Google's Web Environment Integrity Will Destroy The Web
Skills:
Staying Current in AI80%
Key Takeaways
Google's Web Environment Integrity proposal aims to prevent fake users and bots by introducing a form of DRM for the general web, using attestation tokens and device fingerprinting to detect malicious activities.
Full Transcript
I've been saying for a very long time the more you fight against web advertising the more esoteric their protections are going to become and recently we stepped up to the next rung of the ladder this is web environment Integrity now this proposal is being hosted on a personal GitHub account ignore the fact that all of the authors just happen to be Google software Engineers this is definitely not something being proposed at Google whilst this blew up recently this is not exactly new with the latest change being three months ago all the way back in April I guess someone must have found it and posted it on Reddit or Hacker News or made a video about it because nobody heard about this until about a week ago but let's be fair and see what it's all about users often depend on websites trusting the client environment they run I guess that's technically the case but not because users were asking for that that's the case because businesses have forced it under the user it's probably more fair to say that businesses depend on trusting the client environment this trust may assume the client environment is honest about certain aspects of itself keeps user data and intellectual property secure these are two very different things this is completely irrelevant to the website this is entirely based around your business use case and is transparent about whether or not a human is using it users don't care about this in their environment because they're the ones interacting with the environment this trust is the backbone of the open internet no no it's not whatsoever critical for the safety of user data I guess in the context of making sure that SSL is working correctly but that's pretty much it and for the sustainability of the website's business now we are getting to the meat of The Proposal this backwards trust model is Being Framed as a good thing for the user users like visiting websites that are expensive to create and maintain but they often want or need to do it without paying directly these websites fund themselves with ads but advertisers can only afford to pay for humans to see the ads rather than robots this creates a need for human users to prove to websites that they are human sometimes through tasks like challenges or logins how your business can be sustainable is not something at all relevant to the user having this being the first thing they list makes no sense to me users want to know that interacting with real people on social websites but Bad actors often want to promote posts with a fake engagement for example to promote products or make a new story seem more important now for the record this proposal has nothing to do with stopping that users playing a game on a website want to know whether other players are using software that enforces the game's rules sure I'll give you that one that's totally fair users sometimes get tricked into installing malicious software that imitate software like their banking apps to steal from those users the bank's internet interface could protect those users if it could establish that the requests it's getting actually come from the banks or other trustworthy software I don't understand what's even trying to be said here most of the time if you download a malicious banking application it's not actually logging into your bank it's gonna give you a fake login screen that you try to log into and then it will log your credentials and then at a later time someone is going to examine the database and log into the account from that maybe they mean like a web browser that has a key logger in it but that's not a banking app so I don't know what they're trying to say here and these are the goals allow web servers to evaluate the authenticity of the device an honest representation of the software stack and the traffic from the device offer an adversarially robust and long-term sustainable anti-abuse solution don't enable new cross-site user tracking capabilities through attestation and continue to allow web browsers to browse the web without attestation these goals are incredibly generic and arguably don't really mean anything but how is this solution actually going to work there are three parties involved in this solution the web page executing in a user's web browser a third party they're going to test to the device a web browser is executing on referred to as the attesta and the web developer server which can remotely verify attestation responses and act on this information this is the server the website is running on firstly a web page request an environment attestation from the attesta with a Content binding the content binding ensures that even if an attacker intercepts an attestation they can't use it to attest to a modified Quest so if you had to say a man in the middle attack and someone stole your attestation request they couldn't go and modify the request and use that to get their environment tested to instead the attesta will then sign a token containing the attestation and content binding with a private key the tester then Returns the token in signature to the web page the web page returns this in information to the web server the web server then checks that the token came from the tester at truss and inspects the token's payload it verifies the payload by verifying the signature with the attest as public key optionally the web server may call the attest to server endpoint to get additional signals for example to detect potentially hyperactive devices so if there is a client constantly asking for attestation there might be something weird going on there now I don't know about you and maybe I'm just overthinking it but having a system which can verify the environment you're running in and can lock down access to certain content that sounds an awful lot like DRM to Me Maybe I'm imagining it I very well could be but this sounds like a form of generic web-based DRM but I would argue way way worse than that so some of the example use cases are detect social media manipulation and fake engagement to Tech non-human traffic in advertising to improve user experience and access to web content detect phishing campaigns detect bulk hijacking attempts and bulk account creation detect the large-scale cheating in web-based games with fake clients detect compromised devices where user data would be at risk detect account takeover attempts by identifying password guessing what kind of information do you need to send to the attester to identify all of these different situations well they don't say what they do say is