Live data from Hacker News

Google Chrome Proposal – Web Environment Integrity

chromestatus.com

31–40 of 99 posts

Re: Google Chrome Proposal – Web Environment Integrity

#31

API spec: https://rupertbenwiser.github.io/Web-Environment-Integrity/ It's morbidly amusing to see the browser referred to as a "user agent" here.

This probably isn't the best analogy to make the case you're trying to make. Agents in real life don't just blindly do whatever any customer asks. They actually have some standards and boundaries they have to observe, including ensuring integrity in their dealings on behalf of the customer. (To be clear I'm not endorsing the proposal, just commenting on the analogy.)

Re: Google Chrome Proposal – Web Environment Integrity

#32

Fuck you Google, dystopian books were meant as a warning not as a play book.

Perhaps a warning to you and me. But we missed the signs because of all the free stuff they gave us.

Guess what, it wasn't free and now it's time to pay up.

Re: Google Chrome Proposal – Web Environment Integrity

#33
post #16
post #7

Earlier quoted context omitted.

Bot traffic? Anyone using Linux will get blocked because "they can't be trusted". Only people running an "approved" operating system from a billion dollar corporation will be allowed to access. This is already what is happening with SafetyNet on Android. For now most applications don't require hardware attestation so you can pass by spoofing an old device that didn't support hardware attestation but I'm sure that wil…

Can confirm that it's palpable the segregation and poor treatment of Linux users. I need to make my browser talk as if it was on Windows just for websites to not treat me as garbage. Look, it isn't that bad, but enough to make me do it. It's obnoxious.

I haven't notice any poor treatment. I'm using Google Chrome on Fedora 38 and have recently used Chrome on a Mac and on Windoes.

Re: Google Chrome Proposal – Web Environment Integrity

#34

> Motivation: Users often depend on websites trusting the client environment they run in. Aka corporations insist on control & want to make sure users are powerless when using the site. And Chrome is absolutely here to help the megacorp's radically progress the War On General Purpose Computing and make sure users are safe & securely tied to environments where they are powerless. There's notably absolutely no discussi…

Many Googlers here, hope they are more vocal when Google comes up with BS. Rather than when they post a positive blog post.

In general, Googlers tend to be in favor of initiatives like this.

You have to remember, from their point of view they are writing the web software and when a user agent is non-compliant, it gets in their way. UAs with weird quirks translate to impossible-to-reproduce bugs, so the default bias is in favor of standardization and regularity.

Re: Google Chrome Proposal – Web Environment Integrity

#35

Lots of people doom and gloom here about threats to user privacy and freedom. This is the one I'd be worried about. Thought it was annoying to not be able to use banking apps on a rooted Android? Think about how annoying it will be when you can't do much of anything, even on the Web, unless it's from a sealed, signed Apple/Google/Microsoft image-based OS... I realize the way Firefox's user share is going, it might no…

Firefox doesn't allow users to install unsigned extensions unless they use a beta version, because users apparently can't be trusted to install software. I trust Mozilla to fight for privacy (they're great at it), but I do not trust them in the slightest to fight for user freedom (like accessing banking sites on an "insecure" OS).

Re: Google Chrome Proposal – Web Environment Integrity

#37
post #11

Earlier quoted context omitted.

How do you, as website owner, protect your users from something like this? https://www.bleepingcomputer.com/news/security/451-pypi-pack...

You do not, the user is responsible for the operation of their device. Most of the time this should be caught by whatever malicious software detector the user runs. Also, Chrome and Firefox very heavily guard against extensions being installed from outside of the usual way, i.e. by outside programs.

> You do not, the user is responsible for the operation of their device.

As time goes on hand-waving the matter as "user's responsibility" is becoming a less and less acceptable answer. Hard assurances are being demanded and applied technologies are progressively patching the existing loopholes.

Re: Google Chrome Proposal – Web Environment Integrity

#38
post #24

Earlier quoted context omitted.

You don't have to be a billion dollar corporation to become Play Protect certified. Being able to trust the security of a client can protect against many attacks and it is up to web sites to evaluate what to do with into information that a client is proven to be secure.

Play Protect is different from SafetyNet. SafetyNet means the app checks to make sure you're not rooted or running a custom ROM because those are considered a security risk. If you are not running a locked-down OEM ROM, you can't run many apps including banking apps. Microsoft's Pluton on-CPU attestation technology means this is coming to PCs.

I am talking about "Play Protect certification." SafetyNet is deprectaed and has been replaced with the Play Integrity API.

>means the app checks to make sure you're not rooted or running a custom ROM

The purpose is to be able to tell if the user is running a version of the app is from the play store or to be able to tell if the device's integrity isn't compromised meaning that it can not rely on the security guarantees the OS provides. Banking apps are not against people using custom ROMs. They just want to ensure they are running on a secure operating system.

Re: Google Chrome Proposal – Web Environment Integrity

#39
These things Google has been announcing will culminate in an inhuman level of oppression of our digital lives and might irreparably damage people's sense of ownership and sovereignty over their own personal electronic devices.

Gluttony, greed, envy, and arrogance. This is truly sickening.

Re: Google Chrome Proposal – Web Environment Integrity

#40
post #10

I'm surprised the ad corps haven't forked the internet yet: special drm-ed websites accessible only via special drm-ed browsers. At least it would relieve those who want to share knowledge from the presence of those who sell addiction.

The whole point of things like this is to force the open internet to be the one to fork away. The network effect is solved by having enough money to take over an existing network.
Post reply on HN