12 ms·
Google’s nightmare “Web Integrity API” wants a DRM gatekeeper for the web
- ninjaa 3y agoThey keep trying this shady type of thing every few months
- account-5 3y agoNext step Google starts scanning your face and eyeballs but doesn't bother paying for it.
- gloosx 3y agoI'll tell you this – there are people who watched all Netflix titles and never visited netflix.com. People who read the NYT daily but never visited nytimes.com. What does this change mean? There will be more such people.
- everdrive 3y agoLooks like I’m going to be reading a lot more books in the future.
- jqpabc123 3y agoSounds crazy. But a possible way to defeat it is what I do now --- keep two devices. One that meets their requirements for cases where it is absolutely needed and another for everything else.
- teraflop 3y agoAll well and good, until the number of websites that refuse to work without attestation starts inexorably creeping upwards, year after year.
- tumult 3y agoThe cases where your locked device is absolutely necessary will approach 100%.
- rolph 3y agoattested proxies, back n forthing between a user, and the chrome zone
- contravariant 3y agoWhen it comes to a game of chicken it's better to not just seem like you won't move, but to throw out the wheel entirely. Of course it's dubious if it applies here, especially because the playing field doesn't feel quite equal, but I think the most effective thing we can do is simply refuse to use websites that require a custom built user agent to access. Heck maybe we've already mostly lost the battle to keep the internet usable with curl, let's at least try to keep some of the other options open.
- JohnFen 3y agoThis sounds like the final death blow to the web as a useful platform for anyone who isn't a corporation.
- marginalia_nu 3y agoWhy is that?
- JohnFen 3y ago> Google's plan is that, during a webpage transaction, the web server could require you to pass an "environment attestation" test before you get any data. At this point your browser would contact a "third-party" attestation server, and you would need to pass some kind of test. If you passed, you would get a signed "IntegrityToken" that verifies your environment is unmodified and points to the content you wanted unlocked. Because of this. If we're at the point where you need to get permisssion and approval to verify that the platform you're using is acceptable, then the gates are up and the free web is no longer free at all.
- marginalia_nu 3y agoWhy is that? Who is forcing the free web to use this mechanism, since it is the server that requests the confirmation. Why can't it just... not?
- skydhash 3y agoAll the websites demanding that I disable my adblocker say that they definitely will.
- marginalia_nu 3y agoThat doesn't seem like the free web though.
- summerlight 3y ago
- gary_0 3y agoBe Evil™
- danShumway 3y agoSee also previous discussion on https://news.ycombinator.com/item?id=36817305 https://news.ycombinator.com/item?id=36817305 (the same link mentioned in the article) It's honestly good for this to get a lot of attention though, I'm happy to see additional commentary on it getting shared.
- jauntywundrkind 3y agoIt's good that it's happening strong & still semi-early-ish. I'd be curious to know how or if Chrome actually manages the PR around their work. Chrome lead fired off a blog post So you don't like a web proposal which effectively says it's purely a technical decision, and that only constructive technical criticism is regarded at all. https://news.ycombinator.com/item?id=36818409 https://news.ycombinator.com/item?id=36818409 https://blog.yoav.ws/posts/web_platform_change_you_do_not_like/ https://blog.yoav.ws/posts/web_platform_change_you_do_not_li... But I don't feel like Google has the luxury of letting it's image burn like this. TURTLEDOVE is already a huge semi-sound but immensely scary change, MV3 is a disaster of high order and hasn't responded with anything but a stream of bandaids to challenges like Mozilla's far more capable Background Pages proposals. But I think the reputation damage here is vastly higher, as there's basically nothing being offered here to most users, or, if this spec goes through, ex-Web users. This effort is just an abominable horror show, and at some point, it feels like Google/Chrome have to stop being so blinders-on as to treat this as a merely technical discussion. The last time these debates went down, where there was an incredibly contentious spec that got shipped, it basically took the Web creator Tim Berners-Lee using his w3c authority to stamp "ship it" on the spec. https://www.techdirt.com/2017/03/01/tim-berners-lee-endorses-drm-html5-offers-depressingly-weak-defense-his-decision/ https://www.techdirt.com/2017/03/01/tim-berners-lee-endorses...
- keepamovin 3y agoMore importantly, a company of the size, scope and sophistication of Google trying to hide its fundamental redefinition of how people access the web, behind “it’s only a technical change” is unacceptable. As if something with multiple downstream non-technical effects, is only a technical change As if you can minimize and dismiss everyone’s fears and concerns as hollow, invalid and irrelevant by waving the magic wand of tis only a wee technical change, to be sure, to be sure As if everyone’s protests and arguments against can be instantly hosed down, because aye, you guessed it laddie, it’s only a technical change It’s almost as if the folks at Google think people are so stupid that not only do people not know what they’re talking about, but they’ll actually believe the lie and fall for that deception… It’s almost as if Google was trying to gaslight the public about this… If they end up groveling about this, I don’t think “in retrospect, we could have communicated this better” is going to cut it. This is a company the size, scope and sophistication of Google. This is not their first rodeo. They know exactly what they’re doing, and they mean to do it…
- BLKNSLVR 3y agoGoogle seems to be escalating the speed of its efforts to restrict its user base to the completely non-technical, but Apple and Facebook already own that market. It also sounds like they're promoting yet another way to make "the internet" slower, more bloated, and have greater impediments to usage.
- treyd 3y agoThis proposal only impacts "the web", which has already been going downhill for years now due to unsustainable ad-reliant business models. The internet is fine.
- truevelvet 3y agoThat distinction made me feel better about the whole thing. Thank you.
- JohnFen 3y ago> The internet is fine. I wish I could agree. The internet isn't in nearly as bad of shape as the web is, that's true. But it doesn't look nearly as healthy as it used to, as more and more services are moving to the web and abandoning the internet.
- kelnos 3y agoFor the vast majority of people, the internet is the web, as well as mobile apps. The latter are already out of the control of users. Today, we at least have browsers that we can mostly force to do what we want (like stop downloading and displaying ads), but WEI will end up restricting portions of the web to users running browsers that do what the web servers want, not what their users want. And for most people in the world, that is "the internet".
- treyd 3y agoThe distinction is important in my opinion because it means that our technology stack isn't necessarily captured to the root by hostile interests. In these respects, a better world is possible without having to dig everything up and start over, for now.
- anderspitman 3y agoSeems like this is going to get a lot of pushback. It might not go through. But remember whether it goes through or not isn't the important thing. The fact that Google wants it to is what matters.
- thesuperbigfrog 3y ago>> Seems like this is going to get a lot of pushback. It is: https://github.com/RupertBenWiser/Web-Environment-Integrity/issues https://github.com/RupertBenWiser/Web-Environment-Integrity/...
