▲ 274 ▼ Google engineers want to make ad-blocking (near) impossible (stackdiary.com) submitted 3 years ago by seasonone@opidea.xyz to c/technology@lemmy.ml 32 comments fedilink hide all child comments
[+] kadu@lemmy.world 3 points 3 years ago (2 children) [deleted] permalink fedilink source parent hideshow 4 child comments replies: [–] maynarkh@feddit.nl 6 points 3 years ago (1 child) Your TPM unit in the motherboard has more privileges than you do. It attests to the integrity of the kernel, graphics driver included, and the kernel attests to the integrity of the browser and any peripherals. permalink fedilink source parent hideshow 2 child comments replies: [+] kadu@lemmy.world 1 point 3 years ago [deleted] permalink fedilink source parent [–] i_am_not_a_robot@discuss.tchncs.de 3 points 3 years ago (1 child) Why can't it? I'm sure Windows allows non-admin processes to get information about active drivers, secure their own memory, and provide attestation that they are secured, provided TPM and secure boot are enabled. https://www.microsoft.com/en-us/security/blog/2017/10/23/hardening-the-system-and-maintaining-integrity-with-windows-defender-system-guard/ permalink fedilink source parent hideshow 2 child comments replies: [+] kadu@lemmy.world 0 points 3 years ago (1 child) [deleted] permalink fedilink source parent hideshow 2 child comments replies: [–] i_am_not_a_robot@discuss.tchncs.de 2 points 3 years ago (1 child) You said "Google isn’t controlling your graphics driver" permalink fedilink source parent hideshow 2 child comments replies: [+] kadu@lemmy.world 1 point 3 years ago* (1 child) [deleted] permalink fedilink source parent hideshow 2 child comments replies: [–] i_am_not_a_robot@discuss.tchncs.de 2 points 3 years ago The technology is useless if you can pass an integrity check just by running as admin. The point is that Google has control over what the process is doing and knows if you're tampering with it. I guess nothing would stop you from making a device's that uses the hdcp osd support to draw black boxes over ads you find using accessibility information, but if you're able to modify the page through extensions or developer tools or memory manipulation, then you're able to make automated API calls, and preventing that is supposedly the whole point of this system. The reason for using an external device to overlay data on the video signal is that there is a browser API for tracking occlusion. It's supposed to be used for things like disabling animations of elements that are not visible, but could be unethically used for things like making you pay extra to listen to videos if you don't have an extra display to put them on. I don't know why you think secure computing doesn't relate to driver control. Drivers run with special privileges and can modify protected memory. This is why people write root kits, and detecting those root kits is one of the primary motivations behind secure computing. permalink fedilink source parent
[–] maynarkh@feddit.nl 6 points 3 years ago (1 child) Your TPM unit in the motherboard has more privileges than you do. It attests to the integrity of the kernel, graphics driver included, and the kernel attests to the integrity of the browser and any peripherals. permalink fedilink source parent hideshow 2 child comments replies: [+] kadu@lemmy.world 1 point 3 years ago [deleted] permalink fedilink source parent
[–] i_am_not_a_robot@discuss.tchncs.de 3 points 3 years ago (1 child) Why can't it? I'm sure Windows allows non-admin processes to get information about active drivers, secure their own memory, and provide attestation that they are secured, provided TPM and secure boot are enabled. https://www.microsoft.com/en-us/security/blog/2017/10/23/hardening-the-system-and-maintaining-integrity-with-windows-defender-system-guard/ permalink fedilink source parent hideshow 2 child comments replies: [+] kadu@lemmy.world 0 points 3 years ago (1 child) [deleted] permalink fedilink source parent hideshow 2 child comments replies: [–] i_am_not_a_robot@discuss.tchncs.de 2 points 3 years ago (1 child) You said "Google isn’t controlling your graphics driver" permalink fedilink source parent hideshow 2 child comments replies: [+] kadu@lemmy.world 1 point 3 years ago* (1 child) [deleted] permalink fedilink source parent hideshow 2 child comments replies: [–] i_am_not_a_robot@discuss.tchncs.de 2 points 3 years ago The technology is useless if you can pass an integrity check just by running as admin. The point is that Google has control over what the process is doing and knows if you're tampering with it. I guess nothing would stop you from making a device's that uses the hdcp osd support to draw black boxes over ads you find using accessibility information, but if you're able to modify the page through extensions or developer tools or memory manipulation, then you're able to make automated API calls, and preventing that is supposedly the whole point of this system. The reason for using an external device to overlay data on the video signal is that there is a browser API for tracking occlusion. It's supposed to be used for things like disabling animations of elements that are not visible, but could be unethically used for things like making you pay extra to listen to videos if you don't have an extra display to put them on. I don't know why you think secure computing doesn't relate to driver control. Drivers run with special privileges and can modify protected memory. This is why people write root kits, and detecting those root kits is one of the primary motivations behind secure computing. permalink fedilink source parent
