> Motivation: Users often depend on websites trusting the client environment they run in. Aka corporations insist on control & want to make sure users are powerless when using the site. And Chrome is absolutely here to help the megacorp's radically progress the War On General Purpose Computing and make sure users are safe & securely tied to environments where they are powerless. There's notably absolutely no discussi…
How do you, as website owner, protect your users from something like this? https://www.bleepingcomputer.com/news/security/451-pypi-pack...
Google Chrome Proposal – Web Environment Integrity
71–80 of 99 posts
Re: Google Chrome Proposal – Web Environment Integrity
#72Earlier quoted context omitted.
Bot traffic? Anyone using Linux will get blocked because "they can't be trusted". Only people running an "approved" operating system from a billion dollar corporation will be allowed to access. This is already what is happening with SafetyNet on Android. For now most applications don't require hardware attestation so you can pass by spoofing an old device that didn't support hardware attestation but I'm sure that wil…
You don't have to be a billion dollar corporation to become Play Protect certified. Being able to trust the security of a client can protect against many attacks and it is up to web sites to evaluate what to do with into information that a client is proven to be secure.
So the server is wildly insecure and wants to make it my problem.
Re: Google Chrome Proposal – Web Environment Integrity
#73Earlier quoted context omitted.
>AKA as long as you don't give control to the user. A system being secure doesn't mean that the user doesn't have control. The operating system should allow the user to control it, but only in a secure way that doesn't compromise the rest of the security of the system. The Windows way of having an administrator account or Linux of having a root account given to the user has been proven over time to be worse for secur…
Sure, in theory it doesn't but in practice it does. I wanted to extract some data files from an app I was using and Google's Android told me that I was not allowed to do that. That was the apps data not my data. It doesn't really matter root/fine grained permissions. The fact is that on stock Pixel phones the user can't access whatever data they want. So in practice they don't have control.
Re: Google Chrome Proposal – Web Environment Integrity
#74Earlier quoted context omitted.
You don't have to be a billion dollar corporation to become Play Protect certified. Being able to trust the security of a client can protect against many attacks and it is up to web sites to evaluate what to do with into information that a client is proven to be secure.
> Being able to trust the security of a client can protect against many attacks So the server is wildly insecure and wants to make it my problem.
Take for example a simple spam bot. The bot authenticates and then starts sending spam to people. Detecting spam and spammers server side is an imperfect art. It is a constant game of doing things to reduce the rate of spam. It can help a lot if you can ensure that only your client is able to work with your service. This means that attackers can't just write some python script and deploy it somewhere. They have to actually be running your app and actually liking the content in the app. This increases the costs for attackers and reduces the amount of spam.
Both client and server security is important.
Re: Google Chrome Proposal – Web Environment Integrity
#75Earlier quoted context omitted.
You do not, the user is responsible for the operation of their device. Most of the time this should be caught by whatever malicious software detector the user runs. Also, Chrome and Firefox very heavily guard against extensions being installed from outside of the usual way, i.e. by outside programs.
> You do not, the user is responsible for the operation of their device. As time goes on hand-waving the matter as "user's responsibility" is becoming a less and less acceptable answer. Hard assurances are being demanded and applied technologies are progressively patching the existing loopholes.
Re: Google Chrome Proposal – Web Environment Integrity
#76Earlier quoted context omitted.
The frustrating thing is that this is both the final nail in the coffin for computing freedom, while also having a legitimate use case. I'm seeing new banks that flat out do not have a web UI at all. The reality is that desktop OSs and browsers have done nothing to stop the fact that it is trivial for a regular person to accidentally install malware which is completely transparent. Online fraud and theft is exploding…
And in 100 years you will need to have your brain scanned to withdraw cash. The process will validate both your identity and that you aren't being coerced. It has to stop somewhere. 100% security may reduce the banks' fraud costs but it isn't acceptable for personal freedom. "Choose a different bank then" only works until all they all adopt it.
I assume an old person cares about not being left poor and helpless in retirement more than they care about free software and computing freedom.
I think it's probably likely that we will end up in a situation where some devices like phones and maybe laptops are considered "secure environments" where banking transactions and such can be safely executed, while alternative devices will be available for complete freedom and tinkering. You'll likely always be able to run any program you want on your laptop but those programs will be limited to their own sandbox rather than having free access to any other programs data.
Re: Google Chrome Proposal – Web Environment Integrity
#77Earlier quoted context omitted.
Sure, in theory it doesn't but in practice it does. I wanted to extract some data files from an app I was using and Google's Android told me that I was not allowed to do that. That was the apps data not my data. It doesn't really matter root/fine grained permissions. The fact is that on stock Pixel phones the user can't access whatever data they want. So in practice they don't have control.
That same ability makes it possible for 2FA apps to exist since the secrets can't be copied, turning the factor into something you know instead of something you have. Additionally just because someone is using a device that doesn't mean that the current user is the owner of the device.
And the alternative is taking a picture of the QR code.
> Additionally just because someone is using a device that doesn't mean that the current user is the owner of the device.
Yeah that's why you make the owner authenticate. It would be ridiculous to use that as a reason to make escalation impossible.
Re: Google Chrome Proposal – Web Environment Integrity
#78Earlier quoted context omitted.
It could be good if it was my choice. But I actually want to be able to access my bank from my computer running open source software where I can modify configuration and apply patches. I don't want to have to agree to Microsoft or Apple's ToS so that I can access my bank. I do not look forward to trying to find a bank that doesn't require this of me because all of the major banks have jumped on board.
>It could be good if it was my choice. Usually banks don't let you disable antifraud protections. They prefer to make their business and the banking system more secure by reducing the rate of fraud. Fraud is expensive for them to deal with so it doesn't really make financial sense to let customers say that they are okay with having more fraud happen using their account.
Re: Google Chrome Proposal – Web Environment Integrity
#79Earlier quoted context omitted.
Play Protect is different from SafetyNet. SafetyNet means the app checks to make sure you're not rooted or running a custom ROM because those are considered a security risk. If you are not running a locked-down OEM ROM, you can't run many apps including banking apps. Microsoft's Pluton on-CPU attestation technology means this is coming to PCs.
I am talking about "Play Protect certification." SafetyNet is deprectaed and has been replaced with the Play Integrity API. >means the app checks to make sure you're not rooted or running a custom ROM The purpose is to be able to tell if the user is running a version of the app is from the play store or to be able to tell if the device's integrity isn't compromised meaning that it can not rely on the security guarant…
And that effect is against custom ROMs and other kinds of user control.
Re: Google Chrome Proposal – Web Environment Integrity
#80I'm surprised the ad corps haven't forked the internet yet: special drm-ed websites accessible only via special drm-ed browsers. At least it would relieve those who want to share knowledge from the presence of those who sell addiction.
The whole point of things like this is to force the open internet to be the one to fork away. The network effect is solved by having enough money to take over an existing network.