zlacker

[return to "Web Environment Integrity Explainer"]
1. jchw+G5[view] [source] 2023-07-19 13:22:42
>>christ+(OP)
Absolute worst spec I've ever seen. Google needs to be loaded into a cannon and fired into the sun.

> How does this affect browser modifications and extensions?

> Web Environment Integrity attests the legitimacy of the underlying hardware and software stack, it does not restrict the indicated application’s functionality: E.g. if the browser allows extensions, the user may use extensions; if a browser is modified, the modified browser can still request Web Environment Integrity attestation.

Then what's the point? I can make modified bot browser that commits ad fraud as long as I don't use a rooted Android phone?

I don't believe they're being honest with how this will be used. We need to legally regulate remote attestation.

> As new browsers are introduced, they would need to demonstrate to attesters (a relatively small group) that they pass the bar, but they wouldn't need to convince all the websites in the world.

It speaks for itself. Horrid.

◧◩
2. joseph+1B4[view] [source] 2023-07-20 16:45:31
>>jchw+G5
> We need to legally regulate remote attestation.

I'd go a step further. We need to ban it. It should be illegal to sell devices to consumers that already contain private keys, unless all of said keys are provided to the consumer at the time of purchase.

[go to top]