“Increasing trust for embedded media”
> Otherwise please use the original title, unless it is misleading or linkbait; don't editorialize.
121–130 of 247 posts
“Increasing trust for embedded media”
> Otherwise please use the original title, unless it is misleading or linkbait; don't editorialize.
It’s interesting that a single googlers repository was what was being used for wei discussion instead of something more “official”. People celebrating this aren’t realizing that it’ll probably stop api scraping via a web view back door.
Earlier quoted context omitted.
Great. Really dodged a bullet there.
Not really. More like the entity pointing the gun has now decocked it. The scary part is that there is a single entity with that kind of power to begin with. It's a testament of the failure of the modern web, and how far it has strayed from the original spirit of the internet.
Earlier quoted context omitted.
and it would banish Linux from all PCs making Windows the some possible OS We're getting closer to that with things like "secure" boot. Fortunately that can still be disabled, but MS even required that on ARM platforms it can't. The bigger Linux distros have bent over and gotten MS to sign their bootloaders, essentially making them at the mercy of MS.
I’ve complained about this before, but I’ve been hearing “Microsoft is going to block you from installing Linux!” since like 2004, when it was a reliable way to get an easy “+5 Insightful” on Slashdot. It hasn’t happened, even on Microsoft’s own first-party computers. At this point I think it’s firmly FUD and the people who say it’s coming any second now need to put up the evidence. Microsoft doesn’t seem to care, es…
I think the point, at least for me, is that they shouldn't be taking away any user control for consumer products. And yet that is what we have let them do. Its not going to stop.
> The new Android WebView Media Integrity API will give embedded media providers access to a tailored integrity response that contains a device and app integrity verdict so that they can ensure their streams are running in a safe and trusted environment, regardless of which app store the embedding app was installed from.
But this only applies to the Android WebView API, not standalone web browsers like Google Chrome. Otherwise we'd be back to where we started with the original Web Environment Integrity proposal.
But no one has to use the WebView API, it's a convenient option but Chromium is open source! What stops Bob the Evil Android Developer from compiling his own version of Chromium, bundling that into his app, and doing whatever malevolent website trickery his ink black heart desires?
Put another way, if this is only built into the special WebView API, wouldn't a malicious developer just avoid using that API?
This blog post is how they should have started the discussion about WEI, but better late than never. That being said, while I can somewhat understand the use case for preventing fraud, misconception of source, etc, what we're talking about effectively kneecaps the ability to write bonafide Android browsers that leverage the WebView engine, while doing little to prevent the fraud and abuse the proposal intends to solv…
The proposal doesn't limit the Android WebView in any way.
Probably started working on some more cryptic solution already.
Earlier quoted context omitted.
I like the edit. That dull blog title would get ZERO traction.
It’s funny how techies complain about clickbait yet celebrate and engage with… clickbait
Probably started working on some more cryptic solution already.
I really wish Google would go back to being the champion of the Open Internet I once knew them for and step away from the MBA’ification of everything they keep trying. Seems like the moment they dropped “don’t be evil” they started going there. It’s exhausting.
Instead of celebrating a victory, every one of the Open Internet crowd gets to celebrate a smaller project execution and nothing but a pause in the web platform version of it. Yay.