[HN Gopher] Apple confirms it's breaking iPhone web apps in the ...
       ___________________________________________________________________
        
       Apple confirms it's breaking iPhone web apps in the EU on purpose
        
       Author : M2Ys4U
       Score  : 267 points
       Date   : 2024-02-15 20:22 UTC (2 hours ago)
        
 (HTM) web link (techcrunch.com)
 (TXT) w3m dump (techcrunch.com)
        
       | givemeethekeys wrote:
       | It's news like this that makes me want to trade my iPhone for the
       | closest Android phone.
        
       | Fizzadar wrote:
       | Honestly Apple's response to the DMA changes is pathetic, they're
       | acting like a petulant child. I really hope the EU throws the
       | book at them. Will believe it when I see it, fingers crossed.
        
         | Fizzadar wrote:
         | I say all this as a MacBook, iPhone and AirPods user (:
        
       | addicted wrote:
       | I don't think Apple's pettiness is gonna work in their favor.
       | 
       | I am not in the EU but my next iPhone is almost certainly not
       | gonna be an iPhone despite me having used a non iPhone for about
       | 6 months in the last 15 years.
       | 
       | Their throwing their customers under the bus just to throw a
       | tantrum in the EU does not bode well for how they would treat
       | their customers in other situations.
        
         | JadeNB wrote:
         | > I am not in the EU but my next iPhone is almost certainly not
         | gonna be an iPhone ....
         | 
         | Next _phone_ , right?
        
           | shaan7 wrote:
           | Thats just parent's way of playing around with all the AI
           | models reading this page xD
        
         | toyg wrote:
         | They're desperately hoping that their fanbois will howl so
         | much, that MEPs will relent.
        
         | akmarinov wrote:
         | Whatever they manage to eek out in the EU, is the future of
         | what iOS will be in the US and worldwide eventually. If they go
         | with fully fledged PWAs that the other browser engines will
         | enable - there's little reason to use the Appstore, hence Apple
         | losing their 30% commission.
         | 
         | From their perspective it's not so much throwing a tantrum but
         | clawing and screaming their way into giving up as little
         | revenue as possible.
        
           | jkestner wrote:
           | And as a developer, I see how I'm going to be collateral
           | damage, and am less likely to do anything that gives Apple
           | more power over me and my customers. If that means a
           | bookmarked web app, so be it.
        
         | Zagitta wrote:
         | I hope EU comes down HARD on them for trying to pull this shit
        
       | deminature wrote:
       | In combination with the 'Core Technology Fee' that financially
       | cripples any developer that tries to release a popular app
       | outside the official app store, this is pathetic behavior.
       | Hopefully the EU smacks them down for this temper tantrum at
       | being forced to adhere to the DMA. They are trying to flex their
       | market power and should be reminded they operate within a system
       | of laws that doesn't bend for anyone, regardless of their size.
        
         | SllX wrote:
         | I'm going to be level with you: there is nothing so great about
         | PWAs that they're worth mandating or protecting by law in any
         | jurisdiction and the EU doesn't owe it to you to try.
         | 
         | Web developers like them. That's it, and their PWA advocacy
         | completely disregards what a privacy and security nightmare
         | they can be without proper safeguards, because this little
         | device I carry around in my pocket is 1) always with me and 2)
         | stores a lot of information about me 3) has a full sensory
         | array installed within it.
         | 
         | Every new feature browsers add for better hardware access gets
         | immediately disabled on any system I manage: cameras, mics, USB
         | access, sensors, location, notifications, local storage, the
         | whole works because the alternative is letting every website
         | access those or getting spammed with access requests on every
         | site I visit and the more crap that is added, the longer it
         | takes me every time I setup a new browser install from scratch.
         | Why disable them at all? Because 99% of these new features are
         | primarily used to build a better supercookie to track and
         | profile people without their consent. The actual marketable
         | reasons are a secondary use at best.
         | 
         | So if it's not on Apple's priority list to build out whatever
         | they need to support and allow other browsers to support PWAs
         | in a secure and privacy conscious manner, good for them. Web
         | developers who want to circumvent Apple's fees entirely don't
         | need to be anywhere near their top priority and can wait. For
         | Apple: users come before developers, and App developers before
         | web developers.
        
           | deminature wrote:
           | I'm not a fan of PWAs either, but disabling them instead of
           | allowing them to continue to run is an incredibly bad faith
           | response to the DMA.
        
             | SllX wrote:
             | Not if the alternative is allowing other browsers to
             | install them without a privacy and security architecture in
             | place first.
             | 
             | Even if Apple thinks it's worth doing, that takes time, and
             | web developers aren't worth prioritizing for them when they
             | have a lot of other ground to cover building out a new
             | system of APIs and entitlements to comply with the DMA's
             | other requirements.
        
               | deminature wrote:
               | The user is warned already on the App Store that
               | installing apps from third-parties comes with certain
               | risks via 'scare screens'. There's no reason they can't
               | do the same for PWAs.
        
               | SllX wrote:
               | They probably will if they ever re-enable it in the EU,
               | but they also built out over 600 new APIs and an
               | accompanying system of entitlements to go with that scare
               | sheet such that even if it's "riskier", they're not just
               | throwing up their hands and saying "alright devs, we
               | scared them a little, so now go do whatever the hell you
               | want".
               | 
               | EDIT: I should also add that of those 600, that includes
               | APIs Apple built out specifically for third-party
               | browsers.
        
