41 ms·
Google Web Environment Integrity Is the New Microsoft Trusted Computing
- robbie-c 3y agoI doubt it’ll be abandoned so easily. Whilst Google has a track recording of abandoning projects, this doesn’t apply to anything directly related to selling search ads.
- cute_boi 3y agoThey will just come up with new name like Privacy Environment Integrity similar to Privacy Sandbox / Topics or something like that
- enriquto 3y agoInteresting to see a microsoft employee openly rooting for the FSF and the EFF against google. What is going on here?
- EMIRELADERO 3y agoI think Google just went too far on this one, too soon. You know, the whole thing about slowly boiling the frog and all that.
- ozymandias12 3y agoThey had to speed things up, not only Sergey Brin is back at Google's headquarters, other SV companies are going deep into the identity realm, that directly clashes with Alphabet identity exploitation, same for Meta, these companies largely payed to win the "digital identity dilemma" but things will change pretty fast over the next 2 years. Sam Altman WorldCoin and Musk's X platform should be the telltale but people are missing the clues?
- rolph 3y agothats right boiling frogs with a blowtorch, is actually a roasting.
- genocidicbunny 3y agoAlmost like this whole thing is pretty universally bad for everyone but Google.
- caskstrength 3y agoThey only like it when they are the ones doing it. Nothing new here.
- deleted 3y ago[deleted]
- Knee_Pain 3y agoThere is a freedom problem, there is a hardware problem and there is a social problem. The freedom problem is this: you will not be able to roll your own keys. This is probably the biggest nail in the coffin for a ton of computers out there. In theory you could simulate via software the workings of a TPM. If you built a kernel module the browser would have no real way of knowing if it sent requests to a piece of hardware or a piece of software. But the fact that you would have to use Microsoft's or Apple's keys makes this completely impossible. The hardware problem is this: you will not be able to use older or niche/independent hardware. As we established that software simulation is impossible, this makes a ton of older devices utter e-waste for the near future. Most Chromebooks themselves don't have a TPM, so even though they are guaranteed updates for 10 years how are they going to browse the web? (maybe in that case Google could actually deploy a software TPM with their keys since it's closed source). I have a few old business laptops at home that have a 1.X version of the TPM. In theory it performs just as well as TPM 2.X, but they will not be supported because, again, I will not be able to use my own keys. Lastly there is the social problem: is DRM the future of the web? Maybe this trusted computing stuff really is what the web is bound to become, either using your certified TPM keys or maybe your Electronic National ID card or maybe both in order to attest the genuineness of the device that is making the requests. Maybe the Wild West era of the web was a silly dream fueled by novelty and inexperience and in the future we will look back and clearly see we needed more guarantees regarding web browsing, just like we need a central authority to guarantee and regulate SSL certificates or domain names.
- josephg 3y ago> But the fact that you would have to use Microsoft's or Apple's keys makes this completely impossible. Yes completely impossible to fake by design. Otherwise whats the point? But I think the root of trust is whatever signs the hardware TPM module. So, Intel, AMD and Apple. If I understand it correctly, the secure chain of trust will be something like, hardware TPM module -> secure boot -> windows signed kernel -> Chrome (signed binary). Its not clear to me if desktop linux will be able to participate in this ecosystem at all - which is ironic given how much google uses linux. Maybe a couple of the big distributions like Canonical will be able to sign their linux kernel builds. > Lastly there is the social problem: is DRM the future of the web? Its opt-in by website operators at least. Assuming this happens, there are two big questions in my mind: 1. How much of the web will go dark to anyone not using a corpo software stack? I imagine bank websites will adopt this technology immediately, while sites like HN, personal blogs and wikipedia won't touch this stuff. How much of the web will stop working on my terrible "hacker" computer where I use firefox on linux? 2. How will this interact with browser extensions and dev tools? If websites won't function outside of chrome, will we be able to continue to drive chrome programmatically? Will chrome's dev tools still work? Will websites be told about my ad blocker extensions? Will webdriver (and similar tools) be blocked?
