Live data from Hacker News

Alibaba’s UC Browser is dominating in Asian markets with lower-end smartphones

wsj.com

91–100 of 131 posts

Re: Alibaba’s UC Browser is dominating in Asian markets with lower-end smartphones

#91
post #26

There have been reports talking about security issues in UC Browser [0] for a while [1] now [2]. It was also removed from Google Play Store [3] (although temporarily). Kinda surprises me to see it as the 'dominant' browser. Maybe people are indifferent. [0] https://citizenlab.ca/2015/05/a-chatty-squirrel-privacy-and-... [1] https://citizenlab.ca/2016/08/a-tough-nut-to-crack-look-priv... [2] https://tech.blorge.com/20…

My experience casually observing how most people in coffee shops, even developers, leave their laptops unlocked as they go use the bathroom, or ask a random stranger to watch it for them, is that security in general is not as high of a concern for many as it should be.

Re: Alibaba’s UC Browser is dominating in Asian markets with lower-end smartphones

#92

If you’re in iOS, UC is a great way to pop out videos so you can, for example, watch a YouTube video while reading Hacker News. It also enables you to listen to just about any video in the background, when you switch to other apps.

> watch a YouTube video while reading Hacker News. The YouTube app also does that (although possibly only if you have YouTube Red?)

The YouTube app also has ads, which makes it a non-starter.

Re: Alibaba’s UC Browser is dominating in Asian markets with lower-end smartphones

#93

If you’re in iOS, UC is a great way to pop out videos so you can, for example, watch a YouTube video while reading Hacker News. It also enables you to listen to just about any video in the background, when you switch to other apps.

Firefox for Android does background playback too, and even provides media controls (exposing play/pause etc through the standard system API). Some sites may need the Video Background Play Fix [0] add-on. For popping out YouTube videos I use NewPipe, a FOSS Android YouTube client [1]. [0] https://addons.mozilla.org/en-US/firefox/addon/video-backgro... [1] https://f-droid.org/en/packages/org.schabi.newpipe/

Interesting. I've only ever tried YouTube but on my Oneplus, as soon as Firefox loses focus, playback stops.

Re: Alibaba’s UC Browser is dominating in Asian markets with lower-end smartphones

#94

Earlier quoted context omitted.

The question is like why those users do not use iPhone or Samsung Galaxy 7

You’re being disingenuous: people don’t use iPhones or Galaxies because they’re expensive. Browsers are free and it doesn’t cost money to change them.

And the people who author mobile Chrome all use iPhones or Galaxies or Pixels. It's about the dogfooding -- the people who write UC Browser use it on the same phones, mobile networks and websites that the users of UC Browser use, so it's written with their needs in mind.

Re: Alibaba’s UC Browser is dominating in Asian markets with lower-end smartphones

#95
post #26

There have been reports talking about security issues in UC Browser [0] for a while [1] now [2]. It was also removed from Google Play Store [3] (although temporarily). Kinda surprises me to see it as the 'dominant' browser. Maybe people are indifferent. [0] https://citizenlab.ca/2015/05/a-chatty-squirrel-privacy-and-... [1] https://citizenlab.ca/2016/08/a-tough-nut-to-crack-look-priv... [2] https://tech.blorge.com/20…

Very true. Amongst many other security flaws, UC Browser also does not support HSTS (headers or preload list) at all . That means that a connection made by UC Browser to any site can be man-in-the-middled and inspected or modified. As far as the Chinese government is concerned, however, this may be a feature rather than a bug. No one should be using UC Browser, full stop. It's pathologically insecure.

But it correctly supports HTTPS right? If so, then a MITM attack shouldn't be possible unless your system trusts a bad CA.

Re: Alibaba’s UC Browser is dominating in Asian markets with lower-end smartphones

#96
post #95

Earlier quoted context omitted.

Very true. Amongst many other security flaws, UC Browser also does not support HSTS (headers or preload list) at all . That means that a connection made by UC Browser to any site can be man-in-the-middled and inspected or modified. As far as the Chinese government is concerned, however, this may be a feature rather than a bug. No one should be using UC Browser, full stop. It's pathologically insecure.

But it correctly supports HTTPS right? If so, then a MITM attack shouldn't be possible unless your system trusts a bad CA.

sslstrip exists. HTTPS support doesn't matter if you don't get HTTPS.

Re: Alibaba’s UC Browser is dominating in Asian markets with lower-end smartphones

#97
post #50

UC Browser is now holding the web back by not adopting new standards like css-grid and flexbox. No version of UC supports these standards and with the rise of UC globally, developers are hesitant to use these standards as millions of users especially in India and China are left out. I know there are ways to configure fallback, but still.

Good thing about this is that those users are poor so most developers are free to ignore them.

Funny how people said that about China in the 70s.

Those who are last will later be first.

Re: Alibaba’s UC Browser is dominating in Asian markets with lower-end smartphones

#98
post #95

Earlier quoted context omitted.

Very true. Amongst many other security flaws, UC Browser also does not support HSTS (headers or preload list) at all . That means that a connection made by UC Browser to any site can be man-in-the-middled and inspected or modified. As far as the Chinese government is concerned, however, this may be a feature rather than a bug. No one should be using UC Browser, full stop. It's pathologically insecure.

But it correctly supports HTTPS right? If so, then a MITM attack shouldn't be possible unless your system trusts a bad CA.

Your carrier can preload any CA certificates it wants on the device and install them OTA at least on android devices.

iPhones are a bit more restrictive apps can install their own CA/trusted certificates but these are accessible to the only the apps iirc Apple manages the general trust store on its own with system update.

Re: Alibaba’s UC Browser is dominating in Asian markets with lower-end smartphones

#99
post #64

Earlier quoted context omitted.

Consider that Qihoo 360 used to do a lot of "security" work for IE. Given how shady Qihoo 360 was, Alibaba is definitely an improvement!

Qihoo 360 actually does have a lot of contribution to security, for one: they upstreamed a lot of patches to AOSP: https://source.android.com/s/results/?q=%22Qihoo+360%22

Why is this being voted down? Is there something I'm not aware of?

Re: Alibaba’s UC Browser is dominating in Asian markets with lower-end smartphones

#100
post #95

Earlier quoted context omitted.

Very true. Amongst many other security flaws, UC Browser also does not support HSTS (headers or preload list) at all . That means that a connection made by UC Browser to any site can be man-in-the-middled and inspected or modified. As far as the Chinese government is concerned, however, this may be a feature rather than a bug. No one should be using UC Browser, full stop. It's pathologically insecure.

But it correctly supports HTTPS right? If so, then a MITM attack shouldn't be possible unless your system trusts a bad CA.

History lesson incoming: https://www.youtube.com/watch?v=MFol6IMbZ7Y

The only effective way to get guaranteed security is with HSTS preloading. Anything short of that leaves you vulnerable to the linked attack, which dates way back to 2012.

Post reply on HN