Live data from Hacker News

Google’s nightmare “Web Integrity API” wants a DRM gatekeeper for the web

arstechnica.com

351–360 of 484 posts

Re: Google’s nightmare “Web Integrity API” wants a DRM gatekeeper for the web

#351
post #32

> Exactly how the rest of the world feels about this is not necessarily relevant, though. Google owns the world's most popular web browser, the world's largest advertising network, the world's biggest search engine, the world's most popular operating system, and some of the world's most popular websites. So really, Google can do whatever it wants. This is the point that company breakups start to make a lot of sense.…

This line is what makes me roll my eyes whenever I hear someone say "Safari is the new IE". Safari missing a couple of features few websites use is far less of an issue than the dominant browser company can just invent new "standards" that make the web actively worse for everyone. (Sorry, I should say "everyone except for the scummy advertisers".)

Would it surprise you to know that Safari on iOS and OS X already implements exactly this kind of attestation API? It does!

Re: Google’s nightmare “Web Integrity API” wants a DRM gatekeeper for the web

#352

That's wrong on so many levels, I don't know even where to start. First of all I hate this "proposals" which is actually, "we implemented this in our flagship product, and kindly force it on our users, you don't have to use it, if you have a choice", stance. Then comes all the "ensuring they aren't a robot and that the browser hasn't been modified or tampered with in any unapproved ways." part. I'm using an open sour…

> It's 90s DRM wave all over again. Except in the 90s you controlled 100% of the code running on your computer. Now there are all kinds of treacherous computing with all those "trusted" execution environments and TPMs and all the other bullshit that can't be avoided, with someone else's public keys burned into the silicon.

You can still control the code running on your computer. But the websites you send http requests to don’t have to respond.

Re: Google’s nightmare “Web Integrity API” wants a DRM gatekeeper for the web

#353

It's great to see this getting more attention. User-agent discrimination (i.e. "go away if you're not using the latest version of Chrome") needs to become illegal. As long as I'm not overloading your service or similar, what hardware or software I use must not be restricted. The same goes for other deliberate obstacles to accessibility and interoperability --- creating a "standard" that's so complex and churned frequ…

> As long as I'm not overloading your service or similar, what hardware or software I use must not be restricted.

A lot of the push is not for bad actors literally DDOSing servers, but bad users degrading the service for other users. If most users of a service agrees to, for example, run an attestable environment to access a service, then that service should be able to refuse access to users who don’t buy into it.

Re: Google’s nightmare “Web Integrity API” wants a DRM gatekeeper for the web

#355

Earlier quoted context omitted.

> It's 90s DRM wave all over again. Except in the 90s you controlled 100% of the code running on your computer. Now there are all kinds of treacherous computing with all those "trusted" execution environments and TPMs and all the other bullshit that can't be avoided, with someone else's public keys burned into the silicon.

You can still control the code running on your computer. But the websites you send http requests to don’t have to respond.

You can't. On most modern systems there is software that runs with privileges above your OS kernel that you can't remove or modify because it is signed with the manufacturer's key. The key is part of a "trusted" boot chain. The root of trust is usually burned into the silicon in the fuses or the initial bootloader (boot ROM).

TEE on Android, for example. Intel ME on PCs, and probably TPMs also have a firmware of their own. Secure Enclave on Apple devices.

There's an outstandingly good perspective on the issue in another thread: https://news.ycombinator.com/item?id=36859465

Re: Google’s nightmare “Web Integrity API” wants a DRM gatekeeper for the web

#356

Earlier quoted context omitted.

I don't buy this. I'm sure most iphone users don't care when you ask them about privacy or manifest v3 as an abstract concept, but remember what happened when Apple tried to push a U2 album to them? They lost their collective shit. They may not write blog posts about privacy or donate to the EFF, but they have deeply personal relationships with "their" phone and they absolutely hate being reminded that it isn't reall…

> when Apple tried to push a U2 album to them? They lost their collective shit. Yeah, Apple was toast after they did that. Their share price in 2014 when they did that was $24, and immediately afterwards it rose to $33 over the next 12 months. And since then, it's just been one long slow decline to almost $200 a share, as their global mobile market share has gone from the 24% it enjoyed in 2014 to the measly 29% it e…

You’re forgetting a 4:1 stock split in August 2020, so it’s even worse ;-)

I think this illustrates that people only worry about this kind of thing if it gets shoved into their face.

