Lots of people doom and gloom here about threats to user privacy and freedom. This is the one I'd be worried about. Thought it was annoying to not be able to use banking apps on a rooted Android? Think about how annoying it will be when you can't do much of anything, even on the Web, unless it's from a sealed, signed Apple/Google/Microsoft image-based OS... I realize the way Firefox's user share is going, it might no…
Safari, rather than Firefox, might be only actor with the market share and motivation to drag out the implementation and adoption of this proposal.
Google Chrome Proposal – Web Environment Integrity
81–90 of 99 posts
Re: Google Chrome Proposal – Web Environment Integrity
#82I'm surprised the ad corps haven't forked the internet yet: special drm-ed websites accessible only via special drm-ed browsers. At least it would relieve those who want to share knowledge from the presence of those who sell addiction.
Re: Google Chrome Proposal – Web Environment Integrity
#83API spec: https://rupertbenwiser.github.io/Web-Environment-Integrity/ It's morbidly amusing to see the browser referred to as a "user agent" here.
This probably isn't the best analogy to make the case you're trying to make. Agents in real life don't just blindly do whatever any customer asks. They actually have some standards and boundaries they have to observe, including ensuring integrity in their dealings on behalf of the customer. (To be clear I'm not endorsing the proposal, just commenting on the analogy.)
Not on behalf of the website.
Re: Google Chrome Proposal – Web Environment Integrity
#84Earlier quoted context omitted.
> You do not, the user is responsible for the operation of their device. As time goes on hand-waving the matter as "user's responsibility" is becoming a less and less acceptable answer. Hard assurances are being demanded and applied technologies are progressively patching the existing loopholes.
It's not hand-waving; it literally is not the website's responsibility.
Re: Google Chrome Proposal – Web Environment Integrity
#85>bewise@chromium.org
>sergeyka@chromium.org
Re: Google Chrome Proposal – Web Environment Integrity
#86These proposals appear to be coming from the W3C Anti-Fraud Community Group. They haven't identified even a single use case[1] of the technologies they're trying to push onto the world being misused and abused. Use cases and their naivety appear to be largely copied from the OWASP Automated Threats to Web Applications[2]. There are no use case about these technologies being used by a dystopian country. No use case ab…
It's web 2.0, user is a product.
Re: Google Chrome Proposal – Web Environment Integrity
#87Earlier quoted context omitted.
Sure, in theory it doesn't but in practice it does. I wanted to extract some data files from an app I was using and Google's Android told me that I was not allowed to do that. That was the apps data not my data. It doesn't really matter root/fine grained permissions. The fact is that on stock Pixel phones the user can't access whatever data they want. So in practice they don't have control.
That same ability makes it possible for 2FA apps to exist since the secrets can't be copied, turning the factor into something you know instead of something you have. Additionally just because someone is using a device that doesn't mean that the current user is the owner of the device.
Furthermore nothing prevents you from just taking pictures of the individual enrollment keys and printing those out either.
If you want TOTP 2FA that actually follows a one key per device policy you need to buy hardware tokens with some kind of out-of-band keying mechanism and enroll those. Then your problem changes from "how to stop people from copying my 2FA tokens" to "how to not get locked out of my account when my 2FA key device breaks."
Re: Google Chrome Proposal – Web Environment Integrity
#88Re: Google Chrome Proposal – Web Environment Integrity
#89Re: Google Chrome Proposal – Web Environment Integrity
#90They got tired of getting comments from mere web users that don't want this and locked down comments :P