top 50 comments

sorted by: hot top controversial new old
[–] 71 points 3 years ago (1 child)

Maybe the thing to do here, when web sites start enforcing this, is to swamp them with support requests. Don't write a screed or manifesto with ethical or technical reasons why this is wrong. Pretend to be a non-technically-inclined user and tell them you've spent hours trying to get it to work and your browser keeps throwing up errors you don't understand. They will ignore the principles, but if they think the technology is "too hard" for their "dumb users," that might carry more weight.

  • source
  • hideshow 2 child comments
  • [–] 19 points 3 years ago* (last edited 3 years ago) (2 children)

    I don't think this will work. If companies can get away of slapping us by doing "please use Google Chrome or other Chromium-based browsers" just because Google implements the most niche, probably privacy-last, feature ever, then they will get away with it this time, again.

  • source
  • parent
  • hideshow 3 child comments
  • [–] 20 points 3 years ago (4 children)

    I literally can't log into the Amtrak Android app unless I have Chrome installed. It strictly relies on Chrome custom tabs. Other browsers that support custom tabs don't work.

    I cannot imagine any reason for this except sheer ineptitude.

    Guess what Amtrak support told me when I reported this as a bug?

  • source
  • parent
  • hideshow 7 child comments
  • [–] 5 points 3 years ago

    As an AI language model, I cannot understand why you would not already have chrome installed. Chrome is a popular browser choice for the android operating system. Please check the app store for chrome.

  • source
  • parent
  • load more comments (1 reply)
  • load more comments (1 reply)
  • [–] 46 points 3 years ago (2 children)

    I can't wait to have to download a crack for my browser so a website thinks that my browser is using wei and no-adblock.

  • source
  • hideshow 4 child comments
  • [–] 46 points 3 years ago* (last edited 3 years ago) (10 children)

    Just use Firefox. I don't understand why people are so hell-bent on using a Chromium-based browser.

    EDIT: I see now that I was grossly misinformed on the issue. Thanks for the replies.

  • source
  • parent
  • hideshow 12 child comments
  • [+] 43 points 3 years ago (5 children)
  • [–] 39 points 3 years ago (2 children)

    my browser hasn’t got higher privileges than my admin user account

    They'll fix that. The endgame might very well be you can only run a trusted browser, safely checked by your OS, itself trusted, running on fully signed code from a trusted source, started on a trusted motherboard/CPU, with hardware lockdown that would only boot trusted kernel and embed private keys so deep that you'd need a full lab to recover them, only to have them remotely disabled if anything funky seems to be happening at any point in that chain.

    For now, this is fiction. For now. We already started moving that way with secureboot, opaque UEFI in our systems and TPM modules. The only saving grace is that they currently all have flaws.

  • source
  • parent
  • hideshow 2 child comments
  • load more comments (2 replies)
  • load more comments (2 replies)
  • load more comments (8 replies)
  • [–] 7 points 3 years ago (12 children)

    Right. I mean there's always going to be a way. Your open source browser can run a spoof of an "official" browser, present itself as a valid user, load the page with all the ads and tracking in a sandbox in between, strip all of it out and serve you the actual content.

    Or maybe people will eventually be fed up and we'll start our own internet completely out of corporate control.

  • source
  • parent
  • hideshow 14 child comments
  • [–] 9 points 3 years ago

    Your open source browser can run a spoof of an β€œofficial” browser

    Not if the server requires the digital signature of a challenge to be produced by a key whose certificate is signed by a "trusted" third party, said third party only providing that key at runtime, if your browser can also provide the same kind of authorization from the OS, itself being only able to produce it if it can safely determine that it's running on completely locked-down hardware AND having online-activated DRM tells him he can provide such key; the hardware itself requiring constant online connexion to ensure it's "authorized", and including yet another layer of keys in hardware.

    There's been progress toward this kind of things. At every step, people warning about the risks are seen as lunatics. SecureBoot preventing booting a custom kernel? No problem, microsoft will sign your keys. TPM not delivering keys to non-trusted kernels? No problem, just don't use it (and don't get the keys, obviously). UEFI requiring digital signature to be flashed? It's for your safety, but we won't give you the keys or it would defeat the purpose. Embedded CPU inside your CPU running opaque code on every operation you do? Trust me bro, there's no problem here.