               | deminature wrote:
               | I think PWA developers are going to be pretty
               | unsympathetic to 'your PWA is going be available again in
               | the EU at some unspecified time in the future, when some
               | Apple product manager decides to prioritize it for a
               | given year's roadmap and it's all in the interests of
               | protecting users from unspecified privacy and security
               | threats that nobody seems to be able to define'. Most
               | importantly, the EU may feel the same way.
        
               | SllX wrote:
               | Well to correct you, my position is more "Apple might re-
               | enable this" more than "will", which from their
               | perspective I'm guessing is even worse and they will be
               | more unsympathetic to it.
               | 
               | Personally I think Apple will, but I have enough doubts
               | that I don't want to make that claim.
               | 
               | > Most importantly, the EU may feel the same way.
               | 
               | That's the rub. The EU has been arbitrarily writing new
               | laws which mostly target foreign tech companies that
               | don't quite read "show me your bellies so we can pick out
               | the choice cuts" but they're pretty close. So the EU
               | might do a lot of things, but if there's an argument
               | against them doing that, it's what I said in my first
               | comment above: it's not worth any jurisdiction's time to
               | do so. That includes the EU.
               | 
               | You might need to support some technologies to get
               | government contracts, but nobody ever mandated you had to
               | support POSIX or J2ME or whatever to sell a computer or
               | phone to regular people. That would be asinine, and a PWA
               | mandate would also be asinine.
        
               | deminature wrote:
               | The arbitrary laws that the EU has been writing are the
               | one of the last bulwarks consumers have against the
               | creeping power of tech giants and these companies are
               | making more money than ever in spite of regulation, so it
               | doesn't seem to be affecting them too adversely.
        
               | SllX wrote:
               | The biggest abuses in tech come down on the adtech side
               | of things where in order for them to make money, they
               | need to know who you are, and they will do everything
               | within their power to make sure that they do with or
               | without your consent.
               | 
               | Telecoms companies (in which I am including carriers)
               | also often fall within this because they are often
               | envious of adtech companies and want what they have and
               | can theoretically make better guarantees about who
               | somebody is.
               | 
               | Not supporting PWAs isn't in the same league, but I would
               | also add to that: running a popular messenger, running a
               | popular search engine, and controlling distribution of
               | software on a popular phone platform. Spinning up new
               | laws around terminology designed to have bad PR
               | ("gatekeepers") is pretty damn arbitrary as far as
               | lawmaking goes.
        
               | zadokshi wrote:
               | No one meads "scare screens".
               | 
               | I'm. It sure what I think about this yet, but I'm pretty
               | sure I'm going to land on "allowing less privacy aware
               | browsers to run web "apps" with heightened privileges
               | seems like a recipe for disaster.
               | 
               | Maybe in the long term ther is a way to do it well. But
               | for now I'm not sure.
        
               | deminature wrote:
               | Every app on iOS is sandboxed and the damage they can do
               | is very limited. There's risks involved in opening up to
               | third-party apps, and PWAs are only marginally more
               | dangerous. Non-WebKit based browsers don't even exist
               | today, this is not a real problem and won't be for some
               | time.
               | 
               | The obvious solution for now is to enable WebKit PWAs and
               | turn on PWAs for other as-yet uninvented custom browsers
               | as they release, testing for privacy as they get
               | released.
        
           | WirelessGigabit wrote:
           | There is little difference on iOS between a PWA and a website
           | which has a WebKit view and hosts a website.
           | 
           | The only reason PWAs were interesting on iOS was to get an
           | app on iOS, while feeling relatively native, without paying
           | Apple.
        
         | kryptiskt wrote:
         | Yeah, this isn't a parlor game, I have no idea why they think
         | the antitrust pressure will abate by such bad faith nonsense
         | moves. Next step for the EU is to make Tim Cook choose whether
         | he wants to be CEO of the device side or service side of the
         | broken up Apple. It's clear that fining them is useless.
        
           | lannisterstark wrote:
           | Ah yeah man EU is totally gonna break up apple.
           | 
           | Some of y'all need to be reminded to be realistic.
        
             | deminature wrote:
             | The DMA has potential fines of 20% of global annual revenue
             | for non-compliance. Apple is playing with fire here. Laws
             | like GDPR and DMA are designed to be just as scary for big
             | entities as small.
        
         | robertoandred wrote:
         | This IS adhering to the DMA. Every browser engine is treated
         | the same.
        
           | impossiblefork wrote:
           | I think that's very unlikely.
           | 
           | I interpret 6 (a) as basically requiring you to be able to
           | install whatever software you like and to provide no
           | mechanism whereby any fee can be demanded for such
           | installation to be possible.
           | 
           | Apple tries to get around this by this core technology stuff,
           | but APIs aren't even subject to copyright protection, and
           | it's also basic interoperability stuff. I don't think the
           | courts will see it the way I interpret your comment.
        