- rvnx 3y agoThe same was with Privacy Sandbox; Result: billions of device now happily adopted it (by force).
- urda 3y ago> An owner of this repository has limited the ability to open an issue to users that have contributed to this repository in the past. It sure seems like they're silencing opposition.
- JohnFen 3y agoCorrect. If the pushback is successful, rest assured that the reprieve will be temporary. At best, they'll come back around with some tweaks and changes to blunt the more egregious aspects, but it will come back. The "privacy sandbox" stuff is a perfect example of this process.
- caskstrength 3y ago> Correct. If the pushback is successful, rest assured that the reprieve will be temporary. At best, they'll come back around with some tweaks and changes to blunt the more egregious aspects, but it will come back. Yes, they might even intentionally have started with proposal so over-the-top that people who are now protesting may feel that they won when some time afterwards Google presents slightly less creepy second iteration this. And the ones who don't will be cast as radicals who don't want to engage in good-faith discussion while Google seemingly proposes a reasonable compromise. Besides, would anybody please think of the child... err... banks with webpages!
- fidotron 3y agoThe Chrome team have used "the Open Web" as a euphemism for what is to all intents and purposes Google's great ad supported walled garden. That so few people see this for what it is is amazing, and then they get all surprised when Google act to preserve it and close the capability gap with native platforms.
- ASalazarMX 3y agoIt's an incredible hubris to pretend to gatekeep the whole Internet. Google´s being doing a pretty hansome profit, maybe not the meteoric rise they were used to before 2020, but still nothing to warrant such desperate measures to secure future profits.
- px43 3y agoWhen Microsoft did this with IE, they did it with proprietary and undocumented APIs. The fact that this is an open spec, discussed in an open forum, using well established and standard technologies is what ensures it can never be positioned against users in any meaningful way. To me it looks like SGX for the web. Maybe it will introduce some neat and weird capabilities, but at the end of the day, it will be trivial to bypass at scale if it ever positions itself as being harmful to users.
- AlotOfReading 3y agoCan you explain how you'd bypass it? Let's say example.com decides to require attestation from the {MS, Apple, Google} providers, and that they attest to only Chrome without extensions. You can't forge the attestation because cryptography. You can't fail to provide it (because they'll just refuse to send the bits). You can't use a "malicious" attestor because example.com won't trust it. What's the trivial bypass I'm missing? How does a freely accessible standard impact the ability to bypass things in any way?
- px43 3y agoTPMs can be emulated. Also basically every hardware platform can be placed into a hardware debug mode that allows live debugging of the underlying operating system. Keys can also be extracted from hardware. If even one supported platform leaks a key (and in this doomer fantasy world all platforms must be supported right?) then the attestations can be bypassed. It only needs to be bypassed once to be bypassed everywhere, basically forever.
- wiseowise 3y ago> The goal of the project is to learn more about the person on the other side of the web … The intro says this data would be useful to advertisers to better count ad impressions, stop social network bots, enforce intellectual property rights, stop cheating in web games Go f yourself, Google. Browser’s purpose is to serve me web pages, not to learn about me.
- rvz 3y agoAs long as Google is still leading in the browser market share, they do not care or give a shit and will never change.
- rodgerd 3y agoGoogle are a monopoly, near-monopoly, or duopoly on the browser, search, maps, advertising, mobile, and mail. The only regulatory action we've seen - supported on HN - is to go after their competitors.
- BiteCode_dev 3y agoSo many people are harsh Google critics, yet still never use duckduckgo, don't try to migrate from gmail, or stick to firefox. Complaining is easy, but apparently even small compromises like these are hard.
- jeltz 3y agoI use Firefox on desktop and mobile, I use DDG, stopped using Google Analytics but I sadly still use Gmail and Android. I degoogled the east things (e.g. GA and Chrome) but getting totally rid off Google is hard.
- pingohits 3y ago> getting totally rid off Google is hard Sometimes impossible in my case. Google Drive is always used in any collaborative project; so is Google Colab and Google Meet. And I still have the instinctual drive to reach for Google Translate/Maps, because it's so easy to access (physically and mentally). Google google google google google...
- LispSporks22 3y agoThey're going to prevent me from running an adblocker in this "web integrity" environment, aren't they.
- benterix 3y agoNot until Mozilla gives in.
- doliveira 3y agoEven if they don't, a lot of websites are just breaking on Firefox. The development community decided they want a Chrome monoculture.
- hdjdndhfbrb 3y agoWhere do you think Mozilla gets its funding from?
- hdjdndhfbrb 3y agoCapitulation in 3,2,1
- LispSporks22 3y agoAs I recall, Mozilla caved last time with EME so I would not count on it.
- JohnFen 3y agoYeah, that was when I realized that Mozilla wasn't really able to stand up to the bad guys as much as we'd hope.
- jeroenhd 3y agoYou can still disable EME if you don't want it. That's a lot harder to do on other browsers. I would probably have dropped Firefox back then if it was the only browser that I couldn't watch Netflix in, and I wouldn't be the only one. I don't think Mozilla can bear the loss of userbase.
- elforce002 3y agoWell, I think this move by google will divide the chromium project in 2 versions: one with and one without this "feature".
- WirelessGigabit 3y agoIt doesn't matter. It's a DRM. If your version of the software doesn't contain the right keys none of this will work correctly. Kinda like how Widevine works. No keys means lower quality.
- SpaghettiCthulu 3y agoDon't you think people will inevitably crack the software side of things (as has been done with the lower levels of Widevine)? The end game is probably integration with a TPM that produces the token, or at least whatever part of it verifies that the chrome binary is genuine and that there is no forbidden software running on the client machine.
- userbinator 3y agoThe end game is probably integration with a TPM that produces the token, or at least whatever part of it verifies that the chrome binary is genuine and that there is no forbidden software running on the client machine. That is exactly the goal of this, and why it needs to be opposed fiercely.
- pornel 3y agoGoogle will degrade their services for non-DRM browsers. They have a long history of "oops" with UA sniffs and serving slow buggy alternatives to Chrome-only JS. You'll be filling in captchas 10 times a day, getting randomly locked out of your Google account in the name of security, and whatever new feature they add to their services, they'll find an excuse to require the DRM for it.
- codedokode 3y agoCloudflare will happily help Google with displaying captchas to everyone not using Chrome.
- Fartmancer 3y agoIt honestly boggles the mind that the same company I used to respect twenty years ago has morphed into the evil monster that is modern Google. A tragic fall from grace.
