Google’s Plan to DRM the Web Goes Against Everything Google Once Stood For
techdirt.com
techdirt.com
It's pretty clear how to break up Alphabet, because it grew mostly by acquisition.
- Google - search, ads on search pages and nothing more.
- DoubleClick - third party ads on other sites.
- Analytics - services to web sites.
- Cloud - the money-losing data center service. Probably gets sold to AWS or Hurricane Electric.
- Android - phones and similar devices
- Chrome - browsers
- YouTube - streaming content. Probably gets sold to Netflix or AT&T or Comcast.
- Waymo - self-driving cars. Probably gets sold to a car company.
- Alphabet - all the other stuff.
Now, some of these have conflicting interests. That's a good thing. With Chrome separated from Google and Doubleclick, and forced to fight for market share, it's not in Chrome's interest to prevent blocking ads from DoubleClick or Google. Google wants people to see ads on search pages, while Doubleclick wants people to leave the search site and see ads elsewhere. Now there's competition.
Antitrust action against Google is already underway. The State of Texas and several state attorneys general have a case pending.[1] There are other cases.[2] All these cases benefit from Google's move to entrench their monopoly by technical means.
So make lots of noise politically about that. It's quite likely to make Google dump this proposal, on the advice of their antitrust lawyers.
[1] https://www.bloomberg.com/news/articles/2023-06-05/google-an...
[2] https://www.lanierlawfirm.com/google-antitrust-lawsuits-expl...
On thing I feel we are still missing is for FSF, Wiki, Archive.org, etc. to effectively gather enough cash to start lobbying in politics and in industry much in the same way Meta and Alphabet do. Politicians/legislators are ridiculously cheap to lobby in the grand scheme of things.
This is a consequence of Google's structuring. If the pricing is unrealistic after a split, it's also currently an example of price dumping preventing competitors from emerging.
If you don’t charge a normal price for something anywhere, then it’s just a loss leader (costco hot dogs).
Whether a company crosses the line is defined by the impact it has on the market: if a company with enough market power uses that power to damage competitors, then this is deemed predatory. And, when it comes to Google, their history of leveraging their dominant lines of business to force an advantage in new markets, including via pricing, makes a good case for this.
If some spin-offs of a Google antitrust can't swim, let them drown.
I think the trick there is that you legally have to show intent. One could argue that anything a market leader does to grow or even just retain it's market share hurts the smaller competitors.
Android is also a weird case. All funding is coming from Google, but the revenue isn't coming from licensing of the OS. Separating out Android and require manufacturers to pay a license wouldn't kill it at this point, but it could fragment the Android market. Like with Chrome, Google isn't the best steward, because their interests are primarily data mining and advertising, but building the best mobile operating system.
DoubleClick, analytics, Youtube and search are the divisions I'd go for if I where a regulator, but there where would Chrome and Android go?
They'd only have to pay for Google services like the Play Store. However half of them would now belong to a different company and I don't know if the Play Store would be self sustainable on it's own?
Samsung already has their own store, smaller ones will probably still stock to the Play Store for the time but increased fragmentation would be unavoidable.. That might not be a bad thing on its own, however I don't see how/why anyone would continue funding the development of the open-source bits of Android to a degree Google is capable now.
If all they wanted was high quality browser imagine what Apple and Google could have done if google hadn't forked webkit.
In the 1900s, Teddy Roosevelt busted up the biggest monopolies and did it boldy. He was a strong believer in capitalism and market forces, and he believed that government had a responsibility to keep market forces working well.
I know we are not in the early 1900s anymore, but I think it is interesting to ponder how the only politicians who dare to say something similar today are the furthest left we can imagine (Bernie Sanders and AOC and the like).
We still have the antitrust laws of Teddy Roosevelt's era, the Clayton Act and the 1890 Sherman Act.
Sherman Act, Section 2:
"Every person who shall monopolize, or attempt to monopolize, or combine or conspire with any other person or persons, to monopolize any part of the trade or commerce among the several States, or with foreign nations, shall be deemed guilty of a felony."
The US Justice Department hasn't often applied that standard rigorously, but it can if it wants to.
Also thankfully general regulatory situation (and arguable level corruption) isn't as quite yet as bad as it was back in the 1900s.
What I fail to understand is why it's better for society to support these "to big to fail" companies. Why not break them up. Why not plan break them up if they become to "important" for a lack of a better term? How can you not see it as a political failing that taxpayers have to be ready to save a company, just because you failed to bring it under control?
It's mind boggling.
For example, JPMorganChase is “the” big bank lately. It was able to handle the acute financial crisis this year by providing liquidity and a buyer as needed to keep the system from ever losing a deposit. That was likely bad for them as a business, short term, but it happened because the regulators can call up a single organization and get what they want.
Big tech has similar (unrealized) opportunities to keep strategically important things going. One possible example is the ease of releasing the Covid contact tracing system. If there were 20 fragmented parties they may never have aligned.
You can't see what's happening though, because JP Morgan "mistakenly" deleted 47 million emails. [0] Their fine for that came to about 12 minutes worth of revenue.
They "failed" to keep records, firm-wide, right to the top. [1] Again, their punishment was at the "cost of doing business" level.
We're talking about the bank that financed and enabled Epstein here [2].
There are other ways to provide liquidity without relying on these ghoulish overlords who manipulate global markets [3] and finance blackmail operations.
0 - https://www.reuters.com/legal/jpmorgan-chase-is-fined-by-sec...
1 - https://www.sec.gov/news/press-release/2021-262
2 - https://trendingpoliticsnews.com/breaking-attorney-general-t...
And the money is coming from where? Chrome exists mostly, so the ad buisness gets more data and they can influence the direction of the web.
Seperate that and there will be no more chrome as there is no other source of income. (Except maybe a little bit from ChromeOS).
Otherwise I get it, it is mostly politics to threaten google to reach this.:
"It's quite likely to make Google dump this proposal, on the advice of their antitrust lawyers."
But a breakup of google(alphabet) is something very unrealistic and actually not something I want to see, unless we also break up Microsoft at the same time. Otherwise we end up with Microsoft dominating the web again. No thank you, I still remember those times.
Yeah, with tracking and ads from the browser enabled by default and by now allmost non existent marketshare. The money from ad companies does not come with no strings attached.
(But I still use Firefox btw.)
This doesn't sound like a good idea if your goal is to prevent these two companies (or divisions of the company) for co-conspiring.
Microsoft surely will continue to develope edge. That is my main issue with this thing, because they surely would like to be the one with the dominating browser again and if google has to drop chromium, Microsoft will just overtake it.
Antitrust and breakup is not a simple thing to do right.
What apple has done with browsers at least seems more egregious. Windows didn't stop you from installing a different browser, ios does. There was even a long running joke that the only good use for IE was to install a real browser.
It wouldn't be hard to find a reason to sure Microsoft though. Take a look someone at where the legal text states their software builds were made and ask what tax benefits one might get from running production builds on servers in the Caribbean.
If a bunch of websites suddenly required Edge on Windows to view, they'd lose a majority of their visitors.
But they do it any way they can. I never intented to open edge even once, but through various sketchy things, I had it open way too many times.
(when you click on the "learn more about this awesome landscape" - you land in edge, open a pdf, edge, saved a mhtml in chrome and open it, edge again. Search for chrome on edge? It almost tries to block you from downloading it.)
Meanwhile, all of us not using MS platforms (Linux, Android, MacOS, iOS) don't see any of this.
MS only has power over you because you choose to give them that power. They have no power at all over anyone not using an MS OS.
There are indeed the end times. I just saw cats lie down with dogs.
Where exactly did you get this idea?
It runs fine on both Chrome and Firefox on desktop, including voice, camera, screen sharing. They also have desktop apps, including a .deb for Linux (since it's ultimately just an Electron app).
Well, perhaps "runs fine" is not exactly the right word for what Teams does, but it's as awful on every platform at least.
Plainly wrong. I use MS Teams at work too. My machine is running Debian. No, I sure as hell don't have Edge installed on Debian; I use it in Chrome.
I suspect judges that just ordered an antitrust would not be kind to people to people who essentially ignore the order by recreating an informal structure.
It's important to keep things mentally separate here. There is nothing anti-competitive about remote attestation, no more than there is about TLS. It's just far too general a tool for that. Even much more restricted versions as used by the smartphones, games consoles, Windows managed network security etc have never been claimed to be anti-competitive. That would be a very novel legal theory that's unlikely to work on its own (you can use the tech in ways that are anti-competitive, but it needs someone to actually do so).
So if Google were to be broken up, it'd have to be for wider competition and market health concerns, it wouldn't be to do with any specific API getting added to Chrome. And then if they were split up, they'd need to formalize arrangements in contracts that are today informal, like how Chrome is funded exactly. At that point, do you think the newly born AdCorp will just accept paying lots of money for ad impressions to Chrome when the users aren't going to see them? Google tolerates it today for a mixture of reasons e.g. a lot of their own staff use ad blockers, they want to be able to recruit very widely for many different projects, etc. A company specialized only in advertising would have fewer such concerns and could easily demand more aggressive measures, indeed, their new shareholders might insist upon it. Whereas today Google isn't really susceptible to stockholder pressure and is willing to let a lot slide.
2. Your theory was basically proven broke by the fact that ATT which was broken up in anti-trust, became ATT, again.
And the result of a ruling is a court order to do something. Sure, "ordering an antitrust" is a bit less precise than "ordering a series of actions that result from a successful antitrust prosecution", but I was hoping it to be clear enough.
My point was that judge do issue orders, and they really don't like people finessing around the wording.
Browsers are complicated, but let's not pretend that that kind of money wouldn't be enough.
Theoretically this money should be enough to finance the continued investment in Chrome.
Rendering a website should not be a huge project. Websites are a medium for transmitting ideas; communication. A communication scheme that requires a massive engineering effort to interpret it is bad. A web browser should be something that a small community team can throw together in a couple months.
That figuring out the funding required to draw a website is seen as a big issue is a symptom of the problem.
This isn't the 90s anymore. Smartphones exist, where Microsoft is irrelevant.
This is their business problem, not ours.
Since Chrome, the browser, is in some way a new OS paradigm we can think that the open source community would take it seriously to build a new one and/or improve/fork Firefox in the same way we have Linux, OpenBSD, FreeBSD, NetBSD, etc, etc. I think the main issue is UX/UI where the open source community doesn't excel, yet.
