API spec: https://rupertbenwiser.github.io/Web-Environment-Integrity/ It's morbidly amusing to see the browser referred to as a "user agent" here.
Google Chrome Proposal – Web Environment Integrity
31–40 of 99 posts
Re: Google Chrome Proposal – Web Environment Integrity
#32Fuck you Google, dystopian books were meant as a warning not as a play book.
Guess what, it wasn't free and now it's time to pay up.
Re: Google Chrome Proposal – Web Environment Integrity
#33Earlier quoted context omitted.
Bot traffic? Anyone using Linux will get blocked because "they can't be trusted". Only people running an "approved" operating system from a billion dollar corporation will be allowed to access. This is already what is happening with SafetyNet on Android. For now most applications don't require hardware attestation so you can pass by spoofing an old device that didn't support hardware attestation but I'm sure that wil…
Can confirm that it's palpable the segregation and poor treatment of Linux users. I need to make my browser talk as if it was on Windows just for websites to not treat me as garbage. Look, it isn't that bad, but enough to make me do it. It's obnoxious.
Re: Google Chrome Proposal – Web Environment Integrity
#34> Motivation: Users often depend on websites trusting the client environment they run in. Aka corporations insist on control & want to make sure users are powerless when using the site. And Chrome is absolutely here to help the megacorp's radically progress the War On General Purpose Computing and make sure users are safe & securely tied to environments where they are powerless. There's notably absolutely no discussi…
Many Googlers here, hope they are more vocal when Google comes up with BS. Rather than when they post a positive blog post.
You have to remember, from their point of view they are writing the web software and when a user agent is non-compliant, it gets in their way. UAs with weird quirks translate to impossible-to-reproduce bugs, so the default bias is in favor of standardization and regularity.
Re: Google Chrome Proposal – Web Environment Integrity
#35Lots of people doom and gloom here about threats to user privacy and freedom. This is the one I'd be worried about. Thought it was annoying to not be able to use banking apps on a rooted Android? Think about how annoying it will be when you can't do much of anything, even on the Web, unless it's from a sealed, signed Apple/Google/Microsoft image-based OS... I realize the way Firefox's user share is going, it might no…
Re: Google Chrome Proposal – Web Environment Integrity
#36Re: Google Chrome Proposal – Web Environment Integrity
#37Earlier quoted context omitted.
How do you, as website owner, protect your users from something like this? https://www.bleepingcomputer.com/news/security/451-pypi-pack...
You do not, the user is responsible for the operation of their device. Most of the time this should be caught by whatever malicious software detector the user runs. Also, Chrome and Firefox very heavily guard against extensions being installed from outside of the usual way, i.e. by outside programs.
As time goes on hand-waving the matter as "user's responsibility" is becoming a less and less acceptable answer. Hard assurances are being demanded and applied technologies are progressively patching the existing loopholes.
Re: Google Chrome Proposal – Web Environment Integrity
#38Earlier quoted context omitted.
You don't have to be a billion dollar corporation to become Play Protect certified. Being able to trust the security of a client can protect against many attacks and it is up to web sites to evaluate what to do with into information that a client is proven to be secure.
Play Protect is different from SafetyNet. SafetyNet means the app checks to make sure you're not rooted or running a custom ROM because those are considered a security risk. If you are not running a locked-down OEM ROM, you can't run many apps including banking apps. Microsoft's Pluton on-CPU attestation technology means this is coming to PCs.
>means the app checks to make sure you're not rooted or running a custom ROM
The purpose is to be able to tell if the user is running a version of the app is from the play store or to be able to tell if the device's integrity isn't compromised meaning that it can not rely on the security guarantees the OS provides. Banking apps are not against people using custom ROMs. They just want to ensure they are running on a secure operating system.
Re: Google Chrome Proposal – Web Environment Integrity
#39Gluttony, greed, envy, and arrogance. This is truly sickening.
Re: Google Chrome Proposal – Web Environment Integrity
#40I'm surprised the ad corps haven't forked the internet yet: special drm-ed websites accessible only via special drm-ed browsers. At least it would relieve those who want to share knowledge from the presence of those who sell addiction.