Live data from Hacker News

Did Reddit just destroy mobile browser access?

reddit.com

611–620 of 658 posts

Re: Did Reddit just destroy mobile browser access?

#611

Earlier quoted context omitted.

> apps are roughly the opposite of that Although I broadly agree with this assessment, I'd just like to add a slight nuance that, at least in my view, it's specifically _app store apps_ that are roughly the opposite. You can still, for example, install random APKs (on Android, I doubt Apple has anything similar) if you're so inclined, so they can be as user-centric as you want. It's just that the major manufacturers…

I would still say that even FOSS apps off F-Droid are less user-centric than the web. They're more likely to respect the user, for sure, than even most web apps. And a user who is comfortable with code can always fork them and customize them. But the barrier to entry for a custom experience is much higher on an app than it is on the web. Browser extensions are highly accessible to many people and can allow tweaking t…

My thoughts exactly. I do lots of "tinkering" with my web experience and have a few open source apps that I build and install, and the barrier of entry on apps is way higher than for websites. Even for an app that is open and friendly, it's still a major undertaking to get a dev env setup and debug/tinker. And once you do, auditing the app to see what it does is further difficult. With the web you don't even need a dev env, and an extension like uMatrix makes it pretty easy to audit the site and see what it's doing/loading.

I'm to the point where I boycott apps. I will only use an app if there's a real benefit to me for doing so, such as podcasts and music and offline functionality or those that use hardware features.

Re: Did Reddit just destroy mobile browser access?

#612
post #3

There is only one appropriate, effective response to disrespect, and that is to not reward the offending party. I made it a matter of principle to not use the Reddit app. Even if they removed all ads and made it an acceptable user experience, I'll never use the app as long as they are harassing me about it. It's simple. Don't reward bad behavior. Sometimes, denying obnoxious people something they want means denying y…

man I did this with facebook and it obliterated my social connections. it doesn’t make sense from a micro perspective, game theory sucks man i installed instagram in december and it’s so much easier to make friends. I feel in touch with what’s going on in the community

I would've agreed with you 5 years ago. However, my weak connections seem to have thinned themselves out—the people I'd only ever see on FB have gotten bored and stopped posting there. Everyone else, I have other means of contacting.

Re: Did Reddit just destroy mobile browser access?

#613
post #610

Earlier quoted context omitted.

HTTPS means the network connections between the app and the backend are opaque to third parties including the user. Certificate pinning means you cannot insert yourself as the backend and/or MITM the requests. The app will only communicate directly with the owner of the private key it was pinned to. Depending on the app and OS, it may be more or less easy to change the app to remove/crack the pinning. In general, if…

> HTTPS means the network connections between the app and the backend are opaque to third parties including the user. It means the payload is. HTTPS alone doesn't have any special considerations for hiding the domain, which I think is visible so the request can be routed correctly. And since a lot of ad-blocking is based on domain, that ought to work.

You're not wrong, but ads are already moving to a different model with either first-party URLs or random ones that are difficult or impossible to enumerate to get around ad blocking. With Apple's new thing that's going to bring the reckoning even sooner (sigh). This technique is much harder and won't last very long I'm afraid.

Re: Did Reddit just destroy mobile browser access?

#614

Earlier quoted context omitted.

I wouldn't call patching a binary very easy, especially since our point of reference was installing an ad blocker extension in the browser. Also, it takes more than one byte if the binary is obfuscated and full of various ways to check that it hasn't been tampered with.

> I wouldn't call patching a binary very easy it's even easier than that as all apps (except native ones) will be using the java TrustManager interface > Also, it takes more than one byte if the binary is obfuscated but they can't hide the calls into TrustManager a small utility could automatically take in the APK, patch out the calls and return the fixed APK for you (would probably work for 99% of apps out of the bo…

> it's even easier than that as all apps (except native ones) will be using the java TrustManager interface

Is this required? i.e. do all apps have to use the TrustManager interface to accomplish cert pinning, or is that merely the official way?

Re: Did Reddit just destroy mobile browser access?