- wetpaws 3y ago[dead]
- kibwen 3y agoSuch is the fate of all companies. Companies need to be allowed to die in order to facilitate competition, but because of a failure of antitrust regulators to do their jobs, giant companies have been allowed to leverage their war chests to perpetuate themselves by gobbling up competitors and prolonging their own demise, to the detriment of us all. Google needs to be broken up, and the other tech giants too. Bring back competition to the market or we'll continue marching towards Blade Runner corporate dystopia.
- pessimizer 3y agoThese companies are merging with government. It's not about the ads.
- userbinator 3y agoGoogle has almost become a government, and one that we didn't explicitly vote for.
- arciini 3y agoWhile I don't love this API's idea, I understand why they're doing it, and the API it describes really just sounds like any Captcha API today. > Google's plan is that, during a webpage transaction, the web server could require you to pass an "environment attestation" test before you get any data. At this point your browser would contact a "third-party" attestation server, and you would need to pass some kind of test. If you passed, you would get a signed "IntegrityToken" that verifies your environment is unmodified and points to the content you wanted unlocked. You bring this back to the web server, and if the server trusts the attestation company, you get the content unlocked and finally get a response with the data you wanted. The problem with Captchas today is that there are a lot of services you can use to bypass them. You send the token to a human, human gives you the solution-token, and you pass that to Google. I can see why they want to make this more protected. As a user, if this lets me solve captchas less for certain sites, I'm OK with that. Of course, I don't think this API should be used for the entire web, but I definitely understand its use-case.
- rvnx 3y agoIf you liked that idea, you may love "Privacy Pass" by Cloudflare: https://chrome.google.com/webstore/detail/privacy-pass/ajhmfdgkijocedmfjonnpjfojldioehi https://chrome.google.com/webstore/detail/privacy-pass/ajhmf...
- pests 3y agoThis deserves it's own post.
- pptr 3y agoThat's how I read the proposal too. One key difference to Captchas is that since this new system requires no user input, the "cost" of a website requesting attestation is a lot smaller. So it will probably be used more widely.
- alex7734 3y agoCaptchas only let you verify that the user is human, this API lets you do more: it lets you verify that your web application is going to run unmodified and that the user is going to see what you want him to see, _everything_ that you want him to see and nothing else. Unlike captchas with this you can remove adblockers, greasemonkey/stylus edits, extensions adding download links to your youtube videos, etc, from the picture.
- mabbo 3y ago> Exactly how the rest of the world feels about this is not necessarily relevant, though. Google owns the world's most popular web browser, the world's largest advertising network, the world's biggest search engine, the world's most popular operating system, and some of the world's most popular websites. So really, Google can do whatever it wants. This is the point that company breakups start to make a lot of sense. When Google can do something that every one of it's users hates and none of us can do anything about it, they perhaps have too much market power.
- kelnos 3y ago> When Google can do something that every one of it's users hates I don't think this is remotely the case. Quite a few tech-savvy people I know (some of them software developers) use Chrome and mostly don't care about whatever Google does with it. I mention "manifest v3" and get a blank stare. I talk about advertising and ad blockers, and most people don't care, with some of them not even using ad blockers. We really live in a bubble, here on HN. Most people think of privacy as some abstract thing that they have little control over, and are mostly fine with that. And some are even also fine with government erosion of privacy, in the name of "save the children" style arguments, and of corporate erosion of privacy, in the name of getting free stuff in exchange for their personal information. It's a sad state of affairs. If most people really did care strongly about these sorts of issues, then I think it would be baffling why we haven't seen more change here -- after all, Firefox is a perfectly viable alternative to Chrome that very few people use. But the lack of change is no surprise: most people don't care.
- lima 3y agoI'm a tech-savvy person and I consider Manifest v3 an improvement (improves security + performance), and Firefox implements it as well as things like declarativeNetRequest[1]. [1]: https://developer.mozilla.org/en-US/docs/Mozilla/Add-ons/WebExtensions/API/declarativeNetRequest https://developer.mozilla.org/en-US/docs/Mozilla/Add-ons/Web...
- gruez 3y ago
- warning26 3y agoI already hate SafetyNet™ on Android, which punishes people for rooting their phones. This basically appears to be trying to bring that to the web. Want to go to an online banking site? Then we'll need to make sure your computer is unmodified and contains no unapproved software.
- calibas 3y ago> Google's plan is that, during a webpage transaction, the web server could require you to pass an "environment attestation" test before you get any data. At this point your browser would contact a "third-party" attestation server, and you would need to pass some kind of test. If you passed, you would get a signed "IntegrityToken" that verifies your environment is unmodified and points to the content you wanted unlocked. Would you rather a capitalist dystopia, where large corporations get to approve everything you see & hear, or a socialist dystopia, where the government gets to determine what you're allowed to view? [Answer: Neither]
- deleted 3y ago[deleted]
- codedokode 3y ago> Google's plan is that, during a webpage transaction, the web server could require you to pass an "environment attestation" test before you get any data. There is no value in this "attestation" for me as a user. I want to be able to do whatever I want with the browser (for example, remove ads or block access to canvas and webgl) and I want sites to be unable to know this. And probably this attestation will provide additional fingerprinting signals which is what I don't want.
- jeroenhd 3y agoAttestation is a great concept for stuff you're in control of. Employee laptops, your own servers, your own phone, you name it. You want to be able to control and verify your devices are still under your control, preferably without manually entering the data center every week to check. The concept isn't inherently bad. That said, the concept is seemingly aimed at blocking ad blockers and preventing browsers like Brave from impersonating Chrome so it can block ads without the need for extensions and such. The only user-positive use case I can think of for this is for self-hosted software. Maybe it can be used to detect MitM attacks or malware messing with the browser? In practice this will just mean "no Firefox, no Linux, no adblockers".
- crote 3y agoEhhh, it depends. In theory one could imagine a scenario like a bank website refusing to be accessed unless the entire OS & browser stack pass attestation - as that would rule out things like keyloggers, malicious browser extensions, and session hijacking. In practice it'll just be used to lock down content and force unskippable ads on users, of course.
- rezonant 3y agoOne thing from the blink-dev discussion caught my eye: > Anything we might decide would ultimately be influenced by the larger societal debate around privacy (regulations etc.) since perfect privacy means perfect immunity for criminals. Ensuring that your devices don't spy on you on behalf of a government or company does not imply "perfect immunity for criminals". Putting aside attestation for the moment, consider this: Modern enclave driven device encryption (and the self-destructive passcode limitations that often accompany it), for example, could be likened to designing a very good safe that can automatically destroy its contents if it is breached. Do we require governments to have their own keys to all such safes sold?
