zlacker

[return to "Google’s nightmare “Web Integrity API” wants a DRM gatekeeper for the web"]
1. codedo+rg[view] [source] 2023-07-24 22:28:33
>>jakobd+(OP)
> Google's plan is that, during a webpage transaction, the web server could require you to pass an "environment attestation" test before you get any data.

There is no value in this "attestation" for me as a user. I want to be able to do whatever I want with the browser (for example, remove ads or block access to canvas and webgl) and I want sites to be unable to know this. And probably this attestation will provide additional fingerprinting signals which is what I don't want.

◧◩
2. crote+hn[view] [source] 2023-07-24 23:17:49
>>codedo+rg
Ehhh, it depends.

In theory one could imagine a scenario like a bank website refusing to be accessed unless the entire OS & browser stack pass attestation - as that would rule out things like keyloggers, malicious browser extensions, and session hijacking.

In practice it'll just be used to lock down content and force unskippable ads on users, of course.

◧◩◪
3. userbi+wH[view] [source] 2023-07-25 01:44:55
>>crote+hn
one could imagine a scenario like a bank website refusing to be accessed unless the entire OS & browser stack pass attestation - as that would rule out things like keyloggers, malicious browser extensions, and session hijacking.

The important part is that "malicious" isn't up to you to decide anymore; if you have any "unapproved" software that acts in your interests and not others', this could theoretically be used to lock you out too.

[go to top]