Web Environment Integrity has no standing at W3C; understanding new W3C work
w3.org
w3.org
I say this because, at first glance, it seems like the only stakeholders with any influence are W3C Members. The reality is that W3C is very open to contributions from individuals, but just has had a constitutional framework that makes things slightly more complicated for individuals, a situation which they are deliberately improving.
As for myself, I'm an IE for the W3C in the Linked Data area, so whilst of course I do not speak for the W3C, I would be more than happy to answer questions here on HN about how the W3C works.
His team lead (Dmitry Zagidulin) liked what we were doing a lot. But ultimately Tim chose to go in a different direction, spun off "Inrupt" and left MIT. We continued building our open source platform to try to realize the vision he keeps writing about: https://theconversation.com/tim-berners-lees-plan-to-save-th...
I was writing very similar things, but of course I didn't invent the Web: https://cointelegraph.com/news/how-a-web-that-lost-its-way-c...
Ultimately, my point is that we tried our best. I even hired Dmitry when he left Tim's project for a while, but very quickly Dmitry got demotivated to work with us because we were putting out working code for customers, instead of conforming to standards. Back then I argued to him that we don't have a ton of funding and executions matters more, after which the winners can help spearhead the standards. After all, Twitter pioneered oAuth, and Meebo+Google pioneered xAuth (if anyone remembers that). Dmitri and I did.
So we went our separate ways, and I realized that standards are an expensive detour that can work if you have extra funds to hire people. We plan to support Matrix, Mastodon and other interoperability. But for the time being, our platform is "just" free and open source.
Whether it's the UBI "movement", or the decentralized web, or other initiatives, everyone seems to go their separate way and it fizzles out (e.g. https://decentralizedweb.net and https://indieweb.org/). I wish people were willing to join forces on projects more, and get each other funded. That's how we can build real open source alternatives to the corporate internet we are all forced to depend on.
0. seek out appropriate, minimum friction standards before reinventing the wheel
1. refuse to implement solutions that harm users
Data canonicalisation is one such example: although the idea has been around for quite a while, a couple of years ago lots of people spontaneously decided it was something they needed (myself included!), and here we are with RDF canonicalisation[1] nearing Candidate Recommendation not even halfway through its WG's charter, along with several mutually independent approaches also in a good state of development. The result of this is that in about one more year from now, software developers will find cryptographic verification of data considerably more consistent, which can be translated into a pretty significant boon for Web users.
The ideal timing of a standard is surely after the limits of the idea have been found by theorising or prototyping, and before anyone with that idea has a large enough commercial interest in it to benefit from a monopoly on it. Trying to build a monopoly first and then 'donating' it by spearheading a standard is a viable technique, but it feels risky to me unless you can be sure that you're really the only party who understands the idea, and so won't be overtaken by someone with equally monopolistic but less altruistic motives.
I think that a good place to start is limiting the scope of a proposed standard very consciously, unless as you say you have the funds to hire everyone you need to implement it entirely at least once. Although I'm not familiar enough with your project to comment on any details, I suspect that most social network or forum applications could implement one way ActivityPub or Matrix support easily, and also proper two-way federation unless the original software makes too many assumptions about identity.
It's not W3C's (or WhatWG's) role to "oppose" random things browser vendors decide to do.
You should too.
https://www.ftc.gov/about-ftc/bureaus-offices/bureau-competi...
for the FTC's contact information
Most blocs have their own standards. Commonwealth countries follow one standard, EU countries another, North American engineering standards are not the same as Japanese ones.
Who would grant them such a authority and how would it be enforced?
I agree we shouldn't let a single web browser dominate. I'm just saying that the W3C doesn't have any power to do so nor have they shown themselves capable of pulling it off.
Then why are they making standards in the first place?
They're already deeply involved in the operation of browsers; they are practically morally obliged to object to things which could harm the Web.
I'm not arguing if the OP is right or not but I don't think the OED example is correct.
A better example would be a language academy, however English has never had a language academy, unlike French or Spanish, resulting in it being a stubbornly descriptivist, rather than prescriptivist phenomenon.
The OED, in my experience, covers the varieties of English spelling quite well, and if you want no distractions as an American but can deal with less extravagantly complete coveraged, you can always use the OAD.
Oxford seems to know how to spell quite well.
I had to give a chuckle at that, but seriously, the way in which words are spelt (ahem) in the OED is genuinely interesting! They use both -ize and -ise, for instance, choosing one or the other based on each individual word's etymology.
The OED includes American spellings for all of its entries.
Source: I have an OED subscription and look at it regularly.
For one thing, membership in W3C is loaded with representatives from those browser vendors. Which is a good thing, since W3C would be absolutely useless if browser vendors weren't there.
For another, standards aren't the place for rants about who sucks shit and who doesn't. It would be a fun read, but a bad standard. A standard is for saying what you must do, not for saying who sucks shit.
