Live data from Hacker News

An experimental Android WebView Media Integrity API early next year

android-developers.googleblog.com

131–140 of 247 posts

Re: An experimental Android WebView Media Integrity API early next year

#131
post #104
post #38

Earlier quoted context omitted.

It's not intended to benefit the user.

The benefit to the user is they can supposedly "trust" the content that is being shown in the webview is, in fact, owned by or affiliated somehow with the app. They don't give an example, but i'd imagine its something like: "bad app lets user's sign into their bank account through the app's webview, then webview scrapes/intercepts content to do as they wish".

Isn't that something that should be solved at the App Store and/or application fraud detection levels?

I get bad actors exist.

But they're not an excuse to strip everyone else of rights.

>> The Android WebView API lets app developers display web pages which embed media, with increased control over the UI and advanced configuration options to allow a seamless integration in the app. This brings a lot of flexibility, but it can be used as a means for fraud and abuse, because it allows app developers to access web content, and intercept or modify user interactions with it.

This proposal was always a stick of dynamite when a screwdriver was needed.

Start with the assumption that a user client should be able to do whatever the user decides it should. And while keeping that in mind as an absolute, work backwards.

If it creates false ad clicks... tough. Deal with it.

Re: An experimental Android WebView Media Integrity API early next year

#133

Original title: “Increasing trust for embedded media” > Otherwise please use the original title, unless it is misleading or linkbait; don't editorialize. https://news.ycombinator.com/newsguidelines.html

The original title is misleading.

Re: An experimental Android WebView Media Integrity API early next year

#134
post #128
post #3

Probably started working on some more cryptic solution already.

Probably, but I will take this victory. Google has power to make this happen.

> Google has power to make this happen.

they will have more power once current anti-trust trial will be over.

Re: An experimental Android WebView Media Integrity API early next year

#135

Original title: “Increasing trust for embedded media” > Otherwise please use the original title, unless it is misleading or linkbait; don't editorialize. https://news.ycombinator.com/newsguidelines.html

The original title is misleading.

The original title is misleading enough to be incoherent.

Re: An experimental Android WebView Media Integrity API early next year

#136
post #36

The title is misleading. They've dropped the proposal as applied to Chrome, but are still pursuing it for the Android WebView API, which is basically a wrapper around Chrome.

Webviews are particularly vulnerable though, being used for embedded logins for sometimes dubious 3rd party apps. Is there a reasonable angle to view this from? I personally don't think embedded webviews should be allowed general browsing capability unless they are part of a standalone browser. It's usually a trick to capture traffic that would otherwise go off to the open web.

> being used for embedded logins for sometimes dubious 3rd party apps.

That's a difficult problem to solve though. To do it properly you'd need something like Windows' secure key sequence (ctrl-alt-del) which apps can't intercept. Otherwise there's no way that a user can know that what they're seeing is the system rather than a malicious app.

Consider that any app can embed any browser or UI that they want.

Re: An experimental Android WebView Media Integrity API early next year

#137

I don't understand how this works. > The new Android WebView Media Integrity API will give embedded media providers access to a tailored integrity response that contains a device and app integrity verdict so that they can ensure their streams are running in a safe and trusted environment, regardless of which app store the embedding app was installed from. But this only applies to the Android WebView API, not standalo…

All this is about attesting authenticity to the server.

Re: An experimental Android WebView Media Integrity API early next year

#138

I don't understand how this works. > The new Android WebView Media Integrity API will give embedded media providers access to a tailored integrity response that contains a device and app integrity verdict so that they can ensure their streams are running in a safe and trusted environment, regardless of which app store the embedding app was installed from. But this only applies to the Android WebView API, not standalo…

Step 1: Cryptographically fingerprint an attested environment, for one method among alternatives

Step 2: Ban the alternatives

Step 3: Profit

Re: An experimental Android WebView Media Integrity API early next year

#139
post #106
post #10

WEI itself was previously discussed across a number of threads, which make interesting reading: (July 2023, 456 comments) https://news.ycombinator.com/item?id=36854114 - "Google's nightmare Web Integrity API wants a DRM gatekeeper for the web" (July 2023, 431 comments) https://news.ycombinator.com/item?id=36817305 - "Web Environment Integrity API Proposal" (July 2023, 434 comments) https://news.ycombinator.com/item?i…

So we can take that yoavweiss_ character as a Google representative.

This person does not hide the fact that they work for Google (at least that's why take from their about page), so yes, they represent Google. Because if there's anything that was beaten into me in my time at Microsoft, it's that you can put all the "views are my own" in your posts you want, but probably most people that read your post will take you to represent $COMPANY's views no matter the disclaimers.

Re: An experimental Android WebView Media Integrity API early next year

#140
post #42

Earlier quoted context omitted.

For people wondering which of the links to click: https://news.ycombinator.com/item?id=36857676 It's mostly just the classic "nono if you don't agree it's because you don't understand" and "please educate yourself" approach.

> "P.S. I'd love to discuss this with y'all like professional adults. Can we do that?" You can tell somebody is a snake when they aren't from the South but use "y'all" . It's become a sort of corporate snake shibboleth.

Uhhh, what?

I use y'all 'cus that's how all the kids in my school talked growing up.

I ditched a lot of the lexicon because after my family moved to the suburbs, I got made fun of by my new friends, literally calling me "less white". So no more finna', for example.

I will die on the hill of having a good second person plural pronoun though.

Post reply on HN