Live data from Hacker News

An experimental Android WebView Media Integrity API early next year

android-developers.googleblog.com

31–40 of 247 posts

Re: An experimental Android WebView Media Integrity API early next year

#31
> Android WebView Media Integrity API is narrowly scoped

I don't see any benefit to the user... Surely any app which wishes to embed a webview can simply add an api to said webview with native code to use existing android integrity API's?

To me, this looks like a backdoor way to prevent people making "hacked" apps which, for example, play youtube but without ads. This API doesn't benefit the users.

Re: An experimental Android WebView Media Integrity API early next year

#32

TFA is about more than just WEI, but it does address it directly: > We’ve heard your feedback, and the Web Environment Integrity proposal is no longer being considered by the Chrome team. In contrast, the Android WebView Media Integrity API is narrowly scoped, and only targets WebViews embedded in apps. It simply extends existing functionality on Android devices that have Google Mobile Services (GMS) and there are no…

Hallelujah

Re: An experimental Android WebView Media Integrity API early next year

#33

Earlier quoted context omitted.

True, but that seriously buried the lede. Sorry for the edit.

I like the edit. That dull blog title would get ZERO traction.

Caveat that I'm by no means educated about WEI, the actual title feels a bit Orwellian to me. I just wanted to point out the actual title and not an editorialized one (without commenting on whether editorialization is good or bad here).

Re: An experimental Android WebView Media Integrity API early next year

#34
post #26

Earlier quoted context omitted.

What does your heart tell you? Palladium[1] came and went and then suddenly most laptops and mobile devices have a built-in TPM today. No doubt history will repeat. [1] https://en.wikipedia.org/wiki/Next-Generation_Secure_Computi...

Uhm… what? Your beef is with things like Pluton, Intel’s ME and AMD’s PSP. TPM at their base are nothing else than a more secure place to store cryptographic data.

It's a place that applications can store such data without my knowledge or control, and I don't trust applications enough to be comfortable with them having that ability.

Don't get me wrong, it's not a major issue for me, it's just uncomfortable. It just means I prefer my machines to not have TPM hardware in them.

Re: An experimental Android WebView Media Integrity API early next year

#35

Earlier quoted context omitted.

True, but that seriously buried the lede. Sorry for the edit.

I like the edit. That dull blog title would get ZERO traction.

but if the title is "Increasing trust for embedded media", where's the intent to back off? The changed title implies everybody can stop worrying.

Re: An experimental Android WebView Media Integrity API early next year

#36

The title is misleading. They've dropped the proposal as applied to Chrome, but are still pursuing it for the Android WebView API, which is basically a wrapper around Chrome.

Webviews are particularly vulnerable though, being used for embedded logins for sometimes dubious 3rd party apps.

Is there a reasonable angle to view this from?

I personally don't think embedded webviews should be allowed general browsing capability unless they are part of a standalone browser.

It's usually a trick to capture traffic that would otherwise go off to the open web.

Re: An experimental Android WebView Media Integrity API early next year

#37

TFA is about more than just WEI, but it does address it directly: > We’ve heard your feedback, and the Web Environment Integrity proposal is no longer being considered by the Chrome team. In contrast, the Android WebView Media Integrity API is narrowly scoped, and only targets WebViews embedded in apps. It simply extends existing functionality on Android devices that have Google Mobile Services (GMS) and there are no…

What does your heart tell you? Palladium[1] came and went and then suddenly most laptops and mobile devices have a built-in TPM today. No doubt history will repeat. [1] https://en.wikipedia.org/wiki/Next-Generation_Secure_Computi...

Yes and according to discussions at that time Palladium would be always on, on all PCs and it would banish Linux from all PCs making Windows the some possible OS..

Which is totally what happened, right? /s

Re: An experimental Android WebView Media Integrity API early next year

#38

> Android WebView Media Integrity API is narrowly scoped I don't see any benefit to the user... Surely any app which wishes to embed a webview can simply add an api to said webview with native code to use existing android integrity API's? To me, this looks like a backdoor way to prevent people making "hacked" apps which, for example, play youtube but without ads. This API doesn't benefit the users.

It's not intended to benefit the user.

Re: An experimental Android WebView Media Integrity API early next year

#40
post #34
post #26

Earlier quoted context omitted.

Uhm… what? Your beef is with things like Pluton, Intel’s ME and AMD’s PSP. TPM at their base are nothing else than a more secure place to store cryptographic data.

It's a place that applications can store such data without my knowledge or control, and I don't trust applications enough to be comfortable with them having that ability. Don't get me wrong, it's not a major issue for me, it's just uncomfortable. It just means I prefer my machines to not have TPM hardware in them.

I don't trust applications enough to have things like the encryption key for my hard drive outside a TPM.
Post reply on HN