> Aim to reduce centralization in Web architecture, minimizing single points of failure and single points of control.
IMO it is entirely in scope for, and part of the responsibility of, the W3C to introduce a specification that explicitly forbids user agents from implementing Web Environment Integrity or any similar system as currently drafted.
One might say that the members' conflicts of interest make it likely that they will abdicate this responsibility, but that doesn't make it any less their role!
Maybe Google cares, maybe not, but there's no sense in having a spineless standards body that just turns around and says that the spec is whatever Google implements in Chrome.
The only way for FLoC to become a standard is for them to do exactly what they're doing now - opt in/feature-flagged evaluation.
Of course, Google could continue to ignore the standards process and just make this generally available in their browser even if it doesn't become a standard.
That's exactly what they've been doing with dozens of "standards".
Also, nobody really gives a shit about it. WEI could break adblockers and that would be a huge issue.
Google isn't (yet) big enough to force it through: given iOS marketshare in the US it means web-app devs won't (can't?) do anything unless both Apple and Google adopt it (yes, there are plenty of Chrome-only websites, and Safari has been slow to adopt new web-standards, especially when they begin to tread on the toes of Apple's App Store (PWAs, WebUSB, etc).
----
That said, I am sympathetic to the reasons why orgs like banks want things like remote-device attestation (and am less sympathetic to the likes of the MPAA, etc) - it is unfortunate that better ideas are hard to come by.
Many of those are not "new web standards". Those are Chrome-only non-standards, and Firefox agrees with Safari on most of them.
As for PWAs, there's no such thing as a single PWA standard, and Safari has supported the vast majority of the PWA standards for years (but if you point that out, the goalposts of what constitutes a PWA shift faster than superheated plasma).
https://gist.github.com/pesterhazy/4de96193af89a6dd5ce682ce2...
Fortunately, Safari does support OPFS ( https://stackoverflow.com/a/71581910/159145 ) so provided you don't need all of IndexedDB's features and just need an async blob store for large blobs/files/etc (potentially gigabytes and beyond) then OPFS should work for you.
The amount of popular videos served on YouTube in VP9 and Opus may not exactly be WebM, but the codec support byproduct it pushed probably saved Google/YouTube a huge pile of cash.
EDIT: Or do you mean "Private Access Tokens"? I just found out about this now and wow... looks like I've got some reading to do, but so-far it seems far more limited in scope than Google's version, and doesn't seem like it can be used to fingerprint visitors between sessions either. ( https://httptoolkit.com/blog/apple-private-access-tokens-att... )
Though I cannot help but wonder why exactly they did that. Some kind of a corporate requirement?
But also JFC, it is amazing how the moment it is pointed out that Apple is already doing a thing that's being railing at, and the reaction shifts from outrage to basically "I wonder what amazing and important reason they have for doing this" and "nobody but Apple can possibly be allowed to benefit from this because monopoly".
Apple's stated reason is exactly the same as Google's. To make a privacy-preserving anti-abuse signal for browsers. Apple need it because they are piping their best customers' traffic into what is basically an open sewer of IP reputation (Apple Private Relay), and need a way to avoid said customers giving up in disgust due to the high rate of captchas. Google need it because they want to remove all fingerprinting vectors, and need privacy-preserving replacements for legit use cases.
That's not what I said.
I don't care who does this, I will despise it either way, I just hope that Apple at least has a proper justification to do this.
> Google need it because they want to remove all fingerprinting vectors, and need privacy-preserving replacements for legit use cases
"Legit" defined by whom? Google? I am sorry but at this point Google has burned almost all trust, at least with me.
Cautious.
Many of those web-standards e.g. WebUSB have significant security vectors and have been used in the past to fingerprint devices for advertiser tracking. Also many have impacts on battery life and performance.
Whereas Chrome seems to be getting slower and bloated over time, Safari has remained fast and light-weight.
I'm not. I mean, I am in theory; being able to warn a user their device might have some sort of malware upon trying to log into a banking website is useful, but we've already seen how banks handle these things in practice with mobile devices having attestation capabilities.
The result is some banking apps refuse to run on my phone with a very up-to-date and definitely not compromised LineageOS, but will happily run on devices several years out of date. Google SafetyNet can tell that the bootloader is locked and the system partition hasn't been modified, but can't tell that some malware has gained root access by privilege escalation.
I don't want them doing that to their websites as well. This technology should not be let loose on the world.
When they want, Google literally strongarms various vendors into implementing their codecs: https://www.protocol.com/youtube-tv-roku-issues
--- start quote ---
At the core of this allegation appears to be Google's decision to push hardware makers to adopt the AV1 codec, an open video codec that promises better-looking 4K videos at lower bitrates. As Protocol first reported in October, Google is requiring makers of Android TV devices to support AV1 starting this month. Additionally, Google also seems to push makers of smart TVs and streaming devices not based on Android TV to use AV1 for YouTube.
