• krzschlss@lemmy.world
    link
    fedilink
    English
    arrow-up
    168
    ·
    11 months ago

    All this… all this multi billion dollar development, all those ‘brains’, all the time and space a tech company occupies in it’s lifetime… just to force you to watch ads?

    What a shitty society and what a shitty communication system we have, just because some morons want to earn some billions more…

    There is no endgame when it comes to greed, those pricks will always want more.

    • thecoolowl@lemmy.one
      link
      fedilink
      English
      arrow-up
      53
      arrow-down
      1
      ·
      11 months ago

      I feel it’s worse than this. Imagine being the brightest mind in college, have a ton of experience, just to invent new algorithms to get people to click on more ads.

      • aesthelete@lemmy.world
        link
        fedilink
        English
        arrow-up
        35
        ·
        edit-2
        11 months ago

        I consider it close to going to school for engineering or design and winding up being the guy in charge of making airplane seats ever smaller and more uncomfortable.

      • Buttons@programming.dev
        link
        fedilink
        English
        arrow-up
        25
        ·
        11 months ago

        Yeah, the brightest minds of recent generations are figuring out how to get people to watch ads. We probably could have had fusion energy by now, but instead have ads.

        • HurlingDurling@lemm.ee
          link
          fedilink
          English
          arrow-up
          12
          arrow-down
          1
          ·
          11 months ago

          But think of the investors! How can we give them month-after-month gains without forcing ad’s down our user’s throats? /s

          • vacuumflower@lemmy.sdf.org
            link
            fedilink
            English
            arrow-up
            6
            ·
            11 months ago

            It’s more about doing what investors think will give them gains, so that they keep investing, don’t quit, and don’t press out the people in charge of the company.

            Dunno why I have this association, but when directors of Apple pressed out Jobs, Apple’s stuff in the following decade was rather cool. I just played with MacOS 9 a bit, with its classical software like Hotline, and it really had a “culture” and an “ecosystem”, and not what Apple’s ads after 2000 tell you, but these seem to have been real.

    • vacuumflower@lemmy.sdf.org
      link
      fedilink
      English
      arrow-up
      5
      ·
      11 months ago

      What a shitty society

      It has shittier sides than the one you are looking at.

      and what a shitty communication system

      Well, Zuck and others found the way to assemble all blonde girls from your town on one site. It was decided then.

      At least until the general humanity realized that this doesn’t change shit except that we no longer have the normal Web itself, the truly miraculous one which we got used so quickly to.

      I like Gemini, but I’ll take the ActivityPub-based Web. Better both, of course. With old Skype-like IM on top of that as well.

      However, the identities being not cryptography-based and being tied to an instance I don’t really like, that should be fixed in future versions if we want to have stuff working differently from e-mail, which is not as decentralized as one would like.

      And frankly maybe one should separate content instances from authentication instances. The latter would only present identities.

  • TimeSquirrel@kbin.social
    link
    fedilink
    arrow-up
    112
    arrow-down
    10
    ·
    11 months ago

    Long ago, we praised Chrome for helping destroy Internet Explorer. Now it has become the same. No for-profit corporation is your friend.

    • HellAwaits@lemm.ee
      link
      fedilink
      English
      arrow-up
      23
      ·
      11 months ago

      I never praised for Chrome destroying IE. I praised Chrome for standardizing many of the web protocols, which inevitably made it easier to switch between web and mobile.

  • Anemervi@lemmy.world
    link
    fedilink
    English
    arrow-up
    87
    arrow-down
    1
    ·
    edit-2
    11 months ago

    Write to your country’s anti-trust body if you feel Google is unilaterally going after the open web with WEI (content below taken from HN thread https://news.ycombinator.com/item?id=36880390).

