Live data from Hacker News

An experimental Android WebView Media Integrity API early next year

android-developers.googleblog.com

111–120 of 247 posts

Re: An experimental Android WebView Media Integrity API early next year

#111
This blog post is how they should have started the discussion about WEI, but better late than never.

That being said, while I can somewhat understand the use case for preventing fraud, misconception of source, etc, what we're talking about effectively kneecaps the ability to write bonafide Android browsers that leverage the WebView engine, while doing little to prevent the fraud and abuse the proposal intends to solve.

If you are an Android browser author, you certainly can ship your own browser engine, unlike on Apple's platforms where that's still prohibited. However, if your motivation for creating that browser is primarily around the user experience or other "over the top" features, building your own browser engine simply because WebView cannot operate as a real web browser to your users, is unfortunate.

Meanwhile, as an app developer who is interested in engaging in fraud, misinformation, or other nefarious things, they _can_ ship their own browser engine to bypass this functionality entirely. Does it add more work? Yes, but if their goals include this bad behavior, why wouldn't they?

Even without all this, assuming that Chrome itself, Firefox nor anyone else will actually implement some kind of "this is definitely not a web view" attestation, the content owner has no choice but to allow that access, since they have no idea if the user agent they are looking at is a legitimate browser or an embedded webview.

Google, there is no way to solve this problem using attestation short of the original WEI proposal, which is bad for users. All you are doing now is muddying the waters and adding _some_ harm instead of _a lot_ of harm.

Re: An experimental Android WebView Media Integrity API early next year

#112
post #42

Earlier quoted context omitted.

For people wondering which of the links to click: https://news.ycombinator.com/item?id=36857676 It's mostly just the classic "nono if you don't agree it's because you don't understand" and "please educate yourself" approach.

> "P.S. I'd love to discuss this with y'all like professional adults. Can we do that?" You can tell somebody is a snake when they aren't from the South but use "y'all" . It's become a sort of corporate snake shibboleth.

Meh, it spreads a lot more broadly than the corporate snake people. And honestly I’ve never heard the corporate snakes use it myself (at least not before the example which you quoted), but I’m sure there are corporate snakes who do.

Re: An experimental Android WebView Media Integrity API early next year

#113

Official confirmation in the WEI public discussion thread: https://groups.google.com/a/chromium.org/g/blink-dev/c/Ux5h_...

Great. Really dodged a bullet there.

Not really. More like the entity pointing the gun has now decocked it.

The scary part is that there is a single entity with that kind of power to begin with. It's a testament of the failure of the modern web, and how far it has strayed from the original spirit of the internet.

Re: An experimental Android WebView Media Integrity API early next year

#115
post #36

Earlier quoted context omitted.

Webviews are particularly vulnerable though, being used for embedded logins for sometimes dubious 3rd party apps. Is there a reasonable angle to view this from? I personally don't think embedded webviews should be allowed general browsing capability unless they are part of a standalone browser. It's usually a trick to capture traffic that would otherwise go off to the open web.

If that's the problem you're trying to solve, disallow embedded ~~logins~~ webviews and do it through a proper browser, same as on a regular computer. The other way seems overkill and smells like foul play to me.

Is Friendly Social Browser maybe a good solution to this problem?

Re: An experimental Android WebView Media Integrity API early next year

#116

Earlier quoted context omitted.

I like the edit. That dull blog title would get ZERO traction.

Caveat that I'm by no means educated about WEI, the actual title feels a bit Orwellian to me. I just wanted to point out the actual title and not an editorialized one (without commenting on whether editorialization is good or bad here).

In case this is all new to you: effectively WEI aimed to bring hardware-based remote attestation to the web for the purposes of allowing servers to refuse service when the device and its software was not approved by the authors of the server.

Now they just want to do it in WebViews, which is ineffectual at best, and still harmful at worst.

Re: An experimental Android WebView Media Integrity API early next year

#117
post #88

Earlier quoted context omitted.

It'll be back, in another form. Pay no attention to specific projects and proposals that are offered and withdrawn. Look at the bigger picture over a longer time-frame and ask; what are the forces acting within and upon an entity? Meadows' leverage points taxonomy can be used analytically as well as instrumentally. What are the values behind misadventures like WEI ? Google want to own your browser and infiltrate as m…

Sometimes what you're describing is a valid approach-- once a pattern is clear. This is looking pretty reasonable for Google. But it seems like a bit of a toxic, pessimistic response in general. There's other times where a party just screws up. e.g. Apple's CSAM-- once the industry educated them, they took a very different tack. There was no fundamental structural or cultural issue pushing them towards the problemati…

> But it seems like a bit of a toxic, pessimistic response in general.

I'm a twisted firestarter, but it's mostly out of a passionately optimistic and generous view of other human beings. Big corporations are not human beings. I think they fail humanity. They have too much power and no accountability. For that I think they deserve all the toxicity and pessimism fitting for what they are.

Re: An experimental Android WebView Media Integrity API early next year

#118
post #42

Earlier quoted context omitted.

For people wondering which of the links to click: https://news.ycombinator.com/item?id=36857676 It's mostly just the classic "nono if you don't agree it's because you don't understand" and "please educate yourself" approach.

> "P.S. I'd love to discuss this with y'all like professional adults. Can we do that?" You can tell somebody is a snake when they aren't from the South but use "y'all" . It's become a sort of corporate snake shibboleth.

I certainly think that a lot but I sure as hell wouldn’t say it. It doesn’t help, that discussion never goes well.

Re: An experimental Android WebView Media Integrity API early next year

#119
post #10

WEI itself was previously discussed across a number of threads, which make interesting reading: (July 2023, 456 comments) https://news.ycombinator.com/item?id=36854114 - "Google's nightmare Web Integrity API wants a DRM gatekeeper for the web" (July 2023, 431 comments) https://news.ycombinator.com/item?id=36817305 - "Web Environment Integrity API Proposal" (July 2023, 434 comments) https://news.ycombinator.com/item?i…

Oof, that hyper-aggressive whitewashing of the DRM proposal from yoavweiss_ was a harsh lesson in realpolitik. Nerds were bringing good faith arguments to a bad faith optics war and getting slaughtered.

I don't think they were. After reading this my view of this person is just a corporate drone. Obviously this proposal is to serve the content owners, not the users, whatever the thoughts behind it are. And yes it may not be intended to block adblockers but it certainly can easily be used for that once it's ubiquitous. Attestation which is basically what this is, always implies a move of some measure of control from the user to the content or service provider. It exists purely because they don't trust the user. There is just no way this would have ended positively.

And why would I go into discussion with Google? They don't own the web and never will. And their business model means they (and their employees) will always be my enemy because their goals are opposite to my own. I can criticise but it doesn't have to be constructive. A "Just NO" is fine too. I would be very happy with a world where Google doesn't exist.

But in this case the nerds won which means the way it was done worked perfectly fine. Perhaps they will have stepped on a few toes at Google but I'm kinda glad to hear that.

Re: An experimental Android WebView Media Integrity API early next year

#120
post #38

> Android WebView Media Integrity API is narrowly scoped I don't see any benefit to the user... Surely any app which wishes to embed a webview can simply add an api to said webview with native code to use existing android integrity API's? To me, this looks like a backdoor way to prevent people making "hacked" apps which, for example, play youtube but without ads. This API doesn't benefit the users.

It's not intended to benefit the user.

DRM schemes, especially when they masquerade as public service, rarely are.
Post reply on HN