zlacker

[return to "Web Environment Integrity API Proposal"]
1. saurik+L5[view] [source] 2023-07-21 18:35:31
>>reacto+(OP)
This is pretty much the inevitable end-game of the web, in no small part funded by ad-based business models (as the analog gap pretty much destroys most attempts to use this stuff to do copy protection) and enabled by developers who have insisted we shove as much difficult-to-implement functionality (by which I am talking about CSS complex stuff, not powerful-but-easy-to-code APIs for OS-level access) into the browser as possible.

The result: there is now effectively one dominating web browser run by an ad company who nigh unto controls the spec for the web itself and who is finally putting its foot down to decide that we are all going to be forced to either used fully-locked down devices or to prove that we are using some locked-down component of our otherwise unlocked device to see anyone's content, and they get to frame it as fighting for the user in the spec draft as users have a "need" to prove their authenticity to websites to get their free stuff.

(BTW, Brave is in the same boat: they are also an ad company--despite building ad blocking stuff themselves--and their product managers routinely discuss and even quote Brendan Eich talking about this same kind of "run the browser inside of trusted computing" as their long-term solution for preventing people blocking their ads. The vicious irony: the very tech they want to use to protect them is what will be used to protect the status quo from them! The entire premise of monetizing with ads is eventually either self-defeating or the problem itself.)

◧◩
2. tentac+H9[view] [source] 2023-07-21 18:52:36
>>saurik+L5
> who is finally putting their foot down and deciding that we are all going to be forced to either used fully-locked down devices

The person who wrote the proposal[0] is from Google. All the authors of the proposal are from Google[1].

I've been thinking carefully about this comment, but I really don't know what to say. It's absolutely heartbreaking watching something I really care about die by a thousand cuts; how do we protest this? Google will just strong-arm their implementation through Chromium and, when banks, Netflix & co. start using it, they've effectively cornered other engines into implementing it.

This isn't new to them. They did it with FLoC, which most people were opposed to[2]. The most they did was FLoC was deprecate it and re-release it under a different name.

The saving grace here might be that Firefox won't implement the proposal.

[0]: https://github.com/RupertBenWiser [1]: https://github.com/RupertBenWiser/Web-Environment-Integrity/... [2]: >>26344013

◧◩◪
3. tapoxi+xa[view] [source] 2023-07-21 18:56:31
>>tentac+H9
I mean Firefox caved to support EME. This isn't the early days of the web anymore either, the enthusiasts are a small minority of global web traffic that this will probably succeed even with a large scale boycott.
◧◩◪◨
4. riffra+fd[view] [source] 2023-07-21 19:10:30
>>tapoxi+xa
I think in this case Firefox is in a different position: if it didn't support EME netflix wouldn't work.

But in this case it could report "sure, this is a real user alright" by being its own attester, can't it?

◧◩◪◨⬒
5. wmf+SF[view] [source] 2023-07-21 21:17:10
>>riffra+fd
If Firefox lies, sites will refuse to load in Firefox.
◧◩◪◨⬒⬓
6. riffra+g72[view] [source] 2023-07-22 11:49:03
>>wmf+SF
Of course, but if Google did that it would allow Firefox to complain about Google's abuse of monopoly power. I'm not sure that is a path they'd risk going through.
[go to top]