       | LeoPanthera wrote:
       | Since the article doesn't actually repeat what Apple has said,
       | here's what Apple says:
       | 
       | == Begin quote ==
       | 
       | The iOS system has traditionally provided support for Home Screen
       | web apps by building directly on WebKit and its security
       | architecture. That integration means Home Screen web apps are
       | managed to align with the security and privacy model for native
       | apps on iOS, including isolation of storage and enforcement of
       | system prompts to access privacy impacting capabilities on a per-
       | site basis.
       | 
       | Without this type of isolation and enforcement, malicious web
       | apps could read data from other web apps and recapture their
       | permissions to gain access to a user's camera, microphone or
       | location without a user's consent. Browsers also could install
       | web apps on the system without a user's awareness and consent.
       | Addressing the complex security and privacy concerns associated
       | with web apps using alternative browser engines would require
       | building an entirely new integration architecture that does not
       | currently exist in iOS and was not practical to undertake given
       | the other demands of the DMA and the very low user adoption of
       | Home Screen web apps. And so, to comply with the DMA's
       | requirements, we had to remove the Home Screen web apps feature
       | in the EU.
       | 
       | EU users will be able to continue accessing websites directly
       | from their Home Screen through a bookmark with minimal impact to
       | their functionality. We expect this change to affect a small
       | number of users. Still, we regret any impact this change -- that
       | was made as part of the work to comply with the DMA -- may have
       | on developers of Home Screen web apps and our users.
       | 
       | == End quote ==
       | 
       | Source: https://developer.apple.com/support/dma-and-apps-in-the-
       | eu/#...
        
         | sccxy wrote:
         | TLDR: We did not want to give other browsers too powerful apis
         | to compete with Safari & App Store.
        
           | LeoPanthera wrote:
           | I think this is an extremely cynical interpretation.
        
             | akaij wrote:
             | I think any other interpretation is extremely naive.
        
               | rimunroe wrote:
               | Could you explain why?
        
               | fsflover wrote:
               | Because accidentally this move will make more money for
               | Apple. (Follow the money.)
        
               | dylan604 wrote:
               | naive people accept at face value PR speak. unwilling to
               | look past that and look for other ulterior motives even
               | less charitable ones would pretty much be textbook
               | naivety to me.
        
               | rimunroe wrote:
               | I didn't ask because I think someone should take a
               | company's word at face value.
               | 
               | I asked because the thing this company said in this
               | particular instance aligned with what I'd heard from
               | other (independent) parties and I wanted to know why this
               | person seemed so sure about that being wrong.
        
               | dylan604 wrote:
               | Naive people also forget the best lies have some truth
               | woven in.
        
               | akaij wrote:
               | I don't think believing why the most valuable company in
               | the world with the highest and thickest walls around its
               | garden, and a track record of not playing nice with
               | others, is doing this, requires much explanation except
               | that they want to kill the possibility of anyone
               | bypassing the toll gate to the said garden.
        
               | shuckles wrote:
               | Apple could support PWAs and enforce the same Core
               | Technology Fee they do on them as they do for 3p
               | distributed apps, so this argument makes no sense.
        
           | rimunroe wrote:
           | From the (admittedly little) I know about how iOS handles
           | security and the speed at which they responded this sounds
           | like a pretty credible explanation to me. What makes you
           | think it isn't?
        
             | foobarchu wrote:
             | Have to agree (disclaimer, haven't been an iPhone user
             | since the 4). Suddenly allowing all browsers to have those
             | kinds of native permissions, even with massive testing,
             | sounds like a security nightmare. You're introducing an
             | entire extra dimension for security holes, given how much
             | trust people place in their phones.
             | 
             | This doesn't sound at all the same as allowing other
             | engines for use inside browsers, based on both apples
             | defense and the take-downs on them.
        
               | trothamel wrote:
               | Browsers support PWAs on the desktop platforms without
               | there being a security nightmare, and while I'm sure
               | there are some permissions that could be a problem,
               | things like the camera and microphone are managed on the
               | desktop without issue.
               | 
               | Is there some flaw in iOS that makes it harder to secure
               | than the desktop?
        
               | sccxy wrote:
               | They know that giving too powerful apis to other browsers
               | will kill their marketshare and competitors will build a
               | better product in free environment.
        
             | veeti wrote:
             | Because that's literally what it says when you really read
             | into it? They acknowledge that 1) Safari already has all
             | the integrations required to support PWA securely and that
             | 2) they can't be bothered to provide the same API's for
             | third party browsers because it's not "practical".
             | 
             | They built their PWA support in an anticompetitive manner
             | assuming App Store & WebKit would be a monopoly forever,
             | and now as a result the baby is going out with the
             | bathwater.
        
               | rimunroe wrote:
               | > Because that's literally what it says when you really
               | read into it?
               | 
               | I know it's used as an intensifier, but this feels like a
               | particularly bad place to use "literally" that way.
               | 
               | > They acknowledge that 1) Safari already has all the
               | integrations required to support PWA securely
               | 
               | Not really sure how to respond to this. An airliner
               | already has all the controls required for being piloted.
               | Why am I not allowed to pilot my next commercial flight?
               | 
               | But my more serious point:
               | 
               | > 2) they can't be bothered to provide the same API's for
               | third party browsers because it's not "practical".
               | 
               | Why are you glossing over "practical" there and putting
               | it in sarcastic quotes?
               | 
               | This sounds like a huge change in the security model
               | given how tightly Safari is integrated with the rest of
               | iOS. Heavily restricting permissions and sometimes
               | functionality to prevent security threats is very
               | consistent with what I've seen from Apple in the past
               | (and is one of the reasons I prefer them).
               | 
               | Even if they intended to open this stuff up, I can't
               | imagine this is a change which wouldn't require massive
               | changes to iOS and a long review and testing process.
               | 
               | > They built their PWA support in an anticompetitive
               | manner assuming App Store & WebKit would be a monopoly
               | forever, and now as a result the baby is going out with
               | the bathwater.
               | 
               | They built their PWA support for the architecture they've
               | had since the iPhone's release. Why should they have
               | wasted time building affordances for a world in which
               | they were forced to support other browsers?
        
