zlacker

[parent] [thread] 16 comments
1. Alifat+(OP)[view] [source] 2023-07-26 13:22:38
So, how can this be bypassed in theory? Any ideas? Brainstorming is allowed.

EDIT: Saw a few mention two solutions to disable the automatic verification on iOS & macOS.

https://blog.cloudflare.com/how-to-enable-private-access-tok...

https://support.apple.com/en-us/HT213449

replies(5): >>dschue+l >>theK+t >>anders+D9 >>Zren+Hj >>nptelj+SA
2. dschue+l[view] [source] 2023-07-26 13:24:18
>>Alifat+(OP)
Build a new Web w/o Google.
replies(1): >>EGreg+o4
3. theK+t[view] [source] 2023-07-26 13:24:53
>>Alifat+(OP)
It just splits the web. You will have web properties that don't necessitate its usage. These will be available to everyone. Then you will have the Googlesphere which will have all google sites and all sites integrating google services that will only be available from "verified environments"
◧◩
4. EGreg+o4[view] [source] [discussion] 2023-07-26 13:40:12
>>dschue+l
We have been doing it! Join us!

It isn’t perfect but we are ahead of most others (Mastodon, Matrix). We have spent TWELVE YEARS building the free, permissionless open source platform for anyone to assemble and host their own community software with all the features of Facebook/Twitter/TikTok for their own community:

https://github.com/Qbix/Platform

We are about to roll out version 2.0 — I have never done this before but I would like to invite whoever wants to learn about it or build on it, to a Zoom webinar where I will demo anything and answer any questions. Starting in Q3 this year all the webinars will take place on our own platform — no Calendly, no Zoom, no Google, just the free open Web.

Anyway, sign up here if you want. Will do it every Sunday throughout August:

https://calendly.com/qbix/qbix-2-0-platform-demo

Whether you’re a developer, a businessperson, or just want to learn about the latest technologies moving the Free Open Source Web forward, this platform can help empower you to build and engage a community around yourself and your projects.

replies(3): >>Dah00n+Vp >>mikeco+Gq >>dschue+1t
5. anders+D9[view] [source] 2023-07-26 14:00:30
>>Alifat+(OP)
It can't, that's the point. Unless you steal the attestation key from Google.

Disabling the feature on your device will make you fail attestation and thus websites requiring it will just stop working.

replies(1): >>Pannon+0w
6. Zren+Hj[view] [source] 2023-07-26 14:39:19
>>Alifat+(OP)
Can't the browser just fake itself to look like chrome/safari without extensions to get the WEI server token?

* CON: The problem is that the WEI server could change it's tracking faster than the browser app updates it's fakeness though. There's more money in bypassing adblockers than there is in blocking them.

* CON: If it does fake itself, when you return to the original website it can assume there's no adblocker and fail to load with the adblocker unlike now where it's usually ignored.

◧◩◪
7. Dah00n+Vp[view] [source] [discussion] 2023-07-26 15:02:34
>>EGreg+o4
Interesting, if it isn't US based and if it isn't using US politics as a guideline (like banning russian patches).

I have lost a big part of my former trust and want for writing OSS this last few months and one thing I have learned is that if those two can't be answered with a resounding no it is a project I won't ever contemplate even though I'm neither American nor Russian.

replies(1): >>EGreg+4N
◧◩◪
8. mikeco+Gq[view] [source] [discussion] 2023-07-26 15:05:19
>>EGreg+o4
I think the github link is an Andrew Yang campaign site.
replies(1): >>EGreg+SN
◧◩◪
9. dschue+1t[view] [source] [discussion] 2023-07-26 15:13:05
>>EGreg+o4
> It isn’t perfect but we are ahead of most others (Mastodon, Matrix). We have spent TWELVE YEARS building the free, permissionless open source platform for anyone to assemble and host their own community software with all the features of Facebook/Twitter/TikTok for their own community

Why are you using Github then?

replies(1): >>EGreg+OM
◧◩
10. Pannon+0w[view] [source] [discussion] 2023-07-26 15:21:21
>>anders+D9
Well, you know what we must do now..... ;)
11. nptelj+SA[view] [source] 2023-07-26 15:38:00
>>Alifat+(OP)
My semi uninformed theories:

1. Someone could set up a server that proxies WEI required requests to regular clients. The client initiates the process, the request goes to the middleman, the middleman makes the proper WEI authorized request, gets the response, passes the response back to the client.

2. The private key could leak somehow, and so, software can forge the required signature.

I'm not holding my breath for either one. Some kind of regulation has to step in, otherwise Google puts the internet in a chokehold.

replies(1): >>a2128+UP
◧◩◪◨
12. EGreg+OM[view] [source] [discussion] 2023-07-26 16:21:26
>>dschue+1t
Why are we using Hacker News? Go post on https://community.qbix.com/ that is powered by Discourse, a fellow open source company doing good work, and that we are integrated with

Why using calendly, zoom, and google? Well, as I said, we haven't launched Qbix Platform 2.0 to everyone worldwide yet. This is if you want to get involved pre-launch.

We dogfood our own stuff, but we also interoperate with everything else out there, such as Discourse (https://qbix.com/ecosystem for example incorporates it), Zoom, Google, Facebook, etc.

◧◩◪◨
13. EGreg+4N[view] [source] [discussion] 2023-07-26 16:22:37
>>Dah00n+Vp
Unless banning Russian patches is somehow required by US law, why would we ban Russian patches?

https://www.theverge.com/2021/1/5/22215588/github-iran-sanct...

As a side note, many people on our development team that has worked with us since 2013 have spoken Russian, coming from Ukraine, Armenia, Russia, etc. Many of them continue to work together despite the war their governments are conducting.

We are for empowering people uniting communities around the world, and are pretty critical of government overreach:

>>35656705

https://community.qbix.com/t/transparency-in-government/234

https://qbix.com/blog/2021/01/15/open-source-communities/

If that appeals to you, the lowest hanging fruit is just joining the community and introducing yourself:

https://community.qbix.com/

replies(1): >>Dah00n+AB3
◧◩◪◨
14. EGreg+SN[view] [source] [discussion] 2023-07-26 16:25:29
>>mikeco+Gq
The link above is an introduction to the Qbix Platform, which you can download and try out, if you want to rather easily build your own community, that has more advanced features than Mastodon or Matrix.
◧◩
15. a2128+UP[view] [source] [discussion] 2023-07-26 16:32:17
>>nptelj+SA
My guess is that on desktop, the endgame will involve implementing Easy Anti-Cheat levels of anti-tampering into the browser to prevent anyone from proxying through an automated Chrome instance or whatever. On Android, Google already has SafetyNet or Play Integrity, they can already refuse if the app or operating system has been modified
replies(1): >>nptelj+KB3
◧◩◪◨⬒
16. Dah00n+AB3[view] [source] [discussion] 2023-07-27 09:37:48
>>EGreg+4N
Well, I can't give you a rational answer since it is irrational in my opinion, but denying patches from Russians and Russian companies happen, including on the Linux Kernel mailing list:

https://www.theregister.com/2023/03/21/russian_foss_contribu...

But thank you for your reply.

◧◩◪
17. nptelj+KB3[view] [source] [discussion] 2023-07-27 09:39:04
>>a2128+UP
I agree that ultimately, this is what we're going to end up with. This is the only outcome that makes sense politically, and business-wise.
[go to top]