10 ms·
Google Chrome Proposal – Web Environment Integrity
- jauntywundrkind 3y ago> Motivation: Users often depend on websites trusting the client environment they run in. Aka corporations insist on control & want to make sure users are powerless when using the site. And Chrome is absolutely here to help the megacorp's radically progress the War On General Purpose Computing and make sure users are safe & securely tied to environments where they are powerless. There's notably absolutely no discussion or mention of what kind of checks an attestation authority might give, other than "maybe Google Play might attest for the environment" as a throwaway abstract example with no details. Any browser could do whatever they want with this spec, go as afar as they want to say, yes, this is a pristine development environment. If you open DevTools, Google will probably fail you. It appalls me to imagine how much time & mind-warping it must have taken to concoct such a banal "user motivation" statement as this. This is by the far the lowest & most sold-out passed-over bullshit I have ever seen from Chrome, who generally I actually really do trust to be doing good & who I look forward to hearing more from.
- anaganisk 3y agoMany Googlers here, hope they are more vocal when Google comes up with BS. Rather than when they post a positive blog post.
- shadowgovt 3y agoIn general, Googlers tend to be in favor of initiatives like this. You have to remember, from their point of view they are writing the web software and when a user agent is non-compliant, it gets in their way. UAs with weird quirks translate to impossible-to-reproduce bugs, so the default bias is in favor of standardization and regularity.
- prox 3y ago“who generally I actually really do trust to be doing good” These are mega corporations and you aren’t the client. They aren’t making Chrome “for you”. They are for optimizing for Advertisers.
- jauntywundrkind 3y agoI reject having only short, one dimensional views. Generally I am pro Project Fugu & pro building bigger better web. Google spends an enormous amount of effort working on specs with w3c, wicg, and other browser implementers advancing incredibly good & useful causes. They spend huge effort enhancing DevTools so everyone can work the web. Building a good & capable web is necessary for Google to survive. An open & capable web is the only sustainable viable alternative the world has seen to closed proprietary systems, which from history we can see have far more risks hazards & entailed pernicious or particular behaviors. Generally Googles effort to make the web a good viable & healthy platform aligns with my vision. That they want to do good things & make a great connected world wide web because the web's thriving helps them run their advertising business typically does not create a big conflict for me. I'm usually happy with the patronage the web receives & I dread it ever drying up, and it saddens me people are so monofocused, so selective in focusing on only on bad, and I think that perception hurts us all.
- prox 3y agoI agree to an extend that you shouldn’t focus on bad only, but as the old saying goes “so much is lost for the lack of a little more.” What my experience has taught me is that you have these 80% things that are good, but there is the one person or thing that ruins it for everyone. One person, one manager or CEO who pushes something through because he wants some gain, or one selfish move that is born out of short term profit or thinking. From climate change, to wars, to ill-willed software, history sometimes get bend by those bad decisions sometimes stemming from a comparatively small but powerful group who yield too much power. Google is for all purposes a monopoly which makes all their decisions at least suspect since they aren’t competing on the same level as a Mozilla, or name any other search engine. This is bad for any ecosystem. I wish I was still seeing the early Google that was optimistic, people focused, approachable, but that time is at least some years in the past. There are probably good people working for Google still with that ethos, but it gets overshadowed by those nagging decisions that are suspect.
- warkdarrior 3y agoHow do you, as website owner, protect your users from something like this? https://www.bleepingcomputer.com/news/security/451-pypi-packages-install-chrome-extensions-to-steal-crypto/ https://www.bleepingcomputer.com/news/security/451-pypi-pack...
- dotancohen 3y agoWhy do you, as a website owner, think that it is your responsibility to protect your users from mistyping the name of Python packages they are installing via pip?
- Asooka 3y agoYou do not, the user is responsible for the operation of their device. Most of the time this should be caught by whatever malicious software detector the user runs. Also, Chrome and Firefox very heavily guard against extensions being installed from outside of the usual way, i.e. by outside programs.
- flangola7 3y ago> You do not, the user is responsible for the operation of their device. As time goes on hand-waving the matter as "user's responsibility" is becoming a less and less acceptable answer. Hard assurances are being demanded and applied technologies are progressively patching the existing loopholes.
- deleted 3y ago[deleted]
- yjftsjthsd-h 3y agoIt's not hand-waving; it literally is not the website's responsibility.
