Live data from Hacker News

Google’s nightmare “Web Integrity API” wants a DRM gatekeeper for the web

arstechnica.com

301–310 of 484 posts

Re: Google’s nightmare “Web Integrity API” wants a DRM gatekeeper for the web

#301
post #295

Earlier quoted context omitted.

> The New York Times would refuse to serve content to unattested user agents. You forgot one thing – once a copy of the content is server to AT LEAST one attested user agent – what prevents him from sharing his copy with unattested users? It is easy to see that if something will make getting the content harder – it will immediately find the path of least resistance. This is the reason any new Netflix title is availab…

> once a copy of the content is server to AT LEAST one attested user agent – what prevents him from sharing his copy with unattested users? This is already covered by the DRM in all major web browsers today. If your software will allow that, it can't get attested.

I don't understand – how exactly DRM knows that I have a video-capture card recording my screen right now? The browser has no idea.

Or what prevents me from copying NYT article and re-hosting it? What DRM has to do with it?

Re: Google’s nightmare “Web Integrity API” wants a DRM gatekeeper for the web

#302

Earlier quoted context omitted.

Any archive site (archive.org, archive.ph, etc.) can be blocked by sites requiring attestation. What will happen if such a thing actually happens is that the underground market for "trusted device" farms grows, not too different from what's currently already happening but possibly at a far larger scale. Of course, that means the financially motivated scraping services still keep going while the honest individuals wan…

This has been happening already. The market is trying really hard to price out web scraping through scraper detection technologies and it's kinda working - scraping is becoming non-existent in user-space apps. It's also extremely discriminatory. Try running a single scrape with a developing country's IP and Linux, you'll be blocked at TLS step lol

> The market is trying really hard to price out web scraping... scraping is becoming non-existent in user-space apps

Uhh... Those two matters are pretty much unrelated to each other. Scraping is becoming non-existing because the era of static web pages has ended. No need to "scrap" when you have a nice, performant JSON REST API provided for you.

Re: Google’s nightmare “Web Integrity API” wants a DRM gatekeeper for the web

#303

Earlier quoted context omitted.

Mozilla just took position against this DRM API: https://github.com/mozilla/standards-positions/issues/852#is... Also, Firefox just passed ahead of Chrome on some JS speed benchmark, so you should get ready to switch back!

That's nice to know, I'll give it a try soon then!

It's for nightly currently (+2 from prod version), but I'm using dev on my work computer and base prod on my private one, and it's _fast_.

Just setup ublock origin to filter annoyances as well, and it actually quite quickens the browsing experience.

PS Chrome is faster because it cheats and takes shortcuts in loading CSS. Check it out, it skips some frames when loading, to show the page faster.

Re: Google’s nightmare “Web Integrity API” wants a DRM gatekeeper for the web

#305
This highlights the evil of DMCA. DRM is not that big of a deal if you can freely exploit some vulnerability in you tpm / hardware attestation module, extract the keys, lobotomize the creep, visualize minimal functionality and share your research. With DMCA you're suddenly breaking the law at multiple steps of the way.

Re: Google’s nightmare “Web Integrity API” wants a DRM gatekeeper for the web

#306

The people involved in this concept/idea/proposal should be shamed into retirement. They should never work in the tech sector again. They should be afraid to use their names before first knowing their audience (an agricultural audience would likely be OK).

It's really perplexing how people in such privilidged positions would put their name on this. Either their not as smart as they appear or somehow manipulated/corrupted.

I would assume they are prominently putting their names on the proposal to claim they lead this effort during performance review. After all, they are probably expecting a big payout for something like this.

Re: Google’s nightmare “Web Integrity API” wants a DRM gatekeeper for the web

#307
post #114

The Chrome team have used "the Open Web" as a euphemism for what is to all intents and purposes Google's great ad supported walled garden. That so few people see this for what it is is amazing, and then they get all surprised when Google act to preserve it and close the capability gap with native platforms.

