Live data from Hacker News

Apple confirms it's breaking iPhone web apps in the EU on purpose

techcrunch.com

121–130 of 829 posts

Re: Apple confirms it's breaking iPhone web apps in the EU on purpose

#121

Earlier quoted context omitted.

That’s not the point though because WebKit is already secured by Apple but if you have multiple blink related apps like Microsoft edge or brave or Firefox apple will have to audit those too and be on the hook if something breaks and then Apple will have to take the blame over a security oversight they aren’t responsible for.

That assumes that Apple would be blamed for Edge/Brave/Firefox's security oversight.

They would absolutely be blamed by users for it.

Re: Apple confirms it's breaking iPhone web apps in the EU on purpose

#122
post #87

Earlier quoted context omitted.

I think PWA developers are going to be pretty unsympathetic to 'your PWA is going be available again in the EU at some unspecified time in the future, when some Apple product manager decides to prioritize it for a given year's roadmap and it's all in the interests of protecting users from unspecified privacy and security threats that nobody seems to be able to define'. Most importantly, the EU may feel the same way.

Well to correct you, my position is more “Apple might re-enable this” more than “will”, which from their perspective I’m guessing is even worse and they will be more unsympathetic to it. Personally I think Apple will, but I have enough doubts that I don’t want to make that claim. > Most importantly, the EU may feel the same way. That’s the rub. The EU has been arbitrarily writing new laws which mostly target foreign…

The arbitrary laws that the EU has been writing are the one of the last bulwarks consumers have against the creeping power of tech giants and these companies are making more money than ever in spite of regulation, so it doesn't seem to be affecting them too adversely.

Re: Apple confirms it's breaking iPhone web apps in the EU on purpose

#123
post #50

Earlier quoted context omitted.

From the (admittedly little) I know about how iOS handles security and the speed at which they responded this sounds like a pretty credible explanation to me. What makes you think it isn't?

Because that's literally what it says when you really read into it? They acknowledge that 1) Safari already has all the integrations required to support PWA securely and that 2) they can't be bothered to provide the same API's for third party browsers because it's not "practical". They built their PWA support in an anticompetitive manner assuming App Store & WebKit would be a monopoly forever, and now as a result the…

They built their PWA support with assumptions about how the application, OS, and WebKit were going to run. That's like saying, "Oh, Microsoft didn't build an API layer into Windows to support running X11 apps side by side with Win32 apps, so they were being monopolistic." No, you have limited engineering time and you make engineering tradeoffs. You don't need to design an interface layer and API and hooks between system components if your design doesn't call for it or doesn't need it.

> They built their PWA support in an anticompetitive manner assuming App Store & WebKit would be a monopoly forever, and now as a result the baby is going out with the bathwater.

They built it in such a way that it was sustainable and sensible for the time it was made (iOS 2.0). That's a really long time ago in the software world. More than a dozen versions of the OS have been built on top of this. Saying "they should have just figured it out back then" is completely ignoring the reality of what was offered by the OS and the mobile space entirely at the time.

Now laws have been passed that say "you must provide alternatives." OK. They can choose to spend an ungodly amount of time refactoring the OS to undo 16 revisions of the OS of assumptions for zero benefit for the company, or they can say "Sorry we can't comply with that for your market."

It sucks. But it's a result of reasonable business decisions and their evolutions from a significantly different era.

Re: Apple confirms it's breaking iPhone web apps in the EU on purpose

#124
post #104
post #85

Earlier quoted context omitted.

You don't want random processes firing off permissions prompts, you want them to remain meaningful to users on a platform else they'll get prompt fatigue. Think of all the prompts users see and just press 'ok' to.

Heard. But we're going to entirely eliminate all PWAs because there might be an additional prompt added? Seems excessive/specious to me.

It's not one additional prompt, it's a class of prompts that could be exploited over and over again. A single site could trigger hundreds by sites popping up in the background each which trigger it, and then the user's home screen is full of fake PWAs with names like 'save money' 'in debt?' 'casino cash bucks' etc. Next you're developing mitigations, spam cleanup, etc. We've gone through this kind of thing before.

