Apple has deployed a system called Private Access Tokens that allows web servers to verify if a device is legitimate before granting access. This works by having the browser request a signed token from Apple proving the device is approved. While this currently has limited impact due to Safari’s market share, there are concerns that attestation systems restrict competition, user control, and innovation by only approving certain devices and software. Attestation could lead to approved providers tightening rules over time, blocking modified operating systems and browsers. While proponents argue for holdbacks to limit blocking, business pressures may make that infeasible and Google’s existing attestation does not do holdbacks. Fundamentally, attestation is seen as anti-competitive by potentially blocking competition between browsers and operating systems on the web.

  • Quokka
    link
    fedilink
    121 year ago

    Who the fuck goes into a bank in this day and age?

    Shit most branches I see are closing down.

    • @[email protected]
      link
      fedilink
      41 year ago

      This is true. However, I don’t see this happening as the website/browser isn’t really the problem with online banking, it’s more often the user.

      On another note, how about no access at all, because this is a freaking huge attack surface for (D)DOS. Imagine you just invalidate signatures of all traffic to and from an attestation service. You could almost stop countries from functioning. That’s a serious vulnerability which we can easily do without.

    • TehPers
      link
      fedilink
      English
      31 year ago

      I rarely do, but when I do it’s for something a bit specific, like ordering/depositing foreign currency (for travel) or depositing large checks that exceed the online deposit limit (which again is extremely rare). For everything else, it’s online only, especially since every time I go in, there’s only one teller working and the line is super long.