Within Search + Search Ads you have a platform where Google are/have:
- the sole vendor of a digital asset - ads
- the sole marketplace for that asset
- a closed algorithmic trading system with no public auditing
- no public ledger or auditing showing who bid what
- currently one of the main customers for those ads (advertising their own products)
Along with that you as an advertiser have to install tracking on your site allowing Google to see every transaction, all revenue, every customer, of your business. The level of spying on the advertisers is insane, when seen in combination with the closed source algorithm and market for the ads the potential for manipulation is enormous.
The whole ads platform is built for extracting every last cent of margin from advertisers businesses. It's anticompetitive, monopolistic, and to some extent even a protection racket.
The most important "breakup" needs to be the ads business from everything else, including search. That's going to hurt, and I don't have the answers to how to make it work, but changes are needed.
I suspect a "breakup" isn't on the cards, maybe some strong regulation of online ad marketplaces, ring fencing them from the rest of the business and auditing of the platform?
You can be happy then.
https://www.justice.gov/opa/pr/justice-department-sues-googl...
The press release doesn't mention it, but the actual court document asks the court to:
"Order the divestiture of, at minimum, the Google Ad Manager suite, including both Google’s publisher ad server, DFP, and Google’s ad exchange, AdX, along with any additional structural relief as needed to cure any anticompetitive harm"
What if maps only took you to places where you have a loyalty card - or the places that currently have discounts on things in your shopping list.
Give it the right marketing spin and people would love it.
The index should be treated as a utility like water or electric that search engines purchase access to for a regulated fee.
You can then have a thousand competing search engines started in garages with their own ranking algorithms and ads but realistically there are only ever going to be a few indexes. Thats the part that requires enormous data centers and dedicated power stations to run.
The intra-engine competition, meanwhile, would drive up results quality. Search engines would rise and fall on their own merits rather than on the basis that theyve got access to the biggest index.
If/when business was unavoidable between two offspring companies, at minimum, I would expect them to have to inform the FTC, justify how it was unavoidable, and make the details of the transaction public. If someone complained that it wasn't unavoidable, quite possibly there would be additional penalties leveled on each of the participants.
It's not like some Monty Python character waves a wand and declares "you're not n different companies", only to wander off and never exercise oversight. Mind you, I don't think there's enough political capital in the world to manage to break Google up, but if it did happen then the judgement will have the teeth to make sure they're actually broken.
The separate pieces would not be able to engage in business together that constituted a combination in restraint of trade, because that’s illegal whether or not they are breakuo siblings. Breakups turn what used to be sole company actions into combinations, which, in and of itself, adds legal complications.
(Also, as soon as the ownership diverges at all, which will happen almost immediately, between the siblings, a lot of things that are problematic for market effects would also be breaches of fiduciary duty on one side or the other.)
And all of this leaves out the explicit targeted constraints that would inevitably be part and parcel of any breakup order.
That said, AT&T/Bell was broken up in 1984. The "Baby Bells" had all merged back together into 3 different companies (AT&T, Verizon, Lumen) by 2000. So there would need to be better protections in any potential breakup of Google or any other company today
I hate web advertising but it's the model we've got so bear with me.
Once third party cookies are back on the table it helps level the playing field. Programmatic advertising becomes profitable again and all those small players can get back to competing. Only this time they're just competing with each other and doubleclick.
Maybe momentum carries forward and third party cookies are eliminated anyway (such faith in humanity). If that's the case then once again the playing field levels a bit more and everybody is working with the same blinders on.
Search will still be awful because of google.com's market share and its enablement of click bait and echo chambers, but search will always be awful and five years from now everybody will have their own LLM instead of search anyway (and five years after that LLMs will suck because there's no new data to train against but that's another rant).
Analytics will change a lot. Google not legally being able to integrate the data it scrapes from GA into its own products means that there's a lot less of a reason to stick just with their ecosystem. They'll still lag behind as far as privacy goes, so third party analytics providers will actually be able to get their toes in the door.
Anyway like you I agree that a breakup probably isn't going to happen. Most of the people who would legislate a break-up don't even understand the internet or what alphabet is, or what google does.
It's actually perfectly fine to lose money; you have to invest before you can start making a profit, and services like Google Cloud can be money printers once they're established.
But all the cloud providers are competing hard, pumping money into 3rd parties / partners that will then sell it and set it up at companies. I was at one company (a famous flower exchange in the Netherlands) that was in the process of moving all their workloads - hundreds of services, from people's office suites to high volume exchanges - to AWS, and I'm confident that the one guy, the new manager of the IT department, has Connections with Amazon to help sell AWS to companies like this. Because once they're in, it'll cost millions and years to move out again; I don't think many companies will do a sideways step often and move from e.g. AWS to GCP.
They are not competing hard enough. (Or maybe they competing too well? I don’t know)
I used to work for AWS then Azure, and now just do consulting for both. The amount of companies I come across with the chief complaint of “We pay too much for AWS/Azure” is staggering.
In a healthy market with healthy competition, you’d think that would never be a statement to be made. No one says “I pay too much for Chevron, I’ll only buy gas from Total”
AWS, Azure, (and wth) GCP are in the tech support business, not infrastructure resell business. You’d think a cloud only need to sell VMs but there is literally no money in that. That’s the part that “competes hard” also the losing part. As a cloud provider, you want to be out of that shitty business. You want to be SaaS. SaaS is the magic work in Cloud. Selling Software is magic. It made Microsoft in the 80s/90s. It made Oracle in the 90s/2000s. It made Google in the 2000s. Selling software is an incredibly lucrative business. It is where you want to be.
100% of companies I consult for don’t spend money on VMs in the cloud. They always spend it on “log analytics” or “data warehouse” or “serverless”
Why hire a Postgres admin when you can pay AWS/Azure 200k a month for postgresql “managed” offering where you can email them whenever things are not working and have _them_ hire the Postgres experts who would look at your usage/queries/tables and suggest an index here, or a stored proc there.
It's not fine if you use a monopoly in one area to buy your way into another. That's one of the core tenets in antitrust (back when it was being enforced, at least).
The consumer price doctrine (all that matters is what consumers pay, whether by a large monopolist or deep competition doesn’t matter; pick the best for each situation) is seductive: after all the whole point of government, at the end of the day, is what’s better for the people, right?
But lazy analysis meant just imagining the immediate price change for consumers; long term factors like supplier resilience, innovation, supply chain fragility et almare ignored. Also ignored is the reality from empirical data: permitting or even endorsing monopolies ends up with higher prices not lower.
With this thing it is the same. The problem is: nobody will care. And I think everyone who should care will look away again, because it is just too complicated to explain.
The core problem is that a minority raises this concern and this minority is not loud enough. We really need to nag out banks etc if they do not allow to use de-google Android. There should be public visible lists of the few 'good' guys left. Not even tech magazines seem to pick up this topic.
I think the only thing to do for now is really actually using free browsers and free operating systems and on the other hand raise the issues (literally on GitHub?) as loud as possible. The world is just lacking enough web activism. The only loud thing about freedom of the web is web3 and crypto, but obviously to me this is just backed by some people who like keep the buzz up to make some more money with speculation.
Apps that require play services are just as much exclusive as apps that require attestation. Phones that don't use play services can create their own attestation API and partener with apps to support it.
Your solution to breaking up a large monopoly is to boost another (quasi-)monopoly? I'd suggest that both Amazon and Microsoft should be prevented from taking over those assets.
I don't have a solution to the problem but I know this — we can't do the stupidity of breaking alphabet into a bunch of small baby alphabets like what we did with at&t.I think that was complete incompetence, if not corruption.
We can't have a bunch of regional companies. However, we can't do what OP said either, even with your safeguards. Amazon and Microsoft don't care if they get Google cloud for themselves to buy. Either they get to buy it or it dies, they still get its customers.
I think someone else said elsewhere if Microsoft abuses MsEdge, break up Microsoft as well but that's the kicker. That will take time. Microsoft can and will abuse it's position during this time. I don't think it is possible to do a "safe landing" here. An alphabet Google will either be a nothing burger like the AT&T break-up or will be very painful to ordinary people, at least for some time.
After the breakup, it became trivial for me to buy my own phone and hook what I wanted up to my phone connection (including dial-up modems later).
What do you think would have granted+preserved those options, that wasn't an exercise in incompetence and corruption?
Also if we are talking about MS/Amazon/Google's cloud businesses we shouldn't ignore that these companies themselves are generally their own biggest clients which is something they could leverage to a significant degree to outcompete their rivals (initially at least)
I'm a customer of both GCP and HE and this would be a really, really weird merger. Not saying I don't want to see it. :)
Google's ad business (and the need to track ad conversions) affects every business sector it's involved in. From Maps (where you loc. is tracked for 'in-store' conversions' to your Google ID which tracks which ads you click, to Chrome pushing for mechanisms to track conversions after cookie-blocking has become standardized.
You kind of understand their needs (since ads fund search and everything), but I also don't trust them not to 'over-optimize' (esp. given the unchecked powers, both political and technocratic, they have).
I don't think any of this would happen, but I'd rather see it go to Cloudflare so there's still 3 "big player" choices. They seem to be trying to head down the cloud provider path anyway.
How? I've seen similar ideas but the best they do is resonate really nicely in this echo chamber.
All it takes most of the time is a dozen people pushing the issue for a rep to make up their mind on a bill. On contentious issues, a few hundred persistent constituents will convince even Senators in large states.
Seriously it’s not that hard when it’s not a culture war issue. The vast majority of the time our politicians get bought out for a pittance like $10k in contributions. It doesn’t take much to bend them the other way when coming from voters.
Speaking from experience.
Policy on stuff like tech is set by staffers, most of whom work from material helpfully pre-drafted for them by lobbyists. There are some legislators (like Wyden of Oregon) who have very good in-house people on tech policy, while others have no expertise and have to rely on outside parties. But the idea that anyone can be bought for a donation is heartbreakingly naive (and fortunately false). Large donations at best get your calls answered by the junior staffer whose job it is to protect the Senator/Congressman from ever having to talk to people like you directly.
Major legislation on tech is rare, and it's generally much easier to kill something you don't like than to get a provision put into it. The latter course requires being deeply plugged in to the people drafting policy (again, mid-level staff on the Hill, who have zero awareness or interest in which private individuals are making campaign contributions) and enough clout and political ability to shepherd your desired policy through the full sausage-making apparatus of Congress.
Look at the current dueling bills on crypto for an example of how the process actually works. None of it is driven by strongly-worded letters from constituents.
YMMV but I've helped several nonprofits in SoCal navigate Congress and I'm constantly surprised by how little coordinated effort it takes to effect legislation, especially the budget (and I have no previous experience in politics, I was just an interested volunteer). We've only just begun collecting sponsors for the first bill drafted by one of the nonprofits so I can't speak to the whole process for a greenfield bill just yet but already we've had help from the Office of the Legislative Counsel to fix up the bill through our House rep so the ball is rolling.
