Live data from Hacker News

Web Environment Integrity Explainer

github.com

41–47 of 47 posts

Re: Web Environment Integrity Explainer

#42
post #10
post #9

Earlier quoted context omitted.

This is sarcasm right? Because otherwise it sounds like going to the bathroom during a commercial would be illegal.

Kellner did add "I guess there's a certain amount of tolerance for going to the bathroom." But if your bathroom breaks become too frequent, I guess you run the risk of "actually stealing programming".

Looking forward to the debates about the precise number and length of bathroom breaks per session that the networks would be willing to grant.

(I'm very sure they'll be willing to work out reasonable solutions for edge cases - i.e. you'll be granted up to 2 extra bathroom breaks if you have a corresponding medical condition. Just connect your Netflix and Samsung accounts with your healthcare provider's and they'll figure out the rest. We're all humans after all!)

Re: Web Environment Integrity Explainer

#43
post #5
post #3

The first use case they mention is restricting ad fraud (and, presumably, ad blocking): > Users like visiting websites that are expensive to create and maintain, but they often want or need to do it without paying directly. These websites fund themselves with ads, but the advertisers can only afford to pay for humans to see the ads, rather than robots. This creates a need for human users to prove to websites that the…

"Your contract with the network when you get the show is, you're going to watch the spots. Otherwise you couldn't get the show on an ad-supported basis. Anytime you skip a commercial or watch the button you're actually stealing programming." Jamie Kellner's words still ring true today. When corporations make content available supported by advertisements, they are assuming a moral obligation on your part to see those…

Jesus, I thought this was satire, but this guy is for real.

Not a lawyer, but in my understanding, the core property of a contract is that both sides are aware of it, in particular of their obligations in the contract. There must also be a defined moment the contract is concluded.

This is specifically not the case with ads: Ad-supported services are frequently advertised as "for free", not in the sense that ads are the "payment". Even if they were, they would be unlike any other business transaction as the service provider is free to change the "price" (i.e. amount of ads shown) at any time.

That's not even considering all the situations where you're subjected to ads without receiving any kind of service - or where something that you paid money for suddenly starts to show you ads too.

Felony contempt of business model indeed, as well as theft of assumed future profits!

Re: Web Environment Integrity Explainer

#44
post #17

The reason we can still run Linux on our desktops and laptops today, is that Linux was already popular enough back when Secure Boot was specified, so that Microsoft could be convinced to allow Secure Boot to be disabled and/or user-specified keys to be enrolled (and also to sign the bootloader for Linux distributions which follow a specific set of criteria when Secure Boot is enabled). Had desktop Linux not been popu…

I think Microsoft made it mandatory to allow disabling secureboot because they wanted their older OSs to work, didn't want devices getting bricked when a vendor poorly implemented it, and didn't want to get hit with another anti-trust suit. not necessarily in that order.

I've read that Surface ARM hardware had a secure boot that could not be disabled. This would make a lot sense; there was no legacy Windows for ARM to keep backwards compatibility for.

Re: Web Environment Integrity Explainer

#45

I would love to know the personal motivations and moral feelings of those who work on features like this. Are they naive about how these features will be used? Do they not care? Do they not have a personal sense of responsibility for contributing to the end of open, free computing? It's been a while since I took a Big Tech paycheck, but I don't remember being this willing to go build nightmare tech when I was getting…

"It is difficult to get a man to understand something, when his salary depends on his not understanding it."

Re: Web Environment Integrity Explainer

#46
Will anybody be able to do anything about it? This is not API for you and me. This is API for the big tech, for corporations, for Banks. They will use it, they will honour it. You may not use it, but because corporations will use it, it will become a standard. Three is no leeway. You have no control over big business. You will scream, they will do what they want.

Re: Web Environment Integrity Explainer

#47
post #2

Absolute worst spec I've ever seen. Google needs to be loaded into a cannon and fired into the sun. > How does this affect browser modifications and extensions? > Web Environment Integrity attests the legitimacy of the underlying hardware and software stack, it does not restrict the indicated application’s functionality: E.g. if the browser allows extensions, the user may use extensions; if a browser is modified, the…

> We need to legally regulate remote attestation. I'd go a step further. We need to ban it. It should be illegal to sell devices to consumers that already contain private keys, unless all of said keys are provided to the consumer at the time of purchase.

I would do it differently: I would ban remote attestation on all general-purpose electronic devices and for all devices that are meant to be part of the home and run third party software.

So computers, phones, and game consoles cannot have remote attestation but home security systems, ATMs, e-Readers, medical devices, water/electricity usage meters can do remote attestation.

Post reply on HN