Live data from Hacker News

Rotten Apple

adactio.com

51–60 of 226 posts

Re: Rotten Apple

#51

Earlier quoted context omitted.

Aren't apps already sandboxed from eachother on both major Phone OS', unlike on Windows? So on that end something like Edges snooping around other browsers isn't even possible.

In theory, sure. The browser is bigger than the OS in total LOC. No one is auditing that. It is a question of when the video leaks of someone using their phone on the shitter. If its a Samsung... well were gonna hear google and Samsung blame each other and consumers will be confused till everyone forgets about it. If it's an apple, consumers blame apple. The buck stops with them. You have to make a business decision…

If the video leaks due to shitty (pun not intended) sandboxing that is rightlfully on Apple (when on iOS), if it leaks due to the browser being broken then it is on Google and if it's due to an explicit modification of Samsung (when talking about Android) it's on Samsung.

When Facebook has a bug/exploit in their app that results in X hacker being able to gain access to files stored within the sandbox of Facebook noone is blaming Apple for Facebooks bug.

Re: Rotten Apple

#53

Why is it a bad response from Apple to disable a feature that they deem as a security risk if you allow for alternative browser engines? Browsers represent a significant attack surface since they can run code and also transmit data across the network. So when they are allowed to exist now Apple has either two options. One is to do the simple way and remove progressive web apps or extensively test and perform security…

As said elsewhere, the PWA apps could open in Safari.

But would this have legal implications? Could the browser vendors argue they are discriminated against if PWA apps do not open in their browser?

I think this whole thing puts the finger on how fluid the borders have become. What is an app, what is an API, what is a service? Is Safari an Apple API for PWA apps? Or is a PWA app running by mandate on Safari when the user has selected another browser as default somehow wrong legally or ethically?

Re: Rotten Apple

#54
> I’m going to get a lot of emails from confused users wondering why their app is broken, now opening in a regular browser window.

Newsflash incoming for you.. Just about none of your users will (1) care (2) used the "PWA" in the first place.

It's really not that common to add apps to the home screen. Among very technical users, it's a fair bit more common though.

Re: Rotten Apple

#55

A lot of this article appears to be based on the belief that the security architecture of iOS and MacOS are identical. This seems ... an unlikely assumption

I think a more problematic assumption is that iOS and MacOS users are equally aware and knowledgeable about potential security threats. It’s true that the sky hasn’t fallen because MacOS users are exposed to these risks. But they are not new risks on MacOS. They will be on iOS.

They don’t need to use a different browser engine.

You’re talking about a user who has gone out of their way through multiple scary Apple warnings to change their browser engine.

And even once they do that, they’re likely to be installing one of Firefox, Chrome, or Edge, all of which have as good if not better security histories than Safari.

Re: Rotten Apple

#57

I have an ipad through which I subscribed for Apple arcade. I don't use it / play at all on it and there was recently an email that price is going up. Sure, I'll just cancel subscription I said. I don't have my ipad on me, nor any other apple device (I don't use them anymore), nor windows. I have linux machines and android phone. Ok, so how do I cancel subscription? icloud login? no. subscription place of sorts? it w…

So when you sign up for Apple Arcade, which strangely you dont use? Why sign up for it? But then it's okay that you need to have your iPad to signup, but when you want to cancel it is strange that you need your iPad.

I understand it would be nice if you can login to a website and cancel, but reads as if you make your mistake of not taken your iPad, or cancelling in time a fault of others.

Re: Rotten Apple

#58
This is a terrible argument:

> You can read Apple’s announcement on being forced to comply but as you do you so, I’d like you to remember one thing: every nightmare scenario they describe for the security of users in the EU is exactly what currently happens on Macs everywhere in the world.

There's 1.5 billion iPhone users vs 100 million Mac users, Apple believes that at least part of the reason for that difference is the security model of iOS. E.g., arguably the largest changes Apple has made to the Mac since introducing the iPhone is implementing security measures based on iOS.

Re: Rotten Apple

#59
post #54

> I’m going to get a lot of emails from confused users wondering why their app is broken, now opening in a regular browser window. Newsflash incoming for you.. Just about none of your users will (1) care (2) used the "PWA" in the first place. It's really not that common to add apps to the home screen. Among very technical users, it's a fair bit more common though.

For random web pages which have a PWA mode, sure. But there are bona-fide industry specific PWA "apps". The confusion will be real. Probably minor enough for Apple to barely register, but tell that to the users.

Re: Rotten Apple

#60
I don’t understands why this would be such a security issue other browsers are sandboxed. PWA would just dispatch to the chosen browser with whatever parameters are passed along and it would be up to that browser to do the right thing. How would this be a security risk worse than the current existing setup with deep links?
Post reply on HN