8 ms·
“Web Environment Integrity”: Locking Down the Web
- benatkin 3y ago"Brave's browsers" distributions of browsers, there ftfy
- theandrewbailey 3y ago"We are a fork, have been all along" https://twitter.com/BrendanEich/status/1684561924191842304 https://twitter.com/BrendanEich/status/1684561924191842304
- benatkin 3y ago> the “reskinned” claim is complete nonsense With me that's a straw man, I haven't been using the word "reskinned". The way he mentions Chromium proves my point that it's a distribution of Chromium. Chrome is a browser because Google has Chromium, and they've chosen Chrome as the name for their distribution of Chromium. But it is also a distribution of Chromium.
- BrendanEich 3y agoI wasn't talking to you when I used "reskinned". Diatomaceous_ooze used "skinned", so unless you are they, why are you replying here? If you are ooze, quibbling over my adding "re-" won't get you far. "Chromium" is not a distributable binary blob, so you're wrong in your essential claim. We don't distribute the same Chromium bits in Brave as Google does in Chrome. Chromium is open source software. We disable and nullify a lot, as the first document linked in my tweet details: https://twitter.com/BrendanEich/status/1684561924191842304 https://twitter.com/BrendanEich/status/1684561924191842304
- input_sh 3y ago...and then you click on that GitHub link and it explains that they fetch the Chromium codebase and then apply a set of patches on top of it. I wouldn't diminish that work by refering to it as just a reskin, but it's also not what I have in mind when I hear about something being forked. They don't maintain a separate Chromium codebase, nor do they refer to it as a fork anywhere on GitHub. They do refer to it as a customised Chromium, which I think is a far more accurate description: > Brave Core is a set of changes, APIs, and scripts used for customizing Chromium to make the Brave browser. I also think of Chrome as a customised Chromium, not a fork of Chromium.
- indymike 3y ago> I wouldn't diminish that work by refering to it as just a reskin, but it's also not what I have in mind when I hear about something being forked. If the goal is to maintain compatibility with what you've forked, there are not a lot of other ways to do what Brave is doing... when you do the classic fork, the code tends to diverge and compatibility decays. > I also think of Chrome as a customised Chromium, not a fork of Chromium. I've started viewing Chromium based browsers as distributions instead of forks.
- thewataccount 3y agoFWIW brave genuinely has multiple privacy patches that are useful and can't be done properly with extensions in chrome. Several of these either can't be done via a js extension to chrome, or can be detected/bypassed. Brave does them in-engine which is the better way to do it. https://github.com/brave/brave-browser/wiki/Fingerprinting-Protections https://github.com/brave/brave-browser/wiki/Fingerprinting-P...
- smoldesu 3y agoI'm sure Tom Scott wouldn't mind better personal attestation options on the Web: https://www.yahoo.com/now/prominent-youtuber-claims-brave-bat-095126650.html https://www.yahoo.com/now/prominent-youtuber-claims-brave-ba...
- mrguyorama 3y agoInteresting, I'm a fan of Tom's and agree with this take but have not known about it before now!
- jauntywundrkind 3y agoI personally think the upsides of WebBundles are huge. There's nothing that would stop the browser from being able to filter & ignore content coming from in a WebBundle, so I'm not sure what Brave's greivance is here. The adserving topic is complicated as heck, but everyone seems to acknowledge big change is necessary & Google and Firefox both have proposals to radically overhaul the system while enhancing user privacy; Brave's own primary distinguisher at this point is their BAT tokens, their own answer here. There's complicated topics here, but I see Brave following the standard pattern of trying to be a lightning rod of discontent. It's also surprising to me how almost no one has commented on Private Access Tokens shipping for Apple. Which do the same thing. Here's them bragging about being able to avoid catchpa's since the devices are all vouched for by Apple as unmodified & controlled by Apple: https://developer.apple.com/videos/play/wwdc2022/10077/ https://developer.apple.com/videos/play/wwdc2022/10077/ There was a decent submission on this recently, but not much engagement. https://www.snellman.net/blog/archive/2023-07-25-web-integrity-api-vs-private-access-tokens/ https://www.snellman.net/blog/archive/2023-07-25-web-integri... https://news.ycombinator.com/item?id=36866355 https://news.ycombinator.com/item?id=36866355 I think this is absolutely the worst shit, almost as bad as MV3 being a utterly neutered shitty hell hole version of what web extensions were. But it's notable to me that both Google didn't start this particular trend, Apple did, and more broadly - I have such a hard time picking words here - it feels like the stark polemics have been on overdrive to create a reality distortion field, where Chrome is purely bad/evil/awful/no-good everywhere. We should be upset & mad! But I feel like we're pretty far into losing our minds territory, and slipping into strokes of broadsweeping public madness.
