15 ms·
An experimental Android WebView Media Integrity API early next year
- mplewis 3y agoI notice that this post's title hasn't been edited by HN mods for "editorialization." Why not?
- riku_iki 3y agoProbably started working on some more cryptic solution already.
- jahav 3y agoProbably, but I will take this victory. Google has power to make this happen.
- riku_iki 3y ago> Google has power to make this happen. they will have more power once current anti-trust trial will be over.
- happytiger 3y agoI mean this is the problem with the entire situation. I immediately read the article looking for any evidence that they would abandon the direction of the idea rather than do what Google does sometimes and roll out a POC on some other less controversial part of their infrastructure and then come back to it when the timing is more right (like after a large cybersecurity event happens, mark these words). They did exactly that. They rolled it back to the Android team and promised to perfect a smaller effort in a less controversial sandbox but rest assured they are publicly saying only that they are retiring the effort for the web for now. I really wish Google would go back to being the champion of the Open Internet I once knew them for and step away from the MBA’ification of everything they keep trying. Seems like the moment they dropped “don’t be evil” they started going there. It’s exhausting. Instead of celebrating a victory, every one of the Open Internet crowd gets to celebrate a smaller project execution and nothing but a pause in the web platform version of it. Yay.
- danShumway 3y ago> They rolled it back to the Android team and promised to perfect a smaller effort in a less controversial sandbox Conveniently this also seems to mean (assuming I understand the announcement correctly) they get to roll it out for the webview and finalize everything without going through the web standards process and without dealing with any community feedback because it's not technically a web standard anymore. They get to build a working implementation in Chromium (oh, sorry, not Chromium. Android Webview, an entirely different browser that just happens to be based on V8 and the same rendering engine, but is definitely not Chromium) and they get to make sure everything is working and even get websites using it for webapps. And then if they come forward again to standardize it they can say, "look, developers are already using the API so we're not going to change anything, and it's not controversial, and we're just slightly expanding it so that browsers are all compatible with each other, so it's fine if we just launch this in Chrome and ask the standards committee to sign off, right?"
- deleted 3y ago[deleted]
- zlg_codes 3y agoThis is part of what's concerning about 'open' platforms like the Web; large and influential parties inevitably end up steering things to serve someone's bottom line somewhere. I'm beginning to think we need hard forks of the Web, because we already have two "spheres" of the Web: the JS-heavy sites-are-apps Web, and the documents-and-links Web. The former can be argued to be a superset of the latter, but with continued anti-user efforts coming from that crowd and their diametrically opposite endgoals compared to an open platform... what real choice do the major parties have but to part ways...?
- rubenv 3y agoGood
- heywintermute 3y agoRepo has be archived - "NOTE: This proposal is no longer pursued." https://github.com/RupertBenWiser/Web-Environment-Integrity https://github.com/RupertBenWiser/Web-Environment-Integrity
- deleted 3y ago[deleted]
- beej71 3y agoClick on "Issues" for a good time.
- mynameisash 3y agoActual blog post title is, "Android Developers Blog: Increasing trust for embedded media"
- brycewray 3y agoTrue, but that seriously buried the lede. Sorry for the edit.
- nickthegreek 3y agoI like the edit. That dull blog title would get ZERO traction.
- mynameisash 3y agoCaveat that I'm by no means educated about WEI, the actual title feels a bit Orwellian to me. I just wanted to point out the actual title and not an editorialized one (without commenting on whether editorialization is good or bad here).
- rezonant 3y agoIn case this is all new to you: effectively WEI aimed to bring hardware-based remote attestation to the web for the purposes of allowing servers to refuse service when the device and its software was not approved by the authors of the server. Now they just want to do it in WebViews, which is ineffectual at best, and still harmful at worst.
- fsckboy 3y agobut if the title is "Increasing trust for embedded media", where's the intent to back off? The changed title implies everybody can stop worrying.
- endisneigh 3y agoIt’s funny how techies complain about clickbait yet celebrate and engage with… clickbait
- spitfire 3y ago"Google apparently backs off on WEI." For the time being.