what is in the signed attestation the a tester's identity for example Google Play and a verdict saying whether the attest considers the device trustworthy that is all along with some things they may consider including and something they don't want to include like a device ID which I really hope you don't want to include a device ID in every single attestation that should be an absolute no-brainer now partially because Google and partially because of just how absolutely broad the use cases and goals are a lot of people are really worried about the implications they are not listing whilst they say over and over and over again the data is low entropy and the goal here is not to make tracking easier anybody who knows anything about fingerprinting knows that no single data point is enough to fingerprint a user what you need is lots of little data points that all correlate in a similar Direction and this is just one extra point you can use to say this is probably exactly this user the far more concerning issue is around the open web so right now you can relatively easily fill a website with a custom user agent you can say I am on chromium I am on Firefox I am on Windows I am on Linux I'm on Macos and basically the website says okay I believe you but if we're doing attestation on our environment what's to stop the attesta or the web server basically just saying I don't like this browser I don't like this operating system and just excluding it from the pool and this is something even acknowledged by the authors a testers will be required to offer their service under the same conditions to any browser who wishes to use it and meet certain Baseline requirements we can certainly see this about the major attesters but what if someone decides to run their own a tester can you really enforce that across the entire web but even if it is possible it doesn't at all fix the web server side this leads to any browser running on the given OS platform having the same access to the technology but we still have the risks that one some websites might exclude some off-roading systems and two if the platform identity of the application requests the attestation is included some websites might exclude some browsers we can safely assume the major browsers right now are going to be accepted by the media testers but what if you go and make something new maybe something not even based on chromium it is an entirely new web engine well that's also a massive problem as new browsers are introduced they will need to demonstrate to a testers a relatively small group that they pass the bar but they wouldn't need to convince all the websites in the world established browsers would need to only use the testers that respond quickly and fairly to new browsers requests to be trusted either way though there is going to be a period where if you make a new browser on websites that require attestation the web's just not going to work now earlier in the write-up those talks about helping the advertisers so what if a new browser comes along that has ad blocking built in is that a browser that's ever going to pass at a station we know the stats that Google has on ad blocking so I don't know maybe maybe it won't Google has proven themselves time and time again to not be trustworthy Shepherds of the opening internet even if they say ah it's not a goal to enforce or interfere with browser functionality including plugins and extensions after the whole mv3 thing why would anybody trust you on that in just the past week or so this repo has had a ton of feedback almost entirely negative like nobody is in support of this especially if you go to the closed issues which uh is just a lot of people insulting them now the insulting them is not exactly productive but I do agree with the sentiment but as of yesterday Ruth Ben Weiser one of the authors has responded hey everyone thank you for your patience and thank you to everyone who engaged constructively it is clear based on the feedback we received that a bigger discussion needs to take place and I'm not sure my personal repository is the best place to do it we are looking for a better forum and will update when we have found one we want to continue the discussion and collaborate to address your core concerns in an improved explainer no I don't want that and nobody here wants that either what they want to see happen is you delete the repo and never talk about this again there is no discussion that needs to be had here this is something that just doesn't need to happen Wei which is web Integrity is not designed to single app browsers or extensions maintaining users access to the open web on all platforms is a critical aspect of the proposal is an explicit goal that users can browse the web without this proposal which means we want the user to remain free to modify their browser install extensions use devtools and importantly continue to use accessibility features okay well what if you go to a website that requires attestation can you just not have your environment tested and use the website just fine no well you require attestation then Wei prevents ecosystem locking through holdbacks we'd propose a hold back to prevent looking at the platform level essentially some percentage of the time say five percent or ten percent the Wei attestation would be intentionally omitted and would look the same as if the user opted out of Wei or the device is not supported this is designed to prevent Wei from becoming DRM for the web any sites that attempt to restrict browser access based on Wei signals alone would have also restricted access to a significant enough portion of a testable devices to disincentivize this Behavior so basically it's DRM for the web that's a little bit buggy and gives you the wrong information five five or ten percent of the time but also this isn't the only piece of information this attestation token is just one piece of information a site can use they can combine this with other things and still do the lockdown I have no idea how anybody thought this would fly and I have no idea how after all of this feedback the author is still defending it this is objectively a bad idea and I never want to hear about it again but let me know your thoughts do you think I'm wrong do you think this is not actually web DRM or do you completely agree with me and think this is an absolutely insane idea and should never ever happen let me know and if you like the video go like the video and if you really like the video and you want to become one over these amazing people over here check out the patreon scrubs the liberope link in the description down below that's gonna be it for me and just stop [Music] [Music]
Original Description
Of all the terrible ideas to come out of google, the web environment integrity proposal has got to be worst one, effectively it's DRM for the general web.