    US:

    https://www.ftc.gov/enforcement/report-antitrust-violation
    antitrust@ftc.gov
    

    EU:

    https://competition-policy.ec.europa.eu/antitrust/contact_en
    comp-greffe-antitrust@ec.europa.eu
    

    UK:

    https://www.gov.uk/guidance/tell-the-cma-about-a-competition…
    general.enquiries@cma.gov.uk
    

    India:

    https://www.cci.gov.in/antitrust/
    https://www.cci.gov.in/filing/atd
    

    Example email:

    Google has proposed a new Web Environment Integrity standard, outlined here: https://github.com/RupertBenWiser/Web-Environment-Integrity/blob/main/explainer.md
    
    This standard would allow Google applications to block users who are not using Google products like Chrome or Android, and encourages other web developers to do the same, with the goal of eliminating ad blockers and competing web browsers.
    
    Google has already begun implementing this in their browser here: https://github.com/chromium/chromium/commit/6f47a22906b2899412e79a2727355efa9cc8f5bd
    
    Basic facts:
    
        Google is a developer of popular websites such as google.com and youtube.com (currently the two most popular websites in the world according to SimilarWeb)
        Google is the developer of the most popular browser in the world, Chrome, with around 65% of market share. Most other popular browsers are based on Chromium, also developed primarily by Google.
        Google is the developer of the most popular mobile operating system in the world, Android, with around 70% of market share.
    
    Currently, Google’s websites can be viewed on any web-standards-compliant browser on a device made by any manufacturer. This WEI proposal would allow Google websites to reject users that are not running a Google-approved browser on a Google-approved device. For example, Google could require that Youtube or Google Search can only be viewed using an official Android app or the Chrome browser, thereby noncompetitively locking consumers into using Google products while providing no benefit to those consumers.
    
    Google is also primarily an ad company, with the majority of its revenue coming from ads. Google’s business model is challenged by browsers that do not show ads the way Google intends. This proposal would encourage any web developer using Google’s ad services to reject users that are not running a verified Google-approved version of Chrome, to ensure ads are viewed the way the advertiser wishes. This is not a hypothetical hidden agenda, it is explicitly stated in the proposal:
    
    “Users like visiting websites that are expensive to create and maintain, but they often want or need to do it without paying directly. These websites fund themselves with ads, but the advertisers can only afford to pay for humans to see the ads, rather than robots. This creates a need for human users to prove to websites that they’re human, sometimes through tasks like challenges or logins.”
    
    The proposed solution here is to allow web developers to reject any user that cannot prove they have viewed Google-served ads with their own human eyes.
    
    It is essential to combat this proposal now, while it is still in an early stage. Once this is rolled out into Chrome and deployed around the world, it will be extremely difficult to rollback. It may be impossible to prevent this proposal if Google is allowed to continue owning the entire stack of website, browser, operating system, and hardware.
    
    Thank you for your consideration of this important issue.
    
    • SokathHisEyesOpen@lemmy.ml
      link
      fedilink
      English
      arrow-up
      17
      arrow-down
      1
      ·
      11 months ago

      Thanks! Here’s the message without all the BBC quotes to make it easier to copy for app users:

      Dear FTC,

      Google has proposed a new Web Environment Integrity standard, outlined here: https://github.com/RupertBenWiser/Web-Environment-Integrity/…

      This standard would allow Google applications to block users who are not using Google products like Chrome or Android, and encourages other web developers to do the same, with the goal of eliminating ad blockers and competing web browsers.

      Google has already begun implementing this in their browser here: https://github.com/chromium/chromium/commit/6f47a22906b28994…

      Basic facts:

      Google is a developer of popular websites such as google.com and youtube.com (currently the two most popular websites in the world according to SimilarWeb) Google is the developer of the most popular browser in the world, Chrome, with around 65% of market share. Most other popular browsers are based on Chromium, also developed primarily by Google. Google is the developer of the most popular mobile operating system in the world, Android, with around 70% of market share.

      Currently, Google’s websites can be viewed on any web-standards-compliant browser on a device made by any manufacturer. This WEI proposal would allow Google websites to reject users that are not running a Google-approved browser on a Google-approved device. For example, Google could require that Youtube or Google Search can only be viewed using an official Android app or the Chrome browser, thereby noncompetitively locking consumers into using Google products while providing no benefit to those consumers.