- flangola7 3y agoOrganization executives and lawmakers are increasingly demanding that digital services be made un-hackable. Someone with an attitude and trying to shirk duty by claiming we just have to trust that all of the users will always be responsible and non-abusive all of the time, will at best be laughed and shooed out of the room. More realistically be given a final PIP. Telling your bosses "no I'm not going to do that" is a resume generating event.
- Klonoar 3y agoAKA: The shadow war on bot traffic continues humming along.
- michaelt 3y agoI'm sure it'll also detect ad blockers. You know, to ensure the 'integrity' of the 'web environment'.
- kevincox 3y agoBot traffic? Anyone using Linux will get blocked because "they can't be trusted". Only people running an "approved" operating system from a billion dollar corporation will be allowed to access. This is already what is happening with SafetyNet on Android. For now most applications don't require hardware attestation so you can pass by spoofing an old device that didn't support hardware attestation but I'm sure that will change within a decade.
- charcircuit 3y agoYou don't have to be a billion dollar corporation to become Play Protect certified. Being able to trust the security of a client can protect against many attacks and it is up to web sites to evaluate what to do with into information that a client is proven to be secure.
- bitwize 3y agoPlay Protect is different from SafetyNet. SafetyNet means the app checks to make sure you're not rooted or running a custom ROM because those are considered a security risk. If you are not running a locked-down OEM ROM, you can't run many apps including banking apps. Microsoft's Pluton on-CPU attestation technology means this is coming to PCs.
- nine_k 3y agoHaving a dedicated, locked-down device to access banks or other high-stakes services could be a good, if more expensive, solution. Keep it powered down when not needed for extra security. Idealy, it could be smaller than a smartphone, and use smartphone's or laptop's hardware for UI and networking.
- predictabl3 3y agoLots of people doom and gloom here about threats to user privacy and freedom. This is the one I'd be worried about. Thought it was annoying to not be able to use banking apps on a rooted Android? Think about how annoying it will be when you can't do much of anything, even on the Web, unless it's from a sealed, signed Apple/Google/Microsoft image-based OS... I realize the way Firefox's user share is going, it might not matter or they might feel they don't have a choice but I really, really hope Mozilla doesn't even remotely consider implementing this.
- bagacrap 3y agoDo you realize the amount of work that Google has put in over the years to provide Linux support for Google Chrome? Why would they suddenly about face on that? Wouldn't it be great if you never had to deal with another captcha?
- flangola7 3y agoI would rather have a captcha than not be able to access a service at all.
- predictabl3 3y ago> Wouldn't it be great if you never had to deal with another captcha? I run a custom build of Firefox, on a (somewhat, still-ish) niche Linux OS, with the kernel and bootloader signed by my own signing keys. What could I attest with, that will make some banking website perceive me as a trustworthy client? The second this becomes widely available, it won't mean "bypass captchas" - it will mean "can't bank unless you use up-to-date Android or latest iOS".
- wolpoli 3y agoSafari, rather than Firefox, might be only actor with the market share and motivation to drag out the implementation and adoption of this proposal.
- amadeuspagel 3y ago
- akomtu 3y agoI'm surprised the ad corps haven't forked the internet yet: special drm-ed websites accessible only via special drm-ed browsers. At least it would relieve those who want to share knowledge from the presence of those who sell addiction.
- 38 3y agoI guess you've never heard of Widevine? https://wikipedia.org/wiki/Widevine https://wikipedia.org/wiki/Widevine
- DoctorOW 3y agoThe whole point of things like this is to force the open internet to be the one to fork away. The network effect is solved by having enough money to take over an existing network.
- 20after4 3y agoIt might be time to start working on that fork.
- ranting-moth 3y agoThis will enable the fork you've been fearing.
- greyface- 3y agoAPI spec: https://rupertbenwiser.github.io/Web-Environment-Integrity/ https://rupertbenwiser.github.io/Web-Environment-Integrity/ It's morbidly amusing to see the browser referred to as a "user agent" here.
- 38 3y agonothing amusing about it, just a simple statement of fact: > A user agent is a computer program representing a person, for example, a browser in a Web context. https://developer.mozilla.org/docs/Glossary/User_agent https://developer.mozilla.org/docs/Glossary/User_agent > Examples include all common web browsers, such as Google Chrome, Mozilla Firefox, and Safari https://wikipedia.org/wiki/User_agent https://wikipedia.org/wiki/User_agent
- greyface- 3y agoI'm aware of the history of the term. It's not an accurate statement of fact if the browser isn't acting on behalf of or towards the interests of the user.
