23 ms·
Unpacking Google’s Web Environment Integrity specification
- troupo 3y agoWhy use quotes for "dangerous" when the first sentence is literally: "Why Vivaldi browser thinks Google’s new proposal, the Web-Environment-Integrity spec, is a major threat to the open web and should be pushed back."
- gunapologist99 3y ago@dang, is it possible to get the title corrected?
- endisneigh 3y agoHow exactly is WEI any worse than say a peep-hole on a door? At the end of the day bots are a huge problem and it's only getting worse. What's the alternative solution? You need to know who you're dealing with, both in life and clearly on the web. I'm probably alone in this, but WEI is a good thing. Anyone who's run a site knows the headache around bots. Sites that don't care about bots can simply not use WEI. Of course, we know they will use it, because bots are a headache. Millions of engineer hours are wasted yearly on bot nonsense. With the improvements in AI this was inevitable anyway. Anyone who thinks otherwise is delusional. Reap what you sow and what not. edit: removing ssl comparison since it's not really my point to begin with
- JohnFen 3y agoSSL doesn't demand that some third party approve your software and hardware in order for it to work for you.
- endisneigh 3y agoTPMs with attestation do exactly that. Are you opposed to that as well?
- lxgr 3y agoSeems like a strange way to make a point to start out with SSL and then shift the argument to TPM/attestation...
- JohnFen 3y agoYes, I have been opposed to TPM since the start.
- endisneigh 3y agoWhat's your solution then to the problem TPMs solve?
- JohnFen 3y agoThat depends on which problem you're talking about. But this is not the issue at hand.
- mindslight 3y agoWhat do you get from blasting this thread with a bunch of naive one liners that you could answer yourself if you studied the topic on your own for a little bit? The answer to this one is that the fundamental problem that current TPMs aim to "solve" is that of allowing corporate control and inspection of end users' computers. To continue having a free society where individuals have some autonomy over the devices they purportedly own, this needs to be soundly rejected.
- wbobeirne 3y ago> Can we just refuse to implement it? > Unfortunately, it’s not that simple this time. Any browser choosing not to implement this would not be trusted and any website choosing to use this API could therefore reject users from those browsers. Google also has ways to drive adoptions by websites themselves. This is true of any contentious browser feature. Choosing not to implement it means your users will sometimes be presented with a worse UX if a website's developers decide to require that feature. But as a software creator, it's up to you to determine what is best for your customers. If your only hope of not going along with this is having the EU come in and slapping Google's wrist, I'm concerned that you aren't willing to take a hard stance on your own.
- gunapologist99 3y ago> If your only hope of not going along with this is having the EU come in and slapping Google's wrist, I'm concerned that you aren't willing to take a hard stance on your own. This is indeed concerning. I'd like to see Brave's response to this, and we already know how Firefox has responded.
- lxgr 3y agoWhat sets WEI apart is that it, in a way, exerts power over your choice on how to implement other web features, for example whether you're allowed to block elements, or even just show a developer console. Other than Encrypted Media Extensions (and these are much more constrained than WEI!), I don't know of any other web standard that does that.
- wbobeirne 3y agoWhile it's a much lesser offense, many APIs are only available in "Secure Contexts", so it's not entirely a new concept https://webidl.spec.whatwg.org/#SecureContext https://webidl.spec.whatwg.org/#SecureContext
- lxgr 3y agoGetting a secure context costs $0 and takes no effort in many common webservers at this point. I do remember the controversy at the time of everybody shifting to HTTPS only, though, and how it might exclude small/hobbyist sites. Fortunately, we've found ways to mitigate that friction in the end. I'm much less optimistic here.
- jfoutz 3y agoThis kinda seems like a fantastic way to implement micro payments. The site owner sets up a attestor that knows they’ve paid. I hate Wei in general, but it really could open up control over bots and paid access.
- wbobeirne 3y agoThere is no reason that can't be done with existing web technology, WEI does not advance that use case in any meaningful way.
- jfoutz 3y agoIt provides a uniform service for ensuring a client has desired properties. That’s kinda tricky to do well. Traffic for monitoring, you can do with a jwt, but like, enabling chunked transfer in python request lib is a problem you discover. An array of attestors could guarantee feature sets.
- wbobeirne 3y agoI'm not understanding how giving the client a token that you put in a request header that proves you've paid, or is just an account lookup token to then ask a payment processor whether or not their account is in good standing, is limited in a way that WEI makes better. I don't see any use cases that wouldn't work that way that would now work with WEI.
- nobody9999 3y ago>It provides a uniform service for ensuring a client has desired properties. I see that as a downside, not a benefit -- who decides whether or not a client (i.e., my software running on my hardware) has those "desired properties" and what might those properties be?
