The Chrome team says they’re not going to pursue Web Integrity but…

it is piloting a new Android WebView Media Integrity API that’s “narrowly scoped, and only targets WebViews embedded in apps.”

They say its because the team “heard your feedback.” I’m sure that’s true, and I can wildly speculate that all the current anti-trust attention was a factor too.

  • SeriousBug@infosec.pub
    link
    fedilink
    English
    arrow-up
    40
    ·
    8 months ago

    This is worse. Let’s go with an example: on an Android phone, you visit a website. The website asks for an integrity check, the browser works with Google Play Services to complete the check.

    What if you have a de-Googled phone without Play Services, or if you made modifications to restrict Google’s tracking? Then Google can refuse to verify you. What if you installed an ad blocker in your browser? Google can refuse to verify you.

    If you fail verification, the website could ask you to complete a captcha, or just refuse to show you anything.