Live data from Hacker News

An experimental Android WebView Media Integrity API early next year

android-developers.googleblog.com

161–170 of 247 posts

Re: An experimental Android WebView Media Integrity API early next year

#161

Earlier quoted context omitted.

But only Android WebViews can attest their authenticity. Are servers going to block standalone web browsers? If they are, why even use a WebView? Just make it part of your app.

A lot of "native" apps are just thin wrappers around web components, since it's a lot cheaper to develop.

Okay, thanks. So then this truly doesn't affect websites at all, it's for apps which work like websites behind the scenes, but whose content no one is ever supposed to access from within a web browser anyway.

I can live with that!

Re: An experimental Android WebView Media Integrity API early next year

#162
post #104

Earlier quoted context omitted.

The benefit to the user is they can supposedly "trust" the content that is being shown in the webview is, in fact, owned by or affiliated somehow with the app. They don't give an example, but i'd imagine its something like: "bad app lets user's sign into their bank account through the app's webview, then webview scrapes/intercepts content to do as they wish".

> The benefit to the user is they can supposedly "trust" the content that is being shown in the webview is, in fact, owned by or affiliated somehow with the app. You got it backwards. The user gets to trust nothing. The “trust” in this case is for the server to asses if it a trusted (not hacked/hackable) environment to deploy content to. DRM is the only use case.

This is incorrect. If Chase uses attestation then only the Chase app can access their login site. It prevents DefinitelyChaseAndNotMalware from masquerading as Chase.

Re: An experimental Android WebView Media Integrity API early next year

#163
post #74

> Android WebView Media Integrity API is narrowly scoped I don't see any benefit to the user... Surely any app which wishes to embed a webview can simply add an api to said webview with native code to use existing android integrity API's? To me, this looks like a backdoor way to prevent people making "hacked" apps which, for example, play youtube but without ads. This API doesn't benefit the users.

> To me, this looks like a backdoor way to prevent people making "hacked" apps which, for example, play youtube but without ads. More like "impersonate your bank and steal your login credentials". MitM attacks using interposed clients are a genuine threat outside the Apple and Google walled gardens (and even a little bit within). WEI was an attempt at solving a real problem. Now, maybe it had unacceptable side effect…

You’re being downvoted at the moment, but this is absolutely true. Fake bank apps are a huge problem, which this addresses.

Re: An experimental Android WebView Media Integrity API early next year

#164
post #157
post #131

Earlier quoted context omitted.

Isn't that something that should be solved at the App Store and/or application fraud detection levels? I get bad actors exist. But they're not an excuse to strip everyone else of rights. >> The Android WebView API lets app developers display web pages which embed media, with increased control over the UI and advanced configuration options to allow a seamless integration in the app. This brings a lot of flexibility, b…

And if it drains people’s bank accounts because they aren’t savvy enough to know that their bank’s app is realbank not realbankofficial? Deal with it? The stance that other people should have their savings stolen, when we could have easily stopped it, because of nebulous freedom reasons is pretty ghoulish.

Perhaps the solution is to have two classes of machines, some "safe" for those who don't want to (or can't) be proactive and alert to security threats, and some "unsafe" for those who want total control over their machines and are willing to take on the security risks and responsibilities to do that.

Re: An experimental Android WebView Media Integrity API early next year

#165

Earlier quoted context omitted.

Oof, that hyper-aggressive whitewashing of the DRM proposal from yoavweiss_ was a harsh lesson in realpolitik. Nerds were bringing good faith arguments to a bad faith optics war and getting slaughtered.

I don't think they were. After reading this my view of this person is just a corporate drone. Obviously this proposal is to serve the content owners, not the users, whatever the thoughts behind it are. And yes it may not be intended to block adblockers but it certainly can easily be used for that once it's ubiquitous. Attestation which is basically what this is, always implies a move of some measure of control from t…

Even more simply: let's not get dragged into debating the technical merits of something which is philosophically wrong. That particular person was trying really hard to reframe the whole argument into terms that would work in Google's favor -- if we just pointed out what was technically wrong with the proposal, why, they'd just fix those things and then we'd be good to go. But, it was philosophically wrong, because we've all understood the web to be fundamentally open and anonymous and not controlled by any one entity [1] for decades and most of us want it to stay that way. Even if WEI was technically sound, it would still be an enormous erosion of the principles of an open, anonymous, decentralized web. Any attempt to argue against WEI on its technical merits alone was just allowing Google to drag the whole fight into favorable territory.

> And why would I go into discussion with Google? They don't own the web and never will.

Oh, I think this is a big mistake. Google very nearly does own the web. Gmail handles, at last estimates, between 45% and 60% of email traffic, depending on who you talk to. Chrome or Chromium gets somewhere around 65% of the global browser market. Google gets around 90% of search traffic. Google ads. Google domains. YouTube. Google Cloud, which WPEngine for example runs on. Google Docs. Chromebooks. Android.

I really need more people to pause and reflect for a moment on just how much of the internet is currently owned by Google.

[1]: Well, ignoring ICANN, or Microsoft, or Google, or Cisco, or...

Re: An experimental Android WebView Media Integrity API early next year

#166
post #157
post #131

Earlier quoted context omitted.

Isn't that something that should be solved at the App Store and/or application fraud detection levels? I get bad actors exist. But they're not an excuse to strip everyone else of rights. >> The Android WebView API lets app developers display web pages which embed media, with increased control over the UI and advanced configuration options to allow a seamless integration in the app. This brings a lot of flexibility, b…

And if it drains people’s bank accounts because they aren’t savvy enough to know that their bank’s app is realbank not realbankofficial? Deal with it? The stance that other people should have their savings stolen, when we could have easily stopped it, because of nebulous freedom reasons is pretty ghoulish.

If they installed it through a commercial app store, hold the store owner liable as an accessory to fraud.

Re: An experimental Android WebView Media Integrity API early next year

#167
post #140

Earlier quoted context omitted.

> "P.S. I'd love to discuss this with y'all like professional adults. Can we do that?" You can tell somebody is a snake when they aren't from the South but use "y'all" . It's become a sort of corporate snake shibboleth.

Uhhh, what? I use y'all 'cus that's how all the kids in my school talked growing up. I ditched a lot of the lexicon because after my family moved to the suburbs, I got made fun of by my new friends, literally calling me "less white". So no more finna', for example. I will die on the hill of having a good second person plural pronoun though.

If you actually grew up using it, then you're not who I'm talking about. The word, like "folks", has become part of the affected dialect used by corporate ass-kissers to tell other corporate ass-kissers what they're about. Used primarily by slimy management, HR and PR types.

These types do not say finna, that isn't part of this affected dialect. If you say finna then you're not who I'm talking about.

Re: An experimental Android WebView Media Integrity API early next year

#168
post #34

Earlier quoted context omitted.

It's a place that applications can store such data without my knowledge or control, and I don't trust applications enough to be comfortable with them having that ability. Don't get me wrong, it's not a major issue for me, it's just uncomfortable. It just means I prefer my machines to not have TPM hardware in them.

I'm not storing my fingerprint anywhere else.

[deleted]
Post reply on HN