- danShumway 3y ago> for ensuring a client has desired properties. There's nothing about payments that requires testing client properties though. What you want is the ability to test if there's a corresponding payment, that has nothing really to do with the client's device. It just seems like irrelevant information, what are these "desired properties"? You want a corresponding token with the request that matches a payment. And WEI seems like a strictly inferior way to get that instead of just... asking a payment provider for the token. What does my hardware/OS/browser have to do with a payment token?
- haburka 3y agoVery controversial take but I think this benefits the vast majority of users by allowing them to bypass captchas. I’m assuming that people would use this API to avoid showing real users captchas, not completely prevent them from browsing the web. Unfortunately people who have rooted phones, who use nonstandard browsers are not more than 1% of users. It’s important that they exist, but the web is a massive platform. We can not let a tyranny of 1% of users steer the ship. The vast majority of users would benefit from this, if it really works. However i could see that this tool would be abused by certain websites and prevent users from logging in if on a non standard browser, especially banks. Unfortunate but overall beneficial to the masses. Edit: Apparently 5% of the time it intentionally omits the result so it can’t be used to block clients. Very reasonable solution.
- JohnFen 3y ago> I think this benefits the vast majority of users by allowing them to bypass captchas. I don't think it does that. Nothing about this reduces the problem that captchas are attempting to solve. > i could see that this tool would be abused by certain websites and prevent users from logging in if on a non standard browser, especially banks. That's not abusing this tool. That's the very thing that this is intended to allow.
- deleted 3y ago[deleted]
- ec109685 3y agoThe explicit goals are thus: * Allow web servers to evaluate the authenticity of the device and honest representation of the software stack and the traffic from the device. * Offer an adversarially robust and long-term sustainable anti-abuse solution. * Don't enable new cross-site user tracking capabilities through attestation. Continue to allow web browsers to browse the Web without attestation. From: https://github.com/RupertBenWiser/Web-Environment-Integrity/blob/main/explainer.md#goals https://github.com/RupertBenWiser/Web-Environment-Integrity/... If it actually won't do any of those things, then that should be debated first.
- butz 3y agoHow about adding a fair rule to standard, that attester cannot attest their own products? I wonder how long would it take for Microsoft or Apple to attest google.com as trustworthy website?
- pptr 3y agoThe attestation is about the device, not the website. I think just from a security perspective it makes most sense for the device or os manufacturer to handle attestation for that device.
- thyrox 3y agoIt's the insane power that companies like Google, Microsoft, and Apple hold over the tech world. It's like they can just dictate everything to suit their own interests, and it's the users who end up losing out. Remember when Apple killed Flash? I heard it was because they wanted people to use their app store more instead of us playing games in the browser, so they could make more money. And Microsoft installing IE and setting it as the default browser? And now, Google is making changes to how we browse the web and adding things like Manifest v3, to boost their ad business. The most irritating part is it is always gets packaged as being for our safety. The sad thing is I've often seen people even drink this user safety kool-aid, especially with Apple (like restricting browser choices on mobile - not sure if it's changed now). I really think there should be some laws in place to prevent this kind of behavior. It's not fair to us, the users and we can't just rely on the EU to do it all the time.
- deleted 3y ago[deleted]
- baby_souffle 3y ago> Remember when Apple killed Flash? Yes. Every SECOPS person let out a collective sigh of relief when the weekly p0 patches for flash stopped coming. Apple may have been trying to push towards 'native' apps but that was almost certainly secondary; safari was leading the way on html5 APIs. Let's not pretend that the death of Flash was a tragedy.
- raspyberr 3y agoIt was a tragedy for creativity. But that's often the last item on peoples' lists.
- downWidOutaFite 3y agoSecurity people hate features and creativity. There is never any tradeoff allowed. It's always more lockdown, more power for them over you.
- deleted 3y ago[deleted]
- MarkusWandel 3y ago"This website is not compatible with your device" I can see this show up on Youtube (why not - under Google's control, and they want you to watch the ads on their official browser) and on banking apps. Initially. In the longer run, it either withers and dies, or it leads to antitrust action. I really can't see another way.
- deleted 3y ago[deleted]
- yonatan8070 3y agoThis will probably be implemented by every streaming service very quickly to try to prevent piracy (which won't work), and will only end up harming people who just want to watch on more freedom-respecting browsers or operating systems
- Liquix 3y agog**gle and other PRISM partners do not want any users on freedom-respecting browsers/OSes. forcing people onto chromium based browsers isn't an unfortunate side effect, it's a secondary goal of the specification.
- snvzz 3y agoIt's already not possible to login to Twitch on Linux. It rejects Firefox and Chrome outright. The solution is to use either browser on Wine, then copy the session cookies over.