      Google is also primarily an ad company, with the majority of its revenue coming from ads. Google’s business model is challenged by browsers that do not show ads the way Google intends. This proposal would encourage any web developer using Google’s ad services to reject users that are not running a verified Google-approved version of Chrome, to ensure ads are viewed the way the advertiser wishes. This is not a hypothetical hidden agenda, it is explicitly stated in the proposal:

      “Users like visiting websites that are expensive to create and maintain, but they often want or need to do it without paying directly. These websites fund themselves with ads, but the advertisers can only afford to pay for humans to see the ads, rather than robots. This creates a need for human users to prove to websites that they’re human, sometimes through tasks like challenges or logins.”

      The proposed solution here is to allow web developers to reject any user that cannot prove they have viewed Google-served ads with their own human eyes.

      It is essential to combat this proposal now, while it is still in an early stage. Once this is rolled out into Chrome and deployed around the world, it will be extremely difficult to rollback. It may be impossible to prevent this proposal if Google is allowed to continue owning the entire stack of website, browser, operating system, and hardware.

      Thank you for your consideration of this important issue.

    • 7Sea_Sailor@lemmy.dbzer0.com
      link
      fedilink
      English
      arrow-up
      5
      ·
      11 months ago

      Thank you, sent. While I’m crossing my fingers that someone reads/notices this, I am just as doubtful that any valuable action will be taken before it is too late. Democratic governments are simply too slow.

      • narc0tic_bird@lemm.ee
        link
        fedilink
        English
        arrow-up
        36
        ·
        11 months ago

        I sure hope so.

        This is way worse than what Microsoft did back in the day with Internet Explorer. They were forced to build a browser selection popup into their operating system because of that.

        • Valmond@lemmy.ml
          link
          fedilink
          English
          arrow-up
          11
          ·
          11 months ago

          And poured every browser and their sister into it just to make the whole selection process shitty.

    • RagingNerdoholic@lemmy.ca
      link
      fedilink
      English
      arrow-up
      17
      ·
      11 months ago

      It is. Anyone who cares is powerless to change it. Anyone with the power to change it doesn’t care. That goes for a lot of things.

      • 520@kbin.social
        link
        fedilink
        arrow-up
        17
        ·
        11 months ago

        Methinks there is a history lesson you haven’t learned.

        MS didn’t get into trouble just for bundling their browser. They got into trouble using every strongarm tactic they could think of to kill the browser market. They broke competitors, deliberately crippled APIs while IE used undocumented faster ones, and put IE in customer faces whether they wanted it there or not. MS used this tactic repeatedly to corner other markets, such as productivity suites. That’s why MS got nailed.

        • linearchaos@lemmy.world
          link
          fedilink
          English
          arrow-up
          7
          ·
          11 months ago

          At one point it went from an optional download to being required for the offering system. At that point you weren’t allowed to uninstall it.

          Of course that was back before the government was completely owned by tech corporations.

          • SokathHisEyesOpen@lemmy.ml
            link
            fedilink
            English
            arrow-up
            3
            arrow-down
            1
            ·
            11 months ago

            Isn’t that unchanged? Edge is installed by default and I don’t think you can fully remove it…

            • 520@kbin.social
              link
              fedilink
              arrow-up
              4
              ·
              11 months ago

              It was way worse back then. Nowadays you can actually remove it. Back then they hooked IE into numerous core UI things like the desktop wallpaper and file manager, so any attempt at actually removing it completely fucked your system

    • whoareu@lemmy.ca
      link
      fedilink
      English
      arrow-up
      1
      arrow-down
      7
      ·
      11 months ago

      Batter way would be to just watch youtube video on youtube while ad block being enabled that way all the server load goes to google and they can’t get the ad revenue. Isn’t it win win?

