Live data from Hacker News

Google’s nightmare “Web Integrity API” wants a DRM gatekeeper for the web

arstechnica.com

431–440 of 484 posts

Re: Google’s nightmare “Web Integrity API” wants a DRM gatekeeper for the web

#431
The proposed function is impossible to implement in general. More precisely, it's impossible to implement without specific hardware and operating system (you have one of a handful of choices) to the de facto standard that would develop over time if web servers came to depend on the behavior of the function. It would make the web decidedly not open.

Re: Google’s nightmare “Web Integrity API” wants a DRM gatekeeper for the web

#432
So I'm already at the point where if I go to a website and that stupid Cloudflare "securing your connection" dialog pops up, I just click away. Fuck Cloudflare and their walled-garden horse.

If Google does this too then I guess the "mainstream" web will become invisible to me. No great loss since it's mostly thoroughly enshittified anyway.

I'm happy to move to the new un-googled "darkweb" where freedom, anonymity, and non-SEO content still prevail.

Re: Google’s nightmare “Web Integrity API” wants a DRM gatekeeper for the web

#433

Earlier quoted context omitted.

But you can still get computers that have none of that stuff, or where it can be disabled.

Can you give me an example? A computer without TPM, a "management engine", an Ethernet card with real Firmware in a real ROM, no platform controller, nothing. ...and a completely open BIOS w/o any binary blobs, and UEFI layer. Almost a 486DX, almost.

I don't have the models memorized and I'm not at home to check, but I recently bought four towers that don't have TPM or a management engine and allow you to disable UEFI. They're not new, true, but they're certainly not 486 level.

> an Ethernet card with real Firmware in a real ROM, no platform controller, nothing. ...and a completely open BIOS w/o any binary blobs

None of which I was talking about. But I am pretty sure that with any motherboard, you can disable onboard Ethernet and install whatever adapter you want instead.

Re: Google’s nightmare “Web Integrity API” wants a DRM gatekeeper for the web

#434
post #156

Earlier quoted context omitted.

If we're talking cyberpunk dystopias, we'd have to resort to hand-soldered audio couplers that use our locked-down phones as modems. Once the next Android/iOS update detects and blocks unauthorized binary carriers, we'll have to steganographically hide our traffic in fake voice calls. Crappy baud rate, but good enough for encrypted text. Augment with sneakernet and local hard-wired networks running under lawns and do…

You already can't run modems over the phone network anymore. Modern noise reduction algorithms helpfully remove as much modem data as they can.

Now I kind of want to build one just for the challenge. Analyze what frequencies can get through, and reverse engineer the phone company's codec so I can send a pirate signal, like a phreaker of old.

Fun fact: You can no longer do such a project in software on stock Android. They locked down the voice audio API.

Re: Google’s nightmare “Web Integrity API” wants a DRM gatekeeper for the web

#435
post #412

Earlier quoted context omitted.

This is a massive leap in assumptions and arguments. For one, blocking users in a geographic region would not be legally considered racial discrimination unless you can prove intent. This is the bullshit loop hole that makes it easy to get away with discrimination, but that's the way it works. If Google really wants to play this game and create a technical gate preventing usage of sites by anyone that uses a browser…

The grandparent comment asked whether a website owner would ever be unjustified in deciding who can use their website. From a legal viewpoint, the answer is dependent on the complexity of state laws[1]. What a website owner can do with a website in one country obviously differs from what they could do in another country. Most countries have very weak anti-discrimination laws, and if they do exist, they typically only…

Such broad declarations of rights are completely ridiculous.

As a consultant, this would mean I can't turn down a client. Ever. It doesn't matter if I have higher paying offers, moral objections to what they want built, or silly just don't want to work with them.

This type of blanket declaration of freedoms can only extend so far as another person's rights aren't infringed upon. I the consultant example, my right to decide how I spend my time and value my work should be protected. If I can't discriminate for any reason because it could be deemed "[an]other status", my life can be wrecked because anyone asking for my services are owed good faith effort and I can't legally decline.

Re: Google’s nightmare “Web Integrity API” wants a DRM gatekeeper for the web

#436
post #91

> Google's plan is that, during a webpage transaction, the web server could require you to pass an "environment attestation" test before you get any data. There is no value in this "attestation" for me as a user. I want to be able to do whatever I want with the browser (for example, remove ads or block access to canvas and webgl) and I want sites to be unable to know this. And probably this attestation will provide a…

Ehhh, it depends. In theory one could imagine a scenario like a bank website refusing to be accessed unless the entire OS & browser stack pass attestation - as that would rule out things like keyloggers, malicious browser extensions, and session hijacking. In practice it'll just be used to lock down content and force unskippable ads on users, of course.

I hope banks like getting phone calls, then. MacOS and Windows normies are going to get caught up in this, and so are all of the laypeople who got pissed at those two and moved to OS's like Linux Mint.

Re: Google’s nightmare “Web Integrity API” wants a DRM gatekeeper for the web

#437

Earlier quoted context omitted.

This has been happening already. The market is trying really hard to price out web scraping through scraper detection technologies and it's kinda working - scraping is becoming non-existent in user-space apps. It's also extremely discriminatory. Try running a single scrape with a developing country's IP and Linux, you'll be blocked at TLS step lol

> The market is trying really hard to price out web scraping... scraping is becoming non-existent in user-space apps Uhh... Those two matters are pretty much unrelated to each other. Scraping is becoming non-existing because the era of static web pages has ended. No need to "scrap" when you have a nice, performant JSON REST API provided for you.

> No need to "scrap" when you have a nice, performant JSON REST API provided for you.

There are no performant json rest APIs provided these days though. The days of public APIs are long gone.

Re: Google’s nightmare “Web Integrity API” wants a DRM gatekeeper for the web

#438

Earlier quoted context omitted.

I think that depends a bit on context. If I am at home, and my neighbors are advertising an open Wi-Fi network, I’ve never taken that as an invitation to connect and use it. However, if I’m at coffee shop Foo and I see “Foo Guest” advertised, then sure…

Does that also give you the right to sniff their network and steal their email passwords?

No it doesn't. Imo, that would be both poor etiquette, and a violation of trust.

While I do remember hearing about Google Maps vehicles connecting to open WiFi networks in the news, I don't recall hearing about private credentials being published. Was that the case? I thought it was just a map of open WiFi networks that was published with basic details such as SSID?

Edit: I found the article (2010, holy cow does time fly). It looks like they did collect payload data for non-encrypted traffic. Even though the data wasn't published in any way, I must agree that they went too far. I would have no issue if they were to simply verify that they could connect and record basic info such as SSID, but collecting payload data from network requests was inappropriate.

Re: Google’s nightmare “Web Integrity API” wants a DRM gatekeeper for the web

#439
post #327

I think the wisest course of action is to boycott all chromium-based browsers. Yes it might be painful, yes you might not have your favorite extension or add-on. Suck it up. I've been exclusively using Safari for years, even after extensions were killed.

Safari has had functional, good extensions for years.

Extensions got killed during Safari 12 & 13.

Re: Google’s nightmare “Web Integrity API” wants a DRM gatekeeper for the web

#440
Google's proposed 'Web Integrity API' raises some intriguing questions about the future of web security and user privacy. While the intent to secure the web environment and ensure user authenticity is commendable, the approach seems to echo DRM mechanisms, which have often been contentious. The proposal also brings to light the ongoing debate about device control - should users be penalized for wanting full control over their devices? This 'gatekeeping' approach could potentially stifle the open nature of the web and limit user freedom. As we move forward, it's crucial to strike a balance between security and user autonomy.
Post reply on HN