This is a credible proposal for DRM for websites in general. It would enable unbeatable adblock-blocking. It would prevent user customization for not just convenience but also accessibility.

I do not say this lightly: Enabling the forfeiture of control over the browsing experience is a fundamentally evil idea that must be rejected now, as it has been in the past, and we must remain vigilant against its reemergence in the future.

https://github.com/RupertBenWiser/Web-Environment-Integrity/blob/main/explainer.md

Web-Environment-Integrity/explainer.md at main · RupertBenWiser/Web-Environment-Integrity

Contribute to RupertBenWiser/Web-Environment-Integrity development by creating an account on GitHub.

GitHub
@gsderp Jeeez. And I was worried about DNS over HTTPS or TLS, this is a whole other level of horrific.
@noxypaws DOH/DOT is dual-use, attestation is not. DOH/DOT is an unequivocal good when it enforces the free choice/consent of a device user-owner to control what resolver is used, and to enforce privacy in that use, (against/over the interests of a network-path interloper,) which is essential for further privacy improvements like ECH to be meaningful. In contrast, the fundamental purpose of attestation is to subvert a device owner-user’s ability to enforce their consent and exercise meaningful control over the what their device does, which is indefensibly evil.

@gsderp Yah, agreed on all points. DOH/DOT is a double edged sword but seems mostly good - I just think a lot about how my LG TV, for example, could start evading DNS based ad blocking.

But yeah this attestation crap sounds just deeply awful.

@noxypaws The problem with the TV falls squarely under the umbrella of eroded owner-user rights. (Well, at the edge where they just flat out don’t exist any more.) DOH/DOT being available for use by your browser doesn’t enable a shit TV to do anything it couldn’t already have done. At most, DOH/DOT being an off-the-shelf standard means a substantial reduction in the work they would need to do to implement their own secured host resolution.