Live data from Hacker News

Rotten Apple

adactio.com

31–40 of 226 posts

Re: Rotten Apple

#31

Good post, but a bit turbulent to read: "If you’ve ever built a web app, then your users will suffer. Remember, it’s a world wide web, including the European Union." "Create a PDF with the following information:" (me, reading that paragraph: '...what? why?') -- [Edit]: I concluded from the bullet-list on why that is requested, but it would help to introduce that intention before instructing me to do something

you're creating a pdf to send a complaint to EU regulators about Apple behavior.

Re: Rotten Apple

#32

What is really fun about working with Apple is their Appstore connect platform is buggy & slow as hell. Few times I couldn't submit an app because of it. Every time I submit a bug, there first reaction is try it on safari; most of time it was server issues so it didn't resolve it. But sometimes it actually did where I didnt expect it.

They have no reason to improve it as there is no alternative (yet).

Re: Rotten Apple

#33

Earlier quoted context omitted.

>> Microsoft does it all the time with Edge on Windows. Edge on windows, the same edge on windows that got caught slurping up chrome tabs recently? Browsers are now the same size code base wise, as operating systems. They are in fact tiny OS's with permissions models and execution environments. I think the author makes the point that safari made a lot of progress, they paid for a lot of work, that they are throwing a…

Aren't apps already sandboxed from eachother on both major Phone OS', unlike on Windows? So on that end something like Edges snooping around other browsers isn't even possible.

In theory, sure.

The browser is bigger than the OS in total LOC.

No one is auditing that.

It is a question of when the video leaks of someone using their phone on the shitter.

If its a Samsung... well were gonna hear google and Samsung blame each other and consumers will be confused till everyone forgets about it.

If it's an apple, consumers blame apple. The buck stops with them.

You have to make a business decision based on this what are you gonna do? Im gonna lock all the doors I can.

Re: Rotten Apple

#34
post #11

Ah yes, the poor end users suffering and the security being bullshit. I really can't wait to clean the first malicious browser out of a relative's iPhone and try and unsubscribe from Tim Sweeny's app store with his own 30% margin to spend on blackjack and hookers. The new status quo will be worse than the old one.

Somehow this is not a problem on Android even though they have sideloading and alternative app stores even beyond what Apple is going to allow. (Apple still requires apps to go though a review process, even if distributed outside of the App Store, and will enforce this using digital signatures.)

It is somewhat of a problem for android when it comes to sideloading, and this is an additional advantages of PWAs. PWAs are the freedom of sideloading, without the security risk.

Re: Rotten Apple

#35
Why is it a bad response from Apple to disable a feature that they deem as a security risk if you allow for alternative browser engines?

Browsers represent a significant attack surface since they can run code and also transmit data across the network. So when they are allowed to exist now Apple has either two options. One is to do the simple way and remove progressive web apps or extensively test and perform security analysis on all of the new browser engines.

A better compromise would be to make new browser engines have extensive testing by the developer themselves. So, what's the point ? It feels similar to the GDPR where I get a popup and I click disallow all cookies except for essential ones.

This seems the best way to actually implement the directive because it is not only low effort but most secure. We would have a better compromise for testing to be done by the browser engine developer or Apple but its more likely security holes would fall through.

Re: Rotten Apple

#36
post #11

Ah yes, the poor end users suffering and the security being bullshit. I really can't wait to clean the first malicious browser out of a relative's iPhone and try and unsubscribe from Tim Sweeny's app store with his own 30% margin to spend on blackjack and hookers. The new status quo will be worse than the old one.

Somehow this is not a problem on Android even though they have sideloading and alternative app stores even beyond what Apple is going to allow. (Apple still requires apps to go though a review process, even if distributed outside of the App Store, and will enforce this using digital signatures.)

This is actually a big problem on Android. My ex father-in-law literally had his bank account ripped off (£18000) from rogue app installed from outside the app store. And Google's stewardship of the play store is terrible.

Note I'm mostly an Android user.

Re: Rotten Apple

#37

A lot of this article appears to be based on the belief that the security architecture of iOS and MacOS are identical. This seems ... an unlikely assumption

No the article is under the belief that because something has not been a security problem for Mac it will not be a security problem for iOS, this does not necessarily have to be because the security architectures of both are the same.

Re: Rotten Apple

#38
post #18
post #9

It's a shame, Apple is in a place to be the leader and decent, instead it decides not to be both.

I love apple for the hardware, but they would be a better company if they released their iron grip over the software. One day I dream I can install Linux on iOS devices.

[deleted]

Re: Rotten Apple

#39
post #13

Why Safari can’t just launch from a Home Screen bookmark even if the user has chosen another “default browser”? PWAs are already a separate “island” of storage and share nothing with Safari App… Microsoft does it all the time with Edge on Windows.

Perhaps this is just "all we could deliver by the compliance deadline without compromising platform security" ? The truth is usually a lot less interesting than the hypothesis.

Maybe ... but a large company implementing compliance in the most self-serving way possible isn't exactly a shocking idea, either.
Post reply on HN