This is scary. It's (strong) SafetyNet for websites.
Every now and then I run into another Android app I can no longer run because someone decided my phone, running an official build of my choice of OS, that isn't even rooted, is "not trustable".
Now they want to start doing that for websites.
This kills open Linux on the desktop (including Asahi Linux). It kills alternative browsers. It is a backdoor to kill ad blockers.
No. Just no. Please.
https://github.com/RupertBenWiser/Web-Environment-Integrity/blob/main/explainer.md
@lina@vt.social I love how people keep claiming that their arbitrary websites and apps need to know exactly the software you are running "for your own good" while even some bank apps (like the ones I use) don't care about attesting client-side integrity.