Your computer should say what you tell it to say
eff.org
eff.org
I've worked with banks, who are among the most security-minded of organizations. It's not because they're security nerds, it's because the cost of getting hacked is astronomical, and because regulations require them to be "as secure as possible."
Banks won't be chomping at the bit to implement WEI because they hate the open web or they hate Linux users. They'll be chomping at the bit because if they don't it will be a liability, and a "you're not doing all you can for security" type of risk that can open them to lawsuits, regulatory punishments, and even higher insurance costs. WEI is not a requirement right now because it doesn't exist. Once it exists though, you can be sure it will become a standard practice requirement, and anyone arguing against it might as well be arguing that using CC cameras is a privacy invasion: they'll seem absurd and won't last long in that position.
In short order it will be implemented by all the CDNs like Cloudflare, and it will be a simple checkbox for site owners to add to their site. Failure to implement this would be a fiduciary disaster, so they will have no choice. Once that is there, nobody who cares at all about security for their site (which is pretty much all people) are going to uncheck that box.
The same people who instituted and backed these rules and practices are also running the core system for clearing in the national bank of Denmark.
Banks are not secure. They are conservative and political. They will do everything to tell you they are secure. They will make your life hell to uphold their security theater, but it's just a facade. I have no doubt they will implement WEI, but it will not bring security.
Banks do have a pretty good trackrecord of protecting people's money, but they do that through a defense in depth strategy of having a bunch of compliance officers manually reviewing transactions for suspicious activity.
This is precisely OP’s point. WEI will quickly dominate despite having nothing to do with securing anyone.
With intro of html5, (webgpu, webgl, web audio api), that sandbox has being slowly opened up.
Who will have some trouble with this new concept on the web? Smaller browser maker, software developers and crawlers from competitors
Not a single scammer or ad fraud will be affected, same as on mobile.
Easy to see why Google wants that, its attacking the competition
That’s pretty good. A major Canadian bank until ~2020 had 6 character limit passwords (possibly you could enter more, but only the first six count) and mapped all alpha characters to numbers in groups of 3 (so your assigned telephone banking PIN was just a “hash” of your password).
They have the fun pattern of logging you out of your account whenever you are inactive. A bit excessive for a health insurance provider imo, but whatever.
So I tried to login and guess what? Max input length for their login password is 16 characters. I literally couldn't input my password.
I had to go through a stupid process to reset my password because their sign-up front-end validations were different from their sign-in front-end validations. I had to purposely choose a less secure password even though I could technically create a password that was pretty secure, I can't sign in with it.
Luckily it's normally easy enough to edit the tags on the text box but even so, this shouldn't be necessary.
Fucking BT.
This is the problem with having old mainframes somewhere in the backend. Their rules bubble up even where it doesn't make sense.
Hell, many/most of these large institutions seem to still only support SMS for 2FA and even that's a relatively recent introduction to actually mandate.
Which is to say, I expect banks to be about the very last significant account you use to mandate this technology (if it takes off), not the first.
Most banks lock your phone access to your IMEI + phone model + some phone specific data, so people knowing your details can't login without your phone. Web side needs 2FA or special activation depending on the bank.
Forgot your password? You need your biometric ID and your actual face to match at that very moment to make that work.
These are by regulations, yes, but this is very far from a "security theater".
If they are only doing it to tick compliance boxes then there is probably not much motivation to do it better. Those systems are security theatre.
Ah, also the same bank doesn't send SMS anmymore. Everything arrives to their app. Only they fallback to SMS if the app fails to acknowledge receiving the notification, which happens once a year?
Also, banks do not mail financial information by default to prevent wiretapping by 3rd parties.
If you're sending sensitive financial information over the mail, it can be read, classified, tied to you and be used against you if required.
So, we have a directive to not email anything financial to the recipient by default.
Unless Google happens to make fat campaign donations or post-office job offers to elected officials who can insure WEI becomes mandated for banks.
In the face of this, what banks want won't matter much.
I get banking is regulated from a variety of directions. However, the path of lobbyist influence->federal manipulation is so well worn it impacts many (probably most) exertions of power.
where most of the web treats authenticated users as trusted, banks still treat an authenticated user as mostly untrustworthy, and all of their actions as still being a potential risk, so securing the authentication isn't so important.
As Brian Krebs has noted, on top of the already-oligopic banking sector is an even more ologopic banking-computer-services sector: "What Is Your Bank’s Security Banking On?" (2018).[1] Sadly, the industry is dominated by a small handful of banking platform providers. Four, Fiserv, Jack Henry, FIS, and CSI, serv over 80% of the market. Bank regulators, responding to Krebs, said that "small to mid-sized banks are massively beholden to their platform providers, and many banks simply accept the defaults instead of pushing for stronger alternatives."
This does also suggest that there may be a small number of points of control over which to enact useful change, though of course there's also a concentrated lobbying interest in avoiding or counterinfluencing same.
________________________________
Notes:
1. <https://krebsonsecurity.com/2018/03/what-is-your-banks-secur...> (HN: <https://news.ycombinator.com/item?id=20203482>)
But back then, bank security was terrible when viewed through the lens of how hard it is to break in and do bad things. On the other hand, bank security was fantastic in terms of being able to detect when this happened and to be able to find the perpetrators.
