Live data from Hacker News

Apple confirms it's breaking iPhone web apps in the EU on purpose

techcrunch.com

61–70 of 829 posts

Re: Apple confirms it's breaking iPhone web apps in the EU on purpose

#61
post #36

Earlier quoted context omitted.

Without this type of isolation and enforcement, malicious... camera, microphone or location ... Browsers ... 30 some million lines of code in chromium browsers. Thats bigger than the linux kernel. The HN crowed might not LIKE apples response but they have a very defensible position. Edit: Its not like we haven't seen this play out on the desktop recently: https://www.theverge.com/24054329/microsoft-edge-automatic-c..…

But the plain browser already can request camera permissions, in a bad security situation a site that didn't request it still receives it from the browser's system level request. This is just Apple wanting to avoid people being able to develop a platform on top of their platform without paying a tax.

That’s not the point though because WebKit is already secured by Apple but if you have multiple blink related apps like Microsoft edge or brave or Firefox apple will have to audit those too and be on the hook if something breaks and then Apple will have to take the blame over a security oversight they aren’t responsible for.

Re: Apple confirms it's breaking iPhone web apps in the EU on purpose

#62

Earlier quoted context omitted.

> malicious web apps could read data from other web apps and recapture their permissions to gain access to a user’s camera, microphone or location without a user’s consent. How is this even possible? It's shocking that these APIs even exist for any browser to use.

>> How is this even possible? It's shocking that these APIs even exist for any browser to use. https://www.theverge.com/24054329/microsoft-edge-automatic-c... Ask MS, they already did it.

This is completely irrelevant to the discussion, there is no sandboxing on PC.

Re: Apple confirms it's breaking iPhone web apps in the EU on purpose

#63
post #46

Earlier quoted context omitted.

Not if the alternative is allowing other browsers to install them without a privacy and security architecture in place first. Even if Apple thinks it’s worth doing, that takes time, and web developers aren’t worth prioritizing for them when they have a lot of other ground to cover building out a new system of APIs and entitlements to comply with the DMA’s other requirements.

The user is warned already on the App Store that installing apps from third-parties comes with certain risks via 'scare screens'. There's no reason they can't do the same for PWAs.

They probably will if they ever re-enable it in the EU, but they also built out over 600 new APIs and an accompanying system of entitlements to go with that scare sheet such that even if it’s “riskier”, they’re not just throwing up their hands and saying “alright devs, we scared them a little, so now go do whatever the hell you want”.

EDIT: I should also add that of those 600, that includes APIs Apple built out specifically for third-party browsers.

Re: Apple confirms it's breaking iPhone web apps in the EU on purpose

#65

Since the article doesn't actually repeat what Apple has said, here's what Apple says: == Begin quote == The iOS system has traditionally provided support for Home Screen web apps by building directly on WebKit and its security architecture. That integration means Home Screen web apps are managed to align with the security and privacy model for native apps on iOS, including isolation of storage and enforcement of sys…

Without this type of isolation and enforcement, malicious... camera, microphone or location ... Browsers ... 30 some million lines of code in chromium browsers. Thats bigger than the linux kernel. The HN crowed might not LIKE apples response but they have a very defensible position. Edit: Its not like we haven't seen this play out on the desktop recently: https://www.theverge.com/24054329/microsoft-edge-automatic-c..…

Why should we trust Apple for security in that context? Apple also provides all those functionalities via their proprietary API, which is not even audit-able. If Apple really believes in that argument, they should disable their own API as well.

Re: Apple confirms it's breaking iPhone web apps in the EU on purpose

#66
post #58

Since the article doesn't actually repeat what Apple has said, here's what Apple says: == Begin quote == The iOS system has traditionally provided support for Home Screen web apps by building directly on WebKit and its security architecture. That integration means Home Screen web apps are managed to align with the security and privacy model for native apps on iOS, including isolation of storage and enforcement of sys…

[flagged]

It's unethical to spread misinformation. Please don't do that.

Re: Apple confirms it's breaking iPhone web apps in the EU on purpose

#68
post #58

Earlier quoted context omitted.

[flagged]

It's unethical to spread misinformation. Please don't do that.

What did you think Triangulation was about? Its literally a backdoor that requires a secret key to use.

Claiming that it doesn't exist is misinformation

Re: Apple confirms it's breaking iPhone web apps in the EU on purpose

#69
post #63

Earlier quoted context omitted.

The user is warned already on the App Store that installing apps from third-parties comes with certain risks via 'scare screens'. There's no reason they can't do the same for PWAs.

They probably will if they ever re-enable it in the EU, but they also built out over 600 new APIs and an accompanying system of entitlements to go with that scare sheet such that even if it’s “riskier”, they’re not just throwing up their hands and saying “alright devs, we scared them a little, so now go do whatever the hell you want”. EDIT: I should also add that of those 600, that includes APIs Apple built out speci…

I think PWA developers are going to be pretty unsympathetic to 'your PWA is going be available again in the EU at some unspecified time in the future, when some Apple product manager decides to prioritize it for a given year's roadmap and it's all in the interests of protecting users from unspecified privacy and security threats that nobody seems to be able to define'. Most importantly, the EU may feel the same way.

Re: Apple confirms it's breaking iPhone web apps in the EU on purpose

#70
AAPL's recent behavior has really degraded the brand for me personally.

Like I won't be buying the Vision Pro because I'm not really sure I want to get further locked into their ecosystem if they're this hostile towards the will and rights of the people who buy their products.

Post reply on HN