Live data from Hacker News

Tell HN: Apple Pay works in non-Safari browsers in iOS 16 Beta 3

news.ycombinator.com

81–90 of 117 posts

Re: Tell HN: Apple Pay works in non-Safari browsers in iOS 16 Beta 3

#81

Earlier quoted context omitted.

Alternatively we may end up with better app stores with far less malware and trash. As much as apple enthusiasts like to claim the app store is as good as it can get, there's a ton of room for improvement IMO. Just getting rid of the games that prey on children and addiction would be a good start.

It's about 100% more likely that it's going lead to every company that chafes under Apple's current "you have to ask permission before you can do that" rules to begin to only offer their apps outside the App Store. Remember the original Android permission model of "an app gets every permission it wants or you can't install it"? That's where this is heading.

Android also lets you individually enable/disable permissions for apps you install. Yet companies haven't started moving to 3rd party app stores to circumvent this, like you are describing

Re: Tell HN: Apple Pay works in non-Safari browsers in iOS 16 Beta 3

#82
post #79

Earlier quoted context omitted.

Why would you download the Meta App store to begin with?

My gut feeling is that there's a nontrivial chance that the moment 3rd-party app stores are available on iOS, Meta will immediately move their apps to one to work around privacy limitations the App Store currently imposes on them. I also strongly suspect that one of those apps would be WhatsApp, which is an app that a not-insignificant portion of the world uses to communicate. Unfortunately, I don't have a choice in…

What App Store privacy rules are you concerned about?

Re: Tell HN: Apple Pay works in non-Safari browsers in iOS 16 Beta 3

#83
post #24

Apple Pay has been supported in WebKit’s web view (which every browser uses) for a while now, but with some conditions. The biggest obstacle was that an app couldn’t inject any JavaScript code of its own into websites. I wonder if they removed this safeguard.

https://github.com/WebKit/WebKit/commit/aa041a623cf40c0d2f17...

Re: Tell HN: Apple Pay works in non-Safari browsers in iOS 16 Beta 3

#85
post #19

No it doesn't, because there is no such thing as a non-safari browser on iOS. Firefox, Chrome, anything Apple will allow is just Safari in a different costume.

Except they use their own browser features, sync, telemetry, privacy practices, business model etc...

All of those things are ancillary except for privacy (even though privacy capability is closely tied to the browser engine these days). It's like saying it must be a Cadillac... "but I can choose the seat colours and stereo so that counts for something!" - i mean sure if you value the stereo that much but you have no choice over the things that makes it what it is, the engine.

Re: Tell HN: Apple Pay works in non-Safari browsers in iOS 16 Beta 3

#86
post #76

Earlier quoted context omitted.

Apple can’t stop malware on macOS Google can’t stop malware on android Microsoft can’t stop malware on android What makes you think Apple will be able to stop malware on iOS?

Malware is definitely possible in various ways, but my understanding is the permission system is still robust. Unless you have given an app a particular permission, with a UI controlled by the operating system, it is unable to use operating system capabilities that are protected by that permission. For example, the OS can enforce that an app can't use the camera without the user clicking "allow" on an OS-managed pop-…

The permission and security systems will be circumvented by malware authors and unscrupulous developers, just like they are on macOS. Given the enormous amount of personal information on our mobile devices, this represents a particularly concerning potential regression in end user privacy and security.

Like on Windows, macOS and Android it’ll be crucial for users to avoid installing executables from the web. and like Android, users also have to be trained to only install apps from ethical software repositories that respect user privacy and security. This is the best case scenario for privacy/security, and essentially the status quo for Android.

For better or for worse, the days of iOS users installing any and all available applications without worrying about malware is over. Users will get more freedom, but they’ll have to take more responsibility when vetting and running third party apps. I don’t know how a notoriously novice user base will react to that, but we shall see.

Re: Tell HN: Apple Pay works in non-Safari browsers in iOS 16 Beta 3

#87
post #79

Earlier quoted context omitted.