Yes, this seems inevitable. At which point, I will no longer be using the bank's website.
> they'll seem absurd and won't last long in that position.
I'm not sure what you mean here, though. People who object to ubiquitous surveillance don't seem absurd to most (even those who aren't so upset about it), and they certainly aren't changing their position.
That's a great temporary measure, but once this has rolled out everywhere and is part of standard commercial experiences, are you really willing to completely opt out of online banking because you're not permitted to send fake browser identification?
It's a fine philosophical position, but it feels akin to refusing to use public streets because of the existence of surveillance cameras.
Attestation requirements from banks would mean I must run an OS with adware and spyware built in to use online banking. It's not (just) about browsers.
Sure, why not? It's not like it's a huge sacrifice on my part. It's just a little reduction in convenience. No big deal.
> because you're not permitted to send fake browser identification?
That's not the issue for me at all. The issue is if sites require me to use specific browsers, to not use specific extensions, to not be able to modify the browsers, or to adhere to specific requirements in terms of the OS I'm using. Having to maintain a completely different environment in order to use certain websites really is a loss of convenience that I object to.
Don't get me wrong -- I don't see this as a huge moral issue. Sites can do what they want, and if I don't like what they want, I don't have to use them. Opting not to use them strikes me as a reasonable and proportional response.
The only thing that makes me a little sad is that it's just another thing that makes the web worse and less useful.
I can easily imagine a world where in ~20-30 years, there are no bank branches or phones or ATM machines or cash--because 99.99% of people have no interest in using those things anymore. In that world, suddenly it becomes an almost insurmountable inconvenience not to acquiesce to whatever is required to use online banking.
Sure, I get that. I just feel like it's only a little inconvenience now, but in a few years it will be a big one, and so on. After all, the US is _already_ way behind the rest of the developed world in mobile payment/banking tech.
> The issue is if sites require me to use specific browsers, to not use specific extensions, to not be able to modify the browsers, or to adhere to specific requirements in terms of the OS I'm using.
Ah, I didn't think about that angle. That would be pretty draconian. I foresee a shift to dedicated embedded apps for that, like a restricted VM inside of a browser tab. We'll see!
For me it would be as if my bank ceased to exist.
> I'm not sure what you mean here, though. People who object to ubiquitous surveillance don't seem absurd to most (even those who aren't so upset about it), and they certainly aren't changing their position.
Yeah good question/clarification, I'm referring to the CCTV cameras in the bank itself (such as in the vault, in the lobby, etc).
> I'm referring to the CCTV cameras in the bank itself
Ahh, I see what you mean. I do know people who hate even those cameras, but they do also understand why they're there and just silently put up with them while minimizing the amount of time they spend on-premises.
I think there's a bit of a difference, though. If I'm in a bank branch, it's effectively "their house, their rules", so CCTV cameras don't offend me there.
But if the bank required me to be searched when entering the place, I'd be strongly offended by that. To me, WEI is more like being frisked than being surveilled (although neither analogy is great).
> Given that most people don't use ad blockers
In the US, 40% of people do use ad blockers. That's certainly not "most", but it is a large enough number to be significant.
What I'll do instead (and, honestly, this is what I already mostly do anyhow so it's not really a sacrifice) is physically go to the bank branch to conduct my business.
The Mobile app is required to use the debit card anywhere but card present, because 2fa. The Mobile app is required to do interesting things on the website, because of their 2fa. The iPad can't use their website (because reasons, they think it's mobile) and can't use the mobile app because it's not the configured phone with the account.
Credit cards really aren't a thing in this country, and if they are, they will generally have a phone based mobile app for 2fa/strong auth.
I'm not sure what my response would be, but I'd probably lean toward having a separate device that's acceptable to the bank and that I use only for banking purposes. But I don't know.
I don't pay my bills at a bank or bank website regardless, there is no surcharge for going to a bank's physical location, and I don't have to make an appointment.
And people who go to branches aren't exclusively elderly and/or technophobes -- but even if they were, what does that matter?
Meanwhile, arms race being what it will, the freedom gained will be short-lived and can't be relied-upon.
When this happens will this accidentally create a new business model of people selling VPN-like access that mimics WEI or uses a farm of cell phones to create a proxy farm of sorts? What else might people do to circumvent this?
We're not all condemned to FIPS ciphers everywhere because banks are, and so on.
I'm hopeful there's some option to it, like how you don't need 2FA often until doing something like changing the password
This short paragraph summarizes the (ex-ante) improbably unusual situation we have drifted into.
The negatively affected stakeholders being enumerated are more or less the entire society.
These gatekeepers and chokepoint operators do have a few natural allies (the captured politicos, others in direct or indirect payroll, externality-blind markets). Yet somehow they can bully into submission basically the entire universe. With its infinite financial, political, intellectual resources.
Rather strange dont you think? It almost as if they already operate effective mind control at systemic scale.
If the logical conclusion of your reasoning is a mass mind control conspiracy, you should revisit your assumptions.
> somehow they can bully into submission basically the entire universe
I don't think anyone is bullying all of society. I think most people just don't care. It's really not that crazy, no mind control involved. Just good old fashioned apathy and ignorance.
It's a mix of middlemen being the only industry that can still extract more profit, and a level of control over markets by Capital that makes most opinions meaningless.
