Live data from Hacker News

Google’s nightmare “Web Integrity API” wants a DRM gatekeeper for the web

arstechnica.com

411–420 of 484 posts

Re: Google’s nightmare “Web Integrity API” wants a DRM gatekeeper for the web

#411
post #371

Earlier quoted context omitted.

So many people are harsh Google critics, yet still never use duckduckgo, don't try to migrate from gmail, or stick to firefox. Complaining is easy, but apparently even small compromises like these are hard.

I use Firefox on desktop and mobile, I use DDG, stopped using Google Analytics but I sadly still use Gmail and Android. I degoogled the east things (e.g. GA and Chrome) but getting totally rid off Google is hard.

> getting totally rid off Google is hard

Sometimes impossible in my case. Google Drive is always used in any collaborative project; so is Google Colab and Google Meet. And I still have the instinctual drive to reach for Google Translate/Maps, because it's so easy to access (physically and mentally).

Google google google google google...

Re: Google’s nightmare “Web Integrity API” wants a DRM gatekeeper for the web

#412
post #229

Earlier quoted context omitted.

For the same reasons a shop owner must sell to all customers without discriminating on ethnicity, religion, disability, etc? Would it be acceptable for a website owner to block users from Detroit (78% African Americans)[1] or block users from El Paso (82% Hispanic)[2] because the website owner claims that fraudulent ad clicking is more prevalent from those cities? Would it be acceptable to only serve web pages to peo…

This is a massive leap in assumptions and arguments. For one, blocking users in a geographic region would not be legally considered racial discrimination unless you can prove intent. This is the bullshit loop hole that makes it easy to get away with discrimination, but that's the way it works. If Google really wants to play this game and create a technical gate preventing usage of sites by anyone that uses a browser…

The grandparent comment asked whether a website owner would ever be unjustified in deciding who can use their website.

From a legal viewpoint, the answer is dependent on the complexity of state laws[1]. What a website owner can do with a website in one country obviously differs from what they could do in another country. Most countries have very weak anti-discrimination laws, and if they do exist, they typically only apply for very specific purposes such as employment discrimination based on age. These limited laws tend to be near impossible to enforce short of someone self-incriminating themselves. In some countries however, an example being Norway, laws against discrimination can be very strict and routinely enforced to the level of requiring all website owners to implement WCAG 2.0 at AA level[2].

From an ethical viewpoint, the Universal Declaration of Human Rights[3] states in Article 2:

  "Everyone is entitled to all the rights and freedoms set forth in this Declaration, without distinction of any kind, such as race, colour, sex, language, religion, political or other opinion, national or social origin, property, birth or other status.

  Furthermore, no distinction shall be made on the basis of the political, jurisdictional or international status of the country or territory to which a person belongs, whether it be independent, trust, non-self-governing or under any other limitation of sovereignty."
And numerous other articles are relevant, including Article 19:

  "Everyone has the right to freedom of opinion and expression; this right includes freedom to hold opinions without interference and to seek, receive and impart information and ideas through any media and regardless of frontiers."
[1] https://en.wikipedia.org/wiki/List_of_anti-discrimination_ac...

[2] https://www.uutilsynet.no/english/about-us/903

[3] https://www.ohchr.org/en/human-rights/universal-declaration/...

Re: Google’s nightmare “Web Integrity API” wants a DRM gatekeeper for the web

#413

Earlier quoted context omitted.

And in practice it will eventually mean being unable to do online banking if you're on Linux. My Android phone with a custom ROM doesn't pass even a basic SafetyNet check, and this means I essentially cannot use mobile banking. For now, using a browser on my phone is a "workaround", but this proposal could change that

And yet millions of users benefit from SafetyNet every day. Just because something constrains openness does not make it inherently bad.

Millions of users are subjected to SaftetyNet. Your claim that this is to their benefit is unfounded.

Re: Google’s nightmare “Web Integrity API” wants a DRM gatekeeper for the web

#414
post #385

Earlier quoted context omitted.

> If most users of a service agrees to, for example, run an attestable environment to access a service With Chrome's near monopoly in browsers, most users will run an attestable environment when chrome ships it without ever knowing and agreeing to doing so. Even if Google manages to "collect" consent, this has so much potential to adversely impact everyone(including businesses) except Google in the long term that it…

If the customer is already running in an attestable environment, why would they disagree with attesting to that environment? > this has so much potential to adversely impact everyone(including businesses) except Google in the long term How so? It prescribes mechanisms to ensure websites don’t exclude certain browsers/OSes > To protect against both risks, we are evaluating whether attestation signals must sometimes be…

> If the customer is already running in an attestable environment, why would they disagree with attesting to that environment?

