







It's just a "proposal," but it's also being prototyped inside Chrome right now.
Google can keep its Chrome browser but will be barred from exclusive contracts | Hacker News
WebMCP | AI on Chrome | Chrome for Developers
WebMCP has two APIs that allow browser agents to take action on behalf of the user.

Web Crypto’s SubtleCrypto: A Masterclass in Developer Hostility and How It Strangles the Modern Web
Not Subtle, Just Sabotage — An API Against the Web
Building a Browser-Native Verification Stack for Tinfoil
Learn how we built a browser-based confidentiality and integrity verifier with implementations of browser-native Sigstore and TUF libraries.

CrabTrap: Secure Agents in Production
CrabTrap is an LLM-as-a-judge HTTP proxy to secure agents in production. It intercepts and audits AI agent requests in real time. Try it on GitHub now.
CAPSEM: Contextual Agent Privacy and Security Manager
Contribute to google/capsem development by creating an account on GitHub.
Introducing WEBCAT: Web-based Code Assurance and Transparency
In this post, we introduce Web-based Code Assurance and Transparency, a project that supports verifiable in-browser code for single-page browser applications. Along with this post, we are publishing the WEBCAT project repository; follow-up posts will provide more detailed information.

GrapheneOS (@GrapheneOS@grapheneos.social)
Apple and Google are gradually expanding their use of hardware-based attestation. They're convincing a growing number of services to adopt it. Google's Play Integrity API and Apple's App Attest API are very similar. Apple brought it to the web via Privacy Pass, which Google intends on doing too.
Protecting web applications via Envoy OAuth2 filter
Putting our long-tenured investment teams on the line to earn the trust of institutional investors.
Powerful PWAs | ChromeOS | Google for Developers
New and upcoming features coming to the web to superpower your apps, plus a checklist to help you track adding them to your app.

Titan in depth: Security in plaintext | Google Cloud Blog
While there are no absolutes in computer security, we design, build and operate Google Cloud Platform (GCP) with the goal to protect customers' code and data. We harden our architecture at multiple layers, with components that include Google-designed hardware, a Google-controlled firmware stack, Google-curated OS images, a Google-hardened hypervisor, as well as data center physical security and services.

Web Install API Dev Spec
Web Install API Dev Design Spec Author: Amanda Baker, Diego Gonzalez, Kristin Lee, Lia Hiscock Spec status: Last updated: Links: Explainer | Chrome Status | CR bug | UX changes review doc Feature Overview Introduction Goals Non-goals Concepts Interfaces and Interactions JS API changes navig...
Improving the trustworthiness of Javascript on the Web
Today, there's no way to audit a site’s client-side code as it changes, making it hard to trust sites that use cryptography. We preview a specification we coauthored that adds auditability to the web.

Chrome looks set to ship an LLM Prompt API to the web platform. At Mozilla, we oppose this API. We feel it has a large interoperability risk, and Google imposing T&Cs on a web API sets a dangerous precedent. Full details: github.com/mozilla/standards-positions/i…
Prompt API · Issue #1213 · mozilla/standards-positions
github.com