Post #1579860
2026-04-17 02:25 UTC
I've seen a lot of people saying how this will be unenforceable and so isn't something we need to worry about.
Except this could be enforced. Google came out with a proposal a few years ago for a method of validating the a request came from a "trusted" (aka, signed and with secure boot enabled OS), ostensibly to combat bot traffic. They dropped it after push back, but it still provides a blueprint for how this could be enforced.
https://github.com/explainers-by-googlers/Web-Environment-Integrity
If web platforms are mandated by law to enforce something like this then the web could be effectively restricted to only approved operating systems. There could still be a dark web, but with the weight of the law behind it, once anything gained momentum access to it could be shut down at the service provider layer.
This shouldn't be dismissed as a threat because it's "unenforceable", because it is.
Replies (1)
-
@ohshit604@sh.itjust.works 2026-04-17 02:39
I mean… What’s easier, implementing an unpopular APi into your already production ready service or blacklisting a country from making requests to your reverse proxy? Personally I would choose the latter. Enough blowback from people will likely get this overturned. EU has dumped similar legislation out however, they recently have had a poor streak in regards to legislation involving digital privacy.