    • lemmyvore@feddit.nl
      link
      fedilink
      English
      arrow-up
      107
      arrow-down
      3
      ·
      edit-2
      11 months ago

      It’s basically all the bad things that tech writers have already warned about, except shit just got real. Google is actually shipping WEI in Chrome and large important sites and services are no longer working except in Chrome and with Goggle’s blessing.

      The author makes a very good comparison with Android, where you need a locked-down device and Google Services installed to be able to use Netflix, or your bank’s services.

      The rest of the article dives into what WEI claims to achieve vs what it’s actually doing, and who it really benefits. Good read if you’re still unclear about that.

      • kitonthenet@kbin.social
        link
        fedilink
        arrow-up
        32
        arrow-down
        1
        ·
        edit-2
        11 months ago

        Who’s already using this thing? I know Google ships it, but is anyone checking it yet

        • lemmyvore@feddit.nl
          link
          fedilink
          English
          arrow-up
          23
          arrow-down
          2
          ·
          11 months ago

          It’s good odds that banks and streaming services are scrambling to implement it as we speak. You know they are. DRM is the perpetual wet dream for the music & film industry and for streaming services. And banks are paranoid as a matter of course.

          It’s going to be very hard to say no, especially since they can say “but Chrome is working on all platforms, nobody’s pushing you out of anything”. Will you drop stream subscriptions? Everybody loves to say they’ll drop Netflix “as soon as they push me one more time”, but what about a service you actually like? And what about banks, are those as easy to switch?

          I’ve been through this for years now with Android and SafetyNet and it’s a lot of hoops to have to jump through to stop being considered a second class user on your own device. It’s going to suck extra bad when it comes to PC.

          As for Google services themselves, I’m very curious to see in what order and how they choose to make WEI mandatory. Maybe not for Search and Gmail, at first, but what about accessing your Google Account, surely that must be secured? And YouTube of course, that’s got DRM written all over it.

          • Buttons@programming.dev
            link
            fedilink
            English
            arrow-up
            9
            ·
            11 months ago

            Hope my bank likes paying people to answer my calls, because that’s how I’ll be interacting with them if I can’t use a web page.

          • gravitas_deficiency@sh.itjust.works
            link
            fedilink
            English
            arrow-up
            9
            ·
            11 months ago

            My way of saying “no” is going to be cancelling my subscription to whatever service implements this and then pirating and seeding as much of their content library as is feasible and will fit on my NAS.

          • kitonthenet@kbin.social
            link
            fedilink
            arrow-up
            7
            arrow-down
            2
            ·
            11 months ago

            Will you drop stream subscriptions

            Yes, I’ve got one foot out the door already. Shits too expensive, they kill all the best shows, they take down movies and stuff before I get a chance to watch them. I don’t even have Netflix, in my opinion is one of the worse streamers. I cancelled HBO a couple months ago, I only have ESPN+ and Apple TV

            what about banks

            If you’re not using a local bank or credit union I can’t help you, shit sucks and who is actually going to the branches anymore. Bank where old people bank.

            Beyond that Google search is ass (everyone knows this) Gmail is fine but only because it’s “free”, you can easily switch to a cheap alternative. YouTube is the only compelling product Google has anymore and honestly I’ll just pay for nebula if I really care about losing it

            • Corkyskog@sh.itjust.works
              link
              fedilink
              English
              arrow-up
              1
              ·
              11 months ago

              Wait Nebula is actually built out? The YouTubers I listen to make it sound like it’s in its early infancy.

              Google search is ass

              It feels incredibly weird using Bing… I don’t even use it as an FU to Google, it’s just somehow weirdly a better search engine right now.