               | gkbrk wrote:
               | > An airliner already has all the controls required for
               | being piloted. Why am I not allowed to pilot my next
               | commercial flight?
               | 
               | Flying a plane badly risks the lives of your passengers,
               | the lives of people on other planes, and people in the
               | nearby area.
               | 
               | Doing whatever you want with your phone doesn't risk
               | other people's phones.
        
               | veeti wrote:
               | > Not really sure how to respond to this. An airliner
               | already has all the controls required for being piloted.
               | Why am I not allowed to pilot my next commercial flight?
               | 
               | What kind of ridiculous "argument" is this? Am I putting
               | hundreds of other people in risk by installing Firefox on
               | my iPhone? The fact remains that the EU in fact does
               | intend to put you in front the airliner's controls. You
               | can of course choose to turn on autopilot and keep using
               | Safari.
               | 
               | > Why should they have wasted time building affordances
               | for a world in which they were forced to support other
               | browsers?
               | 
               | Guess what, "tight integration" of Internet Explorer into
               | Windows for whatever technical reasons was not a
               | favorable argument for Microsoft in front of the European
               | Commission either. Lack of foresight to design open
               | systems is not an excuse in front of the law.
        
               | rimunroe wrote:
               | > What kind of ridiculous "argument" is this? Am I
               | putting hundreds of other people in risk by installing
               | Firefox on my iPhone?
               | 
               | Certainly it's an extreme example, but yes, giving people
               | the ability to install other browsers and app stores _is_
               | increasing their risk. This ruling makes it possible for
               | some companies to decide to only allow their app to be
               | installed through an alternate app store, which won't
               | necessarily restrict malicious code in the same way.
        
               | Elidrake42 wrote:
               | This is why I purchase iOS devices - ultimately their
               | closed garden provides a smaller attack surface, clearly
               | evidenced by the comparative (to Android) cost of
               | exploits on the black market.
               | 
               | I cannot see this as anticompetitive. If you want open,
               | you have that choice in Android.
        
               | rimunroe wrote:
               | This is exactly my feeling too. I don't want the platform
               | to open up more. I left Android because I wanted to make
               | _fewer_ decisions about my device, and to just think
               | about it less in general.
               | 
               | Also, Safari is a non-Chromium-based (though still
               | related) browser which developers are forced to support
               | because it's the only thing allowed on iPhones. Most
               | users aren't going to install Firefox on their iPhone,
               | they're going to install Chrome, which is just going to
               | make Chrome's market dominance worse.
        
               | veeti wrote:
               | I'm sorry to say the EU regulators disagree with you on
               | that.
        
               | rimunroe wrote:
               | We noticed! I'm not thrilled about the decision.
        
               | TheGlav wrote:
               | They built their PWA support with assumptions about how
               | the application, OS, and WebKit were going to run. That's
               | like saying, "Oh, Microsoft didn't build an API layer
               | into Windows to support running X11 apps side by side
               | with Win32 apps, so they were being monopolistic." No,
               | you have limited engineering time and you make
               | engineering tradeoffs. You don't need to design an
               | interface layer and API and hooks between system
               | components if your design doesn't call for it or doesn't
               | need it.
               | 
               | > They built their PWA support in an anticompetitive
               | manner assuming App Store & WebKit would be a monopoly
               | forever, and now as a result the baby is going out with
               | the bathwater.
               | 
               | They built it in such a way that it was sustainable and
               | sensible for the time it was made (iOS 2.0). That's a
               | really long time ago in the software world. More than a
               | dozen versions of the OS have been built on top of this.
               | Saying "they should have just figured it out back then"
               | is completely ignoring the reality of what was offered by
               | the OS and the mobile space entirely at the time.
               | 
               | Now laws have been passed that say "you must provide
               | alternatives." OK. They can choose to spend an ungodly
               | amount of time refactoring the OS to undo 16 revisions of
               | the OS of assumptions for zero benefit for the company,
               | or they can say "Sorry we can't comply with that for your
               | market."
               | 
               | It sucks. But it's a result of reasonable business
               | decisions and their evolutions from a significantly
               | different era.
        
         | sigmar wrote:
         | tbh, I thought the summary in techcrunch was much easier to
         | read and concise.
         | 
         | >Browsers also could install web apps on the system without a
         | user's awareness and consent.
         | 
         | Couldn't this be entirely solved with an OS permission-like
         | prompt "are you sure you want [progressive web app name] added
         | to home screen?"
        
           | npunt wrote:
           | You don't want random processes firing off permissions
           | prompts, you want them to remain meaningful to users on a
           | platform else they'll get prompt fatigue. Think of all the
           | prompts users see and just press 'ok' to.
        
             | sigmar wrote:
             | Heard. But we're going to entirely eliminate all PWAs
             | because there might be an additional prompt added? Seems
             | excessive/specious to me.
        
               | npunt wrote:
               | It's not one additional prompt, it's a class of prompts
               | that could be exploited over and over again. A single
               | site could trigger hundreds by sites popping up in the
               | background each which trigger it, and then the user's
               | home screen is full of fake PWAs with names like 'save
               | money' 'in debt?' 'casino cash bucks' etc. Next you're
               | developing mitigations, spam cleanup, etc. We've gone
               | through this kind of thing before.
        
               | sigmar wrote:
               | The user would get rid of the app/browser that is doing
               | this, no? The same way they would have to for any
               | malicious app that persistently requests a special
               | permission?
        
               | samatman wrote:
               | I'm guessing you've never had to clean up a relative's
               | Windows machine. I wish I could say the same.
        
