While WEI is thankfully cancelled, it’s not entirely cancelled… They’re planning on making it available still in WebViews with the intention that websites can check if a malicious Android app is trying to do a phishing scheme.

Seems like such a niche “security” feature… what are they really trying to accomplish here? Something seems fishy to me

  • PonyOfWar@pawb.social
    link
    fedilink
    arrow-up
    4
    ·
    1 year ago

    We gotta remain vigilant.

    Agreed, but I disagree about the first part. It being only available in webviews can’t really be abused and makes all the difference. Sure they could try to reintroduce all the bad stuff, even if the had cancelled it altogether, but for now this is a success.

      • Melody Fwygon@beehaw.org
        link
        fedilink
        arrow-up
        3
        ·
        1 year ago

        No; it is a big deal.

        They will bide their time and polish the feature out on Android WebViews then make another push for Desktop.

        You must never agree to allow WEI exist in any form. It WILL BE MISUSED AND ABUSED!

    • Amju Wolf@pawb.social
      link
      fedilink
      arrow-up
      6
      ·
      1 year ago

      You’re completely wrong.

      This means that they will implement it, and then it’s only a tiny change to make it available everywhere if they decide to do so later.

      The option alone also now also allows people to build stuff that will only work in those WebViews, rejecting to work without the integrity check, which is already a huge loss.

      • PonyOfWar@pawb.social
        link
        fedilink
        arrow-up
        2
        ·
        edit-2
        1 year ago

        The option alone also now also allows people to build stuff that will only work in those WebViews, rejecting to work without the integrity check, which is already a huge loss.

        Can you give a concrete example how this would be a huge issue? A webview is part of an app, which is already a closed system. If a developer wants to, they can already build their app using native UI with integrity checks. Now they can do the same when using webviews. It really has none of the implications it would have for browsers.