37 ms·
Web Environment Integrity API Proposal
- cwales95 3y agoGoogle is really trying to distance themselves from their "don't be evil" days I see.
- rpastuszak 3y agoThey grow up so quickly
- wraptile 3y agoThey've probably delusioned themselves that this is not evil. They are saving the internet from small businesses going under because their ads are being blocked!
- muteor 3y agoI could imagine governments getting behind this, there are a few proposed laws that require age verification, like the online safety bill in the UK. You could easily see them adding age verification on top of this proposal.
- WaffleIronMaker 3y agoOof, GitHub issues are not accepting new responses
- toshaexists 3y agoWhat a weird dystopian world we find ourselves in. And, sadly, the despair in the comments reflecting utter defeat is very troubling. Times like this make me really miss the 90s, when the tech culture embraced open source and always found a way to outsmart the "googles" of that day. It is certainly a different time these days, however the game being played has always been the same. I wish people would completely re-envision the internet. Because, in reality, google has only captured one protocol. The web is much bigger than you all think. If you build it they will come sounds like a good philosophical statement to end this with.
- reactormonk 3y agotl;dr: DRM for websites
- PaulHoule 3y agoIt looks very similar to the “secure boot” mechanisms in Windows and other commercial client OS. Strikes me as very dangerous though on the web where there are so many paths for malware to get in and this could get in the way of plugging the holes.
- saurik 3y agoIt was also dangerous for your PC: as soon as people ceded the ability to led their parties control what we run on our devices--such as by "only firmware signed by Apple can run on my phone"--we lost this war.
- cesarb 3y ago> It was also dangerous for your PC: as soon as people ceded the ability to led their parties control what we run on our devices--such as by "only firmware signed by Apple can run on my phone"--we lost this war. If that's how "we lost this war", then it was lost before it even started. Even before Apple released their phones, it was already the case that phone firmware came only from the phone manufacturer. That is: phones come from a different lineage than PCs, and were never as open as general purpose computers ended up being.
- saurik 3y agoI mean, those were by and large fixed function devices and while phone calls are certainly a form of communication they aren't really networked devices. And... while it was technically possible to update the software on them, most people never did. There were only a scant handful of years where there even existed phones where this could matter... but now this same mentality is being applied to every new category of device--all of which acting as general computing devices--based on these precedents.
- 3y ago
- ccheney 3y agoSeems like a path to fingerprinting users for tracking purposes and a potential vector for data leaks
- wmf 3y agoThe one thing this proposal does right is trying to avoid fingerprinting.
- saurik 3y agoThis is pretty much the inevitable end-game of the web, in no small part funded by ad-based business models (as the analog gap pretty much destroys most attempts to use this stuff to do copy protection) and enabled by developers who have insisted we shove as much difficult-to-implement functionality (by which I am talking about CSS complex stuff, not powerful-but-easy-to-code APIs for OS-level access) into the browser as possible. The result: there is now effectively one dominating web browser run by an ad company who nigh unto controls the spec for the web itself and who is finally putting its foot down to decide that we are all going to be forced to either used fully-locked down devices or to prove that we are using some locked-down component of our otherwise unlocked device to see anyone's content, and they get to frame it as fighting for the user in the spec draft as users have a "need" to prove their authenticity to websites to get their free stuff. (BTW, Brave is in the same boat: they are also an ad company--despite building ad blocking stuff themselves--and their product managers routinely discuss and even quote Brendan Eich talking about this same kind of "run the browser inside of trusted computing" as their long-term solution for preventing people blocking their ads. The vicious irony: the very tech they want to use to protect them is what will be used to protect the status quo from them! The entire premise of monetizing with ads is eventually either self-defeating or the problem itself.)
- asistla 3y agoI do not see this as practical at all. To begin with, pretty much every government employee in the world has some proprietary software developed within the country for security reasons. Old, even obsolete machines. Out of date software, unlicensed/unregistered software, etc, etc. Much of this is also true of banks. This means if this is put in place as in the spec, it will affect banks and governments negatively. And as powerful as Google is, I don't think it will win over governments + banks. But again, all the above could be nonsense, and Google will gatekeep the web. It found itself as the loser in the AI race, and it knows pursuing AI during the ongoing arguments on privacy and who owns the data AI is being trained on - the next best thing is to own the playground where the AI trains. That may not be an entirely bad thing either; sad, perhaps, but as this goes on, and browsing becomes a pain, maybe this will result in people just spending less time online? That's a good outcome in my books.
- 3y ago
- TheAceOfHearts 3y agoThis seems like a step closer to killing the open web. "Sorry, you can only access this website using this specific device with a browser compiled by Big Tech, it's for your own good." Not surprising that this is all coming from Google, the world's biggest adtech company.
- akomtu 3y agoIt's the ad-tech sector of the web declaring a secession from the internet, for ads can't live under the law of the open web. The new AdWeb is going to look like appstores: websites will need to pay to the adweb owners, and users will need to use smartphones or locked down browsers. As for the open web, it will stay and continue evolving free from money making concerns.
- Aeolun 3y agoThis is already happening. It’s just mildly harder now. Try opening Teams in Firefox or Safari.
- Dalewyn 3y agoGood luck getting online banking to work outside Chrome and Edge. If you call their support line to say something isn't working, they'll ask if you're using Chrome or Edge. If you aren't, they'll tell you to just use Chrome or Edge.
- leshenka 3y agogonna be real, from now on I'll now look into web browser support of banks I intend to open an account in
- cjameskeller 3y agoI'm not sure what you mean. I used Teams on Firefox, from my Linux laptop just this week.
- circuit10 3y ago
- dmantis 3y agoThe literal attempt to censor web usage of Linux and BSD desktops, other FOSS clients, custom Android ROMs, etc with an open reasoning "to sell you ads". They don't even try to masquerade it.
- jabbany 3y agoYeah I mean the first of their examples is literally: > Users like visiting websites that are expensive to create and maintain, but they often want or need to do it without paying directly. These websites fund themselves with ads, but the advertisers can only afford to pay for humans to see the ads, rather than robots. This creates a need for human users to prove to websites that they're human, sometimes through tasks like challenges or logins. I find it quite cute that they start with "users" as if it's a user demand but in the next sentence switch to "advertisers" --- the real target population.
