I'm happy to see this being noticed more and more. Google wants to destroy the open web, so it's a lot at stake.

Google basically says "Trust us". What a joke.

top 50 comments

sorted by: hot top controversial new old
[–] 29 points 3 years ago* (last edited 3 years ago) (2 children)
  • [–] 7 points 3 years ago (2 children)

    Dense US citizen here. Eli5 how I should explain "just trust us not to abuse collection of all your data or else get locked out of the world wide web" applies to antitrust laws for the FTC?

    I'm genuinely wanting to submit an email complaint/report. I understand that WEI protects nothing, but risks your data with all the sites you visit, all in an effort just to block possibly unprofitable users -- but I'm not sure how to tie in and word the Breaks Antitrust Laws part.

    Thank for your time to post these links.

  • source
  • parent
  • hideshow 4 child comments
  • [–] 8 points 3 years ago

    Nothing dense in this, I don't quite know what to write either. In my opinion what you wrote in your comment is just perfect, you're a citizen simply expressing an honest concern, without lying – not all people are tech-savvy. It also makes it clear that it's a letter from a real person.

    But that's only my point of view, and maybe I haven't thought enough steps ahead. Let's see what other people suggest and why.

  • source
  • parent
  • [–] 4 points 3 years ago

    Another dense citizen here. I ould say that you put it quite eloquently in your comment.

    But direct the question towards them.

    "Would googles new changes on their ad and user policy be affected by FTC data protection laws and GDPR or would they be in compliance"

    Or something among those lines.

  • source
  • parent
  • [–] 25 points 3 years ago (1 child)

    They don't care about a "safe web environment". That is not making them any more money. Knowing much more about their users and being able to perfectly match everything a user does anywhere with Googles advertising business, though, will.

  • source
  • hideshow 2 child comments
  • [–] 24 points 3 years ago

    *waiting patiently for EU to catch on to this.

    Google may not like the outcome…

  • source
  • [–] 23 points 3 years ago (2 children)

    They claim it's to prevent bots, but we all know it'll soon become standard in every WAF out there (Cloudflare, Akamai, etc) to just blanket block browsers failing attestation.

    All you need to know what will happen is to root an Android phone. You'd expect Netflix and bank apps and other highly sensitive apps to stop working. Okay, I can accept that, it kind of make sense. But the more you use the phone the more you realize a ton of apps also refuse to work. Zoom complains and marks your session as insecure, the Speedtest app refuses to test your speed, even the fucking weather app won't give you weather anymore. Jira/Confluence/Outlook/Teams also complain about it. It's ridiculous.

    Even if it'd trust Google to not misuse the feature and genuinely use it to reduce ad fraud, the problem is the rest of the developers and companies. Those, they absolutely cannot be trusted to not abuse the feature to block everyone. Security "consultants" will start mandating its use to pass security audits, government websites will absolute use it, and before you know it, half the web refuses to work unless you use Chrome, Edge or Safari.

  • source
  • hideshow 4 child comments
  • [–] [S] 10 points 3 years ago (3 children)

    Yup I noticed this also. I used a rooted phone without Google apps on it and so many apps simply refused to work. They use Googles api in the background which means Google finds out about literally everything we do on our phones. They already own the entire operating system but we can't even run apps without them being in the middle.

    This is all similar to using Microsoft Windows or Mac OS so I guess people are so used to this behavior that it's somehow ok.

    But I'm a long term Linux user and I'm used to the OS not calling home and not reporting what apps I use. And this is how it should be. I'm so over big tech it's not even funny anymore.

  • source
  • parent
  • hideshow 5 child comments
  • [–] 7 points 3 years ago

    It's even worse without Google apps, but I was talking about SatetyNet/PlayIntegrity specifically.

    The mere act of unlocking the bootloader, without even modifying anything, will cause all the problems I outlined, and it's the same API that Google is proposing to use by browsers to check for device integrity.

    Stuff depending on Google libraries, eh, that annoying but people can and will reimplement those, be it microG or Wine/Proton. Not being able to see the weather I literally could get just looking out the window because my bootloader is unlocked? That's insane.

  • source
  • parent
  • [–] 2 points 3 years ago (1 child)

    I used a rooted phone without Google apps on it and so many apps simply refused to work. They use Googles api in the background

    This has nothing to do with being rooted but with Google encouraging people to build apps using its proprietary libraries to make Google Android more valuable than Android Open Source Project. There may be a connection to the EU's attempts to stop Google from forcibly bundling several of its other apps with the Play Store.

    For most use cases, good alternatives are available and it's just a matter of developers being lazy, but I'm not sure there's another good option for chat apps to get timely notifications without high battery consumption. MicroG provides an open source alternative to Google's libraries and works for most apps, including chat notifications.