So far we've spent far more on travel expenses than any of the orgs have spent on lobbyists or the members have spent on donations.
> Large donations at best get your calls answered by the junior staffer whose job it is to protect the Senator/Congressman from ever having to talk to people like you directly.
They're there to protect the politician from raving abortion/guns/bullshit-of-the-day lunatics. Offer to send them a short fact sheet in the format that they expect and the doors start to open quickly.
Like I said though, I'm in SoCal and YMMV. I have no idea what it's like with the GOP or in states where both Senators are like Feinstein (her office is a black hole). I do agree with the rest of your point about tech bills, my experience is with environmental and social services nonprofits who don't deal with very controversial issues.
Now, if you max out any Democratic race anywhere in the country, Raja Krishnamoorthi will ring you up from Illinois CD8, and you can talk his ear off. But it's a grift. He's not going to do anything for you. With my John Williamson voice activated: he - just - likes - talking - to - donors.
As regards affecting legislation, I'd be interested in hearing some specifics about your experience here. What legislation did you see get altered, and what were the tactics that accomplished it?
If there aren't already that on each side of an issue, its not actually that contentious. In reality, it takes large numbers of people coordinating action or a small number of people who each are financially involved orders of magnitude beyond the maximum legal direct donation (either as fundraisers marshalling donations for others, or as well-known contributors to party committees and SuperPACs as well as candidate committees, or whatever) to sway most members of either House of Congress from where they would otherwise be. (Being an existing org that is known to either bring a lot of voters or act as a proxy for a lot of big donors, or better both, also helps.)
I don’t see how that increases competition.
My take is that this process is inevitable while the following is in play: DoJ rubberstamps monopoly creating mergers, merger desiring companies fund campaigns & otherwise gift politicians, voters keep reelecting those politicians while not overly objecting to their corruption, news orgs fail to cover mergers in a historical context while generally preferring fluff and stenography.
Those wishing to expose flaws in my analysis can use the space below.
But it would still be in their interest in preventing ad fraud on the web.
Although the Chrome team would prefer not to block ads, I'm pretty sure there's some pressure on them to reduce the number of users using ad blockers.
> YouTube - streaming content. Probably gets sold to Netflix or AT&T or Comcast.
Make Netflix more powerful? In what world is that good for competition
>This is such a naive and for lack of a better word stupid take
What is the not naive, not stupid, clearly-more-beneficial-than-what-we-have action that should be taken with youtube?
This goes without saying, but we shouldn't let one company be solely responsible for managing the "world's" information. "Organizing" sounds benign, but they've clearly extended past that.
I don't know that you're totally on point about how to break Alphabet up, but you're right that it should be. If information wants to be free, we should also re-examine how to ensure it stays that way in a world where Google isn't it's supposed shepherd.
Besides IIRC Google cloud is actually profitable these days. No need to find a buyer.
It also means the fall of Firefox because they are still dependent on the Google moneytit.
The future I see in this direction is Chrome ends up getting a free easy takeover/hijack by Microsoft since they are have no problem throwing money at Edge.
Firefox is not comparable because it's not a stock company. They don't have the obligation to maximize profit for shareholders.
> - DoubleClick - third party ads on other sites.
No, hard disagree. One of the things that gives google its position of power is that its both an ad exchange and a publisher (as participant in said exchange).
The correct way of breaking is NOT search+ads vs third party ads. It's search vs ads.
Make google a publisher that DOESN'T own an ad exchange and make it compete for search ad revenue on equal footing with everyone else. Lets see how well it does (I'm guessing not well).
Same goes for facebook.
Android Based on information obtained by Oracle in a lawsuit, Android had, as of 2010-ish, generated $31bn for google
https://www.androidauthority.com/android-generated-google-31...
Chrome: Browsers make money by
- sharing revenue from ( product and service ) ad searches
- prioritization in search engine results in the browser ( eg being set up as the default search engine)
https://www.investopedia.com/articles/investing/041315/how-m...
It is estimated, for instance, that as of 2021, Google was paying Apple $15bn for default browser placement
https://www.theregister.com/2023/02/17/google_apple_chrome_i...
Google Analytics:
This is much harder to research - since looking for 'revenue' with 'Google Analytics' simply shows how to use the tool to track revenue for 'your' site if you are a Google Analytics user and my Google-fu fails at a quick remedy for that.
Best quick result would be a proxy i.e. competitor revenue. MixPanel is a standalone Google Analytics competitor and it makes $96MM from that business
I would hope YouTube could just operate as its own company. Certainly there's enough traffic, and it makes Google billions so presumably there's enough for it to survive on its own.
Google products are getting increasingly crappy. Would be great to see what others could build with their information monopoly.
The "projecty" things like Chrome and Android and Waymo are arguably money sinks that will produce things of significant public value over time-- what if we funded them like other research probjects, with the understanding that the commercial applications will either generate public revenue or directly enhance domestic competitiveness. Imagine if in 5 years, the American carmakers had highly discounted access to Waymo's self-driving technology, but Mercedes and BMW still have to roll their own or license it at an intentionally hostile price?
The revenue-generating stuff could be "commoditized" -- turn it into white-label products they'll resell to all comers. You no longer go to Google, you go to a Google Reseller who provides their own ad or subscription monetization model to pay for the underlying infrastructure cost. Since they all have the same core index, they start from strong competitive parity, and then they can focus on their differentating features-- extended custom indexes, more tools, etc.
Using the strategic tools of the largest Advertising Agency in the world, that allows them to ever grow their dominance. Chrome, GMail and all that jazz all fit into a global-scale ad-tech framework to push shady ads and slurp in your PII for shady business. Google uses monopolies and oligopolies to force itself into your life. In other words..
Google is SHADY BUSINESS. And that should be the framing to spread about. Always repeating that Google is an advertising giant. Not some trustworthy biz. Zero integrity. So how can Chrome relate to integrity then?
Is your Bank using Google's integrity foo? Give them a support call. Act like a noob and keep them busy for as long as possible with "It isn't working". Until they explain about Integrity + Chrome. Then comes the angry phase: "WHAT? Are you in bed with a SHADY advertising agency?? I thought you were a trustworthy bank."
I'm all for grassroots change, but I really don't think that doing this to Tier 1 support staff is going to effect any real change. With all love to my helpdesk folks, what matters is ticket closure metrics and call duration -- an emotional outburst isn't going to change a thing.
my sympathies for the call staff thou
This is exactly what we need to change. "Free" services are never really free. You pay for them in the end, anyway, and doubly so. First with your data, then with your money.
The free internet may be nice for some people, but we all pay the advertising tax in the products we buy. It would be much better if we banned this entire freemium pricing model and started paying for things like in the old days. It would solve a lot of problems.
https://httptoolkit.com/blog/apple-private-access-tokens-att...
You should be more afraid of banks soon requiring Apple devices only
This feeling has ceased entirely in the meantime, due to what Google has become, and how its understanding of its role in the world seems to have shifted. Or maybe its true corporate nature has only become more apparent? I am not sure - but I was a firm believer that Google was a force of good in the corporate landscape of the 00s, and I am fully convinced it is not any more. It actually makes me sad, and I am afraid of the damage it will end up doing to the places (the 'net) and communities (most of the FOSS world) I love.
But let's not fool ourselves, Google at the end of the day is still an ad company. So while we can appreciate what they've contributed using this approach, we can never ignore the fact that ultimately business priorities will always trump everything else, which means they can use their creations against us on the turn of a dime.
Early Google seemed to be genuine and upstanding fellas. The dotcom crash made everyone scramble to pay the bills and monetize which is where the seeds were sown for what we have today.
That didn't happen, though. What happened instead is that Google became a scumbag online ad company.
One relevant example is that they've been doing the "only for ie5+" with their services for 10+ years now. They killed most of their browser competition not by having a good product, but by having or buying up good services that they used to force chrome onto users - voluntarily (billions worth of advertisements) or not (lies about compatibility, performance or outright blocking other UAs).
IE got displaced by Firefox’s predecessors because MS got caught napping - they disbanded the IE team thinking they have won. Firefox simply got outcompeted by Chrome as Google went crazy making it faster and faster. Firefox fell behind often enough that Chrome managed to take almost all of its market share.
I’m not happily with Chrome’s dominance, and Google’s abuse of its market position, but it was a good product for most of its life span.
I disagree - if that was the case then people would be switching back to Firefox now. Firefox got outcompeted by chrome by Google adding a "works better in chrome" button to their home pages.
It's like sayinig people would be switching off of Facebook or Twitter. It's really hard to disengage the general audience.
With that said, I did in fact switch to Firefox in 2023. I still unfortunately need google translate on mobile, but once Firefox can get those add on features out of beta it will be a pretty seemless transition.
Chrome didn’t “win” because it was good. It won because of Google’s hyper-aggressive marketing on all channels. They basically did was Microsoft was fined for by the EU back in the day.
Chrome was however preinstalled on many PCs/laptops as part of the crapware package.
Also, yes, it came bundled with basically everything.
You talk like it's impossible for nerds to have influence on their surroundings. Way before Chrome got preinstalled on a computer or went on a dark pattern campaign, I heavily recommended it to my acquaintances, friends, family. I even remember a perfectly "normal user" type uncle using Chrome before I recommended it to him because he had learned of its existence from another person's word of mouth. I constantly see people try to diminish the power of word of mouth spreading good products here on HN, which is complete nonsense. Contrary to the popular belief on HN that "normies" are idiots who only ever settle for "defaults", they routinely try new things if their peers recommend it, it's how non-preinstalled apps like Whatsapp grow. It's not just the networking effect, you need to be better than the default. Sending things like pictures through texting apps sucked, group messaging sucked, Whatsapp provided something /much better/ so people used it. By the way, it's out of topic, but mentioning messaging apps reminds me of how Google in fact could not, despite its monopoly and advertisement power, get anyone to use theirs. If you think dark patterns and preinstalling apps is enough to gain success, then why has google failed, time and time again? Apps like Google Duo were preinstalled on all android phones I've seen and literally no one I know in real life ever made use of them. Maybe google's apps weren't bad, but they were not /better/ enough to encourage people to give a shit. To convert people, you can't just be "as good" as the competition, you need some serious oomph.