- sircastor 3y agoI don’t mean to be an apologist here, but Google’s vs Apple’s intention seem crystal clear. Google is trying to make it impossible not to see the ads it’s selling. Apple’s intent seems to be lock down the Apple platform…? I know Apple is blatantly abusive in lots of spaces, but Chrome is a super-majority of the browsers in use. It’s an odd take to spin this into “they started it” finger pointing. The reason Chrome is getting all the hate is that Google finally realized its power, position, and needs and became self-serving. Apple is just a lesser demigod is this fight.
- skilled 3y agoHard to listen to anything from a company that constantly: 1) Doesn’t innovate on anything, social media accounts are plagued with pointing fingers at others while using a Chromium fork themselves, ignorance at its finest. 2) Has been accused of selling copyrighted data for AI training and has not made a public statement. 3) Has a history of making stupid decisions and only apologizing when a big news outlet calls them out.
- franczesko 3y agoSeems like a biased opinion. Brave and their products innovate a LOT. Browser, (good) search engine, crypto as a way to keep websites profitable, etc.
- skilled 3y ago[flagged]
- MildRant 3y agoThis might be the most "Hacker News" comment I've ever read. Whether or not I agree with the way Brave goes about their business, I'm not going to deny they are trying new things which is the definition of innovation.
- skilled 3y agoWell, neither of the things I mentioned are hard to look up. I even worded them specifically to make it easier to instantly find a source, I just happen to be away from my PC right now or I would have linked the sources myself. I have not seen any innovation from them so far, sorry to say. They are using a pre-existing browser engine, they are lawyered up and don’t respond to public callouts, and they have a history of doing dumb shit that had their CEO cave and apologise for a “mistake”. If this is opinion then I think you need to look up what that word really means…
- 3y ago
- mrguyorama 3y agoWhat is Brave going to do when the code for WEI becomes load bearing in the chromium code base? Still excuse after excuse after excuse to just not use Firefox. I literally don't care if you have to hold up your nose, there's only one actual alternative browser engine, and it's a matter of survival for anyone who doesn't want the whole internet controlled by google. It could be half as fast (it isn't) and use twice as much RAM (it doesn't) and ask for a damn nude photo of me and I'd still be using it right now. Using a google owned browser engine is like growing cavendish bananas while you know the neighbor's farm has the blight already. Change over and try to get good at the new strain while you have a choice, because soon you won't and it will be out of your hands what happens after that.
- pkulak 3y agoThe excuse is always that Gecko is harder to integrate... but at what point is maintaining all these patches harder?
- MrAlex94 3y agoI’ve been maintaining a “soft” fork now for about 12 years now, most of that time on my own. It’s actually possible to get quite involved and do some cool stuff with the changes you make, while keeping up to date; with the resources the size of a company like Brave have, it’d be incredibly straightforward to actually use your own browser logic, with a bit of good engineering. (To all intents and purposes, using Gecko as the engine and your own browser features on top of that, separate to Firefox itself). I’ve started myself in the past, and am picking that back up again. But by all means it’s quite possible.
- Melatonic 3y agoHonestly modern Firefox works better than Chrome for me at everything - better memory management - faster loading times - better extension support.
- TacticalCoder 3y agoOn Linux the one area where I feel (nothing scientific) that Chrome is faster is for JavaScript code execution. But I still use Firefox instead of Chrome.