...
Google has long forced device makers to use the free VP9 codec for 4K YouTube streams.
--- end quote ---
That's different from making it a web standard. They will want cooperation from other browser vendors (not random people on the Internet) for that.
I doubt they'll make a serious effort at convincing anyone of anything until they decide what they want to do, which will be based on the results of the experiment.
Not sure I understand your point.
https://www.reuters.com/article/idINIndia-29194320070828
https://www.reuters.com/article/us-microsoft-standard/micros...
https://www.computerworld.com/article/2548569/ecma-approves-...
https://www.reuters.com/world/uk/uk-regulator-accepts-google...
Seems like making a browser isn’t profitable at all, and so the hypothetical Chrome Browser Corporation would probably quickly turn to evil tracking schemes as well.
They do implement ad blocking/anti fingerprinting. Mozilla obviously has to continue setting Google as the default search engine.
This could have the effect of normalizing corporate investment in FOSS web engines and browsers, which could benefit Mozilla as well.
Are those accidentally reversed?
In the analogy here, wouldn't the W3C be the UN defiantly making toothless proclamations that Chrome (the US) can simply ignore? That would be my understanding of it, since "mattering about as much" implies not mattering at all.
US does ignore UN in other ways, but the ICC isnt an example of that.
Then point the other half of the test suite at a candidate site and get a similar list of naughies and nices.
Conscientious technologists of the world can then refuse to support browsers or sites that test naughty.
This is my attempt to avoid preaching to the choir. Market share wise, only a tiny slice would opt into the non-evil browser. But it's that slice who also makes things work for the rest of the world, so:
> it's out of my scope of support unless it passes these tests
Might impact a wider audience.
Perhaps we could have a suite of Web Platform Tests? And we could host them at https://wpt.fyi ?
If Google adds WEI to chromium, will wpt.fyi flag it as broken?
If the WEI proposal keeps progressing towards a standard I'd expect that team to submit a test to WPT, yes.
When those neckbeards represent 50-60% of total web traffic their opinion might matter. Marketshare is power and in realpolitik power is all that matters. The tech world is littered with the remains of the companies that made principled stands, google and Microsoft are where they are for a reason and it’s not because of their overriding morals.
Right now google has >80% of traffic and now that they have pried safari open that number is gonna climb. Their opinion is literally the only one that matters - what are you gonna do, not use google products?
if google wants to fight they’ll win, have fun getting into your gmail account if they require attestation. What are you gonna do, not use email? Change your whole internet identity to not run on google? Gmail is effectively email, and small mailservers are fundamentally broken on the modern web. Even for things like outlook.com they could require that other mailservers provide the attestation used to send it and lock people out of gmail entirely, even just needing to gmail.
It’s game over, the apple sideloading case swept away the last resistance to chrome monoculture, and google already runs a supermajority of the other web services that matter. This is google flexing their muscles now that they know they’re utterly unopposed. But unfortunately the EU is way more concerned with outlawing the lightning port and mandating 2000s-vintage removable battery phone designs than actually fighting a monopoly using its monopoly power to leverage abusive behavior in related market segments to the detriment of consumers.
This is a classic useful-idiot situation where all the android fanboys waved their flags at their “team win” over “braindead” apple fans getting the app-review process neutered by sideloading. Because it’s not enough to have a popular brand which supports that too, you need to outlaw any alternative business models to your preferred brand. And despite warnings that exactly this chrome monoculture would be the outcome, people pushed for it anyway. Wait and see, they said, we’ll cross that bridge when we come to it and if google starts to be a problem the EU will step in. It took literally a matter of weeks before google just went ahead and crossed that bridge. Extremely frustrating.
And yea, safari has some attestation features too. Not necessarily the same ones as google, and they don’t prevent Wipr or Adblock Plus extensions from working. But now you’ve gone and made sure there’s no alternative browsers that don’t, either. You pushed this on yourself. sideloading has locked in an unshakeable chrome monopoly marketshare, it’s going to be a massive uphill battle to sell people on Firefox when it doesn’t even work on almost any relevant web services because it doesn’t (by design) allow attestation.
Almost as if... most of Apple's iOS stances aren't just random/exploitative, but actually have some basis in security posture or app-review. And almost as if... Apple is still fundamentally trying to sell you a phone first and foremost, then icloud/apple music revenue, and then adtech is way down on the list, while google makes all its money from (a) ecosystem effect and the monopolistic behaviors it allows, and (b) direct revenue from adtech. People keep trying to push the "apple is the same thing!" and just like you can see from their attestation not caring about adblocking, it's really not.
