Live data from Hacker News

An experimental Android WebView Media Integrity API early next year

android-developers.googleblog.com

151–160 of 247 posts

Re: An experimental Android WebView Media Integrity API early next year

#151

Earlier quoted context omitted.

All this is about attesting authenticity to the server .

But only Android WebViews can attest their authenticity. Are servers going to block standalone web browsers? If they are, why even use a WebView? Just make it part of your app.

Many corporate apps in e.g. banking are just Cordova/browser wrappers around a website.

Re: An experimental Android WebView Media Integrity API early next year

#152

Earlier quoted context omitted.

All this is about attesting authenticity to the server .

But only Android WebViews can attest their authenticity. Are servers going to block standalone web browsers? If they are, why even use a WebView? Just make it part of your app.

A lot of "native" apps are just thin wrappers around web components, since it's a lot cheaper to develop.

Re: An experimental Android WebView Media Integrity API early next year

#153
post #104
post #38

Earlier quoted context omitted.

It's not intended to benefit the user.

The benefit to the user is they can supposedly "trust" the content that is being shown in the webview is, in fact, owned by or affiliated somehow with the app. They don't give an example, but i'd imagine its something like: "bad app lets user's sign into their bank account through the app's webview, then webview scrapes/intercepts content to do as they wish".

> The benefit to the user is they can supposedly "trust" the content that is being shown in the webview is, in fact, owned by or affiliated somehow with the app.

You got it backwards. The user gets to trust nothing.

The “trust” in this case is for the server to asses if it a trusted (not hacked/hackable) environment to deploy content to.

DRM is the only use case.

Re: An experimental Android WebView Media Integrity API early next year

#156
post #84

Until next time, for the sake of the open Internet we can't stop pushing back. It's exhausting.

It only took "privacy sandbox" what two, three years too cool off before it was rolled out to everyone? They're a big company, they'll wait you out.

Re: An experimental Android WebView Media Integrity API early next year

#157
post #131
post #104

Earlier quoted context omitted.

The benefit to the user is they can supposedly "trust" the content that is being shown in the webview is, in fact, owned by or affiliated somehow with the app. They don't give an example, but i'd imagine its something like: "bad app lets user's sign into their bank account through the app's webview, then webview scrapes/intercepts content to do as they wish".

Isn't that something that should be solved at the App Store and/or application fraud detection levels? I get bad actors exist. But they're not an excuse to strip everyone else of rights. >> The Android WebView API lets app developers display web pages which embed media, with increased control over the UI and advanced configuration options to allow a seamless integration in the app. This brings a lot of flexibility, b…

And if it drains people’s bank accounts because they aren’t savvy enough to know that their bank’s app is realbank not realbankofficial? Deal with it?

The stance that other people should have their savings stolen, when we could have easily stopped it, because of nebulous freedom reasons is pretty ghoulish.

Re: An experimental Android WebView Media Integrity API early next year

#158
post #140

Earlier quoted context omitted.

> "P.S. I'd love to discuss this with y'all like professional adults. Can we do that?" You can tell somebody is a snake when they aren't from the South but use "y'all" . It's become a sort of corporate snake shibboleth.

Uhhh, what? I use y'all 'cus that's how all the kids in my school talked growing up. I ditched a lot of the lexicon because after my family moved to the suburbs, I got made fun of by my new friends, literally calling me "less white". So no more finna', for example. I will die on the hill of having a good second person plural pronoun though.

"y'all" is a bit fraught in the US because (incorrectly, in my opinion), in some parts the use is associated with certain unflattering cultural stereotypes. Not usually racial ones.

> I will die on the hill of having a good second person plural pronoun though.

I'm with you there -- we really need one, but I haven't found one that is broadly safe to use.

Re: An experimental Android WebView Media Integrity API early next year

#159
post #88

Earlier quoted context omitted.

Sometimes what you're describing is a valid approach-- once a pattern is clear. This is looking pretty reasonable for Google. But it seems like a bit of a toxic, pessimistic response in general. There's other times where a party just screws up. e.g. Apple's CSAM-- once the industry educated them, they took a very different tack. There was no fundamental structural or cultural issue pushing them towards the problemati…

> There's other times where a party just screws up. e.g. Apple's CSAM Did Apple really screw up? Their proposal is pretty much what the EU and UK governments want now :( I think they screwed up because to have my own phone spying on me is unthinkable and I would never have considered another Apple product again. But politics seem to like the idea.

Those governments are mostly coming around as to why that’s a bad idea.

Re: An experimental Android WebView Media Integrity API early next year

#160

Earlier quoted context omitted.

I don't disagree, but how do you feel about you (the machine owner) also not having access to it? That's my major problem with it; it locks you out of messing with your own machine data, which you can see being instantly abused by third parties to prevent modifications.

> That's my major problem with it; it locks you out of messing with your own machine data, which you can see being instantly abused by third parties to prevent modifications. It locks everybody, including the owner, out of any data it doesn't own. That's the point. If you can pull it out, so can anybody else, and you've just made a small hard drive. Could it be used by vendors for DRM-like things? Sure. That's on the…

> That's on the vendor, though, and not the technology itself.

And that's the problem. I have little actual trust of vendors anymore. Too many bridges have been burned to trust by default.

Post reply on HN