Live data from Hacker News

Apple confirms it's breaking iPhone web apps in the EU on purpose

techcrunch.com

161–170 of 829 posts

Re: Apple confirms it's breaking iPhone web apps in the EU on purpose

#161

Earlier quoted context omitted.

Users trust Apple because Apple is ultimately accountable for security breaches on iOS devices. If a 3rd party app causes a data breach it does not matter if the breach was made possible by compliance with regulations like the DMA, Apple will still take the blame.

> Users trust Apple because Apple is ultimately accountable for security breaches on iOS devices. As a long time user of Windows which historically had an incomparably large amount of security incidents, I can assure you that Apple won't get blamed that much for 3rd party data breach unless it involves Apple's own service and user data.

Since you’re a commenter on HN I’m going to assume you’re a tech person. I’m not talking about tech people, who through their discussions try to find the correct person/company to blame for issues.

I’m talking about the general public. If a story about a data breach in a 3rd party app — affecting iOS users — hits the news cycle, Apple will take the blame and their brand reputation and sales will be impacted. It doesn’t matter whose fault it really is, Apple is the face of the iPhone and through their walled garden they have accepted final responsibility for everything that occurs on iOS.

Re: Apple confirms it's breaking iPhone web apps in the EU on purpose

#162

Since the article doesn't actually repeat what Apple has said, here's what Apple says: == Begin quote == The iOS system has traditionally provided support for Home Screen web apps by building directly on WebKit and its security architecture. That integration means Home Screen web apps are managed to align with the security and privacy model for native apps on iOS, including isolation of storage and enforcement of sys…

Am I missing something?

Couldn’t they allow you open PWAs in Safari, or fall back to opening a URL in another browser?

Is there some part of the DMA which demands full feature parity?

Re: Apple confirms it's breaking iPhone web apps in the EU on purpose

#163
post #79

Earlier quoted context omitted.

You have to trust someone if you're using a computing device connected to the Internet. The point of being in Apple ecosystem is that you trust Apple, and then (supposedly) you can not trust anyone else. To many that's a very strong proposition.

> The point of being in Apple ecosystem is that you trust Apple, This seems to be over-generalization? Users are using Apple devices because those are good products, not because they want to delegate every single trust problem to the Apple ecosystem. That might be a great proposition for people like you, but there is a significant number of people who consider it a compromise rather than a value.

> Users are using Apple devices because those are good products,..

For general populace good also include secure by default.

"every single trust problem to the Apple ecosystem." is rather technical point that very few people would even understand meaning of it.

> significant number of people who consider it a compromise

How significant compare to iPhone user base?

Re: Apple confirms it's breaking iPhone web apps in the EU on purpose

#164

Very questionable argumentation. This can be seen from two different angles: 1. PWA is a native wrapper for a web application, not a browser. It is supposed to be limited to the app website. DMA does not tell Apple that every app with embedded WebView should offer users possibility to switch the engine. Why PWA should be treated differently here? I‘d rather clarify this with regulators first, before harming end users…

> DMA does not tell Apple that every app with embedded WebView should offer users possibility to switch the engine. I don’t see how that’s related to the issue being discussed. > In the meantime current solution could stay simply because it does not hinder any competition. Why do you think “you can install a third party browser, but if you do, you can’t add PWAs to the Home Screen” doesn’t hinder competition?

>I don’t see how that’s related to the issue being discussed.

PWA is not a browser, it is a native app using a browser engine to render a specific website.

>Why do you think “you can install a third party browser, but if you do, you can’t add PWAs to the Home Screen” doesn’t hinder competition?

I literally explained it in my comment you are replying to, but I can repeat. Competition does not exist yet. Browsers do not offer PWA support out of the box, it is a feature to be implemented separately from rendering engine. See Firefox on Windows for an example — it doesn’t support PWA out of the box. This feature has to be built: if Apple were to hinder the competition, they would resist it by not offering the APIs. But they can offer them through the cooperation with vendors, even if those APIs do not exist yet. Say, Mozilla comes and asks for APIs: Apple starts negotiating and proposes the compatibility requirements and a reasonable timeline. They both work on their part and eventually Firefox is released with PWA support. Who would fine or sue them if it worked this way? How the violation of DMA could be proven?