- Terretta 3y agoWhy stop there. Let's see who is behind the problem they're solving with item 2: Some examples of scenarios where users depend on client trust include: 1. Users like visiting websites that are expensive to create and maintain, but they often want or need to do it without paying directly. These websites fund themselves with ads, but the advertisers can only afford to pay for humans to see the ads, rather than robots. This creates a need for human users to prove to websites that they're human, sometimes through tasks like challenges or logins. 2. Users want to know they are interacting with real people on social websites but bad actors often want to promote posts with fake engagement (for example, to promote products, or make a news story seem more important). Websites can only show users what content is popular with real people if websites are able to know the difference between a trusted and untrusted environment. Not written in item two: And the people paying to promote the posts funding these sites want to know the promotions are landing on real consumers' screens.
- Buttons840 3y ago> This creates a need for human users to prove to websites that they're human, sometimes through tasks like challenges or logins. Is... is the Verification Can actually going to happen? https://i.kym-cdn.com/photos/images/original/000/983/286/ea5.png https://i.kym-cdn.com/photos/images/original/000/983/286/ea5...
- pmlnr 3y agoSoon there will be a Plaza Web, for which you'll need an approved device for, like a Chromecast with Google TV, and the Old Web of communities, enthusiasts, and the like.
- teddyh 3y agoCalled it: <https://news.ycombinator.com/item?id=31835121 https://news.ycombinator.com/item?id=31835121> <https://news.ycombinator.com/item?id=33210846 https://news.ycombinator.com/item?id=33210846>
- caesil 3y agoWhether you like it or not (and I certainly don't), you've gotta sort of admire the sheer vision of a fifteen-year project to build a browser so good it comes to monopolize the industry, all because you've had the foresight to realize that monopoly will be crucial to securing your position as the adtech hegemon. An underrated masterpiece of evil genius.
- danielvaughn 3y agoIt's like they had the same dream that IE had back in the 90's, except they actually had the patience and fortitude to see it through.
- netvarun 3y agoAnd I believe this strategy was how Sundar Pichai became CEO of Google. He oversaw the chrome project in the early days and its incredible success catapulted him up the management ladder at Google.
- kibwen 3y agoAnd tech people fell for it hook, line, and sinker. It's completely and utterly irrelevant that Chromium is open source, because the web is a protocol, and having the source for an implementation of the protocol doesn't matter in the least when you don't control the protocol. You can't just fork Chromium and remove a feature, because websites expect the feature, and your browser won't work on them. You can't just fork Chromium and add a feature, because websites don't care about your tiny fork and won't use your feature. You can't fork Chromium, you have to fork the entire web.
- zzo38computer 3y ago> You can't just fork Chromium and remove a feature, because websites expect the feature, and your browser won't work on them. You can't just fork Chromium and add a feature, because websites don't care about your tiny fork and won't use your feature. You can't fork Chromium, you have to fork the entire web. In some cases you can (although it may be difficult, because the code might be difficult too and maintaining with merging changes can make it difficult too). You can remove features you don't want, possibly adding fake features in its place or those that access other features, e.g. the microphone access to instead access a file, etc. You can add features that most people don't use even if you do use them. It can also be implemented in ways that are backward-compatible. Also, some features that are added are not features that the web pages will need to know anything about, because they are user features instead. Nevertheless, some things cannot easily be forked in this way. For example, adding a "Interpreter" header to add support for additional file formats and make it compatible even with browsers that do not support it, cannot be made compatible unless you add a request header to specify its availability too I suppose, and then just complicates it.
- ktosobcy 3y agoI'm highly annoyed by this prospect (I do love tinkering with the websites and cannot imagine using web without UserCSS, UserJS and ad block...)
- jauntywundrkind 3y agoThere's been some wishy claims maybe perhaps users-scripting & debugging will be left intact, that the intent here is about other levels. But there's basically no real actual meat to this specification. It's abstract: it doesn't really say what Web Environment Integrity is, it's up to the browser to determine, and the rules could keep getting more and more and more specific at the browsers leisure.
- lucideer 3y agoThe issues tab is a fun read - never seen a response like this on a web spec.
- leodriesch 3y agoThey seem to have closed down comments on it, I'm seeing > An owner of this repository has limited the ability to comment to users that have contributed to this repository in the past.
- josephcsible 3y agoHas there ever been a case of someone locking GitHub issues while being in the right?
- andrethegiant 3y ago> I’m giving everyone a heads up that I’m limiting comments to contributors over the weekend so that I can try to take a breath away from GitHub. I will reopen them after the weekend https://github.com/RupertBenWiser/Web-Environment-Integrity/issues/28#issuecomment-1646083436 https://github.com/RupertBenWiser/Web-Environment-Integrity/...
- Buttons840 3y agoThe firestorm will be worse by then. I predict this RFC will not allow comments.
- lucideer 3y agoDoes it disturb anyone else that this is (a) in a personal namespace & (b) reason given for closing discourse being a single individual's need to disconnect from work at the weekend, when that person is employed by a large corp to maintain this spec which they are implementing in their product? Surely Google as an org, if they're behind this, or at least a standards bodies own org namespace should both own this project, and also decision making around discourse, with any individual employees being free to leave the project un-answered outside of working hours? This isn't some open source passion project someone's doing in their off time...
- GrinningFool 3y agoThis seems like a very believable parody. Particularly given the 'spec.bs' filename which looks like it's just markdown.
- zzo38computer 3y agoI don't know what ".bs" denotes, and I cannot find anything relevant on Just Solve The File Format Problem.
- basique 3y agoMost likely https://github.com/speced/bikeshed https://github.com/speced/bikeshed
- freeone3000 3y agoFork chromium and have it return true. Problem, websites?
- progbits 3y agoIt doesn't return boolean but an attestation certificate that the server can validate before sending you any content.
- jabbany 3y agoIt's signed? Sure you can fake the results of an attestation in your fork, but your fork would be using your own key to sign the response, a key that the site can reject.
- freeone3000 3y agoAh, we’ll also have to extract the key from chrome. It’s no worse than WideVine.
- jabbany 3y agoHas that been extracted already? I have to admit I'm behind on the current state of browser DRM... Also I wonder if in the future this would require attestation of the entire chain: secure UEFI validated by key burned in CPU, validates secure boot os that prevents "hacking tools", which validates secure Chrome, which attests secure websites... Truly royally screwed at that point...