- Buttons840 3y agoI think you're wrong because I stream on Twitch using Linux.
- snvzz 3y agoWhen did you last login to the website? Sessions last months, if not years. I recommend not logging out, as you'd then be affected by this.
- Pannoniae 3y agoThere is zero point debating this in technical detail because the proposal itself is evil. Don't get distracted by tone policing and how they scream you must be civil and whatnot. Our best hope is kicking up a huge fuss so legislators and media will notice, so Google will be under pressure. It won't make them cancel the feature but don't forget to remember that they aren't above anti-trust law. There is a significant chance that some competition authority will step in if the issue doesn't die down. Our job is to make sure it won't be forgotten really quickly.
- rezonant 3y agoYes, we need to protest. And I don't mean protest by slamming Google's github repositories with comments. That's not a protest. Go tell the media. Go tell your elected officials. I also think web developers getting together like we did with SOPA/PIPA and raising awareness on our web properties can also help. How do we organize that?
- Pannoniae 3y agoThere are some ways ranging from mellow to outright cuntish. These can be applied to websites or social media profiles (depending on the method): - Display a small text or a link to raise awareness about WEI - Display a "Works best with Firefox, a browser which respects you and your privacy" banner in a similar way to the chrome nagging popups. - Display a fullscreen modal (just like the SOPA/PIPA ones) with a detailed write-up of the problem - Subtly degrade the website's experience on chromium (just check window.chrome) - Outright block chromium, and explain why.
- _7tgr 3y agoBlocking Chromium altogether isn't as big of a deal as it seems, either (unless you're a truly huge website). It's so easy to switch to Firefox these days. Probably takes a few minutes. For technical blogs with useful content on them I suspect people's desire to see the content will override the inertia of switching browsers.
- rcxdude 3y agoThis is especially rich coming from google's, who's 'safetynet' for android results in a significant reduction in security (contrary to its stated purpose): it locks out 3rd-party up-to-date and secure ROMs while allowing horrificly insecure manufacturer-provided ROMs to still pass, because to disable those would cause a massive user outcry. So it functions as a vendor lock-in but no meaningful increase in security for the average user, while preventing more advanced users from improving their security without needing to buy more hardware. This needs to be called out more to push back against the claim that this kind of attestation somehow has a legitimate benefit for the users.
- rezonant 3y agoFantastic point.
- StingyJelly 3y agoExactly! Ironically it's a possible reduction in security on custom roms as well if one chooses to bypass it, which is trivial, but requires rooting the device.
- lern_too_spel 3y agoYou're using it wrong. SafetyNet is able to assert that the build the device asserts is what it claims. After you know that, it's up to you to decide whether you trust communications from that build or not. If it's a known-insecure build, you can say that you don't. SafetyNet cannot assert that a third party ROM is what it claims to be, so you have to decide whether you trust communications from that device or not based on not knowing at all what build is on the device.
- realusername 3y agoThen you are back to square one pretty much since the safetynet result doesn't tell you anything about the security of the device.
- wmf 3y agoDoes anyone use SafetyNet "right"? I assume not due to the user outcry issue.
- ForHackernews 3y agoThe only way to oppose this is via regulators and antitrust legislation. You will not beat the Googlers in the marketplace or with some clever technical argument.
- bloopernova 3y agoWould this end up breaking curl, or any other tool that accesses https?
- fooyc 3y agoYes it will
- pdanpdan 3y agoHow?
- toyg 3y agoThe whole point of WEI is that the site can choose to block any combination of browser and OS they see fit, in a reliable way (currently, browsers can freely lie). CURL and friends will almost immediately be branded as bots and banned - that's the stated objective.
- pdanpdan 3y agoHow? The page must first load, then it requests an attestation using js and sends it back to the server for further use (like a recaptcha token). So for something like curl it could be no change. https://github.com/RupertBenWiser/Web-Environment-Integrity/blob/main/explainer.md#how-it-works https://github.com/RupertBenWiser/Web-Environment-Integrity/...
- snvzz 3y agoIt is more severe than that. The design favors a whitelist approach: Only browsers that can get the attestation from a "trusted source" are allowed. Browsers that cannot, don't.
- collaborative 3y agoIt will, but curl and others will likely simply be upgraded with a puppeteer of sorts that plugs into your chrome runtime. So this will have prevented nothing (except force not technical users to adopt chrome and thus kill all new browser incumbents, offering the chance to force feed even more google ads)
- indymike 3y agoThird part attestation is a show stopper for openness. I'm not a fan, and this does not solve any problems I face with the software make or that my users have accessing it.
