Live data from Hacker News

Web Environment Integrity API Proposal

github.com

31–40 of 460 posts

Re: Web Environment Integrity API Proposal

#32

Earlier quoted context omitted.

> who is finally putting their foot down and deciding that we are all going to be forced to either used fully-locked down devices The person who wrote the proposal[0] is from Google. All the authors of the proposal are from Google[1]. I've been thinking carefully about this comment, but I really don't know what to say. It's absolutely heartbreaking watching something I really care about die by a thousand cuts; how do…

> how do we protest this? You do not and you cannot. It was written in stone once Chrome dominated the browser market. What Chrome (Google) wants, Chrome (Google) gets. Despite all the good engineering Google wants to sell ads, that's all there is to it. And the result is this proposal. > The saving grace here might be that Firefox won't implement the proposal. It's irrelevant and we are an irrelevant minority. Unles…

> It's irrelevant and we are an irrelevant minority.

Heh. I was there when it was IE6, and people said the same.

Re: Web Environment Integrity API Proposal

#33

Earlier quoted context omitted.

I still remember the controversy surrounding EME, a LOT of people came out against it (including the EFF[0]); despite that, they still triumphed on[1]. [0]: https://www.eff.org/press/releases/eff-makes-formal-objectio... [1]: https://github.com/w3c/encrypted-media

And thank god for that, otherwise we'd still need to support flash to use most popular websites.

EME is for DRM'ing media. I don't see how that pertains to Flash.

WebAssembly exists as a replacement now, too.

Re: Web Environment Integrity API Proposal

#34
post #5

This is pretty much the inevitable end-game of the web, in no small part funded by ad-based business models (as the analog gap pretty much destroys most attempts to use this stuff to do copy protection) and enabled by developers who have insisted we shove as much difficult-to-implement functionality (by which I am talking about CSS complex stuff, not powerful-but-easy-to-code APIs for OS-level access) into the browse…

> who is finally putting their foot down and deciding that we are all going to be forced to either used fully-locked down devices The person who wrote the proposal[0] is from Google. All the authors of the proposal are from Google[1]. I've been thinking carefully about this comment, but I really don't know what to say. It's absolutely heartbreaking watching something I really care about die by a thousand cuts; how do…

I'm doing this again, but here's my shameless plug for the article I wrote 1 year ago now, "Remote Attestation Is Coming Back," which warned that this was coming to the web and had quite a discussion about that idea at the time:

https://news.ycombinator.com/item?id=32282305

Re: Web Environment Integrity API Proposal

#35
First I wanted to say client trust is one of the two things I‘d really like to see improved from a security standpoint but I think it‘s the wrong way around. Browsers should establish if they feel they operate in a trustworthy enough environment and decide to not work at all if they don‘t. Having the website initiate this check is a bit strange to me. (The other thing being more MitM and DNS Hijacking protection)

Re: Web Environment Integrity API Proposal

#36

Earlier quoted context omitted.

> who is finally putting their foot down and deciding that we are all going to be forced to either used fully-locked down devices The person who wrote the proposal[0] is from Google. All the authors of the proposal are from Google[1]. I've been thinking carefully about this comment, but I really don't know what to say. It's absolutely heartbreaking watching something I really care about die by a thousand cuts; how do…

> how do we protest this? You do not and you cannot. It was written in stone once Chrome dominated the browser market. What Chrome (Google) wants, Chrome (Google) gets. Despite all the good engineering Google wants to sell ads, that's all there is to it. And the result is this proposal. > The saving grace here might be that Firefox won't implement the proposal. It's irrelevant and we are an irrelevant minority. Unles…

What about Safari? It has significant market share. Seems like our best bet now

Re: Web Environment Integrity API Proposal

#37
post #15

Earlier quoted context omitted.

> who is finally putting their foot down and deciding that we are all going to be forced to either used fully-locked down devices The person who wrote the proposal[0] is from Google. All the authors of the proposal are from Google[1]. I've been thinking carefully about this comment, but I really don't know what to say. It's absolutely heartbreaking watching something I really care about die by a thousand cuts; how do…

I mean Firefox caved to support EME. This isn't the early days of the web anymore either, the enthusiasts are a small minority of global web traffic that this will probably succeed even with a large scale boycott.

I think in this case Firefox is in a different position: if it didn't support EME netflix wouldn't work.

But in this case it could report "sure, this is a real user alright" by being its own attester, can't it?

Re: Web Environment Integrity API Proposal

#38

Earlier quoted context omitted.

And thank god for that, otherwise we'd still need to support flash to use most popular websites.

EME is for DRM'ing media. I don't see how that pertains to Flash. WebAssembly exists as a replacement now, too.

If browsers didn't natively support DRM then they would have to come up with external extensions (such as Flash) to support DRM.

DRM isn't going away.

Re: Web Environment Integrity API Proposal

#39
post #9

Whether you like it or not (and I certainly don't), you've gotta sort of admire the sheer vision of a fifteen-year project to build a browser so good it comes to monopolize the industry, all because you've had the foresight to realize that monopoly will be crucial to securing your position as the adtech hegemon. An underrated masterpiece of evil genius.

And I believe this strategy was how Sundar Pichai became CEO of Google. He oversaw the chrome project in the early days and its incredible success catapulted him up the management ladder at Google.

Re: Web Environment Integrity API Proposal

#40

Earlier quoted context omitted.

And thank god for that, otherwise we'd still need to support flash to use most popular websites.

EME is for DRM'ing media. I don't see how that pertains to Flash. WebAssembly exists as a replacement now, too.

Back in the days before the tag, Web sites were using Flash to play video. Flash was also the main way to play DRMed video before EME.
Post reply on HN