all 36 comments

sorted by: hot top controversial new old
[–] 71 points 3 years ago (3 children)

Why are we saying “engineers” when we know full well there isn’t a single qualified engineer in there that thinks this bullshit is a good idea?

This is management being management.

  • source
  • hideshow 6 child comments
  • [–] 38 points 3 years ago*

    It's a bad idea to assume everyone in the field is of a similar mindset and philosophy. There are a LOT of people who genuinely want to make the world worse and see things like adblocking as piracy.

    In fact, I've met people who hate the concept of Open Source and want things to be closer to creative fields. They're shortsighted of course, greedy. But the basis doesn't change the outcome. Yes, it's blatantly their desires to "own" a piece of code the same way musicians often own a movie's score and get licensing fees on them that led that path. But they still walked it and they still exist and they're still out there, hoping for the day they get to go against you.

  • source
  • parent
  • [–] 21 points 3 years ago (1 child)

    I dunno, I’ve met a few engineers that fancied themselves as being smarter than everyone else. Their ideas were the only ones that held merit due to their belief that they were ‘enlightened’, so to speak.

    The vast majority I’ve met are normal, well-adjusted human beings that think the ‘smart’ ones are full of it. Specifically, they they can’t seem to see the forest for the trees.

  • source
  • parent
  • hideshow 2 child comments
  • [–] 3 points 3 years ago (2 children)

    But they will still implement it. Does it really matter if they didn't come up with the idea if they are the people that will build it up?

  • source
  • parent
  • hideshow 4 child comments
  • [–] 7 points 3 years ago

    The world collectively decided that just following orders wasn’t excuse for doing something wrong. While this might be quite as cut and dry a situation, it is definitely partially the fault of those who implement this. Engineers aren’t the type of laborers that risk homelessness and suffering when quitting a job typically. They have the privilege of withholding their labor that most Americans don’t. They choose not to exercise it, which leaves two options, indifference, or support, of these implementations.

  • source
  • parent
  • [–] 16 points 3 years ago (1 child)

    So these assh… are going to pay the wasted data from metered connections? they’ll pay me money? they can also guarantee that malware is not spread anymore via ad networks? sure sure.

  • source
  • hideshow 2 child comments
  • [–] 8 points 3 years ago (1 child)

    When a machine gets infected with malware because of drop-in ad content, the ad broker should be liable to the machine owner for $$$.

  • source
  • parent
  • hideshow 2 child comments
  • [+] 13 points 3 years ago (1 child)
  • [–] 31 points 3 years ago (1 child)

    The browser could just refuse to attest if you've got an ad blocker enabled. That's the whole point of this.

  • source
  • parent
  • hideshow 2 child comments
  • [+] 13 points 3 years ago* (last edited 3 years ago) (3 children)
  • [–] 11 points 3 years ago (3 children)

    Actually, they are controlling your graphics driver. If you're using a custom driver you'll fail attestation because you have untrusted code in your kernel and/or browser process. I expect this will also fail if you're using an old driver with known vulnerabilities that allow you to use your own device in unexpected ways.

  • source
  • parent
  • hideshow 6 child comments
  • [+] 3 points 3 years ago (2 children)
  • [–] 3 points 3 years ago (1 child)

    Why can't it? I'm sure Windows allows non-admin processes to get information about active drivers, secure their own memory, and provide attestation that they are secured, provided TPM and secure boot are enabled.

    https://www.microsoft.com/en-us/security/blog/2017/10/23/hardening-the-system-and-maintaining-integrity-with-windows-defender-system-guard/

  • source
  • parent
  • hideshow 2 child comments
  • [+] 0 points 3 years ago (1 child)
  • [–] 2 points 3 years ago (1 child)

    You said "Google isn’t controlling your graphics driver"

  • source
  • parent
  • hideshow 2 child comments
  • [+] 1 point 3 years ago* (1 child)
  • The technology is useless if you can pass an integrity check just by running as admin. The point is that Google has control over what the process is doing and knows if you're tampering with it. I guess nothing would stop you from making a device's that uses the hdcp osd support to draw black boxes over ads you find using accessibility information, but if you're able to modify the page through extensions or developer tools or memory manipulation, then you're able to make automated API calls, and preventing that is supposedly the whole point of this system.

    The reason for using an external device to overlay data on the video signal is that there is a browser API for tracking occlusion. It's supposed to be used for things like disabling animations of elements that are not visible, but could be unethically used for things like making you pay extra to listen to videos if you don't have an extra display to put them on.

    I don't know why you think secure computing doesn't relate to driver control. Drivers run with special privileges and can modify protected memory. This is why people write root kits, and detecting those root kits is one of the primary motivations behind secure computing.

  • source
  • parent
  • [+] 1 point 3 years ago (2 children)
  • [–] 1 point 3 years ago

    It's still very much a thing and works fairly well to protect high quality DRM content. People forgot it's a thing because a regular person is rarely in a situation where it would prevent them from doing something.

  • source
  • parent
  • [–] 8 points 3 years ago

    The major point is not so much whether your browser could block ads - your point regarding the browser ultimately having to render each element is true. The problem is that if the web server gets a request from an unattested browser (such as an old version, or one that has an ad blocker installed), it will refuse to serve any content, not just ads.

    Regular people will inevitably get frustrated and we end up in scenarios like "is bad, it doesn't work with " because of this proposal, and more and more people end up switching until you have to use a compliant (Chromium-based) browser to do anything at all on the internet, and Google's strangehold on web standards solidifies even further.

  • source
  • parent
  • [–] 12 points 3 years ago

    Louis posted a video on a much bigger problem that Google has with ads. These campaigns seem to completely neglect.

    https://youtu.be/hWJrsz_cmas

    In short: it's fake views. That's were advertisers pay for viewed ads, but the view happened to a bot. Ad block at least doesn't discourage advertisers since they don't pay for unviewed ads.

  • source
  • [–] 10 points 3 years ago (1 child)

    Technical explainer:
    https://github.com/RupertBenWiser/Web-Environment-Integrity/blob/main/explainer.md#how-it-works

    It apparently requires some kind of proprietary operating environment to function, thus making it compatible with free (as in freedom) computing. You would need either a proprietary library/OS or an open OS but a proprietary piece of vendor hardware to act as the attester.

  • source
  • hideshow 2 child comments
  • [–] 9 points 3 years ago

    It's been evident big tech wants their own corporate intranet of sorts. Perhaps we're seeing the beginnings of a great net split. That's if there's enough movement to forge on with a free (as in libre) standards regardless of what big tech is doing on their own.

  • source
  • [–] 2 points 3 years ago

    I'll just use AI to filter out ads in future. Too bad advertisement needs to be recognizable, so AI can.

  • source