  • source
  • parent
  • hideshow 2 child comments
  • [–] 4 points 3 years ago (1 child)

    It's a bit worse than just Google libraries, apps can use Play Integrity which uses hardware attestation to validate it's bootloader lock status and that it's running a vendor signed and Google approved ROM.

    Current bypasses emulate older devices without the necessary hardware, but those will eventually stop working and there won't be bypasses unless someone leaks some master keys or finds TPM exploits to trick it into signing the integrity request. It's very bad.

  • source
  • parent
  • hideshow 1 child comment
  • load more comments (1 reply)
  • load more comments (1 reply)
  • [+] 19 points 3 years ago* (last edited 3 years ago) (6 children)
  • [–] [S] 9 points 3 years ago (10 children)

    Yes exactly. This is what worries me the most since I also run only Linux, and I can't imagine even being interested in computers anymore if Linux is not allowed on the web. That would be horrific.

    It's 100% critically dangerous and must be stopped.

  • source
  • parent
  • hideshow 11 child comments
  • [+] 5 points 3 years ago* (last edited 3 years ago) (1 child)
  • [–] 4 points 3 years ago (3 children)

    They've needed to be broken up for over a decade now, but that'd require the government to actually enforce antitrust/monopoly laws

  • source
  • parent
  • hideshow 4 child comments
  • load more comments (2 replies)
  • load more comments (9 replies)
  • [–] 2 points 3 years ago (3 children)

    "All Google associated platforms hereby block all ios devices."

    I am not a fan of apple. But this would piss a lot of people off but is well within their ability and rights to do. And unfortunately they have enough of a monopoly with the internet (Google, youtube, and all the other sites served through their dns) that they can essentially break the internet for people they block. They would get 90% of those ios users to switch to Android.

    The flow of information through the internet is one of the greatest advancements of man kind and we have to trust a massive cooperation not to destroy it.

  • source
  • parent
  • hideshow 6 child comments
  • load more comments (3 replies)
    [–] 16 points 3 years ago (4 children)

    WEI can potentially be used to impose restrictions on unlawful activities on the internet, such as downloading YouTube videos and other content, ad blocking, web scraping, etc.

    Not one of those things is illegal.

    Some are against a site’s TOS and some are outright fine.

  • source
  • hideshow 6 child comments
  • load more comments (2 replies)
    [–] 10 points 3 years ago (4 children)

    While you are at it, convince Apple to allow Firefox on iOS, and decline to use WEI in Safari. Otherwise there's no way to avoid WEI on iPhone, and only one mainstream rendering engine free of this insidious malware. Many companies will shy away from it if it breaks mobile apps on the Apple platform.

  • source
  • hideshow 5 child comments
  • load more comments (3 replies)
    [–] 10 points 3 years ago (17 children)

    If you are not using Firefox now is a good time to start.

  • source
  • hideshow 18 child comments
  • [–] 5 points 3 years ago (1 child)

    Just switched yesterday, was way easier than I thought it would be. I'm converted on all my devices, all my stuff has been synced from Chrome in a few clicks. Just do it people.

  • source
  • parent
  • hideshow 2 child comments
  • [–] 2 points 3 years ago

    If you haven't already, check out Firefox Sync.

    You can sync your stuff across Firefox instances (PC, mobile, different PC profiles etc.) You can choose to sync logins, open tabs, bookmarks, add-ons etc.

    Each place you use Firefox can choose to sync different stuff, so for example you can sync logins everywhere but only sync open tabs on the PC.

    In case you replace the phone or your PC HDD crashes etc. all you have to do is login back to Firefox Sync and you get all that stuff back.

  • source
  • parent
  • load more comments (16 replies)
    [–] 6 points 3 years ago

    I'm glad the reaction all around seems to be "That's sus as fuck"

  • source
  • [–] 5 points 3 years ago (4 children)

    It's time to use web integrity against them, by blocking access to your site if they "pass" integrity checks, and telling them to use a freedom respecting browser instead.

  • source
  • hideshow 5 child comments
  • load more comments (3 replies)
    [–] 3 points 3 years ago* (3 children)

    There's an ongoing protest against this on GitHub, symbolically modifying the code that would implement this in Chromium. See this lemmy post by the person who had this idea, and this GitHub commit. Feel free to "Review changes" --> "Approve". Around 300 people have joined so far.

  • source
  • hideshow 3 child comments
  • load more comments (3 replies)
    [+] 3 points 3 years ago (4 children)
    load more comments (4 replies)
    [–] 2 points 3 years ago (1 child)

    It won't block browsers that spoof their identity? Yeah, sure.

  • source
  • hideshow 2 child comments
  • There is no defense of the move. It's bad for the internet. Pure and simple!

  • source
  • load more comments
    view more: next ›