Live data from Hacker News

Google’s nightmare “Web Integrity API” wants a DRM gatekeeper for the web

arstechnica.com

461–470 of 484 posts

Re: Google’s nightmare “Web Integrity API” wants a DRM gatekeeper for the web

#461
post #319
post #32

> Exactly how the rest of the world feels about this is not necessarily relevant, though. Google owns the world's most popular web browser, the world's largest advertising network, the world's biggest search engine, the world's most popular operating system, and some of the world's most popular websites. So really, Google can do whatever it wants. This is the point that company breakups start to make a lot of sense.…

Doing stuff their customers hate is the default MO of most tech companies. There's very little recourse. For example, when Apple makes a user-hostile hardware change, every major Android vendor will copy it in a matter of months[0]. The only thing you can go to after that is niche Chinese phone makers that will cause you a bunch of other pain. I'm basically completely disconnected from Google at this point. My phone…

> Google Photos export keeps erroring

Did you try different export options? I recently had to do one export and it kept failing but exporting using another option worked. I don't remember which one but it was either email or drive.

Re: Google’s nightmare “Web Integrity API” wants a DRM gatekeeper for the web

#462
post #454

Earlier quoted context omitted.

Can you explain how you'd bypass it? Let's say example.com decides to require attestation from the {MS, Apple, Google} providers, and that they attest to only Chrome without extensions. You can't forge the attestation because cryptography. You can't fail to provide it (because they'll just refuse to send the bits). You can't use a "malicious" attestor because example.com won't trust it. What's the trivial bypass I'm…

TPMs can be emulated. Also basically every hardware platform can be placed into a hardware debug mode that allows live debugging of the underlying operating system. Keys can also be extracted from hardware. If even one supported platform leaks a key (and in this doomer fantasy world all platforms must be supported right?) then the attestations can be bypassed. It only needs to be bypassed once to be bypassed everywhe…

Key revocation is a thing and no, not all platforms must be supported (or are intended to be supported). Here's the relevant Google blog post:

https://android-developers.googleblog.com/2019/09/trust-but-...

Re: Google’s nightmare “Web Integrity API” wants a DRM gatekeeper for the web

#463

Earlier quoted context omitted.

> The market is trying really hard to price out web scraping... scraping is becoming non-existent in user-space apps Uhh... Those two matters are pretty much unrelated to each other. Scraping is becoming non-existing because the era of static web pages has ended. No need to "scrap" when you have a nice, performant JSON REST API provided for you.

> No need to "scrap" when you have a nice, performant JSON REST API provided for you. There are no performant json rest APIs provided these days though. The days of public APIs are long gone.

HTML "APIs" weren't meant for public either.

In practice, if there is a mobile app, there is an API. Whether it's creators object to your usage is mostly their own problem.

Re: Google’s nightmare “Web Integrity API” wants a DRM gatekeeper for the web

#464
post #319

Earlier quoted context omitted.

Doing stuff their customers hate is the default MO of most tech companies. There's very little recourse. For example, when Apple makes a user-hostile hardware change, every major Android vendor will copy it in a matter of months[0]. The only thing you can go to after that is niche Chinese phone makers that will cause you a bunch of other pain. I'm basically completely disconnected from Google at this point. My phone…

> Google Photos export keeps erroring Did you try different export options? I recently had to do one export and it kept failing but exporting using another option worked. I don't remember which one but it was either email or drive.

Slowly working through them, but you can only do one try every couple of days ;)

Re: Google’s nightmare “Web Integrity API” wants a DRM gatekeeper for the web

#465

Earlier quoted context omitted.

You’re forgetting a 4:1 stock split in August 2020, so it’s even worse ;-) I think this illustrates that people only worry about this kind of thing if it gets shoved into their face. The privacy thing is OK as long as it’s only used for the good. For example, I think nobody would object against a world where every killer would be caught within an hour to get a fair trial. However, such a world also would be one where…

By this argument we should defund the police because they could be used for oppression. Forgetting the reality that they are also stopping thousands of crimes every single day. Privacy absolution is never what most people signed up for.

Where did I make the argument that “we” don’t want to give up any privacy? I’m only claiming “we” don’t want to give up all privacy.

Also, “the police” are thousands of humans. That makes it harder to use the police for oppression than if “the police” were a bunch of computers and robots.

If somebody proposed the latter, I think lots of people would object.

