Live data from Hacker News

Google’s nightmare “Web Integrity API” wants a DRM gatekeeper for the web

arstechnica.com

381–390 of 484 posts

Re: Google’s nightmare “Web Integrity API” wants a DRM gatekeeper for the web

#381
post #237

Earlier quoted context omitted.

They have also violated an important Code of Conduct [1], to the point of even aggressively closing valid complaints [2]. The Googlers RupertBenWiser [3] and yoavweiss [4] are really just toeing the Google line. What's super gross is even yoavweiss tried to play pretend that the original issue they forced closed, without comments or reading, was "spam" [5]. I believe both of these users are acting in very-bad-faith,…

Do not dox individuals. You do not understand their situations, pressures, etc.

Linking to public profiles and GitHub discussions isn't doxxing. Sharing the Googlers' private, personal information would be but I at least don't see anything like that in the GP post now.

Re: Google’s nightmare “Web Integrity API” wants a DRM gatekeeper for the web

#382
post #360
post #63

Earlier quoted context omitted.

> When Google can do something that every one of it's users hates I don't think this is remotely the case. Quite a few tech-savvy people I know (some of them software developers) use Chrome and mostly don't care about whatever Google does with it. I mention "manifest v3" and get a blank stare. I talk about advertising and ad blockers, and most people don't care, with some of them not even using ad blockers. We really…

Yeah, because you called it manifest V3, not gimping adblockers, which is what it actually was. How many of Google's users love that they're gimping adblockers? Same for Web Environment Integrity API. Nobody knows what those jargon terms means . That's part of how enshittification works. If everyone knew how badly they were being fucked, this would never work.

I actually don't understand it well. What does it mean? I can't browse the web from xubuntu any more? I believe it's scary, but can't seem to actually sell myself on that.

If it's so bad, why can't we bring a monopoly lawsuit against them over chrome/chromium? This is pretty similar to what Microsoft did, isn't it?

Re: Google’s nightmare “Web Integrity API” wants a DRM gatekeeper for the web

#383

I think this is one of the shittiest things I've seen so far. The thing with this is that is invisible to 98% of regular users out there. It's already hard to explain things clearly to non-tech persons as why certain policies are harmful at the privacy level. And even if they do understand you, in most cases their perception of you is as someone really paranoid about privacy, and yes they will undoubtly ask things li…

[deleted]

Re: Google’s nightmare “Web Integrity API” wants a DRM gatekeeper for the web

#384

Earlier quoted context omitted.

Safari has far more weight here though people are loathe to admit it. Apple's market share is a direct check on Google's ability to push things through so easily. Firefox unfortunately does not have the numbers on their side nor will they seemingly risk their Google payout deal. At this point, if you're using it, you're doing it because it has specific features or extensions you want, or you believe that it's ethical…

> Safari has far more weight here though people are loathe to admit it. On HN people are more likely to complain about Safari existing and demand Chrome everywhere.

Is thst still the case? I've actually noticed much less Safari bashing over the last year or two, around the time the team seemed to really focus on shipping new specs and features again.

The main complaints I still see are related to the (likely illegal) lack of support for third party browsers, and missing web APIs for things like push notifications. Those are still valid complaints today though, for anyone who cares about them.

Re: Google’s nightmare “Web Integrity API” wants a DRM gatekeeper for the web

#385

It's great to see this getting more attention. User-agent discrimination (i.e. "go away if you're not using the latest version of Chrome") needs to become illegal. As long as I'm not overloading your service or similar, what hardware or software I use must not be restricted. The same goes for other deliberate obstacles to accessibility and interoperability --- creating a "standard" that's so complex and churned frequ…

> As long as I'm not overloading your service or similar, what hardware or software I use must not be restricted. A lot of the push is not for bad actors literally DDOSing servers, but bad users degrading the service for other users. If most users of a service agrees to, for example, run an attestable environment to access a service, then that service should be able to refuse access to users who don’t buy into it.

> If most users of a service agrees to, for example, run an attestable environment to access a service

With Chrome's near monopoly in browsers, most users will run an attestable environment when chrome ships it without ever knowing and agreeing to doing so.

Even if Google manages to "collect" consent, this has so much potential to adversely impact everyone(including businesses) except Google in the long term that it should not be allowed.

Re: Google’s nightmare “Web Integrity API” wants a DRM gatekeeper for the web

#386

I've been reading HN since its birth and have been in the browser game for 25 years. HN, as a collective, shit all over Firefox and Mozilla for a decade while Google, who was never going to to anything but this, did just this. Good job.