Its essentially a return to feudalism, where certain people own vast swaths of productive space, they're untouchable in the legal system and real life, and one is forced to work for them.
To escape the system means leaving behind most of society depending on your convictions. These groups can kill you physically(Monsanto poisoning people with pesticides) or metaphorically(you lose all connection to the general societal social media) and nothing can be done.
For the first one, if you were to suggest violence against those doing violence against you, you're essentially told that violence is never the answer, except when its in the form of collateral damage for profit motive.
For the latter, its not nearly as life ending, annoying, but not life ending or even altering unless your livelihood is based around grifting on social media. For social media it is ironically democratic, if most people find you to be an annoying asshole, they sorta kick you off so you leave everyone alone. No different than getting kicked out of a bar for demanding to see someone's genitals.
You need to provide a practical definition of "most powerful" before your phrase can be evaluated.
But the list of affected entities involves far more than addicted consumers. Digital gatekeepers interfere and reshape the information flows which form the fabric on which all economic, cultural and political activity takes place. There is already plenty of evidence of the potentially dramatic impact. Highly trained and responsible individuals in the corporate world or the public sector cannot possibly be ignorant or detached from this extreme and unprecedented concentration of control that affects their very own roles and power bases.
I didn't really want to speculate as to what perpetuates this (by historical standards) rather extraordinary situation. There is clearly some accommodation taking place. E.g when the entity now known as Meta attempted to introduce a digital currency it was summarily pushed back into its corner.
The mind control possibility was a joke, but - mind you - conspiracy theories thrive in the lack of transparency.
I'm not familiar with Canada but this sounds like oversight there is similar to how the US DoJ operates - which is to say it has a long history of rubberstamping (massive, competition-killing) mergers
> Originally, secure computing relied on a second processor - a "Technical Protection Module" or TPM - to monitor the parts of your computer you directly interact with.
TPM stands for Trusted Platform Module, not Technical Protection Module
This however, absolutely sounds like someone being snarky.
Edit: I'm wrong about this one. It's an actual article, and a pretty good one at that. But it is either a mistake or they are introducing an alternate expansion for TPM (other acronyms have been given different sets of words).
"Trusted Platform Module" sounds good. But what it actually means is that the platform can be "trusted" to place the interests of third parties over the owner of the device. Stallman referred to it as a "Treacherous Platform Module" because he saw it as betraying the user.
I'm guessing that "Technical Protection Module" is a similar attempt to "de-propagandize" the acronym, and that it caught on with some group of users long ago.
People make mistakes sometimes. And this one is not a huge one -- the meaning is conveyed fine.
As we all know, ChatGPT stands for “Chat General Purpose Tool”, as it is an artificial general intelligence.
If this gets rejected, would that mean that services that need a "trusted client" simply deprecate their web apps and rely on a iOS/Android app?
I'm not trying to argue in favor of WEI, I just think this doesn't magically disappear if Google doesn't implement in Chrome, it just moves the problem elsewhere. The fight was implementing TPM in the first place.
Mobile devices already has tons of attestation features. Secure enclaves, security processors, cryptographic capabilities of SIM cards (e.g. I carry my private key inside my SIM card, and use it as a wet signature, legally).
We do not need this tech which can and will be abused to lock any tech savvy person from daily internet based on arbitrary rules. There are no checks and balances. This is a very broad set of capabilities which is forced upon users.
This is no proposal, or experiment. It's a force-push attempt.
Even OS integrity check is done locally. You can’t ask arbitrary measurements out of it.
WEI is different. Rules come from outside. Acceptable parameters are decided by another party. You have no pieces of the system in your possession. You are a Furby forced to tell something with the will of the attester through the filter tuned and configured elsewhere.
I can disable TPM or force it to reset itself if I want to. Even Apple’s security processors can be wiped clean of your data.
WEI is not like that.
It looks like they propose to mix false signals to prevent this from being abused, but oh. That's easy to bypass. Require two attestations back to back to see whether they differ, or put up a page saying, "can you please try again?"
The open question is circling around the question, can we make it work in a way, such that it doesn't work for bad guys, but works for good guys.
Mathematics & cryptography doesn't work like that. It doesn't discriminate. It levels everyone. It'll either become an iron fist or a Swiss Cheese. There can be no middle. This is maths.
What about neurodivergent people who cannot function on an "approved" OS because of the inherent ways it manages, stores, and presents information? What if that OS has an ACID compliant browser capable of accessing the banks website if they didn't have remote attestation?
What about the millions of people unable to afford to upgrade their hardware to Windows 11? Or that don't have TPM available and therefore can't use any other Windows version because 10 fell out of support, so they're running a Linux distro with an unapproved web browser?
Yes, because it's stupid; they don't need to. The bank cares about correctly identifying who I am, not what client I am using. Nor do they exclude certain browsers because those browsers make it easier for a user to lie about who they are; they don't. Banks exclude certain browsers because their technically incompetent coders convinced their technically incompetent managers to do so.
This is true. In these discussions of trust, my measurement of a bad actor is who is in a position to harm me and has a history of causing harm.
High on my list are LEO and other government interests (fed,state,local).
That "proposal" is doublethink in its purest form. WEI is a technology for restricting access to web services. But at the same time, it would try to prevent web service providers from doing exactly that?
When adding new features, design them to preserve the user expectation that visiting a web page is generally safe.
The Web is named for its hyperlinked structure. In order for the web to remain vibrant, users need to be able to expect that merely visiting any given link won’t have implications for the security of their computer, or for any essential aspects of their privacy.
For example, an API which allows any website to detect the use of assistive technologies may make users of these technologies feel unsafe visiting unknown web pages, since any web page may detect this private information.
If users have a realistic expectation of safety, they can make informed decisions between Web-based technologies and other technologies. For example, users may choose to use a web-based food ordering page, rather than installing an app, since installing a native app is riskier than visiting a web page.
I know a lot of savvy, non-technical users who absolutely refuse to install mobile apps on their phone except from the most trusted of sources, and I think this principle is a good structural framework for reasoning through why users still prefer the web.The people pushing these things do not care about this at all. To them it's like something a child would say and marks the speaker as utterly irellevant and silly, not even a real person due any respect at all.
Yes. Mobile apps are far too risky, in my opinion. These days, the only ones I install are ones that I've written myself.
Yes, and this has already been happening. For example, Venmo used to have a fully-functional web app, but now you can't send/receive money on it. Many Chase features are also phone-only.
Edit: And a lot of these apps block jailbroken iPhones or rooted Androids if they can detect that.
If this kind of thing gets implemented by my bank/brokerage, I have to either buy a new computer just for them, or do all my banking over the phone or in person. It's incredibly wasteful and doesn't even help with security, but once it exists, it will get added to a checklist that banks will adhere to.
Good. The point here is to shrink the space where client attestation is used, not to expand it. Every time it shrinks a little bit more is a victory. Let's get it out of the browser and then we can tackle native attestation for apps next.
> If this gets rejected, would that mean that services that need a "trusted client" simply deprecate their web apps and rely on a iOS/Android app?
This is verbatum the argument that was brought up for EME. But now we have the benefit of looking back at EME and seeing what the impact was. It didn't stop the movement towards native apps, businesses like Netflix implemented EME and kept many of the same restrictions they were going to implement anyway. It did end up harming browser diversity.
I understand that it sounds scary to say "we're just not going to do this" on the web when sites might be pushing a scare tactic of "we're just going to go native then." But... we've been through this, caving doesn't work. The sites that want to go native will go native, WEI on its own will not be a business justification for websites to stay on the web or to leave the web. The sites that do want to go native-only will not suddenly make a website just because WEI exists. They'll do the same stuff they wanted to do anyway, and if WEI is available, they will simply add that to their toolkit as a way to limit user agency alongside everything else they're doing.
It's good if businesses that want to rely on client attestation are "punished" by being forced to abandon their web presence. And frankly, people underestimate how much power the web has. Refusing to support WEI will not kill the web.
Should be outlawed, with the exception of dedicated hardware. Stop invading my devices.
Neither. The issue is that this is being framed as a "client attestation" problem, when the actual problem that needs to be solved (as opposed to a "problem" that certain companies would like to "solve" to benefit themselves at users' expense) is a user attestation problem.
My bank has no reason to care what client I am using to access their online services. They do have a reason to care about correctly identifying who I am. But there are already ways to do that that are just as good as anything WEI will provide.
Companies that do care what client I am using don't care for my benefit. They care for their benefit. But as long as they can't get the law to tilt the playing field in their favor, I can just refuse to use their services if they refuse to accept my client. As soon as "client attestation" becomes a legal requirement, though, then it's not just those particular companies that will use it; everybody will have to, including my bank, even though my bank has no reason to do so other than the law if such a law passes.
The way forward is getting it removed in mobile devices as well.
This. Nothing in my skim of the spec prevents me from using your hacked machine as an attestation oracle. This does nothing but add additional value to compromising end user devices.
They will ship this, standard or not. But I don't see a reason for Apple to ship this in Safari, or Firefox neither. So I expect this will be a real test of Chrome's market power. Will any sites start blocking non-WEI browsers? Locking out iPhones seems insane. Or will we see differential ad rates for WEI environments?
True that TPM shouldn't be embraced either, it will just create ambitions.
They make some cool merch too:
If the shirts are Bella Canvas or American Life or something else high quality, I'd happily buy some. Tshirts are a great way to raise funds IMHO, and the EFF is doing extremely important work and needs to be funded.
[1] https://www.eff.org/press/releases/international-coalition-r...
Instead, I look at the total effect. On the whole, EFF (in my opinion) does far more good than ill, so they have my support.
Cool. So since you do think multi-billion dollar companies should be allowed to deny services to a paying customer, I assume if they deny offering their services to gays or blacks, for instance, you are also fine with that? Like, we shouldn't force corporations to do business with anyone...
Infringing on a company's freedom of association does not eliminate consequences for speech.
This is about freedom of association and the right (or lack thereof) to other people's broadcast equipment.
Eventually the government decreed that illegal.
Breakup of ma bell (roughly the same time you were allowed to own a phone) 1984
And even today I can't buy or connect an ONT of my own to the new fiber that Optimum installed a few weeks ago to replace my coax cable and cable modem that I did own (but did not fully control thanks to docsis), somehow.
I am not actually hopeful.
It is not part of the Web. This is exclusively a Google draft for a Google Chrome feature, and whilst Google is a member of the World Wide Web Consortium (W3C), they are not doing this as a member. I don't believe such a proposal would get even as far as a working group charter, given how limited it is to Google's interests. The only reason that it's a threat to the Web is because of their overwhelming market dominance, which is approaching a monopoly already.
I fear that the prominent use of the term 'Web' in this kind of document is tarnishing the reputation of the W3C, who have a solid process[1] to avoid pursuing these short term interests when they come with the risk of long term damage to the openness of the Web.
The W3C is still very much active, and produces the vast majority of specifications that are implemented by 'web browsers' (in the general sense) like Chrome, Firefox and Safari, and they have their own standardisation process which is comparable in quality to organisations like ISO.
The area in which WHATWG are most active, though, is HTML, for which they produce what they call 'Living Standards' that have a different process from W3C's. CSS is done inside the W3C, and JavaScript is formalised by ECMA, an entirely different organisation still.
[1]: https://whatwg.org/
[2]: https://www.w3.org/
I would hope that we see this kind of explanation more frequently.
EFF clearly explains why the holdback mechanism doesn't make sense, and why the proposal authors' personal beliefs are not relevant. What matters is what capabilities this technology allows, and what Google's corporate motivations are.
This is an obvious consequence of this proposal, yes. Ad-block prevention isn't an explicit goal, just a very obvious consequence when you create a mechanism that whereby attesters (OS) inform the server about the presence or absence of software on your computer. It doesn't require a logical leap, it's a plainly obvious use case.
> Goals:
> Allow web servers to evaluate the authenticity of the device and honest representation of the software stack and the traffic from the device.
No, the worry about adblock was that Google could now just remove the ability for that work in chrome and there would be nothing you could do, because your forked chromium wouldn't pass the attestation check (cause it would never be blessed by Google). This concern extends to other browsers as well. Because Google is making themselves the signing authority here, they can choose which browsers are allowed and which aren't, letting them force other browsers to add or drop certain features if they want to be granted attestation.
Not to mention that chrome on android already does not have any access to extensions and thus adblocking. Isn't that awfully convenient? For GOOG that is.
https://httptoolkit.com/blog/apple-private-access-tokens-att...
Google will change the behavior of website operators that use AdSense. They wouldn't want anyone to be artificially inflating their ad revenue with suspicious un-attested traffic: https://blog.google/products/ads-commerce/understanding-acco...
Silly? Yeah. Petty? Yeah. But sometimes it feels good to exercise your rights.
It seems the premise is that those with a computer should be able to access others servers wholesale unconditionally. This premise is obviously wrong.
> It also raises the barrier to entry for new browsers, something Google employees acknowledged in an unofficial explainer for the new feature, Web Environment Integrity (WEI).
This, however, is true for sure.
At the end of the day, even if WEI is implemented it wouldn’t necessarily get rid of an open web as it’s entirely optional. Those who implement it are those who are not interested in an “open web” to begin with and definitionally were never going to support it anyways.
It eliminates a computer user's ability to have their user agent lie about the platform it's operating on. Such a capability is crucial for privacy and adversarial compatibility. Simple example: your bank of choice starts sniffing your UA string and refusing to serve Firefox, as they only test the site in Chrome and don't want to service support tickets for any other browsers. Presently you can spoof your UA string and visit the site with Firefox anyway. With WEI the bank site now has the technical means to ensure your browser accurately reports its identity and to refuse access to anything but Chrome.
I'm not necessarily claiming that this is how WEI will be used, but the point is it's now up to site operators to choose what makes a valid visitor, rather than the UA being just a transparent medium between you and a website (provided that each is implemented to spec).
Streaming video sites are another prime example. They serve low resolution video to Linux machines because the DRM won’t attest to a secure video decoder. I’m not sure I look forward to similar discrimination from the entire web.
"Obviously" is a very strong word for what is pretty much your opinion.
As the system was designed browsers are an agent of the user, not of the web servers or the ad businesses. If you want guaranteed ad impressions and control go make iPhone apps. Taking an open system such as the web and forcefully closing it up using overwhelming monopoly power like Google is doing is not only disgusting but also incredibly anti-competitive.
> At the end of the day, even if WEI is implemented it wouldn’t necessarily get rid of an open web as it’s entirely optional.
For now. "Entirely optional" can be stretched very far. If you were banned from AdSense revenue and from appearing in search unless you enforced this, it would still be "entirely optional" but also pretty much trash your site unless you complied.
Yes, that is obviously wrong. Accessing a website doesn't give you anything like the ability "to access other servers wholesale unconditionally". Requesting files over HTTPS isn't a gorram root ssh session.
All a user-agent does is ask "Can I have file `/x` please?", "Can I have file `/y` please?", "Here is the data `foo=bar` for `/quux`" etc., etc., etc...
The server is free to say "200 OK" or "400 Fuck off" to any request it receives, at its own discretion, based on whatever rules the server administrator wants to put in place. Which they have the absolute capability to do. That is nothing like "unconditional wholesale access" to a server.
That's the point, I think. I own my computer, which means I decide whether it lies. If I want to serve "This website only works in Chrome" when it's actually cross-platform, that's my right. I might want the client to open the page in Chrome automatically, and I would have more control over the connection if I could do so, but that control would be over the client's computer. It's not a question of getting more or less control in general, but of getting rightful control over my own property.
> both operators want not just control over their computer but also what the other computer can do
Are you saying that my demand to not have a server control what my client does is an act of control over what their computer does? Like if I told you not to use your forklift to take my stuff, I'm asserting power over your property?
> Are you saying that my demand to not have a server control what my client does is an act of control over what their computer does?
Yes. The owner of that computer does not want to serve your requests and you want to prevent them from exerting that control over their computer.
>Like if I told you not to use your forklift to take my stuff, I'm asserting power over your property?
Yes that is what is being argued here. Forklift owners demanding the right to lie about using a forklift to property owners like Google who do not want to allow forklifts to take their stuff.
It doesn't reduce your control, you are still welcome to identify your computer however you want to websites by using a browser without WEI or disabling it.
You will just have to live with the reality that a lot of servers aren't going to want to talk to your client.
The devil is just right there. If an implementor is dominant, and that the feature starts to be used extensively by banks / utility providers or other essential utility, nothing prevent those users to enforce using browsers implementing it, event if it's optional per spec.
The feature then become de-facto mandatory for all implementors, and in the long run google can start refusing serving apps on non-compliants to their de-facto standard without much fuss outside the tech people.
You buy a house. Your house has a little box by the front door. The box holds a small House Environment Integrity (HEI) module. This HEI is something your local Home Owners Association installed. They say you cannot open the box or investigate how the module inside works, as this is against the HOA and you will be fined. They tell you this HEI module is meant to help and protect you. To make sure the plumber you hire didn't do a bad job or that the paint you used on your walls doesn't contain lead. They say it's for your benefit and to make your home a better and safer place. This does not reduce the control of your own house.
Just make sure your visiting friends register with the HOA, and don't get excited about being handy with the curtains, that's gonna require an HOA approved contractor.
Requiring to run a software stack signed by a third-party to access a basic Web page definitely reduces my control over my own computer.
> It seems the premise is that those with a computer should be able to access others servers wholesale unconditionally. This premise is obviously wrong.
That is not the premise since you can already run a closed-club server and only provide accounts to people you want with whichever conditions you chose. You just not entitled to verify the software that clients run.
> At the end of the day, even if WEI is implemented it wouldn’t necessarily get rid of an open web as it’s entirely optional. Those who implement it are those who are not interested in an “open web” to begin with and definitionally were never going to support it anyways.
This will be forced on the Web by ad networks. For our own good and to prevent fraud by the bots of course.
No, the preimise is that a server that offers an HTTP endpoint should provide the same behavior at the endpoint regardless of the nature of the device or software that is accessing it.
Obviously, we have some exceptions already, hence robots.txt
But the idea is that if I am a user pointing something with a reasonable functional distance of "a web browser" at an HTTP server, the server should not alter its behavior based on an attempt to verify the internals of my browser.
The premise is that I shouldn't have to give that server control over locally-running code on my PC as a prereq for access. They can enforce whatever conditions they want server-side.
The EFF will go after orgs that fund it, which requires true compunction.
FIRE is a good replacement for the ACLU, FYI. And John Brown Gun Club is becoming a better NRA.
JBCG doesn't really replace much of the NRA. Even if hypothetically people could join JBCG at mass scale, which they can't due to the way its structured.
The NRA-ILA is increasingly useless for 2A advocacy and legal efforts, but JBCG isn't replacing that at all. FPC, 2AF, to a lesser extent GOA do more there.
NRA courses are crufty but don't really have a replacement approaching anywhere near the same scale. Certainly not JBCG. Maybe USCCA for just the pistol side of things, but that has its own issues since their business model is fleecing people.
NRA competition... there's no replacement for bullseye, but that's because bullseye is becoming an afterthought compared to e.g. USPSA in a lot of areas... smallbore and air as a college&younger sport notwithstanding. And nothing is close to trap/skeet/sc in popularity in the US, but that's not NRA either.
NRA club/range support and insurance.... also nothing replaces this.
---
What JBCG has that the NRA doesn't, and never had, is the same thing that the black panthers had in the 60s - armed support of disenfranchised subsets of the population. It's harder for the police to shut you down, or stand and watch as an adjacent supremacist group shuts you down, if you have your own armed guards.
Same as armed guards prevented mobs from attacking schoolchildren during desegregation in the late 60s, you see JBCG in a lot of places protecting pride events, drag events, etc. 'cus the police often don't. (In the US, it's not the police's job to protect anyone, that's been tried in the Supreme Court multiple times)
(Corollary: maybe that makes them a "better NRA", but it's an odd statement to look at because it sounds something like "DuckDuckGo is becoming a better Nvidia". Yes both are computer-adjacent, but they do completely different things, and have roughly never had any overlap in activities)
"web-TPM" needs to be named-and-shamed among literate people in all nations IMHO. It is clearly political -- there are private winners and public losers in the change to locked and enforced access to digital content on the Internet. Any commercial company in any country that can successfully block the roads and check ID will make money, and they know it.
It is deliberately not a compliment
They are both someone else controlling some part of your property, to control your use of the rest of your property.
Neither is benign or honest. Neither actually does what the sales pitch claims. The sales pitch is a Sales Pitch. It is what you say when you need to convince someone to do something they normally would not want. Anyone can make up a good sounding sales pitch for anything. Quoting the good sounding sales pitch does not show that the thing is good. It just makes one wonder about the speaker.
TPM is not merely "safe secret storage", it's someone else's secret used for someone else's purposes, and one of those purposes is absolutely to "attest" that WEI is valid on this machine at this time.
I can only assume that you know all of this perfectly well and can only guess at possible reasons why anyone who knows what these things do would try to sell the bs cover story that TPM is just another bit of neutral useful handy tech that users can use like a special kind of thumb drive, without mentioning anything about Microsoft and the reality of most actual manufactured devices, and what it actually means even on a machine where it's "disabled".
Not true, you can use it for your secrets as well. There are many many great use-cases for such secret storage.
> one of those purposes is absolutely to "attest" that WEI is valid on this machine at this time.
It can be one of the end results. But that's like blaming CPUs for accelerating crypto with AES-NI.
> They are not even merely similar, they are identical.
If you want to wage an ideological battle, at least remain technically correct.
There's that sales pitch again.
Why do Linux bootloaders have to get a blessing from Microsoft? Why does even one machine exist that has a bios that lacks the supposedly spec mandated option for the user to install their own keys? Why are there keys preloaded on every machine that the user did not provide? Why do they all come from Microsoft? And why can't the user edit or remove them? Why can't the user decide that the MS keys are invalid and that things signed by them should not be allowed to run?
There are so many ways and proofs that this tech is not what it's sales pitch claims it's not even funny.
I can understand not being aware of the underhanded aspects by simply not being aware of anything about it. I can not understand being aware of what it is and how it works, and still being OK with it and defending it as reasonable, useful, not dishonest at all, and exerting no outside _and superior_ control over what is supposed to be the users own property and actions and associations.
They graciously, most of the time, allow you to also store some keys of your own in their vault they caused to be placed on your machine even if you didn't want it? How magnanimous and generous of them!
It's not a sales pitch, it's a very practical application for a TPM. Easy-to-use LUKS is nothing to scoff at for example. If you can't use it, that's your fault.
> Why do Linux bootloaders have to get a blessing from Microsoft?
Nothing to do with TPMs. The rest of the paragraph is nearly as misguided.
> They graciously, most of the time, allow you to also store some keys of your own in their vault they caused to be placed on your machine even if you didn't want it? How magnanimous and generous of them!
Yeah, it's so bad when you have extra hardware that you can utilize for your own purposes. It really is like blaming AES-NI being used for doing public key encryption with someone else's public key. Nobody should ever have anything they should want securely stored because some other technology out there is used in restrictive ways, sure. Obviously that's not true, you're simply pointing your finger at the wrong thing.
Is it only to "reduce ad fraud" though, or the wider agenda is deeper entangle their tracking in one's life.
They are all legitimate phones and labor is cheap so it's easier to just do that rather than try to create script to click on ads etc.
If WEI goes through we'll probably see cheap PCs popping up on eBay that are unable to access certain websites.
I think after 16 years it's time to admit that this model is here to stay, and the only question is whether the web supports it, or whether there will be certain apps and features that will never be available on the web.
[0] https://cloud.google.com/compute/shielded-vm/docs/shielded-v...
Originally posited an incorrect fact here. I completely missed who wrote the article at hand (not sure why, but I didn't see the authors names)
Good catch everyone
The EFF is being misleading here by conflating the attestation taken and fingerprintable information like a user agent. An attestation taken does not contain information about the device that can be used to identify since the data the site gets is low entropy. WEI doesn't stop you from changing your user agent, nor does it prevent you from using your privacy web extentions.
>But, despite their valiant attempts to cast these benefits as accruing to device owners, these are really designed to benefit the owners of commercial services; the benefit to users comes from the assumption that commercial operators will use the additional profits from remote attestation to make their services better for their users.
End users are not the only stake holders in the web. I would say most changes to the web are for people who develop sites and end users benefit from sites using those features.
>Putting handcuffs on every shopper who enters a store would doubtless reduce shoplifting, and stores with less shoplifting might lower their prices, benefitting all of their customers. But ultimately, shoplifting is the store’s problem, not the shoppers’, and it’s not fair for the store to make everyone else bear the cost of resolving its difficulties.
This metaphor isn't the same since WEI is transparent to users. Physical handcuffs would be very intrusive, but that isn't what is happening here. Shop lifting affects the profitablity of the store. A better metaphor would be a bouncer for a club. Technically a club could have a set of rules of entering and customers could promise that they follow them. Unfortunately, people lie and just trusting them isn't good enough so clubs end up adding bouncers even though they don't directly make the experience for customers better.
>The problem is, there are lots of websites that would really, really like the power to dictate what browser and operating system people can use
This claim needs a citation of where user agent based blocking isn't enough. People spoofing their user agent won't make much of a difference to support costs of the site.
>The web is the last major open platform left on the internet - the last platform where anyone can make a browser or a website and participate, without having to ask permission or meet someone else’s specifications.
WEI doesn't prevent you from participating in the web or needing to meet someone else's specification. You can even make an attestation service for your own browser.
>We sympathize with businesses whose revenues might be impacted by ad-fraud, game companies that struggle with cheaters, and services that struggle with bots. But addressing these problems can’t come before the right of technology users to choose how their computers work, or what those computers tell others about them, because the right to control one’s own devices is a building block of all civil rights in the digital world..
To prevent ad fraud either you need to increase the fingerprintablity of users on the web, violating people's privacy, or implemented a form of remote attestation, which protects people's privacy.
If EFF cares no much about privacy on the web they should be in favor of this proposal.
I disagree that beivg a to lie about what your device is running in a building block of all civil rights because the physical analog, fraud, is illegal, and the world seems better without people commuting fraud to one another.
Citation needed, how does WEI make it _impossible_ for attesters to return higher entropy information? Pinkie promises are insufficient.
> WEI doesn't stop you from changing your user agent
False, this is an explicit design goal: "Allow web servers to evaluate the authenticity of the device and honest representation of the software stack and the traffic from the device."
> nor does it prevent you from using your privacy web extentions
Not an explicit goal, but a very obvious next step with strong economic incentives.
> Physical handcuffs would be very intrusive, but that isn't what is happening here.
Seeing a message that says "Sorry, this website is only accessible by browsers that support WEI" is very intrusive.
> WEI doesn't prevent you from participating in the web or needing to meet someone else's specification. You can even make an attestation service for your own browser.
Categorically false, no website is going to trust your attestation service. This is equivalent to saying "Just create your own CA".
> I disagree that beivg a to lie about what your device is running in a building block of all civil rights because the physical analog, fraud, is illegal, and the world seems better without people commuting fraud to one another.
No, the physical analog is "lying", which isn't illegal in most situations, and required in some - such as when a stalker asks you where you live.
It isn't impossible, but doing so would violate users privacy which isn't the goal of the proposal. You don't need WEI to violate people's privacy.
>False, this is an explicit design goal: "Allow web servers to evaluate the authenticity of the device and honest representation of the software stack and the traffic from the device."
That statement means that the site would learn that for example the server can trust that the user is using Chrome on windows. A feature of Chrome is that it's possible to spoof your user agent.
>Seeing a message that says "Sorry, this website is only accessible by browsers that support WEI" is very intrusive.
This can apply to anyone API. It's happened for WebGPU. It's blocking users is not a goal of the API.
>no website is going to trust your attestation service. This is equivalent to saying "Just create your own CA".
It is possible to create your own CA. How do you think things like Lets Encrypt came into existence. Trust is hard to earn. That doesn't mean that it is impossible to get people to trust you.
>No, the physical analog is "lying", which isn't illegal in most situations
I agree, but WEI is meant to be used in situations where lying should be illegal.
But here I once again have to point out that in practice this will look very different.
The practical effect is that if someone installs LineageOS or even AOSP to get rid of Google spyware and preinstalled bloatware, then these attestation checks will fail and that user will not be able to use apps that are necessary in practice.
The question is whether this is really a "side effect" or just the actual goal.
They don't need WEI to keep the vast majority of users away from obscure alternative OSes, but as a side effect those would be impacted.
Wrong. RFC 8890 clearly states that the internet is for end users.
As always, Google will do its best to ensure it PRACTICALLY does, while denying it at the same time by pointing out that "you can make your own Google".
> because the physical analog, fraud, is illegal,
I don't know about the US, but in Poland abusive and anticompetitive clauses are not enforceable. Lying about the device seems to be the digital equivalent.
Not all lying is equal. If an ad network uses WEI to avoid lies made to defraud them their goal is not to be anticompetitive.
>If EFF cares no much about privacy on the web they should be in favor of this proposal.
Privacy on the web by implementing remote attestation across the web will inevitably in practice reduce digital rights and user control/freedom. The EFF also cares a lot about this, so it makes sense that they would be against the proposal. Both of these goals could be achieved by websites providing the same behavior regardless of the client browser/software that is requesting pages. The reason we have to lie is because user-hostile businesses/sites don't want to adhere to this (advertising, DRM). (ignoring useful things like providing a mobile version of a site)
To note, fingerprinting is always going to be technically possible (especially given the larger and larger feature scope that businesses have wanted to impose upon the web since its inception), WEI is just an attempt to stop ad-driven sites from trying to do it.
Not true at all in the slightest, even with the sorry explanation Google employees tried to conjure.
> To prevent ad fraud either you need to increase the fingerprintablity of users on the web, violating people's privacy, or implemented a form of remote attestation, which protects people's privacy.
Not true either, you don't have to do any of that. And why exactly should the client be responsible for ad fraud? These suckers, advertisers, try to track me without consent for years and abuse every legal gray area there is. Boot me from a service if you don't like my client for all I care, just be transparent about it.
> You can even make an attestation service for your own browser.
I don't want that. I do indeed vet clients connecting to my service to defend against attacks, but WEI comes with a cost I would never be willing to pay.
Citation needed.
Ads are not beneficial to users of the web. There does not exist a website that is better WITH ads. Users do not care about ad fraud.
Ads are beneficial to adtech and companies with ad spend.
We should not destroy the entire internet to protect/increase adtech profits.
Yeah, ideally businesses wouldn't be built on this model (free service funded by ads at the expense of privacy and now user control). Then we might not have had to worry about widespread fingerprinting AND we can maintain user control too.
Ads can fund the development of the site, the services of the site, and the content on the site. The amount of additional value that the site is able to provide users is much more than the value that gets taken away by including ads. I haven't even mentioned how the ability of users to advertise things on the web is also very useful.
>Ads are beneficial to adtech and companies with ad spend.
Who are both users of the web too.