- asplake 3y agoInteresting thought that this may be a “careful what you wish for” moment: > In many ways, if we get Web Environment Integrity, we’ll need every government to regulate Google, Apple, Microsoft, and adtech in every way possible
- jillesvangurp 3y agoFirefox once was the only alternative to internet explorer. Then Google came along to become the new and improved alternative to the alternative and it became quite successful. MS eventually threw in the towel and their browser market share is lower than it has ever been. And most of that is now Google Chrome. And now history repeats itself and we have Firefox being the alternative to the mighty Google Chrome and Google emulating more and more of what people hated about Microsoft's stewardship of Internet Explorer and dictating to users what they must have their eyeballs exposed to. In Microsoft's case that was obnoxious popups and popunders, shitty toolbars, and endless crap they came up with to somehow lock users into all that. Now Google is whining that nobody wants to see their shitty ads (correct) and somehow feels entitled enough that they can dictate browsers to respect their authority regarding what users can and cannot block. It's the same behavior. And the fix is the same: abandon the Chrome ecosystem. The more users do that, the more the web will basically remain outside of the control of Google.
- genocidicbunny 3y ago> somehow feels entitled enough that they can dictate browsers to respect their authority regarding what users can and cannot block. It's the same behavior. And the fix is the same: abandon the Chrome ecosystem. The more users do that, the more the web will basically remain outside of the control of Google. This is fundamentally the problem isn't it. They feel entitled _because_ they can dictate terms to the rest of the web, or at least they think so. There's no fixing this by changing Google's mind, only by forcing their hand by making this decision hurt their wallet. And as you point out, that only happens if people stay outside of the Google garden.
- gmerc 3y agoMicrosoft thought they can do that too. Where is IE now?
- genocidicbunny 3y agoIE lived on a very long time after the antitrust thing. Also still in relatively widespread use in parts of Asia.
- rand846633 3y agoSomehow I am not convinced that Ad blockers are such big of a problem for Google. Especially when these are not used much on Mobil, and the world is clearly transitioning to Mobil. Do we know the financial impact ad blockers are thought to have? I’m guessing ad fraud is a way bigger problem, although some would argue that add fraud is not googles problem, it still hurts Google. Maybe it’s also a third thing I just can’t think of right now, ad blocks just seem to niche to me. How about just enforcing a stronger monopoly on user tracking?
- genocidicbunny 3y agoGoogle is an advertising company. That's their bread and butter, everything else largely serves to boost that business unit. Blocking ad blockers, alternate clients..etc, is absolutely in line with their business goals of serving more ads. And also, frankly, I don't really frakking care if their purpose is to prevent ad fraud. That's not my problem, why should I be the one paying for Google to make more money from a problem they created themselves in the first place. As far as I'm concerned, if Google really wants to prevent ad fraud, they can just stop doing advertising; Problem solved.
- vorticalbox 3y agoThey make a big fuss about it like the movie industry does about privating movies. They "lose" millions sure but they are making "billions" even with a few people doing it.
- realusername 3y agoThey just blame adblockers for the Google Ads scandal happening right now where they faked ads reports to customers. They can only blame themselves for faking data.
- lozenge 3y agoYes, ad blockers aren't big right now, but Safari on iOS and Samsung Browser on Android has ad blocker support. What happens if Apple or Samsung decides to bundle an ad blocker? Google wants to defend against any future moves. Already, other browsers have led on tracking protection and control of third-party cookies, affecting Google's business model. So Google built Chrome, invested in it so people would prefer it, pushed it on their websites to ensure people would prefer it, and built a walled garden with Chrome Sync + Passwords. Then they started using it to decrease privacy by signing in to Chrome when you sign in to Gmail. They track your websites visited and use it to improve their advertising even when the website doesn't use Google ads. Theirs is the only password manager for Android which is limited to their browser. That's for a reason.
- mnd999 3y agoNo ifs, no buts. Stop using Chrome.
- pleb_nz 3y agoAnd it's derivatives
- pjmlp 3y agoIncluding Electron apps.
- ParetoOptimal 3y agoAh, so no vscode?
- pjmlp 3y agoIt might sound incredible, there are other configurable editors out there, some of them have linage back to the 1970's!
- ParetoOptimal 3y agoI've actually been using Emacs exclusively for a decade or more now :)
- barryrandall 3y agoI do not think anyone would be surprised to discover that these alternatives were released in the 1970's.
- asadotzler 3y agovscode doesn't show up in webmaster stats in a meaningful way, so no.
- deleted 3y ago[deleted]
- pjmlp 3y ago> It’s not impossible to win this fight, we won the fight against Palladium, even with a well-resourced Microsoft combined with the PC industry, if not the NSA and MPAA. Actually it was a pyrrhic victory, as Microsoft went on to apply their ideas to XBox, Azure Sphere, and now the change is coming back as future Windows hardware requirements for secure workstations via Pluton integration. https://www.microsoft.com/en-us/security/blog/2020/11/17/meet-the-microsof-pluton-processor-the-security-chip-designed-for-the-future-of-windows-pcs/ https://www.microsoft.com/en-us/security/blog/2020/11/17/mee... I bet mostly UNIX focused folks haven't noticed that their next PC might have a Pluton CPU on them. https://www.thurrott.com/hardware/260917/here-come-the-first-pcs-with-microsofts-pluton-security-chip https://www.thurrott.com/hardware/260917/here-come-the-first...
