It depends how you look at it and this twitter post takes only one perspective. Mine is different. The security I'm interested in for my use case is that there is one egress point from the operating system as far as a browser goes. That means I don't have apps shipping their own browser engines to circumvent the system block lists and screen time whitelist controls. Also comparing CVE rates is pointless as that's exp…
That means I don't have apps shipping their own browser engines to circumvent the system block lists and screen time whitelist controls. The mechanism for banning third-party browsers is rejection by the App Store reviewer, correct? Supposing Apple allowed third-party browsers but disallowed embedded browsers in non-browser apps, how would this security model change at all?
Apple's claim is that it bans other browsers for security
11–20 of 593 posts
Re: Apple's claim is that it bans other browsers for security
#12So they are saying that they can't make a secure sandbox? Why is running other applications somehow secure?
fwiw: the App Store also prohibits JITed code or in general code pulled in after app publishing. I guess the idea is that (at least in theory) that Apple sees all code that an app runs.
But I think they draw the line at native (read: unsafe) code, which, is not totally unreasonable
Re: Apple's claim is that it bans other browsers for security
#13So they are saying that they can't make a secure sandbox? Why is running other applications somehow secure?
fwiw: the App Store also prohibits JITed code or in general code pulled in after app publishing. I guess the idea is that (at least in theory) that Apple sees all code that an app runs.
[1]: https://apps.apple.com/us/app/pyto-python-3/id1436650069
Re: Apple's claim is that it bans other browsers for security
#14Chrome has dominance similar to IE at the height of its popularity.
Whatever you think of their decisions, Apple is the only thing stopping a 90%+ Chrome web. (Note: not why they’re doing it, just a side effect)
People keep arguing Apple is being anti-competitive. But no one seems to recon with the possible consequences of what they’re asking for. And I fear we may get a pyrrhic victory if these groups/governments keep pushing.
No, I don’t know a good solution. But I don’t think letting Chrome totally own the web is a good outcome.
Re: Apple's claim is that it bans other browsers for security
#15Earlier quoted context omitted.
fwiw: the App Store also prohibits JITed code or in general code pulled in after app publishing. I guess the idea is that (at least in theory) that Apple sees all code that an app runs.
There are development environments that run on the device. For example, Pyto[1] is for developing and running Python code. [1]: https://apps.apple.com/us/app/pyto-python-3/id1436650069
Re: Apple's claim is that it bans other browsers for security
#16Re: Apple's claim is that it bans other browsers for security
#17I’m going to ignore the security angle and post my big fear. Chrome has dominance similar to IE at the height of its popularity. Whatever you think of their decisions, Apple is the only thing stopping a 90%+ Chrome web. (Note: not why they’re doing it, just a side effect) People keep arguing Apple is being anti-competitive. But no one seems to recon with the possible consequences of what they’re asking for. And I fea…
We've written about the harms in detail here: https://open-web-advocacy.org/files/OWA%20-%20Bringing%20Com...
Re: Apple's claim is that it bans other browsers for security
#18So they are saying that they can't make a secure sandbox? Why is running other applications somehow secure?
Re: Apple's claim is that it bans other browsers for security
#19So they are saying that they can't make a secure sandbox? Why is running other applications somehow secure?
fwiw: the App Store also prohibits JITed code or in general code pulled in after app publishing. I guess the idea is that (at least in theory) that Apple sees all code that an app runs.
Re: Apple's claim is that it bans other browsers for security
#20And good lord this line of argumentation is extremely disingenuous even if you think the actual analysis is good (counting CVEs is not exactly the best measure). One because no one except nerds are going to switch browsers in response a random CVE and two because it doesn't even establish what Apple actually means by security and instead goes off on a rant "well if Apple really cared about [my personal view of] security you would blah blah" -- literally zero effort to understand the opposing view or evaluate other possible ways of addressing the security concerns.
But ya know, "Safari lags behind other browsers in RCE mitigations and mean time to patch" doesn't grab headlines and doesn't prescribe a single solution that is also motivated by more than just security ;)