- Loudergood 3y agoGood.
- lol768 3y agoWEI itself was previously discussed across a number of threads, which make interesting reading: (July 2023, 456 comments) https://news.ycombinator.com/item?id=36854114 https://news.ycombinator.com/item?id=36854114 - "Google's nightmare Web Integrity API wants a DRM gatekeeper for the web" (July 2023, 431 comments) https://news.ycombinator.com/item?id=36817305 https://news.ycombinator.com/item?id=36817305 - "Web Environment Integrity API Proposal" (July 2023, 434 comments) https://news.ycombinator.com/item?id=36875940 https://news.ycombinator.com/item?id=36875940 - "Unpacking Google’s Web Environment Integrity specification" (July 2023, 111 comments) https://news.ycombinator.com/item?id=36857676 https://news.ycombinator.com/item?id=36857676 - "So, you don't like a web platform proposal" - Google employee's view on how folks should've responded to the proposal (August 2023, 100 comments) https://news.ycombinator.com/item?id=36960882 https://news.ycombinator.com/item?id=36960882 - "Web Environment Integrity: Locking Down the Web"
- jjoonathan 3y agoOof, that hyper-aggressive whitewashing of the DRM proposal from yoavweiss_ was a harsh lesson in realpolitik. Nerds were bringing good faith arguments to a bad faith optics war and getting slaughtered.
- belval 3y agoFor people wondering which of the links to click: https://news.ycombinator.com/item?id=36857676 https://news.ycombinator.com/item?id=36857676 It's mostly just the classic "nono if you don't agree it's because you don't understand" and "please educate yourself" approach.
- whatshisface 3y agoAt least they didn't try, "I don't have time to educate you about why you're bad!"
- mcpackieh 3y ago> "P.S. I'd love to discuss this with y'all like professional adults. Can we do that?" You can tell somebody is a snake when they aren't from the South but use "y'all". It's become a sort of corporate snake shibboleth.
- hanniabu 3y agoDoesn't matter, they've already showed their hand with how they're wiling to ignore everyone and try to push through whatever they want.
- ls612 3y agoGoogle has been claiming to want to break adblockers (although they don’t put it that way) with Manifest v3 and removing Manifest v2 for a while and they have always backed off actually pulling the trigger on it.
- endisneigh 3y agoThey’ve shown their willingness to ignore by… scrapping something that was disliked?
- hanniabu 3y agoI imagine they're pulling the politician card. When there's a lot of pushback, you scrap it for optics, and then a few months or years later you bring it back under a different name and presented as something new and hope people don't pick up on it. And if they do, then you repeat until people are exhausted enough to not give any pushback anymore.
- teddyh 3y agoA.k.a. “Outrage fatigue”.
- freedomben 3y agoTFA is about more than just WEI, but it does address it directly: > We’ve heard your feedback, and the Web Environment Integrity proposal is no longer being considered by the Chrome team. In contrast, the Android WebView Media Integrity API is narrowly scoped, and only targets WebViews embedded in apps. It simply extends existing functionality on Android devices that have Google Mobile Services (GMS) and there are no plans to offer it beyond embedded media, such as streaming video and audio, or beyond Android WebViews. This is really great to hear, thank you Chrome team! Is there a risk that this is one of those "shelve it for 6 months and we'll try again later" playbooks, and that already having the implementation will make it just "an expansion" of existing tech rather than "new" tech, which will make the pill easier for most people to swallow even though it gets to the same end result?
- iofiiiiiiiii 3y agoWhat does your heart tell you? Palladium[1] came and went and then suddenly most laptops and mobile devices have a built-in TPM today. No doubt history will repeat. [1] https://en.wikipedia.org/wiki/Next-Generation_Secure_Computing_Base https://en.wikipedia.org/wiki/Next-Generation_Secure_Computi...
- jorvi 3y agoUhm… what? Your beef is with things like Pluton, Intel’s ME and AMD’s PSP. TPM at their base are nothing else than a more secure place to store cryptographic data.
