Live data from Hacker News

An experimental Android WebView Media Integrity API early next year

android-developers.googleblog.com

41–50 of 247 posts

Re: An experimental Android WebView Media Integrity API early next year

#42
post #10

WEI itself was previously discussed across a number of threads, which make interesting reading: (July 2023, 456 comments) https://news.ycombinator.com/item?id=36854114 - "Google's nightmare Web Integrity API wants a DRM gatekeeper for the web" (July 2023, 431 comments) https://news.ycombinator.com/item?id=36817305 - "Web Environment Integrity API Proposal" (July 2023, 434 comments) https://news.ycombinator.com/item?i…

Oof, that hyper-aggressive whitewashing of the DRM proposal from yoavweiss_ was a harsh lesson in realpolitik. Nerds were bringing good faith arguments to a bad faith optics war and getting slaughtered.

For people wondering which of the links to click: https://news.ycombinator.com/item?id=36857676

It's mostly just the classic "nono if you don't agree it's because you don't understand" and "please educate yourself" approach.

Re: An experimental Android WebView Media Integrity API early next year

#43
post #26

Earlier quoted context omitted.

What does your heart tell you? Palladium[1] came and went and then suddenly most laptops and mobile devices have a built-in TPM today. No doubt history will repeat. [1] https://en.wikipedia.org/wiki/Next-Generation_Secure_Computi...

Uhm… what? Your beef is with things like Pluton, Intel’s ME and AMD’s PSP. TPM at their base are nothing else than a more secure place to store cryptographic data.

Yeah. Intel SGX seems kinda similar and is or at least was used for DRM.

Re: An experimental Android WebView Media Integrity API early next year

#44
post #38

> Android WebView Media Integrity API is narrowly scoped I don't see any benefit to the user... Surely any app which wishes to embed a webview can simply add an api to said webview with native code to use existing android integrity API's? To me, this looks like a backdoor way to prevent people making "hacked" apps which, for example, play youtube but without ads. This API doesn't benefit the users.

It's not intended to benefit the user.

[deleted]

Re: An experimental Android WebView Media Integrity API early next year

#45
post #26

Earlier quoted context omitted.

What does your heart tell you? Palladium[1] came and went and then suddenly most laptops and mobile devices have a built-in TPM today. No doubt history will repeat. [1] https://en.wikipedia.org/wiki/Next-Generation_Secure_Computi...

Uhm… what? Your beef is with things like Pluton, Intel’s ME and AMD’s PSP. TPM at their base are nothing else than a more secure place to store cryptographic data.

Don’t forget that the anti-TPM stuff comes from the guy, RMS, who opposes “sudo” because it serves to let a machine owner control and audit use of super-user commands, whereas just having a root password shared by multiple users gives anyone who learns the password the freedom to do whatever they want with plausible deniability. He has a very strange and quaint way of thinking but people uncritically parrot him without appreciating what his world-view actually entails.

Re: An experimental Android WebView Media Integrity API early next year

#46
post #34
post #26

Earlier quoted context omitted.

Uhm… what? Your beef is with things like Pluton, Intel’s ME and AMD’s PSP. TPM at their base are nothing else than a more secure place to store cryptographic data.

It's a place that applications can store such data without my knowledge or control, and I don't trust applications enough to be comfortable with them having that ability. Don't get me wrong, it's not a major issue for me, it's just uncomfortable. It just means I prefer my machines to not have TPM hardware in them.

I'm not storing my fingerprint anywhere else.

Re: An experimental Android WebView Media Integrity API early next year

#47

Earlier quoted context omitted.

True, but that seriously buried the lede. Sorry for the edit.

I like the edit. That dull blog title would get ZERO traction.

It’s funny how techies complain about clickbait yet celebrate and engage with… clickbait

Re: An experimental Android WebView Media Integrity API early next year

#49
post #42

Earlier quoted context omitted.

Oof, that hyper-aggressive whitewashing of the DRM proposal from yoavweiss_ was a harsh lesson in realpolitik. Nerds were bringing good faith arguments to a bad faith optics war and getting slaughtered.

For people wondering which of the links to click: https://news.ycombinator.com/item?id=36857676 It's mostly just the classic "nono if you don't agree it's because you don't understand" and "please educate yourself" approach.

At least they didn't try, "I don't have time to educate you about why you're bad!"
Post reply on HN