Live data from Hacker News

I won't download your app. The web version is a-ok

0xsid.com

511–520 of 599 posts

Re: I won't download your app. The web version is a-ok

#511
post #490
post #446

Earlier quoted context omitted.

Well the idea is that the client should be open source, and audited. If you run a proprietary app, you have to blindly trust it (just like if you access a webapp). In terms of security, the best is an open source app, IMO.

Open source helps, but if you didn't build it yourself, you'll need to trust whoever did. F-Droid reproducible builds help in that you only need to trust either F-Droid or the developer, not both. The browser tends to be safer because it has a stronger sandbox than native apps on a mobile OS. It's meant to be able to run potentially malicious code with a very limited blast radius.

> Open source helps, but if you didn't build it yourself, you'll need to trust whoever did.

You need to audit the code. If you are not capable of doing that, you need to trust someone to do it.

Re: I won't download your app. The web version is a-ok

#512
post #478

Earlier quoted context omitted.

Well, you can verify that the code that you downloaded is the same that everyone else downloaded. Even if it contains webviews. Now if it contains webviews, it brings the security issue of... the webapps, of course. Personally, I want an open source app. You can audit an open source app and even compile it yourself. You can't really do that with a website. And I don't mean just mobile apps, that applies to desktop ap…

>Well, you can verify that the code that you downloaded is the same that everyone else downloaded. Even if it contains webviews. Not impossible to do with websites, if the need to do it was there. It would take about 15 minutes to create a browser extension that could make a hash of all the files loaded, to compare with other users with the extension installed - but honestly that's just not needed because if you're c…

> It would take about 15 minutes to create a browser extension that could make a hash of all the files loaded, to compare with other users with the extension installed

You completely underestimate it. I am absolutely certain that you cannot create a browser extension that meaningfully solves this problem in 15 minutes.

> Web applications are sandboxed in the web browser. Very little issue with that

Except that when we are talking about end-to-end encryption, the sandbox has nothing to do with it. The sandbox defends against something else, not the server serving you an end-to-end encryption program abusing it.

> AWS has a web-based terminal for EC2 instances. It's not a problem, a lot of people use it.

I genuinely can't see if you just don't understand the point being discussed at all, or if you keep saying off-topic things as a way to divert the discussion.

Re: I won't download your app. The web version is a-ok

#513

Earlier quoted context omitted.

It's obvious what GP meant - we can verify that the apps we download are the apps everyone else downloads. We can't do this with Proton where our mail is supposedly end-to-end encrypted. They can easily view our mail if they can send us a different code when we load their site. > That isn't what "sandboxed" means, it has nothing to do with checking hashes. And no, mobile apps are not really sandboxed Apps ARE somewha…

>We can't do this with Proton where our mail is supposedly end-to-end encrypted. They can easily view our mail if they can send us a different code when we load their site. That isn't a problem with how the web works vs how apps work, that's a problem with you trusting Protonmail. If you really wanted to be secure sending an email or any communication, you wouldn't trust any third party, be it an app or a website - y…

That is a problem with you not understanding how security works.

> If you really wanted to be secure

There is no such thing as "being really secure". There are threat models, and implementations that defend you against them. Because you can't prevent a bulldozer from destroying your front door does not mean that it is useless to ever lock it.

Even your air-gapped example is wrong, because it means that you have to trust that system (unless you are capable of building a computer from scratch in your garage, which I doubt).

Sending an encrypted over the Signal app is a lot more secure than sending an email over the ProtonMail website, which itself is more secure than sending it in a non-secret Telegram channel. It's a gradient, it can be "more" or "less" secure, it doesn't have to be "all or nothing" as you seem to believe.

Re: I won't download your app. The web version is a-ok

#514

What most people dont get: Most of folks on HN here are much older than todays "first customers" of 16y/17/18 For them: The "Smartphone is the internet", while for most of us the "Smartphone is an extension of the internet from our desktops" that we were used to (remember the years before dot com bubble, saying: "I will be down in the basement at the computer to surf on the net little bit" ? :-) But today, the very f…

I use a phone just for whatsapp and sometimes take a pic. Computer for everything else

Re: I won't download your app. The web version is a-ok

#515

Earlier quoted context omitted.