- bee_rider 3y agoAs noted in the article, Google comes up with a scheme like this every couple months. They also can’t seem to identify good sites anymore, based on their search results. So… fuck it. Let them DRM their part of the internet. It is mostly shit nowadays anyway. They can index Reddit, X, and a bunch of sites that are GPT SEO trash. We’re never getting 201X internet back anyway, so let Google and friends do their thing and everybody who doesn’t want anything to do with it can go back to the 200X internet. It was kind of disorganized but it it better than fighting them on DRM over an over again.
- lambic 3y agoWhat are 200X and 201X internets?
- zls 3y agodecades :) If we had known how fleeting the glory of the early 2010s internet would be, with everything ad-free and seo still comparatively rudimentary, would that have made it easier or harder to watch it die?
- nfw2 3y agoEverything was free because interest rates were nothing, and every startup could use investor capital to cover their costs
- lambic 3y agoAnd everything was simpler, you could throw something up on a $10/month shared host. Now you need a full stack of services running in the cloud charged by the minute.
- deleted 3y ago[deleted]
- bee_rider 3y agoAs the other comment said, the decades. I could have used 2010’s I guess, it is just hard to refer to the first decade of the millennium that way.
- dang 3y agoI think these are the related threads to date—have I missed any? Google is already pushing WEI into Chromium - https://news.ycombinator.com/item?id=36876301 https://news.ycombinator.com/item?id=36876301 - July 2023 (705 comments) Google engineers want to make ad-blocking (near) impossible - https://news.ycombinator.com/item?id=36875226 https://news.ycombinator.com/item?id=36875226 - July 2023 (439 comments) Google vs. the Open Web - https://news.ycombinator.com/item?id=36875164 https://news.ycombinator.com/item?id=36875164 - July 2023 (161 comments) Apple already shipped attestation on the web, and we barely noticed - https://news.ycombinator.com/item?id=36862494 https://news.ycombinator.com/item?id=36862494 - July 2023 (413 comments) Google’s nightmare “Web Integrity API” wants a DRM gatekeeper for the web - https://news.ycombinator.com/item?id=36854114 https://news.ycombinator.com/item?id=36854114 - July 2023 (447 comments) Web Environment Integrity API Proposal - https://news.ycombinator.com/item?id=36817305 https://news.ycombinator.com/item?id=36817305 - July 2023 (437 comments) Web Environment Integrity Explainer - https://news.ycombinator.com/item?id=36785516 https://news.ycombinator.com/item?id=36785516 - July 2023 (44 comments) Google Chrome Proposal – Web Environment Integrity - https://news.ycombinator.com/item?id=36778999 https://news.ycombinator.com/item?id=36778999 - July 2023 (93 comments) Web Environment Integrity – Google locking down on browsers - https://news.ycombinator.com/item?id=35864471 https://news.ycombinator.com/item?id=35864471 - May 2023 (1 comment)
- benatkin 3y agoI had one but it got flagged, ah well: - “I don't know why this enrages folks so much.” Googler re Chrome anti-feature https://news.ycombinator.com/item?id=36868888 https://news.ycombinator.com/item?id=36868888 I think that just meant some users with sufficient karma flagged it, but I was a bit confused because for a while it didn't say "[flagged]" but didn't show up in the first several pages or continue to get upvotes. Is there a delay in saying "[flagged]"?
- dang 3y agoThe [flagged] marker only shows up after flags exceed a certain threshold, but flags can affect a post's ranking before that.
- oidar 3y agoI wonder if this will prod the Ladybird development team to make binaries available for non-savvy end users. Having an additional open-source browser would help. I also wonder how Orion is handling this.
- deleted 3y ago[deleted]
- guy98238710 3y ago> It is also interesting to note that the first use case listed is about ensuring that interactions with ads are genuine. That's just the beginning. Attestation will eventually allow advertisers to demand that user is present and looking at the screen like in Black Mirror episode Fifteen Million Merits.
- userbinator 3y ago...and then you get to the verification can...
- Frotag 3y agoOn android, some video ads will even pause if you pull down the notification bar.
- kevin_thibedeau 3y agoCan't wait till we've added another turtle to the stack with a full browser engine implemented in WASM running in a host browser that is mandatory for all media sites.
- erklik 3y agoSony already owns a patent on that exact scenario from Black Mirror. https://www.creativebloq.com/sony-tv-patent https://www.creativebloq.com/sony-tv-patent > In it, TV viewers are only able to skip an advert by shouting the name of the brand. Yep, crying 'McDonald's!' is the only way to make the Big Mac disappear. Companies will do the most insane, terrible things if not stopped. This will happen.
- icecream_so_gud 3y agoNot sure that it is in Sony's case. But creating patents for anti-user ideas, where you don't intend on using them, locks the idea away for at least a while, and could be seen as pro-user.
