4 ms·
>is very much worth worrying about as a direction of travel, but not without context What's the context where WEI could be seen as a positive?
by veave 3y ago
>is very much worth worrying about as a direction of travel, but not without context
What's the context where WEI could be seen as a positive?
- flangola7 3y agoVerification that online communication is a human and not a bot. In short order it will not be possible to know if the person on the other side even exists unless there is a highly reliable "humanness" indicator. We are almost there for live text and audio communication, and video is advancing swiftly. The FBI has already put out alerts about scammers and other evildoers calling people using the voice of their family members.
- 3LazTjBv-f 3y agoHow exactly does it stop bots? At best it stops everything, but full blown browsers, from communicating with web servers (that includes `curl` and web security scanners). Even if it kills stuff like Selenium, bots can just use mouse/keyboard input. Unless we go all the way, and require DRM in every piece of hardware, so for example "Rubber Ducky" no longer can claim to be a keyboard. That would be more restricting than current MacOS.
- flangola7 3y agoThe OS could have software that detects if bot-like input is occurring. Even if not, they could just rate limits how fast you can make requests to a speed that's plenty for any legitimate user but terrible for bots. If someone wants to astroturf as a million people on social media, they will need a million physical motherboards and a million genuine licenses of Windows, and a million rubber duckies programmed not to act too fast or too continuously. No more Xeon blades with a fat WAN pipe running a credentialed script. I actually don't know if input devices still don't have TPMs or not. I know display devices do - try watching Disney+ on a CRT, or even an old HDTV. You'll get a nice error message saying your display is too old and unsupported.
- 3LazTjBv-f 3y agoWell, enterprise VPN clients have build in similar attestation[0]. So probably there are cases when it could be useful in browsers. The question is not if there are use cases, it is "can we stop all websites from requiring it?" and the answer is no. [0] The Linux support for that goes from "bad" (check `uname` for version kernel) to none. At least with one client I had to use copy of "system report" file from Windows machine and it worked. Makes me wonder how much of it is just security theater.