Live data from Hacker News

Web Environment Integrity API Proposal

github.com

341–350 of 460 posts

Re: Web Environment Integrity API Proposal

#341
post #65

Earlier quoted context omitted.

> How can this view be with this spec, which he is the main author of? Surely Ben sees the parallels? It can be reconciled with love for money and total lack of moral fiber. Aka « I don’t give a shit about my actions destroying every one, as long as I go get paid »

I think it's very easy to treat people in such a binary manner. I get it. What this guy's doing is shameful, but I've seen dozens of otherwise lovely people, working for charities, spending much more time on socially-important and useful work than 90% of the crowd here... and the same people would push barely legal (if not illegal) targeting on masses of people, arguing to push cigarette ads in markets that still all…

> I've seen dozens of otherwise lovely people, working for charities, spending much more time on socially-important and useful work than 90% of the crowd here

As if you personally know 90% of the people here? And how many of those 10% would never ever push advertising on anyone, would you guess?

It's moot anyway, you cannot compensate for a lie by giving someone a lot of cake, even all the cake in the world. It's apples and oranges.

> Advertising is cancer and the current model is not sustainable.

"Advertising" is just a shorthand for the concrete actions concrete individuals engage in. There is no "model" outside of hundreds of decisions people make every day. It's like blaming "capitalism" and pretending people just play the "game" as if that existed outside of those actions. For any person you could name, I can find you someone in the same situation who refused to do the evil thing.

Re: Web Environment Integrity API Proposal

#342

Earlier quoted context omitted.

https://waterfox.net/ to the rescue.

Surely you don't mean Waterfox that states in their FAQ[0]: "Who owns Waterfox?" "System1 now own Waterfox, but Alex Kontos is still leading the direction of Waterfox and will be for the foreseeable future." And who's owner, System1, states at the top of their page[1]: "System1 operates the most dynamic Responsive Acquisition Marketing Platform Connecting high intent customers with advertisers at scale" [0]: https://…

I surely do mean exactly that particular Waterfox. I've had my fair share of concerns back in the day when System1 acqui(hi)red Waterfox, but I haven't seen any suspicious behaviour whatsoever so I'm pretty confident it's fine for the time being.

Of course, if you know a better browser (that is not Chromium-based), I'll be happy to hear your suggestions!

Re: Web Environment Integrity API Proposal

#343
post #336

I am not a hopeful romantic, but the EU has been investing on vendor neutral web-browsers like Nyxt [0] and the UR Browser [1] through the Horizon Europe program. I doubt that legislators (at least in the EU) will view this as a positive development, assuming EU legislators know what they are doing. On the other hand, lobbying by big tech is still very much a threat. [0] https://nyxt.atlas.engineer/ [1] https://www.u…

The first one is close-sourced. Why should I choose it over a open-core alternative (Chrome).

Nyxt is not close sourced :-)

Re: Web Environment Integrity API Proposal

#344
post #124

Earlier quoted context omitted.

I think in this case Firefox is in a different position: if it didn't support EME netflix wouldn't work. But in this case it could report "sure, this is a real user alright" by being its own attester, can't it?

If Firefox lies, sites will refuse to load in Firefox.

Of course, but if Google did that it would allow Firefox to complain about Google's abuse of monopoly power. I'm not sure that is a path they'd risk going through.

Re: Web Environment Integrity API Proposal

#345

Earlier quoted context omitted.

I think in this case Firefox is in a different position: if it didn't support EME netflix wouldn't work. But in this case it could report "sure, this is a real user alright" by being its own attester, can't it?

Sites will just stop trusting that as an attester. Anyone can write their own EME plug in that writes the files to disk. But it won't have the keys of any trusted module, because the reason sites trust them is because they don't do that. So it won't get accepted by anyone. Same here.

But they address this in the spec (kinda), suggesting that whitelisting attesters should not be possible.

Presumably this is because if it was, it would open Google to abuse of dominant position claims.

Re: Web Environment Integrity API Proposal

#346
post #5

This is pretty much the inevitable end-game of the web, in no small part funded by ad-based business models (as the analog gap pretty much destroys most attempts to use this stuff to do copy protection) and enabled by developers who have insisted we shove as much difficult-to-implement functionality (by which I am talking about CSS complex stuff, not powerful-but-easy-to-code APIs for OS-level access) into the browse…

Hello! I am Sampson, from Brave.

Brave is an advertising company, but we’re quite different from Google and others in this space. Brave's ad notifications are opt-in and engineered in such a way to protect and preserve user privacy. I'm not sure where you saw Brave engineers talking about ways to prevent users from blocking our ads—we don’t try to prevent users from blocking Brave Ads.

