Browser developers push back on Google’s “web DRM” WEI API

Teilen:

Google’s plans to introduce the Web Environment Integrity (WEI) API on Chrome has been met with fierce backlash from internet software developers, drawing criticism for limiting user freedom and undermining the core principles of the open web.

Employees from Vivaldi, Brave, and Firefox have taken a strong, opposing stance against Google’s proposed standard, and some have gone as far as to call it DRM (digital rights management) for websites.

What is the WEI proposal?

Web Environment Integrity (WEI) is a new API proposal that introduces a website trust mechanism that allows websites to evaluate the authenticity of devices and network traffic on clients (browsers) and block fake or insecure interactions.

For example, this mechanism can be used to detect whether a human or bot is visiting a website or whether a particular browser on a specific type of device is trustworthy.

Websites will use the API to request a token from a certified “attester,” which will be cryptographically signed to prevent tampering, helping the former validate that the client’s information is legitimate.

WEI logic diagram
WEI logic diagram (GitHub)

The purported goal of the WEI proposal is to help websites ascertain the authenticity of the device and software stack from which they’re receiving traffic and protect users from fraud by deterring malicious online activities.

Example use cases include detecting fake engagement on social media, phishing campaigns, non-human traffic, bulk account hijacking attempts, game cheating, compromised devices, and password brute-forcing.

Google says this is not a privacy risk as it does not enable cross-site user tracking and won’t interfere with browser or plugins/extensions functionality.

Criticism from browser vendors

Although the above sounds positive and helpful, Vivaldi browser’s developer J. Picalausa called WEI “dangerous” in a write-up published earlier this week.

“If an entity has the power of deciding which browsers are trusted and which are not, there is no guarantee that they will trust any given browser,” writes Picalausa.

“Any new browser would by default not be trusted until they have somehow demonstrated that they are trustworthy, to the discretion of the attesters.”

Also, Picalausa underlines the vagueness of Google’s proposal, which he says leaves a significant margin for potential abuse like collecting behavioral data from clients.

Vivaldi’s post further explains that choosing not to implement WEI will be complicated, as Google can very easily abuse its dominant position in the advertising market to enforce its adoption by the majority of sites, rendering dissenting browser projects useless.

Die Brave browser team, however, does not fear this scenario as its co-founder and CEO, Brendan Eich, confirmed that they do not plan to ship WEI.

In response to a thread on Twitter, Eich stated that WEI support will not be shipped in Brave, just as they do with many other privacy-intrusive mechanisms Google inserts into Chrome’s code which Brave uses as its basis.

Tweet

As for Mozilla, the internet organization has yet to express an official opinion. However, Firefox engineer Brian Grinstead commented earlier this week that Mozilla opposes the proposal as it contradicts its principles and vision for the web.

“Mechanisms that attempt to restrict these choices are harmful to the openness of the Web ecosystem and are not good for users,” reads Grinstead’s statement.

“Additionally, the use cases listed depend on the ability to “detect non-human traffic” which as described would likely obstruct many existing uses of the web such as assistive technologies, automatic testing, and archiving & search engine spiders.”

Currently, Google’s WEI API proposal is still in an early development phase and may change form or be significantly changed if all stakeholders agree to its implementation.

Also, it will be interesting to see the response of anti-monopolist legislative mechanisms and competition authorities to this proposal if Google attempts to impose it aggressively despite the voices of concern and multiple objections against it.

BleepingComputer has contacted Apple and Microsoft about whether they will support this new standard but has not received a response at this time.

 

(c) Lawrence Abrams

Kommentar verfassen

Deine E-Mail-Adresse wird nicht veröffentlicht. Erforderliche Felder sind mit * markiert

lade-bild
London, GB
13.17 Uhr, Juni 1, 2025
Wetter-Symbol 20°C
L: 19° | H: 21°
broken clouds
Luftfeuchtigkeit: 47 %
Druck: 1013 mb
Wind: 11 mph W
Windböe: 20 mph
UV-Index: 0
Niederschlag: 0 mm
Wolken: 75%
Regen Chance: 0%
Sichtbarkeit: 10 km
Sonnenaufgang: 4:49 am
Sonnenuntergang: 9:07 pm
TäglichStündlich
Tägliche VorhersageStündliche Vorhersage
Today 10:00 pm
Wetter-Symbol
19° | 21°°C 0 mm 0% 14 mph 70 % 1014 mb 0 mm/h
Tomorrow 10:00 pm
Wetter-Symbol
11° | 21°°C 0 mm 0% 10 mph 82 % 1019 mb 0 mm/h
Di. Juni 03 10:00 pm
Wetter-Symbol
11° | 17°°C 1 mm 100% 16 mph 92 % 1013 mb 0 mm/h
Mi. Juni 04 10:00 pm
Wetter-Symbol
9° | 19°°C 0 mm 0% 13 mph 83 % 1010 mb 0 mm/h
Do. Juni 05 10:00 pm
Wetter-Symbol
11° | 15°°C 1 mm 100% 13 mph 97 % 1009 mb 0 mm/h
Today 4:00 pm
Wetter-Symbol
17° | 19°°C 0 mm 0% 14 mph 44 % 1013 mb 0 mm/h
Today 7:00 pm
Wetter-Symbol
15° | 17°°C 0 mm 0% 12 mph 50 % 1013 mb 0 mm/h
Today 10:00 pm
Wetter-Symbol
16° | 16°°C 0 mm 0% 9 mph 70 % 1014 mb 0 mm/h
Tomorrow 1:00 am
Wetter-Symbol
13° | 13°°C 0 mm 0% 7 mph 82 % 1016 mb 0 mm/h
Tomorrow 4:00 am
Wetter-Symbol
11° | 11°°C 0 mm 0% 6 mph 78 % 1017 mb 0 mm/h
Tomorrow 7:00 am
Wetter-Symbol
12° | 12°°C 0 mm 0% 9 mph 72 % 1018 mb 0 mm/h
Tomorrow 10:00 am
Wetter-Symbol
16° | 16°°C 0 mm 0% 8 mph 48 % 1019 mb 0 mm/h
Tomorrow 1:00 pm
Wetter-Symbol
19° | 19°°C 0 mm 0% 8 mph 31 % 1018 mb 0 mm/h
Name Preis24H (%)
Bitcoin(BTC)
€91,772.33
0.42%
Ethereum(ETH)
€2,202.20
-0.98%
Fesseln(USDT)
€0.88
0.01%
XRP(XRP)
€1.89
-0.17%
Solana(SOL)
€133.97
-0.89%
USDC(USDC)
€0.88
-0.01%
Dogecoin(DOGE)
€0.166779
0.94%
Shiba Inu(SHIB)
€0.000011
2.94%
Pepe(PEPE)
€0.000010
1.71%
Peanut das Eichhörnchen(PNUT)
€0.227225
4.08%
Nach oben scrollen