3 ms·
> if you for example would trust let's say Opera as the attester, Opera would need to trust windows or Linux or Android as the OS attester. But it's not the u
by trogdolon 3y ago
> if you for example would trust let's say Opera as the attester, Opera would need to trust windows or Linux or Android as the OS attester.
But it's not the user ("you") deciding which attesters to trust - it's website operators. And they will choose to trust only attesters that meaningfully (cryptographically) verify the user's client environment, including the secure boot chain, OS, and browser. Otherwise the attestation can be spoofed, in why case why would they bother using the EnvironmentIntegrity API at all?
- meragrin_ 3y ago> But it's not the user ("you") deciding which attesters to trust - it's website operators. You know what? They are already doing it. This just gives them another option. > And they will choose to trust only attesters that meaningfully (cryptographically) verify the user's client environment, including the secure boot chain, OS, and browser. Otherwise the attestation can be spoofed, in why case why would they bother using the EnvironmentIntegrity API at all? You might as well complain that any website requires any sort of authentication or authorization. How is WEI any different from all the other current methods which have not killed the "open web" in the way the hysteria over WEI is claiming?
- zb3 3y agoThose methods didn't kill the open web because they could be bypassed, and that's precisely why WEI was proposed.
- meragrin_ 3y agoReally?? Mind telling me how to access Netflix, Disney+, or any other streaming service without authentication/authorization? I'll take the information on banks too.
- zb3 3y agoWhere did I say you could access these without authentication? Nowhere. But I can still access them with my device being controlled by me, I can create bots/extensions to export and archive content. I can because there's no reliable method to identify whether my device acts in my interest, so they have no choice - they have to restort to methods that can be cracked. WEI is an attempt to introduce that reliable method. Sure, there's EME with Widevine L1, but this is currently limited to providing media content, not apps themselves. That's why WEI is considered the DRM for the web.