And since you won’t be able to modify web pages, it will also mean the end of customization, either for looks (ie. DarkReader, Stylus), conveniance (ie. Tampermonkey) or accessibility.

The community feedback is… interesting to say the least.

  • AraozuBanned
    link
    fedilink
    English
    arrow-up
    9
    ·
    2 years ago

    Wouldn’t spoofing work? Like, if the browser just sends “yes, no extensions, adblock, blah blah” then how would the attestation server know if that’s true? Or does it require signed binaries, or some special hardware?

    • vvvvv
      link
      fedilink
      English
      arrow-up
      14
      ·
      2 years ago

      That is conveniently left out of the speck. Attestation server may require signed binary on a client system, it may require whatever it wants really, because why not? It’s a website who decides to trust attestation server or not.

    • count_duckula@discuss.tchncs.de
      link
      fedilink
      English
      arrow-up
      7
      ·
      2 years ago

      Depends on if they used cryptographic signatures. Those would be impossible to spoof because any change in the client would change the hash completely.

      • AraozuBanned
        link
        fedilink
        English
        arrow-up
        16
        ·
        2 years ago

        Google silently shipping signed chrome executables soon…

        And then people wonder why non chromium browsers are important