- hnbad 3y agoIt's funny how they frame laws and regulations designed to prevent companies from abusing people's rights as a "larger societal debate". Yes, the debate is between people who want companies to respect their rights and companies who don't wanna. That's not a debate and framing it as such is just an obvious attempt to narrativize their stance for lobbyists. Also "perfect privacy" is a red herring (binary fallacy or what is it called?) because the compromise between no privacy and perfect privacy doesn't have to be "Google gets to harvest users' data against their wishes".
- minerva23 3y ago"Those who would give up essential liberty to purchase a little temporary safety, deserve neither liberty nor safety." The problematic dude's disdain for humanity aside, the quote serves as a good reminder that the "but the criminals!" argument is often used and rarely justified.
- zimbatm 3y agoRemember they already added DRM to browsers once. There was a big outcry at the time, and they still went ahead and implemented it. Now even Firefox supports Widevine. If they believe that it's in their best interest, I'm not really sure what we can do against this...
- themerone 3y agoWho benefits from browsers not supporting EME? The choices were EME, Flash, or no premium VOD on the web.
- jcranmer 3y ago> The choices were EME, Flash, or no premium VOD on the web. Actually, it was Silverlight, not Flash. But still a plugin nonetheless.
- zimbatm 3y agoThat's the premise that the RIAA and friends was pushing. There is of course another choice; to stream the movies without DRM. Once Flash was gone, eventually they would have caved in because there is a lot of money to be made by streaming movies. This was a faustian bargain. Now that DRM is in the browser, it's going to be pushed further, as with this proposal. It forced Firefox to compromise on their values of open-source in order to stay relevant. Streaming movies are still getting copied the same day. We know from experience with the gaming and music industry that what protects the publishers is to provide a convenient platform, with reasonable prices. And of course the legal system to take down pirate websites.
- account42 3y agoAnd? Making people who can't help themselves from consuming DRM'd content jump trough hoops is much better than integrating this shit into the browser. Eventually media companies might have caved in and accepted DRM-free distribution like the music industry already has.
- hardcopy 3y agoThanks for reminding me, turned that shit off.
- karaterobot 3y ago> Exactly how the rest of the world feels about this is not necessarily relevant, though. Google owns the world's most popular web browser, the world's largest advertising network, the world's biggest search engine, the world's most popular operating system, and some of the world's most popular websites. So really, Google can do whatever it wants. On one hand, I think this is wrong, because the world is full of tech companies who thought they could do whatever they want because they're big enough. "Nobody would dare switch away from Facebook! Err, I mean Twitter. No wait, I meant Chrome!" But that's a bet, not a fact. Sometimes it works out, and sometimes everyone leaves and goes somewhere else. You think you have a moat, and you do, it's just you don't always realize it's ankle deep. On the other hand, Google can do what it wants with Chrome, because it's their product. I use Firefox, and it won't affect me. All the people who don't care about this are free to use Chrome. Likewise, anyone who wants to listen to a man in his forties tell them about why some browsers are better than others can ask me about my thoughts. Nobody has done that yet, but the offer is on the table.
- PolCPP 3y agoIsn't Mozilla's main source of revenue actually google?
- JohnFen 3y ago> I use Firefox, and it won't affect me. It will affect you a lot if websites start refusing to serve to you because you're not using an approved browser.
- pessimizer 3y agoThey don't even have to do that. In five or ten years your browser will be bitrotted and unable to read tons of webpages, since you'll be stuck on the version before Firefox completely capitulated and called the users who complained about it "childish bullies."
- thesuperbigfrog 3y agoThe use cases for the WEI proposal are pretty clear from the explainer (https://github.com/RupertBenWiser/Web-Environment-Integrity/ https://github.com/RupertBenWiser/Web-Environment-Integrity/...): Google "will be able to request a token that attests key facts about the environment their client code is running in." Google "will ultimately decide if they trust the verdict returned from the attester." "Allow" Google "to evaluate the authenticity of the device and honest representation of the software stack and the traffic from the device." I have replaced "web sites" and "web servers" in the original explainer text with "Google" for clarity of intent. Why would Google want these capabilities in web browsers? What does Google plan to do with them? What follow-on actions is Google planning? Google marketing exec: "We need to lock down web browsers so we can make more money by showing ads." "Ad blockers need to be prevented. The new WEI APIs will ensure that ad blockers aren't running, that our ads are being seen, and that no DRM is being compromised." "We also want to prevent ad fraud. With WEI we can ensure that ad clicks are legit and that people are watching the ads we show. If we can't control the operating system like we can on Chromebooks and Android phones, then we need to control the web browser with cryptographic certainty." Getting browsers to adopt and implement Web Environment Integrity is Step 1. Step 2 is where all Google web sites start requiring Web Environment Integrity to be used or they lock you out of the site. Step 3 is where all websites serving Google ads require Web Environment Integrity to be used. Step 4 Profit! Web Environment Integrity is the beginning of the further DRM-ification and enshittification of the Web.
- cobbzilla 3y ago“There is a tension between utility for anti-fraud use cases requiring deterministic verdicts and high coverage, and the risk of websites using this functionality to exclude specific attesters or non-attestable browsers. We look forward to discussion on this topic, and acknowledge the significant value-add even in the case where verdicts are not deterministically available (e.g. holdouts).” See, don’t worry, they’re thinking about you, holdout.
- userbinator 3y agoWe look forward to discussion on this topic Also known as "we'll read what the opponents say, and keep trying to poke them with convincing-sounding arguments until they surrender."
- klipklop 3y agoHopefully Apple/Safari refuses to implement this. Apple loves DRM though...
- pepe234 3y agoBut they told me that Google being the one of the largest advertising companies in the world, had no interest in handicapping ad-blockers. BTW its the same company spreading FUD over AGPL.
