Live data from Hacker News

Google’s nightmare “Web Integrity API” wants a DRM gatekeeper for the web

arstechnica.com

71–80 of 484 posts

Re: Google’s nightmare “Web Integrity API” wants a DRM gatekeeper for the web

#71
post #23
post #6

Google seems to be escalating the speed of its efforts to restrict its user base to the completely non-technical, but Apple and Facebook already own that market. It also sounds like they're promoting yet another way to make "the internet" slower, more bloated, and have greater impediments to usage.

This proposal only impacts "the web", which has already been going downhill for years now due to unsustainable ad-reliant business models. The internet is fine.

For the vast majority of people, the internet is the web, as well as mobile apps. The latter are already out of the control of users. Today, we at least have browsers that we can mostly force to do what we want (like stop downloading and displaying ads), but WEI will end up restricting portions of the web to users running browsers that do what the web servers want, not what their users want.

And for most people in the world, that is "the internet".

Re: Google’s nightmare “Web Integrity API” wants a DRM gatekeeper for the web

#72

They're going to prevent me from running an adblocker in this "web integrity" environment, aren't they.

Not until Mozilla gives in.

And if they don't give in, Firefox users will stop being able to access Google properties, and then probably others like video and music streaming sites, and possibly even the larger news outlets. Banking sites might get in on the action, being led to believe that doing so will increase security.

Re: Google’s nightmare “Web Integrity API” wants a DRM gatekeeper for the web

#73
post #26
post #20

Earlier quoted context omitted.

It won't at all, of course, but personal websites are a vanishing breed.

HTTPS has a lot to do with that. let's encrypt is free, but requires things common users dont have, such as control of a domain, as it is if google can see your stored certificates it could exclude you from a site based on "sites you hang around with"

Yeah, HTTPS accelerated it quite a lot, but the trend was already in play before that push.

Re: Google’s nightmare “Web Integrity API” wants a DRM gatekeeper for the web

#74

Seems like this is going to get a lot of pushback. It might not go through. But remember whether it goes through or not isn't the important thing. The fact that Google wants it to is what matters.

Correct. If the pushback is successful, rest assured that the reprieve will be temporary. At best, they'll come back around with some tweaks and changes to blunt the more egregious aspects, but it will come back.

The "privacy sandbox" stuff is a perfect example of this process.

Re: Google’s nightmare “Web Integrity API” wants a DRM gatekeeper for the web

#75

> Exactly how the rest of the world feels about this is not necessarily relevant, though. Google owns the world's most popular web browser, the world's largest advertising network, the world's biggest search engine, the world's most popular operating system, and some of the world's most popular websites. So really, Google can do whatever it wants. On one hand, I think this is wrong, because the world is full of tech…

Isn't Mozilla's main source of revenue actually google?

Re: Google’s nightmare “Web Integrity API” wants a DRM gatekeeper for the web

#76
post #44

> Google's plan is that, during a webpage transaction, the web server could require you to pass an "environment attestation" test before you get any data. At this point your browser would contact a "third-party" attestation server, and you would need to pass some kind of test. If you passed, you would get a signed "IntegrityToken" that verifies your environment is unmodified and points to the content you wanted unloc…

[deleted]

Re: Google’s nightmare “Web Integrity API” wants a DRM gatekeeper for the web

#78
I'll add to this, notably, issues are still closed after the weekend: https://github.com/RupertBenWiser/Web-Environment-Integrity/...

If this proposal gets rejected it'll be because of feedback in the press that is impossible to ignore. My experience watching how Google has handled contentious issues in the past makes me personally feel that Google will not be receptive to concerns about whether this spec should exist. Google and the Chromium team are not willing to hear community feedback about the direction of the web or about what the web should be. They demand that feedback start from a position of assuming the best intentions of the spec, and start from a position of assuming that the spec is basically good and might just have additional concerns to address (https://blog.yoav.ws/posts/web_platform_change_you_do_not_li...).

This has been a longstanding issue with how Google approaches web standards; according to Google there's no such thing as a harmful feature and Google's approach is never wrong; it just might need refining. The refining is the only thing that Google wants to talk about.

There is a predictable arc to this narrative as well. If blowback gets out of control, Google will blame that blowback on misinformation and accuse the community of operating in bad faith or fearmongering. At best, you'll get a few people from the Chromium team saying "we hear you and we need to communicate better." Note the underlying implication behind that statement that the original proposal wasn't bad, it just wasn't communicated well. People just need to do a better job of "getting involved" in the web standards process so that the Chromium team knows to address their concerns. And it just comes down to learning to be kind and "remembering the human" -- ie ignoring the structural damage that the human is capable of causing to the largest and arguably most important Open platform on the planet.

There will never in any situation be an acknowledgement that the direction or intent was wrong; that's just overwhelmingly not how the Chromium team operates on any issue big or small.

It's good for larger sites like Ars to cover this, and it's good for people to share thoughts on social media; the only way that users have a say over this is if the press runs with it and generates a metric ton of bad publicity for Google; and even then it's a toss-up. It comes down to what the company feels like it can ignore or dismiss with a couple of Twitter posts. And this is not just where issues like adblocking are concerned, the Chromium team has been hostile to user feedback even on more minor technical issues for a pretty long while. I was writing about this issue back in 2018 (https://danshumway.com/blog/chrome-autoplay) and it was a trend before that point as well.

It stinks to go into a conversation not assuming good will from all of the parties (and it usually is wrong to do so), but the Chromium team has not earned an assumption of good will, and it's done quite a bit to squander that assumption. It's regrettably kind of a waste of time to try and engage on this stuff, it's better to just criticize on social media and hope that the press runs with it. Because that's the only thing that Google listens to.

Re: Google’s nightmare “Web Integrity API” wants a DRM gatekeeper for the web

#79

> Google's plan is that, during a webpage transaction, the web server could require you to pass an "environment attestation" test before you get any data. There is no value in this "attestation" for me as a user. I want to be able to do whatever I want with the browser (for example, remove ads or block access to canvas and webgl) and I want sites to be unable to know this. And probably this attestation will provide a…

Attestation is a great concept for stuff you're in control of. Employee laptops, your own servers, your own phone, you name it. You want to be able to control and verify your devices are still under your control, preferably without manually entering the data center every week to check. The concept isn't inherently bad.

That said, the concept is seemingly aimed at blocking ad blockers and preventing browsers like Brave from impersonating Chrome so it can block ads without the need for extensions and such.

The only user-positive use case I can think of for this is for self-hosted software. Maybe it can be used to detect MitM attacks or malware messing with the browser? In practice this will just mean "no Firefox, no Linux, no adblockers".

Re: Google’s nightmare “Web Integrity API” wants a DRM gatekeeper for the web

#80

> Exactly how the rest of the world feels about this is not necessarily relevant, though. Google owns the world's most popular web browser, the world's largest advertising network, the world's biggest search engine, the world's most popular operating system, and some of the world's most popular websites. So really, Google can do whatever it wants. On one hand, I think this is wrong, because the world is full of tech…

> I use Firefox, and it won't affect me.

It will affect you a lot if websites start refusing to serve to you because you're not using an approved browser.

Post reply on HN