If you wish not to see Brave’s ad notifications, you can easily avoid them (by not opting-in in the first place, or by throttling/disabling-entirely). There are no special hoops to hop through, or technical incantations to utter. We believe digital advertising is better when it is built on user-first principles and consent.

If a user opts-in to Brave’s ad notifications, their device proceeds to routinely download-and-maintain a regional catalog of available inventory. The user's device then evaluates the catalog entries for relevance. User data is NOT sent off-device in Brave’s model. If a relevant ad entry is found, it is then displayed to the user in such a time and manner for minimal distraction. When an ad notification is shown, the user receives 70% of the associated ad revenue for their attention (no clicks required).

Again, if the user wishes to not see ad notifications, they can simply choose not to opt-in to viewing them. If the user wishes to not see the occasional sponsored image on the New Tab Page, they can turn those off from the New Tab Page itself with 2 clicks ( Customize › Show Sponsored Images). Importantly, the user is always in control. They decide whether ads will be displayed, and to what degree (e.g., the user can set a limit on ad notifications per hour).

Brave isn't interested in coercing users to view advertisements.

Re: Web Environment Integrity API Proposal

#347
post #340

Proposal author here I’m hoping to get back to everyone as soon as possible. I hope you can all appreciate that I’m a human being and this has been a lot! In the mean time, I wanted to repost my last comment on the GitHub issue thread [1]: Hey all, we plan to respond to your feedback but I want to be thorough which will take time and it’s the end of a Friday for me. We wanted to give a quick TL;DR: - This is an early…

> It’s also an explicit goal to ensure that user agents can browse the web without this proposal How, in an information theory sense, can you stop website operators from using this attestation information to block subsets of users? The "holdback" mentioned in your reference link seems like an optional thing, as if we're concerned about good faith actors rather than the opposite. It would be nice if the spec included…

I'm one of the blink API owners who would need to approve this feature if it were to ship in Chrome. I outlined some of my thoughts on this earlier here: https://groups.google.com/a/chromium.org/g/blink-dev/c/Ux5h_...

It's complex and nuanced, all about altering probabilities of various bad things and TBH work still needs to be done to prove a useful middle ground even exists.

But one thing I can say for sure is there's no way I'm approving Chrome adding a feature which makes it possible for websites to be viewed only in Chrome. Nobody wants that and it's listed as an explicit anti-goal of the feature. Chrome couldn't have existed in the first place without masquerading as Safari, who masqueraded as Netscape etc.., this is something we're all very aware of and committed to in Chrome as its core to the openness of the web.

Re: Web Environment Integrity API Proposal

#348

Earlier quoted context omitted.

> how do we protest this? You do not and you cannot. It was written in stone once Chrome dominated the browser market. What Chrome (Google) wants, Chrome (Google) gets. Despite all the good engineering Google wants to sell ads, that's all there is to it. And the result is this proposal. > The saving grace here might be that Firefox won't implement the proposal. It's irrelevant and we are an irrelevant minority. Unles…

We could at least get everyone here to use Firefox. There's really no excuse for a technically minded person to still be using Chrome for their day to day browsing. If you do eventually run into a poorly crafted webpage that doesn't work on Firefox you have the wherewithal to decide if you are simply not going to use that site or hop over to chrome just this once. But the important thing is checking in automatically…

I use Vivaldi (not chrome itself but another Chromium browser) because I want PWA support on my Linux machine so I can have an app for outlook with notifications and Chromium browsers make that far more convenient than Firefox.

Re: Web Environment Integrity API Proposal

#349
post #305
post #289

Earlier quoted context omitted.

> We could at least get everyone here to use Firefox. That would accomplish nothing. > But the important thing is checking in automatically as a Firefox user in the logs of every other site online. No, that's not important. HN users are a tiny minority compared to the billions of people that use the web daily. I'm sorry, there's no easy way to say this: Firefox is never coming back. The web of old is never coming bac…

Google is not stronger than the EU.

This presumes that the EU

(1) Understands what this is about

(2) cares about its citizens' freedom

(3) has enough coherence to actually do something about it

It's not obvious to me that any of these apply. The EU is pushing -- in fits and starts -- towards self-reliance in its computing infrastructure, but at a slow pace.

Re: Web Environment Integrity API Proposal

#350
post #265

Earlier quoted context omitted.

but "Netflix and my bank actually work in Chrome" is Google's endgame.

the adblock "endgame" will be a self-hosted DNS system that blocks requests to ad-server urls (or return benign responses). Then the game will switch to encrypted proxied traffic that you cannot block. Then the adblocking software will switch to the GPU layer, and use machine learning and AI to wipe the region of memory in the GPU containing the ads (and replace it with something benign). Then the next logical step f…

The browser... or the javascript running in it, served from the primary domain you are browsing will just do DNS over HTTP from within the browser, completely avoiding your dns filter
Post reply on HN