“Web Environment Integrity” is an attack on the free Internet
fsf.org
fsf.org
Google's browser security plan slammed as dangerous, terrible, DRM for websites - https://news.ycombinator.com/item?id=36893071 - July 2023 (63 comments)
Google Web Environment Integrity Is the New Microsoft Trusted Computing - https://news.ycombinator.com/item?id=36888156 - July 2023 (282 comments)
Google employee responds to negative feedbacks on WEI - https://news.ycombinator.com/item?id=36881506 - July 2023 (25 comments)
Google is already pushing WEI into Chromium - https://news.ycombinator.com/item?id=36876301 - July 2023 (832 comments)
Unpacking Google’s Web Environment Integrity specification - https://news.ycombinator.com/item?id=36875940 - July 2023 (431 comments)
Google engineers want to make ad-blocking (near) impossible - https://news.ycombinator.com/item?id=36875226 - July 2023 (468 comments)
Google vs. the Open Web - https://news.ycombinator.com/item?id=36875164 - July 2023 (191 comments)
Apple already shipped attestation on the web, and we barely noticed - https://news.ycombinator.com/item?id=36862494 - July 2023 (421 comments)
Google’s nightmare “Web Integrity API” wants a DRM gatekeeper for the web - https://news.ycombinator.com/item?id=36854114 - July 2023 (456 comments)
Web Environment Integrity API Proposal - https://news.ycombinator.com/item?id=36817305 - July 2023 (441 comments)
Web Environment Integrity API - https://news.ycombinator.com/item?id=36808231 - July 2023 (2 comments)
Web Environment Integrity Explainer - https://news.ycombinator.com/item?id=36785516 - July 2023 (45 comments)
Google Chrome Proposal – Web Environment Integrity - https://news.ycombinator.com/item?id=36778999 - July 2023 (93 comments)
Web Environment Integrity – Google locking down on browsers - https://news.ycombinator.com/item?id=35864471 - May 2023 (1 comment)
You know, I hardly ever see those things.
They come up as part of a challenge-response when the server thinks your traffic is sus. I generally avoid them by staying logged in, not blocking cookies, and not using Tor or another route obfuscator.
(BTW, the "server" is very often a reverse proxy hosted by Cloudflare that decrypts your connection to the actual server by design. In all likelihood, there's more data mining done there than we're made aware of :)
Which sounds great until you leave your cozy little corner of the first world and discover that millions of people are behind CGNAT.
Besides, Google doesn't need help in picking out pictures of motorcycles or buses or bridges.
It doesn't need to know that your selections are "correct", only that they match responses given by most other users.
My intent was to disabuse the notion that captchas are how Google trains for image recognition.
I expect the idea is the same with images, if there are 4 buses I expect 2 it knows are correct and used as a sanity test, 1 it's pretty sure it's correct (from majority of users selecting it), and 1 has some heuristics that might be a bus but it is currently testing to see whether users believe is or not. Similarly with the 5 not a bus images.
https://httptoolkit.com/blog/apple-private-access-tokens-att...
https://blog.cloudflare.com/eliminating-captchas-on-iphones-...
Some interesting bits:
> [...] We don’t actually need or want the underlying data that’s being collected for this process, we just want to verify if a visitor is faking their device or user agent. [...]
> [...] In the example above, a visitor opens the Safari browser on their iPhone and tries to visit example.com.
> * Since Example uses Cloudflare to host their Origin, Cloudflare will ask the browser for a token.
> * Safari supports PATs, so it will make an API call to Apple’s Attester, asking them to attest.
> * The Apple attester will check various device components, confirm they are valid, and then make an API call to the Cloudflare Issuer (since Cloudflare acting as an Origin chooses to use the Cloudflare Issuer).
> * The Cloudflare Issuer generates a token, sends it to the browser, which in turn sends it to the origin.
> * Cloudflare then receives the token, and uses it to determine that we don’t need to show this user a CAPTCHA. [...]
Sounds an awful lot like WAI to me, but at least it's called a "Privacy Access Tokens" so it surely must be good...?