- AnthonyMouse 3y agoIt isn't for no reason that a lot of people are interested in RISC-V.
- pjmlp 3y agoThey are day dreaming if they expect the whole eletronic stack to be open, from thinking rocks all the way to the boot loader.
- AnthonyMouse 3y agoLots of people work to make their dreams a reality. Some of them succeed.
- pjmlp 3y agoYou mean like making the Year of Linux Desktop a reality, by shipping Linux VMs running on mainstream OSes?
- spacephysics 3y agoThere’s enormous momentum with closed source computing. I think that’s an amazing step in the right direction, as it lowers the barrier of entry for someone to try out Linux.
- baz00 3y agoThe problem here is that most people don't give a crap. I was explaining this situation to my girlfriend last night over a drink. She's a high level academic with a strong mathematical and logical background in a different field but she didn't really formulate an opinion on it past "if my stuff keeps working, why is it a problem?". Which is fair, because it's a hypothetical risk, but the side effects are a net negative and the open nature of the web is at risk. As always people see the happy path down the middle of the forest, not the creatures waiting to leap out and eat them two steps down the line.
- genocidicbunny 3y ago> "if my stuff keeps working, why is it a problem?" "Is your stuff going to keep working? There's literally a website dedicated to the products Google has killed. What makes you think you're so special that they won't do that to something you use?" Of course, you're probably sleeping on the couch that evening...
- baz00 3y agoWell that's exactly it. Her entire professional life is also tied to a free Gmail account she refuses to pay for too.
- genocidicbunny 3y agoI will preface this with the agreement that I am kind of an asshole on some things. With that out of the way... I would find quite a bit of value in getting that person locked out of their google accounts and forcing them to deal with the consequences; Especially if the lock-out was just me getting in and changing their password so that their access can still be recovered. A little controlled scare would be far better than getting locked out at some unknown/unprepared-for point in the future. So perhaps in your case, the wise thing to do would be to ask your gf to try to pretend she was locked out of her google accounts for a week. Force her to see how much she relies on it, and how bad it is when that spf actually fails. You could probably accomplish it by allowing her to change the password to something she doesn't know for a week.
- icecream_so_gud 3y agoThis is the content of a email I have sent to a number of politicians, government agencies, and consumer advocacy groups. You are welcome to use as is, reformat or modify as you see fit, or just generally complain about structure/grammar/arguments etc. --- Dear <<REPLACE>>, I am a <<COUNTRY>> citizen, and I live and vote in <<REPLACE>> district. Professionally I am a software engineer <<blah blah blah years of exp, exp with web etc>>. I am writing to you with a concern about a recent planned change by Google called Web Environment Integrity (WEI). I believe this change is anti-competitive, against the open web, and a risk to our country's security agencies. Very simply WEI allows websites to verify the users browser (e.g. Chrome), and potentially the Operating System (e.g. Windows) is official and unmodified, this process is called attestation. Basically how it will work is: 1. User navigates to a website 2. The website executes a challenge to the browser (e.g. Chrome) asking for attestation and listing the acceptable attestation services. 3. The browser makes a request to a third-party attestation service (e.g. Google) 4. Software, an attestation agent, runs on the user's computer. This software scans files and memory of the user's computer or phone and sends back proof, to the attestation service (e.g. Google), the user is running an acceptable, official and unmodified browser and/or operating system. 5. Once satisfied, the attestation service issues the user's browser a token. 6. The user's browser forwards this token to the website 7. The website can use this token to check against the attestation service that the user is indeed running official or unmodified software. 8. The website then permits the user to access the site. In the event the attestation fails or the browser fails to provide a valid token the website will likely deny access to the site. On the face of it it may seem like this is a noble goal, unfortunately it mainly entrenches Google's position of power. Google's browser Chrome is used by 85% of users, Google search is the most popular search engine, and Google controls the biggest online advertisement service, AdWords. Once implemented Google's existing dominance places it in a position to push it onto websites and users. Google could deny access to GMail, Google Maps, and YouTube unless the user has this feature. Google could deny placement of ads, and subsequent payment to website owners unless those accessing their site have WEI enabled. The proposal is bad for the following reasons. 1. Limited Attestation Services - Website owners have a list of attestation services they trust. It is extremely unlikely a large number of websites will add Joe Bloggs third-party attestation service as trusted. As a result it is likely only 3 attestation services will exist: Google, Microsoft and Apple. This proposal will further entrench these three companies as owners of the web. This is anti-competitive. 