Live data from Hacker News

An experimental Android WebView Media Integrity API early next year

android-developers.googleblog.com

81–90 of 247 posts

Re: An experimental Android WebView Media Integrity API early next year

#81
post #64

Earlier quoted context omitted.

and it would banish Linux from all PCs making Windows the some possible OS We're getting closer to that with things like "secure" boot. Fortunately that can still be disabled, but MS even required that on ARM platforms it can't. The bigger Linux distros have bent over and gotten MS to sign their bootloaders, essentially making them at the mercy of MS.

This is a weird way to describe an open, transparent standard. https://wiki.debian.org/SecureBoot#What_is_UEFI_Secure_Boot_...

It doesn't matter how open and transparent the standard is if part of the de facto implementation is that Microsoft is the only one with the keys.

Some BIOSes let you enter your own Secure Boot keys (like my desktop and laptop), but not all.

Re: An experimental Android WebView Media Integrity API early next year

#82
post #26

Earlier quoted context omitted.

Uhm… what? Your beef is with things like Pluton, Intel’s ME and AMD’s PSP. TPM at their base are nothing else than a more secure place to store cryptographic data.

TPM at their base are nothing else than a more secure place to store cryptographic data. One which you, as the owner, don't have the keys to.

> One which you, as the owner, don't have the keys to.

One which nobody, not even the owner, can extract keys from. I don't understand why people don't like the fact that they can't pull keys out of the TPM. If you, the owner, can pull them so can anybody else. I know TPMs aren't invulnerable but you have to admit they significantly raise the bar of compromise.

Re: An experimental Android WebView Media Integrity API early next year

#88

TFA is about more than just WEI, but it does address it directly: > We’ve heard your feedback, and the Web Environment Integrity proposal is no longer being considered by the Chrome team. In contrast, the Android WebView Media Integrity API is narrowly scoped, and only targets WebViews embedded in apps. It simply extends existing functionality on Android devices that have Google Mobile Services (GMS) and there are no…

It'll be back, in another form. Pay no attention to specific projects and proposals that are offered and withdrawn. Look at the bigger picture over a longer time-frame and ask; what are the forces acting within and upon an entity? Meadows' leverage points taxonomy can be used analytically as well as instrumentally. What are the values behind misadventures like WEI ? Google want to own your browser and infiltrate as m…

Sometimes what you're describing is a valid approach-- once a pattern is clear. This is looking pretty reasonable for Google.

But it seems like a bit of a toxic, pessimistic response in general.

There's other times where a party just screws up. e.g. Apple's CSAM-- once the industry educated them, they took a very different tack. There was no fundamental structural or cultural issue pushing them towards the problematic choices.

Re: An experimental Android WebView Media Integrity API early next year

#89
post #69

Earlier quoted context omitted.

I'm not sure how you disallow embedded login without disallowing embedded webviews. The line is very blurry.

I'm sorry, I wrote embedded logins but was thinking embedded webviews in general. The only legitimate use of that in my mind is "a web browser app that's a usability skin over Chrome". Everything else is just a way of keeping you in a walled garden, and would be better if it just sent you to your default browser.

Ok. So I think we are in agreement. I struggle to think of a use case that is in the user's best interests.

Re: An experimental Android WebView Media Integrity API early next year

#90
Wow that surprises me. A lot.

I'm sure they will cook up something else evil though. FLoC just came back under a different name.

It is so surprising to me that the one company that had "don't be evil" in their motto has become the one most antagonous company to society (or at least in a digital services manner, I'm sure Palantir and Monsanto can take that crown in their own areas).

Post reply on HN