EDIT: turns out there was an HN thread about this a few days ago, I just missed it: https://news.ycombinator.com/item?id=36862494
(I know web APIs can't directly prevent those things, but they might be able to let a site determine whether a user is doing something to prevent CSS or Javascript tricks from preventing them.)
What does it mean to fake a device or user agent? Their intent is probably devices and user agents who say they’re one thing but are actually another. But browsers have been lying about who they are for decades. And what’s the difference between a fake device/UA and an unusual device/UA? Probably none, as far as they’re concerned.
Google's PR strategy is to say "no need to worry, it's just like this Apple thing". But as Google themselves note in their explainer¹, they're quite different, and Google considers PAT insufficient for the kind of enforcement they intend to do.
For example, PAT is ultimately just "not a bot" attestation and so doesn't involve the exchange of device and browser environment data. In contrast, WEI needs that data to enable the kind of "DRM for the web" use cases we're reading about.
https://github.com/RupertBenWiser/Web-Environment-Integrity/...
Companies are doing all the can to create Walled Gardens after watching Apple's success. And to a lesser extent seems Corporations are starting to influence the direction of Linux Development. I wonder when will have full embedded DRM, validating streaming sites.
https://www.linuxjournal.com/content/diff-u-kernel-drm-suppo...
People DO-NOT-GIVE-A-SHIT. Because there are bigger problems, like "what the fuck am I going to pay the rent with tomorrow", and more entertaining spectacles, like watching a person pretend it's an NPC for 5 hours straight and give them money for it.
And I feel a lot of the people I have worked with are the same type of individual, used to realizing they are getting screwed sideways, addicted to complaining, but only as long as it's among a very select group of individuals sharing common interests.
It's the most draining type of revolution. Nothing ever gets done, fucks are handed left and right: DNS, JS-fiasco, web neutrality, browserland... And we always just kick the buck and revisit the good 'ol days on another thread further down the line, once no other rights are left be destroyed...
And yet, what am I going to do? reject the PR?
They pivoted to cloud services and their server products still do robust business.
Google's address is 1600 Amphitheatre Parkway, Mountain View, CA 94043.
Which, hey, if you think that's worth it, it's a free country and I can't tell you not to. Maybe you'll convince a front desk receptionist to petition the temp agency she works for to change companies.
Google maintains a physical address because Googlers sometimes order packages and it's a legal requirement so they can be served formal court papers. That's it.
1. Contact antitrust authorities: https://news.ycombinator.com/item?id=36880224
2. Use a template: https://news.ycombinator.com/item?id=36881511
3. Provide Google's address to the authorities: 1600 Amphitheatre Parkway, Mountain View, CA 94043.
you are upset so.. empathy on that, first. Please consider that the pressure of the situation somehow escalates blame on exactly the people who are not doing this.
Consumer electronics users are not the ones who "vote" on the content. Closed-box computer systems with hierarchical, private and internal decision making, are arriving at decision points.
You know what Google fears most? Being broken down. If they push for this, we can organize calls to our representatives and raise our concerns and call for regulations and/or breakdown of Google's anti competitive behavior.
Activism isn't restricted to the real world, or to "regular" people.
What exactly is this supposed to mean? All we have to do is control the government and the industry that we're complaining about, and we can win? They already have that. Doesn't that mean they already won?
> Keep that up and push for other companies to reject it or for regulation to stop it.
They are being paid to push in the opposite direction. You are paying to try to defeat them. Each of their victories brings them more money and influence, each of yours means you have to reset and construct an entirely new argument to defeat the same thing again, differently worded. The outcome is obvious.
And in this special case, Google needs no approval to take the web, because they bought Firefox and cooperate with Apple. There is no pressure that you can bring to a politician that will counteract the campaign funding, or access, or future employment, these awful companies can offer.
edit: This is a "why didn't the slaves all get together and end slavery" type argument. It's not cynical to resent the suggestion of the same tactics that have failed before so many times. Our problem is government, not any particular company.
