{"id":41003,"date":"2023-11-03T21:56:06","date_gmt":"2023-11-04T01:56:06","guid":{"rendered":"https:\/\/mjtsai.com\/blog\/?p=41003"},"modified":"2023-11-03T21:56:06","modified_gmt":"2023-11-04T01:56:06","slug":"google-abandons-web-environment-integrity-api","status":"publish","type":"post","link":"https:\/\/mjtsai.com\/blog\/2023\/11\/03\/google-abandons-web-environment-integrity-api\/","title":{"rendered":"Google Abandons Web Environment Integrity API"},"content":{"rendered":"<p><a href=\"https:\/\/www.theregister.com\/2023\/11\/02\/google_abandons_web_environment_integrity\/\">Thomas Claburn<\/a> (via <a href=\"https:\/\/news.ycombinator.com\/item?id=38121994\">Hacker News<\/a>):<\/p>\n<blockquote cite=\"https:\/\/www.theregister.com\/2023\/11\/02\/google_abandons_web_environment_integrity\/\"><p>Amid rising community concern, Google says it will no longer develop controversial technology that was said to fight fraud online though to critics looked more like DRM for websites.<\/p><p>[&#8230;]<\/p><p>Apple incidentally has already shipped its own attestation scheme called Private Access Tokens, which while it presents some of the same concerns is arguably <a href=\"https:\/\/httptoolkit.com\/blog\/apple-private-access-tokens-attestation\/\">less worrisome<\/a> than Google&rsquo;s proposal because Safari&rsquo;s overall share of the web browser market across all devices is far lower than Chrome&rsquo;s.<\/p><p>Google also offers two more limited attestation services, the <a href=\"https:\/\/developer.android.com\/google\/play\/integrity\">Play Integrity API<\/a> and <a href=\"https:\/\/firebase.google.com\/docs\/app-check\">Firebase App Check<\/a>. And its YouTube subsidiary&rsquo;s <a href=\"https:\/\/www.theregister.com\/2023\/10\/26\/privacy_advocate_challenges_youtube\/\">scanning<\/a> of client browsers for ad blocking extensions also represents a form of attestation or integrity check, albeit where what&rsquo;s evaluated is installed software rather than a cryptographic token.<\/p><p>[&#8230;]<\/p><p>Instead, the Android team aims to focus on the Android WebView Media Integrity API, which provides a similar form of attestation but only for WebViews embedded in Android apps.<\/p><\/blockquote>\n\n<p>Previously:<\/p>\n<ul>\n<li><a href=\"https:\/\/mjtsai.com\/blog\/2023\/08\/30\/analysis-of-obfuscation-techniques-found-in-fairplay\/\">Analysis of Obfuscation Techniques Found in FairPlay<\/a><\/li>\n<li><a href=\"https:\/\/mjtsai.com\/blog\/2023\/07\/27\/web-environment-integrity\/\">Web Environment Integrity<\/a><\/li>\n<\/ul>","protected":false},"excerpt":{"rendered":"<p>Thomas Claburn (via Hacker News): Amid rising community concern, Google says it will no longer develop controversial technology that was said to fight fraud online though to critics looked more like DRM for websites.[&#8230;]Apple incidentally has already shipped its own attestation scheme called Private Access Tokens, which while it presents some of the same concerns [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"apple_news_api_created_at":"2023-11-04T01:56:10Z","apple_news_api_id":"cb8a135e-ccb9-4598-90a4-e7f3513417e5","apple_news_api_modified_at":"2023-11-04T01:56:10Z","apple_news_api_revision":"AAAAAAAAAAD\/\/\/\/\/\/\/\/\/\/w==","apple_news_api_share_url":"https:\/\/apple.news\/Ay4oTXsy5RZiQpOfzUTQX5Q","apple_news_coverimage":0,"apple_news_coverimage_caption":"","apple_news_is_hidden":false,"apple_news_is_paid":false,"apple_news_is_preview":false,"apple_news_is_sponsored":false,"apple_news_maturity_rating":"","apple_news_metadata":"\"\"","apple_news_pullquote":"","apple_news_pullquote_position":"","apple_news_slug":"","apple_news_sections":"\"\"","apple_news_suppress_video_url":false,"apple_news_use_image_component":false,"footnotes":""},"categories":[2],"tags":[248,412,182,51,456,96,50],"class_list":["post-41003","post","type-post","status-publish","format-standard","hentry","category-technology","tag-android","tag-chromium","tag-drm","tag-google","tag-googlechrome","tag-web","tag-webapi"],"apple_news_notices":[],"_links":{"self":[{"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/posts\/41003","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/comments?post=41003"}],"version-history":[{"count":1,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/posts\/41003\/revisions"}],"predecessor-version":[{"id":41004,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/posts\/41003\/revisions\/41004"}],"wp:attachment":[{"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/media?parent=41003"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/categories?post=41003"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/tags?post=41003"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}