- JohnFen 3y agoIt's a place that applications can store such data without my knowledge or control, and I don't trust applications enough to be comfortable with them having that ability. Don't get me wrong, it's not a major issue for me, it's just uncomfortable. It just means I prefer my machines to not have TPM hardware in them.
- Arainach 3y ago
- ZeroCool2u 3y agoThe title is misleading. They've dropped the proposal as applied to Chrome, but are still pursuing it for the Android WebView API, which is basically a wrapper around Chrome.
- andybak 3y agoWebviews are particularly vulnerable though, being used for embedded logins for sometimes dubious 3rd party apps. Is there a reasonable angle to view this from? I personally don't think embedded webviews should be allowed general browsing capability unless they are part of a standalone browser. It's usually a trick to capture traffic that would otherwise go off to the open web.
- TremendousJudge 3y agoIf that's the problem you're trying to solve, disallow embedded ~~logins~~ webviews and do it through a proper browser, same as on a regular computer. The other way seems overkill and smells like foul play to me.
- andybak 3y agoI'm not sure how you disallow embedded login without disallowing embedded webviews. The line is very blurry.
- TremendousJudge 3y agoI'm sorry, I wrote embedded logins but was thinking embedded webviews in general. The only legitimate use of that in my mind is "a web browser app that's a usability skin over Chrome". Everything else is just a way of keeping you in a walled garden, and would be better if it just sent you to your default browser.
- andybak 3y agoOk. So I think we are in agreement. I struggle to think of a use case that is in the user's best interests.
- endisneigh 3y agoIt’s interesting that a single googlers repository was what was being used for wei discussion instead of something more “official”. People celebrating this aren’t realizing that it’ll probably stop api scraping via a web view back door.
- deleted 3y ago[deleted]
- dylan604 3y agoThis way, they can hide it in another repo later
- harshitaneja 3y agoI have been walking around with this dread ever since the proposal was announced. Thinking about its implications made me appreciate even in today’s screwed up internet we still don’t have it that bad.
- _Algernon_ 3y ago... (for now)
- sarahdellysse 3y ago> backed off WEI for now
- londons_explore 3y ago> Android WebView Media Integrity API is narrowly scoped I don't see any benefit to the user... Surely any app which wishes to embed a webview can simply add an api to said webview with native code to use existing android integrity API's? To me, this looks like a backdoor way to prevent people making "hacked" apps which, for example, play youtube but without ads. This API doesn't benefit the users.
- JohnFen 3y agoIt's not intended to benefit the user.
- deleted 3y ago[deleted]
- ugh123 3y agoThe benefit to the user is they can supposedly "trust" the content that is being shown in the webview is, in fact, owned by or affiliated somehow with the app. They don't give an example, but i'd imagine its something like: "bad app lets user's sign into their bank account through the app's webview, then webview scrapes/intercepts content to do as they wish".
- ethbr1 3y agoIsn't that something that should be solved at the App Store and/or application fraud detection levels? I get bad actors exist. But they're not an excuse to strip everyone else of rights. >> The Android WebView API lets app developers display web pages which embed media, with increased control over the UI and advanced configuration options to allow a seamless integration in the app. This brings a lot of flexibility, but it can be used as a means for fraud and abuse, because it allows app developers to access web content, and intercept or modify user interactions with it. This proposal was always a stick of dynamite when a screwdriver was needed. Start with the assumption that a user client should be able to do whatever the user decides it should. And while keeping that in mind as an absolute, work backwards. If it creates false ad clicks... tough. Deal with it.
- pshirshov 3y ago> In contrast, the Android WebView Media Integrity API is narrowly scoped I guess it means that at some point I won't be able to use many apps under GrapheneOS with its Vanadium WV?
- jwr 3y agoI expect to see the usual Google approach: back off, then come back with another take on the same thing, but wrapped differently.
- TremendousJudge 3y agoThey have been tamed in the past. Correct me if I'm mistaken, but Google Native Client was completely discontinued and wasm was adopted eventually. I see that as a victory for the open internet.
