Google’s nightmare “Web Integrity API” wants a DRM gatekeeper for the web

Google’s plan is that, during a webpage transaction, the web server could require you to pass an “environment attestation” test before you get any data. At this point your browser would contact a “third-party” attestation server, and you would need to pass some kind of test. If you passed, you would get a signed “IntegrityToken” that verifies your environment is unmodified and points to the content you wanted unlocked. You bring this back to the web server, and if the server trusts the attestation company, you get the content unlocked and finally get a response with the data you wanted.

The web mercilessly mocked this idiotic proposal over the weekend, and rightfully so. This is an unadulterated, transparent attempt at locking down the web with DRM-like nonsense just to serve more targeted ads that you can’t block. This must not make its way into any browser or onto any server in any way, shape, or form. The less attention we give to this drivel, the better.


  1. 2023-07-24 5:06 pm
  2. 2023-07-24 5:55 pm
    • 2023-07-25 10:21 am
      • 2023-07-25 1:15 pm
  3. 2023-07-25 3:37 am
  4. 2023-07-25 5:16 am
    • 2023-07-29 1:31 am
    • 2023-07-29 2:02 am
  5. 2023-07-26 3:40 pm
    • 2023-07-26 7:07 pm
      • 2023-07-26 9:08 pm
  6. 2023-07-29 2:23 am