Live data from Hacker News

Web Environment Integrity API Proposal

github.com

421–430 of 460 posts

Re: Web Environment Integrity API Proposal

#421
post #30

Earlier quoted context omitted.

Yeah I mean the first of their examples is literally: > Users like visiting websites that are expensive to create and maintain, but they often want or need to do it without paying directly. These websites fund themselves with ads, but the advertisers can only afford to pay for humans to see the ads, rather than robots. This creates a need for human users to prove to websites that they're human, sometimes through task…

> This creates a need for human users to prove to websites that they're human, sometimes through tasks like challenges or logins. Is... is the Verification Can actually going to happen? https://i.kym-cdn.com/photos/images/original/000/983/286/ea5...

Just need to change 2019 to 2024 apparently.

Re: Web Environment Integrity API Proposal

#422
post #310

Earlier quoted context omitted.

Something to consider when you save your passwords in Google, you can "forget" and reset your Google account password and all your passwords are still there. Compare that to a proper password manager where if you forget the master password (assuming sufficient complexity) nobody is getting those passwords back ever. So Google has full access to your passwords whenever it feels like it. As the other commenter said, th…

That's a feature, not a bug. I don't want to lose all of my passwords if I have to reset my Google password.

You will lose them all when Google decides to lock your account.

Re: Web Environment Integrity API Proposal

#424

Earlier quoted context omitted.

what are Google going to do to China? throw ads at them?

Yes information on the worlds largest search engine , video repository, and browser definitely have zero value in wartime

Mark Roper's videos on firework construction might have had military value 1000 years ago

but I'm afraid the Chinese already know how to make them

Re: Web Environment Integrity API Proposal

#425
post #314
post #271

Earlier quoted context omitted.

The intent may genuinely be to help decrease bot activities versus human activities. Even the ad example is about not charging advertisers for bot views, which is a huge problem right now. The problem is that a tool can often be used for evil as easily as for good, and the more the standard was used to block ad blockers over simply filtering out User Agent spoofing bots, the more this tool ends up evil. And even if t…

This is meant to be a Play Integrity API proxy for the web. Now, I'm not opposed to having a locked down device when performing actions like using a bank app. However, Google is abusing this, because they force their adware and spyware into that device, so I can't have a secure, locked down Android device without that.

Ironically my bank app allows me to bypass the jailbreak detection screen at my own risk, but Mario Kart Tour and a parking app won’t and expect me to factory reset my device to use them (and Mario Kart doesn’t even tell you and just crashes)

Re: Web Environment Integrity API Proposal

#426
post #163

Earlier quoted context omitted.

This is already happening. It’s just mildly harder now. Try opening Teams in Firefox or Safari.

I'm not sure what you mean. I used Teams on Firefox, from my Linux laptop just this week.

Last time I tried some icons were showing up huge (so they would take up most of the page)

Re: Web Environment Integrity API Proposal

#427
post #337

Earlier quoted context omitted.

You don't send any data to the attester. It runs locally on your device, or rather is part of its core functionality. Building a chain of trust from the TPM hardware module, validating secure boot is enabled, validating the kernel and drivers have not been tampered with, eventually validating the browser has not been tampered with. You can't run your own attester - these are implemented by the companies who provide t…

Could this be reverse engineered so that third-party browsers sent the same hash as Chrome?

Not without exploits. This is a cryptographically signed chain of trust from hardware to booloader to kernel to the OS to Chrome. If any of these are tampered with the signature will not validate and they won't load. If you try to run an unsigned version the layer above you will refuse to sign the attestation. The only solution is finding exploits in the chain. If at any point you get unsigned code running or manage to get a signature outside of the signed environment then you can "spoof" the attestation. But while it is a big stack it is explicitly designed to prevent this exact issue, so it won't be easy and it will be quickly patched.

This is the same setup as SafetyNet on Android. SafetyNet can be worked around right now for "Basic Integrity" but this works by making your device claim to be an older device. Newer devices support hardware backed attestation for which there is no general work around. You can be sure that this proposal will be using hardware-backed attestation from the start.

Re: Web Environment Integrity API Proposal

#428
post #422

Earlier quoted context omitted.

That's a feature, not a bug. I don't want to lose all of my passwords if I have to reset my Google password.

You will lose them all when Google decides to lock your account.

I have them backed up to a second account.

Re: Web Environment Integrity API Proposal

#429
post #289

Earlier quoted context omitted.

> We could at least get everyone here to use Firefox. That would accomplish nothing. > But the important thing is checking in automatically as a Firefox user in the logs of every other site online. No, that's not important. HN users are a tiny minority compared to the billions of people that use the web daily. I'm sorry, there's no easy way to say this: Firefox is never coming back. The web of old is never coming bac…

> That would accomplish nothing. Firefox came into the mainstream because of power-user recommendations and the browser ballots. It should be illegal for a significan platform (say 10mln users) to make its own browser, or any really, the unquestioned default. Users should be prompted on first use, giving a randomly ordered selection of any capable browser. If users can just click through it the choice should be rando…

You're describing the old Firefox before they became Google's controlled opposition. Since 2011 all they have done is continuously stripped out every useful power user feature in a bid to turn into a shitty copy of Chrome; the last straw was gutting their powerful XUL/XPCOM extension system in favor of Chrome's far limited web extensions because muh security (and since then there's been more, not less cross browser malware). Today you can't even write your own extension for use on the main build thanks to forced extension signing (which ended up disabling everyone's extensions a few years ago due to an invalid certificate). And that's before all their unethical tracking, in browser advertising and privacy violation over the years, that requires various 'hardening' about:config changes out of the box, or the erosion of configurable features with almost every release. Mozilla are woke hypocrites today, financially dependent on Google while claiming to be privacy champions and squandering their money on multiple other projects instead of focusing on Firefox. The only browser that continues to be the old Firefox in spirit - the one that upended Microsoft's IE monopoly - is its hard fork, Pale Moon (which gets derided as oLd aNd iNSeCuRe by Mozilla fanboys). Doesn't need any 'hardening' because it doesn't snoop on you to begin with, and the latest versions have massively improved web compatibility while retaining support for the original powerful XUL extension system.

Re: Web Environment Integrity API Proposal

#430

Earlier quoted context omitted.

https://waterfox.net/ to the rescue.

Surely you don't mean Waterfox that states in their FAQ[0]: "Who owns Waterfox?" "System1 now own Waterfox, but Alex Kontos is still leading the direction of Waterfox and will be for the foreseeable future." And who's owner, System1, states at the top of their page[1]: "System1 operates the most dynamic Responsive Acquisition Marketing Platform Connecting high intent customers with advertisers at scale" [0]: https://…

Get with the times, Waterfox is independent of System 1 now. https://www.waterfox.net/blog/2023/07/03/a-new-chapter-for-w...
Post reply on HN