this post was submitted on 25 Jul 2023
277 points (100.0% liked)

Technology

37699 readers
368 users here now

A nice place to discuss rumors, happenings, innovations, and challenges in the technology sphere. We also welcome discussions on the intersections of technology and society. If it’s technological news or discussion of technology, it probably belongs here.

Remember the overriding ethos on Beehaw: Be(e) Nice. Each user you encounter here is a person, and should be treated with kindness (even if they’re wrong, or use a Linux distro you don’t like). Personal attacks will not be tolerated.

Subcommunities on Beehaw:


This community's icon was made by Aaron Schneider, under the CC-BY-NC-SA 4.0 license.

founded 2 years ago
MODERATORS
 

Apple has deployed a system called Private Access Tokens that allows web servers to verify if a device is legitimate before granting access. This works by having the browser request a signed token from Apple proving the device is approved. While this currently has limited impact due to Safari's market share, there are concerns that attestation systems restrict competition, user control, and innovation by only approving certain devices and software. Attestation could lead to approved providers tightening rules over time, blocking modified operating systems and browsers. While proponents argue for holdbacks to limit blocking, business pressures may make that infeasible and Google's existing attestation does not do holdbacks. Fundamentally, attestation is seen as anti-competitive by potentially blocking competition between browsers and operating systems on the web.

you are viewing a single comment's thread
view the rest of the comments
[–] nan@lemmy.blahaj.zone 34 points 1 year ago* (last edited 1 year ago) (8 children)

Google mentioned these in their explainer (they don’t like that they’re fully masked): https://github.com/RupertBenWiser/Web-Environment-Integrity/blob/main/explainer.md#privacy-pass--private-access-tokens

Cloudflare explains them more too: https://blog.cloudflare.com/eliminating-captchas-on-iphones-and-macs-using-new-standard/

They are currently going through an IETF standardization: https://datatracker.ietf.org/wg/privacypass/about/

You can also read the architecture. In general I do trust Cloudflare more than Google. I have no doubt shitty sites won’t fall back to a captcha and will instead block access though, with either solution.

[–] dan@upvote.au 30 points 1 year ago (7 children)

In general I do trust Cloudflare more than Google.

A large portion of the internet runs through Cloudflare's network though, so IMO they're just as much of a risk as Google.

[–] fonix232@kbin.social 13 points 1 year ago (6 children)

However unlike Google, CloudFlare doesn't have a history of killing off products just as users begin to adapt to them.

[–] itsAllDigital@feddit.de 8 points 1 year ago

That still however doesn't relieve them. Whether they've killed of less products, IMHO still leaves them at the position that they route MASSIVE amounts of the entire internet.

One point of failure or control is still a big risk, no matter how you turn it

load more comments (5 replies)
load more comments (5 replies)
load more comments (5 replies)