Live data from Hacker News

Google Chrome Proposal – Web Environment Integrity

chromestatus.com

1–10 of 99 posts

Re: Google Chrome Proposal – Web Environment Integrity

#2
> Motivation: Users often depend on websites trusting the client environment they run in.

Aka corporations insist on control & want to make sure users are powerless when using the site. And Chrome is absolutely here to help the megacorp's radically progress the War On General Purpose Computing and make sure users are safe & securely tied to environments where they are powerless.

There's notably absolutely no discussion or mention of what kind of checks an attestation authority might give, other than "maybe Google Play might attest for the environment" as a throwaway abstract example with no details. Any browser could do whatever they want with this spec, go as afar as they want to say, yes, this is a pristine development environment. If you open DevTools, Google will probably fail you.

It appalls me to imagine how much time & mind-warping it must have taken to concoct such a banal "user motivation" statement as this. This is by the far the lowest & most sold-out passed-over bullshit I have ever seen from Chrome, who generally I actually really do trust to be doing good & who I look forward to hearing more from.

Re: Google Chrome Proposal – Web Environment Integrity

#4

> Motivation: Users often depend on websites trusting the client environment they run in. Aka corporations insist on control & want to make sure users are powerless when using the site. And Chrome is absolutely here to help the megacorp's radically progress the War On General Purpose Computing and make sure users are safe & securely tied to environments where they are powerless. There's notably absolutely no discussi…

Many Googlers here, hope they are more vocal when Google comes up with BS. Rather than when they post a positive blog post.

Re: Google Chrome Proposal – Web Environment Integrity

#6

> Motivation: Users often depend on websites trusting the client environment they run in. Aka corporations insist on control & want to make sure users are powerless when using the site. And Chrome is absolutely here to help the megacorp's radically progress the War On General Purpose Computing and make sure users are safe & securely tied to environments where they are powerless. There's notably absolutely no discussi…

How do you, as website owner, protect your users from something like this?

https://www.bleepingcomputer.com/news/security/451-pypi-pack...

Re: Google Chrome Proposal – Web Environment Integrity

#7
post #3

AKA: The shadow war on bot traffic continues humming along.

Bot traffic? Anyone using Linux will get blocked because "they can't be trusted". Only people running an "approved" operating system from a billion dollar corporation will be allowed to access.

This is already what is happening with SafetyNet on Android. For now most applications don't require hardware attestation so you can pass by spoofing an old device that didn't support hardware attestation but I'm sure that will change within a decade.

Re: Google Chrome Proposal – Web Environment Integrity

#8
Lots of people doom and gloom here about threats to user privacy and freedom.

This is the one I'd be worried about. Thought it was annoying to not be able to use banking apps on a rooted Android? Think about how annoying it will be when you can't do much of anything, even on the Web, unless it's from a sealed, signed Apple/Google/Microsoft image-based OS...

I realize the way Firefox's user share is going, it might not matter or they might feel they don't have a choice but I really, really hope Mozilla doesn't even remotely consider implementing this.

Re: Google Chrome Proposal – Web Environment Integrity

#9

> Motivation: Users often depend on websites trusting the client environment they run in. Aka corporations insist on control & want to make sure users are powerless when using the site. And Chrome is absolutely here to help the megacorp's radically progress the War On General Purpose Computing and make sure users are safe & securely tied to environments where they are powerless. There's notably absolutely no discussi…

How do you, as website owner, protect your users from something like this? https://www.bleepingcomputer.com/news/security/451-pypi-pack...

Why do you, as a website owner, think that it is your responsibility to protect your users from mistyping the name of Python packages they are installing via pip?
Post reply on HN