Re: Apple confirms it's breaking iPhone web apps in the EU on purpose

#165
Honestly this doesn't bother me as much as some of the other malicious compliance Apple has been doing. It sounds like Safari had a pretty tight level of integration with the operating system in order to allow PWAs, and creating secure APIs to allow other 3rd party browsers to achieve the same thing would have been expensive. So in order to avoid giving preferential treatment Safari over competing browsers without incurring that cost they had to remove PWA support.

Obviously long-term what should happen is that Apple should build out those necessary APIs, then re-introduce PWA support to Safari and 3rd party browsers, but I personally feel like the EU trying to legislate an entirely new platform feature into existence like that would be a step too far.

Some of the other concerns with Apple's recent moves (like them trying to charge developers for installs that don't go through Apple's App Store, and that Apple therefore has nothing to do with) are a far bigger issue.

Re: Apple confirms it's breaking iPhone web apps in the EU on purpose

#166

Earlier quoted context omitted.

That’s not the point though because WebKit is already secured by Apple but if you have multiple blink related apps like Microsoft edge or brave or Firefox apple will have to audit those too and be on the hook if something breaks and then Apple will have to take the blame over a security oversight they aren’t responsible for.

That assumes that Apple would be blamed for Edge/Brave/Firefox's security oversight.

If you add a PWA (with Safari) a year ago to your Home Screen and then change your browser to Firefox, and that PWA breaks out and steals some other application data...

Will you blame the software maker that you used to install the icon on the screen? or the one that is seemingly unrelated to the icon on your Home Screen?

Re: Apple confirms it's breaking iPhone web apps in the EU on purpose

#167
post #146

Earlier quoted context omitted.

The “low usage” comment is going to be more ammo against Apple unfortunately. The whole reason they are low usage on PWAs is because of a lack of investment from Apple and a lack of parity, yet for the longest time Apple has played both sides by saying PWAs are a viable alternative to the App Store, all while channeling people to App Store for actual app downloads and not providing similar marketing or anything for P…

Are you sure this isn't a tech industry viewpoint? I don't know anyone who knows what the difference between an app and a PWA is. I don't think I've seen anyone outside of the tech industry with a PWA active. In context 99% of the users I meet don't even know what USB-C is.

The only PWA that I think gets any use on i(Pad)OS is that for the Financial Times.

Re: Apple confirms it's breaking iPhone web apps in the EU on purpose

#168
post #79

Earlier quoted context omitted.

Why should we trust Apple for security in that context? Apple also provides all those functionalities via their proprietary API, which is not even audit-able. If Apple really believes in that argument, they should disable their own API as well.

You have to trust someone if you're using a computing device connected to the Internet. The point of being in Apple ecosystem is that you trust Apple, and then (supposedly) you can not trust anyone else. To many that's a very strong proposition.

[deleted]

Re: Apple confirms it's breaking iPhone web apps in the EU on purpose

#169
Bad move from Apple. It's time to boycott iOS and move to FOSS alternatives, such as: AOSP, Ubuntu Touch, GNOME Mobile, KDE Plasma, Sailfish OS. Personally I am using both UBports and Sailfish OS and I appreciate the privacy they provide.

As a possible workaround to fullscreen PWAs in iOS in the EU, I propose a convention to append some hash to the Web App Manifest start_url, e.g. #__pwa__, then set the default iOS web browser to e.g. Firefox, then add the PWA to the home screen from it with this special hash. When a user clicks on a PWA icon in the home screen, it would open in the default browser (e.g. Firefox), the browser then checks if the newly opened tab is opened from external source and its URL ends with #__pwa__ and if so, then hides the UI providing a fullscreen viewport for the opened PWA.

Re: Apple confirms it's breaking iPhone web apps in the EU on purpose

#170
It’s disappointing to see that Apple’s spin job is apparently working (based on some of the comments here). While it sounds superficially plausible, it’s actually quite deceitful.

For example, the argument that one web app could steal the permissions of another web app is predicated on the assumption that a non-Apple browser engine will fail to sandbox the apps. But *the exact same* threat vector will exist for non-Home Screen web apps accessed through third party browsers. That’s because ordinary websites ALSO have the ability to request access to microphones and cameras, and it will be up to the developers of the browser engines to ensure that these permissions are properly sandboxed. Apple won’t be able to eliminate this risk without breaking vast numbers of sites that people use every day.

In truth, a PWA is no different from a website. It’s built using the same technologies and APIs. The main difference is that it can run in full-screen mode like an app, and it has its local storage cleared less often. These are nice extras that benefit users who choose to “install” such apps, and they carry no special security risks.

Post reply on HN