- charcircuit 3y agoThe current state of DRM is that you have to find a hardware vulnerability in order to extract a certificate. With this you can now decrypt DRM content, but you have to be careful not to get that key blacklisted.
- gray_-_wolf 3y agoThere is no key in chrome, the signing is done via a 3rd party server.
- eropple 3y agoThis is a level or two below where my knowledge of the browser trails off, so I'll ask generally: how would this interact with things like the WebKit Content Blocker API?
- wmf 3y agoMost likely all extensions and content blockers would be disabled for DRMed sites. Or maybe they'd be enabled but the browser would tell the site you have a blocker enabled and the site would refuse to load.
- jabbany 3y agoStep 1: Sites require a "secure" (read proprietary) browser like "Google Chrome", "Microsoft Edge", "Safari" or refuse to operate. Step 2: "Secure" browsers change the behavior of their implementation of the Content Blocker API so an industry-accepted "secure" site lile Google Ads can opt-out of being blocked ("You wouldn't want a misconfigured content blocker to accidentally break a verified secure site right?") Step 3: ??? (Force the users into a take it or leave it choice for whether they want to be part of the internet or not) Step 4: Profit
- madeofpalk 3y agoI don't understand how the Apple that introduced their Content Blocker APIs would choose to invest into this API to kneecap their own content blockers?
- jabbany 3y agoThey wouldn't have to. Unless you use an iDevice you're not using an Apple made browser. (The content blocker API is WebKit so it's used across multiple browsers) As for revenue from Apple users, they already want to have control over that and would be more than happy if Google and co voluntarily stopped serving their users so they can make ad money off of them on their own terms.
- wmf 3y agoI can imagine a situation where "low-quality" sites get ad blocked and "high-quality" sites get DRM.
- croes 3y agoRelated https://news.ycombinator.com/item?id=36785516 https://news.ycombinator.com/item?id=36785516
- garganzol 3y agoThe empire strikes again being driven by the insatiable greed. Just wait till its minions will fill up this thread with classical astroturfing and comments in vain of "We were waiting for this feature since forever!" and "It's for better security". I can also easily see how they massively downvote everyone who disagrees with the righteous direction of The Corporation. This is so Orwellian 1984.
- sergiomattei 3y agoProposals like this demonstrate the utter failure of our ethics education in computer science. In a field facing increasingly harder ethical questions every day, it’s important to start empowering our engineers to say “no” to ethically bankrupt things like this.
- wmf 3y agoYou might be disappointed. Ethics training can't force people with different political viewpoints to conform to yours; in fact it gives them better tools to explain their views.
- enumjorge 3y agoI don't understand why ethics in engineering has to be framed as a political discussion.
- wmf 3y agoYou can call it values if you want.
- Klonoar 3y agoI would take being disappointed over our current situation, which is effectively little to no focus on teaching the ethics at all.
- dgb23 3y agoYou mean rhetoric?
- Anvoker 3y agoI don't think any amount of ethics education will matter in the end in the face of the incentive structure that appeared in the industry. Strong cultural norms (e.g. hacker culture) might help for a while. But incentive structures eternally erode opposition. It could make it easier for developers to band together and try to collectively veto things like this. But corporations with money can always buy the expertise of people, have them undermine the community, create their own parallel communities and influence public opinion and legislators. FAANG salaries supercharge people's cognitive dissonance. They will find ways to excuse, minimize and ignore their contribution to the current situation. Even HackerNews developed a sub-subculture of people that were constantly going on threads and calling remote attestation worries as "FUD". It's unclear how to preserve cultural norms that stand in the way of market dominance. The only thing I can think of is having competing interests in the market. But whenever these align -- hell breaks loose.
- tshaddox 3y agoIt seems like a pretty clever way to propose extremely powerful DRM functionality, phrased as if it’s about trust and security.
- jabbany 3y agoIt's not even phrased like that... If you read their examples it's very clear that they're not hiding the goal of using it as DRM for advertisiers. In fact, their first example (!) outlines how this would be appealing to advertisers because they can attest a real human is viewing the content.
- rpastuszak 3y agoIt's very likely that technical (or otherwise) decision makers at ad-tech adjacent businesses are the target audience of that documentation, not us.
- charcircuit 3y agoL1 DRM for browsers already exists. This is about providing an extra layer of security to sites that may need it like banks.
- Zamicol 3y agoI can't help but see this as evil. Giving more control to corporations and less control to individuals.
- hightrix 3y agoI highly doubt it, but I wonder if this will be the straw that breaks the camels back where general perception of Google flips to where they are viewed in the same circle as Comcast or EA. Google is heading in that direction and their velocity is accelerating.
- traspler 3y agoFirst I wanted to say client trust is one of the two things I‘d really like to see improved from a security standpoint but I think it‘s the wrong way around. Browsers should establish if they feel they operate in a trustworthy enough environment and decide to not work at all if they don‘t. Having the website initiate this check is a bit strange to me. (The other thing being more MitM and DNS Hijacking protection)
- garganzol 3y agoI see one more dangerous development imposed by this move: limiting access to web content for rival search engines. I'm sure that Google Robot will pass all "high security standards" and web integrity checks, while others won't be able to do so.
- supriyo-biswas 3y agoThis is one of those times I hoped politicians were more competent in a technical field like computer science. I’d have a field day grilling the CEOs of Big Tech companies over stuff like this that only serves to kneecap their current and future competitors.
- phpnode 3y agoThe underhanded way this is being proposed is really something else. It's hosted on a non-google github to provide distance, it's worded in a way that makes it seem like this is something that benefits users, when it's the absolute opposite of that. It subverts the whole concept of a user agent. This is a huge threat to our industry and we cannot allow this to happen.
- jabbany 3y agoI agree with everything except the last part... It's not a "threat to" the industry... It literally _comes from_ the industry... Unless the tech industry is willing to lose one of its biggest sources of revenue, this is exactly what the industry wants...
- xg15 3y agoThis. As much as they'd like to pretend they're still free-spirited hippies, this is the tech industry.
- userbinator 3y agoMore precisely, Big Tech. There are lots of other smaller players in the tech industry who are against monopoly-building hostilities like this.