==========Support The Channel==========
► $100 Linode Credit: https://brodierobertson.xyz/linode
► Patreon: https://brodierobertson.xyz/patreon
► Paypal: https://brodierobertson.xyz/paypal
► Liberapay: https://brodierobertson.xyz/liberapay
► Amazon USA: https://brodierobertson.xyz/amazonusa
==========Resources==========
Web Environment Integrity Explainer: https://github.com/RupertBenWiser/Web-Environment-Integrity/blob/main/explainer.md
=========Video Platforms==========
🎥 Odysee: https://brodierobertson.xyz/odysee
🎥 Podcast: https://techovertea.xyz/youtube
🎮 Gaming: https://brodierobertson.xyz/gaming
==========Social Media==========
🎤 Discord: https://brodierobertson.xyz/discord
🎤 Matrix Space: https://brodierobertson.xyz/matrix
🐦 Twitter: https://brodierobertson.xyz/twitter
🌐 Mastodon: https://brodierobertson.xyz/mastodon
🖥️ GitHub: https://brodierobertson.xyz/github
==========Credits==========
🎨 Channel Art:
Profile Picture:
https://www.instagram.com/supercozman_draws/
🎵 Ending music
Track: Debris & Jonth - Game Time [NCS Release]
Music provided by NoCopyrightSounds.
Watch: https://www.youtube.com/watch?v=yDTvvOTie0w
Free Download / Stream: http://ncs.io/GameTime
DISCLOSURE: Wherever possible I use referral links, which means if you click one of the links in this video or description and make a purchase I may receive a small commission or other compensation.
Watch on YouTube ↗
(saves to browser)
Sign in to unlock AI tutor explanation · ⚡30
Playlist
Uploads from Brodie Robertson · Brodie Robertson · 0 of 60
← Previous
Next →
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
This Linux Patch Removes Spectre & Meltdown Protections
Brodie Robertson
Linux's Most Degenerate Terminal Application
Brodie Robertson
You Can Buy Modern Linux Distros On A DVD??
Brodie Robertson
Bypass Paywalls Vanishes From Firefox Addon Store
Brodie Robertson
CoreJS: The Web & Open Source Are Broken!
Brodie Robertson
Begone GTK4, Long Live The New King GTK5
Brodie Robertson
Flathub Finally Adds Much Needed Flatpak Feature
Brodie Robertson
Google Should Be Worried About ChatGPT Bing
Brodie Robertson
How To Never Improve The Linux Wayland Experience
Brodie Robertson
Fedora Linux Unveils New 5 Year Roadmap
Brodie Robertson
Linux Desktop Randomly Stuttering? Here's Why #shorts
Brodie Robertson
Why We Need Even More Linux Distros!?!
Brodie Robertson
This Wayland Change Will Improve Linux Forever
Brodie Robertson
Ubuntu Linux Was Once Spyware Says EFF & Stallman
Brodie Robertson
Rise Of A New Kind Of Linux Package Manager
Brodie Robertson
Rolling Release Linux Distro Probably Isn't For You
Brodie Robertson
Ubuntu Flavors Put An End To Shipping Flatpak
Brodie Robertson
WINE Will Finally Run On Wayland NATIVELY!!
