This is scary. It's (strong) SafetyNet for websites.

Every now and then I run into another Android app I can no longer run because someone decided my phone, running an official build of my choice of OS, that isn't even rooted, is "not trustable".

Now they want to start doing that for websites.

This kills open Linux on the desktop (including Asahi Linux). It kills alternative browsers. It is a backdoor to kill ad blockers.

No. Just no. Please.

https://github.com/RupertBenWiser/Web-Environment-Integrity/blob/main/explainer.md

Web-Environment-Integrity/explainer.md at main · RupertBenWiser/Web-Environment-Integrity

Contribute to RupertBenWiser/Web-Environment-Integrity development by creating an account on GitHub.

GitHub
@lina I love how people keep claiming that their arbitrary websites and apps need to know exactly the software you are running "for your own good" while even some bank apps (like the ones I use) don't care about attesting client-side integrity.
@PeterCxy @lina My government sign-in app only cares if my phone is rooted, which is easy to spoof. Same with my bank's app. But a Norwegian friend-payment app is so dependant on Google services that I can't use it, which is annoying because in Norway "everyone" has it ... If I asked them why they deny me access without Google services on my phone, I'm almost certain they'd respond with some vague security nonsense :/