Google's browser security plan slammed as dangerous, terrible, DRM for websites
theregister.com
theregister.com
And how about asking customers to pay $50 license for Android when they buy a smart phone? Or an annual fee, for updates and maintenance.
I mean, those payments are already done, except they are currently obfuscated because we only see the purchase price when we buy a phone, not the money passed under the table in exchange for yielding our privacy.
Yes. Though they could fundraise also using other methods.
On a less cheeky note, I’m all for breaking up Google but the reality is that outside of this small tech circle nobody cares. People like the current system and they have no problem with web DRM either because if anything it might benefit them (no stupid captchas for example).
1) Netflix restricting password sharing 2) RedHat pushing the limits of the GPL to restrict RHEL re-distribution
In some ways, I think this could be a good thing, in that it clearly separates the advertising funded web (the commerical web) from the altruistically funded web (the free web). Maybe with a little luck, the free web becomes something more akin to the web circa 2000 even it has alot less information. That might be better than the open sewer of a web that we have today.
WEI gives too much control to browser-making big tech companies.
Should browser-making big tech companies get to control your computer more than they already do?
You could just not visit any of those sites.
Want to visit this website? Is your webcam on? Has it been switched on for at least 4 hours/day on average. Do you have Meta written on your forehead as you smile?
If not, forget it buddy, are not getting in.
Have you installed this .exe file? No? Hit the road.
Either people will complain that the tangible example is narrowly scoped, or people will complain that the topic is abstract nerd bullshit will no real-world meaning, it won't actually change anything, and insinuate having an opinion about it is cringe.
This happens in every fucking conversation on this website about the technical details of a technical coordination (protocols, formats, platforms, interfaces, etc...).
Google is the tail wagging the dog. Everyone knows it. Maybe it's time we all give up on the fantasy of technology as an enabler. Just accept that everything will be maximally locked-down and we should only see it as something to interact with when absolutely necessary. Accept that bland cable tv-esqe milquetoast culture with some playskool business collab tools bolted on is the fate of the internet.
A blogger - I think The Last Psych - said that technology will be the biggest disappointment since the death of god. I think I understood his point 5 years ago. Recently though, I agree.
Firefox is the most obvious alternative, and for those who prefer a Chromium base: Brave, Iridium and ungoogled-chromium, in order of how much functionality has been stripped away from least to most, are open source, privacy-focused solutions.
I'm so sick of this bullshit. AMP, Manifest V2, buying their way into every corner of the web, ...
In the meantime, please call your legislators and regulators. Tell them Google's too big to be allowed to have a web browser and that one solution is splitting out their business units.
It's hard to support a heterogeneous space of user agents running on a heterogeneous set of platforms. Eventually, abstractions break and you end up with a weird bug that only manifests on such-and-such browser in so-and-so configuration.
How much easier life is if you only have to support a few browsers on hardware that checksums to have a known-good configuration...
Chasing down render errors in the deep interactions between declarative HTML rendering and an esoteric-but-important hardware / software configuration is drudgework.
Some of my best ideas even, came out of clearing drudge.
Google employees are the ones writing this code, doing the designs, the QA, the project planning.
You can't expect the people who work for these companies to do the right thing. Time and time again, it requires outside forces. Either customers or legislation.
Gen Z knows nothing of what the web was once like, and lots of folks now embrace companies being stewards of the commons, eg. Apple App Store.
There's also the current down hiring market and macro economic conditions.
In hindsight, perhaps none of us should have been surprised the latter was a better proposal for most people.
A commonly repeated concern is that if WEI is implemented, banks will leap on it and it will become infeasible to do online transactions at most banks without either using a WEI-blessed software / hardware configuration or the bank's app in a commercial app store.
Banks are lazy, they shouldn't need to rely on infrastructure of commercial app stores, blessed devices since they've already proven they could develop it themselves (chip cards, dongles, time-based one time codes, etc.).
WEI is mainly aimed at suppressing the unauthenticated noise, when reading a signal from GET requests (ie tracking) that was never meant to convey any information beyond what is asked for, in the first place.
I'm not really seeing how we're reaching that conclusion. Suppressing GET request noise isn't any of the use cases described at https://github.com/RupertBenWiser/Web-Environment-Integrity/...
Some examples of scenarios where users depend on client trust include:
* Users like visiting websites that are expensive to create and maintain, but they often want or need to do it without paying directly. These websites fund themselves with ads, but the advertisers can only afford to pay for humans to see the ads, rather than robots. This creates a need for human users to prove to websites that they're human, sometimes through tasks like challenges or logins.
Ie.: To make sure that ads are only delivered to actual living humans bothering them with a login, payment or CAPTCHA and heavily invest add-blocker detection arms race, they want the web client to attest that the genuine user actually saw the ad.The rest of the time I can use a non-WEI browser and the sites that lock me out would probably be doing me a favor.
Conversation over here about the actual slamming: https://news.ycombinator.com/item?id=36881506
Screw the post-1999 Internet.