Live data from Hacker News

Web Environment Integrity API Proposal

github.com

451–460 of 460 posts

Re: Web Environment Integrity API Proposal

#451

Earlier quoted context omitted.

You're describing the old Firefox before they became Google's controlled opposition. Since 2011 all they have done is continuously stripped out every useful power user feature in a bid to turn into a shitty copy of Chrome; the last straw was gutting their powerful XUL/XPCOM extension system in favor of Chrome's far limited web extensions because muh security (and since then there's been more, not less cross browser m…

My point wasn't to gush praise on Firefox here, rather to point out that we need browser ballots again -- and permanently. Otherwise Palemoon is as doomed to obscurity as Firefox, if not moreso.

It may well be too late, given Google has absolute control over web standards and their policy of introducing draft features in Chrome and then making them part of the standard. Unless an anti-trust case is brought against them which explicitly mentions their browser engine and standards monopoly, and correctly points out that every other browser today is just a skin around Chrome while Firefox is controlled opposition. Every case against them seems to obsess on the search engine monopoly.

Re: Web Environment Integrity API Proposal

#452
post #266

Earlier quoted context omitted.

> There's really no excuse for a technically minded person to still be using Chrome for their day to day browsing. Sadly, Chrome is substantially more secure than Firefox.

It is extremely disingenuous to claim the only browser to still refuse to block third party cookies by default, because it helps their ad partners, is "more secure". The only way in which Chrome is more secure at anything appears to be securely forcing you to view ads via this API. And a shocking amount of malware fails to work when you use a running environment that 95% of society are not using. You are far safer on…

Why do most FAANG-type businesses require use of Chrome then?

Re: Web Environment Integrity API Proposal

#453

Earlier quoted context omitted.

It is extremely disingenuous to claim the only browser to still refuse to block third party cookies by default, because it helps their ad partners, is "more secure". The only way in which Chrome is more secure at anything appears to be securely forcing you to view ads via this API. And a shocking amount of malware fails to work when you use a running environment that 95% of society are not using. You are far safer on…

Why do most FAANG-type businesses require use of Chrome then?

So as someone who deals with enterprise software: Network effects.

Where I work, we treat Chrome as the malware it is: It's banned both by technical measures and security policy. We deploy Firefox, and begrudgingly deal with Edge when people insist on a Chromium-based browser. (At least Microsoft added some modicum of privacy settings here.)

Here's what I've learned over the past several years: Web developers are lazy. We're commonly told such and such app or service "only works on Chrome" or they'll "only support on Chrome". When we call for support, half the time we'll get told it's because we're not on Chrome, and I have to actually prove to them on an isolated machine that the issue occurs on Chrome so they'll shut the heck up and do their job. "Oh, I found an issue on our server" after I spent two hours trying to convince them their app works fine on Firefox.

In most cases, things "not working on Firefox" entails exempting a site from the popup blocker. In 2023, troubleshooting alternative browsers is usually... roughly that easy. But blaming your web browser is easy and lets them shift blame, so that's what they do.

But enterprise software companies have completely turned Chrome into the modern Internet Explorer: The only browser they'll even deal with. And since a lot of people buy Google's marketing that they know security and aren't completely clueless how security works (they are), people have by and large given in and installed Chrome.

Re: Web Environment Integrity API Proposal

#454
post #5

This is pretty much the inevitable end-game of the web, in no small part funded by ad-based business models (as the analog gap pretty much destroys most attempts to use this stuff to do copy protection) and enabled by developers who have insisted we shove as much difficult-to-implement functionality (by which I am talking about CSS complex stuff, not powerful-but-easy-to-code APIs for OS-level access) into the browse…

I do not see this as practical at all.

To begin with, pretty much every government employee in the world has some proprietary software developed within the country for security reasons. Old, even obsolete machines. Out of date software, unlicensed/unregistered software, etc, etc. Much of this is also true of banks.

