TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

Google Chrome Proposal – Web Environment Integrity

119 点作者 screenshot将近 2 年前

18 条评论

jauntywundrkind将近 2 年前
&gt; <i>Motivation: Users often depend on websites trusting the client environment they run in.</i><p>Aka corporations insist on control &amp; want to make sure users are powerless when using the site. And Chrome is absolutely here to help the megacorp&#x27;s radically progress the War On General Purpose Computing and make sure users are safe &amp; securely tied to environments where they are powerless.<p>There&#x27;s notably absolutely no discussion or mention of what kind of checks an attestation authority might give, other than &quot;maybe Google Play might attest for the environment&quot; as a throwaway abstract example with no details. Any browser could do whatever they want with this spec, go as afar as they want to say, yes, this is a pristine development environment. If you open DevTools, Google will probably fail you.<p>It appalls me to imagine how much time &amp; mind-warping it must have taken to concoct such a banal <i>&quot;user motivation&quot;</i> statement as this. This is by the far the lowest &amp; most sold-out passed-over bullshit I have ever seen from Chrome, who generally I actually really do trust to be doing good &amp; who I look forward to hearing more from.
评论 #36780049 未加载
评论 #36779823 未加载
评论 #36779949 未加载
dahwolf将近 2 年前
There it is, the AI scraping detector. The hints in the text are obvious:<p>&quot;This trust may assume that the client environment is honest about certain aspects of itself, keeps user data and intellectual property secure.&quot;<p>The smoking gun is &quot;intellectual property&quot;. In a conventional browsing session the website has no idea what the human user is going to do with copyright-protected information published on the website. Hence, it assumes good intent and grants open access.<p>In the case of an AI scraper, assuming you detect it reliably, the opposite is true. Bad intent is assumed as the very point of most AI scrapers is to harvest your content with zero regard for permission, copyright or compensation.<p>To make this work, Google outsources the legal liability of distinguishing between a human and a bot to an &quot;attester&quot;, which might be Cloudflare. Whatever Cloudflare&#x27;s practice is to make this call will of course never be transparent, but surely must involve fingerprinting and historical record keeping of your behavior.<p>You won&#x27;t have a choice and nobody is liable. Clever!<p>Not to mention the extra new avenue created for false positives where you randomly lose all your shit and access, and nobody will explain why. Or, a new authoritarian layer that can be used for political purposes to shut down a digital life entirely.<p>All of this coming from Google, the scraping company.<p>I have a much simpler solution: it should be illegal to train AI on copyrighted content without permission from the copyright holder. Training AI is not the same thing as consuming information, it&#x27;s a radically new use case.
predictabl3将近 2 年前
Lots of people doom and gloom here about threats to user privacy and freedom.<p>This is the one I&#x27;d be worried about. Thought it was annoying to not be able to use banking apps on a rooted Android? Think about how annoying it will be when you can&#x27;t do much of anything, even on the Web, unless it&#x27;s from a sealed, signed Apple&#x2F;Google&#x2F;Microsoft image-based OS...<p>I realize the way Firefox&#x27;s user share is going, it might not matter or they might feel they don&#x27;t have a choice but I really, really hope Mozilla doesn&#x27;t even remotely consider implementing this.
评论 #36780534 未加载
评论 #36780714 未加载
评论 #36780740 未加载
评论 #36780330 未加载
评论 #36780294 未加载
krono将近 2 年前
These things Google has been announcing will culminate in an inhuman level of oppression of our digital lives and might irreparably damage people&#x27;s sense of ownership and sovereignty over their own personal electronic devices.<p>Gluttony, greed, envy, and arrogance. This is truly sickening.
dhx将近 2 年前
