TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

“Web Environment Integrity”: Locking Down the Web

181 pointsby edsimpsonalmost 2 years ago

9 comments

mrguyoramaalmost 2 years ago
What is Brave going to do when the code for WEI becomes load bearing in the chromium code base?<p>Still excuse after excuse after excuse to just not use Firefox. I literally don&#x27;t care if you have to hold up your nose, there&#x27;s only one actual alternative browser engine, and it&#x27;s a matter of survival for anyone who doesn&#x27;t want the whole internet controlled by google.<p>It could be half as fast (it isn&#x27;t) and use twice as much RAM (it doesn&#x27;t) and ask for a damn nude photo of me and I&#x27;d still be using it right now.<p>Using a google owned browser engine is like growing cavendish bananas while you know the neighbor&#x27;s farm has the blight already. Change over and try to get good at the new strain while you have a choice, because soon you won&#x27;t and it will be out of your hands what happens after that.
评论 #36962322 未加载
评论 #36962756 未加载
评论 #36962514 未加载
评论 #36962477 未加载
评论 #36963764 未加载
评论 #36962429 未加载
评论 #36962384 未加载
评论 #36962447 未加载
评论 #36971926 未加载
评论 #36963298 未加载
评论 #36962475 未加载
评论 #36964064 未加载
评论 #36962446 未加载
评论 #36962838 未加载
评论 #36962636 未加载
happytigeralmost 2 years ago
The faster we can build usable decentralized apps and get users onto them, the better.<p>It should only lend urgency to leave the “old web” for those of us who are builders, makers and evangelizers.<p>They’re after encryption, they’re attacking anonymity, they want all of finance for themselves, and they want to kill privacy too -- I for one say NO thank you.<p>There is a level — almost a treble —- in these comments on how “it’s inevitable” or “already cooked” but only if you see these fights in isolation. It most assuredly it is <i>not</i> inevitable.<p>Let’s get positively focused and make hay while the sun shines and it’s not too late. There’s so much intelligence, compassion and love for humanity in this community. Let’s use it.
评论 #36973366 未加载
renegat0x0almost 2 years ago
Browsing these days is like going into jungle. I use Adblock, ghostery, noscript, pihole. To have a good experience you cannot go in unprepared. Some pages require some scripts to be running. Then I will not go in. I think it will be the same with WEI. If a page asks me for it, I will not go in. Sorry, but no. It may be harder over time, but if I cant&#x27;t change the world, I van browse on my own terms. There needs to be extension that will be blocking WEI.<p>We need a list od pages that supports it and we need to same the for their support of WEI
smoldesualmost 2 years ago
I&#x27;m sure Tom Scott wouldn&#x27;t mind better personal attestation options on the Web: <a href="https:&#x2F;&#x2F;www.yahoo.com&#x2F;now&#x2F;prominent-youtuber-claims-brave-bat-095126650.html" rel="nofollow noreferrer">https:&#x2F;&#x2F;www.yahoo.com&#x2F;now&#x2F;prominent-youtuber-claims-brave-ba...</a>
评论 #36962227 未加载
saurikalmost 2 years ago
It&#x27;s nice that they are changing their marketing on this a bit now that there is a wave to ride and the evils of DRM are coming for them; but, let&#x27;s not forgot that, at the end of the day, <i>Brave is just another company that makes money on ads</i> :(, and (thereby) has most of the same anti-user incentives.<p>So, sure... they clearly don&#x27;t want to be prevented from blocking <i>other peoples&#x27; ads</i> (a big part of their pitch); but, blocking <i>their ads</i> while still getting paid--which is, of course, extremely easy to pull off on an unrestricted computer--is an existential threat to their only actual revenue stream which they want to protect against.<p>The ramification: Brave&#x27;s product managers--and even Brendan Eich himself (whom all of the later quotes I have in this comment were taken from, directly or indirectly)--have often talked about using the very same remote attestation technology to protect their SDK and even their browser for the same reasons as Google.<p><a href="https:&#x2F;&#x2F;www.reddit.com&#x2F;r&#x2F;BATProject&#x2F;comments&#x2F;bw6sek&#x2F;" rel="nofollow noreferrer">https:&#x2F;&#x2F;www.reddit.com&#x2F;r&#x2F;BATProject&#x2F;comments&#x2F;bw6sek&#x2F;</a><p><a href="https:&#x2F;&#x2F;www.reddit.com&#x2F;r&#x2F;BATProject&#x2F;comments&#x2F;b7rwbx&#x2F;" rel="nofollow noreferrer">https:&#x2F;&#x2F;www.reddit.com&#x2F;r&#x2F;BATProject&#x2F;comments&#x2F;b7rwbx&#x2F;</a><p>&gt; 1&#x2F; native C++&#x2F;Rust code, no JS tags on page that have zero integrity. That means ability to use SGX&#x2F;TrustZone to check integrity and develop private user score from all sensor inputs in the enclave; ...