3 ms·
Yes, but each and every website needs to explicitly allow each and every browser key. Which increases barriers to entry for new browser vendors and makes Open S
by irdc 3y ago
Yes, but each and every website needs to explicitly allow each and every browser key. Which increases barriers to entry for new browser vendors and makes Open Source / Free Software browsers nigh impossible.
The EU isn’t stupid and is kinda fond of Open Source / Free Software (because it serves as a way to make the EU economy and society less dependent on foreign tech giants).
Don’t worry, Brussels will save ya. :)
- mike_hearn 3y ago> Yes, but each and every website needs to explicitly allow each and every browser key You mean like how browsers need to explicitly allow each and every root CA key? If that's the basis on which a legal case is built then it'd fail even in the ECJ, because all that's required is set up an equivalent of the root store programmes and it's solved. The way this would actually work is something like: websites just "apt-get install browser-keys", add a bit of JS to their HTML and now their nginx or apache or AWS LB just adds an extra header to proxied HTTP requests saying "X-User-Agent-Accuracy: HIGH" and "X-Extensions-Signing-Keys: <...>". Then every so often you do an apt-get update and the latest round of browser/extension signing keys get added. So there's no reason why obscure browsers can't take part in this scheme, just like how obscure CAs can take part in the web PKI. Nor does it make open source browsers impossible. Just like how there are open source CA software stacks, so too can you compile your own browser, publish the code, sign binaries of it and get those signing keys into whatever equivalent of the root store programme would appear. Availability of source code is irrelevant. Establishing trust in your operation is the hard part but you have to do that anyway if you want to get users, just like how you can set up your own CA using a simple GUI on macOS but getting people to actually trust it is a different kettle of fish. Not that there's much chance of any of this actually happening outside of mobile anyway. It's all quite theoretical on desktop. Windows is too far behind on remote attestation tech and the general OS security stance for it to happen anytime soon, especially with so many users not upgrading to Windows 11. But if people want to argue against remote attestation, you'll have to learn how it actually works. Otherwise you're just going to make bad arguments and your opponents will beat you.
- irdc 3y ago> The way this would actually work is something like: websites just "apt-get install browser-keys" (…) Then every so often you do an apt-get update and the latest round of browser/extension signing keys get added. Do you remember when MSIE was the dominant browser and websites started to sniff User-Agent headers to dissuade or sometimes even block visitors using other browsers? Because I do. This will be even worse.