- danShumway 3y agoI'll add to this, notably, issues are still closed after the weekend: https://github.com/RupertBenWiser/Web-Environment-Integrity/issues/28#issuecomment-1646083436 https://github.com/RupertBenWiser/Web-Environment-Integrity/... If this proposal gets rejected it'll be because of feedback in the press that is impossible to ignore. My experience watching how Google has handled contentious issues in the past makes me personally feel that Google will not be receptive to concerns about whether this spec should exist. Google and the Chromium team are not willing to hear community feedback about the direction of the web or about what the web should be. They demand that feedback start from a position of assuming the best intentions of the spec, and start from a position of assuming that the spec is basically good and might just have additional concerns to address (https://blog.yoav.ws/posts/web_platform_change_you_do_not_like/ https://blog.yoav.ws/posts/web_platform_change_you_do_not_li...). This has been a longstanding issue with how Google approaches web standards; according to Google there's no such thing as a harmful feature and Google's approach is never wrong; it just might need refining. The refining is the only thing that Google wants to talk about. There is a predictable arc to this narrative as well. If blowback gets out of control, Google will blame that blowback on misinformation and accuse the community of operating in bad faith or fearmongering. At best, you'll get a few people from the Chromium team saying "we hear you and we need to communicate better." Note the underlying implication behind that statement that the original proposal wasn't bad, it just wasn't communicated well. People just need to do a better job of "getting involved" in the web standards process so that the Chromium team knows to address their concerns. And it just comes down to learning to be kind and "remembering the human" -- ie ignoring the structural damage that the human is capable of causing to the largest and arguably most important Open platform on the planet. There will never in any situation be an acknowledgement that the direction or intent was wrong; that's just overwhelmingly not how the Chromium team operates on any issue big or small. It's good for larger sites like Ars to cover this, and it's good for people to share thoughts on social media; the only way that users have a say over this is if the press runs with it and generates a metric ton of bad publicity for Google; and even then it's a toss-up. It comes down to what the company feels like it can ignore or dismiss with a couple of Twitter posts. And this is not just where issues like adblocking are concerned, the Chromium team has been hostile to user feedback even on more minor technical issues for a pretty long while. I was writing about this issue back in 2018 (https://danshumway.com/blog/chrome-autoplay https://danshumway.com/blog/chrome-autoplay) and it was a trend before that point as well. It stinks to go into a conversation not assuming good will from all of the parties (and it usually is wrong to do so), but the Chromium team has not earned an assumption of good will, and it's done quite a bit to squander that assumption. It's regrettably kind of a waste of time to try and engage on this stuff, it's better to just criticize on social media and hope that the press runs with it. Because that's the only thing that Google listens to.
- rpdillon 3y agoI've been thinking about this for a few days but just realized that this is a complete end run around all web scraping in general. All 'adversarial compatibility' from projects like Nitter, Teddit, Invidious, and youtube-dl go out the window. Any archive site (archive.org, archive.ph, etc.) can be blocked by sites requiring attestation. And just like the book industry was terrified of piracy and were 'rescued' by Kindle, so too will journalism outlets that can't find a business model flock to Google to save them. This is going to be rough.
- dceddia 3y agoYeah, exactly this, and on top of that, it also conveniently for Google makes it impossible or wildly expensive to build an index of the web if most of it is behind this attestation stuff.
- deleted 3y ago[deleted]
- userbinator 3y agoAny archive site (archive.org, archive.ph, etc.) can be blocked by sites requiring attestation. What will happen if such a thing actually happens is that the underground market for "trusted device" farms grows, not too different from what's currently already happening but possibly at a far larger scale. Of course, that means the financially motivated scraping services still keep going while the honest individuals wanting user-agent freedom get screwed, just like with many other forms of DRM...
- wraptile 3y agoThis has been happening already. The market is trying really hard to price out web scraping through scraper detection technologies and it's kinda working - scraping is becoming non-existent in user-space apps. It's also extremely discriminatory. Try running a single scrape with a developing country's IP and Linux, you'll be blocked at TLS step lol
- 3y ago
- skybrian 3y agoI don't know if anyone's all that interested in a possible explanation that doesn't make Google look like the bad guy, but if so, I wrote about it here: https://tildes.net/~comp/18h8/web_environment_integrity_a_google_proposal_for_general_web_drm#comment-9rh9 https://tildes.net/~comp/18h8/web_environment_integrity_a_go...
- EvanAnderson 3y agoThe proposal author (who locked the issue[0] on Github) also commented on HN and has, so far, remained silent here too: https://news.ycombinator.com/item?id=36825097 https://news.ycombinator.com/item?id=36825097 [0] https://github.com/RupertBenWiser/Web-Environment-Integrity/issues/28#issuecomment-1646083436 https://github.com/RupertBenWiser/Web-Environment-Integrity/...
- voramok 3y agoAs far as I am concerned the reputation of this Ben Wiser guy is so far down the toilet that there’s practically nothing he can do or say to recover it. Like the old joke goes “you screw a goat once…”
- urda 3y agoBoth RupertBenWiser and yoavweiss reputations are fully gone from this. Pretty much the moment they closed an issue without a single comment [1], locked the repo from everyone else, and then a much later time claiming it was "spam" is a pretty dirty tactic [2]. [1] https://github.com/RupertBenWiser/Web-Environment-Integrity/issues/112 https://github.com/RupertBenWiser/Web-Environment-Integrity/... [2] https://github.com/RupertBenWiser/Web-Environment-Integrity/issues/131#issuecomment-1647892692 https://github.com/RupertBenWiser/Web-Environment-Integrity/...
- troupo 3y agoOf course nothing happened to their reputations. Unfortunately there are very few people who care about this, or now who the people are in these proposals. A reminder: the tech lead for AMP who promptly closed all discussions critical of AMP and AMP for email, and banned people who raised the questions repeatedly is now the CTO of Vercel.
- SauciestGNU 3y agoThat explains the bad vibes I get from vercel.
- superkuh 3y agoEven if this DRM doesn't get accepted and used Google's QUIC protocol they call "HTTP/3" that they whitewashed through the IETF with MS makes it so it's impossible to establish a connection to a server unless it gets 'attestation' from a third party CA TLS corporation. It's the same thing in different clothing but everyone is cool about it for some reason. Google should've just called this HTTPS+ Everywhere and there'd be no blowback.
- no_time 3y agoCan you post the relevant part of the spec or discussion of it? This sounds wack but I'm not seeing it.
- superkuh 3y agoThe spec suggested defaults don't matter when all current HTTP/3 implementations will not let compiled software users connect to a site with a self-signed cert (or none at all). But also the spec itself is bad: "MUST" in capital letters when talking about setting up the HTTP3 endpoint and verifying the cert. https://datatracker.ietf.org/doc/rfc9114/ https://datatracker.ietf.org/doc/rfc9114/ There are compile-time flags you can use to enable it in the QUIC HTTP/3 libs you can then manually link when compiling your personal browser. But with Google/Microsoft/Apple/Mozilla browser binaries used by the public they will not be able to connect.
- nl 3y agoAre you using Chrome now? Hate to say it, you are part of the problem. Switch to anything else. I'm not a super anti-Google person. I use Gmail and Google as my search engine. But Firefox is a good browser that I use as my daily driver, and Edge, Brave, Safari and the DDG browser are other options. Switch today and start taking away Google's leverage.
- kevincox 3y agoEdge and Brave are based on Chromium. While Brave would likely block this API for a while (until too many sites require it and it would hurt their market share) they don't block most changes that Google pushes into Chrome so are still largely contributing to Google's power over the Internet. So if you really want to disrupt Google's control over the web platform the only options are really Firefox and Safari.
