While WEI is thankfully cancelled, it’s not entirely cancelled… They’re planning on making it available still in WebViews with the intention that websites can check if a malicious Android app is trying to do a phishing scheme.

Seems like such a niche “security” feature… what are they really trying to accomplish here? Something seems fishy to me

  • Onii-Chan@kbin.social
    link
    fedilink
    arrow-up
    5
    ·
    1 year ago

    As someone who uses GrapheneOS but knows very little about the technical side of things, what implications does this have for the OS? I’ll actually just not use a smartphone anymore if I’m going to be forced back onto the privacy nightmare that is stock Android.

      • Baut [she/her] auf.
        link
        fedilink
        arrow-up
        3
        ·
        1 year ago

        I’d expect them to support basic integrity. They already do that for apps, so no reason to not expand it. It’d break compatibility.
        Since they don’t (want) to offer a way to circumvent the basic integrity check right now, I don’t see why they would undo the expansion into the webview.

    • Pantherina@feddit.de
      link
      fedilink
      arrow-up
      2
      ·
      1 year ago

      They will strip out the DRM part, maybe. GrapheneOS, other than even Firefox or any Linux Distro, has many DRM packages installed. Widevine and lots of others.

      So it may be that they dont even remove it from the Vanadium Webview. But if they do, Apps may break as the Developers looove the extra control. And then GrapheneOS needs to do annoying work again, to for example have a sandboxed Webview-DRM app that can be enabled per-App.