do they realize that you can use a custom certificate / patch the check routines? I don't think they quite realize what they are even suggesting.
Google Chrome Proposal – Web Environment Integrity
61–70 of 99 posts
Re: Google Chrome Proposal – Web Environment Integrity
#62There it is. Decades of turning up the heat and boiling the frog has culminated in this proposal. From secure boot and TPMs to SafetyNet and Pluton. Even in this very thread there are people saying this is not so bad because “it will help prevent fraud” lmao.
Re: Google Chrome Proposal – Web Environment Integrity
#63These proposals appear to be coming from the W3C Anti-Fraud Community Group. They haven't identified even a single use case[1] of the technologies they're trying to push onto the world being misused and abused. Use cases and their naivety appear to be largely copied from the OWASP Automated Threats to Web Applications[2]. There are no use case about these technologies being used by a dystopian country. No use case ab…
> Some examples of scenarios where users depend on client trust include:
> Users like visiting websites that are expensive to create and maintain, but they often want or need to do it without paying directly. These websites fund themselves with ads, but the advertisers can only afford to pay for humans to see the ads, rather than robots. This creates a need for human users to prove to websites that they're human, sometimes through tasks like challenges or logins.
So it's essentially Google further entrenching its tentacles in web standards in the most invasive ways with no regards towards privacy and user control. It's a shame what the W3C has degenerated into.
[1] https://github.com/RupertBenWiser/Web-Environment-Integrity/...
Re: Google Chrome Proposal – Web Environment Integrity
#64Earlier quoted context omitted.
Fair. Two questions: - What is the least expensive device that can be certified like that? The least expensive process? - What is the highest level of openness such a device can offer to the user, and why? To my mind, it would be best to have an option of a completely locked down and certified hardware token, a device like a Yubikey, that could talk to my laptop, desktop, phone, or any other computing device using a…
>What is the least expensive device that can be certified like that? I don't know. I haven't personally gone through the process. >What is the highest level of openness such a device can offer to the user, and why? You have to follow the CDD. https://source.android.com/docs/compatibility/13/android-13-... and you of course must pass the compatibility tests. So it can be as open as you would like as long as you do not…
AKA as long as you don't give control to the user.
Re: Google Chrome Proposal – Web Environment Integrity
#65Earlier quoted context omitted.
Play Protect is different from SafetyNet. SafetyNet means the app checks to make sure you're not rooted or running a custom ROM because those are considered a security risk. If you are not running a locked-down OEM ROM, you can't run many apps including banking apps. Microsoft's Pluton on-CPU attestation technology means this is coming to PCs.
Having a dedicated, locked-down device to access banks or other high-stakes services could be a good, if more expensive, solution. Keep it powered down when not needed for extra security. Idealy, it could be smaller than a smartphone, and use smartphone's or laptop's hardware for UI and networking.
I don't want to have to agree to Microsoft or Apple's ToS so that I can access my bank.
I do not look forward to trying to find a bank that doesn't require this of me because all of the major banks have jumped on board.
Re: Google Chrome Proposal – Web Environment Integrity
#66Earlier quoted context omitted.
>What is the least expensive device that can be certified like that? I don't know. I haven't personally gone through the process. >What is the highest level of openness such a device can offer to the user, and why? You have to follow the CDD. https://source.android.com/docs/compatibility/13/android-13-... and you of course must pass the compatibility tests. So it can be as open as you would like as long as you do not…
> as long as you do not break the android security model. AKA as long as you don't give control to the user.
A system being secure doesn't mean that the user doesn't have control. The operating system should allow the user to control it, but only in a secure way that doesn't compromise the rest of the security of the system. The Windows way of having an administrator account or Linux of having a root account given to the user has been proven over time to be worse for security. Windows has been trying to roll back this mistake, but most Linux distributions don't do anything because they don't care that much about security compared to an operating system like Android.
Re: Google Chrome Proposal – Web Environment Integrity
#67Earlier quoted context omitted.
> as long as you do not break the android security model. AKA as long as you don't give control to the user.
>AKA as long as you don't give control to the user. A system being secure doesn't mean that the user doesn't have control. The operating system should allow the user to control it, but only in a secure way that doesn't compromise the rest of the security of the system. The Windows way of having an administrator account or Linux of having a root account given to the user has been proven over time to be worse for secur…
I wanted to extract some data files from an app I was using and Google's Android told me that I was not allowed to do that. That was the apps data not my data.
It doesn't really matter root/fine grained permissions. The fact is that on stock Pixel phones the user can't access whatever data they want. So in practice they don't have control.
Re: Google Chrome Proposal – Web Environment Integrity
#68Earlier quoted context omitted.
Having a dedicated, locked-down device to access banks or other high-stakes services could be a good, if more expensive, solution. Keep it powered down when not needed for extra security. Idealy, it could be smaller than a smartphone, and use smartphone's or laptop's hardware for UI and networking.
It could be good if it was my choice. But I actually want to be able to access my bank from my computer running open source software where I can modify configuration and apply patches. I don't want to have to agree to Microsoft or Apple's ToS so that I can access my bank. I do not look forward to trying to find a bank that doesn't require this of me because all of the major banks have jumped on board.
Usually banks don't let you disable antifraud protections. They prefer to make their business and the banking system more secure by reducing the rate of fraud. Fraud is expensive for them to deal with so it doesn't really make financial sense to let customers say that they are okay with having more fraud happen using their account.
Re: Google Chrome Proposal – Web Environment Integrity
#69>6.1.1. Secure context only Web environment integrity MUST only be enabled in a secure context. This is to ensure that the website is not spoofed. Todo do they realize that you can use a custom certificate / patch the check routines? I don't think they quite realize what they are even suggesting.
Re: Google Chrome Proposal – Web Environment Integrity
#70Lots of people doom and gloom here about threats to user privacy and freedom. This is the one I'd be worried about. Thought it was annoying to not be able to use banking apps on a rooted Android? Think about how annoying it will be when you can't do much of anything, even on the Web, unless it's from a sealed, signed Apple/Google/Microsoft image-based OS... I realize the way Firefox's user share is going, it might no…
The frustrating thing is that this is both the final nail in the coffin for computing freedom, while also having a legitimate use case. I'm seeing new banks that flat out do not have a web UI at all. The reality is that desktop OSs and browsers have done nothing to stop the fact that it is trivial for a regular person to accidentally install malware which is completely transparent. Online fraud and theft is exploding…
It has to stop somewhere. 100% security may reduce the banks' fraud costs but it isn't acceptable for personal freedom. "Choose a different bank then" only works until all they all adopt it.