- 38 3y agoI agree with you, but in regards to Chrome, thats been the case for at least 10 years, so I'm not sure what good pointing it out now will do. that ship has sailed, and aint comin back. better would be to point people toward better options, if they exist.
- dataflow 3y agoThis probably isn't the best analogy to make the case you're trying to make. Agents in real life don't just blindly do whatever any customer asks. They actually have some standards and boundaries they have to observe, including ensuring integrity in their dealings on behalf of the customer. (To be clear I'm not endorsing the proposal, just commenting on the analogy.)
- dblohm7 3y ago
- deleted 3y ago[deleted]
- mattigames 3y agoFuck you Google, dystopian books were meant as a warning not as a play book.
- ranting-moth 3y agoPerhaps a warning to you and me. But we missed the signs because of all the free stuff they gave us. Guess what, it wasn't free and now it's time to pay up.
- ranting-moth 3y agoThe final nail in the coffin for the open internet. "Don't be evil" has really turned into "Google is evil"
- slater 3y ago?PHPSESSID - but now via JS! /s
- krono 3y agoThese things Google has been announcing will culminate in an inhuman level of oppression of our digital lives and might irreparably damage people's sense of ownership and sovereignty over their own personal electronic devices. Gluttony, greed, envy, and arrogance. This is truly sickening.
- dahwolf 3y agoThere it is, the AI scraping detector. The hints in the text are obvious: "This trust may assume that the client environment is honest about certain aspects of itself, keeps user data and intellectual property secure." The smoking gun is "intellectual property". In a conventional browsing session the website has no idea what the human user is going to do with copyright-protected information published on the website. Hence, it assumes good intent and grants open access. In the case of an AI scraper, assuming you detect it reliably, the opposite is true. Bad intent is assumed as the very point of most AI scrapers is to harvest your content with zero regard for permission, copyright or compensation. To make this work, Google outsources the legal liability of distinguishing between a human and a bot to an "attester", which might be Cloudflare. Whatever Cloudflare's practice is to make this call will of course never be transparent, but surely must involve fingerprinting and historical record keeping of your behavior. You won't have a choice and nobody is liable. Clever! Not to mention the extra new avenue created for false positives where you randomly lose all your shit and access, and nobody will explain why. Or, a new authoritarian layer that can be used for political purposes to shut down a digital life entirely. All of this coming from Google, the scraping company. I have a much simpler solution: it should be illegal to train AI on copyrighted content without permission from the copyright holder. Training AI is not the same thing as consuming information, it's a radically new use case.
- leokeba 3y agohttps://hnrankings.info/36778999/ https://hnrankings.info/36778999/ Is this HN moderation ?
- monkaiju 3y agoYeah wtf...
- 000ooo000 3y ago"The server needs to be sure that it's dealing with a client capable of showing ads.. whoops no I mean a client that is human. For safety. Yep."
- dhx 3y agoThese proposals appear to be coming from the W3C Anti-Fraud Community Group. They haven't identified even a single use case[1] of the technologies they're trying to push onto the world being misused and abused. Use cases and their naivety appear to be largely copied from the OWASP Automated Threats to Web Applications[2]. There are no use case about these technologies being used by a dystopian country. No use case about enabling anti-competitive practices from incumbent companies. Seemingly little to no care or attempts to balance the longer term strategic impacts of these technologies on society, such as loss of innovation or greater fragility due to increased centralisation/monopolisation of technology. No cost-benefit analysis or historical analysis for identified threat actors likelihood to compromise TPMs and attested operating systems to avoid these technologies (there's no shortage of Widevine L1 content out there on the Internet). No environmental impact consideration for blacklisting devices and having them all thrown into a rubbish tip too early in their lifespan. No political/sovereignty consideration to whether people around the world will accept a handful of American technology companies to be in control of everything, and whether that would push to the rest of the world to abandon American technology. The majority of the contributors to these projects appear to be tech employees of large technology companies seemingly without experience outside of this bubble. Discussions within the group at times self-identify this naivety. The group appears very hasty to propose the most drastic, impractical technical security controls with significant negative impacts such as whitelisting device hardware and software. But in the real world for e.g. banking fraud, attacks typically occur through social engineering where the group's proposed technical controls wouldn't help. There appears to be little to no attempt made to consider more effective real world security controls with fewer negative impacts, such as delaying transactions and notifying users through multiple channels to ensure users have had a chance to validate a transaction or "cool off". [1] https://github.com/antifraudcg/use-cases/blob/main/USE-CASES.md https://github.com/antifraudcg/use-cases/blob/main/USE-CASES... [2] https://owasp.org/www-project-automated-threats-to-web-applications/ https://owasp.org/www-project-automated-threats-to-web-appli...