Re: Google’s nightmare “Web Integrity API” wants a DRM gatekeeper for the web

#466
post #445

Earlier quoted context omitted.

i dont need debug tools in the browser - if the bytes of encoded content are getting transmitted to the socket on my machine, there is no realistic way to prevent me from taking and replicating them, i don't see how some software inside the browser can have any effect on this, because the browser has zero idea where these bytes can go after they hit the socket. A good analogy would be filming your screen manually - c…

> because the browser has zero idea where these bytes can go after they hit the socket The attestation uses a secure enclave in your processor with a secret key you can't access to verify that secure boot is on, you booted a signed OS, the OS is in locked-down mode, etc.

>The attestation uses

>you can't access

Don't you see how contradictory this is?

No secure enclave of registers or hidden secret keys can help, because a person can utilize the lower-level physical world around the processor to manipulate it (e.g sending electrical currents from a programator device manually). But that is a last resort, there are simple software attacks available already to fake as many "attested" devices as needed (for the same DRM system of Android). It will only bring more jeopardy to the "integrity"

Re: Google’s nightmare “Web Integrity API” wants a DRM gatekeeper for the web

#467
post #466

Earlier quoted context omitted.

> because the browser has zero idea where these bytes can go after they hit the socket The attestation uses a secure enclave in your processor with a secret key you can't access to verify that secure boot is on, you booted a signed OS, the OS is in locked-down mode, etc.

>The attestation uses >you can't access Don't you see how contradictory this is? No secure enclave of registers or hidden secret keys can help, because a person can utilize the lower-level physical world around the processor to manipulate it (e.g sending electrical currents from a programator device manually). But that is a last resort, there are simple software attacks available already to fake as many "attested" de…

See that's exactly the issue why I hate this. You can always circumvent it, worst case with an electron microscope and some acid. So all it really does is prevent the average user from gaining control over their own hardware.

And for tech-minded people it doesn't fundamentally change anything, it just means that it now takes more time to do the same than before

Re: Google’s nightmare “Web Integrity API” wants a DRM gatekeeper for the web

#468

Earlier quoted context omitted.

>when Apple tried to push a U2 album to them? They lost their collective shit and that's exactly it. putting something in your music library is a hugely more visible and tangible thing than all the nebulous privacy concerns the internet wants me to be afraid of. nobody gives a shit if google or apple or facebook or whoever else introduces some techical measure that could be used for nefarious things. they only care i…

> as long as the argument is "well if google implements X, then it would potentially allow them to do Y", that's a failing argument. It's similar to privacy 'dead bodies'[1], where users want to know actual concrete examples. I keep a collection of them in a larger directory of web pages about privacy, about instances where 'nebulous' privacy aspects meet reality and users are impacted and upset by it. [1] Term used…

> Daniel J. Solove's "I've got nothing to hide" and Other Misunderstandings of Privacy

That was an interesting read, thank you!

Re: Google’s nightmare “Web Integrity API” wants a DRM gatekeeper for the web

#469
post #466

Earlier quoted context omitted.

>The attestation uses >you can't access Don't you see how contradictory this is? No secure enclave of registers or hidden secret keys can help, because a person can utilize the lower-level physical world around the processor to manipulate it (e.g sending electrical currents from a programator device manually). But that is a last resort, there are simple software attacks available already to fake as many "attested" de…

See that's exactly the issue why I hate this. You can always circumvent it, worst case with an electron microscope and some acid. So all it really does is prevent the average user from gaining control over their own hardware. And for tech-minded people it doesn't fundamentally change anything, it just means that it now takes more time to do the same than before

True, a cat-and-mouse game going on forever. Anyways, I don't believe they can succeed in walling such a monstrosity of technologies as the web, just by controlling some parts of it, even significant parts like the browser or search. It is only something governments can do by requiring a passport scan each time you open a connection (which is closing when you eject the passport from the scanner)

Re: Google’s nightmare “Web Integrity API” wants a DRM gatekeeper for the web

#470
I'm totally behind all opposition against this, as I'm massively in line with the sentiment here. However thinking about it more and more, I get the impression that it will be essential to explain the impact of this to normal people (like my mom) and that's, what I just don't succeed in so far.

Without a broad support and public opinion about this, they might shockingly just be able to get this started. Apple and on-device CSAM scanning is something I have in mind about this, as s counter example.

What's a simple narrative non-tech people understand about this? Should I ask ChatGPT?

Post reply on HN