The much maligned "Trusted Computing" idea requires that the party you are supposed to trust deserves to be trusted, and Google is DEFINITELY NOT worthy of being trusted, this is a naked power grab to destroy the open web for Google's ad profits no matter the consequences, this would put heavy surveillance in Google's hands, this would eliminate ad-blocking, this would break any and all accessibility features, this would obliterate any competing platform, this is very much opposed to what the web is.
Note of amusement: The GitHub issues tracker for that proposal got swamped with tickets either mocking this crap or denouncing it for what it is, this morning the person who seems to be the head of the project closed all those tickets and published this blog post, in essence saying "Shut up with your ethical considerations, give us a hand in putting up this electric fence around the web". Of course that didn't stop it.
Currently, attestation and "trusted computing" are already a thing, the main "sources of trust" are:
Microsoft
Apple
Smartphone manufacturers
Google
Third party attestators
This is already going on, you need a Microsoft signed stub to boot anything other than Windows on a PC, you need Apple's blessing to boot anything on a Mac, your smartphone manufacturer decides whether you can unlock it and lose attestation, all of Microsoft, Apple and Google run app attestation through their app stores, several governments and companies run attestation software on their company hardware, and so on.
This is the next logical step, to add "web app" attestation, since the previous ones had barely any pushback, and even fanboys of walled gardens cheering them up.
PS: Somewhat ironically, Google's Play Store attestation is one of the weaker ones, just look at Apple's and the list of stuff they collect from the user's device to "attest" it for any app.
You are logged out, please log in or sign up for an account.
To verify your identity, please enter your phone number, a text message will be sent, please enter verification code.
Error, your account has been flagged for further review, please submit 3 different government IDs, with at least 2 containing your photo, and 2 containing your address.
Error, name doesn't match, if you have changed you name, please submit proof of name change.
Error, no citizenship status detected, please submit birth certificate or naturalization certificate
Please wait 7-14 bussiness days. A phone call will be made to the number you've submitted.
Error, missed call. Please wait 30 days for another call.
Error, unsupported operating system, please use Chrome OS, Android, or Google Smart TV OS
Error, Google Smart Home assistant not installed, please purchase one within the next 3 days to avoid losing signup process.
Error, could not confirm identity, please purchase Google 360 cameras to verify identity.
Error, server maintenance in progress, please retry signup at a later time.
The number of people protesting against them in their "Issues" page is amazing. The devs have now blocked the creation of new issue tickets or of comments in existing ones.
It's funny how in the "explainer" they present this as something done for the "user", when it's clearly not developed for the "user". I wouldn't accept something like this even if it was developed by some government – even less by Google.
I have just reported their repository to GitHub as malware, as an act of protest, since they closed the possibility of submitting issues or commenting.
Ad blockers are my best disability accommodation. The things they do with ads to capture attention f with my brain. I'm really going to struggle if this happens. And I'm dependent on the internet for so many things, from groceries to prescriptions to people.
This is a total affront to the ethos of the web and everyone involved in drafting this awful proposal should be publicly shamed. Stick sandwich boards on each of them saying "I tried to build the Torment Nexus", chain them together and march them through the streets while ringing a bell and chanting "shame".
This is so silly. There is no technical solution to trust. What if Russia or China want to run a bit farm? Or the US goverbment? Are you not going to trust their signatures, and face legal action i their markets? This stuff is so stupid, just be honest that you want people to watch your ads. Than we can all refuse and move on with our lives.
OTOH, this will create a massive "in" group, and a much smaller "out" group. It almost formalizes the Indie Web, which would take us back to the early 90's, but with better bandwidth. I'd be into that.
I just had to change my domain name because Google wouldn't stop blocking my personal server webpage for being a "phishing" website, there was no way it could be interpreted in that way at all and it didn't matter, my personal server apps were basically blocked on 80% of browsers.
Alright, I'm kinda slow today, so tell me if I got it right: We, the users, will be "kindly asked" to get one thingamabob signature/identifier of "integrity", so websites "know" whether we're good or bad guys?
Ugh. DRM. I freaking hate DRM. I "buy" a book from Amazon and it's all DRMed. I like the Kindle app so I keep buying there. But when I can I buy physical books at a LBS