Live data from Hacker News

Web Environment Integrity API Proposal

github.com

1–10 of 460 posts

Re: Web Environment Integrity API Proposal

#3

tl;dr: DRM for websites

It looks very similar to the “secure boot” mechanisms in Windows and other commercial client OS.

Strikes me as very dangerous though on the web where there are so many paths for malware to get in and this could get in the way of plugging the holes.

Re: Web Environment Integrity API Proposal

#5
This is pretty much the inevitable end-game of the web, in no small part funded by ad-based business models (as the analog gap pretty much destroys most attempts to use this stuff to do copy protection) and enabled by developers who have insisted we shove as much difficult-to-implement functionality (by which I am talking about CSS complex stuff, not powerful-but-easy-to-code APIs for OS-level access) into the browser as possible.

The result: there is now effectively one dominating web browser run by an ad company who nigh unto controls the spec for the web itself and who is finally putting its foot down to decide that we are all going to be forced to either used fully-locked down devices or to prove that we are using some locked-down component of our otherwise unlocked device to see anyone's content, and they get to frame it as fighting for the user in the spec draft as users have a "need" to prove their authenticity to websites to get their free stuff.

(BTW, Brave is in the same boat: they are also an ad company--despite building ad blocking stuff themselves--and their product managers routinely discuss and even quote Brendan Eich talking about this same kind of "run the browser inside of trusted computing" as their long-term solution for preventing people blocking their ads. The vicious irony: the very tech they want to use to protect them is what will be used to protect the status quo from them! The entire premise of monetizing with ads is eventually either self-defeating or the problem itself.)

Re: Web Environment Integrity API Proposal

#6
This seems like a step closer to killing the open web.

"Sorry, you can only access this website using this specific device with a browser compiled by Big Tech, it's for your own good."

Not surprising that this is all coming from Google, the world's biggest adtech company.

Re: Web Environment Integrity API Proposal

#9
Whether you like it or not (and I certainly don't), you've gotta sort of admire the sheer vision of a fifteen-year project to build a browser so good it comes to monopolize the industry, all because you've had the foresight to realize that monopoly will be crucial to securing your position as the adtech hegemon. An underrated masterpiece of evil genius.

Re: Web Environment Integrity API Proposal

#10

tl;dr: DRM for websites

It looks very similar to the “secure boot” mechanisms in Windows and other commercial client OS. Strikes me as very dangerous though on the web where there are so many paths for malware to get in and this could get in the way of plugging the holes.

It was also dangerous for your PC: as soon as people ceded the ability to led their parties control what we run on our devices--such as by "only firmware signed by Apple can run on my phone"--we lost this war.
Post reply on HN