When Chrome came out, it was a landslide. IE was dead, and Firefox was dramatically inferior in both performance and security. The multiprocess architecture of Chrome combined with other security related decisions, and the V8 JIT for javascript made it a vastly superior browser and people knew about it. Firefox took a VERY long time to get to a place where it didn't feel bad to use once websites started taking advantage of Chrome's superior performance and got more bloated in the process. Some of the changes it made to get there were heavily contentious with the nerds who ended up being the main population of users for FF, like removing XUL, further pushing FF into a very specific niche : the privacy conscious and people who use it solely to reject google's monopoly. The "normal people" who would have used Firefox instead of IE back in the day because of peer recommendations would not use Firefox instead of Chrome today unless they're very obsessed with those things, because FF is no longer clearly better than the alternative, to the contrary, it's still weaker, though not as much as it used to be.
And while the crowd on HN tends to focus heavily on things like privacy, if there's anything the average person doesn't care about in my experience, it's that. They will never trade convenience for more privacy.
Currently, Chrome has a number of CSS features that Firefox and/or Safari don't support. You can find them at [1]. Some make life a bit easier, and devs use them because they like easy or even because they think everyone should force their browser maker to adapt all those features ASAP.
In an old thread, I explained that my code ignores these features because we want to be compatible with as many users as possible. I got some miffed replies saying we should make our users upgrade. Really.
Then there are also APIs in Chrome that have not been standardized, and some of which should not be in a browser (IMO), like USB access (see [2]). Some of that is an attempt by Google to replace "native" applications by web pages, which would give them even more leverage.
[1] https://caniuse.com/?compare=chrome+115,firefox+116&compareC... [2] https://caniuse.com/?compare=chrome+115,firefox+116&compareC...
Google Cloud’s login page frequently broke for Firefox users.
YouTube was famously slower for a long period of time where they used a proprietary API which only Chrome supported instead of the standard API which Firefox and Safari implemented.
I suspect that all of those weren’t malice as much as neglect but for such a large company it’s definitely not a lack of resources if they choose not to test on browsers they don’t make.
The real damage, however, was not things actually breaking but the constant push to use Chrome. If you used Firefox you would be prompted to do that frequently visiting Google search, mail, YouTube, etc. with various allegations of better performance which didn’t hold up in testing.
Then chrome came along and people reluctantly switched at first, then enthusiastically. Firefox had the reputation of eating RAM like candy.
It wasn't unwarranted. They were dealing with a great deal of memory leak issues in the early Chrome vs FF era. The most important thing is that even when Chrome ended up taking more ram than FF for an equal amount of tab and equal websites loaded, closing tabs on Chrome was far more likely to let you free ram usage than on Firefox, and nobody likes to have to close the entire browser session to reclaim ram.
In the XUL days, Firefox was quite janky. XUL enabled powerful addons that made it a great power user browser, and people still occasionally can be seen missing it on places like HN, but it was also a curse upon the browser and they took too long to decide to get rid of it and rearchitect their browser into something more modern.
Yes, a lot of issues are of Firefox's own making. Google sabotaging them helped, too: https://archive.is/tgIH9
https://www.businessinsider.com/google-sergey-brin-employees...
This shouldn't be an unusual demand or even a demand at all-- it should be table stakes.
Even back when the concept of Free Software had just become an identifiable thing people advocated it in terms of respecting the user. But for a long time the disrespect was largely banal-- rent seeking, over priced, indifference to features or bugs that matter to you, rules that benefit the author but didn't care about the user's needs. The fact that software could actively and intentionally work against its users wasn't a surprise-- the freedom to inspect, modify, and share the results answers those risks too, at least in theory. But back then it wasn't a common problem. Somehow software and systems that actively betray their users became common, even normalized. And in large part it seems most people never noticed.
I have the strong impression that the vast majority of people simply do not care and mostly don't even want to know.
Most of the people I know are in this group. When they ask why I won't install the latest app they are playing with, they often cut me off before I even finish explaining. They seriously don't care about privacy, lock-in, loss of access to resources, right to repair, etc.
Personally, I'm investing as much time as I can in learning the alternatives: Gemini, Fediverse apps, Linux phones, etc. That combined with having a "mainstream" laptop that is used only for banking and similar life critical services that has nothing else installed and otherwise stays turned off.
They care even less about this stuff than they do about plastic pollution, or systemic inequality and racism, or PFAS contaminating the world's water, or pesticides and runoff decimating biospheres. They don't care about corruption at the highest levels of government and justice, black sites and torture, or illegal wars for profit.
It's impossible to care about everything that's going on. It's unreasonable to expect people to care or even know about everything, even if politics wasn't a wrestling show and corporate news wasn't enraging entertainment.
And, most citizens are two paychecks away from destitution.
Lobbyists, on the other hand, have full access to decision makers and a truck or two of cash, determined to make concrete specific changes.
This is by design, and Google just take advantage of it the same way every other company does. Blaming 'people' for this is blaming the victim.
If they already have the phone all the information in the world is literally at their fingertips.
That's not actually true though. That just shows a lack of empathy on your part.
> If they already have the phone all the information in the world is literally at their fingertips.
While that's sort of true, there's a mountain of propaganda and bullshit to wade through, with thin seams of truth. The education system doesn't prepare people for this, nor does our media, nor do our politicians or corporations.
The wealthy who profit on our ignorance like things this way, and (hire people to) work very hard to keep things that way. So again, blaming the victim is missing the point.
You can currently argue that the topics you're marginally informed are "more important" than the ones you're not, but how would you honestly know? Can it be objectivelly substantiated?
If you just see what happens in reality, it is that different people is focusing on different issues, oftentimes pushing for different or even opposing goals, and everybody believing their focus is more important than the others.
Also, you get a lot of people without any focus outside their physical scope, living perfectly fulfilling lives, which are the ones your parent poster refers as the "victims" being "blamed".
> Should your computer be able to be compelled to tell the truth, even when you would prefer that it lie on your behalf? Should there be a facility in your computer that you can’t control that other people can remotely trigger?
It is an apt application of the quote, and a fundamental question that is likely based on culture and each persons or organizations past experience with abusive overlords. I personally opposed it.> Should your computer be able to be compelled to tell the truth
In the context of the soldered chip that "can't be removed" that can report the "truth" of the kernel etc, the answer to me is a simple, "it's impossible to know if the computer is telling the truth or not." Go to defcon once and you'll know this as true as well. No matter what, there's always a way in. There's always a hack. The harder you make it to hack, the more motivated those crazy people at defcon will be to break it.
> Should there be a facility in your computer that you can’t control that other people can remotely trigger?
"Other people" will never be "just the people you want." It will always include criminals, stalkers, and authoritarian governments. So the answer is a simple, "no."
Absolutely, but I don't want to have to use 0days like a criminal or to open up a TPM chip in an $1M electron microscope just to have my PC render webpages the way I want it to (without ads that is).
2010s
https://nakedsecurity.sophos.com/2011/08/26/real-canadian-ph...
"we don't collet private data" https://europe.googleblog.com/2010/04/data-collected-by-goog...
"ops we do" https://googleblog.blogspot.com/2010/05/wifi-data-collection...
google wage fixing, all the way back from 2001 https://www.cnet.com/tech/tech-industry/apple-google-seek-ap...
before that it's harder to search data, but you get the idea.
Explicit non-goals for WEI:
"Enforce or interfere with browser functionality, including plugins and extensions."
https://github.com/RupertBenWiser/Web-Environment-Integrity/...
That link needs to be passed around a little bit more. Whoops.
The attester verdict is an abstract concept that refers to the response from attester. It reports how much an attester trusts the web environment the user agent is executing in.
The web environment is defined as TODO [sic]
So essentially google has carte blanche for information from your browser.
And they are prototyping that into browser - so forgive me but I'm concerned even more.
> There is a tension between utility for anti-fraud use cases requiring deterministic verdicts and high coverage, and the risk of websites using this functionality to exclude specific attesters or non-attestable browsers.
This risk is already present and actually happening. What makes this not widespread is not that it is not possible (it is) but that it is unpopular. Websites that you are forced to use (many banks for example) do it every day and they get away it with it because you have no choice.
Many articles are just reapeating the "DRM" claim without explaining how is this different, what does Google have to do with how websites choose to treat their users or what solution they would propose. It seems to me just protest for the sake of it because it's trendy to question every Google Initiative. And yes every Google Initiative must be questioned but I don't see any questioning here beside just parroting in article after article what someone identified as a potential misuse without any critical thought going into it. Might as well autogenerate the contents with AI already because the utility of all articles i have seen on this topic is the same, just rearrange words without adding anything to it.
Google owns YouTube. Is it so hard to imagine that some product manager at YouTube counted the losses due to adblockers and asked a team in Chrome to prevent them?
You're either paid or delusional.
For all that we know all kinds of closed source software are already doing something like this (especially ones who do a lot of natural network traffic so you cant even distinguish from the capturing raw data what is legit and what not.)
For example, Netflix allows you to download a movie from their native apps but not from the browser, this is only because in the native Apps they have access to all kinds of hardware information and they can attest themselves about the "environment"
Chrome runs in the userspace, whereas I can write a kernel module which chrome can't interfere with (I did that for widevine in 2017!) that will emulate/lie to chrome about the hardware I have, and there's no way that the website owner could know whether I lie or not (this might require some effort on my part, but it's doable).
Hardware based attestation was created precisely because the software based one can be bypassed.
Google could accomplish all of their supposedly nefarirous goals by just ignoring the linux users. Do you really think they are going through all this trouble to make sure that they deliver adds to those 2-3 people? I can already see the next earnings call, "adds impression targets increased by 2".
Notice again the Netflix example. They just don't have a linux App and you cant legally view Netflix movies offline in Linux. it's cheaper to ignore linux users. like it or not, that is a fact.
outside of Linux, if chrome were to provide an API, for hardware information it can be completely trusted and even in linux case I would say that it still can be trusted with 99.99% confidence.
No, because in order to ignore linux users you'd need to know that the device in question is actually running linux. But then again, I can run a windows VM inside (sure, this might require effort to patch the windows inside), with no need to write a kernel module because this time I can introduce custom logic in the VM which the virtualized chrome-on-windows process will not be able to interfere with and with enough effort, they have no way to tell whether this setup is "legit".
Of course this will be legit in 99.99% cases, except that the 0.01% case is precisely what causes the damage (bots, fraud, piracy and so on).
Thankyou, that's precisly my point. All this trouble is worth only for fighting fraud and bots and not for making sure that that 0.1% can't use a adblocker like anyone is crying about.
1) I meant damage to them, bots are beneficial for users (scrapping services) just like piracy (but this is a political point)
2) Even if the reason for these changes it to fight that "fraud", it does NOT mean it won't be used to further restrict the user freedom.