When Microsoft did this with IE, they did it with proprietary and undocumented APIs. The fact that this is an open spec, discussed in an open forum, using well established and standard technologies is what ensures it can never be positioned against users in any meaningful way. To me it looks like SGX for the web. Maybe it will introduce some neat and weird capabilities, but at the end of the day, it will be trivial t…

Yeah, like it is completely trivial to watch 4K Netflix in Firefox on Linux, right? Oh wait...

Re: Google’s nightmare “Web Integrity API” wants a DRM gatekeeper for the web

#308
post #74

Seems like this is going to get a lot of pushback. It might not go through. But remember whether it goes through or not isn't the important thing. The fact that Google wants it to is what matters.

Correct. If the pushback is successful, rest assured that the reprieve will be temporary. At best, they'll come back around with some tweaks and changes to blunt the more egregious aspects, but it will come back. The "privacy sandbox" stuff is a perfect example of this process.

> Correct. If the pushback is successful, rest assured that the reprieve will be temporary. At best, they'll come back around with some tweaks and changes to blunt the more egregious aspects, but it will come back.

Yes, they might even intentionally have started with proposal so over-the-top that people who are now protesting may feel that they won when some time afterwards Google presents slightly less creepy second iteration this. And the ones who don't will be cast as radicals who don't want to engage in good-faith discussion while Google seemingly proposes a reasonable compromise. Besides, would anybody please think of the child... err... banks with webpages!

Re: Google’s nightmare “Web Integrity API” wants a DRM gatekeeper for the web

#309
post #229

Earlier quoted context omitted.

For the same reasons a shop owner must sell to all customers without discriminating on ethnicity, religion, disability, etc? Would it be acceptable for a website owner to block users from Detroit (78% African Americans)[1] or block users from El Paso (82% Hispanic)[2] because the website owner claims that fraudulent ad clicking is more prevalent from those cities? Would it be acceptable to only serve web pages to peo…

I block China and Turkey from some of my websites to reduce bots and hacking attempts, does this make me a bad person for discriminating or should I have to tolerate the script kiddies, ddosing and exploit searches? I’m not defending google’s crap but I should be able to block anyone I want from my websites if I choose.

That's the same approach as requesting a valid phone number for a service that absolutely doesn't need a phone number, just to filter out potentially problematic users.

Is it within your rights ? totally. Does it make sense from a business perspective ? yes, probably. Is it morally right ? I'd say no. Will most people give you a damn about it ? probably not.

Most people won't care if you discriminate against some minority they're not part of and don't interact with. Some will, but I'm not sure how much it matters to you if you're seen as a "bad person" either way ?

Re: Google’s nightmare “Web Integrity API” wants a DRM gatekeeper for the web

#310
post #282

Earlier quoted context omitted.

> does this make me a bad person for discriminating Yes. And not only for discriminating. You make the web shittier than it already is, and more fragmented. > or should I have to tolerate the script kiddies, ddosing and exploit searches? This part is unrelated to the first part.

Yes, I am the bad guy for defending my sites from being defaced and my clients private data stolen from the bad actors coming from those two countries specifically. It is totally me making the internet a shittier place. If only I had the strength and energy to unblock those countries to tolerate the unrelenting abuse and attacks so I won't be such a terrible, horrible person.

> Yes, I am the bad guy

What's the point of asking a question (...does this make me a bad person for discriminating?) if you're not ready to accept some of the answers?

Yes, geoblocking totally makes the internet a shittier place. In the same way as the hackers and scriptkiddies make it the shittier place. It's a chicken and egg situation. You're blocking part of the world because it's dangerous waters. I am blocking part of the world because I disagree with the politics of that particular part. We are together making geo-blocking tolerable and acceptable. We're together making the internet more shitty than it deserves. Congratulations.

By the way, I'm not sure I wouldn't have done the same thing you did. I guess if I can't properly manage the security of a resource, the easiest way to deal with it would be to eliminate the source of the attack vector. I wouldn't deny that I'm part of the problem though. Because that's exactly what I am.

Post reply on HN