- KMag 3y agoI'm not sure WASM is markedly different from PNaCL, other than using SSA-based LLVM bitcode instead of a stack-based bytecode.
- the_duke 3y agoIt's a well-defined standard with lots of different implemenetations, instead of "whatever Chrome does", tied to one specific codegen backend. That's a huge difference.
- user3939382 3y agoThey learned it from Congress.
- deleted 3y ago[deleted]
- vsgherzi 3y agoGlad to see the chrome team listening to feedback
- pkaye 3y agoCan anyone summarize what WEI is an why its bad?
- zarzavat 3y agoDRM for web browsing. A website would be able to request an attestation that your browser is “trusted”, i.e. it is secure and unmodified. Because some systems are by definition untrusted, e.g. Linux, or Firefox compiled from source, these users might be blocked from certain websites. At least that seemed like the intention, otherwise what’s the point of building such a feature?
- jezzamon 3y agoIf you want the "assuming good intent" explanation it was to be able to detect spam and bots which apparently are a significant problem now and are no longer stopped by captchas. One online community I'm part of literally turned off new sign ups because they couldn't stop the bot problem (ldjam.com). Users also find captchas annoying so it supposedly stop the need for that for many cases (except for when you're in the 10% hold out group or whatever)
- zarzavat 3y agoThere’s still no way to tell the difference between a Linux user and a bot through such an attestation mechanism. So the effect on users is the same regardless of the intention.
- keepamovin 3y agoThis is really good. Google did the right thing. We don’t need to thank them for acting the way they should have originally, but we can appreciate it.
- cmrdporcupine 3y agoSorry Google, too late, already switched to Firefox.
- i-am-gizm0 3y agoOfficial confirmation in the WEI public discussion thread: https://groups.google.com/a/chromium.org/g/blink-dev/c/Ux5h_kGO22g/m/Iu5w_dcoAgAJ https://groups.google.com/a/chromium.org/g/blink-dev/c/Ux5h_...
- wkat4242 3y agoGreat. Really dodged a bullet there.
- imiric 3y agoNot really. More like the entity pointing the gun has now decocked it. The scary part is that there is a single entity with that kind of power to begin with. It's a testament of the failure of the modern web, and how far it has strayed from the original spirit of the internet.
- happytiger 3y agoThis is the point. Let’s celebrate a reduced scope implentation on a more limited number of platforms until we perfect the technology? No. Not really a victory. Just a pause.
- skydhash 3y agoMostly because most people don’t care about the original spirit of the internet. As long as they can get their job done, consume entertainment, and play status game, they are content. Which is why for most people, their internet is just a handful of tech companies. It’s basically Minitel, but fueled by ads.
- ok123456 3y agoFor now.
- m-p-3 3y agoUntil next time, for the sake of the open Internet we can't stop pushing back. It's exhausting.
- sgammon 3y agoWe did it. Massive hckrnews W
- deleted 3y ago[deleted]
- wkat4242 3y agoWow that surprises me. A lot. I'm sure they will cook up something else evil though. FLoC just came back under a different name. It is so surprising to me that the one company that had "don't be evil" in their motto has become the one most antagonous company to society (or at least in a digital services manner, I'm sure Palantir and Monsanto can take that crown in their own areas).
- deleted 3y ago[deleted]
- exabrial 3y agoReading between the lines: They're leveraging their monopolistic position to force APIs into an "open source" project to prevent users from skipping ads.