<p>&gt; We already have to deal w&#x2F; fraud. That is inherent in any system with users and revenue shares or grants. We do it better via C++ and (under way) SGX or TrustZone integrity checking + OS sensor APIs, vs today’s antifraud scripts that are routinely fooled.<p>&gt; What Brave offers that&#x27;s far better than today&#x27;s joke of an antifraud system for ads is as follows: 1&#x2F; integrity-checked open source native code, which cannot be fooled by other JS on page; ... (1) requires SGX or ARM equivalent, widespread on mobile.<p><a href="https:&#x2F;&#x2F;www.reddit.com&#x2F;r&#x2F;BATProject&#x2F;comments&#x2F;" rel="nofollow noreferrer">https:&#x2F;&#x2F;www.reddit.com&#x2F;r&#x2F;BATProject&#x2F;comments&#x2F;</a><p><a href="https:&#x2F;&#x2F;www.reddit.com&#x2F;r&#x2F;BATProject&#x2F;comments&#x2F;97trex&#x2F;comment&#x2F;e4axu6h&#x2F;?context=1" rel="nofollow noreferrer">https:&#x2F;&#x2F;www.reddit.com&#x2F;r&#x2F;BATProject&#x2F;comments&#x2F;97trex&#x2F;comment&#x2F;...</a><p>&gt; Part of the roadmap (details in update) is a BAT SDK. Obviously it would be open source, but more: we would require Secure Remote Attestation (Intel SGX broken but ARM TrustZone as used by Trustonic may be ok) to prove integrity of the SDK code in app.
评论 #36963024 未加载
gmercalmost 2 years ago
Turning the browser into a foreign entity on your own PC. From the company that went from “Making the worlds knowledge accessible’ to ‘rentseeking on the collected knowledge and the trying to lock everyone else out from it’
benatkinalmost 2 years ago
&quot;Brave&#x27;s browsers&quot; <i>distributions of browsers</i>, there ftfy
评论 #36962281 未加载
评论 #36962253 未加载
skilledalmost 2 years ago
Hard to listen to anything from a company that constantly:<p>1) Doesn’t innovate on anything, social media accounts are plagued with pointing fingers at others while using a Chromium fork themselves, ignorance at its finest.<p>2) Has been accused of selling copyrighted data for AI training and has not made a public statement.<p>3) Has a history of making stupid decisions and only apologizing when a big news outlet calls them out.
评论 #36962251 未加载
jauntywundrkindalmost 2 years ago
I personally think the upsides of WebBundles are huge. There&#x27;s nothing that would stop the browser from being able to filter &amp; ignore content coming from in a WebBundle, so I&#x27;m not sure what Brave&#x27;s greivance is here. The adserving topic is complicated as heck, but everyone seems to acknowledge big change is necessary &amp; Google and Firefox both have proposals to radically overhaul the system while enhancing user privacy; Brave&#x27;s own primary distinguisher at this point is their BAT tokens, their own answer here. There&#x27;s complicated topics here, but I see Brave following the standard pattern of trying to be a lightning rod of discontent.<p>It&#x27;s also surprising to me how almost no one has commented on Private Access Tokens shipping for Apple. Which do the same thing. Here&#x27;s them bragging about being able to avoid catchpa&#x27;s since the devices are all vouched for by Apple as unmodified &amp; controlled by Apple: <a href="https:&#x2F;&#x2F;developer.apple.com&#x2F;videos&#x2F;play&#x2F;wwdc2022&#x2F;10077&#x2F;" rel="nofollow noreferrer">https:&#x2F;&#x2F;developer.apple.com&#x2F;videos&#x2F;play&#x2F;wwdc2022&#x2F;10077&#x2F;</a><p>There was a decent submission on this recently, but not much engagement. <a href="https:&#x2F;&#x2F;www.snellman.net&#x2F;blog&#x2F;archive&#x2F;2023-07-25-web-integrity-api-vs-private-access-tokens&#x2F;" rel="nofollow noreferrer">https:&#x2F;&#x2F;www.snellman.net&#x2F;blog&#x2F;archive&#x2F;2023-07-25-web-integri...</a> <a href="https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=36866355">https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=36866355</a><p>I think this is absolutely the worst shit, almost as bad as MV3 being a utterly neutered shitty hell hole version of what web extensions were. But it&#x27;s notable to me that both Google didn&#x27;t start this particular trend, Apple did, and more broadly - I have such a hard time picking words here - it feels like the stark polemics have been on overdrive to create a reality distortion field, where Chrome is purely bad&#x2F;evil&#x2F;awful&#x2F;no-good everywhere. We should be upset &amp; mad! But I feel like we&#x27;re pretty far into losing our minds territory, and slipping into strokes of broadsweeping public madness.
评论 #36962325 未加载