              • kitonthenet@kbin.social
                link
                fedilink
                arrow-up
                1
                ·
                edit-2
                11 months ago

                I use kagi, all that money I saved from not paying for cable (streaming) lol

                Yeah nebula rules, (practical engineering legaleagle minute physics etc) I’m procrastinating dropping Apple TV for it but I figure as soon as I do I’ll be happy I did, YouTube isn’t so good anymore either. The other good one imo is dropout tv, it’s comedy and dnd type stuff with some surprisingly big names imo

                The through line is that now figuring out streaming services is cheap enough that smaller companies can do it, so buying a streaming thing from a company the creators actually work for is a better business model for both viewers and creators than YouTube or other streaming platforms

                • Corkyskog@sh.itjust.works
                  link
                  fedilink
                  English
                  arrow-up
                  1
                  ·
                  edit-2
                  11 months ago

                  so buying a streaming thing from a company the creators actually work for is a better business model for both viewers and creators than YouTube or other streaming platforms

                  Sounds like a Uoptian paradise. I just assumed there wouldn’t be enough content for it ever to be worth it.

      • RagingNerdoholic@lemmy.ca
        link
        fedilink
        English
        arrow-up
        14
        ·
        11 months ago

        Google is actually shipping WEI in Chrome

        Is this confirmed? Last I saw, it was still a proposal on github.

        • tony@lemmy.hoyle.me.uk
          link
          fedilink
          English
          arrow-up
          33
          ·
          11 months ago

          They ignored the objections to the proposal, pushed it directly into their tree and it’s already live. I’ve had the prompt to enable it just today.

        • theneverfox@pawb.social
          link
          fedilink
          English
          arrow-up
          8
          ·
          11 months ago

          Yeah, they pushed it in chrome very soon after the proposal made the rounds

          It’s pretty telling seeing as it happened so fast it must’ve predated the proposal. The proposal was super vague - if you take it (and their statements) at face value, this was a nebulous idea with none of the details ironed out.

          And then like a week later, they push this update that would lock people out of sites? No way in hell they didn’t test the crap out of this.

          Nah, this is definitely being done in bad faith.

    • BrianTheeBiscuiteer@lemmy.world
      link
      fedilink
      English
      arrow-up
      40
      arrow-down
      1
      ·
      11 months ago

      I was multitasking while watching but I’m pretty sure this is the idea.

      Googles “web DRM” makes it impossible (or extremely difficult) to lie to a website about your browser, operating system, and whether or not you’re human (or a bot). Websites can then use this info to deny access if they decide not to trust any of the info given.

      This could easily be used to suppress the use of open source software which is probably why so many FOSS projects and foundations oppose it.

      • Noah@lemmy.federated.club
        link
        fedilink
        English
        arrow-up
        24
        ·
        edit-2
        11 months ago

        It doesn’t prove you’re not a bot though, only that the request is coming from a ‘genuine device’. You just need to pipe your malicious requests through a ‘real browser’ to get them approved and you’re set.

        • fishhf@reddthat.com
          link
          fedilink
          English
          arrow-up
          1
          ·
          11 months ago

          WEI could require secureboot, so you could no longer modify the OS or Chrome to “pipe” those requests.

    • RagingNerdoholic@lemmy.ca
      link
      fedilink
      English
      arrow-up
      28
      ·
      11 months ago

      DRM in your web browser to forcibly require you to be running an “approved” browser (ie.: Chrome) in an “approved” configuration (ie.: no ad blockers) to load certain websites, and probably all major websites.

    • Blxter@lemmy.zip
      link
      fedilink
      English
      arrow-up
      7
      arrow-down
      1
      ·
      11 months ago

      I love that bot that goes around and does it. No idea who made it etc but it’s great.

  • arin@lemmy.ml
    link
    fedilink
    English
    arrow-up
    31
    ·
    11 months ago

    So the old Internet we knew is dead, time for Internet 2.0?

  • narc0tic_bird@lemm.ee
    link
    fedilink
    English
    arrow-up
    23
    ·
    edit-2
    11 months ago

    That was quick (Google integrating it). But of course it was…

    About time I finally switch (back) to Firefox then. Have been using Vivaldi, but the only real solution is to move to a non-Chromium browser.