There are countless modern PCs that have secureboot enabled by default. Does that mean all their users endorse and agree with secure boot based attestation knowingly?

My point is defaults cannot and should not automatically be treated as implicit consent/knowledge.

Attestation will be enabled by default when Chrome ships WIE and the "majority" condition you mentioned will most certainly be true from day one. That doesn't necessarily mean that every single user of chrome is onboard and happy with WIE.

Re: Google’s nightmare “Web Integrity API” wants a DRM gatekeeper for the web

#415
post #371

Earlier quoted context omitted.

So many people are harsh Google critics, yet still never use duckduckgo, don't try to migrate from gmail, or stick to firefox. Complaining is easy, but apparently even small compromises like these are hard.

I use Firefox on desktop and mobile, I use DDG, stopped using Google Analytics but I sadly still use Gmail and Android. I degoogled the east things (e.g. GA and Chrome) but getting totally rid off Google is hard.

The very last Google service I still use is YouTube, and I'm looking to leave that very soon.

Re: Google’s nightmare “Web Integrity API” wants a DRM gatekeeper for the web

#416

Earlier quoted context omitted.

You can still control the code running on your computer. But the websites you send http requests to don’t have to respond.

You can't. On most modern systems there is software that runs with privileges above your OS kernel that you can't remove or modify because it is signed with the manufacturer's key. The key is part of a "trusted" boot chain. The root of trust is usually burned into the silicon in the fuses or the initial bootloader (boot ROM). TEE on Android, for example. Intel ME on PCs, and probably TPMs also have a firmware of thei…

But you can still get computers that have none of that stuff, or where it can be disabled.

Re: Google’s nightmare “Web Integrity API” wants a DRM gatekeeper for the web

#417

Earlier quoted context omitted.

Even so, on most of the platforms you list you can disable the security checks and attestation mechanisms with a custom OS, which mitigates the risk of letting a site know that your computer is running any specific version of an OS with the proper anti-tamper checks. If you find a device that doesn’t, you can just not buy that device. At a certain point it’s not constructive to say “you can’t build that” when there i…

The problem is not someone knowing something. The problem is that since 99% of people use their devices in stock configuration, "no attestation available" would be interpreted as "attestation not passed". We're already seeing that with banking apps on Android. It doesn't matter whether you've rooted your stock ROM or running something without Google services, the app will refuse to work either way.

The bank thing doesn't bother me, personally. I can circumvent such restrictions entirely by using a bank that has a physical branch near me, and doing my business in person.

Re: Google’s nightmare “Web Integrity API” wants a DRM gatekeeper for the web

#418

It's great to see this getting more attention. User-agent discrimination (i.e. "go away if you're not using the latest version of Chrome") needs to become illegal. As long as I'm not overloading your service or similar, what hardware or software I use must not be restricted. The same goes for other deliberate obstacles to accessibility and interoperability --- creating a "standard" that's so complex and churned frequ…

> User-agent discrimination

At least you can spoof the user-agent string.

Re: Google’s nightmare “Web Integrity API” wants a DRM gatekeeper for the web

#419

Earlier quoted context omitted.

> when Apple tried to push a U2 album to them? They lost their collective shit. Yeah, Apple was toast after they did that. Their share price in 2014 when they did that was $24, and immediately afterwards it rose to $33 over the next 12 months. And since then, it's just been one long slow decline to almost $200 a share, as their global mobile market share has gone from the 24% it enjoyed in 2014 to the measly 29% it e…

You’re forgetting a 4:1 stock split in August 2020, so it’s even worse ;-) I think this illustrates that people only worry about this kind of thing if it gets shoved into their face. The privacy thing is OK as long as it’s only used for the good. For example, I think nobody would object against a world where every killer would be caught within an hour to get a fair trial. However, such a world also would be one where…

By this argument we should defund the police because they could be used for oppression. Forgetting the reality that they are also stopping thousands of crimes every single day.

Privacy absolution is never what most people signed up for.

Re: Google’s nightmare “Web Integrity API” wants a DRM gatekeeper for the web

#420

Earlier quoted context omitted.

The problem is not someone knowing something. The problem is that since 99% of people use their devices in stock configuration, "no attestation available" would be interpreted as "attestation not passed". We're already seeing that with banking apps on Android. It doesn't matter whether you've rooted your stock ROM or running something without Google services, the app will refuse to work either way.

The bank thing doesn't bother me, personally. I can circumvent such restrictions entirely by using a bank that has a physical branch near me, and doing my business in person.

Or by using the website... oh wait.

From what I gather it depends a lot on the country, but in some countries, including Russia where I'm from, money transfers are done through your bank's app. You probably won't go to a branch to send someone $15 for pizzas they ordered at a party or something. Your only option would be to carry cash for such occasions.

Post reply on HN