Live data from Hacker News

Apple confirms it's breaking iPhone web apps in the EU on purpose

techcrunch.com

151–160 of 829 posts

Re: Apple confirms it's breaking iPhone web apps in the EU on purpose

#151

Earlier quoted context omitted.

Without this type of isolation and enforcement, malicious... camera, microphone or location ... Browsers ... 30 some million lines of code in chromium browsers. Thats bigger than the linux kernel. The HN crowed might not LIKE apples response but they have a very defensible position. Edit: Its not like we haven't seen this play out on the desktop recently: https://www.theverge.com/24054329/microsoft-edge-automatic-c..…

Why should we trust Apple for security in that context? Apple also provides all those functionalities via their proprietary API, which is not even audit-able. If Apple really believes in that argument, they should disable their own API as well.

Using an Apple device requires trust in Apple even if you run a 3rd party operating system let alone a 3rd party application on their OS.

Re: Apple confirms it's breaking iPhone web apps in the EU on purpose

#152

Earlier quoted context omitted.

Sure it's reasonable ... because of course all these browsers don't have a security model and just allow web apps to do whatever they want. This is essentially saying no-one can build a secure browser.

I know at least Firefox has per-site permissions for location, webcam, and microphone access. Is it a correct interpretation that Safari on iOS does not have this feature?

Safari has those features.

Re: Apple confirms it's breaking iPhone web apps in the EU on purpose

#153
On the point of trusting (big) Apple to keep us safe.

This was linked in a similar discussion today. Either they knowingly provide backdoors for state actors or they are being so incompetent that it is laughable. Zero interaction remote exploit of hardware features designed to circumvent their own security measures? Why ?

Seriously, find someone worthy of your trust, because that isn't Apple

https://www.kaspersky.com/about/press-releases/2023_kaspersk...

Re: Apple confirms it's breaking iPhone web apps in the EU on purpose

#154

Earlier quoted context omitted.

The technical justification are bullshit. They simply could ask browser vendor to follow strict rules, that they can check themselves. This is not like they would have to verify dozens of browsers every day. Only a few per months, top.

They are not saying it is impossible, only that they have not done it. How long do you think it will take to spin up such a review and certification program? How much will it cost, and how many sales will they lose because of the lack of this feature in the EU?

There will already be a review and certification program for third party browsers that want the required entitlements (https://developer.apple.com/support/alternative-browser-engi...), so why don't you ask Apple?

Re: Apple confirms it's breaking iPhone web apps in the EU on purpose

#155
post #144

Earlier quoted context omitted.

They ain't never been cool. The shit practices they are trying to defend were there from day 1 and are baked into their DNA. Treating their users like stupid animals that don't know what's good for them is what they do. And they will fight tooth and nail to continue to do it. Even as EU tries to kick their predatory ways out of them. To think there's a hardware thing in 2024 that does not allow its owner to compile a…

Most users are stupid though. Reminder that a US congressman once grilled Google's CEO about whether Google was tracking his iPhone's precise location. And this one was smart enough to con his way into Congress. "I have an iPhone, and if I move from here and go over there and sit with my Democrat friends, which would make them real nervous, does Google track my movement?" -- Ted Poe https://www.cnet.com/tech/mobile/g…

> "I have an iPhone, and if I move from here and go over there and sit with my Democrat friends, which would make them real nervous, does Google track my movement?" -- Ted Poe

The thing is, if this was a real life situation, and he would seek out and politically collaborate with/stalk and listen in on his Democrat friends, there's a good chance Google would know. Not because of a digital AirTag Google installed on his phone, but because of the tracking and data analysis Google has access to.

The indirection and hidden mechanisms Google (and other data trading companies) use are impossible to comprehend for normal people, and they're banking on that to continue being allowed to do that.

Re: Apple confirms it's breaking iPhone web apps in the EU on purpose

#156
post #85
post #17

Earlier quoted context omitted.

tbh, I thought the summary in techcrunch was much easier to read and concise. >Browsers also could install web apps on the system without a user’s awareness and consent. Couldn't this be entirely solved with an OS permission-like prompt "are you sure you want [progressive web app name] added to home screen?"

You don't want random processes firing off permissions prompts, you want them to remain meaningful to users on a platform else they'll get prompt fatigue. Think of all the prompts users see and just press 'ok' to.

"Yes, allow install (this time)" / "No, don't allow install (this time)" / "No, and never prompt me again"?

iOS has been doing something very similar and it's arguably worked pretty well.

Re: Apple confirms it's breaking iPhone web apps in the EU on purpose

#158

Earlier quoted context omitted.

Nobody can build a secure browser.

Truer words have not been spoken! Maybe only second to nobody can build a secure baseband.

Security is well achievable, absolute security is not. Somehow almost everyone seems to grasp that intuitively, but a subset of IT keeps pretending they're the same thing.

Re: Apple confirms it's breaking iPhone web apps in the EU on purpose

#159
post #59

Earlier quoted context omitted.

Or they could just not.

They could develop APIs to support alternate browser engines but could not allow them to install sandboxed web apps on the system? Like all other OSes do, including macOS? How surprising.

The whole point is that doing so would privilege safari over other browsers, which is illegal.

Re: Apple confirms it's breaking iPhone web apps in the EU on purpose

#160

Is there anything we can actually do to push back on this? I get we can long term just not buy their products, but it feels like there needs to be more urgent action then that.

I don't think so. Either the EU takes action (assuming what Apple does is illegal, though I doubt it) or you'll have to vote with your wallet.

Perhaps your best bet would be to loudly proclaim Apple's user-hostile behaviour as the reason you're switching to another brand of phone, so non-tech people also learn about Apple's hissy fit, but I doubt it'll do much to their bottom line.

Post reply on HN