- nl 3y agoSee I thought about this. Google's issue if the leverage they have by having Chome used. If it is just a derivative then that lessens their leverage because the vendors of those derivative browsers do have the option of modifying Google's choices. But if you disagree, then yes, sure: use Firefox.
- kevincox 3y agoI agree that it lessens their control to use a derivative but it is still some control. I agree that these are far better than Chrome, but still less of an impact than a fully independent browser.
- nl 3y agoI think on HN there are too many people who don't switch because they are letting "perfect" be the goal rather than "improvement".
- Klonoar 3y agoSafari has far more weight here though people are loathe to admit it. Apple's market share is a direct check on Google's ability to push things through so easily. Firefox unfortunately does not have the numbers on their side nor will they seemingly risk their Google payout deal. At this point, if you're using it, you're doing it because it has specific features or extensions you want, or you believe that it's ethically the right choice and you're comfortable with the trade-offs. (I love Firefox, I just think we need to be realistic here) Edit: I will actually note, in thinking after posting this comment, that it wouldn't surprise me if Apple was actually down for this proposal. Sigh.
- javajosh 3y agoSurprising even myself, I actually like this proposal. It does two things, one which is good, and the other which is not as bad as people are saying. The good thing is to give browsers a way to attest to their inviolability to systems on the other end. This is generally useful! In particular, it opens up a huge potential for people to run what are effectively servers in their browsers - which was TBL's vision for the web in the first place. The not-as-bad-as-you-think thing is that Google (and others) will use this to disable ad-blockers. Ad blockers are fundamentally dishonest, and people who use them may feel guilty for doing so. The more honest approach is to simply not consume the media. And this, it turns out, is better for society at large. Anyone who gets paid to talk ekes out a living by hacking the algorithm, making a brand, and telling people what they want to hear. It's bad and it's a bad system that makes the world worse.
- doliveira 3y agoDo you know how rooting Android is basically useless nowadays? Most banking and government apps, at least in my country, don't work if Google didn't give the seal of approval for your system. I take it you see as good thing to bring this to the browser as well, because this somehow has to do "personal computer advocacy"? It literally cripples the users' devices.
- javajosh 3y agoI don't see the connection between Chrome attestation and Android attestation. A computer has only one operating system (in general) but many browsers. I see some value in attesting to a "pristine" browser environment to any application developer, as it removes a wide array of error modes (particularly useful if you have a weak or underfunded team). Now, if the application provider chooses not to support the alternatives, I'd argue that's on the app provider (the bank and gov apps). And again, perhaps the best thing is to NOT USE THOSE KINDS OF APPS ON A PHONE. I am very concerned that people are essentially locked out of essential services if they don't have a smartphone and a working SIM card. After all "the best way to repeal an imperfect law is to enforce it perfectly." I'm not Nostradamus; but I'm hopeful that if Google goes down this path that it will hasten the end of a wide variety of error modes in the world. Of course that may be putting a little too much faith in neoliberal capitalism, to come up with alternatives that aren't smothered in the cradle.
- 2OEH8eoCRo0 3y agoThere are conflicting "requirements" for the web it seems. We want freedom and anonymity but not too much because bots and because we want to use the web to buy things but not too little because dissidents, but not too much because pedos and terrorists...you get the idea.
- chromoblob 3y agoPlease explain how attestation by TPM works exactly, and why the device owner cannot break it.
- zac23or 3y agoWhen Google created Chrome, some people were very happy! "It's the end of Microsoft's monopoly." The monopoly has been successfully changed ... to another monopoly!
- dang 3y agoRecent and related: Web Environment Integrity API Proposal - https://news.ycombinator.com/item?id=36817305 https://news.ycombinator.com/item?id=36817305 - July 2023 (428 comments)
- userbinator 3y agoIt's great to see this getting more attention. User-agent discrimination (i.e. "go away if you're not using the latest version of Chrome") needs to become illegal. As long as I'm not overloading your service or similar, what hardware or software I use must not be restricted. The same goes for other deliberate obstacles to accessibility and interoperability --- creating a "standard" that's so complex and churned frequently enough that only Google can implement it and keep up with changes, and then spreading propaganda to encourage all sites to essentially become Chrome-only regardless of their actual utility, is something that needs to be stopped. I recommend finding everyone responsible for this and exercising your right to free speech on them. It works for politicians, and it should work on this other flavour of bastard too. Once again, Stallman was very prescient: https://www.gnu.org/philosophy/right-to-read.html https://www.gnu.org/philosophy/right-to-read.html
- TylerE 3y agoWhy shouldn't the owner/operator of a website be able to decide who to sling bits to? How is this, conceptually, any different from sites that used to block IE out of spite?
- userbinator 3y agoHow is this, conceptually, any different from sites that used to block IE out of spite? I don't agree with doing that either, but whereas things like changing UA headers/page-rewriting proxies would easily get around that sort of discrimination, this is now cryptographically secure. Governments are scared of encryption because it could be used against them. The population should've realised the same could also apply to them, because it is now actually happening.
- dhx 3y agoFor the same reasons a shop owner must sell to all customers without discriminating on ethnicity, religion, disability, etc? Would it be acceptable for a website owner to block users from Detroit (78% African Americans)[1] or block users from El Paso (82% Hispanic)[2] because the website owner claims that fraudulent ad clicking is more prevalent from those cities? Would it be acceptable to only serve web pages to people without disabilities and without a need for specialist accessibility software because it's not economically viable to consider users with disabilities? Would the poorest 10% of the population be able to access web pages and services delivered over the Internet with old hardware (all they can afford) and with limited computer literacy and limited ability to raise complaints (that are ignored anyway or responded to by an AI algorithm that doesn't care)? A website owner is still discriminating when they hide behind technology such as AI algorithms, Web Integrity APIs, etc and pretend that their use of such technology is non-discriminatory. [1] https://www.census.gov/quickfacts/fact/table/detroitcitymichigan,MI/PST045222 https://www.census.gov/quickfacts/fact/table/detroitcitymich... [2] https://www.census.gov/quickfacts/fact/table/elpasocitytexas,elpasocountytexas/PST045222 https://www.census.gov/quickfacts/fact/table/elpasocitytexas...
- Havoc 3y agoMore dystopian nonsense by the totally not evil company
- chromoblob 3y agoIf one thinks of computers as (cybernetic) extensions of brains then remote attestation is direct thought control.
- NotYourLawyer 3y agoInstall Firefox. Disregard google.
- deleted 3y ago[deleted]
- asadotzler 3y agoI've been reading HN since its birth and have been in the browser game for 25 years. HN, as a collective, shit all over Firefox and Mozilla for a decade while Google, who was never going to to anything but this, did just this. Good job.
- lolinder 3y agoThere's not necessarily a contradiction here—both companies can be completely screwed up at the same time.