               | npunt wrote:
               | Yeah ideally. Given there are nearly 1.5 billion active
               | iPhones tho, a lot (100s of millions) of users aren't
               | going to understand the relationship between the prompts
               | and the browser and/or know (/know how) to uninstall the
               | browser and/or have desire to do it at the moment they
               | experience the problem, especially if the browser has
               | other qualities they like. Many more would just blame it
               | on themselves, ignore the problem, etc. These users may
               | make up a plurality or majority of iOS users, and have a
               | totally different experience from a technical user
               | working on a desktop OS (HN crowd).
        
               | anakaine wrote:
               | Are you sure we can't have additional plugin toolbars for
               | Safari? Maybe have one or two that tell us that we can
               | get paid to surf the Web, and a couple of others that
               | definitely don't show popups?
        
             | lxgr wrote:
             | "Yes, allow install (this time)" / "No, don't allow install
             | (this time)" / "No, and never prompt me again"?
             | 
             | iOS has been doing something very similar and it's arguably
             | worked pretty well.
        
           | madeofpalk wrote:
           | I guess that's why they say that "would require building an
           | entirely new integration architecture that does not currently
           | exist in iOS and was not practical to undertake given the
           | other demands of the DMA and the very low user adoption of
           | Home Screen web apps"
        
         | crazygringo wrote:
         | Thanks for posting that. I'm no iOS expert but it actually
         | sounds like a pretty reasonable explanation. It's at least good
         | to hear Apple's side here, and more knowledgeable commenters
         | here can weigh in as to whether it really does seem genuine.
        
           | candiodari wrote:
           | Sure it's reasonable ... because of course all these browsers
           | don't have a security model and just allow web apps to do
           | whatever they want.
           | 
           | This is essentially saying no-one can build a secure browser.
        
             | MrDarcy wrote:
             | No, it's saying they're being forced to support at least
             | one insecure browser which would affect the security of an
             | obscure feature so they're removing the feature.
        
             | bee_rider wrote:
             | Nobody can build a secure browser.
        
               | shuckles wrote:
               | Truer words have not been spoken! Maybe only second to
               | nobody can build a secure baseband.
        
               | dividedbyzero wrote:
               | Security is well achievable, absolute security is not.
               | Somehow almost everyone seems to grasp that intuitively,
               | but a subset of IT keeps pretending they're the same
               | thing.
        
             | nozzlegear wrote:
             | Nobody but Apple has experience building a secure browser.
             | [1]
             | 
             | [1] On iOS.
        
             | weberer wrote:
             | I know at least Firefox has per-site permissions for
             | location, webcam, and microphone access. Is it a correct
             | interpretation that Safari on iOS does not have this
             | feature?
        
               | manmal wrote:
               | Safari has those features.
        
               | shuckles wrote:
               | Their argument was they want the system (iOS) to enforce
               | those permissions, not browsers on behalf of apps they've
               | added.
        
             | dividedbyzero wrote:
             | I don't think they're saying that. I read their statement
             | more like "someone might build an insecure browser", which
             | isn't that invalid a concern I think. I'd like Apple to be
             | a bit more daring and just open up those APIs too, but I
             | kind of get their incentives point the other way. Apart
             | from some landmark design decisions, Apple is an extremely
             | conservative company, and stalling on an issue like this is
             | just what such an org would do.
        
         | secondcoming wrote:
         | > malicious web apps could read data from other web apps and
         | recapture their permissions to gain access to a user's camera,
         | microphone or location without a user's consent.
         | 
         | How is this even possible? It's shocking that these APIs even
         | exist for any browser to use.
        
           | zer00eyz wrote:
           | >> How is this even possible? It's shocking that these APIs
           | even exist for any browser to use.
           | 
           | https://www.theverge.com/24054329/microsoft-edge-
           | automatic-c...
           | 
           | Ask MS, they already did it.
        
             | veeti wrote:
             | This is completely irrelevant to the discussion, there is
             | no sandboxing on PC.
        
             | cqqxo4zV46cp wrote:
             | iOS and Windows' security models are not remotely
             | comparable. I can't imagine that you'd be making such
             | intellectually lazy comparisons if it wasn't in the context
             | of some perceived holy war.
        
           | amelius wrote:
           | I didn't read the article, but to me it sounds like Safari's
           | security mechanisms need more work.
        
             | MBCook wrote:
             | Safari is fine.
             | 
             | Other browsers would have to be trusted, Apple doesn't have
             | a mechanism to ensure that they do what they're supposed
             | to.
             | 
             | So until they have time to add one (remember they already
             | had to create all the API's for third-party browsers to
             | use), they're not allowed to give Safari preferential
             | treatment. So they had to remove the feature.
        
           | kemayo wrote:
           | I assume you mean the "read data from other web apps" part.
           | That'd be because there's (presumably) not a system-level way
           | to launch a third-party browser in "web app mode", with all
           | data siloed off per-PWA. Thus the only way they could
           | currently make web apps work would be to launch the third-
           | party browser and trust that it silos everything adequately
           | itself internally.
           | 
           | Apple _could_ add a bunch of new APIs to support this case
           | for third-party browsers. Presumably there 's something
           | equivalent that's being done for said web apps currently in
           | Safari. But they're not wrong to say that there's not an
           | existing system in place that said third-party browsers are
           | already written to use. (And, you know, they're clearly not
           | invested in trying to make this law _succeed_.)
        
         | zer00eyz wrote:
         | Without this type of isolation and enforcement, malicious...
         | camera, microphone or location ... Browsers ...
         | 
         | 30 some million lines of code in chromium browsers.
         | 
         | Thats bigger than the linux kernel.
         | 
         | The HN crowed might not LIKE apples response but they have a
         | very defensible position.
         | 
         | Edit: Its not like we haven't seen this play out on the desktop
         | recently: https://www.theverge.com/24054329/microsoft-edge-
         | automatic-c...
        