On Android, banking apps require hardware attestation and this can be seen as reasonable from the security perspective.
But Google abuses it to insert their Adware and Spyware into the system, just like other vendors. Now if you root your device to remove that crap, then poof - you're no longer considered secure. With WEI this is about the same thing.
Seriously? Would you give the kiddies sharp knives and loaded guns, and then be shocked when someone is injured?
If we let this become available, we will all have to live with the consequences. We can see clearly what those consequences will be. Let's not be stupid.
In your knife-analogy, Google is producing sharp knifes for the cooks, not the children. the DRM crowd here is saying but what if the Cook uses the knife the attack the restaurant clients? Do you know of anyone seriously discussing that we should stop all production of knifes because someone might give one to a child? SO yes I agree, let's not be stupid.
Your analogy once again falls apart because in this hypothetical scenario, the cooks have a decade-long history of attacking the guests every single time they get a hold of a new knife.
In which case, yes, these cooks shouldn't have access to knives anymore. Of course that's not very practical, so perhaps they shouldn't be allowed to work as cooks anymore - i.e. separate Chrome from the ad business at the regulatory level and use Firefox or other alternatives on a personal level.
They have every incentive to require websites running their ads to only allow ("google play" + other big players) verified software on their sites.
They can a) prevent ad blockers and b) assure their customers that ads will be viewed by real humans.
Not doing so once this is in place would be intentionally saying no to profit
Why in the world would google care about anything else?
How about you offer a reasonable opposing viewpoint? It's hard to see this, at best, as anything other than an extremely naive viewpoint. Every feature that can be used to lock down content and/or spy on users, will be used to do just that. That's true for every single feature that exists today. Claiming otherwise borders on bad faith.
> Google or any other Browser vendor do not have a say on how websites use or misuse features.
That's settled then. Full filesystem, location, camera, and microphone access should therefore come on by default without a permission dialog. Why not bring back Java and Flash while we're at it! It's not the browser vendor's fault that websites are misusing it.
> Many articles are just reapeating the "DRM" claim without explaining how is this different
This is different because any meaningful "attestation about the environment the browser is running in" can only be achieved via a full chain of trust, starting with secure boot, which will allow Google (and websites you visit) to verify that your system is using a Google-approved bootloader to load a Google-approved operating system which only loads Google-approved drivers and Google-approved software (or worse, website-approved software).
Read the proposal: https://github.com/RupertBenWiser/Web-Environment-Integrity/...
>That's settled then. Full filesystem, location, camera, and microphone access should therefore come on by default without a permission dialog. Why not bring back Java and Flash while we're at it! It's not the browser vendor's fault that websites are misusing it.
Now who is arguing in bad faith? if you have read the proposal, it's clear that they are being careful and are upfront about the some potential misuses and the proposed handing of them.
> to verify that your system is using a Google-approved bootloader to load a Google-approved operating system which only loads Google-approved drivers and Google-approved software (or worse, website-approved software).
again there is no such thing proposed. The "attester" is not specifically Google. anyone can become an "attester". The chain of trust is a chain that trusts tokens not specific "things". if you for example would trust let's say Opera as the attester, Opera would need to trust windows or Linux or Android as the OS attester.
The analogy here is the certificate Authorities. You may very well have a "let's encrypt" attester that democratizes the good parts (certification) without the bad parts (too much information) .
But it's not the user ("you") deciding which attesters to trust - it's website operators. And they will choose to trust only attesters that meaningfully (cryptographically) verify the user's client environment, including the secure boot chain, OS, and browser. Otherwise the attestation can be spoofed, in why case why would they bother using the EnvironmentIntegrity API at all?
You know what? They are already doing it. This just gives them another option.
> And they will choose to trust only attesters that meaningfully (cryptographically) verify the user's client environment, including the secure boot chain, OS, and browser. Otherwise the attestation can be spoofed, in why case why would they bother using the EnvironmentIntegrity API at all?
You might as well complain that any website requires any sort of authentication or authorization.
How is WEI any different from all the other current methods which have not killed the "open web" in the way the hysteria over WEI is claiming?
But I can still access them with my device being controlled by me, I can create bots/extensions to export and archive content. I can because there's no reliable method to identify whether my device acts in my interest, so they have no choice - they have to restort to methods that can be cracked. WEI is an attempt to introduce that reliable method.
Sure, there's EME with Widevine L1, but this is currently limited to providing media content, not apps themselves. That's why WEI is considered the DRM for the web.
I have, and that is not a viewpoint unless you wrote the proposal.
> if you have read the proposal, it's clear that they are being careful and are upfront about the some potential misuses and the proposed handing of them.
The goal of the proposal is strictly incompatible with our freedoms. After all, restricting which devices, environments and software we're allowed to use to visit the website is the entire point of this proposal, is it not?
> again there is no such thing proposed. The "attester" is not specifically Google. anyone can become an "attester". The chain of trust is a chain that trusts tokens not specific "things". if you for example would trust let's say Opera as the attester, Opera would need to trust windows or Linux or Android as the OS attester.
So what? Even if this were true in any practical sense, as a user I have no control over which attesters the website trusts - and they will require attestation from parties that attest that I'm running the latest version of Windows or MacOS with Spyware version 5.49.182 installed, and another party that attests that their ads are visible in my framebuffer.
That won't happen immediately, of course, it would be much too obvious. But introduction of WEI establishes a clear path forward towards that reality. Once WEI is in place, the chain of trust will continuously creep up the stack until everything from the TPM chip up to your framebuffer and display is locked down. They'll slowly boil the frog, like they always do.
> The analogy here is the certificate Authorities. You may very well have a "let's encrypt" attester that democratizes the good parts (certification) without the bad parts (too much information) .
That's a terrible analogy. For one, the only thing TLS server certificates attest to is that I *the user* am connected to the *server* that I intended to connect to.
A better analogy would be mandatory TLS client certificates which would attest that I'm John Doe, underage, registered to reside in a country where the legal drinking age is 18, warning the websites that my juvenile criminal record is spotty. That's what WEI is comparable to, and you'd see a similar level of pushback if that's what was being introduced.
Good luck getting your bank to trust any ol' attester and not just FAANGs.
On the contrary, my main issue is that they identify one of the primary issues and fail to address it.
The biggest issue is that web designers will design around WEI such that the web is unusable without it. For example, while the current use case might be “captcha without WEI, no captcha with WEI”, a future use case might be “captcha with WEI, 401 without WEI”
Essentially this means an end to the open web: websites block you if you aren’t attested. If you want to browse from NewOS, tough cookies that’s not recognized by attesters
This is addressed in the proposal in “Open Questions > How will we prevent this signal from being used to exclude vendors”.
The only proposed solution is in section “Holdback”:
“[…] we are evaluating whether attestation signals must sometimes be held back for a meaningful number of requests […] Such a holdback would encourage web developers to use signals for aggregate analysis and opportunistic reduction of friction, as opposed to a quasi-allowlist […]”
This is a massive potential issue. The author acknowledges WEI could become an allowlist for the web. The author implicitly acknowledges this is most likely if most clients are using WEI (hence, the proposed solution of artificially decreasing WEI usage via holdback)
And even then, the proposed solution of holdback is not a solid one. There’s no technical reason that WEI will continue to have holdback in the future, at best maybe a google pinky promise. Further, there’s solid game theoretic reasons we can predict that holdback may vanish: if popular sites start using WEI as an allowlist, then any browser with holdback will have a degraded browsing experience on a percentage of visits. You can win market share by abandoning holdback!
As a tragedy of the commons, we can reasonably assume in the long term WEI is supported on all visits by all major browsers and a nontrivial number of websites use it as an allowlist.
In conclusion: the author admits WEI breaks the open web with sufficient market share, but the only proposed solution seems guaranteed to fail in a competitive browser marketplace based on game theory.
You know they can do that right now, right? They aren't doing it. Will more do it because it is simpler now? Sure. Will it put "an end to the open web"? Nope. If they wanted to end it, they could have already achieved that. WEI is just simply another better option for the websites which sorely need it. Sure, some other sites will abuse it, but I think you already avoid them since you still think the "open web" is still a thing.
More to the point, even the author of this proposal has recognized this is an issue, identified it as so in the proposal, then failed to put forward a workable solution. That’s my problem.
Making the web impossible to use if you don't fit into their specific requirements. WEI is just another signal. It won't be the only signal for the vast majority of the web. Google cannot do anything to break the web without the help of Apple. Frankly, Apple has a better chance of breaking anything open than Google does. Apple has the vertical control. Google has what? Chrome? I just don't understand how people seem to think Google has all this power, but continue to ignore Apple.
> WEI doesn’t exist yet, obviously nobody is blocking clients who aren’t attested.
Yet a lot people seemingly know its going to do this, that, and some other bad thing even though there is no proof and stated goals which are the opposite.
> More to the point, even the author of this proposal has recognized this is an issue, identified it as so in the proposal, then failed to put forward a workable solution. That’s my problem.
They cannot prevent websites from requiring X to access their sites. There is no workable solution to force someone to accept traffic against their wishes. If they only accept requests with some custom header, that's their prerogative. Many features of browsers have been (ab)used for "nefarious" purposes. Should we get rid of those? This whole thing feels like since Trump is not president in the US any more, certain people need a boogeyman and are using Google in his place. Anything Google does is automatically bad.
> Yet a lot people seemingly know its going to do this, that, and some other bad thing
Original https://news.ycombinator.com/item?id=36935843
New
Because any other option is not sensible:
1. Authors don't understand what tech they use. (not possible as they acknowledge issues)
2. Authors don't understand that something unrealistic is unrealistic.
Idea that you can give companies or corporations tools to check "did user modify his environment" and they would not use it to exclude users is stupid or disingenuous because advocates for this did exactly comment in such way: We want this proposal to do precisely that.
Again Google tries to defend it by saying "we will return invalid 'false' for some of the users/times of Chrome users" [to make sure that website will not do that] which for me is not only bad because it then creates "when google revokes this policy we are in even worse situation" but then leaves the issue how google decides "who" to give back this 'false':
I will reject times immediately not only because this can be easily circumvented by website [check n-times] to detriment of user but it would also contradict official documentation of WEI (same token for same input from user).
And this leads us to another point - if Google wants to return false negatives it would need to either keep information that is supposed to return 'false' - EU will not be very happy with that (also it does contradict this "chrome users"); or more likely it will be implemented in chrome.
Now when we established that implementation in chrome is most probable - we can also establish that:
A) Implement this on profile basis - companies will ask you to reset profile if you are this false negative.
B) Implement on connection basis - companies will ask you to refresh.
