Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Private Access Tokens are bad too, but they were much more limited in scope based on their design. One of the design elements of WEI in its own words is that some use cases would only work if it could be required for all users. Meanwhile PAT is attestation but the scope is explicitly intended to be for fulfilling the role CAPTCHA does today... optionally. Nothing about extensions like adblock that I am aware of. The point was to put users on proxies at the same level as users on residential IPs.

But is PAT good? Well no. It's bad for similar but ultimately different reasons. But until Chrome adopts it, it's just not scary.

The health of the open web depends on not having different user agents being treated as second-class citizens. Not only that, but locking the internet behind CAPTCHAs and remote attestation to fight bots is bad because it will always be playing favorites to bots like Google's. Today, and in the past, we've already seen what it looks like when the Internet does this. But it's just not going to be an acceptable solution to bots. If the Internet of the future is a hellscape of big corps controlling literally everything that remains with cryptographically enforced adblock, Yes I'd happily see it burn down instead. I don't really care if other people would prefer that to nothing, because to me its a worthless future and a waste.

Attestation is not a real option that's really on the table.



Consider applying for YC's Winter 2026 batch! Applications are open till Nov 10

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: