Live data from Hacker News

Google’s nightmare “Web Integrity API” wants a DRM gatekeeper for the web

arstechnica.com

441–450 of 484 posts

Re: Google’s nightmare “Web Integrity API” wants a DRM gatekeeper for the web

#441

Earlier quoted context omitted.

Are you referring to Google Maps automobiles connecting to open WiFi networks? Because to be fair, those networks were wide open, and they were being advertised. I don't see how advertising an open WiFi network is much different from advertising an open house. In both cases you should expect visitors.

That Wi-Fi router shouldn’t have dressed like that if it didn’t want to get Googled.

[deleted]

Re: Google’s nightmare “Web Integrity API” wants a DRM gatekeeper for the web

#442

Earlier quoted context omitted.

I disagree. An open WiFi network that is not being advertised would be similar to leaving a door unlocked or the shades open. When that network is actively advertised it ceases to be an open blind, and moves into open house territory.

The splitting of hairs between “open” and “advertised” is ridiculous. It’s the users who had their passwords stolen, not the hotspot. A better analogy is: I leave my door open with a welcome sign out the front. Two people enter. One of them picks the pocket of the other. And then the thief blames the guy who told him about the open door in the first place.

To be clear, my stance on the matter is that it is 100% okay for anyone to connect to any open WiFi network.

I don't find it particularly troublesome that maps of open WiFi networks exist.

I do not, however, think that it's okay to behave maliciously, or inappropriately on open WiFi networks.

My earlier response to your comment about hoovering plain text passwords didn't properly acknowledge the bad behavior that took place. I concede that you are correct, it was rude and insidious behavior.

Re: Google’s nightmare “Web Integrity API” wants a DRM gatekeeper for the web

#443

Earlier quoted context omitted.

Are you referring to Google Maps automobiles connecting to open WiFi networks? Because to be fair, those networks were wide open, and they were being advertised. I don't see how advertising an open WiFi network is much different from advertising an open house. In both cases you should expect visitors.

That Wi-Fi router shouldn’t have dressed like that if it didn’t want to get Googled.

[deleted]

Re: Google’s nightmare “Web Integrity API” wants a DRM gatekeeper for the web

#444

Earlier quoted context omitted.

Are you referring to Google Maps automobiles connecting to open WiFi networks? Because to be fair, those networks were wide open, and they were being advertised. I don't see how advertising an open WiFi network is much different from advertising an open house. In both cases you should expect visitors.

That Wi-Fi router shouldn’t have dressed like that if it didn’t want to get Googled.

Pause button: it's not super cool to make light of atrocities by not-so-subtly equating them with connecting to open WiFi networks.

Re: Google’s nightmare “Web Integrity API” wants a DRM gatekeeper for the web

#445
post #301

Earlier quoted context omitted.

I don't understand – how exactly DRM knows that I have a video-capture card recording my screen right now? The browser has no idea. Or what prevents me from copying NYT article and re-hosting it? What DRM has to do with it?

Google's DRM today already enforces HDCP. You only see an encrypted mess in all debug tools of the browser in that case.

i dont need debug tools in the browser - if the bytes of encoded content are getting transmitted to the socket on my machine, there is no realistic way to prevent me from taking and replicating them, i don't see how some software inside the browser can have any effect on this, because the browser has zero idea where these bytes can go after they hit the socket. A good analogy would be filming your screen manually - computer has no idea of this filming and in no way can prevent it, because it cannot act on a real world around it, the same applies for browser, i can take a document, video or sound from any page without involing the browser

Re: Google’s nightmare “Web Integrity API” wants a DRM gatekeeper for the web

#446
post #445

Earlier quoted context omitted.

Google's DRM today already enforces HDCP. You only see an encrypted mess in all debug tools of the browser in that case.

i dont need debug tools in the browser - if the bytes of encoded content are getting transmitted to the socket on my machine, there is no realistic way to prevent me from taking and replicating them, i don't see how some software inside the browser can have any effect on this, because the browser has zero idea where these bytes can go after they hit the socket. A good analogy would be filming your screen manually - c…

> because the browser has zero idea where these bytes can go after they hit the socket

The attestation uses a secure enclave in your processor with a secret key you can't access to verify that secure boot is on, you booted a signed OS, the OS is in locked-down mode, etc.

Re: Google’s nightmare “Web Integrity API” wants a DRM gatekeeper for the web

#447

Earlier quoted context omitted.

This defies my Occam's Razor view. You seem to be assuming Google is an extremely well connected organism with vast coherency: each limb knows what the others are doing, they are working together in close fashion, & doing things for ulterior motives. This is such a horrific & bastardly case - of creating unparalleld rank awfulness hither-to-fore unimaginable - that I am tempted to agree. And I do think there probably…

> You seem to be assuming Google is an extremely well connected organism with vast coherency: each limb knows what the others are doing, they are working together in close fashion, & doing things for ulterior motives. Nah dog, you're overcomplicating it. All it requires is a person or two in a management chain to recognize the hint of long term business potential in a technical change. It doesn't have to be a sure th…

Exactly! You get it, bro! Nice point about Occam's razor. People just don't have systems thinking when it comes to systems of people.

Re: Google’s nightmare “Web Integrity API” wants a DRM gatekeeper for the web

#448

Earlier quoted context omitted.

The splitting of hairs between “open” and “advertised” is ridiculous. It’s the users who had their passwords stolen, not the hotspot. A better analogy is: I leave my door open with a welcome sign out the front. Two people enter. One of them picks the pocket of the other. And then the thief blames the guy who told him about the open door in the first place.

To be clear, my stance on the matter is that it is 100% okay for anyone to connect to any open WiFi network. I don't find it particularly troublesome that maps of open WiFi networks exist. I do not, however, think that it's okay to behave maliciously, or inappropriately on open WiFi networks. My earlier response to your comment about hoovering plain text passwords didn't properly acknowledge the bad behavior that too…

No worries, thanks for being a good sport. I think we agree all around.

It was never the connecting that bothered me, it was the storage of the data encountered.

Re: Google’s nightmare “Web Integrity API” wants a DRM gatekeeper for the web

#449

Earlier quoted context omitted.

thats because mozilla simply stopped having any interest in browsing whatsoever. They now have an interest in limited edition color drops and with their bespoke charactaristic allowing users to select color that best resonates with them. You and I, as mere mortals, may not know what this means, but rest assured, mozilla does.

to whomever downvoted this, you clearly need some more independent voices in your life, but fear not, Mozilla got you covered: https://blog.mozilla.org/en/products/firefox/firefox-news/in...

Worth linking this epic: https://connect.mozilla.org/t5/discussions/mozilla-now-only-...

Re: Google’s nightmare “Web Integrity API” wants a DRM gatekeeper for the web

#450
post #150

Earlier quoted context omitted.

The current browser stack is a lost cause. There's just no way for anyone who cares to compete with Google. But we still have TCP and HTTP. We will rebuild this place.

HTTP is terrible though. It's a big part of the problem with the web.

I'm curious. Could you please elaborate further
Post reply on HN