C) Implement on device age / os version / type - Google can even make the manufacturers happy with this one.
… as you can see at most this will be nuisance and if by some weird way:
Z) Implement on Super-complicated basis - this will be still possible because…
3. Google plays disingenuous word game with us here by saying - We won't destroy open web
Other Chromium browsers may ignore that Google X% false negative (Google may loose few % of users before it scrapes this policy). And there is 0 need for Google to actually do something when companies will misuse this API.
In simple words the part that should worry you is not that "Google will destroy web by using this API on Chrome and it services", what must worry you is that other companies will do that for Google and Google will wash their hands from this by saying "We wanted good but didn't work". You can see that tone from the Google - We don't want that so we created these "holdouts".
They are proposing thing that any sensible person see as clear cut attack (or stupid idea that can only work this way) on Privacy and Your Right to use Your Device (and for some people Your OS and/or Your Browser) as You want to use. They are at fault here.
> They cannot prevent websites from requiring X to access their sites.
They can by lowering amount of signals site gets - so to make it impossible to guess what client is running.
> There is no workable solution to force someone to accept traffic against their wishes.
Not give someone way to disallow traffic based on OS or Browser.
> If they only accept requests with some custom header, that's their prerogative.
And it is users prerogative to not give you any custom header which they do not want - or if you force them to do so give you not real one.
>Many features of browsers have been (ab)used for "nefarious" purposes. Should we get rid of those?
Yes we should. Or at least we should do risk assesment on those to check if they should be part of standards and Browsers. We should do more risk assessment of any new feature and standard.
>Anything Google does is automatically bad.
If they start championing privacy and less pro-corpo bs - I will applaud them for that.
> This whole thing feels like since Trump is not president in the US any more, certain people need a boogeyman and are using Google in his place.
Don't bring your (USA) bs politics to this - if anything it is your fault to not make proper regulations on your market.
> even though there is no proof
If you understand even tiny bit of tech - you will see the definite proof - the proposal.
> "and stated goals which are the opposite."
PR is irrelevant.
While trivial fingerprinting methods can be bypassed, TEE-based methods are pretty much impossible to bypass ($500K reward for that)
The WEI attester is exactly same - if site decides that it trust only Google, Apple and Microsoft - you do not have any way to access the site if you don't have attestation from that group, period.
"Opera would need to trust Linux" - Again I need to stress out to anyone who doesn't understand anything about Linux - Linux is not single uniform OS - it is bunch of distributions (OSes) that agree on some common API (not always) to produce more or less something that seems to be single OS for application (often not really) - binary compatibility is not a thing to this degree that linux has many (again no uniformity) separate solutions to make closed source binaries to work.
In reality trying to attest "that binary is not modified" on Linux is simply fallacious or outright misguided on basic idea - leaving aside distros that do not ship binaries (Gentoo) many ship often modified versions of software. And Users may modify software as they see fit - so there is literary no way that you can attest Linux.
then it isn't anyone.
>and the same can happen in the WEI case too
It is impossible to happen in this case.
If client has to be certified, then as product OS must be certified out-of-the-box for non-technical user. This will make sure 97% of market is covered by Apple, Microsoft and Google - these are "Authorities" web will have - even if the remaining few percent would be unified - it still will lead to most often then not "not being included" as trustworthy from server side.
>The TLS analogy stands.
no it does not. TLS cares about connection not OS stack. Also power dynamic flows in opposite direction.
>Ofcourse noone can trust self-certification.
If you want you can - because You (user) can import any certificate. The problem for me is that:
[Free/Open] Source/Linux in their entirety can be attested only if self-certification is possible. AND Self-certification means that WEI doesn't work. AND Any proposal that excludes any OS (or Linux distribution) from web is unacceptable.
Do you see logical outcome which this reasoning leads me to?
>No browser has made the decision to trust only one authority.
But it is not the browser here who has the final power "to trust", it is the server. And companies will only care about Windows, Mac(Safari), Android and Chrome.
>A motivated and funded organisation can become an Authority (like Let's Encrypt did)
Let's Encrypt could do that because TLS works in reverse direction and it is website that must be certified not the user.
> At the "trust-me-bro" game bots are more convincing than real users.
Yes exactly which is again everyone's point - for 10001 times and again "You cannot trust the client" - it is impossible to create privacy/[freedom of use for browsers and OS]-focused 'secure' and perfect attestation about client.
One has to give - 'security'/perfection or privacy/[freedom of use for browsers and OS].
We calculated what this proposal brings and rejected it on basis that bad is bigger than potential 'good' it can bring.
And again to put it clear - you need bots: search crawlers, web archive bots, URL scanners.
So put it clear - it is clearly from my perspective a wrong proposal.
P.S. This another thing worth considering if you think WEI will create real security: https://news.ycombinator.com/item?id=36985317
Apologies for just repeating a previous post I made about this but:
The first goal of the proposal is to
> Allow web servers to evaluate the authenticity of the device and honest representation of the software stack and the traffic from the device.
That is, to give web servers the ability to Digitally restrict (or Manage) a user's Rights to access content on a device and software stack of their choice.
The fact that this is DRM is unquestionable. What you seem to be taking at face value is Google's claim that this DRM will only be used to discriminate against bots and other abusive traffic, whereas everyone else is just pointing out that this technology can very easily be used for evil and that Google has every incentive and ability to do so.
> what solution they would propose
A man on the street stops you, points a gun to your head and instructs you to give him all of your money. How do you propose to solve the man's problem of lack of your money in his hands? Also, you cannot ask him to put down the gun before solving that problem.
Nothing in this proposal gives publishers those means (beyond what is currently available). Verifying the authenticity of a device in this case is a generic "trusted/not trusted" not "OK for movie 123/KO for skipping on movie 456"
Sure, if you redefine DRM to mean whatever you want it to mean, this is not DRM. I'm not even sure what authentication has to do with it if you prevent access to your website before I even got a chance to see it.
> Netflix requiring you to login to view a movie is not DRM.
Not sure where you came up with this strawman, I said nothing about requiring you to log in.
I said "access content on a device and software stack of their choice.", so for example, limiting streaming quality to 720p on Linux, or blocking a user using FireFox, or blocking a user on Linux, or blocking a user with a custom kernel, or blocking a user without a TPM.
> Nothing in this proposal gives publishers those means
It gives them the means to discriminate based on hardware and software, for example by only trusting a single attestor of their choosing which only gives a trusted signal for whatever passes their hardware or software criteria.
As an example, Google may decide that as a requirement to having their ads on your website, you must only trust a single attestor - "Google Play" (as named in the proposal), because otherwise you may be trusting an attestor that facilitates ad fraud, and we can't have that. Google naturally only treats devices running Chrome as trusted, how can they trust anything else that they don't own?
Naturally, the same applies to their own websites, can't have you using FireFox to send people CP via gmail, right?
Do you want your website to be protected from bots via Google's reCaptcha? I'm sure they know how to decide which access attempt belongs to a valid user or not. And they'll be happy to cooperate with Cloudfront to make sure everyone online is equally safe.
Obviously, it is also on Google to protect users from websites that host botted content, so if you want to appear on search results and don't want the browser to give a scary warning when accessing your website, be sure to only trust the trustworthy attestor.
And let's not get started on what happens if you want to take payment from users while "mitigating fraud"...
> (beyond what is currently available)
Right, the justification to do more evil is that we already do some evil, I'm convinced.
> Verifying the authenticity of a device in this case is a generic "trusted/not trusted" not "OK for movie 123/KO for skipping on movie 456"
In just this specific example you prove yourself wrong. You can use the generic "trusted/not trusted" signal to decide "movie 123 is OK for not trusted, but movie 456 we will restrict to trusted only".
This workaround only works currently because these systems rely on software-based DRM, perhaps because there isn't yet a convenient built-into-the-browser hardware-backed root-of-trust-based attestation system for the web.
Same way HDCP can tell an application whether the video is being played on a screen rather than a capture card. No trusted screen? No video for you. That's DRM.
With Android Safetynet attestation, you can't work around the problem because the attestation is backed by a root of trust which your custom ROM can't provide. Being able to supply your own thing doesn't matter, because everyone will just support the one that Google supplies. LineageOS is a good example of this; they have their own Safetynet implementation which has very little buy-in.
WEI is effectively an extension of Safetynet to the Web.
In summary, this is fundamentally different because it takes away your control of your own device.
The issue with this seems to be a sort of a restricting freedom for the greater good idea. If you restrict the ability of web developers to check security values and stuff, then they can't do some good things like improve security, but they also can't do any really bad things like block ad-blockers. But if you allow this access then you get the opposite.
In particular:
"""
If the root certificate doesn't contain the public key on this page, there are two likely reasons:
[It is from an old version of Android, or]
The other likely reason is that the device isn't a Google Play device. In that case, the device maker is free to create their own root and to make whatever claims they like about what the attestation means. Refer to the device maker's documentation. Note that as of this writing Google isn't aware of any device makers who have done this.
"""
In other words, to get into the Google attestation party you have to get your device Google Play certified. Obviously device manufacturers are strongly incentivised to do this.
Edit: If this were to be applied to desktops as well, the obvious approach would be to partner with Microsoft and make use of their trust root, because Microsoft's keys are installed in ~every TPM.
Edit: I wasn't aware Microsoft was already pre-signing basically all desktop TPMs, that's crazy. Makes sense thinking about it now, especially with Windows 11 requiring it.
No, it allows a business to deny to you if you can't attest to the security of your device. You are still free to do whatever you want on your own device.
If a business had an office that required you to unlock a door, but it also had a pickable lock that wouldn't be great security. It allows people to lie about having a badge by letting them pick the lock to get in. If a business increased security by making the lock no longer printable that seems like a good thing to me.
>LineageOS is a good example of this; they have their own Safetynet implementation which has very little buy-in.
Have they actually approached apps and offered compensation for them to implemented it? Or are they hoping apps just randomly decide to adopt it?
The issue is that making modifications to anything in the chain of trust requires approval from a trusted third party.
I was oversimplifying. A service doesn't have to trust every attestation and a service does not need to do anything with the attestation if it doesn't want to.
>The issue is that making modifications to anything in the chain of trust requires approval from a trusted third party.
That is by design because it means untrusted people can't make changes while remaining trusted.
Businesses not trusting every random person is not anticompetitive. Doing that is how businesses make bad deals, get hacked, or make bad decisions.
That isn't what is happening. Anyone can become a manufacturer for Windows PCs or Android certified phones.
Whole point of WEI is that you are following Google's rules.
You essentially acknowledged that YOU CANNOT become manufacturer - you become subcontractor for corporation that dictates what you can and cannot do.