- quenix 3y agoWhat's strange to me is that the main author of the spec -- Ben Wiser -- seems to be against closed, wall-garden paradigms as he has written in a blog post "I just spent £700 to have my own app on my iPhone" [1]. In the post, he laments the state of the App Store monopoly on iOS and ponders returning to Android for the app installation freedom. How can he reconciliate these views with this spec, which he is the main author of? Surely Ben sees the parallels? He writes: "Apple’s strategy with this is obvious, and it clearly works, but it still greatly upsets me that I couldn’t just build an app with my linux laptop. If I want the app to persist for longer than a month, and to make it easy for friends to install, I had to pay $99 for a developer account. Come on Apple, I know you want people to use the app story but this is just a little cruel. I basically have to pay $99 a year now just to keep using my little app." It's honestly comical and a little sad. [1]: http://benwiser.com/blog/I-just-spent-%C2%A3700-to-have-my-own-app-on-my-iPhone.html http://benwiser.com/blog/I-just-spent-%C2%A3700-to-have-my-o...
- jbk 3y ago> How can this view be with this spec, which he is the main author of? Surely Ben sees the parallels? It can be reconciled with love for money and total lack of moral fiber. Aka « I don’t give a shit about my actions destroying every one, as long as I go get paid »
- rpastuszak 3y agoI think it's very easy to treat people in such a binary manner. I get it. What this guy's doing is shameful, but I've seen dozens of otherwise lovely people, working for charities, spending much more time on socially-important and useful work than 90% of the crowd here... and the same people would push barely legal (if not illegal) targeting on masses of people, arguing to push cigarette ads in markets that still allow it. Advertising is cancer and the current model is not sustainable. What I'm (poorly) trying to say is: be angry, let everyone know that you're angry, make more people angry, but remember that focusing on this guy is a distraction from a bigger systemic issue and it actually helps organisations like Alphabet.
- 3y ago
- mellosouls 3y agoRelated(?) to this recent blog by Google [1], discussed here [2] at the time as "Google to explore alternatives to robots.txt". [1] https://blog.google/technology/ai/ai-web-publisher-controls-sign-up/ https://blog.google/technology/ai/ai-web-publisher-controls-... [2] https://news.ycombinator.com/item?id=36641607 https://news.ycombinator.com/item?id=36641607
- kibwen 3y agoIt's time to break Google up. They're the AT&T and Standard Oil of our generation. Make Ads, YouTube, Search, Cloud, Chrome, etc. all independent companies. Demand that antitrust regulators do their damn jobs for a change.
- stainablesteel 3y agocounterargument: let's say the us gets in a real war with china, a massive conglomerate like google would probably make massive contributions to cyber/technological warfare that the individual pieces would have a hard time doing i agree they should be broken up, but it might be the wrong time for it.
- deleted 3y ago[deleted]
- JBiserkov 3y agoSo what you are saying is we should break up the US so they don't get in a real war with China?!
- blibble 3y agowhat are Google going to do to China? throw ads at them?
- mardifoufs 3y ago
- rpastuszak 3y agoJust a reminder that AdTech is not paying for our access to content, or supporting publishers -- it's keeping them hostage.
- drbawb 3y agoThere is one thing I'm not quite clear on here: >The attestation is a low entropy description of the device the web page is running on. >The attester will then sign a token containing the attestation and content binding (referred to as the payload) with a private key. >The attester then returns the token and signature to the web page. >The attester’s public key is available to everyone to request. I'm assuming "attester" here means "hardware authenticator." How is the attestation low entropy if it's presumably signed by a key that is unique & resident to my device? There is nothing higher entropy than a signature w/ "my" private key. That is literally saying "I [the single universal holder of the corresponding private key] signed this attestation." These days that key is realistically burned into my device at manufacturing time, and generally even if I can enroll keys on "my" device (big if), there is a very limited number of keyslots on hardware authenticators. Certainly not enough slots to present a random throwaway identity to each webpage. I don't understand how you can have public/private key crypto as the basis for attestation and also have privacy? The two seem mutually exclusive. Is the private key supposed to be shared among a large cohort? (Which seems rather unwise, as it would make the blast radius of a compromised key disastrously huge.)
- wmf 3y agoMaybe your device sends a signed attestation to the OS vendor and they generate a more generic attestation (basically "this is a legit Chrome browser running on Android but I won't tell you anything else").
- cesarb 3y ago> I'm assuming "attester" here means "hardware authenticator." How is the attestation low entropy if it's presumably signed by a key that is unique & resident to my device? From what I understood, the "attester" is a remote server, which signs the attestation with its own key, after somehow verifying that the browser and operating system and drivers and machine is not running any code that this remote server does not completely trust. That key can be used at most to identify the remote server, which is supposedly shared by a wide number of devices. Yes, this means that your browser depends on having a working connection to that remote server for every attestation it makes, and that if that remote server colludes with the web page (or is compromised), it can leak your identity.
- kykeonaut 3y agoI am not a hopeful romantic, but the EU has been investing on vendor neutral web-browsers like Nyxt [0] and the UR Browser [1] through the Horizon Europe program. I doubt that legislators (at least in the EU) will view this as a positive development, assuming EU legislators know what they are doing. On the other hand, lobbying by big tech is still very much a threat. [0] https://nyxt.atlas.engineer/ https://nyxt.atlas.engineer/ [1] https://www.ur-browser.com/ https://www.ur-browser.com/
- maxloh 3y agoThe first one is close-sourced. Why should I choose it over a open-core alternative (Chrome).
- jmercouris 3y agoNyxt is not close sourced :-)
- goku12 3y agoI assume you are referring to the UR-browser. Despite being closed source, it seems to have better privacy policy compared to Chromium. By using chromium or many of its derivatives, you are automatically lending credibility and subjecting yourself to anti-user features like these. Chromium is one of those software that I consider as open source, but not free/libre. It absolutely doesn't respect users' interests. The usual argument of "but it's open source, modify it" isn't practical either, because the code base is too massive and complicated. Despite all that, I would recommend only FOSS browsers with good privacy policy - because they exist.
