Live data from Hacker News

Web Environment Integrity API Proposal

github.com

401–410 of 460 posts

Re: Web Environment Integrity API Proposal

#403

Earlier quoted context omitted.

Unfortunately, what you link doesn't answer how they will prevent it being used to create walled gardens. It's just an open question, and as such, it does seem it's an afterthought, when it should be front and center if anyone care for an open web.

Wouldn't a holdback prevent it from being used to create walled gardens?

I doubt it. As explained by GitHub user tbrandirali, the stated goals seem to be inherently contradictory. Quoting in part:

"This internal contradiction is further demonstrated by the fact that the proposed solution to prevent misuse by websites - holdbacks - is to simply sabotage the functionality of the system itself, by making attestation probabilistic. This is not a workable solution to the problem: if the holdback rate of requests is low enough, the denial of service to legitimate users will simply be a cost of business that websites will accept; if instead it is high enough, websites will not use this system as it does not provide meaningful enough information, even for analytics purposes, due to the high uncertainty. There is no goldilocks zone where this system is useful but not open to abuse by implementer websites. You're either implementing a feature that can - and most likely will - be used by websites to exclude unattested clients, or you're implementing a useless feature."

https://github.com/RupertBenWiser/Web-Environment-Integrity/...

Re: Web Environment Integrity API Proposal

#404
post #83

There is one thing I'm not quite clear on here: >The attestation is a low entropy description of the device the web page is running on. >The attester will then sign a token containing the attestation and content binding (referred to as the payload) with a private key. >The attester then returns the token and signature to the web page. >The attester’s public key is available to everyone to request. I'm assuming "attes…

There's some quite complex cryptographic machinery called Direct Anonymous Attestation that would make this possible. I don't know if they plan on using this though.

Re: Web Environment Integrity API Proposal

#405
post #289

Earlier quoted context omitted.

> We could at least get everyone here to use Firefox. That would accomplish nothing. > But the important thing is checking in automatically as a Firefox user in the logs of every other site online. No, that's not important. HN users are a tiny minority compared to the billions of people that use the web daily. I'm sorry, there's no easy way to say this: Firefox is never coming back. The web of old is never coming bac…

>Google is more powerful than most governments See that's where I disagree. Rich governments like the EU or the US can and do have power to push regulations if they wanted to . Pretending we the people (in a broad sense), i.e. the state, have no power whatsoever to control the terms under which these companies operate within the state , is defeatist.

Bringing up "We, the people" here is ridiculous, regardless of the "sense". We have zero power. Zero. Protests, revolts, riots ... all make no difference anymore and making a cross on a piece of paper once every couple years, aka voting, doesn't give us power. Anyone believing that is a fool.

Re: Web Environment Integrity API Proposal

#406
This isn't just Google. The whole hardware industry is moving towards the Digital Lockdown. This idea has been around, at least, since the early 2000s, but the people who were talking about it, of course, got shouted down as conspiracy theorists.

And as far too often, the "conspiracy theorists" were right, but nobody cares about ever thinking about that, because nobody seems to be actually able to think about things anymore, unless the thoughts are breast-fed.

We're heading towards a reality, where copypasting from a website is going to cost you money if the license requires you to do so. Looking at it, considering the status quo of technology, almost everything required for a "trusted" environment is already present in consumer-hardware.

We have hypervisors, virtualization, containerization. Encryption/Decryption of data in RAM/CPU in real-time is coming eventually. Blockchain technology makes verification of digital ownership secure and easy. AI will make it stupidly easy for corporations to make sure that everyone complies and I will be everywhere within the next few years.

A glimpse of this reality can be seen in NovaQuark's "Dual Universe", where everything is behind DRM. A "metaverse" company for a reason, I guess.

Re: Web Environment Integrity API Proposal

#407

Earlier quoted context omitted.

>Google is more powerful than most governments See that's where I disagree. Rich governments like the EU or the US can and do have power to push regulations if they wanted to . Pretending we the people (in a broad sense), i.e. the state, have no power whatsoever to control the terms under which these companies operate within the state , is defeatist.

Bringing up "We, the people" here is ridiculous, regardless of the "sense". We have zero power. Zero. Protests, revolts, riots ... all make no difference anymore and making a cross on a piece of paper once every couple years, aka voting, doesn't give us power. Anyone believing that is a fool.

It certainly allows us to avoid the worst of 2 evils in any case and nudge the ship of state away from obvious rocks where extremist positions cause politicians to lose elections. Furthermore many states have a means for individuals to directly make law on matters that directly concern enough sufficient voters.

Re: Web Environment Integrity API Proposal

#408

Add "integrity" to the list of adjectives used for obfuscating the rise of authoritarian dystopia... It all started with "trusted computing", where "trusted" means "not under the owner's control". Then they tried to spin it as a "security" thing with TPMs, and created the impression that those speaking out against them were either malicious actors or insane conspiracy theorists. Now it is actually happening. They wan…

This would be the method of last resort. I think secure boot as a technology actually has security advantages, if you can freely set the keys. That was what the tech was advertised as to console the critics, but if course it would run counter to the goal of controlling hardware if this was actually implemented consistently. I think regulation to force vendors to provide this option (and in a frictionless, actually usable manner) could do a lot here.

Second is more focus on nag screens, "nudges" and other deliberately degraded UX. I.e. with the Surface tablets, you're technically able to disable secure boot, however you'll then be greeted with an ugly bright red boot screen every time you turn the device on. This stuff can have significant psychological impact, especially for "casual" users.

Re: Web Environment Integrity API Proposal

#409
post #5

This is pretty much the inevitable end-game of the web, in no small part funded by ad-based business models (as the analog gap pretty much destroys most attempts to use this stuff to do copy protection) and enabled by developers who have insisted we shove as much difficult-to-implement functionality (by which I am talking about CSS complex stuff, not powerful-but-easy-to-code APIs for OS-level access) into the browse…

Hello! I am Sampson, from Brave. Brave is an advertising company, but we’re quite different from Google and others in this space. Brave's ad notifications are opt-in and engineered in such a way to protect and preserve user privacy. I'm not sure where you saw Brave engineers talking about ways to prevent users from blocking our ads—we don’t try to prevent users from blocking Brave Ads. If you wish not to see Brave’s…

Does Brave support this proposal?
Post reply on HN