148
submitted 1 year ago by eterps@sopuli.xyz to c/privacy@lemmy.ml
you are viewing a single comment's thread
view the rest of the comments
[-] kenblu24@lemmy.world 88 points 1 year ago* (last edited 1 year ago)

You know captchas? They're there because bot activity can be really hard to moderate. So those are there to test if there's an actual human talking to the website: They try to give a test that only a human can do. The problem is, now that machine learning models can actually do some of those things, like read handwritten words and identify cars vs bikes, we need a new test that only humans can pass. Also, these captchas are annoying to users, and if you're a website that runs off of clicks and ads, a captcha might piss off a user and they leave, and you get to show fewer ads.

So, the people running a website have a need to stave off bot traffic, but also not piss off real, legitimate human traffic. One solution is "attestation", which basically means getting someone else to attest, or plead on your behalf, that you are running on an unmodified device. In a perfect world, Apple would like their phones to be so incredibly locked down that you can only do things that they allow. One of those things would be using an iPhone to do bot stuff. So, since Apple controls what software runs on your iPhone, they can (in theory) prevent you from running bot software. This means that iPhone users would be (in theory) guaranteed safe human traffic. But if you're a website owner, how do you know that the request is actually coming from an iPhone? Simple. Request the device ID from the iPhone, and ask a question that only an iPhone would know the answer to. This is essentially what web attestation is. From the article: "a way that web servers can demand your device prove it is a sufficiently 'legitimate' device before browsing the web" and "your treatment on the web depends on whether Apple says your device, OS & browser configuration are legitimate & acceptable."

This has significant implications for the openness of the device you use, as well as the control that you as a user have over how you use the web. The primary example would be adblockers. Apple and Google get to say whether you're human or not, so if you have an adblocker, Google can just say "no, I won't attest that this user is human" and you'll get treated differently. It's not difficult to imagine a world in which Youtube would just refuse to serve users who aren't 100% trustworthy, given their recent adblocker experiment. And this is the case for every link in the chain, from the device, to the OS, to the browser (and other stuff you might have on your system), and browser extensions. There are concerns that this will hurt competition in all of these spaces. Built your own computer? Well now you might be considered non-legitimate. Developed your own browser? Haha, definitely can't get attested.

tl;dr: Instead of captchas, ask the device if it's real and unmodified. See above for why this is bad.

Also see #why-is-attestation-bad-generally from the article. In summary, be especially concerned if you:

  • Use an adblocker or extensions that Google or Apple might not like
  • Built, repaired, or modified your computer/laptop/phone/smart fridge
  • Use an older, less-supported computer/laptop/phone, or one from a smaller brand/manufacturer
  • Like open-source software
  • Like competition & free market for the hardware/software of computers and phones and browsers
  • Don't like the monopoly of Chrome
  • Don't like Cloudflare or similar services

Worth noting that if all this comes to pass, these people aren't stupid. They will toe the line to make sure not too many people are pissed off. But if you are pissed off, better make noise now, as they almost certainly won't change their minds later.

[-] makingStuffForFun@lemmy.ml 9 points 1 year ago

Brilliant, thank you for this dark information. I appreciate the effort

[-] CarbonIceDragon@pawb.social 5 points 1 year ago

Hypothetically, I wonder if it would be possible to spoof this if you also had an actual unmodified attested device. Something like a device in your home network that would, if you have an iPhone as well as an unattested computer that you actually want to use: get request for attestation from a website, send that request to your iphone instead, as if your iphone had opened the page and was receiving the request (or just have the iphone also try to load the page), intercept the signature the iphone sends to the website, and have your computer send it to the website instead.

this post was submitted on 25 Jul 2023
148 points (96.8% liked)

Privacy

32177 readers
602 users here now

A place to discuss privacy and freedom in the digital world.

Privacy has become a very important issue in modern society, with companies and governments constantly abusing their power, more and more people are waking up to the importance of digital privacy.

In this community everyone is welcome to post links and discuss topics related to privacy.

Some Rules

Related communities

much thanks to @gary_host_laptop for the logo design :)

founded 5 years ago
MODERATORS