    Sure, opensource (or even just open at this point) alternative will most likely remain available as a niche, but once all major services that people want requires such a chain of control, the vast majority of people will gladly flock to locked-down system. Heck, it's already happening. Nowadays I can't even log into my bank website without a trusted iOS or Android device. The "free, open" alternative will be rare, expensive, and only work for people that cares. Which is not too much sadly.

  • source
  • parent
  • load more comments (10 replies)
  • [–] 36 points 3 years ago (1 child)

    The free internet is bad for Google.

  • source
  • hideshow 2 child comments
  • [–] 27 points 3 years ago
    [–] 26 points 3 years ago (4 children)

    So what can we do? Egg their headquarters? Because so far our useless politicians haven't passed bills to fight this.

  • source
  • hideshow 6 child comments
  • [–] 20 points 3 years ago (2 children)

    It'd help if the government wasn't run by a bunch of ancient humans that were there when cavemen would draw on cave walls. The government has shown time and time again they don't understand tech but always try to act like they do. Take that tiktok case for example. They made themselves look like idiots to the USA. Pathetic.

  • source
  • parent
  • hideshow 4 child comments
  • [–] 7 points 3 years ago

    I think the moment for me was when they had Mark Zuckerberg himself, testify to Congress.

    They didn't "grill him" as media would've liked to have you believe. The guy danced around all of Congress because they themselves didn't know a damn thing about what he was saying. Of course he wasn't penalized and got off scot-free.

    Just like every other tech company. The FTC, has no teeth. The FCC, has no teeth. Congress, has no brain.

  • source
  • parent
  • load more comments (2 replies)
    [–] 20 points 3 years ago

    More DRM. Browsers already support DRM schemes for media playback.

  • source
  • [–] 16 points 3 years ago (1 child)

    Not overly worried - the EU anticompetition laws will swat this down on this side of the atlantic - but not sure about the US

  • source
  • hideshow 2 child comments
  • [–] 14 points 3 years ago (1 child)

    That's not a WEB browser, that's a Googleverse browser.

  • source
  • hideshow 2 child comments
  • [–] 10 points 3 years ago (1 child)

    where linux

    i know google sucks but still

  • source
  • hideshow 1 child comment
  • load more comments (1 reply)
    [–] 7 points 3 years ago (3 children)

    They’re adding DRM? In what way?

  • source
  • hideshow 4 child comments
  • [–] 24 points 3 years ago (7 children)

    Basically by allowing websites to refuse to load unless the browser the operating system running the browser promises that the user isn't allowed to know what the computer is doing. And Google super duper promises this won't be used for evil.

    https://arstechnica.com/gadgets/2023/07/googles-web-integrity-api-sounds-like-drm-for-the-web/

  • source
  • parent
  • hideshow 10 child comments
  • [–] 5 points 3 years ago (1 child)

    allowing websites to refuse to load unless the browser the operating system running the browser promises that the user isn’t allowed to know what the computer is doing

    So they won't support Linux anymore?

  • source
  • parent
  • hideshow 2 child comments
  • [–] 6 points 3 years ago

    That seems to be the message everyone is drawing from this.

    I think it'll be more insidious than that, there will be Linux, but only "signed, verified" Linux will be allowed, and the only Linux distributions that will make that list are the ones with corporate or government versions. Specifically distributions like Google's Android, IBM's Red Hat, Canonical's Ubuntu, and China's Kylin.

    This is still as horrible. Imagine Ubuntu winning the snap vs flatpack exchange, because their OS is 'legit', whereas every other distro is pushed out, because it's too much work to install an unsigned OS.

  • source
  • parent
  • load more comments (4 replies)
  • load more comments (2 replies)
    [–] 7 points 3 years ago

    Secutity is not priotity.

  • source
  • [–] 6 points 3 years ago

    One of the four authors of the proposal is on my mastodon instance. How ironic (and kinda embarrassing).

  • source
  • load more comments
    view more: next β€Ί