There's not necessarily a contradiction here—both companies can be completely screwed up at the same time.

I think the intent and scope of their failures is orders of magnitude different in terms of their impact on society and the free Internet though.

Re: Google’s nightmare “Web Integrity API” wants a DRM gatekeeper for the web

#387
post #287
post #249

Earlier quoted context omitted.

Both RupertBenWiser and yoavweiss reputations are fully gone from this. Pretty much the moment they closed an issue without a single comment [1], locked the repo from everyone else, and then a much later time claiming it was "spam" is a pretty dirty tactic [2]. [1] https://github.com/RupertBenWiser/Web-Environment-Integrity/... [2] https://github.com/RupertBenWiser/Web-Environment-Integrity/...

Of course nothing happened to their reputations. Unfortunately there are very few people who care about this, or now who the people are in these proposals. A reminder: the tech lead for AMP who promptly closed all discussions critical of AMP and AMP for email, and banned people who raised the questions repeatedly is now the CTO of Vercel.

That explains the bad vibes I get from vercel.

Re: Google’s nightmare “Web Integrity API” wants a DRM gatekeeper for the web

#388
post #382
post #360

Earlier quoted context omitted.

Yeah, because you called it manifest V3, not gimping adblockers, which is what it actually was. How many of Google's users love that they're gimping adblockers? Same for Web Environment Integrity API. Nobody knows what those jargon terms means . That's part of how enshittification works. If everyone knew how badly they were being fucked, this would never work.

I actually don't understand it well. What does it mean? I can't browse the web from xubuntu any more? I believe it's scary, but can't seem to actually sell myself on that. If it's so bad, why can't we bring a monopoly lawsuit against them over chrome/chromium? This is pretty similar to what Microsoft did, isn't it?

The problem with remote attestation is that there's no bound to exactly how bad it could become. If you can get enough of the internet on browsers that support remote attestation, to the point where it's an acceptable loss to simply reject anyone who does not have a browser that does support remote attestation, you can theoretically assert full control over the end user.

What will actually happen? Nobody knows for sure. The most likely outcome is that you will not be able to do banking, watch Twitch streams, etc. on anything other than Chrome, Firefox and Edge, on Windows and macOS. Linux will probably be relegated to the legacy web that does not enforce remote attestation. Alternate browsers like Librewolf, Brave and Mullvad Browser will just disappear as if they never existed. You can not browse Tor on clearnet websites anymore, as if you really could anyways. Etc, etc.

> If it's so bad, why can't we bring a monopoly lawsuit against them over chrome/chromium? This is pretty similar to what Microsoft did, isn't it?

Microsoft of today is doing things blatantly in the open, that Microsoft of 199x would never dream of doing. The difference now is that all of the major computer manufacturers are basically going the same way, just at different rates.

The legal system is not coming to rescue us.

Re: Google’s nightmare “Web Integrity API” wants a DRM gatekeeper for the web

#389

It's great to see this getting more attention. User-agent discrimination (i.e. "go away if you're not using the latest version of Chrome") needs to become illegal. As long as I'm not overloading your service or similar, what hardware or software I use must not be restricted. The same goes for other deliberate obstacles to accessibility and interoperability --- creating a "standard" that's so complex and churned frequ…

> It's great to see this getting more attention. User-agent discrimination (i.e. "go away if you're not using the latest version of Chrome") needs to become illegal. I really hate this attempt by Google and hope they don't follow through, but why should this be illegal? Software users agent strings are just an identifier added on by a browser to give the server context, it's not a protected class. Google has every ri…

[dead]

Re: Google’s nightmare “Web Integrity API” wants a DRM gatekeeper for the web

#390

The people involved in this concept/idea/proposal should be shamed into retirement. They should never work in the tech sector again. They should be afraid to use their names before first knowing their audience (an agricultural audience would likely be OK).

I don't think calling for targeted harassment is acceptable in *any* case. That's just taking it way too far. It would be more productive to make it impersonal. E.g., by asking Chrome users to abandon it fast.

You don't think that targetted "harassment" (e.g. publicly calling them dangerous people working against the interests of almost all of us) is called for when they advocate for and actively attempt design a system designed to take away power from us all as individuals?

What would justify targetted harassment, then?

> by asking Chrome users to abandon it fast.

More productive? Or just utterly ineffective?

Post reply on HN