This means if this is put in place as in the spec, it will affect banks and governments negatively. And as powerful as Google is, I don't think it will win over governments + banks.

But again, all the above could be nonsense, and Google will gatekeep the web. It found itself as the loser in the AI race, and it knows pursuing AI during the ongoing arguments on privacy and who owns the data AI is being trained on - the next best thing is to own the playground where the AI trains. That may not be an entirely bad thing either; sad, perhaps, but as this goes on, and browsing becomes a pain, maybe this will result in people just spending less time online? That's a good outcome in my books.

Re: Web Environment Integrity API Proposal

#455

Earlier quoted context omitted.

If only the wikimedia foundation would fork firefox, then the open web might have a chance. Wikimedia is honestly the only organization with the right ideology, the right business model, and enough money to do something like this sustainably.

I thought Wikimedia was quite shady itself when it comes to funding and money management?

Wikimedia is much much less shady than Mozilla in a bunch of ways. Some people might take issue with the way they spend their money, or the tactics they use to raise money, but I don't think I would consider them shady.

Full disclosure: I was employed as a software release engineer at the Wikimedia Foundation from 2015 through 2022.

Re: Web Environment Integrity API Proposal

#456
post #179

Earlier quoted context omitted.

I thought Wikimedia was quite shady itself when it comes to funding and money management?

Mozilla and Wikimedia both have a reputation for wasting money by trying to branch out beyond their main product. Wikimedia is totally overfunded so wasting money doesn't threaten their survival but they've also been criticized for begging for donations that they don't need. Personally I don't see a reason to combine them.

Coincidental observation:

Your username is the same as the initialism used internally to refer to the Wikimedia Foundation.. The WikiMediaFoundation: WMF

Re: Web Environment Integrity API Proposal

#457

Earlier quoted context omitted.

Yes, but that is fairly recent! Did anyone even notice? For years, you could siphon every song you listened to and save it locally. But did it affect anything? I did it for a little while, but then found it wasn't worth the trouble.

It affected Spotify enough to engineer a solution to stop it. And five years isn't "fairly recent". One would also note Spotify is a failing business, and it was failing even harder then.

The majority of Spotify's lifetime there was NO DRM, and ripping it was easy.

The majority of users had no idea and it didn't affect them at all. Nor is there any evidence that it had any impact on Spotify's business.

Re: Web Environment Integrity API Proposal

#458

Earlier quoted context omitted.

> who is finally putting their foot down and deciding that we are all going to be forced to either used fully-locked down devices The person who wrote the proposal[0] is from Google. All the authors of the proposal are from Google[1]. I've been thinking carefully about this comment, but I really don't know what to say. It's absolutely heartbreaking watching something I really care about die by a thousand cuts; how do…

> how do we protest this? You do not and you cannot. It was written in stone once Chrome dominated the browser market. What Chrome (Google) wants, Chrome (Google) gets. Despite all the good engineering Google wants to sell ads, that's all there is to it. And the result is this proposal. > The saving grace here might be that Firefox won't implement the proposal. It's irrelevant and we are an irrelevant minority. Unles…

Doesn't Apple have some leverage here? They may not control the overall browser market but they mostly control the smartphone market (or at least the profitable segment of that market) and lots of those users prefer to use Safari.

I'm aware Apple implemented similar tech a while ago, but I have infinitely less confidence that Google would use it responsibly.

Re: Web Environment Integrity API Proposal

#460

Proposal author here I’m hoping to get back to everyone as soon as possible. I hope you can all appreciate that I’m a human being and this has been a lot! In the mean time, I wanted to repost my last comment on the GitHub issue thread [1]: Hey all, we plan to respond to your feedback but I want to be thorough which will take time and it’s the end of a Friday for me. We wanted to give a quick TL;DR: - This is an early…

In much the same vein as something clearly profoundly hurt you and you want to ruin the web out of spite, I root for global warming because it will destroy all the infrastructure on which you wish to take a giant dump.
Post reply on HN