I suspect that what happens, during this "daily checkin," is that the app sends a bunch of encrypted data that it got from your device, to the servers in China. What information do you think they got from your device other than what you gave them permission to have? If you actually have any info on how apps can break Apple's sandbox to leak your personal info, you should share it.

Yeah, it's OK. I said that I wouldn't argue, and I'm sticking to that. Have a great day!

Just thought I'd help you understand how this works so you don't spread misinformation, but you too!

Re: I won't download your app. The web version is a-ok

#516

Hall of shame: * Reddit won't let you read "unreviewed" content on mobile web (but will on desktop web) * PayPal won't let you pick your 5% rewards category, or set up balance auto-replenish without their app * Robinhood Banking won't let you see your credit card statement or pay your balance without their app * Instagram won't let you share posts as stories without their app * SeatGeek won't let you attend events wi…

Robinhood gets double shame points for naming the app "Banking" (previously "Credit Card"), no Robinhood or RH in the name. I love the card but hate everything about that app.

Re: I won't download your app. The web version is a-ok

#517
post #356

Earlier quoted context omitted.

> Companies are seeing this switch, so they adapt. You’re confusing cause and effect here. Companies are pushing apps very hard because it gives them a lot more ability to wield their various revenue enhancing dark patterns. That kids see apps as the primary option is a corporate success metric, not an organic choice. Anyway, the premise that “phone screen ==> native app not web app” is rather faulty, is it not?

They’re not confusing anything, you’re just sticking your head in the sand. The modern entry path to “computing” is small screen devices (phones). Their point of newcomers not having our same entry path is accurate. This is organic, however much we don’t like it. Anything past that is just market skating where the puck is.

We're talking about web app vs native app here, not big screen vs small screen.

Obviously, you can have either kind of app on either size of screen, so small screen first doesn't mean native apps. It's enshitification that's driving native adoption, not small screens.

Re: I won't download your app. The web version is a-ok

#518
post #265

Earlier quoted context omitted.

OP had no problem with pointers prior to trying C++. I think there is a case to be made that C(++) makes pointers unnecessarily confusing and there is no real disconnect between understanding pointers in theory and in practice otherwise

And C++ makes everything extra confusing with the capability of operator overloading. That has to be one of the worst features ever added to a language.

> C++ makes everything extra confusing

Re: I won't download your app. The web version is a-ok

#519
post #324

Web browser is a sandbox by default. Worst a sketchy site does is eat a tab, less if you run an adblocker. Native app? Background processes, hardware ID shenanigans, your contacts, location. The whole buffet.

> Web browser is a sandbox by default. So I take this is a security concern. How do you feel about the fact that when you open a webapp in your browser, you re-download that app code every time? That the server can send you a backdoor every single time, made just for you, and nobody else will ever know? And that you can't check the "hash" of the webapp, like you can with an app? On the other hand, an app is sandboxed…

I think the question is: where should the information barrier exist? A web browser puts a barrier between your OS and the company, while an app (potentially) puts a barrier between the client and the server.

For security minded and source-available apps like Signal, the latter is the right choice. For low trust companies with no expectation of app/server separation, the former seems right.

Re: I won't download your app. The web version is a-ok

#520

Earlier quoted context omitted.

> Computers screens have gotten wider and wider, and UIs bigger and bigger Sadly, most websites forcefully limit the width of the text. It's like they pretend our monitors are oriented to be tall rather than wide. Even HN has unnecessarily big margins. So unless I try to cram another window in my FHD monitor, I have ~50% or more completely wasted space. Margins should be 2-3 pixels wide, not 20-30% of the screen.

There are actual user studies to show that wider text is harder to read. https://baymard.com/blog/line-length-readability The major difference is that in the era of print, it was pretty logical where a multicolumn wide layout could go like on a newspaper, but in an desktop experience the browser markup is theoretically endless.

The studies go back way earlier than that; there's a reason why they call them "newspaper columns"
Post reply on HN