- swayvil 3y agoWhy does everything need to be secure now? I can understand shopping. And reporters of hot news. But why everything? Why does my http site, which has nothing important on it at all, get flagged by chrome as "insecure"? This strikes me as a bunch of bs.
- nobody9999 3y ago>Why does everything need to be secure now? >I can understand shopping. And reporters of hot news. But why everything? So Google can capture more ad revenue by refusing to "attest" clients who run ad blockers? And so other attestors can dictate the "approved" software that can be used. What could go wrong? /s
- RodgerTheGreat 3y agoThe usual argument is that vanilla HTTP makes it possible for a man-in-the-middle (your ISP, presumably?) to tamper with data payloads before they're delivered. Requiring HTTPS means you require clients to have up-to-date TLS certificates and implementations. This provides a ratchet that slowly makes it harder and harder to use old computers and old software to access the web. Forced obsolescence and churn is highly desirable for anybody who controls the new standards, including Google.
- Vecr 3y agoYou can run TLS stacks that work with modern websites on old devices, it's just not really that secure, see https://www.dialup.net/wingpt/tls.html https://www.dialup.net/wingpt/tls.html for running "Modern TLS/SSL on 16-bit Windows"
- Vecr 3y agoIt's insecure because someone on path (or actually off-path but harder) could replace the contents of your website with whatever they want, including taking payments "on your behalf" and then just pocketing them. The main original point of HTTPS, and why I assume it does not use starttls or similar, is so people in the late 1990s and early 2000s could figure out what websites they were allowed to put their credit card numbers into.
- rolph 3y agothis abuse of tech, potentially goes beyond antitrust, and damages global economic wellbeing, as well as impoverishing information systems on global scale, generating isolation, ignorance, division, and radicalization. How to Email to the President and Members of Congress https://www.whitehouse.gov/contact/ https://www.whitehouse.gov/contact/ https://www.facebook.com/joebiden/ https://www.facebook.com/joebiden/ https://twitter.com/JoeBiden https://twitter.com/JoeBiden Write a Letter The online form is the fastest way to send a message, but if you prefer to write or type a letter, keep the following in mind: Use 8 1/2 by 11-inch paper Either type your message or handwrite it as neatly as possible Include your return address on both the letter and the envelope Mail the letter to The White House, 1600 Pennsylvania Avenue NW, Washington, DC 20500 Include the appropriate postage (stamp) If you have any additional questions about how to email Joe Biden or Kamala Harris, please post a comment below. If you are still trying to email Donald Trump or Mike Pence, please post a comment below. Contact the White House By Phone Even though you can’t email the President, you can call the White House. However, to be clear, you will likely only speak with a staff member. To call, use the following phone numbers: For general comments, call 202-456-1111 To reach the switchboard, call 202-456-1414 For TTY/TTD, use Comments: 202-456-6213 or the Visitor’s Office: 202-456-2121 It is highly unlikely that you will get to speak with any sitting POTUS directly on the phone. How to Send an E-mail Your House Representative To find your representative, search the House of Representatives database by zip code. As an alternative, visit the Representative’s personal website. Most government websites have email and mailing addresses listed on the Contacts page. Many websites also offer a contact form, but we recommend using this only as a last resort. Many online contact forms go to the website maintenance team and often don’t reach the representative or their staff. If you want a response, send a direct email or a letter. How to Send an E-mail to Your Senator To find your state Senator(s), select your Senator from the state-by-state list on the United States Senate’s Web site. Note the list is in alphabetical order and provides the following information for each senator: Senator’s full name Political party affiliation and state they represent Mailing address Phone number Link to an email contact form, usually on the Senator’s website. Also, you can call the United States Capitol switchboard at (202) 224-3121. A switchboard operator will connect you directly with the state Senator’s office you request. Questions and Comments If you have any questions about how to email the President, Joe Biden, U.S. representatives, members of Congress, or other government officials, please leave a message below. Please don’t post a comment on the form below and think it will be forwarded to the White House, Congress, the Biden administration, President Joe Biden, or Kamala Harris. lifted from, https://www.einvestigator.com/government-email-addresses/ https://www.einvestigator.com/government-email-addresses/
- infogo 3y ago[flagged]
- nobody9999 3y ago>It will actually be very positive for the web overall and you'll see the benefits soon enough. What might those benefits be? Not being snarky here, but AFAICT the only folks who gain any benefit seem to be Google and their customers (advertisers). What am I missing here?
- Animats 3y agoWe now need two things. First, an antitrust breakup of Google, separating search and ads. Second, a tax on ads. It must be made against the economic interests of search engines to show too many ads.
