This might sound silly but assuming you are using firefox or even safari how will this proposal affect these browsers. Only thing I can currently think of is banking sites (on android) would force you to use chrome and check play integrity (safteynet) to block acess.
At the end of the day won’t this only affect people using Google chrome? (Forks of chrome, firefox, safari could by pass the issue)?
Yeah, I just don’t get the point of what Google is doing with all of this. The while point is to require attestation because than you know people are viewing ads. So websites can either “trust” certs issued by Firefox, or not and lose out on ad revenue. I guess Google absence doesn’t have to trust firefoz attestation, but then it is going to payout less and people will seek other providers.
SSL certs provide trust because you ultimately trust the issuing authority, which is supposedly garunteednby world governments. Their are known corrupt actors issuing certs, but ultimately you can be pretty sure that the SSL cert matches the domain you are on, and that it was requested by the owner of that domain. But you can still choose to not visit that domain if you don’t trust it. There are a lot of services that will block its already, so I don’t really get what the point of attestation is.
This might sound silly but assuming you are using firefox or even safari how will this proposal affect these browsers. Only thing I can currently think of is banking sites (on android) would force you to use chrome and check play integrity (safteynet) to block acess.
At the end of the day won’t this only affect people using Google chrome? (Forks of chrome, firefox, safari could by pass the issue)?
Sorry if I seem a bit ignorant
Firefox could always spoof the standard to maintain compatibility.
If it could be spoofed easily, wouldn’t that defeat the point?
I mean you can’t just “spoof” a ssl cert or private ssh key, I have to assume this is at least that good.
Removed by mod
Yeah, I just don’t get the point of what Google is doing with all of this. The while point is to require attestation because than you know people are viewing ads. So websites can either “trust” certs issued by Firefox, or not and lose out on ad revenue. I guess Google absence doesn’t have to trust firefoz attestation, but then it is going to payout less and people will seek other providers.
SSL certs provide trust because you ultimately trust the issuing authority, which is supposedly garunteednby world governments. Their are known corrupt actors issuing certs, but ultimately you can be pretty sure that the SSL cert matches the domain you are on, and that it was requested by the owner of that domain. But you can still choose to not visit that domain if you don’t trust it. There are a lot of services that will block its already, so I don’t really get what the point of attestation is.
Good point.
Mozilla is working on their own v3, without a lot of the restrictions Google has added. I think you can already try out the relevant mode in Firefox.
On Firefox Nightly looks like they have v3 enabled
Yeah. I saw the announcement in the nightly channel couple of days ago. They’re letting extension makers port their add-ons as well in advance.