           | cma wrote:
           | But the plain browser already can request camera permissions,
           | in a bad security situation a site that didn't request it
           | still receives it from the browser's system level request.
           | 
           | This is just Apple wanting to avoid people being able to
           | develop a platform on top of their platform without paying a
           | tax.
        
             | zitterbewegung wrote:
             | That's not the point though because WebKit is already
             | secured by Apple but if you have multiple blink related
             | apps like Microsoft edge or brave or Firefox apple will
             | have to audit those too and be on the hook if something
             | breaks and then Apple will have to take the blame over a
             | security oversight they aren't responsible for.
        
               | spaceribs wrote:
               | That assumes that Apple would be blamed for
               | Edge/Brave/Firefox's security oversight.
        
               | etchalon wrote:
               | They would absolutely be blamed by users for it.
        
               | ChilledTonic wrote:
               | Why wouldn't they be? Especially considering their
               | existing reputation in consumers minds for security and
               | reliabilty?
        
               | shagie wrote:
               | If you add a PWA (with Safari) a year ago to your Home
               | Screen and then change your browser to Firefox, and that
               | PWA breaks out and steals some other application data...
               | 
               | Will you blame the software maker that you used to
               | install the icon on the screen? or the one that is
               | seemingly unrelated to the icon on your Home Screen?
        
               | seszett wrote:
               | I would probably blame the "the software maker" for
               | silently switching the engine used by previously
               | installed PWAs. Why do that?
        
               | rickdeckard wrote:
               | You think this uneducated me would know that this was a
               | PWA and no app and also remember that it was installed by
               | Safari, an app I apparently don't own anymore at this
               | stage...?
               | 
               | Why wouldn't Safari remove all its PWA icons when I
               | uninstall it, considering that it anyway cannot transfer
               | the data to another browser...?
        
               | Ajedi32 wrote:
               | So extending this logic to other platforms: if Chrome has
               | a security bug on Windows... you believe people will
               | blame Microsoft? And you think that would be valid
               | justification for Microsoft pushing a "security update"
               | that uninstalls all competing browsers and replaces them
               | with Edge?
        
             | Gigachad wrote:
             | Browsers can still do that. It's more that PWAs look like
             | entirely separate apps which the user would expect to be
             | sandboxed. While a tab in a browser is clearly part of the
             | browser app.
        
               | anon373839 wrote:
               | This is not a meaningful distinction. Users ALSO expect
               | ordinary websites' data to be sandboxed. Users trust that
               | pornhub.com won't be allowed to read data entered into
               | irs.gov.
        
           | summerlight wrote:
           | Why should we trust Apple for security in that context? Apple
           | also provides all those functionalities via their proprietary
           | API, which is not even audit-able. If Apple really believes
           | in that argument, they should disable their own API as well.
        
             | M4v3R wrote:
             | You have to trust someone if you're using a computing
             | device connected to the Internet. The point of being in
             | Apple ecosystem is that you trust Apple, and then
             | (supposedly) you can not trust anyone else. To many that's
             | a very strong proposition.
        
               | summerlight wrote:
               | > The point of being in Apple ecosystem is that you trust
               | Apple,
               | 
               | This seems to be over-generalization? Users are using
               | Apple devices because those are good products, not
               | because they want to delegate every single trust problem
               | to the Apple ecosystem. That might be a great proposition
               | for people like you, but there is a significant number of
               | people who consider it a compromise rather than a value.
        
               | chongli wrote:
               | Users trust Apple because Apple is ultimately accountable
               | for security breaches on iOS devices. If a 3rd party app
               | causes a data breach it does not matter if the breach was
               | made possible by compliance with regulations like the
               | DMA, Apple will still take the blame.
        
               | summerlight wrote:
               | > Users trust Apple because Apple is ultimately
               | accountable for security breaches on iOS devices.
               | 
               | As a long time user of Windows which historically had an
               | incomparably large amount of security incidents, I can
               | assure you that Apple won't get blamed that much for 3rd
               | party data breach unless it involves Apple's own service
               | and user data.
        
               | chongli wrote:
               | Since you're a commenter on HN I'm going to assume you're
               | a tech person. I'm not talking about tech people, who
               | through their discussions try to find the correct
               | person/company to blame for issues.
               | 
               | I'm talking about the general public. If a story about a
               | data breach in a 3rd party app -- affecting iOS users --
               | hits the news cycle, Apple will take the blame and their
               | brand reputation and sales will be impacted. It doesn't
               | matter whose fault it really is, Apple is the face of the
               | iPhone and through their walled garden they have accepted
               | final responsibility for everything that occurs on iOS.
        
               | Wowfunhappy wrote:
               | I don't see how this matters to the GP's argument.
               | Windows was a virus hotbed for decades and that does not
               | appear to have affected its reputation in a meaningful
               | way.
        
               | chongli wrote:
               | That's because Windows' reputation was already mud.
               | Microsoft made their business on corporate users anyway.
               | Apple is a consumer brand. A data breach on iOS is like
               | nudity in a Disney movie: utterly brand-destroying.
        
               | Wowfunhappy wrote:
               | Windows was both. If you were buying a computer in the
               | early 2000s, it was almost certainly a Windows PC.
        
