Live data from Hacker News

Google’s nightmare “Web Integrity API” wants a DRM gatekeeper for the web

arstechnica.com

451–460 of 484 posts

Re: Google’s nightmare “Web Integrity API” wants a DRM gatekeeper for the web

#451
post #114

The Chrome team have used "the Open Web" as a euphemism for what is to all intents and purposes Google's great ad supported walled garden. That so few people see this for what it is is amazing, and then they get all surprised when Google act to preserve it and close the capability gap with native platforms.

When Microsoft did this with IE, they did it with proprietary and undocumented APIs. The fact that this is an open spec, discussed in an open forum, using well established and standard technologies is what ensures it can never be positioned against users in any meaningful way. To me it looks like SGX for the web. Maybe it will introduce some neat and weird capabilities, but at the end of the day, it will be trivial t…

This is as much of an "open spec" as EME - if you don't have the keys Google uses you can't implement it in a meaningful way.

Re: Google’s nightmare “Web Integrity API” wants a DRM gatekeeper for the web

#452

Earlier quoted context omitted.

One day Google may well flag your sure as lower security, refuse to let you show ads, or disappear you from search results.

I never had ads on my site and if it disappears from search results, no problem. I'll give the URL to the very few people that might be interested to browse it. I probably know all of them, plus a number of bots.

They may also flag your site as "unsafe" and will refuse to display it with scary warnings and hidden overrides that the average user will not be able to access it. This already exists btw. Also in Firefox, using Google's blacklist.

Re: Google’s nightmare “Web Integrity API” wants a DRM gatekeeper for the web

#453

Earlier quoted context omitted.

You already get flagged as hazardous and uncool for not using https, even on a perfectly-static site. Some of us called that out as a slippery slope leading to ubiquitous gatekeeping, but we were shouted down in the name of (as usual) "security."

That is because without https, there is no guarantee that the site requested is bring delivered as the site intends. For example, an ISP could insert data or scripts into the page.

Then make laws to force your ISPs to be neutral carriers and prosecute any pulling shit. Most of the world doesn't have this problem yet we are still forced to waste countless of cycles and man-hours on TLS for public read-only content.

Re: Google’s nightmare “Web Integrity API” wants a DRM gatekeeper for the web

#454
post #114

Earlier quoted context omitted.

When Microsoft did this with IE, they did it with proprietary and undocumented APIs. The fact that this is an open spec, discussed in an open forum, using well established and standard technologies is what ensures it can never be positioned against users in any meaningful way. To me it looks like SGX for the web. Maybe it will introduce some neat and weird capabilities, but at the end of the day, it will be trivial t…

Can you explain how you'd bypass it? Let's say example.com decides to require attestation from the {MS, Apple, Google} providers, and that they attest to only Chrome without extensions. You can't forge the attestation because cryptography. You can't fail to provide it (because they'll just refuse to send the bits). You can't use a "malicious" attestor because example.com won't trust it. What's the trivial bypass I'm…

TPMs can be emulated. Also basically every hardware platform can be placed into a hardware debug mode that allows live debugging of the underlying operating system. Keys can also be extracted from hardware. If even one supported platform leaks a key (and in this doomer fantasy world all platforms must be supported right?) then the attestations can be bypassed. It only needs to be bypassed once to be bypassed everywhere, basically forever.

Re: Google’s nightmare “Web Integrity API” wants a DRM gatekeeper for the web

#455
post #114

Earlier quoted context omitted.

When Microsoft did this with IE, they did it with proprietary and undocumented APIs. The fact that this is an open spec, discussed in an open forum, using well established and standard technologies is what ensures it can never be positioned against users in any meaningful way. To me it looks like SGX for the web. Maybe it will introduce some neat and weird capabilities, but at the end of the day, it will be trivial t…

This is as much of an "open spec" as EME - if you don't have the keys Google uses you can't implement it in a meaningful way.

EME is a great example. It's been around for over a decade now. In what way has it negatively impacted users? Is piracy any harder than it was? EME has been built into Chrome since long before it was an official W3C spec, which it has been for six years now. People lost their minds when EME was getting standardized, yet here we are. This same nonsense is playing out with WEI, yet people haven't seemed to learn a thing.

Re: Google’s nightmare “Web Integrity API” wants a DRM gatekeeper for the web

#456
post #59

Remember they already added DRM to browsers once. There was a big outcry at the time, and they still went ahead and implemented it. Now even Firefox supports Widevine. If they believe that it's in their best interest, I'm not really sure what we can do against this...

Who benefits from browsers not supporting EME? The choices were EME, Flash, or no premium VOD on the web.

And? Making people who can't help themselves from consuming DRM'd content jump trough hoops is much better than integrating this shit into the browser. Eventually media companies might have caved in and accepted DRM-free distribution like the music industry already has.

Re: Google’s nightmare “Web Integrity API” wants a DRM gatekeeper for the web

#457

Google's proposed 'Web Integrity API' raises some intriguing questions about the future of web security and user privacy. While the intent to secure the web environment and ensure user authenticity is commendable, the approach seems to echo DRM mechanisms, which have often been contentious. The proposal also brings to light the ongoing debate about device control - should users be penalized for wanting full control o…

Please test your machine learning algorithms elsewhere.

Re: Google’s nightmare “Web Integrity API” wants a DRM gatekeeper for the web

#458

Earlier quoted context omitted.

This line is what makes me roll my eyes whenever I hear someone say "Safari is the new IE". Safari missing a couple of features few websites use is far less of an issue than the dominant browser company can just invent new "standards" that make the web actively worse for everyone. (Sorry, I should say "everyone except for the scummy advertisers".)

Safari is just Apples Opera (before they went Blink and made themselves irrelevant). They aren't great, just another proprietary browser. Every time I've used it has been sub-par. It reminded me a lot of Opera in that it was very opinionated, even if it tried to offer some feature. Apple makes money off of apps, not websites, though, so it makes sense they don't invest much into their browser.

Subpar on what? That’s the important part. For my non-techie family, it seems to do everything they need WHILST saving a lot of battery life. If that’s the criteria, it’s a great browser.

I’d never use it due to lack of uBlock Origin and good dev tools, but it’s hard to argue with the speed and battery efficiency on macOS.

Re: Google’s nightmare “Web Integrity API” wants a DRM gatekeeper for the web

#459
Friendly reminder to don't just comment and complain, contact your antitrust authority today:

US:

- https://www.ftc.gov/enforcement/report-antitrust-violation

- antitrust@ftc.gov

EU:

- https://competition-policy.ec.europa.eu/antitrust/contact_en

- comp-greffe-antitrust@ec.europa.eu

UK:

- https://www.gov.uk/guidance/tell-the-cma-about-a-competition...

- general.enquiries@cma.gov.uk

India:

- https://www.cci.gov.in/antitrust/

- https://www.cci.gov.in/filing/atd

Canada:

- https://www.competitionbureau.gc.ca/eic/site/cb-bc.nsf/frm-e...

Re: Google’s nightmare “Web Integrity API” wants a DRM gatekeeper for the web

#460

Earlier quoted context omitted.

Nope firefox still runs gecko. It's a small difference, perhaps, but its "my" browser in a way chrome will never be. Blink sucks. Also, not a clue what you are on about - I don't have an issue with firefox. Chrome is basically for dealing with google stuff, and for the rest of the web I don't care about them.

Which Google stuff requires Chrome? I run even Google sites on Firefox and they seem to run fine.

Sometimes Drive stops working for me, trying to download something results in a redirection loop. Clearing the cache sometimes fixes it. I suspect the Firefox anti tracking settings but I haven't bothered to test it.
Post reply on HN