- goku12 3y agoThe big problem with many of the alternative browsers like the ones you mentioned is that they are powered by the Blink engine (it's one of the 2 options for nyxt). The overwhelming market-share of Blink and the institutional monopoly on its development is the biggest driver for introduction of anti-features like these. WEI for example, is being prototyped in it [1]. These anti-features make it into every browser that uses Blink. While some browsers like UR-browser and Brave disable many of these features, they still lend credibility to the blink engine. We need to promote alternative web engines like Servo and libweb and browsers based on them. Many of these engines need a major push to be competent enough for daily use. Gecko is also fine - but building a new browser with it is said to be hard. [1] https://chromium.googlesource.com/chromium/src.git/+/refs/heads/main/third_party/blink/web_tests/wpt_internal/environment-integrity/ https://chromium.googlesource.com/chromium/src.git/+/refs/he...
- 66fm472tjy7 3y agoI am not optimistic that the de-facto end of general computation can be prevented, or that there will even be noteworthy opposition. There are so many powerful interests that stand to gain from preventing e.g. ad-blocking and content capture. Thanks to Windows 11 requiring TPM, it is just a matter of time until hardware support for remote attestation is ubiquitous even on desktop computers. Meanwhile, our (including myself) attention is (perhaps justifiably to some extent) on the latest news about $EXISTENTIAL_THREAT and how $THE_OTHER_SIDE did $EVIL_THING fed to us by the algorithm. Organizations that used to effectively fight threats to freedom like this (FSF, pirate parties, CCC, EFF, etc) have lost a lot of their support/influence and clarity of purpose over the last decade.
- dahwolf 3y agoThe chess pieces for the end-to-end unblockable ad machine are in place. You'll have the cynically named "Privacy sandbox" that builds tracking directly into the browser. You curtail ad blockers by capping browser extensions. And then you allow access only to "attested" clients. Inescapable tracking and unblockable ads. And you'll get to see ever more of them over time. If this isn't evil enough in itself, the way Google presents these initiatives in grossly misleading ways makes my blood boil. Fuck "Be as evil as possible" Google. Absolutely pathetic company. I'm so done with them.
- JeremyNT 3y agoPreviously: https://news.ycombinator.com/item?id=36800789 https://news.ycombinator.com/item?id=36800789 https://news.ycombinator.com/item?id=36785516 https://news.ycombinator.com/item?id=36785516 https://news.ycombinator.com/item?id=36800744 https://news.ycombinator.com/item?id=36800744 https://news.ycombinator.com/item?id=36808231 https://news.ycombinator.com/item?id=36808231 https://news.ycombinator.com/item?id=36791711 https://news.ycombinator.com/item?id=36791711 https://news.ycombinator.com/item?id=36789691 https://news.ycombinator.com/item?id=36789691 https://news.ycombinator.com/item?id=36816208 https://news.ycombinator.com/item?id=36816208 https://news.ycombinator.com/item?id=35862886 https://news.ycombinator.com/item?id=35862886 By the HN guidelines this is a repost, but it would be a mistake IMO to delete it. This would mark the end of the open web, but for whatever reason this issue has never really bubbled to the surface here before. It feels like something is different this time.
- benatkin 3y agoIt's an Orwellian name, but makes a certain amount of sense. That's the most effective kind of Orwellian name. Even still, I think that it is wrong to give something a convenient name that espouses some virtue. They should have chosen something like Web Environment Verification API. I think it's spyware, and I don't like it. It reminds me of the Stripe API, where you have to run some JavaScript on your site that snoops on your interactions and reports stuff to Stripe that it uses to detect fraud. https://news.ycombinator.com/item?id=22937303 https://news.ycombinator.com/item?id=22937303
- joelthelion 3y agoWill people stop using Chrome now?
- miniBill 3y agoNo, unfortunately
- snowc0de 3y agoThis isn't extreme enough. If they're going to put out a very controversial proposal like this, they may as well go all in. The push back against this is going to fizzle out, and it will be shoved through regardless of anyones opinions. Governments will love this due to protection and security it provides among other things. I wish I could say I was surprised, but Google has continued to fail to deliver even when they try for a power-grab play like this. Feature requests: - Add a distributed bad-actors list similar to DNS. - Start the process of introducing this functionality at the hardware level. - Require photo personal identification to prove humanity.
- xg15 3y agoI think "don't use Chrome" is really not the best way to fight this - instead, make it known. Get out to as many people as possible that this thing exists, spread awareness, explain the consequences, make a stink. Google is absolutely in a position to implement this and I figure a good number of sites would immediately join. However, the image of "tech" is tarnished enough already and the general population is more aware of the importance of having control about their online experience. So I'm kinda optimistic that more public awareness of this might lead to a larger backlash and might make Google think twice in continuing this, lest risking a PR disaster.
- doubt_me 3y ago[dead]
- signed_keys 3y agoPlease drink a verification can to continue.
- politelemon 3y ago> Attesters will be required to offer their service under the same conditions to any browser who wishes to use it and meets certain baseline requirements. This leads to any browser running on the given OS platform having the same access to the technology, but we still have the risks that 1) some websites might exclude some operating systems, and 2) if the platform identity of the application that requested the attestation is included, some websites might exclude some browsers. I feel this is the bit that's going to be hand waved away for the sake of convenience.
- danShumway 3y ago> and meets certain baseline requirements I also wonder what those certain baseline requirements are going to be? Weird that they're left ambiguous. It's probably nothing to worry about. We have a ton of precedent with Widevine that "it's okay, we'll license to anyone who meets requirements" wouldn't ever be abused[0]. It's fine, you just meet the baseline requirements that aren't spelled out yet and that might be subject to change and that certainly won't include headless or highly scriptable or experimental browsers. Nothing to worry about. [0]: https://blog.samuelmaddock.com/posts/google-widevine-blocked-my-browser/ https://blog.samuelmaddock.com/posts/google-widevine-blocked...
- minimaul 3y agoI fully expect the attestors to be platform vendors - Google, Apple, MS. It’ll be cryptographic chain-of-trust based, with it sending a fingerprint, probably encrypted/signed with a per device key stored in something like a TPM, to the attestor, who will say if the fingerprint is valid or not. They’ll inevitably only attest to the state of apps running under this full chain - so full secure boot, no unsigned drivers, only signed/approved apps - probably with a requirement to be installed via the platform’s App Store. No one will be attesting for Linux because there’s no chain of trust and no control over what runs. It’s a recipe for eliminating user choice and freedoms. The current spec has a holdback mechanism. It actually gets implemented, I don’t expect that holdback mechanism to actually be part of the final implementation - because it makes the whole idea useless.