- saurik 3y agoIt's nice that they are changing their marketing on this a bit now that there is a wave to ride and the evils of DRM are coming for them; but, let's not forgot that, at the end of the day, Brave is just another company that makes money on ads :(, and (thereby) has most of the same anti-user incentives. So, sure... they clearly don't want to be prevented from blocking other peoples' ads (a big part of their pitch); but, blocking their ads while still getting paid--which is, of course, extremely easy to pull off on an unrestricted computer--is an existential threat to their only actual revenue stream which they want to protect against. The ramification: Brave's product managers--and even Brendan Eich himself (whom all of the later quotes I have in this comment were taken from, directly or indirectly)--have often talked about using the very same remote attestation technology to protect their SDK and even their browser for the same reasons as Google. https://www.reddit.com/r/BATProject/comments/bw6sek/ https://www.reddit.com/r/BATProject/comments/bw6sek/ https://www.reddit.com/r/BATProject/comments/b7rwbx/ https://www.reddit.com/r/BATProject/comments/b7rwbx/ > 1/ native C++/Rust code, no JS tags on page that have zero integrity. That means ability to use SGX/TrustZone to check integrity and develop private user score from all sensor inputs in the enclave; ... > We already have to deal w/ fraud. That is inherent in any system with users and revenue shares or grants. We do it better via C++ and (under way) SGX or TrustZone integrity checking + OS sensor APIs, vs today’s antifraud scripts that are routinely fooled. > What Brave offers that's far better than today's joke of an antifraud system for ads is as follows: 1/ integrity-checked open source native code, which cannot be fooled by other JS on page; ... (1) requires SGX or ARM equivalent, widespread on mobile. https://www.reddit.com/r/BATProject/comments/ https://www.reddit.com/r/BATProject/comments/ https://www.reddit.com/r/BATProject/comments/97trex/comment/e4axu6h/?context=1 https://www.reddit.com/r/BATProject/comments/97trex/comment/... > Part of the roadmap (details in update) is a BAT SDK. Obviously it would be open source, but more: we would require Secure Remote Attestation (Intel SGX broken but ARM TrustZone as used by Trustonic may be ok) to prove integrity of the SDK code in app.
- mminer237 3y agoBlocking Brave's ads is literally three clicks. I don't care if I don't get paid if I block ads. What I don't want is to lose the ability to block ads or to allow websites to block me for using an unapproved system. Google seems to be working for both of those things while I don't see any chance Brave ever allows either.
- happytiger 3y agoThe faster we can build usable decentralized apps and get users onto them, the better. It should only lend urgency to leave the “old web” for those of us who are builders, makers and evangelizers. They’re after encryption, they’re attacking anonymity, they want all of finance for themselves, and they want to kill privacy too -- I for one say NO thank you. There is a level — almost a treble —- in these comments on how “it’s inevitable” or “already cooked” but only if you see these fights in isolation. It most assuredly it is not inevitable. Let’s get positively focused and make hay while the sun shines and it’s not too late. There’s so much intelligence, compassion and love for humanity in this community. Let’s use it.
- smoldesu 3y ago> in these comments on how “it’s inevitable” or “already cooked” but only if you see these fights in isolation. It is, in fact, over. Commodity hardware has no "escape hatch" anymore. If you want to, say, implement custom encryption or ensure anonymity/financial independence for yourself, you cannot stop the Powers That Be. You are helpless to resist Apple or Google or Microsoft if they tell you "no". The fight was lost when we decided that we didn't need computing rights. The rest, as they say, is history.
- renegat0x0 3y agoBrowsing these days is like going into jungle. I use Adblock, ghostery, noscript, pihole. To have a good experience you cannot go in unprepared. Some pages require some scripts to be running. Then I will not go in. I think it will be the same with WEI. If a page asks me for it, I will not go in. Sorry, but no. It may be harder over time, but if I cant't change the world, I van browse on my own terms. There needs to be extension that will be blocking WEI. We need a list od pages that supports it and we need to same the for their support of WEI
- gmerc 3y agoTurning the browser into a foreign entity on your own PC. From the company that went from “Making the worlds knowledge accessible’ to ‘rentseeking on the collected knowledge and the trying to lock everyone else out from it’