These proposals appear to be coming from the W3C Anti-Fraud Community Group. They haven&#x27;t identified even a single use case[1] of the technologies they&#x27;re trying to push onto the world being misused and abused. Use cases and their naivety appear to be largely copied from the OWASP Automated Threats to Web Applications[2].<p>There are no use case about these technologies being used by a dystopian country. No use case about enabling anti-competitive practices from incumbent companies. Seemingly little to no care or attempts to balance the longer term strategic impacts of these technologies on society, such as loss of innovation or greater fragility due to increased centralisation&#x2F;monopolisation of technology. No cost-benefit analysis or historical analysis for identified threat actors likelihood to compromise TPMs and attested operating systems to avoid these technologies (there&#x27;s no shortage of Widevine L1 content out there on the Internet). No environmental impact consideration for blacklisting devices and having them all thrown into a rubbish tip too early in their lifespan. No political&#x2F;sovereignty consideration to whether people around the world will accept a handful of American technology companies to be in control of everything, and whether that would push to the rest of the world to abandon American technology.<p>The majority of the contributors to these projects appear to be tech employees of large technology companies seemingly without experience outside of this bubble. Discussions within the group at times self-identify this naivety. The group appears very hasty to propose the most drastic, impractical technical security controls with significant negative impacts such as whitelisting device hardware and software. But in the real world for e.g. banking fraud, attacks typically occur through social engineering where the group&#x27;s proposed technical controls wouldn&#x27;t help. There appears to be little to no attempt made to consider more effective real world security controls with fewer negative impacts, such as delaying transactions and notifying users through multiple channels to ensure users have had a chance to validate a transaction or &quot;cool off&quot;.<p>[1] <a href="https:&#x2F;&#x2F;github.com&#x2F;antifraudcg&#x2F;use-cases&#x2F;blob&#x2F;main&#x2F;USE-CASES.md">https:&#x2F;&#x2F;github.com&#x2F;antifraudcg&#x2F;use-cases&#x2F;blob&#x2F;main&#x2F;USE-CASES...</a><p>[2] <a href="https:&#x2F;&#x2F;owasp.org&#x2F;www-project-automated-threats-to-web-applications&#x2F;" rel="nofollow noreferrer">https:&#x2F;&#x2F;owasp.org&#x2F;www-project-automated-threats-to-web-appli...</a>
评论 #36784469 未加载
评论 #36805365 未加载
no_time将近 2 年前
There it is. Decades of turning up the heat and boiling the frog has culminated in this proposal. From secure boot and TPMs to SafetyNet and Pluton.<p>Even in this very thread there are people saying this is not so bad because “it will help prevent fraud”<p>lmao.
评论 #36782885 未加载
评论 #36842557 未加载
greyface-将近 2 年前
API spec: <a href="https:&#x2F;&#x2F;rupertbenwiser.github.io&#x2F;Web-Environment-Integrity&#x2F;" rel="nofollow noreferrer">https:&#x2F;&#x2F;rupertbenwiser.github.io&#x2F;Web-Environment-Integrity&#x2F;</a><p>It&#x27;s morbidly amusing to see the browser referred to as a &quot;user agent&quot; here.
评论 #36780470 未加载
评论 #36780213 未加载
leokeba将近 2 年前
<a href="https:&#x2F;&#x2F;hnrankings.info&#x2F;36778999&#x2F;" rel="nofollow noreferrer">https:&#x2F;&#x2F;hnrankings.info&#x2F;36778999&#x2F;</a> Is this HN moderation ?
评论 #36781975 未加载
ranting-moth将近 2 年前
The final nail in the coffin for the open internet.<p>&quot;Don&#x27;t be evil&quot; has really turned into &quot;Google is evil&quot;
000ooo000将近 2 年前
&quot;The server needs to be sure that it&#x27;s dealing with a client capable of showing ads.. whoops no I mean a client that is <i>human</i>. For safety. Yep.&quot;
Klonoar将近 2 年前
AKA: The shadow war on bot traffic continues humming along.
评论 #36779962 未加载
评论 #36779898 未加载
mattigames将近 2 年前
Fuck you Google, dystopian books were meant as a warning not as a play book.
评论 #36780483 未加载
yukkuri将近 2 年前
<a href="https:&#x2F;&#x2F;github.com&#x2F;RupertBenWiser&#x2F;Web-Environment-Integrity&#x2F;blob&#x2F;main&#x2F;explainer.md">https:&#x2F;&#x2F;github.com&#x2F;RupertBenWiser&#x2F;Web-Environment-Integrity&#x2F;...</a><p>They got tired of getting comments from mere web users that don&#x27;t want this and locked down comments :P
kmeisthax将近 2 年前
Tim Berners-Lee is spinning in his grave and he&#x27;s not even dead yet.
评论 #36834845 未加载
ShowalkKama将近 2 年前
&gt;6.1.1. Secure context only Web environment integrity MUST only be enabled in a secure context. This is to ensure that the website is not spoofed. Todo<p>do they realize that you can use a custom certificate &#x2F; patch the check routines? I don&#x27;t think they quite realize what they are even suggesting.
评论 #36790365 未加载
akomtu将近 2 年前
I&#x27;m surprised the ad corps haven&#x27;t forked the internet yet: special drm-ed websites accessible only via special drm-ed browsers. At least it would relieve those who want to share knowledge from the presence of those who sell addiction.
评论 #36780237 未加载
评论 #36780683 未加载
评论 #36799855 未加载
slater将近 2 年前
<i>?PHPSESSID</i> - but now via JS! &#x2F;s
minton将近 2 年前
&gt;Owners<p>&gt;bewise@chromium.org<p>&gt;sergeyka@chromium.org