2 ms·
Holdout sounds like it is explicitly added to ward off any criticisms insinuating DRM. If a server is not denying access for clients with no valid attestation
by devsda 3y ago
Holdout sounds like it is explicitly added to ward off any criticisms insinuating DRM.
If a server is not denying access for clients with no valid attestation then what exactly are the servers gaining from implementing WEI?
CAPTCHAs also reasonably prove that the user is a human and legitimate but not all captcha challenges are solveable by humans in one go.
Businesses have denied access for those failures and they just repeat the challenge until the captcha is solved successfully. If the failures are less per client they can easily be treated as tradeoff against security.
What's stopping websites from doing the same with WEI? They can always deny access and repeatedly request attestation until a positive reply comes.
This is acceptable for those "attested" clients where the failures are random and within an upper bound. But a client without attestation can always be denied or they can be shown different limited content altogether.
In both the cases the unapproved clients are at a disadvantage.
- hurutparittya 3y agoI 100% agree with this. But even if holdouts could magically prevent the abuse of this API there is still a massive issue. Once this standard gets wider adoption and it's time to boil the frog further literally all it takes to disable holdouts is editing a single value in the attester code. They will justify it by saying holdouts are no longer needed because 98% of clients are already compliant.