Tech giants are hijacking the internet
dw.com
dw.com
DW does not even have an RSS feed for chris sake.
The press is complicit in the hijacking of the internet. They made a Faustian pact. Now they are crying foul.
Might sound smart but perhaps not the wisest of criticism.
Let’s encourage dissent so we can preserve democracies.
The author argues they are too powerful. We had open standards and big tech embraced and then locked it into their platforms. We need regulations at this point.
On the back end, there is I'm sure a complex and covert dashboard project and monitoring systems to detect ideas and trends that fuel/drive decisions in Google's deeply anti-competitive behavior. There's even a solid chance that legislators are tapped via enterprise Gmail services the government now heartily uses (for example), and Google knows everything that is coming through the pipeline. Everyone was warned by scholars long ago about exactly this scenario, but we keep re-inventing the Titanic and the Hindenburg on hubris and ignorance, it never fails. It's far too late to regulate this away. Google needs to be broken up and diversified into new and totally individually distinct and independent companies for future accountability and segregation of info to be upheld.
If you want to self host a site your ISP won't let you. If you want to self host email, none of your messages will get through.
15 years ago I could host a site at home. Today, it can't be done.
Want to regulate something... Make ISP's allow for self hosting. My 5 year old android phone has the power to host a small personal site, but my ISP won't let it happen.
But those giant sclerotic organizations could assume some responsibility for the mess they have helped create by, in the first instance signalling they understand this.
Somebody mentioned in the thread they have a trial account on mastodon. Good, five years late but better than never.
Only because they got caught with leaks like the Twitter Files. Now their trustworthiness is at an all time low, and they need to make someone else look like the bad guy. Insert spiderman pointing at spiderman meme here...
https://en.wikipedia.org/wiki/Whataboutism
The "whatabout" type replies would seem to require that the only websites that can report on the ills of the internet are ones that have no ads, no tracking, no telemetry, no data collection, and so on. Everything must be perfect. That's a bit silly. Shooting the messenger.
Arguably, it does not really matter who is delivering the message. It's the message that matters.
It's not too difficult to transform sitemap XML into RSS.
"A straw man fallacy (sometimes written as strawman) is the informal fallacy of refuting an argument different from the one actually under discussion, while not recognizing or acknowledging the distinction"
I did not ask that they don't have ads, not track their readers, and so on. I asked why there is no link whatsoever besides the usual big tech traps.
Critical question or argument: Tech giants are hijacking the internet
Counter-question or counter-accusations: 1. Why doesn't DW have a link to a fediverse. 2. DW does not have an RSS feed. 3. The press is complicit in hijacking the internet.
The critical question or argument is neither answered or discussed.
Some media companies are experimenting with it right now: https://www.bbc.com/rd/blog/2023-07-mastodon-distributed-dec...
It makes sense for media companies to self host.
You try to download chrome, but since you once used some ad-block plugin, you've been banned from using all alphabet products. Google has also decided that in order to use chrome, you need to have a valid user account to login with.
Clients says screw this, I'm gonna find someone else.
(switch out client with friends, family, or whatever - one web for you, one web for the rest).
Nowadays it is super simple to use GPG with email using Thunderbird, barely an inconvenience. [1] In my opinion everyone should set this up even if they do not plan to use it in the event something sensitive needs to be discussed and one does not trust platforms like Signal or WhatsApp which I do not. GPG is email provider agnostic. Mozilla are working on Thunderbird for phones. [2]
[0a] - https://winscp.net/
[0b] - https://ohblog.net/sftp_accounts_with_null_passwords.txt
[1] - https://www.zdnet.com/article/how-to-encrypt-email-in-thunde...
[2] - https://blog.thunderbird.net/2022/06/faq-thunderbird-mobile-...
Notably, this also requires that you are important enough. To some people, like the hypothetical client, you are not.
That part is particularly likely because that's literally what Web Environment Integrity does.
https://en.wikipedia.org/wiki/Web_Environment_Integrity
The use it to validate if the browser you are using is one of their signed binaries.
Of course the original intention was to detect fraudulent ad clicks, but the reality will that you will be met by captchas every step of the way if you dare to compile your own binary.
> It would provide websites with an API telling them whether the browser and the platform it is running on that is currently in use is trusted by an authoritative third party (called an attester).
And https://www.xda-developers.com/google-web-environment-integr... says:
> The proposal threatens the free and open internet in a number of ways, but one of the biggest revolves around the fact that should there be a central server that attests to whether a browser can be trusted or not, it means that anything non-standard will not be trusted. In other words, new browsers would not be trusted, and legacy software would no longer be able to access much of the internet after a certain length of time. Given that it verifies the integrity of the browser, it could also technically block certain extensions (such as Adblock) if Google were to go down that route.