- dgb23 3y agoAre they trying really hard to shoot themselves in the foot? Google needs to stop this bullshit start innovating again. First AMP, now this? Leave the web alone! Where's the Google that makes great web applications with simple, great UX, like Maps, Gmail, Drive and Search (which has severely degraded)? Or great tools like Go, Lighthouse and Devtools? Disappointing! It's like they're trying really hard to be the villain.
- thrown1212 3y agoBecause when you own the land you can just tax the serfs who do that work. Rentierism is the ultimate goal of capitalism.
- hamishwhc 3y agoHow can the “attesters” verify the integrity of the user agent? Sure the attestation is signed, but why can’t we mess with the data sent to the attester and just nullify the entire point of the proposal? The “browser acceptance criteria” in the spec, that would presumably contain this info, is just “TODO”. Thanks Google for conveniently omitting that key detail. Also interesting that its implied in the explainer that attesters are just HTTP endpoint dealing with “billion-qps” traffic. Again, point above, but also how can we trust any attester to not use the (completely unobfuscated) information the user agent is sending them? I guarantee that big websites will host their own attesters, only allow use of their attester, and require attestation for every request, allowing them to fingerprint every single user.
- andersa 3y agoYou don't send any data to the attester. It runs locally on your device, or rather is part of its core functionality. Building a chain of trust from the TPM hardware module, validating secure boot is enabled, validating the kernel and drivers have not been tampered with, eventually validating the browser has not been tampered with. You can't run your own attester - these are implemented by the companies who provide the hardware, such as Microsoft or Apple.
- maxloh 3y agoCould this be reverse engineered so that third-party browsers sent the same hash as Chrome?
- kevincox 3y agoNot without exploits. This is a cryptographically signed chain of trust from hardware to booloader to kernel to the OS to Chrome. If any of these are tampered with the signature will not validate and they won't load. If you try to run an unsigned version the layer above you will refuse to sign the attestation. The only solution is finding exploits in the chain. If at any point you get unsigned code running or manage to get a signature outside of the signed environment then you can "spoof" the attestation. But while it is a big stack it is explicitly designed to prevent this exact issue, so it won't be easy and it will be quickly patched. This is the same setup as SafetyNet on Android. SafetyNet can be worked around right now for "Basic Integrity" but this works by making your device claim to be an older device. Newer devices support hardware backed attestation for which there is no general work around. You can be sure that this proposal will be using hardware-backed attestation from the start.
- charcircuit 3y agoIf this isn't added to the web you will see things like banking websites go away and require a mobile app. Features like this keep the web relevant.
- jauntywundrkind 3y agoBanking web sites seem alive & fine & well, so unsure what you are trying to claim here.
- charcircuit 3y agoWhen P(fraud|request from browser) increases and P(fraud|request from mobile app) decreases and P(customer has mobile device) approaches 1 it starts making less and less sense to support running a web interface.
- saagarjha 3y agoA good way to drive fraud to zero is to make it so that nobody uses your service.
- charcircuit 3y agookay?
- saagarjha 3y agoThe point is that if you actually don’t offer web banking people may decide to not bank with you.
- danShumway 3y agoI don't care if the web is relevant if it's not the web anymore. Ruining a platform to keep it relevant isn't in my interest as a user. If we shoot this down and every bank requires me to download a mobile app, then fine. What this is proposing is basically to turn websites into mobile apps: device controlled, unmodifiable, broken on any non-approved hardware. If that's going to be the case regardless, I'd rather just download the app, at least that would be more honest about what's actually going on, and at least I'd still be able to use my adblocker when I browse the web.
- rad_gruchalski 3y agoOkay, the proposal is what it is but it doesn’t explain how the attestation is generated. So this would look into the underlying OS and decide if my computer is a real computer? And when it has doubts it displays some pictures and asks me which ones show bicycles?
- quickthrower2 3y agoOh by "Web Environment" you mean "my machine" lol! I already got caught by this kind of thing - a https://github.com/nativefier/nativefier https://github.com/nativefier/nativefier app wrapping Youtube Music doesn't work, because Google detects somehow that you are not using a trusted browser and refuses to serve. This is sort of moving in the "zero trust" (as in let's use ML etc. to detect if we trust something. username/password is not enough), which I fear because it will break a bunch of stuff for genuine users and make things less reliable.
- wraptile 3y agoThe thing is with existing fingerprinting you can patch against it, with this it would be very difficult.
- maxloh 3y agoDid you mirror Chrome's useragent?
- quickthrower2 3y agoThe workaround was pretend to be Firefox, which didn't work. Gave up after that as this was a passing curiosity.
- economyballoon 3y agoIs this Web4? Time to free the web again. An we thought Web3 is nonsense :(
- interjectionne 3y ago[flagged]
- danShumway 3y agoI commented similarly elsewhere (https://news.ycombinator.com/item?id=36815276 https://news.ycombinator.com/item?id=36815276) but shoutout to all the people during the Web Video DRM debate who said that DRM wasn't going to be proposed for HTML or Javascript.
- dynamorando 3y agoBring back AOL!
- keepamovin 3y agoAt DOSYAGO, we're definitely concerned about this. We see concerns of Alphabet’s Web Environment Integrity API Proposal, we see a potential threat to the very democracy of the web. The danger isn't merely about preserving the ad business model, but the potential for market monopolization by Google Chrome. Yet, the beauty of open source presents us with hope and solutions. As creators of a competing open-source browser, we're stirred by this. We're concerned about the future integrity of browsing - whether run remotely, headlessly, or semi-automated, we see all these threatened by such attestations. But we believe in the power of the collective, and the spirit of innovation that thrives in the open-source community. The conundrum is real for Alphabet, but leveraging control over such a global, ubiquitous means of access cannot be the answer. However, we don't advocate a future where Google cannot derive value from its creations. The economic balance may be hard to find, but technically, solutions will emerge. We're committed to standing up for the future of the web, because we believe in its open, democratic potential. Now, more than ever, we need you to join us in safeguarding the web's future. Come, contribute, and be part of the change. Visit https://github.com/dosyago/BrowserBoxPro https://github.com/dosyago/BrowserBoxPro today. Stand up for an open, fair, and free web.
