4 ms·
Youtube can and in some measure is already doing it without this new API. If google wanted to be sneaky they can provide whatever data they want to Youtube alon
by cowl 3y ago
Youtube can and in some measure is already doing it without this new API. If google wanted to be sneaky they can provide whatever data they want to Youtube alone without making it a public standard. you see how all of these fears are contorted reasoning because you want to try to find something wrong with the proposal because all fo your fears do not require this proposals and would be easier and with much less backlash without a public standard API.
- choeger 3y agoYeah right. "Don't worry, the leash you'll be wearing is a public standard.". You're either paid or delusional.
- zb3 3y agoHow can they get hardware attestation right now? They can't, that's why WEI is proposed.
- cowl 3y agoChrome has access to all kind of hardware information. they could have implemented that hidden in Chrome without all of this dust raising for a public Standard that gets scrutinized by everyone. Note that all discussion about chain of trust is there only because of all actors involved in a public standard, in case they wanted to just do this themselves they would just trust whatever the hidden chrome api would answer and that's that. much simpler, total control, no noise. For all that we know all kinds of closed source software are already doing something like this (especially ones who do a lot of natural network traffic so you cant even distinguish from the capturing raw data what is legit and what not.) For example, Netflix allows you to download a movie from their native apps but not from the browser, this is only because in the native Apps they have access to all kinds of hardware information and they can attest themselves about the "environment"
- zb3 3y agoHaving access to hardware information doesn't imply being able to transfer them to websites in a trusted way that the user can't modify. Chrome runs in the userspace, whereas I can write a kernel module which chrome can't interfere with (I did that for widevine in 2017!) that will emulate/lie to chrome about the hardware I have, and there's no way that the website owner could know whether I lie or not (this might require some effort on my part, but it's doable). Hardware based attestation was created precisely because the software based one can be bypassed.
- cowl 3y agoIn what universe do you live that Google or anyone else should device this complicated scheme to just capture 2-3 people. Linux has only 3% share of the users. of those maybe 0.1% could write a kernel module (or even install one) and of those maybe 1% would be maniac enough to dedicate time and effort to it just to "stick it to the Pawaaa" Google could accomplish all of their supposedly nefarirous goals by just ignoring the linux users. Do you really think they are going through all this trouble to make sure that they deliver adds to those 2-3 people? I can already see the next earnings call, "adds impression targets increased by 2". Notice again the Netflix example. They just don't have a linux App and you cant legally view Netflix movies offline in Linux. it's cheaper to ignore linux users. like it or not, that is a fact. outside of Linux, if chrome were to provide an API, for hardware information it can be completely trusted and even in linux case I would say that it still can be trusted with 99.99% confidence.
- zb3 3y ago> Google could accomplish all of their supposedly nefarirous goals by just ignoring the linux users. No, because in order to ignore linux users you'd need to know that the device in question is actually running linux. But then again, I can run a windows VM inside (sure, this might require effort to patch the windows inside), with no need to write a kernel module because this time I can introduce custom logic in the VM which the virtualized chrome-on-windows process will not be able to interfere with and with enough effort, they have no way to tell whether this setup is "legit". Of course this will be legit in 99.99% cases, except that the 0.01% case is precisely what causes the damage (bots, fraud, piracy and so on).