But that doesn't mean that its sole purpose is to verify that you're using an official Chrome build.
It's being used to be able to tell bots from humans. A human will be required to run a browser with proper attestation that they're a human. It can be used for good (prevent bots from accessing the site) and bad (prevent humans from using anything but chrome).
> WEI is a way to cryptographically prove to a remote website that you're really browsing it with an unmodified build of Chrome
What you're saying (and what I read) appears much more general than that. It could be used to block anything but official builds of Chrome, but that doesn't mean that's what it's for.
It's like a knife, it has lots of uses, one of them is to kill people.
adversarial indeed.
[0] https://en.wikipedia.org/wiki/Chromium_(web_browser)#Active
1. I can't use anything else other than WhatsApp for messaging with families and friends. Thank God my kids' school still uses good-old email for communications.
2. Almost all the useful video tutorials/mini-documentaries/science-shorts are on Youtube and nowhere else.
3. Family and friends always send me links to videos and posts on Facebook, Twitter and Tiktok. I don't usually click when it's just some meme or for laughs but sometimes it a post that matters to me/them enough to click on it.
Old web I care is still there too, but I mirror everything I feel I will need in the future. Just in case.
There are various ways ads could be regulated and historical precedents.
Regardless of whether this ever happens, currently, online advertising is highly centralised and under increasing scrutiny. This centralisation is not the result of innovation by a select few companies but plain old M&A by the so-called "tech" giants, while the the government was apparently sleeping. If more competition were to take place in online ad services, this could potentially have a serious effect on the lifeblood of so-called "tech" giants. Time will tell.
The reason there are tech monopolies is because of the network effect. It's not practical to expect healthy competition in domains where your product's quality is primarily driven by the number of users you have, and they start with billions, and you start with zero.
Enforce open standards, prevent companies from coercing users to sign away their rights to content they generate, and you will have rich competition because you effectively eliminate the network effect.
How many people are paying for their news? For something like YouTube? That stuff costs mega $$$
Back in the day, you were forced to pay for things. You wanted news? You had to put in some coins for a newspaper.
Now you sign on and you get news and YouTube seemingly for free… open standards or not, someone has to pay for it one way or another.
Anyway my point is that the problem is not the lack of open standards. The problem is that we discovered how to do “free” and a lot of people prefer this way whether they want to think about it or not.
I can get behind ads in moderation or subscriptions that aren't mired in dark patterns, but I feel like 30% of my time consuming anything on social media is spent on watching ads, so I just go do something else now.
You’re simply making the case that these services that no one believes useful enough to pay for are controlling everything because they’re frontends for marketing agencies. This isn’t the gotcha you seem to think it is
The only things I willingly and voluntarily pay for are news and music subscriptions and that’s because I value them the most and consider them important to society but I definitely don’t necessarily use them the most.
Anyway my only point is that it has nothing with open standards. People want free and will take advertising if it means it’s free.
Or you could contribute to open protocols, and do to the tech giants what:
The Web did to AOL, MSN, etc.
VoIP did to AT&T, Sprint, etc.
Wikipedia did to Britannica
OpenStreetMap will do to Google Maps
etc.
Open, permissionless networks beat closed, proprietary ones once they are good enough.I spent 10 years and over $1 million from my company’s revenues to build an open source social operating system to power pretty much all the applications you’d want:
Hope it helps! About to release v2.0 on GitHub
https://github.com/Qbix/Platform
(And 5 years ago spun off https://intercoin.org/applications — we are still in the development stage on that one).
I have not looked into it too deeply, but I also have not seen any mention of any sort of open standards that would lift Qbix from being another vendor to be locked into. No OID/OID Connect, ActivityPub, etc. Instead it mentions integration with Facebook of all things. Where is the openness?
I’m using Firefox Focus on an iPhone 14, iOS 16.6.1
Generally yes, but not necessarily - look at what happened when we (the nerds who write free software) collectively decided that IRC was “good enough” :(
The diseases are centrally controlled IP, DNS and root certificates.
The removal attempt of HTTP/1.1 is the biggest censorship in history.
The only way to fight back is to self host DNS, HTTP and SMTP at home.
I’d love some more context on this.
Anti-virus software blocks native applications that use HTTP.
The only context in which plain HTTP is ok on today's internet is when you a loading a page from your own server on the same LAN, behind a firewall, when you are reasonably sure that nobody else is in you network.
I'd appreciate if self-signed certs of some kinds weren't so alerty though. Though, that might inspire false confidence.
Safety and freedom are natural enemies.
No they can't. If they can inject malicious content then you should fix the exploits on your platform. HTTPS isn't going to save you. If exploitable under HTTP hey can do the same under HTTPS.
So, How is a static webpage of "hello world" unsafe?