- djaychela 3y agoI think the intent and scope of their failures is orders of magnitude different in terms of their impact on society and the free Internet though.
- gochi 3y agoYou mean the same browser getting paid by Google to maintain it as the default search engine? The same organization that relies on those payments as majority of income? This isn't to shit all over Mozilla, this is to highlight that browser choice is irrelevant here, this is not a "war" won by installing another program.
- 1vuio0pswjnm7 3y ago"The explainer is authored by four Googlers, including at least one person on Chrome's "Privacy Sandbox" team, which is responding to the death of tracking cookies by building a user-tracking ad platform right into the browser." Mr Amadeo does a good job succinctly explaining the explainer.
- PaulDavisThe1st 3y agoThe people involved in this concept/idea/proposal should be shamed into retirement. They should never work in the tech sector again. They should be afraid to use their names before first knowing their audience (an agricultural audience would likely be OK).
- wraptile 3y agoIt's really perplexing how people in such privilidged positions would put their name on this. Either their not as smart as they appear or somehow manipulated/corrupted.
- piva00 3y agoOne of them has been a SWE for only about 5-6 years, probably a smart person but naive enough to be the face of this proposal being pushed by some bigger fish in Google Corp that didn't want their name attached to it.
- caskstrength 3y agoI would assume they are prominently putting their names on the proposal to claim they lead this effort during performance review. After all, they are probably expecting a big payout for something like this.
- nvm0n1 3y agoNah, they just realize that the sort of rank ideological hatred they're gonna get from the sort of people posting here isn't representative of the software industry as a whole let alone the wider world. The iPhone is a bastion of remote attestation. You can't just rock up and download apps from the iPhone app store using a convenient API, it's restricted so only the iPhone itself can do it. Do Apple engineers hesitate to use their real names? No, because nobody cares and heck HN threads often fill up with praise over the fact that you can't even install apps outside the app store, let alone download apps from it and emulate them on a PC. Games consoles are fully based on remote attestation. You can't connect a PC to the Xbox or PS gaming networks because they do RA to keep you out. Do the engineers who work on games consoles have to go into hiding? No, because nobody cares. HN never discusses it because it works and lots of gamers, especially the casual ones, prefer it. Fact is that users like this tech because it solves problems that they'd otherwise have. The web lacks it and therefore has to rely on user hostile stuff like CAPTCHAs, phone codes, magic JavaScripts and social network logins which people hate, so they switch to native apps instead. And devs hate dealing with all the automated abuse they get, so that pushes them towards app-only services too.
- insanitybit 3y ago> Google's plan is that, during a webpage transaction, the web server could require you to pass an "environment attestation" test before you get any data. Sounds pretty sweet from a corp security perspective. Context Aware Access lets you do attestation at SSO time but baking device integrity further into the system would be helpful. Unfortunately, this gives a lot of power to webpages. I'm not sure it's worth the tradeoff. This seems like something better handled by an extension, but I'll have to read the spec.
- afs35mm 3y agoScraping webpages is extremely useful and this would seem to combat this. It's also extremely useful by... oh yes... Google. And I'm sure they would find a way to whitelist their scrapers to index pages, but archive.org? Oh you're SOL.
- grajmanu 3y agoThe attestation need not be done by Google or web browser owner themselves. This can be done by operating systems or any third party attestation just like a simple version of certification attestation. I think even though the intention behind the idea is good, the integrity of the company that suggested this is so doomed that we are all afraid. I think such proposals will come and need to come so that gradually these proposals will mutate into something useful
- rezonant 3y agoPractically speaking yes, the OS (and further down the TPM/enclave) will be the root of attestation. Google here is starting with Google Play Integrity (previously known as SafetyNet), which is an OS-level attestation authority. On Windows, this attestation would probably be done via TPM/Secureboot and Windows integrity APIs. That's what's scary about it, because it has the potential to make large parts of the web inaccessible unless you have a signed and sealed OS layer and browser to browse it with.
- grajmanu 3y agoI agree and I understand the damning nature of change.
- maxlin 3y agoI hope this somehow backfires so badly that EU wakes up and somehow forces them to remove widevine to restore some semblance of an open web. One can hope.
- timwaagh 3y agoIt looks like a good proposal. Botfarms are a pita for a lot of sites. Cheating in games is bad. Asking someone for their id to receive a package or content they paid for is normal in the offline world.
- heipei 3y agoWhat I've seen missing in these discussions is what happens with Headless browsers. Yes, these are used a lot for scraping, but there are also many legitimate use-cases. If the Web Integrity API is available to everyone then you can effectively no longer use Headless Chrome to browse to any of these pages, or am I missing something?
- meddlin 3y agoAnybody want a new Internet yet?
- bayindirh 3y agoThat's wrong on so many levels, I don't know even where to start. First of all I hate this "proposals" which is actually, "we implemented this in our flagship product, and kindly force it on our users, you don't have to use it, if you have a choice", stance. Then comes all the "ensuring they aren't a robot and that the browser hasn't been modified or tampered with in any unapproved ways." part. I'm using an open source browser which is not Chromium based (i.e. Firefox). I can modify and recompile the way I want it. I can use links/elinks/lynx/dillo if I want (and I use them, too). Who do you think you are, and how come dictate my software I use on my own computer? It's 90s DRM wave all over again. Constant attacks towards open software, open platforms, open protocols. It's maddening and saddening at the same time.
- grishka 3y ago> It's 90s DRM wave all over again. Except in the 90s you controlled 100% of the code running on your computer. Now there are all kinds of treacherous computing with all those "trusted" execution environments and TPMs and all the other bullshit that can't be avoided, with someone else's public keys burned into the silicon.
- judge2020 3y agoYou can still control the code running on your computer. But the websites you send http requests to don’t have to respond.
- grishka 3y agoYou can't. On most modern systems there is software that runs with privileges above your OS kernel that you can't remove or modify because it is signed with the manufacturer's key. The key is part of a "trusted" boot chain. The root of trust is usually burned into the silicon in the fuses or the initial bootloader (boot ROM). TEE on Android, for example. Intel ME on PCs, and probably TPMs also have a firmware of their own. Secure Enclave on Apple devices. There's an outstandingly good perspective on the issue in another thread: https://news.ycombinator.com/item?id=36859465 https://news.ycombinator.com/item?id=36859465
- person3 3y agoThis won't even work to solve the problem they're trying to solve. If I'm a scraper or someone that wants to drive fake ad impressions, what stops me from faking the attestation info? There's some mention in the original article about the attester validating the attestation data is signed on the client, but that just pushes the problem down the stack a bit. Someone could still spin up VMs, and just automate the scraping in a real environment that passes attestation. The author is claiming this will ensure only humans are viewing said data, but it doesn't really ensure that, it only adds a couple steps. I also find it funny that the authors point to mobile platforms as an example of how this will work well. Last time I worked with ad tech, mobile ads were flooded with fake impressions, and I highly doubt that has changed. The funny thing about players like Google is that they want to be able to tell advertisers they're doing a lot to prevent fake impressions to get them to buy ads, but they don't really want to solve the problem because it would cost them a lot of money. So they kinda play the line and develop tech like this that sounds fancy but doesn't actually stop the problem in practice.