2. Prevents alternative browsers - Create a standards compliant browser is a monumental task which is why only a limited number exist Chrome (uses Chromium which is based off Webkit), Safari (based of Webkit), and Firefox (uses its own Gecko browser engine), most others (Brave, Microsoft Edge) use Chromium browser engine under the hood. Currently, apart from the effort, there is nothing preventing a group from creating a brand new browser engine. An extremely dedicate team could create a new browser and all websites would work with it. If WEI was implemented this new browser would need permission from the incumbents otherwise attestation would fail and users would be denied access to, potentially, most of the web. This is anti-competitive. 3. Prevents accessibility tools - Some people have additional needs due to disability or age and may use tools like screen readers or text only browsers to navigate the web. This involves additional software which injects itself into the browser in order to provide the functionality. This process, while legitimate, may result in attestation failing, especially after new software updates, and as a result denying marginalized users access to the web. This is against the open web. 4. Prevents alternative web crawlers - In order for your website to be listed in Google search an apps called Googlebot and Google crawler need to connect to your website and go through each page, this is then indexed and the results are presented based on relevant search terms. There are other web crawlers by Microsoft/Bing and Yandex which do something similar for their search engines. While they are likely to provide themselves attestation tokens in order to continue the service and new company may invent a better way of providing internet search but in order to crawl, with WEI in place, they would need to ask permission from Google to authorize their crawler. This is anti-competitive. 5. Prevents legitimate scraping - Similar to crawling there are legitimate uses for scraping, which is extracting data from a webpage by an automated tool for use as some other purpose. One example is the Internet Archive (archive.org) they regularly visit millions of websites around the world take a copy of them for historical purposes. You can use archive.org to view Google's first homepage from 1999, or Yahoo! from 1996. WEI prevents new companies or groups from creating novel tools created from legitimate scraping without asking permission from Google first. This is anti-competitive. 6. Prevents security agencies from doing their jobs - Government security agencies and police hack, monitor, and scrape, as permissible under law. These actions are performed by expert agents who are also supported by various scripts, bots, and custom built apps. These tools are rapidly modified and continuously changing depending on the operation. WEI would require these tools to be authorized by the attestation agent or service, while there are a number of ways this could occur, ultimately this requires Google to authorize each tool in order for the tool to successfully collect a valid token. Google could temporarily or permanently deny access to valid tokens, or change the algorithm for generating them to prevent security agencies from generating their own, which would deny security agencies from using their tools against operational targets. This is a risk to our country's security agencies.
- politelemon 3y agoNote: not to be confused with trustworthy computing which was a different initiative. https://www.microsoft.com/en-us/security/blog/2022/01/21/celebrating-20-years-of-trustworthy-computing/ https://www.microsoft.com/en-us/security/blog/2022/01/21/cel...
- websap 3y agoWhat a great way to start an article. Insult your audience. > If you haven’t been under a rock, you may have heard about Google’s evil Web Environment Integrity “proposal”. Supposedly, this is to make sure a browser environemnt can be “trusted”, but it seems Google wants this so they can kill ad blockers. Also you misspelled environment. Surprising for a geological enthusiast.
- nubinetwork 3y agoSee also https://news.ycombinator.com/item?id=36875940 https://news.ycombinator.com/item?id=36875940 https://news.ycombinator.com/item?id=36875226 https://news.ycombinator.com/item?id=36875226
- fsflover 3y agoand https://news.ycombinator.com/item?id=36882654 https://news.ycombinator.com/item?id=36882654
- laniakean 3y agoI grew up in India, and the majority of the population doesn't have access to the latest hardware. If websites starts implementing these changes, a lot of these people would be cut off from the internet. Most of these people belong to marginalized communities. My country has a history of discriminating people based on their castes, and any progress we have made in this aspect would be destroyed by this change by further limiting the online resources available for people from these communities. This is outrageous.
- _wolfie_ 3y agoI would expect the actual restrictions to be 10, maybe 15 years into the future. After all, this is a long term plan how to make world worse, not a spontaneous idea. Will people not refresh the hardware by then?
