Revert Web Environment Integrity
github.com
github.com
It was terribly proposed. The idea has some interesting merits but, Jesus Christ, horribly proposed and so obviously abusable.
Of course in this case it’s a bit more than that, in that Google was deliberately and strategically aiming to use this to further monopolize its position and inweave itself into the fabric of the internet.
It’s easy to preach that everyone should refuse to do work that is “bad” in some nebulous, long term way. Especially if you’re comfortable and can afford to quit as a matter of principle. But not everyone can do that.
The problem with 1984 isn't just the power Big Brother wields, but the malevolence with which it is inflicted. Would it be the same story if Big Brother were benevolent?
This is why we want tech people to learn ethics and consider social impact. If you ignore (or are blind to) the massive social consequence of WEI, you can see all the problems it'd solve or help mitigate. Goodbye spam and LLM spam, revenge porn and traffickers can be tracked back, etc.
To be clear, this is not an endorsement of WEI, only that it's very easy to imagine the type of person who can passionately implement it.
Yes. Try Huxley's 'Brave New World'.
You can solve plenty of interesting problems in your spare time when you're able to retire at 40-50.
I don't doubt this was something somebody thought was a good idea and was willing to invest their engineering career in pulling off. History is full of people who were excited about building the biggest bomb or a gun that could shoot space.
Probably folks who remember trying to play Counterstrike against wallhackers and enjoy that experience.
1) Implement your own authentication to filter out bots, even if the service could be otherwise public (permanently identifying all your users)
2) Pay some WAF provider like Cloudflare to sit in front of your service and send Captcha's (and while you are at it let them man in the middle all your users traffic somewhat defeating the purpose of TLS).
3) Be rich enough to scale your backend to deal with any DDOS/scraper
A cheap way to throttle or drop non-human traffic and bringing back the option of being able to spin up a couple of VPS's and host a website without involving a WAF seems like a cool problem to me.
Of course its more dubious coming from a company that already has the ability to do 3).
The web is uniquely unblemished, still filled with ideas hope and rfc8890 the internet is for end users optimism. https://datatracker.ietf.org/doc/rfc8890/
https://android-developers.googleblog.com/2023/11/increasing...
As a reminder attestation does not steal control away from users. They are free to use whatever software and do whatever they want. They just will not be able to attest to a server that they were using a trusted stack in the case they were not.
Similarly by having people prove what software stack they are using to a website, that website may be able to improve the user experience for everyone.
It should be up to a site to be the one who chooses what stacks to trust and how much trust to put in them or what to trust them with. I do think a way to delegate a third party to manage what to trust would be useful so new browsers would only have to go to a few big players instead of every single site to get their browser trusted.
>If it's about piracy and ad blocking, say it with your chest, don't say it's about my user experience.
It can be about both. You specifically asked for ways it improved the user experience, so I gave you that.
You sir are in flagrant violating of rfc8890 & need to get your head screwed on straight. The browser is called a user-agent because it is grants the user agency. It does not represent the sites; it is the user. It should empower not restrict them. https://datatracker.ietf.org/doc/rfc8890/
Regardless, attestation benefits the user as it allows the websites they use and share data with to be more secure. WEI didn't make sense because it didn't actually prove the integrity of anything.
It's unclear that websites would be more secure by virtue of having a Google or Microsoft or Apple attested OS. What examples have we seen of users running their own OS contributing to a web host's security issues? Got anything? Probably not! WEI has always been of dubious use.
Your original claim that extensions needed to be blocked was an explicit anti-goal of web. Users obviously have a right to extensions, which allows for accessibility affordances, for example. Would you also propose turning off view source and the debugged? What other nastygram blocks of shit do you propose smacking users in the face with?
It feels like you are trying really hard to be obtuse negative & nasty to users, and throwing absurd ridiculous arguments out to anger people, who care about users.
The RFC is about the development of those standards. It is not talking about the usage of them.
>What examples have we seen of users running their own OS contributing to a web host's security issues?
For example there are scripts that take lists of email password combos and send network requests to attempt logging into these accounts. Then using these accounts the attackers do malicious actions. Platforms that make it harder or more expensive to automate things will have less people using them abuse services.
>Your original claim that extensions needed to be blocked was an explicit anti-goal of web.
If sites only want to allow input injection that comes from preapproved password manager extentions they should be able to get proof of if that's the case. The alternative to the browser blocking the extention is that the site could ask the user to disable the extention or just provide an error that the input came from an untrusted source. There are some different options in how this could be handled.
>Users obviously have a right to extensions, which allows for accessibility affordances
Yes, but my concern is mainly with the proof part on the server side. So the server can be sure that actions taken were not being done by an untrusted extention. Accessiblity also needs to be carefully considered as bad actors may use accessibility features to bypass security.
>Would you also propose turning off view source and the debugged?
No, I have not seen a big demand for keeping code a secret. For the relevant problems trying to hide the come is security by obscurity.
>What other nastygram blocks of shit do you propose smacking users in the face with?
I don't indented to smack any users. 99% of users will not even notice anything has changed, but attackers will realize that their job just got a lot harder.
>It feels like you are trying really hard to be obtuse negative & nasty to users
I feel if you had to deal with protecting a website from bad actors you would appreciate my viewpoint.