    • void_wanderer@lemmy.world
      link
      fedilink
      English
      arrow-up
      11
      ·
      11 months ago

      Thing is, if this takes off and websites adopt it, FF will be forced to integrate it aswell. I’d be fine with some websites not working in FF, but my mother will call me and say “the internet is broken”. I guess Mozilla doesn’t want and/or cannot afford that.

      • narc0tic_bird@lemm.ee
        link
        fedilink
        English
        arrow-up
        8
        ·
        11 months ago

        That is correct, but for now, Mozilla has the right stance on the matter.

        I’m still waiting for what Apple’s stance is. They integrated functionality into Safari that technically works similarly, but that’s only used for captcha verification. I can see them choosing either side to be honest. They can embrace the Web Integrity API because it fits their “closed ecosystem” (in case of iOS devices) type of product quite well, but on the other hand they don’t really have a website that would be suitable to use the Web Integrity API, so why would they give in to what Google wants? If Apple doesn’t integrate Web Integrity API into Safari, I don’t see any major website using it. They can’t afford to lose ~28% of the mobile market.

        • cstine@lemmy.uncomfortable.business
          link
          fedilink
          English
          arrow-up
          14
          arrow-down
          1
          ·
          11 months ago

          Apple will follow suit: don’t be taken in by the ‘we love our customers’ nonsense they like to present. They make billions in selling ads too, they just do it a little more quietly than Google.

          • Sendbeer@lemm.ee
            link
            fedilink
            English
            arrow-up
            3
            arrow-down
            1
            ·
            11 months ago

            Agreed. Apples stance on privacy is more about PR and keeping ad competitors at a disadvantage on their platform than actual privacy. Only reason they might not fall in line is if they feel there is enough public opposition to it to get some PR and make Google look bad. Not too optimistic on that though since most people are oblivious to the issue.

          • narc0tic_bird@lemm.ee
            link
            fedilink
            English
            arrow-up
            3
            arrow-down
            1
            ·
            11 months ago

            They don’t sell ads on the web though, so I don’t see how this would be related.

            • cstine@lemmy.uncomfortable.business
              link
              fedilink
              English
              arrow-up
              1
              ·
              edit-2
              11 months ago

              I kinda have two answers to this:

              1. Not yet,

              2. It was more an intent to show that they’re not some shining defender of the ad-free private internet, who would never take action to defend a potential future revenue stream if they thought it might be profitable later.

              Remember everyone, corporations are not your friends, your buddy, your pal, or even slightly gives a shit about you beyond how much money they can extract from your wallet and anything that’s in the way of them doing so they’ll work around, stomp on, and kill by any means necessary.

      • RagingNerdoholic@lemmy.ca
        link
        fedilink
        English
        arrow-up
        3
        ·
        11 months ago

        Likely true, but as someone pointed out in another thread, it should be possible to “technically” comply with WEI enforcement, and then have a transparent abstraction layer to extract the “enforced” markup and code, exposing it to the user-facing browser to interpret like it normally would.

        It’s some real asinine bullshit software engineering that shouldn’t be necessary, but it should work.

      • loutr@sh.itjust.works
        link
        fedilink
        English
        arrow-up
        4
        ·
        11 months ago

        Exactly, why don’t all these chromium-based browsers which came out against WEI don’t fork Chromium to maintain a base version without this bullshit? And manifest V3 while they’re at it.

        • narc0tic_bird@lemm.ee
          link
          fedilink
          English
          arrow-up
          2
          ·
          11 months ago

          It’s likely a lot of work to maintain a fork of the Chromium/Blink engine with your own changes applied to it. I’m not sure how deeply the Web Integrity API is integrated into the code, but if it’s anything more than a flag to disable it, it will likely be hard to keep integrating upstream changes timely while ensuring your fork still works.

            • narc0tic_bird@lemm.ee
              link
              fedilink
              English
              arrow-up
              1
              ·
              11 months ago

              Although Chromium/Blink is forked from WebKit, it’s far from being WebKit these days.