- akyuu 3y agoOn the explainer page [1], the first use case example is to prevent ad fraud (and, presumably, ad blocking...): > Some examples of scenarios where users depend on client trust include: > Users like visiting websites that are expensive to create and maintain, but they often want or need to do it without paying directly. These websites fund themselves with ads, but the advertisers can only afford to pay for humans to see the ads, rather than robots. This creates a need for human users to prove to websites that they're human, sometimes through tasks like challenges or logins. So it's essentially Google further entrenching its tentacles in web standards in the most invasive ways with no regards towards privacy and user control. It's a shame what the W3C has degenerated into. [1] https://github.com/RupertBenWiser/Web-Environment-Integrity/blob/main/explainer.md https://github.com/RupertBenWiser/Web-Environment-Integrity/...
- no_time 3y agoThere it is. Decades of turning up the heat and boiling the frog has culminated in this proposal. From secure boot and TPMs to SafetyNet and Pluton. Even in this very thread there are people saying this is not so bad because “it will help prevent fraud” lmao.
- chii 3y agoIt's sad that "prevent fraud" is the supposed benefit, when most fraud happens via phishing and social engineering rather than a technical exploit. And yet this is the way it would be sold to the unknowing public. It's "think of the children!" way of arguing for intrusions and surveillance.
- pixxel 3y agoMany of Google’s parasites frequent this site.
- ShowalkKama 3y ago>6.1.1. Secure context only Web environment integrity MUST only be enabled in a secure context. This is to ensure that the website is not spoofed. Todo do they realize that you can use a custom certificate / patch the check routines? I don't think they quite realize what they are even suggesting.
- kevincox 3y agoYou are the one being naive. This will be a cryptographically signed stack from the TPM, to the bootloader to the OS to the browser. If you flip a single bit away from the "approved" that signature will fail.
- chii 3y agoThis is why TPM should never have been allowed. It's a way for control to be removed from the user, even tho they wholly own the physical machine!
- kevincox 3y agoI'm not sure about this. TPMs can provide valuable features such as non-bruteforcable disk encryption and other secret management and secure boot can be valuable protection for your devices. The real problem here is that this is allowing a third-party to verify what software you are running. Doing these things on my device by my choice is one thing. Having another party require that I am using a specific unmodified software stack is another.
- minton 3y ago>Owners >bewise@chromium.org >sergeyka@chromium.org
- kmeisthax 3y agoTim Berners-Lee is spinning in his grave and he's not even dead yet.
- goku12 3y agoAre you sure? He was the one who green-lighted Encrypted Media Extensions, the earlier, unfortunately successful attempt to shoehorn proprietary DRM blob into browsers.
- kmeisthax 3y agoDRM blobs were already in browsers, it's the only reason why Hollywood let streaming services have websites at all. First it was trojan-horsed through Flash Player and Silverlight, and then individual browsers all licensed or built their own solutions[0] to make "plugin-free" DRM happen. The attitude of the W3C was basically "we either kiss the ring or Hollywood forks us". So I can totally imagine Tim Berners-Lee spinning in his nonexistent grave then too. That doesn't mean he's Stallman levels of freedom-or-death. [0] AFAIK, Google bought Widevine, Apple uses FairPlay, and Mozilla originally used Adobe but now uses Chrome's Widevine library.
- deleted 3y ago[deleted]
- yukkuri 3y agohttps://github.com/RupertBenWiser/Web-Environment-Integrity/blob/main/explainer.md https://github.com/RupertBenWiser/Web-Environment-Integrity/... They got tired of getting comments from mere web users that don't want this and locked down comments :P
- kevin_faithwood 3y ago[dead]