- adithyassekhar 3y agoAll android and ios phones sold in the last couple of years comes with ARM trustzone or secure enclave or something similar. It's already here. The vast majority of Indian internet users are from mobile. It's a market lead by Xiaomi and other Chinese OEMs who sell phones that dies after a year or two with horrible ota updates. Some people downgrade, some use custom roms. But the majority just buys a new phone every 2-3 years. Or even 1 year. The poorest of people here buys iPhones with financing. Besides you don't need to buy expensive devices. Every GMS certified phone made in the last couple of years has it. Now for actual computers, most are either prebuilts or laptops. They all come with secure boot since 2013?. The last Windows release without a mandatory TPM is going to be discontinued in 2025, microsoft will scare people into upgrading. These are old machines. Any laptop made in the last 4 years will be able to access the new closed web so it won't be hard to replace of them. I'm just hoping this "end of internet" happens really quickly. So that people would notice. One day people should wake up locked out of the web on their expensive devices. If it's a slow boil, we'll be too late to stop it. Again.
- LunicLynx 3y agoUse and support firefox
- deleted 3y ago[deleted]
- dathinab 3y agoI would argue its way worse, due to it's far larger reach and potential consequences.
- blibble 3y agosurely if they're successful they'll create a market for ripping the keys out of TPMs and selling them? at which point you could attest any environment you wish, across as many machines as you want a nice side hustle for bored university students with access to the equipment needed (currently this doesn't happen as the TPM keys are essentially worthless)
- wizee 3y agoSuch keys sold in large numbers could be detected and blacklisted though.
- blibble 3y agowhich will increases demand for keys, and will encourage increased economies of scale of extracting them would I pay $500 for a TPM key I can use to "attest" my hacked version of Chromium that removes ads? hell yes would cheaters pay $500 for a TPM key to bypass valorant anti-cheat? hell yes (they do already) would spammers pay $500 to spam Google? and so on ultimately attestation to control the user (vs. protect them) sows the seeds of its own demise
- kevincox 3y agoIIRC these keys are often produced in batches to help protect anonymity so revoking them may have undesirable impact on the bystanders who happen to have a key in the same batch. So if we could reliably extract keys it may be enough to break this. (or force TPM makers to have per-device keys instead of per-batch keys)
- rolph 3y agothats advantageous in the context of key spraying attacks, aiming to get as many possible keys blacklisted as forgeries, leading to large scale key losses. you dont have to know any keys just the structure of a valid key, then make things up according to spec
- rolandog 3y agoI'd expect world leaders to be more vocally opposed at having their citizens' (and their own) freedom being singlehandedly restricted by an american company that seems to have huffed authoritarian paint fumes.
- tjpnz 3y agoHow does Google intend to implement this when they've been preaching for years that there's no such thing as 100% uptime? Will they be ready to compensate operators for lost profit during the five minutes plus each year that the internet is unavailable? Or was this an afterthought like everything else in their proposal?
- nologic01 3y agoIts insane that the digital technology of Western world has come to be completely dominated by a couple of advertising companies. The conflicts of interest with societal (including economic) objectives are enormous and the solutions so simple and natural. That such a pivotal issue is not handled competently with the top priority attention it deserves says more about the state of the US polity than the horned man storming the Capitol.
- ozymandias12 3y agoAFAIK the US bigtech dictates a lot of the tech movement narratives and America is already a P2W society if you think about it from a game industry perspective, so this isn't exactly a surprise, what comes next should be a surprise, like, either AI outpaces US capability to dictate digital narratives in the western countries and states manage to get into their own digital narratives or the America vs China technology/economic warfare winners will. Would love to have a 3rd alternative but all other assumptions sound stale to me at this point.
- tetrep 3y agoIf you think about it a bit, it's almost expected. Ads are a (the only?) effective way to monetize any digital device. So an advertiser has an interest in nearly all (internet connected) digital technology, as all areas can be exploited for additional advertising revenue by them. Their only meaningful competition at that scale is other ad companies, as nobody else can monetize arbitrary digital devices as effectively. This is why we need to be politically active and politically effective and I'm glad OP called that out in their post too. It's like reminding people to vote when dealing with the consequences of elected officials. edit: What business, other than an ad business, can safely say "we don't care what digital technologies we invent, as long as they are popular we can make piles of money." IMO, that is the motto of a dominant tech company. You can see a striking example of this failing with the various home assistants. Despite their popularity, tech companies can't figure out a way to shove ads into the UX, so they can't make money.
- flagrant_taco 3y agoI have always wondered if political solutions are really viable when the free market doesn't care. We didn't have to buy into these products or allow them to take over or lives if we has an issue with ad companies running them. We could simply not use them, accepting the negative impact that will have on parts of our current life. If the majority of our people don't care and have chosen the convenience, and the dopamine hit of, the digital products should politicians really step in though? If politicians in a representative democracy are meant to represent the people then it really isn't their job to fix this, the people have already spoken. I don't agree with it and do my best to limit my use of these ad companies, but that doesn't mean it's my responsibility to rip these products of everyone else's hands of they chose their own tradeoffs. If Google wants to do this and people really care, they'll just stop using Google and accept that they won't have access to any services that decide to require this kind of DRM-like verification.
- mrweasel 3y agoOne of the "issues" the this is suppose to address is that advertisers "need" to know that humans are viewing their ads and not some robot. That seems really one sided. To me that indicates that I as a user have a right to know that a human and not a robot is responsible for me seeing this ad. That's not the case of course. What this would do is kneecap the enemy/users and let the advertisers be the only ones with access to automation and integrity validation. I doubt that many objects to see ads for powertools on a DYI forum or developer tools on Stackoverflow, seems reasonable. The objection is to being bombarded by obvious scams, micro transaction laden mobile games, online casinos and anything that in no way benefits me as a consumer. Google should perhaps focus a bit more on validating the integrity of their consumers i.e. the advertisers.
- 634636346 3y agoOne of the devs is using the CoC to silence criticism, even CoC-based criticism: https://github.com/RupertBenWiser/Web-Environment-Integrity/issues/131 https://github.com/RupertBenWiser/Web-Environment-Integrity/...
- yomlica8 3y agoThat is what the CoC is for. Kind of funny to see it used so blatantly so quickly and publicly though.
- bakugo 3y ago> Well, guess what? People who root their devices and use custom ROMs like LineageOS (myself included) nowadays hide root from bad apps and can pass these checks anyways. I use Google Pay all the time on my OnePlus 11 running an unofficial LineageOS build, thanks to root hiding. Does Google not realize how commonly bypassed Play Integrity is? In fact, it is easy even on Google’s very own Pixel devices, as someone who previously used multiple generations of Pixel devices, including the Pixel 7. Important to note here that it's only possible to "fool" SafetyNet/Play Integrity because of compatibility with older devices. The strongest Play Integrity level (MEETS_STRONG_INTEGRITY) is simply not possible to fake on a device with an unlocked bootloader, it's just not a big problem right now because most apps do not require it yet, since there are still many old devices that don't pass it, because of missing hardware or outdated android versions. Eventually, in a few years, a time will come where the number of non-unlocked devices not compatible with MEETS_STRONG_INTEGRITY will be low enough that apps will start requiring it, and that will be the end of bootloader unlocking for most users that still do it.
- kevincox 3y agoIt seems to me that they plan on "fixing" that bug in this API by requiring hardware attestation from the start.
- Mountain_Skies 3y agoDuring the pandemic society as a whole showed a strong affinity for authoritarianism over freedom if it could be justified in terms of dubious safety gains. Governments and businesses took note of just how easy it was and especially how willing much of the public was to assist the authoritarians to achieve their goals. Expect a never ending series of these initiatives to make everything "safe", that will coincidentally also accelerate the centralization of power over everything.
- larata_media 3y agoIt seems like this solution is intended to solve the problem of bots padding numbers for sites providing advertisements on the web. This isn’t a userland problem, it’s an advertiser problem. But the user experience will be worse for it. I’m seeing the biggest issue is who decides what a “trusted” browser is. Is it Google? I’m guessing the will establish a non-profit “independent” advisory board which will have members who somehow align with the interests of all major advertising stakeholders in the world. This is dripping with anti-compete potential. Some lawyers are going to get rich from this.
- userbinator 3y agoNo mention of the FSF in regards to this issue is complete without a reference to Stallman's Right to Read story: https://www.gnu.org/philosophy/right-to-read.html https://www.gnu.org/philosophy/right-to-read.html He wrote that 26 years ago. It's worth reading again just to see how much he got right.
- deleted 3y ago[deleted]
- Paul_S 3y agoI think I have become a web accelerationist. I hope this newest bit of mendacity succeeds and we abandon this flaming disaster that the modern internet will become. The tiny (just depressing how tiny) subset of its useful functionality can be reimplemented in any other system that might come take its place in minutes.
