they've developed around it are practically the state of the art. Also Apple is in bed w/ traditional media. (Apple News, Apple TV, iTunes, etc.) Microsoft has been doing the same[1] for years w/ Pluton on the Xbox to protect their IP. Google has been doing this on Android using, dm-verity,…

> Also Apple is in bed w/ traditional media. True. Try to screenshot anything from Apple TV+ content. You'll get a black image.

It works fine in VLC with ATV content I have torrented.

If you subscribe to Apple TV, you are literally voting with your dollars for more of this crap. Stop giving them money!

Re: Web Environment Integrity API Proposal

#269
post #258

Earlier quoted context omitted.

Changing away from Gmail would lose me access to an uncounted number of sites where my login is Oauth of some flavor or other.

You can move away now or wait until they lock you out (and thereby lock you out of all you OAuth sites) with no recourse. The endless cries for help in /r/GMail/ says it all. OAuth sites will let you change your OAuth provider or even better switch to a local account on their site and use a password manager so you don't tie everything to an OAuth provider unless the site will accept a self hosted one.

I avoid giving a password to random sites online for a reason: I trust Google's password databases to be a lot more airtight than joerandomsite.tld.

That includes password databases.

Re: Web Environment Integrity API Proposal

#270

Earlier quoted context omitted.

>I don't see how anyone could credibly make this claim >device controlled A website is limited in what it can do by the browser it runs in. >unmodifiable Since responses are generated server side you can not modify what they send you. >broken on nonaproved hardware There are existing sites which don't support Linux or don't support mobile devices. >true neutrality of OS and hardware is incompatible with attestation A…

Respectfully, that response is kind of a roller-coaster. It's hard to know where to even begin. > device controlled [...] unmodifiable [...] nonaproved hardware Conflating serverside generated code to native app restrictions is nonsensical, they are not the same thing. Conflating device control to browser restrictions is also nonsensical given that the whole point of the web is that sites are browser neutral, and (ag…

>Conflating serverside generated code to native app restrictions is nonsensical, they are not the same thing

You did it first. Attestation has nothing to do with extentions.

>Building a website that reliably blocks Linux is hard, borderline impossible

With attestation doesn't reveal what OS you are using, so it owned still be impossible to reliably block Linux.

>And there is a ton of evidence that attestation will be used for DRM and to prevent adblocking

Please share it.

>It's a content decision made to block users from altering the client/content (ie, exactly what adblockers do).

The difference is that web browsers allow extentions, but the Netflix app doesn't.

>uBlock Origin already objectively runs worse on Chrome than Firefox

I use it just fine on Chrome and do not see any ads.

>Chrome's Manifest V3 API is worse for adblockers.

It has the same API for blocking ads. The API for blocking network requests is what changed.

>You can't even consistently keep up the charade of arguing that this isn't about adblockers for two comments before accidentally slipping into arguments that the advertisers are the real victims.

FLOC is about trying to get advertisers to stop invading people's privacy. You shouldn't be surprised that advertisers are a stakeholder when talking about FLOC. Advertisers are as important stakeholder in the web in general. In regards to attestation there are more stakeholders than just users and advertisers since security is important to almost any type of service on the internet.

>I have no idea how on earth anyone paying attention to the direction of the web could come to the conclusion that those proposals didn't have problems

The direction is not going away from web extentions and I don't see anything going after adblock extentions.

Post reply on HN