Re: Apple confirms it's breaking iPhone web apps in the EU on purpose

#125

Earlier quoted context omitted.

Why should we trust Apple for security in that context? Apple also provides all those functionalities via their proprietary API, which is not even audit-able. If Apple really believes in that argument, they should disable their own API as well.

[flagged]

Your argument might be only applicable to some sort of fundamentalists. Most people in the real world make informed decision based on lots of different factors. I'm pointing out that Apple speaks like a security fundamentalist but doesn't act like such. They should choose either one of being fundamentalist or realist, not cherrypicking whatever traits that work in favor of themselves.

Re: Apple confirms it's breaking iPhone web apps in the EU on purpose

#126

Earlier quoted context omitted.

Thanks for posting that. I'm no iOS expert but it actually sounds like a pretty reasonable explanation. It's at least good to hear Apple's side here, and more knowledgeable commenters here can weigh in as to whether it really does seem genuine.

Sure it's reasonable ... because of course all these browsers don't have a security model and just allow web apps to do whatever they want. This is essentially saying no-one can build a secure browser.

I know at least Firefox has per-site permissions for location, webcam, and microphone access. Is it a correct interpretation that Safari on iOS does not have this feature?

Re: Apple confirms it's breaking iPhone web apps in the EU on purpose

#127
post #112

Earlier quoted context omitted.

Could you explain why?

I don't think believing why the most valuable company in the world with the highest and thickest walls around its garden, and a track record of not playing nice with others, is doing this, requires much explanation except that they want to kill the possibility of anyone bypassing the toll gate to the said garden.

Apple could support PWAs and enforce the same Core Technology Fee they do on them as they do for 3p distributed apps, so this argument makes no sense.

Re: Apple confirms it's breaking iPhone web apps in the EU on purpose

#128
post #92

Earlier quoted context omitted.

As an end user who has been fucked over by the other side (MS/Google/crappy app vendors), I am behind their decision. If I was not I can choose to leave. I know this is a divisive comment. Please see my further extrapolation in a child comment.

How does removing web apps help anything? To me it seems like part of a ploy to create backlash against this law by removing features

It's a move against the third party browser engines which have been the bane of my existence from a security perspective on other platforms. For example, the about box in an Android app bundled a whole different browser engine which circumvented device policy entirely and allowed data to be exfiltrated. This app change was delivered in an update by clueless or lazy developers. This is not possible on iOS due to the platform restrictions.

In this case they have to change the integration and sandbox model to allow the security policy to remain intact for people who want and need it. That breaks a few things but it stops the integration from being used for exfiltration among other things.

Note that they're not completely breaking it, just ensuring that the security model stays intact when browser engines have to coexist on the same device. That means sacrificing some convenience for security.

Re: Apple confirms it's breaking iPhone web apps in the EU on purpose

#129
post #79

Earlier quoted context omitted.

You have to trust someone if you're using a computing device connected to the Internet. The point of being in Apple ecosystem is that you trust Apple, and then (supposedly) you can not trust anyone else. To many that's a very strong proposition.

> The point of being in Apple ecosystem is that you trust Apple, This seems to be over-generalization? Users are using Apple devices because those are good products, not because they want to delegate every single trust problem to the Apple ecosystem. That might be a great proposition for people like you, but there is a significant number of people who consider it a compromise rather than a value.

>there is a significant number of people who consider it as a compromise rather than a value.

I suspect that from Apple's perspective, it is definitively not a significant number.

For Apple, ownership of the "trust problem" is an intrinsic part of "making good products".

Re: Apple confirms it's breaking iPhone web apps in the EU on purpose

#130

Earlier quoted context omitted.

That’s not the point though because WebKit is already secured by Apple but if you have multiple blink related apps like Microsoft edge or brave or Firefox apple will have to audit those too and be on the hook if something breaks and then Apple will have to take the blame over a security oversight they aren’t responsible for.

That assumes that Apple would be blamed for Edge/Brave/Firefox's security oversight.

Why wouldn't they be? Especially considering their existing reputation in consumers minds for security and reliabilty?
Post reply on HN