<html> <body> hello world <a href ref="byesantiy.html"> sigh </a> </body> <html>
Replace hello world with whatever information. My father stores his studies in HTML, no GETs, POST requests. Just a href to the next page.
Unless you have actual access to the html file.. You tell me, why should I require cert for that following syntax? You don't.
There is no such thing as a "static" web page in the context of a MITM attack. The MITM can change the page to ANYTHING he wants it to be. The HTML you receive can be a completely different page than the one sitting on your server.
HTTPS protects you from that. It ensures that the HTML you receive is the same HTML from the server. That's why I sad: The only way unencrypted HTTP is reasonable is when you are fairly sure that there isn't a MITM. Like on your local LAN--anything that goes across the public internet is suspect.
> If they can inject malicious content then you should fix the exploits on your platform.
This is not reasonable. Literally every browser out there has multiple 0-days show up every year. Chrome, Firefox, Brave, Safari, Edge, you name it.
Or not even a public wifi. Someone can put a device somewhere between your home and ISP and MiTM attack you the same way as above.
Oh, and I will just show you fake e.g. Google login page, not just replace the context. And you are tired and just want to use the web... You won't notice the unsecured connection.
If you were visit that page on an network that is not MiTM the website is still secure. There is no requirement for SSL.
The scenarios you listed can even make HTTPS insecure.
The users laptop is infected with a virus, their antivirus software has been exploited with a bogus root cert.
You don't understand what HTTPS does, then.
HTTPS is specifically designed to counter MITM attacks, so it is, in fact, not insecure in the scenarios listed by the parent comment.
> If you were visit that page on an network that is not MiTM the website is still secure. There is no requirement for SSL.
That is really only relevant when you and your sever are on the same LAN, behind a firewall, and you are reasonably sure that you don't have an intruder (like I mentioned upthread).
When you are browsing a server across the public internet, you should assume you are being MITM'd. With HTTP (not S), the MITM attacker does not need to be between you and the server. If they can guess the TCP sequence number and when you are browsing, the MITM can inject (or replace) arbitrary content into the pages you load.
You're missing the point, which is that this statement has nothing to do with TLS.
Agreed, but DNS at least needs to be shared via encrypted p2p, to avoid congesting someones broadband with million requests and prevent the inevitable hijacking by malicious actors.
You mean blockchain? DNS has been solved with namecoin more than a decade ago. One of the few blockchain applications that actually make sense.
That hindsight is always 2020 (semi-related - https://www.explainxkcd.com/wiki/index.php/875:_2009_Called)
This doesn't sound like a good idea. The collection of user data and the underlying advertising business model is a problem to be removed, not a playing field for more competition and "improvement".
They are just shaping the narrative for Google antitrust case.
Check the number of article on Google's case. "Something" is happening just today.
I think that's what Facebook wants.
There was no hijacking. Anyone can still make their own site and become popular. TikTok was able to become the number one site despite not being from big tech.
As for the comment that TikTok got big, sure they've managed to amass a fairly large user base but they pail in comparison against the likes of Google, Apple, Facebook, Amazon, etc on any metric that matters.
TikTok are also the new hotness and could just as easily go as much as they came. The big tech companies have survived massive market shifts, economic catastrophes, dodged/maneuvered their way through government regulatory apparatus around the world measured in decade time scales.
https://www.historyextra.com/period/victorian/rise-of-the-ro...
Just because someone creates a good product does not allow them to be free from scrutiny.
Certainly if whole traffic goes from the Internet to Facebook, Amazon, and other you may say that the traffic has been hijacked.
Internet giants control your browser, your smartphone, your search engine, your digital assistant, your DNS, most of the traffic going through CDNs, advertising, online shopping, app purchases, news, etc. Most of the internet is only accessible through the giants. Most of the experiences people have with the rest of the world is through them. (I'm being charitable; it's likely all the experiences people have with the rest of the world is through them)
I do think that antitrust should stop big tech companies from acquiring potential competitors (or all their customers) though. Facebook should not have been allowed to acquire WhatsApp. Microsoft should not have been allowed to acquire Activision.
There has never been so much wealth and power amassed (legally) by exploiting the cracks of governance.
They are still attractive enough to keep billions of users using their services.
Google is spending many millions of dollars per year developing and maintaining free software like Chrome and Android.
If the government will miraculously enforce the current anti-competition laws and break the company like they did with Bell Systems in 1982, these Google’s products will suddenly become unsustainable.
And it is "free" because it does not impact their business models, on the contrary
From AOSP docs:
> Android is intentionally and explicitly an open source effort (as opposed to free software)
One of the reasons Android was a success while Windows Phone failed, Microsoft charged something like $30 per device for the OS license.
Google has to play store on Android which earns them billions of dollars.