Live data from Hacker News

An experimental Android WebView Media Integrity API early next year

android-developers.googleblog.com

121–130 of 247 posts

Re: An experimental Android WebView Media Integrity API early next year

#122

It’s interesting that a single googlers repository was what was being used for wei discussion instead of something more “official”. People celebrating this aren’t realizing that it’ll probably stop api scraping via a web view back door.

This way, they can hide it in another repo later

Re: An experimental Android WebView Media Integrity API early next year

#123
post #113

Earlier quoted context omitted.

Great. Really dodged a bullet there.

Not really. More like the entity pointing the gun has now decocked it. The scary part is that there is a single entity with that kind of power to begin with. It's a testament of the failure of the modern web, and how far it has strayed from the original spirit of the internet.

This is the point. Let’s celebrate a reduced scope implentation on a more limited number of platforms until we perfect the technology? No. Not really a victory. Just a pause.

Re: An experimental Android WebView Media Integrity API early next year

#124

Earlier quoted context omitted.

and it would banish Linux from all PCs making Windows the some possible OS We're getting closer to that with things like "secure" boot. Fortunately that can still be disabled, but MS even required that on ARM platforms it can't. The bigger Linux distros have bent over and gotten MS to sign their bootloaders, essentially making them at the mercy of MS.

I’ve complained about this before, but I’ve been hearing “Microsoft is going to block you from installing Linux!” since like 2004, when it was a reliable way to get an easy “+5 Insightful” on Slashdot. It hasn’t happened, even on Microsoft’s own first-party computers. At this point I think it’s firmly FUD and the people who say it’s coming any second now need to put up the evidence. Microsoft doesn’t seem to care, es…

If you keep track of the changes to the BIOS firmware, you can see the changes. Their minuscule but happening. We don't have full blow preventing from disabling secure boot yet, but it appears to me that's were this is going. (Disabling usb ports, having keys that prevent disabling Secure boot unless you clear them or change them. All it takes is some event to bring these companies over the edge. The Asus MB development relies totally on Microsoft's decisions about this.

I think the point, at least for me, is that they shouldn't be taking away any user control for consumer products. And yet that is what we have let them do. Its not going to stop.

Re: An experimental Android WebView Media Integrity API early next year

#126
I don't understand how this works.

> The new Android WebView Media Integrity API will give embedded media providers access to a tailored integrity response that contains a device and app integrity verdict so that they can ensure their streams are running in a safe and trusted environment, regardless of which app store the embedding app was installed from.

But this only applies to the Android WebView API, not standalone web browsers like Google Chrome. Otherwise we'd be back to where we started with the original Web Environment Integrity proposal.

But no one has to use the WebView API, it's a convenient option but Chromium is open source! What stops Bob the Evil Android Developer from compiling his own version of Chromium, bundling that into his app, and doing whatever malevolent website trickery his ink black heart desires?

Put another way, if this is only built into the special WebView API, wouldn't a malicious developer just avoid using that API?

Re: An experimental Android WebView Media Integrity API early next year

#127

This blog post is how they should have started the discussion about WEI, but better late than never. That being said, while I can somewhat understand the use case for preventing fraud, misconception of source, etc, what we're talking about effectively kneecaps the ability to write bonafide Android browsers that leverage the WebView engine, while doing little to prevent the fraud and abuse the proposal intends to solv…

Sure, malware can ship its own browser engine but it can not attest authenticity to the server.

The proposal doesn't limit the Android WebView in any way.

Re: An experimental Android WebView Media Integrity API early next year

#129

Earlier quoted context omitted.

I like the edit. That dull blog title would get ZERO traction.

It’s funny how techies complain about clickbait yet celebrate and engage with… clickbait

I don't think you know what clickbait is, because "accurate description of the main content" is not clickbait.

Re: An experimental Android WebView Media Integrity API early next year

#130
post #3

Probably started working on some more cryptic solution already.

I mean this is the problem with the entire situation. I immediately read the article looking for any evidence that they would abandon the direction of the idea rather than do what Google does sometimes and roll out a POC on some other less controversial part of their infrastructure and then come back to it when the timing is more right (like after a large cybersecurity event happens, mark these words). They did exactly that. They rolled it back to the Android team and promised to perfect a smaller effort in a less controversial sandbox but rest assured they are publicly saying only that they are retiring the effort for the web for now.

I really wish Google would go back to being the champion of the Open Internet I once knew them for and step away from the MBA’ification of everything they keep trying. Seems like the moment they dropped “don’t be evil” they started going there. It’s exhausting.

Instead of celebrating a victory, every one of the Open Internet crowd gets to celebrate a smaller project execution and nothing but a pause in the web platform version of it. Yay.

Post reply on HN