- jesprenj 3y ago> Supposedly, this is to make sure a browser environemnt can be “trusted”, but it seems Google wants this so they can kill ad blockers. How would they kill ad blockers this way? I can just use librewolf browser, sites will detect it and not work. But we already have this in form of Widevine DRM. Spotify does not work in my browser without DRM. They can't really force this on google search, because many clients will never support it (older Nokia 3x4 keyboard phones etc).
- asadotzler 3y agoSure, a few sites with drm'd content today is no big deal, but when any site that wants to serve advertising is using drm, when google.com and gmail both are, when amazon.com is, that's a step change.
- EGreg 3y agohttps://community.qbix.com/t/transparency-in-government/234 https://community.qbix.com/t/transparency-in-government/234 All these elites always want to know what we plebs are running. The governments want Venmo to report anything that adds up to over $600 a year to the IRS. FATCA travel rule pushes all countries to do the same, for $1K but FINCEN has lobbied for as low as $250! Meanwhile the Pentagon can’t account for trillions, and both parties give them more money than they even ask for. We have government officials in constant secret meetings, failing to avert disasters, then the plebs have to fight. I say — we should have attestation that the server is running verified code, the one that was audited by third parties that I accept! That would be what I always wanted on the Web. Instead, they only do it the other way. We the People have to rise up and demand that Google implements a standard that uses SGX extensions or whatever, to guarantee that the code managing the website matches the audited code. This is long overdue! It is also why we use smart contracts and Web3 for now. All I really want, on the mobile Web, is a way to visit a URL that has a content hash, and it will load a static file matching a content hash, and save it so it’s always available locally. That’s it! So I can trust the code. Without having to install an extension. Instead Apple clears everything after 7 days, making it useless! And SRI only works for subresources. Which means the server can be hacked and serve malicious code to me anytime! https://arstechnica.com/information-technology/2022/08/architectural-bug-in-some-intel-cpus-is-more-bad-news-for-sgx-users/ https://arstechnica.com/information-technology/2022/08/archi...
- commandlinefan 3y agoIt's actually worse - Microsoft wanted to use Trusted Computing to sell more software. Google wants to use Environment Integrity to control what you can and can't see, hear and say.
- schnable 3y agoThis is a really weak argument. Chase "requires" certain OSes because that's all the QA and develop for, not for some client trust reason. There's no reason for a bank to require a trusted environment, user authentication is sufficient. Trust environments really do matter for other cases and provide security for the user. All good tech has bad applications.
- abirch 3y ago"requires" is correct. I use chase.com on my Linux computer all the time without any pop-ups or warnings that I'm using it on an unauthorized OS. I'm sure if I had some type of QA Issue they would then point out that they don't support Linux but I haven't had an issue yet.
- dnnywhatdid 3y agoIt seems like someone switched out the execs of Google and Microsoft. (Specific communication)
- dnnywhatdid 3y agoFWIU Schmidt is now personally hiring folks to do the government's work? We need PQ FIPS and TLS revisions; not this.
- jusoren 3y agoI just contacted EFF regarding this. Hopefully many will do so to.
- hooverd 3y agoGiven the current political climate, you could call it Google trying to Chinafy (Chinatize?) the Western internet.
- fleventynine 3y agoThis will force fraudsters to build farms of "trusted" devices, with cameras pointing at the display with computer vision and simulated fingers clicking on the ads.
- evah 3y agoOne part of the proposal describes web servers getting information from attestors on the amount of activity coming from the user. And I imagine in the future web servers will contribute information back to the attestor indicating how likely they think the user is a bot based on their activity. I think, for sure, attestation accomplishes what it intends to. It's the end of the cat and mouse game. Tom catches and eats Jerry and there won't be a sequel.
- dlopes7 3y agoIs everyone ignoring that “holdback” mechanism google is introducing with the idea? Where 5-10% of the traffic behaves as if it did not have attestation enabled, I would like to understand how that does not address the “web DRM” concerns but I can’t find an explanation anywhere
- gigel82 3y agoIt's very obvious that is disingenuous; they will use that as an excuse to make it palatable while planning to silently turn it off in a couple of years. Clearly it's a "foot in the door" technique similar to how Apple tried (but ultimately backed down) to introduce local scanning of all content on user devices (in the name of CSAM of course - a palatable scenario - which later opens the door for scanning anything a government entity dislikes).
- mplewis 3y agoBecause once WEI is ubiquitous, they will turn off holdback.
