Live data from Hacker News

Apple confirms it's breaking iPhone web apps in the EU on purpose

techcrunch.com

201–210 of 829 posts

Re: Apple confirms it's breaking iPhone web apps in the EU on purpose

#201
post #16

Earlier quoted context omitted.

I’m going to be level with you: there is nothing so great about PWAs that they’re worth mandating or protecting by law in any jurisdiction and the EU doesn’t owe it to you to try. Web developers like them. That’s it, and their PWA advocacy completely disregards what a privacy and security nightmare they can be without proper safeguards, because this little device I carry around in my pocket is 1) always with me and 2…

There is little difference on iOS between a PWA and a website which has a WebKit view and hosts a website. The only reason PWAs were interesting on iOS was to get an app on iOS, while feeling relatively native, without paying Apple.

Apple can make security guarantees about their own rendering engine that they can’t for any other rendering engine.

It’s not about what PWAs are like in Safari, it’s about what they’re like in third-party browsers that have to by law be allowed to do whatever Safari can do with their own fully enabled rendering engines.

Re: Apple confirms it's breaking iPhone web apps in the EU on purpose

#202

Bad move from Apple. It's time to boycott iOS and move to FOSS alternatives, such as: AOSP, Ubuntu Touch, GNOME Mobile, KDE Plasma, Sailfish OS. Personally I am using both UBports and Sailfish OS and I appreciate the privacy they provide. As a possible workaround to fullscreen PWAs in iOS in the EU, I propose a convention to append some hash to the Web App Manifest start_url, e.g. #__pwa__, then set the default iOS w…

Nah, I'm good. I'm going to happily continue using my current phone. You do you though.

Re: Apple confirms it's breaking iPhone web apps in the EU on purpose

#203

Earlier quoted context omitted.

That’s not the point though because WebKit is already secured by Apple but if you have multiple blink related apps like Microsoft edge or brave or Firefox apple will have to audit those too and be on the hook if something breaks and then Apple will have to take the blame over a security oversight they aren’t responsible for.

So extending this logic to other platforms: if Chrome has a security bug on Windows... you believe people will blame Microsoft? And you think that would be valid justification for Microsoft pushing a "security update" that uninstalls all competing browsers and replaces them with Edge?

If you made a "Microsoft Windows Desktop Citibank App" from Edge, and then in stall Chrome, and the Uber app now uses Chrome, and a bug in Chrome lets someone steal your Citibank info, yes, the user probably would blame Microsoft as it was Windows software which made the Desktop app for Citibank.

And yes, if Windows had this feature and then Europe demanded it work like I described, Microsoft would be acting reasonably if it disabled the Desktop App feature in Europe.

Apple doesn't disable competing browsers, it just doesn't allow different web engines to underly the browsers. You can argue with that but it isn't the same as "uninstalling all competing browsers".

Re: Apple confirms it's breaking iPhone web apps in the EU on purpose

#204
post #124
post #104

Earlier quoted context omitted.

Heard. But we're going to entirely eliminate all PWAs because there might be an additional prompt added? Seems excessive/specious to me.

It's not one additional prompt, it's a class of prompts that could be exploited over and over again. A single site could trigger hundreds by sites popping up in the background each which trigger it, and then the user's home screen is full of fake PWAs with names like 'save money' 'in debt?' 'casino cash bucks' etc. Next you're developing mitigations, spam cleanup, etc. We've gone through this kind of thing before.

If that's a real potential problem, why doesn't this already happen on Android?

Why would this be exploited on the relatively small marketshare platform that is iOS, when in all those years this year not been a problem on the dominant platform?

Because it's not a real problem.

Re: Apple confirms it's breaking iPhone web apps in the EU on purpose

#205
I am on Apples side here. I have been a macOS and iPhone user for over a decade now, but have had Android devices and I use Windows for games and work.

I think what the EU has done to Apple is unfair. It is unfortunate in my opinion that they can’t just tell them to get stuffed. They have had to build probably 100-million LOCs just so EU have the right to pick their own browser, and yet Safari works just fine. In fact the great thing about Safari (and Apple knew this) is that compatibility was really good precisely because everyone on mobile was using the same browser. Now I’m just waiting to get those stupid “only supported in Chrome” pop ups on my mobile phone too..