- rezonant 3y agoThis blog post is how they should have started the discussion about WEI, but better late than never. That being said, while I can somewhat understand the use case for preventing fraud, misconception of source, etc, what we're talking about effectively kneecaps the ability to write bonafide Android browsers that leverage the WebView engine, while doing little to prevent the fraud and abuse the proposal intends to solve. If you are an Android browser author, you certainly can ship your own browser engine, unlike on Apple's platforms where that's still prohibited. However, if your motivation for creating that browser is primarily around the user experience or other "over the top" features, building your own browser engine simply because WebView cannot operate as a real web browser to your users, is unfortunate. Meanwhile, as an app developer who is interested in engaging in fraud, misinformation, or other nefarious things, they _can_ ship their own browser engine to bypass this functionality entirely. Does it add more work? Yes, but if their goals include this bad behavior, why wouldn't they? Even without all this, assuming that Chrome itself, Firefox nor anyone else will actually implement some kind of "this is definitely not a web view" attestation, the content owner has no choice but to allow that access, since they have no idea if the user agent they are looking at is a legitimate browser or an embedded webview. Google, there is no way to solve this problem using attestation short of the original WEI proposal, which is bad for users. All you are doing now is muddying the waters and adding _some_ harm instead of _a lot_ of harm.
- nolist_policy 3y agoSure, malware can ship its own browser engine but it can not attest authenticity to the server. The proposal doesn't limit the Android WebView in any way.
- rezonant 3y agoYes, but that's not sufficient. If, say, YouTube would like to prevent an Android game from running an invisible and silent webview watching videos on YouTube.com (because some ethically challenged YouTubers paid them to help juice their view counts), YouTube could use the new web view integrity API to validate that webview, but if the developer ships an engine inside of that game and uses that instead of using the WebView, then YouTube cannot tell that its not just a third party browser. So unless they are going to block all third party browsers, which they can't actually do because the browser could be configured to emulate Chrome, and Chrome doesn't actual implement any kind of attestation... So there's already a way to bypass what they are trying to do.
- jader201 3y agoOriginal title: “Increasing trust for embedded media” > Otherwise please use the original title, unless it is misleading or linkbait; don't editorialize. https://news.ycombinator.com/newsguidelines.html https://news.ycombinator.com/newsguidelines.html
- digging 3y agoThe original title is misleading.
- ethbr1 3y agoThe original title is misleading enough to be incoherent.
- keepamovin 3y agoRead in the voice of a Sith master: they have learned their lesson well, my young Android apprentice.
- phoronixrly 3y agoThis title is also misleading. Google backs off on WEI in Chrome, but still pushes it in the webview, thus making it easier to create apps that limit what you can do with your own hardware.
- Wowfunhappy 3y agoI don't understand how this works. > The new Android WebView Media Integrity API will give embedded media providers access to a tailored integrity response that contains a device and app integrity verdict so that they can ensure their streams are running in a safe and trusted environment, regardless of which app store the embedding app was installed from. But this only applies to the Android WebView API, not standalone web browsers like Google Chrome. Otherwise we'd be back to where we started with the original Web Environment Integrity proposal. But no one has to use the WebView API, it's a convenient option but Chromium is open source! What stops Bob the Evil Android Developer from compiling his own version of Chromium, bundling that into his app, and doing whatever malevolent website trickery his ink black heart desires? Put another way, if this is only built into the special WebView API, wouldn't a malicious developer just avoid using that API?
- nolist_policy 3y agoAll this is about attesting authenticity to the server.
- Wowfunhappy 3y agoBut only Android WebViews can attest their authenticity. Are servers going to block standalone web browsers? If they are, why even use a WebView? Just make it part of your app.
- KRAKRISMOTT 3y agoMany corporate apps in e.g. banking are just Cordova/browser wrappers around a website.
- creshal 3y agoA lot of "native" apps are just thin wrappers around web components, since it's a lot cheaper to develop.
- Wowfunhappy 3y ago
- dools 3y agoTitle should be: “Increasing trust for embedded media” There is a guideline against editorialising in the title
- samrus 3y agobullying corporations once again yields results
- ilc 3y agoSorry big G. You lost the trust on this one.
- m463 3y agoWeb Environment Integrity (WEI) is a controversial API proposal currently being developed for Google Chrome. https://en.wikipedia.org/wiki/Web_Environment_Integrity https://en.wikipedia.org/wiki/Web_Environment_Integrity
- 867-5309 3y agoshould firstly explain what WEI is
- sensanaty 3y ago...for the time being, but them being the comic-book, mustache twirling evil villains they are there's no doubt WEI will be coming back, in a even more evil package, sometime down the line.