- danShumway 3y agoI won't copy paste the whole comment, but I wrote about this at: https://news.ycombinator.com/item?id=36885174 https://news.ycombinator.com/item?id=36885174 TLDR holdbacks might help with specifically the DRM component; but they can only go one of three ways: - They can be effective at forcing sites not to rely on attestation, in which case there is no benefit to this proposal because everyone (including users of browsers like Chrome) will still be subjected to the same invasive backup strategies. You'll still be fingerprinted and tracked no matter what because even if you're using Chrome 1/20 times you send a request the website will just revert back to the original fingerprinting. - Or if they aren't effective at forcing sites not to rely on attestation, well... then they haven't solved the DRM problem. - Finally, attestation might be used to primarily decrease annoying behaviors, which will still in practice make browsing the web for anyone who doesn't use a browser with attestation so painful that they'll eventually switch. Think "you're not on Chrome, so you're going to see 9x the captchas you otherwise would see." You can't simultaneously have "this allows us to trust the client" and "we can't rely on it." One of them has to give. At their best holdbacks would turn this into another tracking vector and would change nothing about the web for the better. More likely, holdbacks will allow sites that would previously be judicious about where they used captchas and blocks around the site to start spamming them everywhere -- because Chrome users will only see 5-10% of those annoyances. And at their worst, sites would just not implement the fallbacks because the attestation signal is still reliable enough. Holdbacks call the entire motivation of this spec into question, since the whole point of holdbacks is to make it impossible for websites to get rid of the invasive "backup" walls and tracking and captchas that the spec claims to be trying to replace. Blocking ad fraud? Blocking automated requests? WEI only helps with that if websites can trust the signal and block browsers that aren't sending it; otherwise websites are right back to square one trying to prevent fraud. But if they can do better blocking based on that signal, then we're back in DRM territory. ---- Another point raised by another commenter: https://news.ycombinator.com/item?id=36884649 https://news.ycombinator.com/item?id=36884649 Implementing holdbacks in a way that actually prevents DRM is likely to be fairly challenging. In the most straightforward implementation, websites can simply retry the request until they get an attesation token or until they hit 10 iterations, at which point they'll ban you as normal. Statistically profiling users and determining whether or not their browser supports attestation is likely to be fairly easy, unless Google has a much cleverer implementation of holdbacks than they've revealed so far in the spec. This would be the worst case scenario -- holdbacks would be used as an excuse to push the changes through and sites would simply ignore them and block users based on aggregate stats: you haven't passed an attestation check in the past 30 minutes even though you made 20 different requests that should have had a token attached? Yeah, you're pretty likely on an "unsupported" browser.
- animex 3y agoIf it's possible to detect the feature and reject delivering to a browser that has this feature enabled. Fight.
- gjvnq 3y agoWhere is the petition or letter we can sign to bring attention to this issue?
- evah 3y agoI hope HN has a different blog post with its own take on WEI on the first page every day until the proposal is closed and Google publishes an apology and promises never to try this again. Maybe we can get Apple's web attestation removed too.
- 634636346 3y agoI wonder how many HNers angry about this are also some combination of 1) working for bigtech 2) using iOS/OSX/Android instead of Linux (yeah, I know Android is technically a Linux) 3) using Chrome/Safari instead of Firefox and 4) have endorsed, at least in the past, bigtech firms like Google and Cloudflare acting as arbiters of what is/is not acceptable content for the internet, and even whether it should be viewable by anyone at all.
- kobalsky 3y agoyou don't have to be a perfect bastion of morale without any hint of hipocrisy to oppose something that is so blatantly wrong. if we don't allow people who are contributing to the problem in any way or are benefitted by it, to oppose it, we are doomed to fail.
- 634636346 3y agoIt's not just hypocrisy. Many of the HNers railing against this are actually responsible, even if just indirectly, for it. Take Chrome (including Chromium) use, for example. Chrome has never been that much better (e.g. 2-3x) than FF. Maybe at its best, when it first debuted and V8 wowed everyone, it was 20-30% better--not enough to justify the investment a poweruser (who heavily customizes their browser) would have to make to jump ship, and not enough for anyone concerned about the open web. Yet I would guess most people here jumped ship at some point (probably when it was new and shinny and Google still paid lip service to "don't be evil"), and they've never looked back, despite FF having caught up and remaining competitive. Asking people to not use Chrome isn't asking much, and yet people here can't even manage that.
- piyuv 3y ago[dead]
- lakomen 3y agoFinger pointing, Win11 requires TPM and not just a TPM chip but also a, special CPU. How is that not different from TCPA Palladium etc?