- manuelabeledo 3y agoWhile I believe that the idea of splitting Search and Ads could be a game changer, how would Search become profitable without Ads, and without compromising the rank algorithm?
- Buttons840 3y agoSearch placement ads stay with search. Ads people can put on their own page go with the new company that is broken off.
- wardedVibe 3y agofreemium? See e.g. Kagi
- Andrex 3y agoGoogle Search could still show ads, but they'd need to evaluate which ad exchange to use, of which Google Ads would only be one option.
- sircastor 3y agoI agree with the first. The second I think is missing the target. This really doesn't have anything to do with search. Instead this is Google (The largest ad seller) using it's market position (as the maker of Chrome/Chromium, the most popular browser) to prevent users from not seeing its ads on any website where they're displayed.
- contravariant 3y agoIt's never going to be against the economic interest of search engines to show ads, they can sell spots on their front page which are always going to be valuable. This should be against their tactical interests, because it hurts their accuracy driving away users, but absent a significantly more accurate competitor they'll get away with it for a long time. Regarding Google search there are some hopeful signs. For one some people report Google's accuracy dropping, and Google keeps switching up its idiosyncrasies to avoid spam but in doing so they devalue the effort people put into SEO and into refining their Google-fu. These might be the same thing however.
- codetrotter 3y ago> Any browser choosing not to implement this would not be trusted and any website choosing to use this API could therefore reject users from those browsers. If we are serious about protesting this, let’s do as follows: We implement code in our websites that checks whether the user agent implements this API. If the check passes, we tell the user that their browser is not welcome and why that is. #BoycottGoogle #BoycottChrome #BoycottBullshit
- worik 3y ago> let’s do as follows: We implement code in our websites that checks whether the user agent implements this API. If the check passes, we tell the user that their browser is not welcome and why that is. I am sympathetic, I agree let's all do that.... ...I cannot imagine any of the money people I work with agreeing
- koromak 3y agoTell that to your boss. Also if google wants to, I'm sure they can obscure it
- pptr 3y agoI'm curious to hear from someone familiar with web development: How much do websites invest in accessibility and related features that cater to a small audience? Can we draw any conclusions from this to how websites will deal with accessibility to non attested users?
- etchalon 3y agoDepends on the company size, really. Large companies will invest significant resources with us to achieve AAA compliance with WCAG 2.1 Smaller companies will spend SOME additional budget to achieve AA. Tiny companies will spend nothing until they get a demand letter.
- Null-Set 3y agoThis would complete the transformation of the user-agent into the vendor-agent.
- nneonneo 3y agoI wanted to write some proper feedback on the GitHub repo, but they've closed issues and PRs. Until they open it back up again, here are my thoughts on the spec: - Mozilla is already publicly and officially opposed (https://github.com/mozilla/standards-positions/issues/852#issuecomment-1648820747 https://github.com/mozilla/standards-positions/issues/852#is...), on principle ("Any browser, server, or publisher that implements common standards is automatically part of the Web") as well as on technical concerns around the safeguards and downsides of the proposal. - WebKit is not committed to a position, but has mentioned several concerns (https://github.com/WebKit/standards-positions/issues/234 https://github.com/WebKit/standards-positions/issues/234): "We have Private Access Tokens (aka Privacy Pass) for some of the claimed use cases of this spec. We think it's a more privacy-respecting solution. The Explainer isn't very clear on why specifically Web Environment Integrity is better. It mentions a feedback mechanism, but not the specific mechanism. It also exposes more info to the page. The Explainer claims this spec is necessary because Privacy Access Tokens don't support feedback from websites on false positives / false negatives, however, neither the spec nor the explainer include a feedback mechanism. Without more specifics, we would not be enthusiastic about duplicating an existing standards-track solution for the same use cases." - Vivaldi is clearly opposed, per this blog post. - Holdback as a mechanism is a weak defense against abuse. Some potential stakeholders are already suggesting to scrap holdback to support their use-cases (https://github.com/RupertBenWiser/Web-Environment-Integrity/issues/5 https://github.com/RupertBenWiser/Web-Environment-Integrity/...), leading to the possibility that it may not even be part of the final standard. Holdback is not technically enforced: a user agent can choose not to hold back, and if they are sufficiently popular they may induce web site operators to rely on their signal (at least for that browser) which would have the exact "DRM" effect that the proposal claims to avoid. The exact implementation of holdback matters a lot: if it's e.g. per-request, a site can simply ask repeatedly; if it's per-session or per-user, a malicious agent can pretend to be heldback the entire time. - Since holdback is being touted as essentially the only defense against "DRMing" the web, it's a real mistake to have it be so poorly specified. The way it's currently specified makes it sound more like an afterthought than a serious attempt to mitigate harm. - Compared to Private Access Tokens, WEI leaks far more information. WEI allows attesters to provide arbitrary metadata in their (signed) attestation verdict, whereas PAT tokens are fully opaque and blindly signed. Furthermore, PAT tokens can be in principle obtained through alternate attestation mechanisms (e.g. captcha, authentication, ...) without leaking the details of how that attestation is performed. WEI does not provide for this, and instead is designed around explicitly validating the "web environment".