Which from point of trust is precisely that - anticompetitive behaviour.
That would be the point of the Google Play attestor. With WEI sites can use anyone as an attestor. It is up for attestors to compete in providing a valuable signal to sites.
It's not anticompetitive because you can come up with your own standard of a secure device and get sites to trust your attestor.
But let's go back to the "anyone as attestor" argument. I don't see it in the API at all - I see only content binding..
Of course then substitute browser for Chrome and we'll get the obvious outcome - Google will decide.
Firstly on Android Chrome implementation (testing) only Google Play is now implemented as attester and it does not seem that probable for it to change. (so presumably at least Chrome+Root wont work).
Second and Most Important - the mechanism does not allow for "willing to attest it" - it actually contains this phrase "The web server then checks that the token came from an attester it trusts" so it is disingenuous to say that "any single atestor" is OK - it must be attestor that server decided beforehand (so if server decide we only trust Google and Microsoft - and you have Mac, then tough luck. [more realistically Linux will be at issue]) - so we are getting system that can exclude certain OS and Browsers permanently without recourse - by server side.
@zb3 >doesn't it mean it will be the browser that decides which atestor can run on a given platform? That seems to be case in Chrome implementation* - and there is nothing about this in standard so unless other browsers would create another standard - this way seems likely.
This would be disastrous for any decentralized OS like Linux or BSD - it would be completely impossible for it to realistically work as it requires single "platform" by design - and I should remark "there is no single uniform thing in Linux".
* - note that server decides which attestors it trusts. Which means in essentia that sever decides which platforms it trusts.
Again this must be scrapped.
right because users will chose attestor - oh wait they will not.
This system is designed (at least in Chrome) with PLATFORMS in mind not independent attestors - so you clearly didn't get the memo.
>valuable signal
rather highly intrusive signal.
>It's not anticompetitive because you can come up with your own standard of a secure device and get sites to trust your attestor.
Again it is anticompetitive when you produce a standard that benefits you (or biggest players) on market and makes nearly impossible for another competitor to emerge - it is even more anticompetitive when you create standard that "is impossible to implement" for architectural and 'branding' (ideological) reason by another competitor.
Such situation can be understood as public attempt: to form cartel at best, monopoly at worst. Both are anticompetitive by nature - and would result in dissolution of company if it is registered in any country with working and not totally corrupt government.
>secure device
about "security": https://news.ycombinator.com/item?id=36985317
"Android certified" means it follows Google's rules, so there's no way to compete by creating alternative security model (for example where the user has more power).
So the anticompetitive part is the attestation part, which artificially makes it impossible to run an app that'd otherwise work on the system that doesn't follow Google's rules.
There is a way, by creating a new attestor service that provides less guarantees than what Google Play's attestor provides.
But this isn't really my problem as I'm not a business. As an user, I'd be happy to have a secure OS with hardware attestation and app security but without Google Adware and Spyware.
Trust isn't anticompetitive.
I acknowledge though, that this is incompatible with many practical scenarios, and CPC advertisements are one of those.
It's hard for me to argue here theoretically without taking context into account, as it turns out what I'm arguing for depends on it heavily..
It could be possible for Google to make changes where while theoretically possible to compete, it's not practical, and when it gets practical, Google could make another change and so on..
I use DuckDuckGo or Brave search for most of my searches, but half the time I have to add "!g" to the search to switch to Google to get actually useful results. Does anyone have any tips or tricks (or search engines I'm unfamiliar with) so I can break free? I know Bing is technically an option, but I'm under the impression it's not much better than Google (privacy wise) and their AI integration is off-putting.
Ahh, this is an EXCELLENT tip.
https://seirdy.one/posts/2021/03/10/search-engines-with-own-...
I suppose they told us what they are when they scrapped their "don't be evil" motto.
You want to know if someone is truly a nice person - put them into a now growth situation for a while. Before that, it’s all talk.
Maybe it's easier to stop projecting our ideas of what "ought to be" into entities who inhabit a system in which those ideas don't have value, like for-profit businesses, no?
Google can achieve horizontal integration since they own youtube, search and lead the Chromium project. They are "the web" and make money with ads so they are going to force you to watch these ads, nothing more.
First they positioned themselves very early in the web user experience: After the user turned on their Dell computer, booted Windows and started Internet Explorer, the next step was to use Google.
Then they moved one step closer to the user by building their own browser: Chrome
Then they moved even closer to the user by building their own OS: Android
Then they moved even closer to the user by building their own computer: The Pixel Phone
The question is what the next platform shift could be. And if the big players will miss it so that a new player can emerge. And if there will be a new player which is as smart and driven as the Google founders.
Chrome was made to prevent whoever controls the browser from blocking users’ access to Google.
Android was created because they were afraid Apple would block them on mobile.
All tech companies do this kind of positioning.
Apple made Apple Maps to make sure Google Maps isn’t the only choice on iOS fearing Google could withdraw Google Maps and hurt the utility of iOS devices - at least in the short term.
It’s why Apple made Safari and enforces it as the only browser on iOS.
Apple learnt relatively early the dangers of being dependent on another company, https://www.folklore.org/StoryView.py?story=MacBasic.txt
Everyone is very actively working on making the browser dead and serving you content exclusively via corporate controled apps on locked platforms.
You can kill off Chrome, but the result isn't going to be a renessaince of Firefox, but a move into your content being only available on locked iPhone.
Aka cable box.
[1]: https://ec.europa.eu/commission/presscorner/detail/en/ip_23_...
So while those were big aquisitions (Around $3B and $2B) they only accelerated the process of Google turning into the web's central player. It was already set in motion before the aquisitions.
- OpenAI is already 'evil'.
- Apple has staying power but I still wouldn't consider it cool anymore.
- Likewise Tesla.Regulatory capture attempts to prevent others from releasing actually-open models.
They a few billion dollars later and you realise that morality and stakeholder profits can never be aligned...
What would be the one-sentence technical explanation of how Google wants to achieve this?
>Could you man-in-the-middle the connection and alter the message to say whatever needs to be said to convince the other computer that my computer is working the way it expects?
If you're willing to break modern cryptography for that to happen, sure. Also, requests include a hash and a timestamp to prevent replay attacks and delayed attacks too. So you better crack that cryptography _fast_
The TPM has an API that returns a signature of the running OS code. If you tamper with the OS, you get a signature mismatch.
Denuvo for browsers. Rootkit disguised as a browser from your favorite Ads service provider.
My advice to everyone is to watch out, and be carefull. Look over the license changes over the incoming days to see how you might potentially be squeezed.
What makes them "extra" dangerous (or evil), in this this regard, is they have such broad reach and control over the Internet and tools people use in their daily lives that many have no idea to the extent of censorship, manipulation, spying, or damage that is being done. Any perceived rival, threat to their business, or to any of their products can be silenced, censored, or inhibited in ways few will ever know or realize was possible.
And to the extent they can keep getting away with it, is likely the extent they will keep pushing their control and corruption.
Must be a biz opp to run a proxy that strips everything google from pages and web communications. I would pay a few $/month to not be farmed without consent.
Yes there is Firefox
But Brave still faster + own search engine
If you don't trust them, you can compile it on your own.
or Apple, the hardware is their profit center, as well as getting you to buy their software product, but your info isn't sold to 3rd parties (yet?)
or Google (circumvent some of it with firefox+adblock origin)
or just don't participate at all and get a flip burner.
FTFY:
uBlock Origin
In my case, my bank won't allow me to do online payments unless I validate the payments through a smartphone app as the 2fa. They do not do texting/sms based 2fa anymore.
The app will refuse to launch on a rooted phone or a custom rom. To me, this means a degoogled phone is absolutely unusable. I can't do without being able to use my credit card online.
This is in fact the sort of thing that will happen soon to the web if browser attestation becomes a thing. I can already see it coming, my bank rejecting logins from browsers that are not untempered, Google-provided.
Sure that's easier said than done given how much we depend on them today, but is it really harder than convincing the federal government to step in and break up companies that pay huge lobbying bills, understand how tech companies work in the first place, design new regulations to prevent this happening again, and sit waiting to scrutinize any acquisitions that may come from the break up?
Call me naive, but I think if people really care they have a much better chance to avoid Google than the government has of actually fixing this on our behalf.
As much as I personally like discussing the economic and political impact of various web specifications – there are a lot of things happening in modern society, and everybody only has so much time and mental resources to care about every single one in detail.
If I think Google's latest antics are dangerous enough for society as whole to warrant government intervention, I first have to assume that the majority of people don't get it but would be opposed if only they better understood. What gives me the right to make that decision on their behalf? And if I don't know they would care, can I really push through my own intervention?
Not to mention the assumption we have to make that government regulators actually do understand and can relate in an unbiased way with only consumers best interests in mind.
Google squashed most of the competition in a lot of sectors, and the few remaining competitors aren't any better often.
Aside, even if you do not actively use google, google will still be in your life, by tracking and selling you. Already there is realistically no way to entirely "ungooglify" your life as long as you live and partake in some modern western society.
And soon it seems, you will be using a Google browser because you have to, because your bank or employer website or whatever will require their web "attestation" DRM, and will not accept your Firefox, Brave, Chromium, Vivaldi, Opera or whatever attestation.
And if you're hoping for other attestation vendors... Try streaming anything that needs a subscription without using Google's widevine DRM. You will be surprised on how few options there are, not just in implementations but in streaming services that support anything besides Google's widevine.
Google and probably Microsoft and Apple will be big enough browser vendors to be widely supported "attested environments" and attestation providers. Everybody else will bite the dust on that front.
E.g. "x% of websites do not accept Firefox's attestation" will drive more users away from Firefox, and that in turn will lead to even fewer websites supporting Firefox attestation because why spend the dev resources to support it with that measly market share when people can just use one of the big browsers?!
And google knows this very well, from the "works best/only in Chrome" to widevine. They were even able to make MS abandon their browser engine and jump on the google engine train, after all.
This to me is very clearly an antitrust issue that needs antitrust suits and regulation.
The sacrifice is almost entirely on convenience unless you're employment depends on it. Use Firefox, install some basic ad blockers, and don't use Gmail or Google maps. That definitely won't be totally de-googked but it goes pretty far.
If Google does force through this attestation model that's a different story. Though that is effectively Google killing the internet if companies decide to use the feature. Thankfully we survived without the internet for a long time, we can go back to going in person to our bank or calling them on the phone.
Where can I collect my $10?
At the time, I found it to be a mockable suggestion, and never really thought much beyond it. Seemed like harmless IT/nerd banter back then.
