5 ms·
Is there a link to an article that actually goes into WEI on a technical level that isn't the proposal itself? So many things posted to HN about it have been t
by gochi 3y ago
Is there a link to an article that actually goes into WEI on a technical level that isn't the proposal itself?
So many things posted to HN about it have been the grand overview, which is a perspective worth diving into but also has drowned out every other perspective to the point where it's very difficult to figure out what's really happening with the proposal here.
- tedunangst 3y agoNot really. Every explainer assumes the proposal is lying, and explains how half of it means the opposite of what it says.
- daurentius523 3y agoBecause any other option is not sensible: 1. Authors don't understand what tech they use. (I will leave it to your belief - but that would be even worse for Internet) 2. Authors don't understand that something unrealistic is unrealistic. Idea that you can give companies or corporations tools to check "did user modify his environment" and they would not use it to exclude users is stupid or disingenuous because advocates for this did exactly comment in such way: We want this proposal to do precisely that. Again Google tries to defend it by saying "we will return invalid 'false' for some of the users/times of Chrome users" [to make sure that website will not do that] which for me is not only bad because it then creates "when google revokes this policy we are in even worse situation" but then leaves the issue how google decides "who" to give back this 'false': I will reject times immediately not only because this can be easily circumvented by website [check n-times] to detriment of user but it would also contradict official documentation of WEI (same token for same input from user). And this leads us to another point - if Google wants to return false negatives it would need to either keep information that is supposed to return 'false' - EU will not be very happy with that (also it does contradict this "chrome users"); or more likely it will be implemented in chrome. Now when we established that implementation in chrome is most probable - we can also establish that: A) Implement this on profile basis - companies will ask you to reset profile if you are this false negative. B) Implement on connection basis - companies will ask you to refresh. C) Implement on device age / os version / type - Google can even make the manufacturers happy with this one. … as you can see at most this will be nuisance and if by some weird way: Z) Implement on Super-complicated basis - this will be still possible because… 3. Google plays disingenuous word game with us here by saying - We won't destroy open web Other Chromium browsers may ignore that Google X% false negative (Google may loose few % of users before it scrapes this policy). And there is 0 need for Google to actually do something when companies will misuse this API. In simple words the part that should worry you is not that "Google will destroy web by using this API on Chrome and it services", what must worry you is that other companies will do that for Google and Google will wash their hands from this by saying "We wanted good but didn't work". You can see that tone from the Google - We don't want that so we created these "holdouts". Don't let Google move Overton window, they are proposing thing that any sensible person see as clear cut attack (or stupid idea that can only work this way) on Privacy and Your Right to use Your Device (and for some people Your OS and/or Your Browser) as You want to use. They are at fault here.
- Gigachad 3y agoAs far as I can tell, there are two reasons for this feature, the legitimate one is that users largely have browser extensions which are malware. They may have even been legitimate when they installed them, but then auto updated to be malware later. This poses a problem for banking sites because desktop browsers can no longer be trusted to be secure so they push you to use the mobile app or at least confirm transactions with the app which is trusted. The illegitimate reason is they can stop ad blockers and content downloaders / DRM bypassers.
- jsnell 3y agoWhat you've written is a great illustration of what tedunangst said people are doing. The proposal literally is not about extensions. The only context in which extensions are mentioned is to explicitly say that the mechanism is not for policing the installed extensions or other browser features. So how exactly are you determining that this is what the proposal is really about? It seems that it can only be by ignoring the proposal text and making up your own ideas of what it is about.
- therein 3y agoI'd avoid taking that route because that would move the Overton window [0] on the issue to Google's side. The premise is unacceptable and discussion on the technical merits will only give it the fuel to make it more material. [0] - https://en.wikipedia.org/wiki/Overton_window https://en.wikipedia.org/wiki/Overton_window
- haswell 3y agoIf the window even applies here, it expanded the moment Google initiated all of this publicly. We're in it now, and fully understanding the issue and the problems it purports to solve is incredibly important. Dialogue is all we have, and to even build a solid argument against WEI, understanding the details matters.
- JoshTriplett 3y agoIt's worth understanding the problem it purports to solve in order to properly dismiss it. WEI positions itself in a way that sounds ambiguously like it might ever serve the user's purposes, and a clear framing of the problem statement would make it more obvious that it does not serve the user at all. For instance, one of the framings of WEI is that it gives advertisers a way to verify the client so they don't "have" to do fingerprinting. Except WEI does nothing to take away fingerprinting, so advertisers will then have fingerprinting and WEI. (Even if it did simultaneously take away fingerprinting it would still not be OK, but the current framing is not even offering the user benefit it claims to offer.)
- charcircuit 3y agoBefore taking away fingerprinting there would need to be a sunset period to have everyone migrate over to the new API. Ripping it out before new APIs are available or doing it at the same time is irresponsible.
- ImPostingOnHN 3y agoI'm not sure how that addresses the point you're responding to: regardless of the excuse, WEI with fingerprinting is bad, and WEI without fingerprinting is also bad, and fingerprinting without WEI is also bad doing bad things (for example, any of the 3 above options) is more irresponsible than implementing bad things poorly