               | anon84873628 wrote:
               | >there is a significant number of people who consider it
               | as a compromise rather than a value.
               | 
               | I suspect that from Apple's perspective, it is
               | definitively _not_ a significant number.
               | 
               | For Apple, ownership of the "trust problem" is an
               | intrinsic part of "making good products".
        
               | summerlight wrote:
               | > For Apple, ownership of the "trust problem" is an
               | intrinsic part of "making good products".
               | 
               | Yes, this might be true. And the majority of elected
               | officials in EU fundamentally disagrees with that
               | statement.
        
               | geodel wrote:
               | > And the majority of elected officials in EU
               | fundamentally disagrees with that statement.
               | 
               | Well, EU can and will force, fine, or ban US companies as
               | they see fit but there is not some fundamental
               | correctness to their viewpoint
        
               | paulmd wrote:
               | Yeah, as I've said before: the root problem here is that
               | the EU wants to outlaw apples business model.
               | 
               | People don't think of it that way, they tell themselves
               | all the reasons why that's a good thing, but that's
               | ultimately what it is - a legislative solution to end the
               | "android vs iOS" debate for all time.
               | 
               | The argument is walled gardens shouldn't exist, so the
               | solution is to either legislate requirements that apple
               | destroy the walls, or that they exit the market. That is
               | a statement that most android advocates would agree with.
               | 
               | And the EU will largely just keep ratcheting up the
               | legislation until that happens. Driving apple out is the
               | point - walled gardens are (in the EU sense) unacceptable
               | and the option for a walled-garden business model needs
               | to be removed from the market.
               | 
               | Apple is (correctly) perceiving this and pulling out of
               | the market, first by dropping the affected features, and
               | I'm sure there will be a "next compliance requirement"
               | before many years too.
        
               | dingle_thunk wrote:
               | Because of course elected officials without any
               | expertise, representing a very small minority of
               | humanity, are the best arbiters of reality.
        
               | geodel wrote:
               | > Users are using Apple devices because those are good
               | products,..
               | 
               | For general populace good also include secure by default.
               | 
               | "every single trust problem to the Apple ecosystem." is
               | rather technical point that very few people would even
               | understand meaning of it.
               | 
               | > significant number of people who consider it a
               | compromise
               | 
               | How significant compare to iPhone user base?
        
             | cqqxo4zV46cp wrote:
             | If you truly have this view then I all but guarantee that
             | you aren't using iOS in the first place. This is a thought-
             | terminating bad-faith argument.
        
               | summerlight wrote:
               | Your argument might be only applicable to some sort of
               | fundamentalists. Most people in the real world make
               | informed decision based on lots of different factors. I'm
               | pointing out that Apple speaks like a security
               | fundamentalist but doesn't act like such. They should
               | choose either one of being fundamentalist or realist, not
               | cherrypicking whatever traits that work in favor of
               | themselves.
        
               | Wowfunhappy wrote:
               | I share the GP's view and I use an iPhone because I must
               | have access to iMessage and there is no alternate way to
               | do that.
        
             | zaphirplane wrote:
             | Apple's business model excludes Clickjacking, stealing
             | personal Information, stealing passwords, commissions from
             | redirects, commissions from gambling sites redirects. Those
             | in that business use browser plugins to get inside your
             | security boundary so your argument maybe over my head or
             | baby bath water thing
        
             | thimp wrote:
             | We don't entirely trust Apple. We just trust them more than
             | other vendors.
        
               | rickdeckard wrote:
               | Who is "we"?
        
               | thimp wrote:
               | Probably the folk upvoting my comment.
        
             | Retric wrote:
             | Using an Apple device requires trust in Apple even if you
             | run a 3rd party operating system let alone a 3rd party
             | application on their OS.
        
           | thimp wrote:
           | As an end user who has been fucked over by the other side
           | (MS/Google/crappy app vendors), I am behind their decision.
           | 
           | If I was not I can choose to leave.
           | 
           | I know this is a divisive comment. Please see my further
           | extrapolation in a child comment.
        
             | circuit10 wrote:
             | How does removing web apps help anything? To me it seems
             | like part of a ploy to create backlash against this law by
             | removing features
        
               | thimp wrote:
               | It's a move against the third party browser engines which
               | have been the bane of my existence from a security
               | perspective on other platforms. For example, the about
               | box in an Android app bundled a whole different browser
               | engine which circumvented device policy entirely and
               | allowed data to be exfiltrated. This app change was
               | delivered in an update by clueless or lazy developers.
               | This is not possible on iOS due to the platform
               | restrictions.
               | 
               | In this case they have to change the integration and
               | sandbox model to allow the security policy to remain
               | intact for people who want and need it. That breaks a few
               | things but it stops the integration from being used for
               | exfiltration among other things.
               | 
               | Note that they're not completely breaking it, just
               | ensuring that the security model stays intact when
               | browser engines have to coexist on the same device. That
               | means sacrificing some convenience for security.
        
               | anon84873628 wrote:
               | I know it is not en vogue to be charitable towards tech
               | companies, but it seems fair to assume that some teams
               | are making a good faith effort to follow the law, and may
               | be forced to accept imperfect design tradeoffs. Like they
               | say, it affects a relatively small number of users, there
               | is a sufficient workaround, and the technical fix would
               | require major investment.
               | 
               | Not everything is a conspiracy.
        
           | anon373839 wrote:
           | > The HN crowed might not LIKE apples response but they have
           | a very defensible position.
           | 
           | You and Apple both are ignoring the fact that these
           | permission APIs exist even if the website isn't being
           | displayed in standalone/full screen mode. The modern web is
           | built on them, and third-party browser engines WILL provide
           | access to these APIs in Europe.
        