Nobody controls all of the industry or all of the government. Half the people on this site work in the industry, often in prominent companies in a position of influence. Many of them own a major stake in a prominent startup, or operate a community with a large number of users.
Legislators care about whatever they think voters care about, and use voters calling them as a proxy for this. Don't pretend this doesn't matter.
> They are being paid to push in the opposite direction. You are paying to try to defeat them. Each of their victories brings them more money and influence, each of yours means you have to reset and construct an entirely new argument to defeat the same thing again, differently worded. The outcome is obvious.
Every time they do something like this, another person gets pissed off enough to extricate the perpetrator's services from their life even if it means re-implementing some of them themselves, and then post what they used to do it on Github. Which makes it easier for the next person to do it.
Some of them even find a way to make a business out of it and make money. I know it's not a popular belief, but it's actually possible to build a sustainable business by giving customers what they want for a fair price and not screwing them over -- businesses may find that customers even prefer this.
We're not all connecting to AOL using AT&T Unix(R) on Itanium. Why not? Those companies had real power. How did they lose?
> This is a "why didn't the slaves all get together and end slavery" type argument.
Your argument is what, that no one should make any attempt to end slavery because the slavers have too much power?
No, you keep fighting until you win. Be creative, coordinate with like-minded people. This is not a community of powerless victims. There are people who hate this who have money and skill in surplus. It's not illegal to do something which is net negative for you but net positive for society purely out of altruism, or anger, because it's your life and you get to choose what you do.
Reallocate the time you spend advocating defeatism to building something which is a threat to the people attacking you.
My question reading, assuming it’s main purpose is preventing as blocking, this is whether my pinhole dns blocker would be affected. If the new standard is dns blockers for everyone that’s an improvement in the landscape, at a small cost to the users.
There is little adoption or support of privacy tools when there is no need for it and we trust our systems to be free and open, everyone is a tinfoil hat wearer until they aren’t and the boundaries have shifted. People should generally have better understanding of personal data protections, control over their services and the like but we are lazy until there is no other option but to take back control.
People do care, but there are steps to creating public pressure. The public needs to become aware of the issue, to learn and understand the technical aspects of it, and to organize opposition. This is not necessarily a quick process.
This really isn't just Google. They apparently just want to be the first.
This is what the "conspiracy theory" about the digital lockdown (i call it that) is about. It's one more step in that direction and from the looks of what this does, we're getting too close to the destination.
Fine, I lived without Internet before ... installed Microsoft Flight Simulator from floppy disks. Will be a little more floppies this time, I guess. No big deal.
And no, you can't just go back to playing flight simulator off of floppies. Your bank, your airplane and concert tickets, heck even your child's pediatrician will require it. Not that doctors are hungrily reading up new web specifications, but they'll be using a medical services platform that relies on some cloudflare defaults that all the security guys like because it cuts down on bots and DDoS.
You'll be left using walled garden operating systems that spy and advertise as incessantly as cable TV.
Maybe a big stink will cause Google to backtrack a little, or make promises they won't and can't ultimately keep. The only real solution is to use the government to prevent users from losing control.
They could have stopped Linux support from Chrome at any time, or not created it to begin with. Plus there are lots of people at Google who are using Linux, not to mention Chromebooks which are built on it.
There is no reason to think that Google will kill Linux support with this or any feature.
Specifically, ChromeOS running the google-signed, untampered, OS image
Lets all use chromium-based browsers!
What could possibly go wrong?
XD
So "Your bank will require you to login with Edge on Windows 11, or with their smartphone app."
The social concern enabled by the tech concern is that we might see, say, Google go "GMail can only be accessed by a browser running Chrome," and they lock-in their market dominance not on quality of the application but on network-effect necessity of installing it to access your data.
Google can do that right now. They don't need attestation to do so. They can take gmail off the web and build it into Chrome itself.
Wait until they implement verification cans :)
It is normal for proposals, even very early ones that are not accepted, to be implemented before becoming a standard - that way there's an actual implementation to point to when saying "and it would work this way".
It isn't "proposal first, implementation later".