Live data from Hacker News

Web Environment Integrity API Proposal

github.com

281–290 of 460 posts

Re: Web Environment Integrity API Proposal

#281
post #36

Earlier quoted context omitted.

> how do we protest this? You do not and you cannot. It was written in stone once Chrome dominated the browser market. What Chrome (Google) wants, Chrome (Google) gets. Despite all the good engineering Google wants to sell ads, that's all there is to it. And the result is this proposal. > The saving grace here might be that Firefox won't implement the proposal. It's irrelevant and we are an irrelevant minority. Unles…

What about Safari? It has significant market share. Seems like our best bet now

Already does device attestation. https://www.macrumors.com/how-to/how-to-bypass-website-captc...

Re: Web Environment Integrity API Proposal

#282
The first line

> Users often depend on websites trusting the client environment they run in.

is already a lie. Users don't depend on websites trusting the client environment. Users expect the client to limit the way in which they have to trust websites.

Sure website owners would love to be able to trust user input, but that has little to do with the interest of the users.

If something starts with that kind of framing already you certainly know that this is not going to benefit the user.

Re: Web Environment Integrity API Proposal

#283
I could imagine governments getting behind this, there are a few proposed laws that require age verification, like the online safety bill in the UK. You could easily see them adding age verification on top of this proposal.

Re: Web Environment Integrity API Proposal

#284
post #59

What's strange to me is that the main author of the spec -- Ben Wiser -- seems to be against closed, wall-garden paradigms as he has written in a blog post "I just spent £700 to have my own app on my iPhone" [1]. In the post, he laments the state of the App Store monopoly on iOS and ponders returning to Android for the app installation freedom. How can he reconciliate these views with this spec, which he is the main…

[dead]

Re: Web Environment Integrity API Proposal

#285
post #45
post #18

This is a level or two below where my knowledge of the browser trails off, so I'll ask generally: how would this interact with things like the WebKit Content Blocker API?

Step 1: Sites require a "secure" (read proprietary) browser like "Google Chrome", "Microsoft Edge", "Safari" or refuse to operate. Step 2: "Secure" browsers change the behavior of their implementation of the Content Blocker API so an industry-accepted "secure" site lile Google Ads can opt-out of being blocked ("You wouldn't want a misconfigured content blocker to accidentally break a verified secure site right?") Ste…

[dead]

Re: Web Environment Integrity API Proposal

#286
This proposal is attempted theft. The web does not belong to Google, it belongs to everybody. Who are they to suggest that users with “non-attestable” (read: not controlled by Google) user agents or operating systems should be excluded or punished?

If Google wants a war, let’s give them one. Tell everyone who will listen. Give Google hell.

Re: Web Environment Integrity API Proposal

#287
post #87
post #73

Earlier quoted context omitted.

I wouldn't necessarily view it as malice from the beginning. It's entirely likely that early Chrome was really trying to solve usability problems in hosting complex applications like GMail. A goal that was attempted throughout history, as seen from the days of ActiveX, Java Web Applets, Flash, etc. But capitalism does what it does best, and will happily take advantage of (and try to prolong) a natural monopoly situat…

> I wouldn't necessarily view it as malice from the beginning. It's entirely likely that early Chrome was really trying to solve usability problems in hosting complex applications like GMail. A goal that was attempted throughout history, as seen from the days of ActiveX, Java Web Applets, Flash, etc. I would say that the actual goal early Chrome was really trying to solve, was to prevent the browser monopoly of the d…

That's a fair take. Which kind of begs the question: How much innovation in tech is actually just people getting around limitations imposed by monopoly/high influence players?

I'd guess not an insignificant amount.

Re: Web Environment Integrity API Proposal

#288

Earlier quoted context omitted.

>Conflating serverside generated code to native app restrictions is nonsensical, they are not the same thing You did it first. Attestation has nothing to do with extentions. >Building a website that reliably blocks Linux is hard, borderline impossible With attestation doesn't reveal what OS you are using, so it owned still be impossible to reliably block Linux. >And there is a ton of evidence that attestation will be…

>Conflating serverside generated code to native app restrictions is nonsensical, they are not the same thing > You did it first. Attestation has nothing to do with extentions. First of all, extensions are not serverside code, so... no, that doesn't make any sense. Second of all, attestation has a lot to do with extensions because extensions are based on browser functionality, and attestation impacts which software yo…

>attestation means websites can check to see if you're running modified or forked browsers that might allow for broader extension APIs.

It does not tell you what browser the user is using. Websites can not block a specific browser.

>Blocking ad fraud, blocking bots, blocking malware from a banking site, and blocking cheating in web games -- all of that requires blocking extensions

    How does this affect browser modifications and extensions?
    Web Environment Integrity attests the legitimacy of the underlying hardware and software stack, it does not restrict the indicated application’s functionality: E.g. if the browser allows extensions, the user may use extensions; if a browser is modified, the modified browser can still request Web Environment Integrity attestation.
It's about reducing the rate of those things.

>Do you genuinely think that an Open Linux environment is going to support attestation?

When Linux distributions start to actually care about security yes I do see plenty.

>Play Integrity

Play Integrity covers both attesting to if the system is in a secure state and if the app you are running is from the play store. This proposal only has an equivalent for the former.

>this is also not very difficult to look up

Chrome has worked on CNAME stuff since that was written and most of it does not really matter to most people.

>another long explanation of why advertisers are the victim and FLOC is actually making the web more private

Advertisers aren't the victim in this situation. It's the users who are losing privacy due to cross site tracking.

Re: Web Environment Integrity API Proposal

#289

Earlier quoted context omitted.

> how do we protest this? You do not and you cannot. It was written in stone once Chrome dominated the browser market. What Chrome (Google) wants, Chrome (Google) gets. Despite all the good engineering Google wants to sell ads, that's all there is to it. And the result is this proposal. > The saving grace here might be that Firefox won't implement the proposal. It's irrelevant and we are an irrelevant minority. Unles…

We could at least get everyone here to use Firefox. There's really no excuse for a technically minded person to still be using Chrome for their day to day browsing. If you do eventually run into a poorly crafted webpage that doesn't work on Firefox you have the wherewithal to decide if you are simply not going to use that site or hop over to chrome just this once. But the important thing is checking in automatically…

> We could at least get everyone here to use Firefox.

That would accomplish nothing.

> But the important thing is checking in automatically as a Firefox user in the logs of every other site online.

No, that's not important. HN users are a tiny minority compared to the billions of people that use the web daily.

I'm sorry, there's no easy way to say this: Firefox is never coming back. The web of old is never coming back. It's over. Even if this particular proposal gets defeated somehow, a future similar proposal will make it through. There is nothing you or I can do about it. Google is more powerful than most governments, and they are vastly more powerful than any random group of like-minded people who get together on the Internet in the belief that they can accomplish something.

Re: Web Environment Integrity API Proposal

#290
post #92
post #36

Earlier quoted context omitted.

What about Safari? It has significant market share. Seems like our best bet now

I doubt Apple will be our savior here. Apple is in a great position to implement this spec: their secure enclave and the systems they've developed around it are practically the state of the art. Also Apple is in bed w/ traditional media. (Apple News, Apple TV, iTunes, etc.) Microsoft has been doing the same[1] for years w/ Pluton on the Xbox to protect their IP. Google has been doing this on Android using, dm-verity,…

Apple is really the only party in a position to be a savior.

For example, they threaten to remove FaceTime and iMessage from UK iPhones if the government there changes the law on encryption [1].

[1]: https://www.macrumors.com/2023/07/20/apple-threatens-to-pull...

Post reply on HN