Web Environment Integrity: Difference between revisions

Content deleted Content added
Reception: mozilla ce changes are nonsensical. "significantly limit browsers" phrasing is repeated multiple times and not supported by any source. w3c change is MOS:PRESUME ("made clear") and makes unsubstantiated claims about the future ("won't"). i'm inclined to agree with the characterization made in Talk:Triboelectric_effect of "a weird form of denial of service"
m Proposal: No hyphens after -ly
Tags: Mobile edit Mobile app edit Android app edit
Line 5:
[[Image:Web Environment Integrity attestation - How it works.svg|thumb|480px|[[Sequence diagram]] showing WEI attestation]]
 
The draft proposes an API for websites to get a [[Digital signature|digitally- signed]] token that contains the certifier's name and whether or not they deem the web client to be authentic. The stated goal is to only allow access to certain sites for human users instead of automated programs and "allow web servers to evaluate the authenticity of the device and honest representation of the software stack and the traffic from the device". Access to this API will not be allowed in non-secure ([[HTTP]]) contexts.<ref>{{Cite web |title=Web-Environment-Integrity/explainer.md at main · RupertBenWiser/Web-Environment-Integrity |url=https://github.com/RupertBenWiser/Web-Environment-Integrity/blob/main/explainer.md |access-date=2023-07-26 |website=GitHub |language=en}}</ref>
{{clear}}