Conversation

The painful reality seems there is no 'best' way. Appreciate fear that normalising strong attestation for ad-views may lead to mandatory rather than optional ad-view by industry even if not Brave. Also appreciate that without attestation fraud wins, content loses.
2
Replying to and
I do call that DRM consistently. I'm using the same standards. I was very put off when I saw that Brave was doing this. Regardless, I suggested a stronger way of doing it without a hard dependency on a Google service to try to be helpful and was basically told to fuck off.
2
I talked about it on Twitter a while ago, which was followed with you folks spreading misinformation about Chromium and Android without Play Services. I took a deeper look into what Brave has been doing in particular with using SafetyNet attestation as a form of advertising DRM.
2
You can whine all you want in my mentions about a couple tweets that I posted retracting my endorsement of Brave while saying I still considered it a better choice than Firefox. You did the opposite of changing my mind about not supporting it. I will actively fight you scumbags.
2
2
Hmm - publicly calling out a project as nefarious absent any evidence / rationale, getting a strong response from project team, then dismissing it as 'whining' and doubling-down on 'scumbags' language all seems very bad faith tbh.
3
1
Replying to and
I gave evidence and rationale. This conversation has been incredibly strong evidence. Calling out someone for being completely dishonest, misrepresenting my arguments and doubling down on ridiculous spin is absolutely called for and I wasn't the one showing up acting that way.
1
1
Appreciated you elaborating on concerns, then asked for clarification of logical inconsistencies and don't see them resolved. Questions still have: * weak or all attestation bad? * 1 or all vendors bad for using attestation? * what model works to provide ad-fraud and privacy?
2
I don't think it has much value for security, and I only use it because it's there. If I was implementing the feature from the bottom up in hardware, it's not how I would approach it. The root of trust is primarily for DRM use case for the feature. It's flawed for security uses.
1
I would be perfectly happy with an attestation implementation without the root of trust. I'd consider that as essentially nothing of value being lost. In my opinion, pairing is far more compelling and deserves to have thought put into improving the API to better support it.
1
Show replies