#615
post #429
post #357

There's something that I don't get about forcing mobile browser users into mobile apps - how does it make sense for the company? They're forcing themselves into a walled garden, where the gardener takes a hefty "app store tax" on your revenues and has countless levers to force you to style the app how it suits their interests, not yours. For some apps, this might still be the best way to gain traction. But if have al…

I work at a company trying to get more people into our app. The logic is completely flawed: "we want more engagement, app users show more engagement than web users, so if we get more users from web into the apps we'll get more engagement". It's obviously completely flawed but the product people and analytics department don't seem to get it. At least we aren't doing hostile stuff to get people into the apps, yet.

I'm generally not cynical about human motivations, but after seeing many of these things and how thoroughly the "internal propaganda" at tech companies works, I think those are just the reasons they tell themselves. The real reason is the control and the deep analytics that you can get from mobile apps. Plus having an app icon which really does boost engagement, but nowhere enough to justify on its own.

Re: Did Reddit just destroy mobile browser access?

#616
post #343
post #318

Earlier quoted context omitted.

> time sink without any value Indeed, time is little and precious and should be spent wisely. Very virtuous of you. > hobby specific subreddits have wealth of information Ah the virtue of doing hobbies > New posts are 99% attention seeking posts without value Only the most virtuous of us completely avoid the trap of attention seeking, well done. > political virtue signalling Ah the biggest virtue of all, avoiding vir…

Some of your points might have merit, but your tone is very off putting.

[dead]

Re: Did Reddit just destroy mobile browser access?

#617

Earlier quoted context omitted.

It could be worse. If you get to ‘there I am’, it’s too late.

To say “there I am”, you’d need to possess a level of self awareness that would prevent you from acting in a way that would make lampooning you fun

Or you could literally be some of the people from the Techcrunch Disrupt bit. Which is what I literally knew people from.

Re: Did Reddit just destroy mobile browser access?

#618

Earlier quoted context omitted.

> I wouldn't call patching a binary very easy it's even easier than that as all apps (except native ones) will be using the java TrustManager interface > Also, it takes more than one byte if the binary is obfuscated but they can't hide the calls into TrustManager a small utility could automatically take in the APK, patch out the calls and return the fixed APK for you (would probably work for 99% of apps out of the bo…

> it's even easier than that as all apps (except native ones) will be using the java TrustManager interface Is this required? i.e. do all apps have to use the TrustManager interface to accomplish cert pinning, or is that merely the official way?

> Is this required?

well, Java is Turing complete, so you could completely re-implement TLS yourself instead of using the API that comes with the platform

in practice no-one is going to do that

Re: Did Reddit just destroy mobile browser access?

#619
post #605

Earlier quoted context omitted.

Star Wars: The Old Republic is probably the biggest example. Edit: Rift is probably another good example, though less high-profile than SWTOR.

Lord of the Rings Online, Archeage, Tera, Wildstar, Kingdoms of Analur, City of Heroes, The Matrix Online are all from that era of every MMO trying to be the WoW killer and needing to supplant WoW for their business model to work. What's funny is WoW has declined so much but is still clearly a viable business, but I'm sure things like LOTRO, City of Heroes and Tera peaked at higher levels than current WoW. But the Wo…

Yeah, it's been so long since I thought about some of these that I honestly was blanking on many of them.

Re: Did Reddit just destroy mobile browser access?

#620

Earlier quoted context omitted.

> Users can't block ads in an app. Yeah, they can. By which I mean, they can do it right away , for the official Reddit app: – https://revanced.app/patches?pkg=com.reddit.frontpage – https://revanced.app/download Or, for even less work, you can just use a pre-patched APK with the ads removed: https://github.com/revanced-apks/build-apps/releases No need for root access nor flimsy DNS solutions.

any recommended links to learn more about revanced? the best I can find from their website is that they're a continuation of the "vanced" project but it doesn't say what that was and I haven't had luck on google. It's clear that they have something to do with providing patched apps, but is revanced a framework? is it a library? is it a person or group that does the patching?

It's a community-driven collection of patches[0] for popular Android apps, supported by a patching framework which includes patch management software (ReVanced Manager[1]).

The documentation[2] is very sparse right now.

[0] https://github.com/revanced/revanced-patches

[1] https://github.com/revanced/revanced-manager

[2] https://github.com/revanced/revanced-documentation

Post reply on HN