- deleted 3y ago[deleted]
- jwally 3y agoSo basically it works like this? google watches everything I do because chrome, and has a good idea if I'm a bot or not. through clever cryptography google tells each website I visit its assessment of me? Does it also give them the same Id for me each time I visit? (But unique to them)
- jchw 3y agoI will be self-destructively opposing this until I'm dead. I have nothing else to add.
- rezonant 3y agoDeveloper Signals: Extremely Negative
- userbinator 3y agoAdd "integrity" to the list of adjectives used for obfuscating the rise of authoritarian dystopia... It all started with "trusted computing", where "trusted" means "not under the owner's control". Then they tried to spin it as a "security" thing with TPMs, and created the impression that those speaking out against them were either malicious actors or insane conspiracy theorists. Now it is actually happening. They want to control exactly what hardware and software you use, and they're doing it by ostracisation, which makes this even more sinister: you're still technically allowed to use software and hardware of your choosing, but you'll be blocked from participating. I still remember when Intel was forced to revert adding a unique serial number to its processors because of widespread outrage, so it is possible for the public to make a difference; they just need to be educated about the coming dystopia and agitated enough to care and act upon it. Perhaps we can start by spreading instructions on how to disable TPMs and "secure" boot along with all the advantages that come with doing so (custom drivers, running whatever OS you want, hardware you actually own, etc.) Of course the corporate-owned "security" lobby is going to start screaming that it's "insecure", but we need to make it clear that this is not the "security" we want because it is inherently hostile to freedom. "Those who give up freedom for security deserve neither." https://www.gnu.org/philosophy/right-to-read.html https://www.gnu.org/philosophy/right-to-read.html
- xg15 3y agoThis would be the method of last resort. I think secure boot as a technology actually has security advantages, if you can freely set the keys. That was what the tech was advertised as to console the critics, but if course it would run counter to the goal of controlling hardware if this was actually implemented consistently. I think regulation to force vendors to provide this option (and in a frictionless, actually usable manner) could do a lot here. Second is more focus on nag screens, "nudges" and other deliberately degraded UX. I.e. with the Surface tablets, you're technically able to disable secure boot, however you'll then be greeted with an ugly bright red boot screen every time you turn the device on. This stuff can have significant psychological impact, especially for "casual" users.
- atoav 3y agoThe first line > Users often depend on websites trusting the client environment they run in. is already a lie. Users don't depend on websites trusting the client environment. Users expect the client to limit the way in which they have to trust websites. Sure website owners would love to be able to trust user input, but that has little to do with the interest of the users. If something starts with that kind of framing already you certainly know that this is not going to benefit the user.
- zarzavat 3y agoThis proposal is attempted theft. The web does not belong to Google, it belongs to everybody. Who are they to suggest that users with “non-attestable” (read: not controlled by Google) user agents or operating systems should be excluded or punished? If Google wants a war, let’s give them one. Tell everyone who will listen. Give Google hell.
- joepie91_ 3y agoProbably more action than just telling people will be necessary for that.
- vbezhenar 3y agoSo basically it's a democratization of DRM. Now everyone can easily use it. I think it's a good step forward.
- c0l0 3y agoCalled it, unfortunately: https://news.ycombinator.com/item?id=30104740 https://news.ycombinator.com/item?id=30104740 The only way around the dystopia this will lead to is to constantly and relentlessly shame and harass all those involved in helping create it. The scolding in the issue tracker of that wretched "project" shall flow like a river, until the spirits of those pursuing it breaks and it is disbanded. And once the corporate hydra has regrown its head, repeat. Hopefully, enough practise makes those fighting the dystopia effective enough to one day topple over sponsoring and enabling organisations as a whole, instead of only their little initiatives leading down that path. Not a pretty thing, but necessary.
- tsujp 3y agoThis is the most disgusting thing I have ever read. My blood is boiling to the point where I genuinely don't see a bright future. Ben Wiser (Google), Borbala Benko (Google), Philipp Pfeiffenberger (Google), and Sergey Kataev (Google) have got to be the most repugnant people on the planet for pretending this is anything but a scheme to destroy all privacy and freedom on the web all so fucking Google can sell more ads.
- spacebanana7 3y agoWe need to start a community of people who interact with plain text files over encrypted protocols for business and pleasure. The more bandwidth and OS features we use the more dependent we become on the cloud/ISP vendors and device/OS makers.
- RupertWiser 3y agoProposal author here I’m hoping to get back to everyone as soon as possible. I hope you can all appreciate that I’m a human being and this has been a lot! In the mean time, I wanted to repost my last comment on the GitHub issue thread [1]: Hey all, we plan to respond to your feedback but I want to be thorough which will take time and it’s the end of a Friday for me. We wanted to give a quick TL;DR: - This is an early proposal that is subject to change based on feedback. - The primary goal is to combat user tracking by giving websites a way to maintain anti-abuse protections for their sites without resorting to invasive fingerprinting. - It’s also an explicit goal to ensure that user agents can browse the web without this proposal [2] - The proposal doesn’t involve detecting or blocking extensions, so ad-blockers and accessibility tools are out of scope. - This is not DRM - WEI does not lock down content - I’m giving everyone a heads up that I’m limiting comments to contributors over the weekend so that I can try to take a breath away from GitHub. I will reopen them after the weekend [1] https://github.com/RupertBenWiser/Web-Environment-Integrity/issues/28#issuecomment-1646083436 https://github.com/RupertBenWiser/Web-Environment-Integrity/... [2] https://github.com/RupertBenWiser/Web-Environment-Integrity/blob/main/explainer.md#goals https://github.com/RupertBenWiser/Web-Environment-Integrity/...