[+] kadu@lemmy.world 0 points 3 years ago (1 child) [deleted] permalink fedilink source parent hideshow 2 child comments replies: [–] i_am_not_a_robot@discuss.tchncs.de 2 points 3 years ago (1 child) You said "Google isn’t controlling your graphics driver" permalink fedilink source parent hideshow 2 child comments replies: [+] kadu@lemmy.world 1 point 3 years ago* (1 child) [deleted] permalink fedilink source parent hideshow 2 child comments replies: [–] i_am_not_a_robot@discuss.tchncs.de 2 points 3 years ago The technology is useless if you can pass an integrity check just by running as admin. The point is that Google has control over what the process is doing and knows if you're tampering with it. I guess nothing would stop you from making a device's that uses the hdcp osd support to draw black boxes over ads you find using accessibility information, but if you're able to modify the page through extensions or developer tools or memory manipulation, then you're able to make automated API calls, and preventing that is supposedly the whole point of this system. The reason for using an external device to overlay data on the video signal is that there is a browser API for tracking occlusion. It's supposed to be used for things like disabling animations of elements that are not visible, but could be unethically used for things like making you pay extra to listen to videos if you don't have an extra display to put them on. I don't know why you think secure computing doesn't relate to driver control. Drivers run with special privileges and can modify protected memory. This is why people write root kits, and detecting those root kits is one of the primary motivations behind secure computing. permalink fedilink source parent
[–] i_am_not_a_robot@discuss.tchncs.de 2 points 3 years ago (1 child) You said "Google isn’t controlling your graphics driver" permalink fedilink source parent hideshow 2 child comments replies: [+] kadu@lemmy.world 1 point 3 years ago* (1 child) [deleted] permalink fedilink source parent hideshow 2 child comments replies: [–] i_am_not_a_robot@discuss.tchncs.de 2 points 3 years ago The technology is useless if you can pass an integrity check just by running as admin. The point is that Google has control over what the process is doing and knows if you're tampering with it. I guess nothing would stop you from making a device's that uses the hdcp osd support to draw black boxes over ads you find using accessibility information, but if you're able to modify the page through extensions or developer tools or memory manipulation, then you're able to make automated API calls, and preventing that is supposedly the whole point of this system. The reason for using an external device to overlay data on the video signal is that there is a browser API for tracking occlusion. It's supposed to be used for things like disabling animations of elements that are not visible, but could be unethically used for things like making you pay extra to listen to videos if you don't have an extra display to put them on. I don't know why you think secure computing doesn't relate to driver control. Drivers run with special privileges and can modify protected memory. This is why people write root kits, and detecting those root kits is one of the primary motivations behind secure computing. permalink fedilink source parent
[+] kadu@lemmy.world 1 point 3 years ago* (1 child) [deleted] permalink fedilink source parent hideshow 2 child comments replies: [–] i_am_not_a_robot@discuss.tchncs.de 2 points 3 years ago The technology is useless if you can pass an integrity check just by running as admin. The point is that Google has control over what the process is doing and knows if you're tampering with it. I guess nothing would stop you from making a device's that uses the hdcp osd support to draw black boxes over ads you find using accessibility information, but if you're able to modify the page through extensions or developer tools or memory manipulation, then you're able to make automated API calls, and preventing that is supposedly the whole point of this system. The reason for using an external device to overlay data on the video signal is that there is a browser API for tracking occlusion. It's supposed to be used for things like disabling animations of elements that are not visible, but could be unethically used for things like making you pay extra to listen to videos if you don't have an extra display to put them on. I don't know why you think secure computing doesn't relate to driver control. Drivers run with special privileges and can modify protected memory. This is why people write root kits, and detecting those root kits is one of the primary motivations behind secure computing. permalink fedilink source parent
[–] i_am_not_a_robot@discuss.tchncs.de 2 points 3 years ago The technology is useless if you can pass an integrity check just by running as admin. The point is that Google has control over what the process is doing and knows if you're tampering with it. I guess nothing would stop you from making a device's that uses the hdcp osd support to draw black boxes over ads you find using accessibility information, but if you're able to modify the page through extensions or developer tools or memory manipulation, then you're able to make automated API calls, and preventing that is supposedly the whole point of this system. The reason for using an external device to overlay data on the video signal is that there is a browser API for tracking occlusion. It's supposed to be used for things like disabling animations of elements that are not visible, but could be unethically used for things like making you pay extra to listen to videos if you don't have an extra display to put them on. I don't know why you think secure computing doesn't relate to driver control. Drivers run with special privileges and can modify protected memory. This is why people write root kits, and detecting those root kits is one of the primary motivations behind secure computing. permalink fedilink source parent