My gut feeling is that there's a nontrivial chance that the moment 3rd-party app stores are available on iOS, Meta will immediately move their apps to one to work around privacy limitations the App Store currently imposes on them. I also strongly suspect that one of those apps would be WhatsApp, which is an app that a not-insignificant portion of the world uses to communicate. Unfortunately, I don't have a choice in…

What App Store privacy rules are you concerned about?

I'm not sure if this is exactly what you're asking about, but submitting an app to the App Store currently performs pretty stringent checks on things the app does — including automated scanning for usage of private system APIs and ensuring that apps include appropriate reasons for asking for access to private data (contacts, photos, location data, etc.).

Without certain forms of review, it's much easier for apps to exploit weaknesses (whether in the OS, frameworks, the user, etc.), and I can't imagine that Meta would self-regulate any more than they are forced to now. Their apps and SDKs already hoover up as much data as the system will silently allow, but I'd rather not be forced to expand my device to them, if possible.

Re: Tell HN: Apple Pay works in non-Safari browsers in iOS 16 Beta 3

#88
post #76

Earlier quoted context omitted.

Malware is definitely possible in various ways, but my understanding is the permission system is still robust. Unless you have given an app a particular permission, with a UI controlled by the operating system, it is unable to use operating system capabilities that are protected by that permission. For example, the OS can enforce that an app can't use the camera without the user clicking "allow" on an OS-managed pop-…

The permission and security systems will be circumvented by malware authors and unscrupulous developers, just like they are on macOS. Given the enormous amount of personal information on our mobile devices, this represents a particularly concerning potential regression in end user privacy and security. Like on Windows, macOS and Android it’ll be crucial for users to avoid installing executables from the web. and like…

Mac OS, like all traditional desktop operating systems, gives almost all permissions to every process running as the user. This is a very difficult environment to defend!

It's also very different from how iOS and Android heavily restrict what each app can do, hiding most things you might want to do behind permissions. Installing an app is not quite as safe as visiting a web page, but it's very nearly so if you don't agree to any permissions requests.

The most common way for malware to abuse the permissions system is to ask for permissions to do something plausible, or even implausible, and then abuse those permissions to do other things that the user wasn't expecting. For example, a speed dialer might ask for permission to read your contacts, which is quite reasonable for a speed dialer, but then exfiltrate and sell them.

Re: Tell HN: Apple Pay works in non-Safari browsers in iOS 16 Beta 3

#89
post #72

Probably preparations due to the upcoming EU framework. As a short summary, here are some of the new EU requirements on gatekeepers such as Apple. Gatekeepers must: - Allow users to install apps from third-party app stores and sideload directly from the internet. - Allow developers to offer third-party payment systems in apps and promote offers outside the gatekeeper's platforms. - Allow developers to integrate their…

It seems like every perceived problem these days is grounds for legislation. Let’s work on additive solutions as opposed to regulation.

What do you suggest?

Re: Tell HN: Apple Pay works in non-Safari browsers in iOS 16 Beta 3

#90
post #55

Earlier quoted context omitted.

Remember Facebook offering people a few bucks to MITM their entire phone? Oh wait, that was on the official App store! And they didn't even ban them!

>Remember Facebook offering people a few bucks to MITM their entire phone? Oh wait, that was on the official App store! And they didn't even ban them! No, companies can apply for their own app signing key that allows them to create apps for their own in-house-only uses that completely bypass the App Store. Facebook used that enterprise signing key to install spyware on user's devices. This had nothing to do with the…

Please read carefully what you wrote.

> that completely bypass the App Store [..] Apple did revoke their signing key

Do you see it yet? There is no "bypassing the App Store". At the end of the day, the root of trust comes back to Apple.

And, of course, they "revoked" it meaning they waited for a week or so and then Facebook had all their enterprise apps back. This isn't the treatment in store for you if you attempted this.

Post reply on HN