Live data from Hacker News

Web Environment Integrity API Proposal

github.com

301–310 of 460 posts

Re: Web Environment Integrity API Proposal

#301
post #15

Earlier quoted context omitted.

I mean Firefox caved to support EME. This isn't the early days of the web anymore either, the enthusiasts are a small minority of global web traffic that this will probably succeed even with a large scale boycott.

I think in this case Firefox is in a different position: if it didn't support EME netflix wouldn't work. But in this case it could report "sure, this is a real user alright" by being its own attester, can't it?

Sites will just stop trusting that as an attester.

Anyone can write their own EME plug in that writes the files to disk. But it won't have the keys of any trusted module, because the reason sites trust them is because they don't do that. So it won't get accepted by anyone. Same here.

Re: Web Environment Integrity API Proposal

#302
post #258

Earlier quoted context omitted.

You can move away now or wait until they lock you out (and thereby lock you out of all you OAuth sites) with no recourse. The endless cries for help in /r/GMail/ says it all. OAuth sites will let you change your OAuth provider or even better switch to a local account on their site and use a password manager so you don't tie everything to an OAuth provider unless the site will accept a self hosted one.

I avoid giving a password to random sites online for a reason: I trust Google's password databases to be a lot more airtight than joerandomsite.tld. That includes password databases.

What's the harm in giving some sketchy site a unique, random password only used with that site? (In contrast to letting them have your Google profile and all that comes with it)

Re: Web Environment Integrity API Proposal

#303
post #109

Earlier quoted context omitted.

> Interesting that fixing "how to center a div" is considered harmful, but WebSerialPort is actually very good? It is certainly "interesting", but "true" nonetheless: one determined person--think Fabrice Ballard if you want an example--is in a great position to throw together a web browser and even implement ALL of the crazy API wrapper specs, but when if they aren't you simply don't need most of them to browse any g…

The end result of this seems to me like clicking on any link means I’m going to download 50 MB before I can see any content?

So... you prefer the end result we got, with there being only ~1.75 browsers in existence--and only 1 that truly matters to developers--where ~1.66 of them are owned by companies that would prefer to implement this specification? :(

Re: Web Environment Integrity API Proposal

#304
post #5

This is pretty much the inevitable end-game of the web, in no small part funded by ad-based business models (as the analog gap pretty much destroys most attempts to use this stuff to do copy protection) and enabled by developers who have insisted we shove as much difficult-to-implement functionality (by which I am talking about CSS complex stuff, not powerful-but-easy-to-code APIs for OS-level access) into the browse…

It's important to note that a browser that implements something like this is simply not a User Agent, in the most clear way - it's just not there to serve the User, it's there to serve the website. When you consider this, it's clear that this goes against the core principals of the WWW, making this an Anti-WWW feature, or better put, a regression.

Hopefully this will not be implemented, but still it's a good wake up call for those who still think that Chrome is more than an ads-delivery app with some browser functionality.

Re: Web Environment Integrity API Proposal

#305
post #289

Earlier quoted context omitted.

We could at least get everyone here to use Firefox. There's really no excuse for a technically minded person to still be using Chrome for their day to day browsing. If you do eventually run into a poorly crafted webpage that doesn't work on Firefox you have the wherewithal to decide if you are simply not going to use that site or hop over to chrome just this once. But the important thing is checking in automatically…

> We could at least get everyone here to use Firefox. That would accomplish nothing. > But the important thing is checking in automatically as a Firefox user in the logs of every other site online. No, that's not important. HN users are a tiny minority compared to the billions of people that use the web daily. I'm sorry, there's no easy way to say this: Firefox is never coming back. The web of old is never coming bac…

Google is not stronger than the EU.

Re: Web Environment Integrity API Proposal

#307
post #70

Earlier quoted context omitted.

Yes. The solution is very simple: uninstall Chrome and Chromium. We are the people with the most influence on the tech. We are prescriptors. We are legion. – Yes but Chrome is a tad faster and I have my bookmarks and my favorites extension and blablablabla… — Then you are the root cause of the problem. If you are not ready to sacrifice an ounce of comfort to save the web, then you are the one killing the web. Simple:…

> The solution is very simple: uninstall Chrome and Chromium. No. Firefox, beyond being slower, also keeps constantly displaying ads… for itself. Want to open a new tab? “Big Browser cares about your privacy, read how!” I just want to open a new tab!!! I’m working! Restarting? “Discover what’s new with Firefox”, “Hohoho, we care about your privacy, LOOK HOW MUCH WE CARE! ALSO WE HAVE NO ADS!” Worse, they suggest to s…

https://waterfox.net/ to the rescue.

Re: Web Environment Integrity API Proposal

#308
post #5

This is pretty much the inevitable end-game of the web, in no small part funded by ad-based business models (as the analog gap pretty much destroys most attempts to use this stuff to do copy protection) and enabled by developers who have insisted we shove as much difficult-to-implement functionality (by which I am talking about CSS complex stuff, not powerful-but-easy-to-code APIs for OS-level access) into the browse…

It feels like this cannot fly in the EU already though. And if they someone found a way around the regulatory, there will be amendments to shoot it down.

The entire premise of 'people want expensive to make websites, but don't want to pay for them' is already a bit flawed. I do pay for youtube to not see ads, I wish I could pay Google (and Meta) to not serve me ads on any site including Google search, they have ads on. That would make life a lot nicer. And I personally know no-one who would not sign up for that. But that doesn't happen, I guess because ads make more (not from me, but he)?

Re: Web Environment Integrity API Proposal

#310
post #258

Earlier quoted context omitted.

You can move away now or wait until they lock you out (and thereby lock you out of all you OAuth sites) with no recourse. The endless cries for help in /r/GMail/ says it all. OAuth sites will let you change your OAuth provider or even better switch to a local account on their site and use a password manager so you don't tie everything to an OAuth provider unless the site will accept a self hosted one.

I avoid giving a password to random sites online for a reason: I trust Google's password databases to be a lot more airtight than joerandomsite.tld. That includes password databases.

Something to consider when you save your passwords in Google, you can "forget" and reset your Google account password and all your passwords are still there. Compare that to a proper password manager where if you forget the master password (assuming sufficient complexity) nobody is getting those passwords back ever. So Google has full access to your passwords whenever it feels like it.

As the other commenter said, there's zero risk giving a dodgy site a randomly generated password used only for that site, the randomly generated password gives them no information or pathway to any other web site.

Post reply on HN