Live data from Hacker News

Apple confirms it's breaking iPhone web apps in the EU on purpose

techcrunch.com

311–320 of 829 posts

Re: Apple confirms it's breaking iPhone web apps in the EU on purpose

#311

Earlier quoted context omitted.

Have to agree (disclaimer, haven't been an iPhone user since the 4). Suddenly allowing all browsers to have those kinds of native permissions, even with massive testing, sounds like a security nightmare. You're introducing an entire extra dimension for security holes, given how much trust people place in their phones. This doesn't sound at all the same as allowing other engines for use inside browsers, based on both…

Browsers support PWAs on the desktop platforms without there being a security nightmare, and while I'm sure there are some permissions that could be a problem, things like the camera and microphone are managed on the desktop without issue. Is there some flaw in iOS that makes it harder to secure than the desktop?

iOS was never conceived of as something which would run arbitrary code that could access system-level data (the siloed data). So basically the situation exists by design, and in order to achieve security when enabling PWAs from other browser engines, they'd have to add another layer of security that currently doesn't exist (since they never had to trust anyone's code but their own).

So... yes, there is apparently a lack of security there, but that's because the layer in question was never intended to be anything but proprietary until this ruling.

Re: Apple confirms it's breaking iPhone web apps in the EU on purpose

#312
post #304

Earlier quoted context omitted.

> However, as I said, adding a simple confirmation prompt would be plenty enough. That would be enough for you. That is apparently not enough for Apple, and you can tell that isn’t enough for Apple by their actions because despite the fact that there were less expensive and time consuming ways they could have complied with the whole rest of the DMA, the only feature regression they’ve had is PWA support in the iPhone…

Yes, so rather than allowing other browsers to have PWAs with a warning, they instead don't allow anyone to do it. Allowing so may be insecure, but at least provide a way.

Correct. Maybe one day they’ll return, but probably not without a brand spanking new security and privacy architecture tailored for PWAs.

Re: Apple confirms it's breaking iPhone web apps in the EU on purpose

#315

Earlier quoted context omitted.

Without this type of isolation and enforcement, malicious... camera, microphone or location ... Browsers ... 30 some million lines of code in chromium browsers. Thats bigger than the linux kernel. The HN crowed might not LIKE apples response but they have a very defensible position. Edit: Its not like we haven't seen this play out on the desktop recently: https://www.theverge.com/24054329/microsoft-edge-automatic-c..…

It really doesn't make sense. By that logic, I shouldn't be allowed to load web pages because it's impossible to secure a browser. PWA's only need a few extra integration privileges like badge- and window control, rest is just a web as usual. What you link is a case of one app (edge) reading the data of another app (chrome), which is entirely unrelated to PWAs.

> By that logic, I shouldn't be allowed to load web pages because it's impossible to secure a browser.

Indeeed, and 'whatever browser engine you picked here' is responsible for correctly implementing these additional security features.

That's the argument; if you write an app that lets you run other apps inside it how do we make sure your app does security correctly?

When you look at it from that perspective, you can see that unless at an OS level you provide additional 'meta-security' features that allow apps that run in other apps to have fine grains access control that is managed by the OS, it's pretty much "security? Well, whatever...".

Right? I mean, whether you agree or not, it's a pretty reasonable position to take and it entirely makes sense.

Re: Apple confirms it's breaking iPhone web apps in the EU on purpose

#316
post #178

Earlier quoted context omitted.

> And the majority of elected officials in EU fundamentally disagrees with that statement. Well, EU can and will force, fine, or ban US companies as they see fit but there is not some fundamental correctness to their viewpoint

Any fundamental correctness of their viewpoint is by virtue of them representing more people (EU citizens) than Apple's CEO represents (himself and, I guess, the Apple corporation, if you count that). On moral issues, the fundamentally "correct" viewpoint (if there is one) is, by definition, the one that more people say is the fundamentally "correct" viewpoint.

Governments in other countries have come to a different view, and it's for Apple to determine how worth it is for them to conform to the view come to by the representatives of the EU citizens versus catering to markets with other regulatory regimes.