- Zopieux 3y agoAs usual, a thousand word essay on Google's WEI without ever mentioning that Apple sailed that ship silently a while ago, therefore not attracting any attention or backlash. https://httptoolkit.com/blog/apple-private-access-tokens-attestation/ https://httptoolkit.com/blog/apple-private-access-tokens-att... https://toot.cafe/@pimterry/110775130465014555 https://toot.cafe/@pimterry/110775130465014555 The sorry state of tech news / blogs. Regurgitating the same drama without ever looking at the greater picture.
- hooverd 3y agoClearly it should have gotten more attention.
- ur-whale 3y ago> As usual, a thousand word essay on Google's WEI without ever mentioning that Apple sailed that ship silently The "look! there's a bigger asshole over there" defense. Never a winning strategy.
- bryanrasmussen 3y agoisn't it - you forgot to mention the smaller asshole who has less power to abuse?
- Spivak 3y agoOr realistically, this has already shipped and the world didn't end.
- Klonoar 3y agoThe reach of Apple doing it isn’t the same as what Google will do with Chrome.
- fecs 3y agohttps://www.statista.com/statistics/1045192/share-of-mobile-operating-systems-in-north-america-by-month/#:~:text=Google's%20Android%20and%20Apple's%20iOS,accounted%20for%20around%2054%20percent https://www.statista.com/statistics/1045192/share-of-mobile-.... iOS is the dominant mobile platform in the US. Yet, the sky did not fall when thiw was introduced. Why not?
- benreesman 3y agoThe Internet in general, programmers especially, and the Web community especially especially owe Google a massive debt of gratitude for all they’ve done over the years. But this one’s simple: “literally go fuck yourself with this. we will fight you tooth and fucking nail every fucking angstrom on this one. it’s a bridge too far.”.
- e4e5 3y agoWhy are we in debt to them? Google has become stinking rich from everything that they've done. That's payment enough.
- luroc 3y agoCould this be the end of my Youtube addiction arc?
- cmrdporcupine 3y agoWell, it's making me finally kick my Chrome habit. My work machine runs Firefox and it's fine, but my personal stuff is all on Chrome because it's also my password management, etc. etc. I tried once before, when I quit working at Google and was trying to de-Google a bunch, and I never succeeded. I plan to move everything over over the next few days. Wish me luck! Next up: getting my photos out of Google Photos.
- LelouBil 3y agoUse Bitwarden! You can self host it or even use the alternative server implementation Vaultwarden. I'm also in the process of de-googling, so far I have passwords, contact sync and calendar sync all self hosted. Photos are tricker since my home server doesn't have a lot of storage right now.
- tjpnz 3y agoDon't give those cunts your passwords.
- papruapap 3y agoWell... I stopped watching Twitch after ublock stop blocking its ads, so maybe...
- ori_b 3y agoNote that this doesn't even prevent people from using tools like AutoHotKey or their moral equivalents to make malicious requests from browsers. It only makes it impossible for legitimate users to run their own code -- people who want to run OpenBSD, or fork Chrome to make sure that ManifestV3 doesn't permanently hobble adblockers, or maintain their own alternative browser UI.
- luroc 3y agoCory Doctorow on this issue (kind of): https://pluralistic.net/2023/07/24/rent-to-pwn/ https://pluralistic.net/2023/07/24/rent-to-pwn/
- dahwolf 3y agoThere's a lot of moral outrage regarding this proposal, rightfully so. In fact, it should be further intensified. But apart from that, I don't think this proposal will work in any case. When implemented without holdouts (closed loop), you do have a tight DRM web, which will attract legislators. Or so we hope. When implemented with holdouts, it's barely useful to websites since they still need the backup mechanisms to detect fraud that they have anyway. If they need to keep it around, might as well use that as singular solution which has the added "benefit" of collecting way more personal data.
- tjpnz 3y ago>it's barely useful to websites since they still need the backup mechanisms to detect fraud that they have anyway. Remember, this was never for individual websites. It's strictly a measure to protect Google's ad business.