              But of course, Vivaldi could base their browser on WebKit or Gecko. Many of these “smaller” browsers tend to be based on Chromium though, likely because it’s the most compatible (because of its marketshare).

              And it’s likely too much work for them to switch engines now.

  • flop_leash_973@lemmy.world
    link
    fedilink
    English
    arrow-up
    23
    ·
    edit-2
    11 months ago

    Sadly the only real move the average person has to play in all of this is if they do this, refuse to use any site that blocks access or extensions based on it.

    Go back to paying your property tax with checks, etc if you have to. But the only way to deal with these companies is being willing to go to whatever lengths are required to avoid using their products and services.

    Which is of course way easier to say than do.

  • SparkyLight@lemmy.world
    link
    fedilink
    English
    arrow-up
    22
    ·
    11 months ago

    i don’t quite get why can’t the attester just… lie… about who he is like if I’m using firefox on linux, why cant my linux attester claim to be actually windows attester and say I’m using chrome?

    • SkyNTP@lemmy.ml
      link
      fedilink
      English
      arrow-up
      20
      arrow-down
      1
      ·
      11 months ago

      I am not an expert, but it’s likely signed and cryptographically secured. Change a single byte in the be Browser executable and your browser goes on the naughty list. This is total lockdown of the browser, and in principle you can extend certification of both software and hardware all the way down through the OS into the hardware.

        • Anafabula@discuss.tchncs.de
          link
          fedilink
          English
          arrow-up
          7
          ·
          11 months ago

          If you are on android or ios the phone already cryptografically verifies that the operating system has not been tampered with on a hardware level. Since the operating system is then “trusted” it can verify anything you do on it

          • l0v9ZU5Z@feddit.de
            link
            fedilink
            English
            arrow-up
            7
            ·
            11 months ago

            Doesn’t work. It’s possible to let many banking apps think they are running on a normal device although it is rooted.

            • Koffiato@lemmy.ml
              link
              fedilink
              English
              arrow-up
              6
              ·
              11 months ago

              Yup Play attestation is dead, even the new and shiny “secure” one is bypassed. It’s now just a hinderence.

    • chaospatterns@lemmy.world
      link
      fedilink
      English
      arrow-up
      18
      ·
      11 months ago

      Attestation depends on a few things:

      1. The website has to choose to trust a given attestation provider. If Open Source Browser Attestation Provider X is known for freely handing out attestations then websites will just ignore them
      2. The browser’s self-attestation. This is tricky part to implement. I haven’t looked at the WEI spec to see how this works, but ultimately it depends on code running on your machine identifying when it’s been modified. In theory, you can modify the browser however you want, but it’s likely that this code will be thoroughly obfuscated and regularly changing to make it hard to reverse engineer. In addition, there are CPU level systems like Intel SGX that provide secure enclaves to run code and a remote entity can verify that the code that ran in SGX was the same code that the remote entity intended to run.

      If you’re on iOS or Android, there’s already strong OS level protections that a browser attestation can plugin to (like SafetyNet.)

    • Dark Arc@lemmy.world
      link
      fedilink
      English
      arrow-up
      13
      ·
      edit-2
      11 months ago

      WebChain of trust, the site only trusts certain attesters (yes this would be really bad for Linux).

      EDIT: Used the wrong “of trust”

      • vacuumflower@lemmy.sdf.org
        link
        fedilink
        English
        arrow-up
        7
        ·
        11 months ago

        Every time somebody calls this “web of trust” I feel the need to remind that really Web of Trust is a system of, well, decentralized manual trust, like with PGP. Like in Retroshare or Freenet for some people.

        Every such attempt at replacing the actually relevant meaning of a thing which is still good and needed is suspicious.

  • MoonRaven@feddit.nl
    link
    fedilink
    English
    arrow-up
    16
    ·
    11 months ago

    We had the dominance of Microsoft with IE back in the day. They made sure that the web was being kept back. Google is doing the same now, even though people have been shouting that they’d never do that. Here we are…