I loathe that the brand wars have gotten to this place, "both sides are the same" but also they are different enough that you need to literally outlaw the business model of your competition and reduce choice in the market. Can't let some "brainless" apple fan make a different choice from you, you know best for everyone.
their mission is only to write formal standards to describe and document the things that browsers have already implemented, not to drive browser development.
W3C is not only about HTML, JavaScript, and CSS.
https://en.m.wikipedia.org/wiki/World_Wide_Web_Consortium#St...
E.g., I don't see WHATWG contributing anything of relevance regarding web accessibility, whereas W3C takes care of accessibility with WAI-ARIA and WCAG.
To actually become a standard it needs at least two inependent implementations.
But it's interesting that you wrote what you wrote. Because that's exactly what Chrome is doing: it's announcing an intent to implement, and then enables whatever they intend by default. Oh, they do pretend to ask other vendors about their position, but ship anyway. And then use web.dev to pretend it's a standard.
- Accessibility
- Authentication
- CSS
- Self-Sovereign Identity
- Virtual Reality
- Linked Data
- XML
I wrote a comment about the W3C's relationship with WHATWG a few days ago: https://news.ycombinator.com/item?id=37052428
If you do nothing else, please pass your eyes over the list of W3C Recommendations and other publications on standards track: https://www.w3.org/TR/
And yes, even VRML :)
https://www.w3.org/MarkUp/html-spec/ HTML 2 (the wild west)
https://www.w3.org/MarkUp/Wilbur/ HTML 3.2
https://www.w3.org/TR/WD-html40-970708/appendix/changes.html Diffs of HTML 3.2 -> 4
https://www.w3.org/People/Raggett/book4/ch02.html History of HTML until 3.2
https://www.w3.org/TR/html401/ HTML 4
https://www.w3.org/TR/html5-diff/ Diffs of HTML 4 -> 5
https://www.w3.org/TR/2021/NOTE-html53-20210128/ HTML 5.3 (last version on W3C)
https://html.spec.whatwg.org/multipage/ HTML5.3+ (moved to whatwg)
https://www.w3.org/MarkUp/VRML/ Virtual Reality Markup Language
https://web.archive.org/web/20041204114715/http://www.cc.uka...
A stance to irrelevance, sadly.
This was always the deal with the devil that W3C had; play ball with the vendors or get left in the dust.
But could someone else create a W3C proposal that could counteract WEI? It wouldn't have to implementation-specific but rather one or more principles drawing a line in the sand that shouldn't be crossed like what WEI is built to achieve?
If a user who is not you uses a browser using WEI (implicitly approving of this attestation tech) and connects to a website that uses WEI, that's entirely up to third-parties and there's nothing legal that you can do.
The most you can do is protest this with:
1. Using a browser without WEI or with WEI disabled.
2. Modifying your own site to talk the WEI protocol but for any browser that can talk that protocol, you ban the user from using your site (or redirect them to a site explaining how WEI is DRM of the entire internet, etc)
Moving beyond White Hat to Grey Hat and Black Hat, you get things like:
1. Modifying your own hosting company to apply this WEI-blacklisting mechanism to your clients' websites.
2. Convincing (or "convincing") owners of core backend libraries in popular programming languages to introspect connections and blacklist WEI-compatible browsers.
3. Take advantage of XSS vulnerabilities to interfere with WEI operations on other tabs within the same browser on the user's machine if they happen to be using your website.
4. Take advantage of vulnerabilities in the WEI protocol to corrupt the underlying attestation system so it fails to function in all future WEI requests for that physical machine.
5. Hack/Crack attestation system security and publicly release the keys, making any hardware using that version suspicious/blacklisted by users of WEI.
6. Probably some other things I haven't thought of, but as you can see they quickly go from dubiously legal to straight-up illegal. It would be best to nip WEI in the bud before such measures are deemed necessary.
In those situations, enterprises have the jurisdiction and need to know who is connecting to their network.
Putting a technology like this into a browser seems to only benefit sites that monetize their content...
I thought it lost some of it's influence, but can't recall why.
I would say that it was a pretty minor loss of influence overall, and their Linked Data is now used in almost all websites in at least a basic metadata capacity, which is how those 'social links' work (where you paste a URL in a chatroom or social network and find the title, logo and header picture appear automatically) for instance. More extensive use of Linked Data is often not directly visible to website visitors, but will soon form the foundation of a number of digital identity card systems, even for entire countries, and will do so in a way which has the potential to be significantly more privacy-friendly than a traditional 'citizen number' approach.
I'm currently a participant in the Linked Data area of W3C's work, but I wasn't around during the events I describe above. Resilient Web Design[1], a short but excellent ebook by Jeremy Keith is a good read for understanding why RDF didn't catch on initially, and anything by Manu Sporny will be worth reading/watching for getting a positive description of how useful RDF and Linked Data can be (his introduction video to the topic, for instance[2]).