- roody15 3y agoCorporations (apple / Google / Microsoft / Nintendo? Sony). They all want a rental model along with a console model. iOS is already just this … a device in which you rent software as a service on a personal device that you restricted from modifying. The consolifocation of personal computing has been moving this way for sometime. It’s essentially late stage capitalism gate keeping. As a child of the 80’s is hard to watch things keep moving in this direction :/
- xcf_seetan 3y agoWould it be possible for someone using a zero day vulnerability to develop a botnet that will infect enough computers on the web, and their payload would be some way to modify browsers in a way to render them untrusted to WEI, and effectivelly render anybody infected out of the web? Would it be a new way to DDOS users out of the "trusted" web?
- hellojesus 3y agoI asked a similar question: Can someone send attlestation requests from the range of residential ips with such frequency that the attlestation sequence is forced to captcha users, thus defeating it? You don't need the token response back from an attlestation, so you could spoof your ip and not worry about getting a response.
- gclawes 3y agoWhat's the potential for this to enable mandatory remote attestation that your personal machine is running For-Your-Own-Good™ spying software in order to use any significant services (banking, etc)?
- yawboakye 3y agoto call the write-up underwhelming is to be the most generous one can be. the minimum requirement that qualifies one to add 'unpacking' to title wasn't met. this all reads as a poorly argued opinion of something google is apparently trying to force down our throats. the specification isn't discussed (they're generous to point you to it though), a cursory mention of the supposed pros are mentioned but an even lazier attempt is made at describing the cons. really disappointing read!
- serafettin 3y agoIt didn't scare me at all. As Google moves away from the open web, the open web also moves away from them.
- dingaling 3y agoA concern is that websites vital to people's lives, such as banks and government services, will adopt this to mimic the control they have on mobile platforms. With few brick-and-mortar branches remaining, it leaves few options open.
- gorgoiler 3y agoI agree that extending trusted platform trust all the way up into web APIs is gross — it would be fine if the TPA club was wide open to anyone building their own OS, but that clearly will never happen and only the corporate-aligned cabal will ever be trusted, and all the free/open OSs will never be allowed to join. But… is there scope for the attestor in WEI to be a third party site that does a super fancy “click on all the stop lights / stairs / boats” captcha, and then repurposes that captcha result for every other site? That doesn’t sound like an awful service to add to the web. It would mean each individual site no longer had to do their own captcha. (Probably impossible without third party cookies. But then that kind of implies that if WEI does make it possible then it could be shown to provide a tracking service equivalent to third party cookies? Again, gross.)
- foota 3y agoI agree, I think a third party attribution service makes a lot of sense, similar to how https has trusted CAs there could be different trusted attributors that can verify that a user has some account with some kind of verification, and these pluggable attributors could then be trusted by sites. You'd still need to integrate with a trusted authenticator, which some people might find objectionable, but it's probably better than the current proposal in that regard. This of course only covers half of the use cases discussed (the half about preventing bots, not to say anything about the more DRM-ey aspects).
- fecs 3y agoit still boggles my mind that Apple->Safari, which is in the only choice on iOS - the dominant mobile OS in the US, already implemented and shipped a very similar feature but the reaction to Google's proposal is 10X worse. I have not seen a single #BoycottApple post here in this thread but more importantly, the sky did not fall after apple introduced this.
- zarzavat 3y agoI’m disappointed by this response. I have to know, will they implement it or not? Because I will not use a browser that implements this thing.
- deleted 3y ago[deleted]
- n00bs 3y agoread something recently that makes me think google is doing this to develop tools that allow browsers to detect replayed tokens on platforms like macOS and iOS. https://medium.com/@danielraffel/compromised-apple-id-exposes-a-potential-vulnerability-in-googles-advanced-protection-program-5e9ce3f51e6e https://medium.com/@danielraffel/compromised-apple-id-expose...
- pabs3 3y agoI wonder if any web servers or web apps have started to block Chrome users yet.
- rejectfinite 3y agoSo this will affect Vivaldi, Brave and Edge too, even if Brave has an integrated adblocker and Vivaldi does too, but less effective? And Firefox will get blocked by even more sites if they don't implement this shit too?
- koffiezet 3y agoWhat unclear to me is how the actual verification by this attester would happen. Somehow the attester, which is also a remote service, verifies your device? Are there any details on how that would happen specifically?
- salawat 3y agoBasically, you build up a set of cryptographically verified computing primitived (like secure enclave) that are enforced by a hardware component with baked in from the manufacturer keys. Basically it's setting up an "owned by vendor computing channel" and baking it into the Silicon. You won't get the chance to refuse this feature. There'll be too much money at stake for manufacturers to not retool for it. It'll be the only thing they make to sell, so take it or leave it chump.
- koffiezet 3y agoSure, but the communication channel between the attester and the client which it needs to verify/attest is pretty much undefined?