About a decade later I started to reflect on what he said and began feel like I might have been working with a time traveler or other inside person.
It really does spin in my head quite a bit. If you think about how much human information flows through Google's systems... how many of us have considered some other form of intention and motivation here?
Nothing strange or mind blowing really, for example Crypto AG, a famous swiss crypto vendor was secretly a joint USA-Germany operation from the 70s onward.
For me the nuance is in the origins and ongoing leadership and effects on the consumer experience. The "Killed by google" phenomenon paints a darker picture in my mind. I start to read each google product as a folder in a CIA Sharepoint system - Only to be kept around until it is no longer valuable to the agency. Each with some sort of ulterior mission that seems ever-narrower in scope.
I've talked about interviewing as the Office Security Architect in 2003, but the job that got me talking to MSFT was one in what was going to become NGSCB, bits of which were eventually rolled into Windows Vista. My interview for that team was scuttled when I talked with their senior tech person who asked me... "Oh. I see you have experience in Crypto(graphy), then you clearly know how to tractably factor a 2000 bit number." I admitted that I was still under the impression that it was a difficult problem, but he assured me that all you had to do was print it out in binary and apply a particular regular expression to it. When I pointed out that primality testing and factoring are different things the interview went south. I later found out this was some sort of MIT shibboleth and I was supposed to respond with some comment about the compilers class.
In any event... It always seemed odd to me that NGSCB tried to make MAC a mainstream feature, but I wasn't really thinking about DRM. Like I said, if you're a big organization and can properly manage the classification problem, and have info security peeps who are cleared and trusted, MAC (as embodied in any of the C2 Unices from the 90s, NGSCB or SE Linux) can be useful. But yeah, the only reason you would want this on a consumer machine is to prevent the "owner" from doing something with downloaded media the person who produced the media doesn't want you to do (aka DRM.)
Use Kagi or DDG or anything else as your primary search engine.
It's very hard to "turn the tables" on companies when it comes to remote attestation because companies rarely directly lie to consumers about the true nature of their operations. When they do they tend to end up like Sam Bankman-Fried or Elizabeth Holmes. That's why all the big cloud vendors support remote attestation of servers to clients:
https://cloud.google.com/confidential-computing
So not only do they want you to demand remote attestations from their servers but they even document how to do it and provide significant infrastructure support to do so.
Not many people are using it though, and when they do it's usually to generate trust in non-tech firms running software on top of those clouds. Which is certainly a decent use case, but it's more like defense in depth than something existential for most companies. Whereas the inverse can be existential (multiplayer shooters without anti-cheat will rapidly become unplayable because so many players will lie to get ahead).
Since inception nobody said that IME was for the user. Nobody said that Palladium is for the user. Google arguments are all propaganda. Nicey nicey words for the people.
Judging about the amount of recent pressure on open source, and encryption we are already toasted. Cyber resilience act, earn it act, patriot act, restrict act. It is all written using nice words, but I am interested in effect. It is all about crypto wars, and taking possession of your computer. About limiting anonymity and privacy using only arguments against it.
Big companies already have monopoly. They can already shadow ban, ban users, decrease reach of comments, track users using fingerprinting, cookies etc. They can decide what is acceptable, what is not, what is a social norm, what is not, what is a conspiracy theory, and not. Why do they need also breaking the encryption, or force signed software? Why they require more control? Because they can. Corporations lobby for more power, they receive more power. Where is the limit? Government also only benefits from corporations accumulating more powah.
I do not understand how people may think about how 'good' these things will bring, because on the scales there is something really terrifying - a Government that can spy on you without any problems, where you cannot hide. Through surveillance laundering, where government buys user data. Through censorship where government can moderate anything it wants to through hidden portals for the government [1]. Maybe the problem is that the western world never really experience communism.
[1] https://reclaimthenet.org/new-zealand-government-facebook-co...
By the way. I understand the difference between moderation and censorship
That level of control was already achieved on mobile. Android is the wet dream that Microsoft had with palladium and failed to execute.
I can't use my banking app on a degoogled phone. It requires an untempered, manufacturer provided rom, and it will not run on a rooted phone either. The thing is, the banking app is not a side toy for me to just check up my accounts or do bank transfers instead of using the website, it's the only tool the bank provides to allow for online payment validation. You /need/ the app to make online payments with my bank. No app, no using your credit card online at all. Want the app, need to live under google (or iOS, which is even more closed and disgusting).
Palladium is real today.
TechCrunch spends 80% of its time farming Elon Musk stories but won't lift a hand to promote a good fight.
Are these news companies so entangled in the corporate world they can't risk taking a stand because it risks them losing access to real-time news? I don't really understand it so I am kind of guessing, but it is nonetheless strange.
The media outlets are pushing for this. Hey, no more adblockers! I'm surprised they aren't running glowing testimonials of the new Google-overlord future.
The Google of today is a completely different company than the Google of yesterday.
The beginning of the article summarizes why Google is no longer committed to its original motto, and It's sad to see such a dramatic change in the culture of the company.
> first, they are good to their users; then they abuse their users to make things better for their business customers; finally, they abuse those business customers to claw back all the value for themselves.
______________________
And anybody here actually thinks that you will be strong enough to stop WEI?
One could just laugh, if it wouldn't be so sad....
You will - as always - stop nothing from happening, I guess. And you will again happily call it 'pragmatism' or say 'ohh, but I had to; they forced me'...
My understanding is that google tries to make money, everything else is brand marketing.
But, TL;DR: Google and Microsoft have always been ‘evil’. We’re just arguing about which circle of hell they rule over.
It's this about eliminating those annoying, and at times confusing, CAPTCHAs?
29% of all internet traffic is malicious bots [1].
Why is it a bad thing for browser makers to signal to websites that the party interacting with their website is a real human being or not?
Why is there so much hate for what Google is doing with WEI, but I don't sense the same hate for Apple Private Access Tokens (PAT)?
Isn't WEI just a response to Apple PAT?
"Devil's advocate" statements can be useful as a thought experiment in exploring a topic by generating something new that prompts others to make the counterargument explicit.
There's a lot of articles and comments here flying around in the last few days trying to reify google's idea and explore the boundaries of the implications.
When you raise one of the advertised positives, I don't feel like that's a novel point that prompts exploration of a new angle on the topic.
>Why is it a bad thing for [google's pitch]
/me gestures widely in the direction ongoing conversations and articles over the last few days
If you don't care about everything discussed, you can just say you don't care.
There is zero control over the future.
That is, we don't have to ascribe malice to Google while running away from this potentially evil mechanism.
The Web Environment Integrity proposal isn't much different than requiring that, in order to receive an email, the sender both secures their machine with anti-virus and provides proof to you, the receiver, that the message in question is virus-free. Otherwise, without this proof, you won't accept the message.
Metal detectors and the requirement to pass through one to enter certain, defined spaces are probably the physical analogy that people are most familiar with.
1) WEI doesn't attest that your device isn't running malware, it attests that your device is running a particular set of software -- it is a positive filter, rather than a negative one. This means that you can't run your own software (if it's part of the WEI trust chain), even if you know it's not malware, without changing the attestation (and see the next point for why this isn't viable).
2) Because WEI doesn't have a way to prove that software is malicious or not, it instead requires you to trust the attestor (in a cryptographically secure way). In the usual case, this will mean trusting Google. This means that if I write my own attestor, there is no particular reason that people should trust what it says. On the other hand, there are plenty of reasons to trust what Google says, given that they wrote the software and certified the phone. The attestor model, because it relies on trust, is fundamentally biased towards organisations which you already are obliged to trust to some extent.
The same arguments apply to metal detectors. This isn't about detecting metal (negative filter), it's about detecting approved clothing.
I disagree with your characterization of metal detectors defining success on approval. Consider the practical difficulty of defining a whitelist of every possible piece of "approved clothing" compared to a blacklist of known knowns (e.g. guns, knives, poison, etc.).
2. I think we're in agreement that who is permitted as a legitimate attestor is a core issue. I wouldn't ultimately conclude that it must be Google, although many web admins would be satisfied with that.
Keeping a continuously-updated list of all attestations you're interested in trusting does indeed sound practically difficult. So it's quite likely that most sites will only trust attestations from Google about unmodified Google-supplied software (and perhaps some of the larger third parties).
I'm still coming to the opposite conclusion: For example, as a web admin, it would be useful to me to block requests that forge the User Agent. In your mind, is this a white or black list?
""" Attester-level acceptable browser policy If the community thinks it's important for the attestation to include the platform identity of the application, and is more concerned about excluding certain browsers than excluding certain OS/attesters, we could standardize the set of signals that browsers will receive from attesters, and have one of those signals be whether the attester recommends the browser for sites to trust (based on a well-defined acceptance criteria). As new browsers are introduced, they would need to demonstrate to attesters (a relatively small group) that they pass the bar, but they wouldn't need to convince all the websites in the world. """
In other words, they realise it's infeasible for sites to keep up with new browsers and figure out whether to trust them. This is an implicit whitelist (I believe the preferred term is allowlist) because each site would have to keep a list of attested "platform identities" that they trust.
Instead, in the above paragraph, Google proposes that new browsers demonstrate to Google that they are worth attesting, and then Google will get the attester to say "Additionally, as the Google attester, I trust this browser". This is an explicit allowlist.
In other words, if you want to write a new browser, or fork an existing browser, or write or a site scraper, or whatever else, you either have to convince every site using WEI in the world to trust you, or you have to convince Google to trust you. Both methods involve an allowlist.
To use your example, as a Web admin, you wouldn't get information like "forges user agent". You would get a signal like "Genuine Chrome running on unrooted stock Android" (the attestation), plus "Google's attester recommends this browser for sites to trust" (the extra signal proposed by the paragraph I quoted above).
If you use the former signal, you have an explicit allowlist on your site. If you use the latter signal, you are relying on Google's allowlist.
What we know now is that they wanted to run an experiment to gather some data. Since it's in Chromium, they needed to explain it, and they explained it poorly.
If a server is not denying access for clients with no valid attestation then what exactly are the servers gaining from implementing WEI?
CAPTCHAs also reasonably prove that the user is a human and legitimate but not all captcha challenges are solveable by humans in one go.
Businesses have denied access for those failures and they just repeat the challenge until the captcha is solved successfully. If the failures are less per client they can easily be treated as tradeoff against security.
What's stopping websites from doing the same with WEI? They can always deny access and repeatedly request attestation until a positive reply comes.
This is acceptable for those "attested" clients where the failures are random and within an upper bound. But a client without attestation can always be denied or they can be shown different limited content altogether.
In both the cases the unapproved clients are at a disadvantage.