- jauntywundrkind 3y agoMajor war on general purpose computing vibes resumes 'It's in the users best interest to not let them bring their own computer & have to use a Google approved computer because [fill in corporate doublespeak bullshit here]'. Fwiw, the whole system of native apps have dealt with this hlkind of crap forever & it's expected. An old super small native app we had failed pen testing because it would run on jailbroke devices. Google Play SafetyNet and probably three other frameworks on Android all exist to make sure users don't have ownership of devices. So this is basically a Google Project Fugu effort, but the dark side. the web should be capable of doing everything native apps do, even when that thing is placing a huge boot on the face of users & rejecting their user-agency. Womp womp. Also, notably, Apple already shipped a just as bad implementation of PrivateTokens where websites can ask Apple to make sure the device is legitimate. I'm not sure why Google built a new spec, why they decided to be a huge lightning rod for this, a lightning rod with much less cover from publicity, as instead of being a generic attestation system (and relying on Apple having dominion over their platform in a way Android lacks), it's a very narrow attestation system about device integrity. https://httptoolkit.com/blog/apple-private-access-tokens-attestation/ https://httptoolkit.com/blog/apple-private-access-tokens-att...
- jacknews 3y ago"We’ve heard your feedback, and the Web Environment Integrity proposal is no longer being considered by the Chrome team." Instead we'll roll it out bit-by-bit with different names.
- danShumway 3y agoSo... it's being implemented anyway, just only for the embedded browser? This doesn't make me feel better. And it's a very Google type of answer to give: announce that you're moving forward anyway, but pretend like you're listening to feedback and giving everyone what they want. It's annoying that the entire retrospective is two sentences. Still no conversation with the dev community of course, just two sentences that say it's not being considered and we move on. And it's convenient that the new API is no longer a proposal, it's just an internal program that Google is building on their own. ---- Off the top of my head, I think some of the concerns here still apply? Not all of them, this is better than the original proposal, but this is now dividing the web up into webviews that are supposedly only going to work on Android? Because iOS I don't think supports this kind of thing -- maybe I'm wrong though. We still have this inversion of the Open web where clients attest DRM capabilities to the server, which is not how the web is supposed to work. But I guess that's supposedly OK because the idea is you'd only use this API on a site that was only ever intended to be viewed in a webview for a single app? I'll admit I don't know how common that is. And all of this to paper over embedded web views, which arguably should be used less on Android anyway. I don't know, that could be a long conversation; but the point being I'm still worried about the announcement -- less worried, but still worried. It's both so weirdly narrow and so unsuitable for the goals that the original proposal outlined that my most cynical side almost feels like it's being done purely because Google doesn't like complete capitulation and wants to have the last word? But it's also still so weirdly antithetical to how an Open web works (even within that very narrow band of apps it would apply to) that I can't shake the feeling there's some horrible side-effect that isn't immediately obvious to me. Of course I don't know the details or whether or not it'll all be fine; maybe this will be nothing and mostly won't matter for anything. It's hard to tell because we're no longer talking about a standards proposal as far as I can tell. It sounds like Google is just going to do this internally and roll it out to small numbers of partners and then will launch it and that will be that, no community feedback required. Which... :shrug: not having your attestation plans be publicly available to comment on is definitely a way to avoid criticism, I guess.
- zlg_codes 3y agoThe world needs to stop looking to a global data broker who feeds data to advertisers as a legitimate and good faith steward of Web technologies. It violates the separation of concerns between server and client, for starters. Clients are user agents, i.e. they do what the user wants, not what the server wants. This fundamental misunderstanding/skewing of perspective is part of the problem. If we want HTTP(S) and friends to remain a free and open protocol for all, we have to cut Google out of the decision-making process. They've been behind Encrypted Media Extensions, they've been behind Manifest v3, and now WEI.. The Web doesn't belong to Google. They can go do QUIC and leave HTTP alone.