- dhx 3y ago> giving websites a way to maintain anti-abuse protections for their sites without resorting to invasive fingerprinting. What prevents a website from using invasive fingerprinting _AND_ WEI together? I strongly suspect websites will end up using both WEI and invasive fingerprinting because: 1. Websites will want to use invasive fingerprinting on old browsers and it would work within browsers that deliberately don't implement WEI. 2. Websites will want to get as much invasive fingerprinting information as they can get their hands on. 3. It is another layer of fingerprinting in the likely event that WEI is ineffective due to TPM exploits[1], operating system/driver exploits, web browser exploits, determined actors using rooms of computer display recording devices and robotic arm mouse movers, etc. Invasive fingerprinting further increases the cost and complexity to actors the website is trying to block. > This is not DRM - WEI does not lock down content It is absolutely 100% DRM. Your proposal states that devices would need to attest their configuration to the website. The website can then block the user because it doesn't want to show the news article to a Linux device where the user can block annoying pop-up ad videos, copy and paste the text or save the web page. The website can instead only allow devices which are factory-configured to block copy+paste, block saving web pages, block screenshots, etc. It's still DRM even with the proposed holdback mechanism because in the best case, a user will still be blocked 9/10 times (or whatever the holdback mechanism is set to). The more likely scenario is a website owner will just refuse to serve content until the client has attested itself. "The requested page can not be provided due to an unexpected problem. Try again in a few minutes." There are so many flaws with the scheme as currently proposed I feel I could write for days: Will websites be expected to block and ban users of AMD-SP now that it is broken[1]? Or will whoever conducts ad fraud just buy all the AMD-SP devices they can get their hands on? As another author replied, are Gentoo users that compile their web browsers and operating systems from scratch just ignored, and the proposal pretends it won't impact these users? How does the proposal allow users with specialist accessibility software to browse the web without being blocked for being a minority group that is not economically worth website owner's time to support? What prevents abuse of said specialist accessibility software for other purposes? How would a new start-up developing a competing browser or phone from scratch, and are very much unknown and in a minority position, be able to convince millions of website owners to unblock/allow their new browser or phone? Cloudflare's Friendly Bots program refuses to respond to open source projects, so why would Cloudflare as an implementer of WEI care about new start-ups or small open source software projects? [1] https://arxiv.org/abs/2304.14717 https://arxiv.org/abs/2304.14717
- yonatan8070 3y agoThis already exists on Android in the form of "SafetyNet", which apps can use to detect if they are running on a device that isn't "secure", like a device with a custom ROM or a rooted device
- jwally 3y ago/tinhat on Cynical outlook because I guess its where my mind wanders I guess... In the last year Puppeteer became a lot harder to detect, which creates a problem. THIS would provide a solution, no? Probably a coincidence, but a fortuitous one if creating demand for THIS feature was your goal. /tinhat off
- nfriedly 3y agoI hate to say it, but if you used Chrome to read this, then you're part of the problem. Awful stuff like this wouldn't stand a chance if Google didn't have such a monopoly position. For the sake of the open internet, please switch to a different browser. IMO, Firefox is best, but even something chromium based is probably fine. Just not Google Chrome.
- schroeding 3y agoThe idea behind this proposal is what I feared the moment remote attestation(-ability) started to gain traction on clients. Google will arguably kill legacy SafetyNet (which is circumventable, as it's not rooted in hardware) soon. Microsoft pushes extremly hard for remote attestation-ability by requiring TPMs. Very soon only an insignificant number of client devices will not be able to perform remote attestation by the major vendors based on hardware trust modules. Hard to stay optimistic for the open web. :/
- pptr 3y agoCan someone explain to me what's so fundamentally bad with this proposal? My understanding is that websites can essentially confirm whether the user is likely to be a human because he/she accesses the website from a certified device. Won't this mean there is less need for Captchas, logins and pay walls? The doc also mentions that this will remove the need for some use-cases of fingerprinting. I imagine from a user perspective this will be an improvement. Disclaimer: Googler, but not working on Chrome
- locriacyber 3y agoHTTP/3, HTTP/2, many useless JS API are pushed by Google. Is there any real alternative to the multimedia Web? Or do We need to make one now? What we need: - hypertext, links - raster and vector images - videos - responsive layout system of said hypertext (cassowary) - programs that can control the page content fully
- _8j50 3y agoWould moving control of web standards under governmental control help? The FTC and similar government orgs can take ownership and enforce standards, labeling browsers commercial utility.
- pc2g4d 3y agoI'm glad to be a paying Protonmail and Kagi user right now.
- renegat0x0 3y agoDoes that relate to web scraping? Will it be possibile at all?
- renegat0x0 3y agohttps://gabrielsieben.tech/2022/07/29/remote-assertion-is-coming-back-how-much-freedom-will-it-take/ https://gabrielsieben.tech/2022/07/29/remote-assertion-is-co...
- MrYellowP 3y agoThis isn't just Google. The whole hardware industry is moving towards the Digital Lockdown. This idea has been around, at least, since the early 2000s, but the people who were talking about it, of course, got shouted down as conspiracy theorists. And as far too often, the "conspiracy theorists" were right, but nobody cares about ever thinking about that, because nobody seems to be actually able to think about things anymore, unless the thoughts are breast-fed. We're heading towards a reality, where copypasting from a website is going to cost you money if the license requires you to do so. Looking at it, considering the status quo of technology, almost everything required for a "trusted" environment is already present in consumer-hardware. We have hypervisors, virtualization, containerization. Encryption/Decryption of data in RAM/CPU in real-time is coming eventually. Blockchain technology makes verification of digital ownership secure and easy. AI will make it stupidly easy for corporations to make sure that everyone complies and I will be everywhere within the next few years. A glimpse of this reality can be seen in NovaQuark's "Dual Universe", where everything is behind DRM. A "metaverse" company for a reason, I guess.
- Slimemaster 3y agoIf a lot of JS library's international break them selvs if the browser passes the check then it may kill Web Enviroment Integrity.
- Slimemaster 3y agoIf a lot of popular JS library's break on purpose if the browser passes the check, then any browser that passes the check is unusable.
- sadn1ck 3y ago> ... This creates a need for human users to prove to websites that they're human, sometimes through tasks like challenges or logins. No I do not? This sounds incredibly condescending as a user – I don't need to prove anything. Their example of Play Integrity API is alarming because that essentially means either use this OS and this browser which has been verified only by us or we will not allow you to use the internet (SafetyNet vibes)
- landsman 3y agoLouis strikes back! https://www.youtube.com/watch?v=0i0Ho-x7s_U https://www.youtube.com/watch?v=0i0Ho-x7s_U
- sjatkins 3y agoI will not use any browser that incorporates this. If some sites fail if it is not present then I will find work arounds to using those sites.