Live data from Hacker News

Apple's whitelist of the 250k auto-completable domains in iOS

cdn.smoot.apple.com

31–40 of 182 posts

Re: Apple's whitelist of the 250k auto-completable domains in iOS

#31

My competitor is in this list and I'm not, even though my site is more popular. There even are some small Dutch campings, municipalities and regional football clubs on this list. It's a strange list for sure.

My website is in there but with a typo (people often make that mistake) :( The website with typo doesn't exist.

Can you buy the domain and redirect them?

Re: Apple's whitelist of the 250k auto-completable domains in iOS

#32
post #14

Assuming this is a list for Apple's autocomplete feature on Safari and other apps, what damage can a hacker do if they were to maliciously update this file?

Homoglyph Attacks come to mind. Replace legitimate domains like nytimes.com with ones that look identical but lead to phishing sites. (The hacker would have to build those convincing phishing sites as well, of course...)

Re: Apple's whitelist of the 250k auto-completable domains in iOS

#34
post #14

Assuming this is a list for Apple's autocomplete feature on Safari and other apps, what damage can a hacker do if they were to maliciously update this file?

Not much if you use a password manager that checks the domain before auto filling and/or use U2F tokens as your 2nd factor.

The threat model isn’t too different from other things that can happen if a malicious user is on the same network as you. The scale would be different though.

Re: Apple's whitelist of the 250k auto-completable domains in iOS

#36
post #33
post #30

Quoted post unavailable.

> The more I learn about open source the more i see their point.. Stallman is consistently mocked and diminished, but he is also consistently right.

...and we see what happens when we do the things he warns about in a consistent manner, yet people still continue to mock and ignore him.

Sad.

Re: Apple's whitelist of the 250k auto-completable domains in iOS

#37
post #30

Quoted post unavailable.

> 2. Crippled and never let PWAs fully work because security and battery. How are PWAs insecure?

That one stuck out at me as well. The real reason is that it's a threat to their walled garden app store.

Re: Apple's whitelist of the 250k auto-completable domains in iOS

#40
post #30

Quoted post unavailable.

1. Killed flash because it's insecure and drains battery.

2. Crippled and never let PWAs fully work because security and battery.

Your hypothesis raises two slightly ugly questions - "Why could't Apple make those things work on their platform in the past?" and "What's changed in the security and battery aspects of PWAs that means Apple are now moving to support them?" If you look at the changes for iOS 15.4 there are a lot of things that improve support for PWAs. If you're right, and the reasons that they didn't support PWAs in the past are security and battery life, then the new changes in iOS presumably mean that Apple is intentionally crippling their platform's security to support PWAs. That's a scary move, and should make every Apple device owner somewhat concerned.

I think it's significantly more likely that the reason why they killed Flash and haven't supported PWAs is because they represented a threat to the App store, but now Apple believe that supporting PWAs doesn't do that (either because they believe PWAs can't compete with apps, or because they believe users will choose a platform that supports PWAs). There was nothing about PWAs that meant they couldn't be secure, or that they had to drain the device battery. Apple just chose not to support the features because they didn't want to, and not because they couldn't.

Post reply on HN