Their core strategy has always been to keep cost low by supporting one hardware, one browser engine, one App Store. That’s how they kept things lean and integrated. The EU has forced them to take an approach that is fundamentally different to what made them successful. Some might say - who cares? It only affects the EU right? That’s to be seen.. we all might be affected globally from the security bugs caused by the unhardening of the OS required to conform to EU standards. And this huge code base is going to cost something to maintain and I doubt we won’t pay for that either.

Re: Apple confirms it's breaking iPhone web apps in the EU on purpose

#206
post #189

Earlier quoted context omitted.

> For Apple, ownership of the "trust problem" is an intrinsic part of "making good products". Yes, this might be true. And the majority of elected officials in EU fundamentally disagrees with that statement.

Yeah, as I’ve said before: the root problem here is that the EU wants to outlaw apples business model. People don’t think of it that way, they tell themselves all the reasons why that’s a good thing, but that’s ultimately what it is - a legislative solution to end the “android vs iOS” debate for all time. The argument is walled gardens shouldn’t exist, so the solution is to either legislate requirements that apple de…

Apple is free to switch to a less fascistic business model.

Re: Apple confirms it's breaking iPhone web apps in the EU on purpose

#207
post #31

Earlier quoted context omitted.

> malicious web apps could read data from other web apps and recapture their permissions to gain access to a user’s camera, microphone or location without a user’s consent. How is this even possible? It's shocking that these APIs even exist for any browser to use.

I assume you mean the "read data from other web apps" part. That'd be because there's (presumably) not a system-level way to launch a third-party browser in "web app mode", with all data siloed off per-PWA. Thus the only way they could currently make web apps work would be to launch the third-party browser and trust that it silos everything adequately itself internally. Apple could add a bunch of new APIs to support…

the bunch of new APIs might just be a containerized copy of the users browser? Seems very easy.

Re: Apple confirms it's breaking iPhone web apps in the EU on purpose

#208

Since the article doesn't actually repeat what Apple has said, here's what Apple says: == Begin quote == The iOS system has traditionally provided support for Home Screen web apps by building directly on WebKit and its security architecture. That integration means Home Screen web apps are managed to align with the security and privacy model for native apps on iOS, including isolation of storage and enforcement of sys…

Am I missing something? Couldn’t they allow you open PWAs in Safari, or fall back to opening a URL in another browser? Is there some part of the DMA which demands full feature parity?

>Is there some part of the DMA which demands full feature parity?

Very likely the EU wouldn't like them prioritizing their own browser for a feature

Re: Apple confirms it's breaking iPhone web apps in the EU on purpose

#209

Earlier quoted context omitted.

Why should we trust Apple for security in that context? Apple also provides all those functionalities via their proprietary API, which is not even audit-able. If Apple really believes in that argument, they should disable their own API as well.

[flagged]

Not everyone makes their own device choices. Or they didn't know the problems involved yet when they bought the device. Or there could be a thousand other reasons.

Re: Apple confirms it's breaking iPhone web apps in the EU on purpose

#210
post #124

Earlier quoted context omitted.

It's not one additional prompt, it's a class of prompts that could be exploited over and over again. A single site could trigger hundreds by sites popping up in the background each which trigger it, and then the user's home screen is full of fake PWAs with names like 'save money' 'in debt?' 'casino cash bucks' etc. Next you're developing mitigations, spam cleanup, etc. We've gone through this kind of thing before.

If that's a real potential problem, why doesn't this already happen on Android? Why would this be exploited on the relatively small marketshare platform that is iOS, when in all those years this year not been a problem on the dominant platform? Because it's not a real problem.

You mean like this? https://www.tomsguide.com/news/hackers-are-using-a-new-trick...

This stuff is part of the reason people commit to the Apple ecosystem despite its shortcomings.

While Android dominates globally, iOS has nearly 60% market share in the US and some other countries.

Post reply on HN