Brodie Robertson
No ZDNET, Linux 6.2 WILL NOT Run On M1 Macs
Brodie Robertson
Ubuntu Linux Announces New Kind Of Mini ISO??
Brodie Robertson
Fedora Linux Finally Kills Off Delta RPM
Brodie Robertson
Linus Torvalds Is Sick Of Useless Git Merges
Brodie Robertson
Arch Linux Bricks Dual Boot With One Kernel Change
Brodie Robertson
Linux AppImage Finally Addresses Greatest Flaw!!
Brodie Robertson
Refusing To Use Windows For "Religious Reasons"
Brodie Robertson
GNOME Shell & Mutter Finally Drop GTK3!!
Brodie Robertson
11 Documents Showing Microsoft Tried To Destroy Linux
Brodie Robertson
Manjaro Linux Is The Joke That Never Ends
Brodie Robertson
The New Ubuntu Linux "Flavor" We All Expected
Brodie Robertson
NEVER Write Git Commit Messages With ChatGPT
Brodie Robertson
Why GNOME? Why Didn't KDE Takeover Linux?!?
Brodie Robertson
Discord Tried To END This Reverse Engineered Server
Brodie Robertson
Mesa 23 Makes Linux Shader Stuttering A Thing Of The Past
Brodie Robertson
Linux Kernel Broke A Feature NOBODY Uses!
Brodie Robertson
Manjaro Broke Asahi Linux... AGAIN!!!
Brodie Robertson
Linux Hasn't Become Complicated & Limiting | Distrotube Reply
Brodie Robertson
Ubuntu Linux's Steam Snap Is Almost Stable
Brodie Robertson
Wayland Is Linux's Future, But Why Do I Care?
Brodie Robertson
John Deere Refuses To Respect Free Software & GPL
Brodie Robertson
Why BSD Documentation Is Just Better Than Linux
Brodie Robertson
KDE Fixes Discord On Wayland Because Discord Can't
Brodie Robertson
Xorg Foundation Has A Serious Problem
Brodie Robertson
Manjaro Linux's Biggest Drama That Never Happened
Brodie Robertson
I'm Leaving Arch Linux For A Better Distro!!
Brodie Robertson
Red Hat Linux Once Featured A REDNECK Translation
Brodie Robertson
Android Authority Doesn't Understand Linux or Android
Brodie Robertson
Switching To Wayland: Why I'm Daily Driving Hyprland
Brodie Robertson
Private Security Patching Is A Nightmare In Open Source
Brodie Robertson
Xorg Vs Wayland Is Just A Technical Detail
Brodie Robertson
Why Did Fedora Linux Drop Its Wacky Release Names?
Brodie Robertson
KDE App Theming On Other Desktops Is A Mess
Brodie Robertson
Xenocara: That X11 Server That Isn't Xorg
Brodie Robertson
PopOS New COSMIC Desktop Has Me Excited Again!
Brodie Robertson
Hilarious GNOME Archive Bug Finally Gets Addressed
Brodie Robertson
Rust Foundation Has A Serious Trademark Problem
Brodie Robertson
Top 5 Best Hyprland Linux Features
Brodie Robertson
Installing Linux Software Is More Confusing Than Ever
Brodie Robertson
Clipboard: Simple Unified Linux Clipping Tool
Brodie Robertson
Solus Linux Returns From The Distro Afterlife
Brodie Robertson
uBlue Linux: Immutable Fedora With Batteries Included
Brodie Robertson
More on: Staying Current in AI
View skill →Related Reads
📰
📰
📰
📰
How Artificial Intelligence Affects Everyday Life
Several years ago, the term "artificial…
Medium · AI
Most Americans don’t want an AI data centre next door. Virginia shows why some say yes
The Next Web AI
Arcee, a US open source AI lab, says Chinese models are not inherently dangerous
TechCrunch AI
Substack’s new tool tells you who’s been writing their newsletters with AI
TechCrunch AI
🎓
Tutor Explanation
DeepCamp AI