Live data from Hacker News

Google’s nightmare “Web Integrity API” wants a DRM gatekeeper for the web

arstechnica.com

421–430 of 484 posts

Re: Google’s nightmare “Web Integrity API” wants a DRM gatekeeper for the web

#421

Earlier quoted context omitted.

So your argument is that as long as the harms are invisible enough to the consumer that no action should be taken? May I introduce you to Tobacco?

No. They're just saying that if they're invisible, most people won't care. They're not saying anything about what should or shouldn't happen.

Why is it that no one comprehends the existence, let alone nature, of _implicit_ statements?

Re: Google’s nightmare “Web Integrity API” wants a DRM gatekeeper for the web

#422

Earlier quoted context omitted.

So your argument is that as long as the harms are invisible enough to the consumer that no action should be taken? May I introduce you to Tobacco?

No. They're just saying that if they're invisible, most people won't care. They're not saying anything about what should or shouldn't happen.

[deleted]

Re: Google’s nightmare “Web Integrity API” wants a DRM gatekeeper for the web

#423

Earlier quoted context omitted.

The bank thing doesn't bother me, personally. I can circumvent such restrictions entirely by using a bank that has a physical branch near me, and doing my business in person.

Or by using the website... oh wait. From what I gather it depends a lot on the country, but in some countries, including Russia where I'm from, money transfers are done through your bank's app. You probably won't go to a branch to send someone $15 for pizzas they ordered at a party or something. Your only option would be to carry cash for such occasions.

> Your only option would be to carry cash for such occasions.

I'm in the US, but this is exactly what I do. I don't think I've ever actually used a banking app to send a small payment to someone for things like this, nor has anyone tried to use an app to send money to me. Cash is king.

(I fully understand that not everyone can or wants to handle payments this way. I'm just saying what works for me. I have no banking apps on my phone at all.)

Re: Google’s nightmare “Web Integrity API” wants a DRM gatekeeper for the web

#424

Earlier quoted context omitted.

You can't. On most modern systems there is software that runs with privileges above your OS kernel that you can't remove or modify because it is signed with the manufacturer's key. The key is part of a "trusted" boot chain. The root of trust is usually burned into the silicon in the fuses or the initial bootloader (boot ROM). TEE on Android, for example. Intel ME on PCs, and probably TPMs also have a firmware of thei…

But you can still get computers that have none of that stuff, or where it can be disabled.

Can you give me an example?

A computer without TPM, a "management engine", an Ethernet card with real Firmware in a real ROM, no platform controller, nothing.

...and a completely open BIOS w/o any binary blobs, and UEFI layer.

Almost a 486DX, almost.

Re: Google’s nightmare “Web Integrity API” wants a DRM gatekeeper for the web

#425
post #96

Are you using Chrome now? Hate to say it, you are part of the problem. Switch to anything else. I'm not a super anti-Google person. I use Gmail and Google as my search engine. But Firefox is a good browser that I use as my daily driver, and Edge, Brave, Safari and the DDG browser are other options. Switch today and start taking away Google's leverage.

Edge and Brave are based on Chromium. While Brave would likely block this API for a while (until too many sites require it and it would hurt their market share) they don't block most changes that Google pushes into Chrome so are still largely contributing to Google's power over the Internet. So if you really want to disrupt Google's control over the web platform the only options are really Firefox and Safari.

Firefox and Safari have the same market-share pressure. Why/how would people use a browser that doesn't work on websites they use?

Re: Google’s nightmare “Web Integrity API” wants a DRM gatekeeper for the web

#426

Earlier quoted context omitted.

So if my front door is open, or my garage door is open, you feel you have the right to enter my home without permission?

If you are advertising that your door is unlocked, and the precedent is to enter unlocked doors - as it is to connect to open networks, then yes. Permission in such a scenario is implied. You make these analogies attempting to equate an advertised open WiFi network to an unlocked home, while ignoring the precedent around both of those things. It is expected that people connect to your advertised open WiFi network. It…

I've never felt that it's appropriate to connect to residential open wifi. If I see one near where I live, I assume it's a misconfiguration.

Re: Google’s nightmare “Web Integrity API” wants a DRM gatekeeper for the web

#427
post #371

Earlier quoted context omitted.

I use Firefox on desktop and mobile, I use DDG, stopped using Google Analytics but I sadly still use Gmail and Android. I degoogled the east things (e.g. GA and Chrome) but getting totally rid off Google is hard.

> getting totally rid off Google is hard Sometimes impossible in my case. Google Drive is always used in any collaborative project; so is Google Colab and Google Meet. And I still have the instinctual drive to reach for Google Translate/Maps, because it's so easy to access (physically and mentally). Google google google google google...

Google Meet is easy to replace. Look at jitsi or MiroTalk. Google Maps, not so much...

Re: Google’s nightmare “Web Integrity API” wants a DRM gatekeeper for the web

#428
post #412

Earlier quoted context omitted.

This is a massive leap in assumptions and arguments. For one, blocking users in a geographic region would not be legally considered racial discrimination unless you can prove intent. This is the bullshit loop hole that makes it easy to get away with discrimination, but that's the way it works. If Google really wants to play this game and create a technical gate preventing usage of sites by anyone that uses a browser…

The grandparent comment asked whether a website owner would ever be unjustified in deciding who can use their website. From a legal viewpoint, the answer is dependent on the complexity of state laws[1]. What a website owner can do with a website in one country obviously differs from what they could do in another country. Most countries have very weak anti-discrimination laws, and if they do exist, they typically only…

How far do you take this?

It is ok to ban people who spam? Who post hate speech?

Re: Google’s nightmare “Web Integrity API” wants a DRM gatekeeper for the web

#429
post #282

Earlier quoted context omitted.

> does this make me a bad person for discriminating Yes. And not only for discriminating. You make the web shittier than it already is, and more fragmented. > or should I have to tolerate the script kiddies, ddosing and exploit searches? This part is unrelated to the first part.

Defending the integrity of the internet isn't OP's job. He's not making the internet a shittier place, the governments of China and Turkey are. Blame them, not some random web host.

> Defending the integrity of the internet isn't OP's job.

It’s everyone’s job. It’s the least we can do to prevent entshitification of this beautiful and wild ecosystem.

Re: Google’s nightmare “Web Integrity API” wants a DRM gatekeeper for the web

#430

One thing from the blink-dev discussion caught my eye: > Anything we might decide would ultimately be influenced by the larger societal debate around privacy (regulations etc.) since perfect privacy means perfect immunity for criminals. Ensuring that your devices don't spy on you on behalf of a government or company does not imply "perfect immunity for criminals". Putting aside attestation for the moment, consider th…

"Those who would give up essential liberty to purchase a little temporary safety, deserve neither liberty nor safety."

The problematic dude's disdain for humanity aside, the quote serves as a good reminder that the "but the criminals!" argument is often used and rarely justified.

Post reply on HN