Re: Apple confirms it's breaking iPhone web apps in the EU on purpose

#317
So, here's Apple's concern, which is valid: every website (PWA) should have isolated storage (cookies etc), and independent access to system resources (webcam etc) confirmed by the user on a per-site basis. I think we can all agree that's how things should be.

Previously, Safari handled these requirements because it's a modern browser (isolated storage has been a cornerstone of browser security for a long time), and had special privileges in iOS to configure per-site user permissions, whereas normal apps only had app-wide permissions.

Luckily, Chrome already has isolated per-site storage because it's also a modern browser. If it didn't, the world would probably explode.

That leaves per-site permissions as the only real problem. I'm sure the Chrome-on-iOS team would do whatever it takes to make this a good user experience, but let's assume for the sake of argument that this would actually be a burden for Apple to support.

How does disabling PWA functionality change the security situation whatsoever? Users preferring Chrome would just load the sites in Chrome as a bookmark, which has no meaningful difference from a "security" perspective. Users strictly using Safari obviously have a strictly-worse experience. Who does this help? What is made more secure by disabling this?

Re: Apple confirms it's breaking iPhone web apps in the EU on purpose

#318

Earlier quoted context omitted.

Without this type of isolation and enforcement, malicious... camera, microphone or location ... Browsers ... 30 some million lines of code in chromium browsers. Thats bigger than the linux kernel. The HN crowed might not LIKE apples response but they have a very defensible position. Edit: Its not like we haven't seen this play out on the desktop recently: https://www.theverge.com/24054329/microsoft-edge-automatic-c..…

It really doesn't make sense. By that logic, I shouldn't be allowed to load web pages because it's impossible to secure a browser. PWA's only need a few extra integration privileges like badge- and window control, rest is just a web as usual. What you link is a case of one app (edge) reading the data of another app (chrome), which is entirely unrelated to PWAs.

> What you link is a case of one app (edge) reading the data of another app (chrome), which is entirely unrelated to PWAs.

In one sense, sure.

But in another sense Edge taking Chrome's tabs means Microsoft is getting insight into Google's data. A lot of Apple's defenses seem really targeted at reducing the ability of Microsoft, Google, and Meta to extract value from Apple's users. Apple sees the union of all the app data, but their competitors can't put together that picture. So in that sense, Edge eating Chrome data may be the sort of thing they're looking to prevent.

Re: Apple confirms it's breaking iPhone web apps in the EU on purpose

#319
post #288

Earlier quoted context omitted.

I don't see how you can call EU having any expectation of freedom when commenting about a law which forces a company to comply to regulation. This actively reduces freedom, the freedom of running your business. You just don't care about it. If you don't like walled gardens you can just not use them (I certainly never bought anything Apple for this very reason), there's no need to infringe on the freedom of everyone e…

I think this is a great example of what I had mentioned as social differences of freedom between the EU and NA - in NA the freedom of businesses is often well protected up until it causes actual harm to human beings[1] - in the EU the freedom of human beings tend to be given priority of those of companies. It's important to remember that there are a lot of freedoms in this world and they often conflict in major ways.…

That dissent sent him to the top of the Heritage Foundation SC shortlist for being a corporate kowtowing stooge.

Re: Apple confirms it's breaking iPhone web apps in the EU on purpose

#320
post #5

I don’t think Apple’s pettiness is gonna work in their favor. I am not in the EU but my next iPhone is almost certainly not gonna be an iPhone despite me having used a non iPhone for about 6 months in the last 15 years. Their throwing their customers under the bus just to throw a tantrum in the EU does not bode well for how they would treat their customers in other situations.

Whatever they manage to eek out in the EU, is the future of what iOS will be in the US and worldwide eventually. If they go with fully fledged PWAs that the other browser engines will enable - there’s little reason to use the Appstore, hence Apple losing their 30% commission. From their perspective it’s not so much throwing a tantrum but clawing and screaming their way into giving up as little revenue as possible.

Idk if you have kids, but tantrums usually involve trying to claw and scream your way into not giving something up
Post reply on HN