- chromoblob 3y agoI failed to learn how this exactly works, but you're looking for the term 'remote attestation'. This aims to prove that your computer is only running the approved software by having the TPM look into the computer's memory, hash the running software and its configuration and signing the hash with a unique private key burned into the TPM that is impossible to extract without physically invading the chip.
- est 3y agoChrome should be split from Google for anti-trust reasons
- StingyJelly 3y agoThis highlights the evil of DMCA. DRM is not that big of a deal if you can freely exploit some vulnerability in you tpm / hardware attestation module, extract the keys, lobotomize the creep, visualize minimal functionality and share your research. With DMCA you're suddenly breaking the law at multiple steps of the way.
- liendolucas 3y agoI think this is one of the shittiest things I've seen so far. The thing with this is that is invisible to 98% of regular users out there. It's already hard to explain things clearly to non-tech persons as why certain policies are harmful at the privacy level. And even if they do understand you, in most cases their perception of you is as someone really paranoid about privacy, and yes they will undoubtly ask things like: "so you don't have twitter, facebook, instagram, ...". It's really hard to convince people or at least make them truly see all these dark things going on behind the scenes. Regular people won't even talk about this, they don't/won't care. As long as they still able to see the content they are requesting this is something that do not affect them, it affects the people that know the shit is going on under the hood because we understand how machiavelic a move like this is. On the other side if this somehow manages to ever see the light of the day, it's a huge opportunity for other people to come up with alternatives that effectively fight back this initiative and/or bypass it. If there's something that we do not run out of in this industry is creativity, for all sort of things, even the craziest ones, and that's something no corporation will ever be able to mitigate. Also keep in mind that no browser is going to ever be in the podium eternally. Chrome has a expiry date, we just don't know when it will expire.
- deleted 3y ago[deleted]
- BiteCode_dev 3y ago> So if you root an Android phone and get flagged by the Android Integrity API, several types of apps will just refuse to run. That's just messed up. If like saying if your car detect you have been doing maintenance yourself, you can use this particular brand of carburetor because they will refuse to work. And they want that... for the web?
- Gud 3y agoWhat is the best way to block google? I mean, everything to do with them. On your router and on your phone.
- choeger 3y agoWe need legislation that clarifies who owns a device and what consequences this ownership has. But we won't ever get it as governments and corporations feel that they should own the device. If they ever agree on a separation of ownership, it's game over. Our devices will become our biggest enemies.
- kotaKat 3y agoGood old Google forcing itself upon users like always.
- fouc 3y agoI think the wisest course of action is to boycott all chromium-based browsers. Yes it might be painful, yes you might not have your favorite extension or add-on. Suck it up. I've been exclusively using Safari for years, even after extensions were killed.
- wiz21c 3y agoDoes this relate to the TPM chips ? https://en.wikipedia.org/wiki/Trusted_Platform_Module https://en.wikipedia.org/wiki/Trusted_Platform_Module
- otabdeveloper4 3y agoGood. I never liked the "Web" in 2023 anyways, so good riddance.
- fifteen1506 3y agoI watch all my DRM on Edge just to be annoying.
- evah 3y agoThe proposed function is impossible to implement in general. More precisely, it's impossible to implement without specific hardware and operating system (you have one of a handful of choices) to the de facto standard that would develop over time if web servers came to depend on the behavior of the function. It would make the web decidedly not open.
- dreamcompiler 3y agoSo I'm already at the point where if I go to a website and that stupid Cloudflare "securing your connection" dialog pops up, I just click away. Fuck Cloudflare and their walled-garden horse. If Google does this too then I guess the "mainstream" web will become invisible to me. No great loss since it's mostly thoroughly enshittified anyway. I'm happy to move to the new un-googled "darkweb" where freedom, anonymity, and non-SEO content still prevail.
- thepaulthomson 3y agoGoogle's proposed 'Web Integrity API' raises some intriguing questions about the future of web security and user privacy. While the intent to secure the web environment and ensure user authenticity is commendable, the approach seems to echo DRM mechanisms, which have often been contentious. The proposal also brings to light the ongoing debate about device control - should users be penalized for wanting full control over their devices? This 'gatekeeping' approach could potentially stifle the open nature of the web and limit user freedom. As we move forward, it's crucial to strike a balance between security and user autonomy.
- account42 3y agoPlease test your machine learning algorithms elsewhere.
- 4oo4 3y agoFriendly reminder to don't just comment and complain, contact your antitrust authority today: US: - https://www.ftc.gov/enforcement/report-antitrust-violation https://www.ftc.gov/enforcement/report-antitrust-violation - antitrust@ftc.gov EU: - https://competition-policy.ec.europa.eu/antitrust/contact_en https://competition-policy.ec.europa.eu/antitrust/contact_en - comp-greffe-antitrust@ec.europa.eu UK: - https://www.gov.uk/guidance/tell-the-cma-about-a-competition-or-market-problem https://www.gov.uk/guidance/tell-the-cma-about-a-competition... - general.enquiries@cma.gov.uk India: - https://www.cci.gov.in/antitrust/ https://www.cci.gov.in/antitrust/ - https://www.cci.gov.in/filing/atd https://www.cci.gov.in/filing/atd Canada: - https://www.competitionbureau.gc.ca/eic/site/cb-bc.nsf/frm-eng/GH%C3%89T-7TDNA5 https://www.competitionbureau.gc.ca/eic/site/cb-bc.nsf/frm-e...
- thorio 3y agoI'm totally behind all opposition against this, as I'm massively in line with the sentiment here. However thinking about it more and more, I get the impression that it will be essential to explain the impact of this to normal people (like my mom) and that's, what I just don't succeed in so far. Without a broad support and public opinion about this, they might shockingly just be able to get this started. Apple and on-device CSAM scanning is something I have in mind about this, as s counter example. What's a simple narrative non-tech people understand about this? Should I ask ChatGPT?
- deleted 3y ago[deleted]
- deleted 3y ago[deleted]
- nintendo1889 3y agoElinks, Lynx, w3m still works. Heck, you can run Opera, Vivaldi, Firefox, and Chrome 78 on 2000 or XP with a 2023 build of KernelEx.