The privacy thing is OK as long as it’s only used for the good. For example, I think nobody would object against a world where every killer would be caught within an hour to get a fair trial.

However, such a world also would be one where every traffic offense could be fined, and where powers that be could find some dirt on anybody in their email history, presence on on-street cameras, etc. Worse, it would take relatively few people to pull that of.

That’s something I think nobody wants, but it’s abstract until it affects you, so few people worry about it.

Re: Google’s nightmare “Web Integrity API” wants a DRM gatekeeper for the web

#357

Earlier quoted context omitted.

Using Firefox on a couple of Macs (one of them is >8 years old), and a couple of Linux systems. Setting aside the fact that it's as fast as or faster than Chrome, it doesn't crawl any of my machines with >500 tabs (this has 562 as of now). If you want to dig into your performance numbers there's "about:performance" to see what is using your processor and RAM.

Did that and weirdly nothing seems to be excessive... indeed the Macs own performance monitor doesn't suggest anything is particular excessively using cpu or ram but here it is juddering away especially when scrolling pages. Three year old Mac btw... everything else runs pretty well... if I get a chance I might fire up Firefox in Parallels and see if it's a Mac issue

When you write "about:performance" to your address bar, and press enter, you should access to the internal performance monitoring page of Firefox. That should list every tab and extension by RAM use and power impact.

Give it a go.

Re: Google’s nightmare “Web Integrity API” wants a DRM gatekeeper for the web

#358
post #156

Earlier quoted context omitted.

ISPs will not be letting that traffic through. So no little romantic underground. No cycle; the internet is happening just once, and we're in it. The assumption that everything is necessarily part of a little epicycle of history somehow mashes together Whig history and and an inert nihilism. Don't worry, nothing matters? We're not in a movie. When they close the open internet, there will be no reason for them to open…

If we're talking cyberpunk dystopias, we'd have to resort to hand-soldered audio couplers that use our locked-down phones as modems. Once the next Android/iOS update detects and blocks unauthorized binary carriers, we'll have to steganographically hide our traffic in fake voice calls. Crappy baud rate, but good enough for encrypted text. Augment with sneakernet and local hard-wired networks running under lawns and do…

> If we're talking cyberpunk dystopias, we'd have to resort to hand-soldered audio couplers that use our locked-down phones as modems

…and they will make us use lead free solder.

Re: Google’s nightmare “Web Integrity API” wants a DRM gatekeeper for the web

#359

The people involved in this concept/idea/proposal should be shamed into retirement. They should never work in the tech sector again. They should be afraid to use their names before first knowing their audience (an agricultural audience would likely be OK).

I don't think calling for targeted harassment is acceptable in *any* case. That's just taking it way too far.

It would be more productive to make it impersonal. E.g., by asking Chrome users to abandon it fast.

Re: Google’s nightmare “Web Integrity API” wants a DRM gatekeeper for the web

#360
post #63
post #32

> Exactly how the rest of the world feels about this is not necessarily relevant, though. Google owns the world's most popular web browser, the world's largest advertising network, the world's biggest search engine, the world's most popular operating system, and some of the world's most popular websites. So really, Google can do whatever it wants. This is the point that company breakups start to make a lot of sense.…

> When Google can do something that every one of it's users hates I don't think this is remotely the case. Quite a few tech-savvy people I know (some of them software developers) use Chrome and mostly don't care about whatever Google does with it. I mention "manifest v3" and get a blank stare. I talk about advertising and ad blockers, and most people don't care, with some of them not even using ad blockers. We really…

Yeah, because you called it manifest V3, not gimping adblockers, which is what it actually was. How many of Google's users love that they're gimping adblockers?

Same for Web Environment Integrity API. Nobody knows what those jargon terms means. That's part of how enshittification works. If everyone knew how badly they were being fucked, this would never work.

Post reply on HN