Conversation

Replying to and
I do call that DRM consistently. I'm using the same standards. I was very put off when I saw that Brave was doing this. Regardless, I suggested a stronger way of doing it without a hard dependency on a Google service to try to be helpful and was basically told to fuck off.
2
I talked about it on Twitter a while ago, which was followed with you folks spreading misinformation about Chromium and Android without Play Services. I took a deeper look into what Brave has been doing in particular with using SafetyNet attestation as a form of advertising DRM.
2
You can whine all you want in my mentions about a couple tweets that I posted retracting my endorsement of Brave while saying I still considered it a better choice than Firefox. You did the opposite of changing my mind about not supporting it. I will actively fight you scumbags.
2
2
Hmm - publicly calling out a project as nefarious absent any evidence / rationale, getting a strong response from project team, then dismissing it as 'whining' and doubling-down on 'scumbags' language all seems very bad faith tbh.
3
1
Replying to and
I gave evidence and rationale. This conversation has been incredibly strong evidence. Calling out someone for being completely dishonest, misrepresenting my arguments and doubling down on ridiculous spin is absolutely called for and I wasn't the one showing up acting that way.
1
1
Appreciated you elaborating on concerns, then asked for clarification of logical inconsistencies and don't see them resolved. Questions still have: * weak or all attestation bad? * 1 or all vendors bad for using attestation? * what model works to provide ad-fraud and privacy?
2
Attestation via verifying up to a trusted root is a weak form of it. It has some genuine use cases, but it's inherently a weak approach and only really serves as a mild barrier to an attacker. Auditor uses it to bootstrap trust but I explicitly document and show that it's weak.
1
I don't think it has much value for security, and I only use it because it's there. If I was implementing the feature from the bottom up in hardware, it's not how I would approach it. The root of trust is primarily for DRM use case for the feature. It's flawed for security uses.
1
I don't care about ad fraud. Advertising is inherently manipulative and abusive. It's the gaslighting industry. I don't see why I should want it to survive. The internet worked fine before it was totally plastered with advertising and commercialized and will work fine without it.
2
5
Companies like the New York Times and Google based on selling advertising space will need to adapt. That's okay. Many industries need to adapt to changing times. There isn't some inherent value in preserving the traditional approach of mass brainwashing as a business model.
4