         | jensensbutton wrote:
         | Seems like an OS problem. They should fix that.
        
           | lannisterstark wrote:
           | Or they could just not.
        
             | agust wrote:
             | They could develop APIs to support alternate browser
             | engines but could not allow them to install sandboxed web
             | apps on the system? Like all other OSes do, including
             | macOS?
             | 
             | How surprising.
        
               | kmbfjr wrote:
               | Are not some of the changes in the EU so that people
               | won't have to rely on Apple's APIs?
        
               | bobbylarrybobby wrote:
               | The whole point is that doing so would privilege safari
               | over other browsers, which is illegal.
        
             | luuurker wrote:
             | What's the benefit for you as a user to side with Apple on
             | things like this?
        
               | moogly wrote:
               | A seat at Steve Jobs' table in the lunch cafeteria in
               | he...aven?
        
               | vdaea wrote:
               | He's not necessarily siding with Apple. He's pointing out
               | they don't have to do that.
        
               | gretch wrote:
               | Apple has a decade+ track record of making devices that i
               | really like. (At several points I've compared solutions
               | across the market).
               | 
               | Instead of siding with Apple, why would I side with
               | anonymous and random internet commentators who have never
               | made devices I want to buy?
        
               | cqqxo4zV46cp wrote:
               | Please drop the tribalistic vitriol and be an adult about
               | this. The statement is "or they could not". It's factual.
               | It's what Apple did. It's not a religious stance.
        
               | masto wrote:
               | The question was "What's the benefit for you as a user to
               | side with Apple on things like this?". There's no vitriol
               | there. Jumping to the defense of a trillion dollar
               | corporation seems religious or at least tribalistic to
               | me.
               | 
               | And lest I be dismissed as a hater, I currently own five
               | Apple computers, an iPhone I've upgraded every year since
               | they came out, an iPad, a watch, and a virtu^wspatial
               | computing heads^wdevice. But that's because of the
               | transactional value they provide, not because I believe
               | Apple loves me and has my best interests at heart. They
               | love my money and that's where it ends.
               | 
               | I use several PWAs and I will be very disappointed if
               | this is the stick Apple uses to close the window on this
               | short period of time where we had a reasonably
               | interoperable standard for making "apps" using web
               | technologies. I can run Elk in a browser, but it's
               | suboptimal.
        
               | pb7 wrote:
               | Pretty simple: I like the way Apple does most things. I'm
               | rarely disappointed by the culmination of all of their
               | decisions. I'm _frequently_ disappointed with how other
               | companies do things therefore I don 't want their disease
               | to spread to things I'm perfectly content with.
        
               | shuckles wrote:
               | The sides in this debate are: Apple, Chrome advocates
               | (with a little bit of separation), and the EU. It's not
               | that perplexing to choose the first.
        
               | robertlagrant wrote:
               | > What's the benefit for you as a user to side with Apple
               | on things like this?
               | 
               | Looking at these things as sides is a mistake. Instead of
               | just being tribal, it's better to look positions on their
               | merits.
        
           | TheGlav wrote:
           | Of course they could. They looked at the cost of rewriting
           | the entire integration and framework for running PWAs and
           | said, "eh, nah."
        
             | jeroenhd wrote:
             | They'll have to allow some kind of app installation API to
             | allow for alternative app stores. If Google implements some
             | kind of WebAPK technology on iOS, they may just be able to
             | launch a Google Play for iOS to work around these PWAs as a
             | workaround, and Safari will be down a feature.
             | 
             | I have the feeling Apple is betting on Google not caring
             | enough about the PWA platform to try to compete. Maybe
             | they're right, but if they're not, they're only making the
             | browser wars worse for themselves.
        
         | carlosrg wrote:
         | Didn't Apple made a comprehensive list of requirements for
         | alternative web browsers and web browser engines so they are
         | secure and don't compromise the user's security?
         | (https://developer.apple.com/support/alternative-browser-
         | engi...)
         | 
         | I'm a little confused. So that long list of requirements is
         | useless for PWAs?
         | 
         | Some people will actually believe this. I'm utterly disgusted
         | by Apple and their arrogance regarding the DMA, and the way
         | they've managed all of this. My perception of them has
         | completely changed. However, they seem very obedient when China
         | asks them to censor apps or, for example, limit AirDrop when
         | there's a protest going on.
        
         | agust wrote:
         | Repeating Apple's lies is really not useful. Probably why the
         | original article didn't do it, and instead provided an analysis
         | with diverse sources.
        
           | lambdas wrote:
           | That's ridiculous. It's the antithesis of RTFA; you have to
           | read an argument for yourself else you're just parroting the
           | opinions of others.
        
         | shmerl wrote:
         | _> Addressing the complex security and privacy concerns
         | associated with web apps using alternative browser engines
         | would require building an entirely new integration
         | architecture_
         | 
         | Translation from Apple talk to real talk: allowing competing
         | browser engines will undermine our grip on the market through
         | lock-in to the engine we fully control. We don't want to lose
         | power. As control freaks, we'll do all we can to sabotage it.
        
         | sgift wrote:
         | so, tldr: Apple tries to bullshit the EU again. EU commission -
         | get them.
         | 
         | They say themselves it would be possible to be compliant with
         | the DMA without removing what is obviously competition they
         | don't like. But they try to take the road which - just by
         | chance, obviously, the security is the real reason - helps them
         | to keep more people away from competition. I don't buy it.
        
         | stephc_int13 wrote:
         | The technical justification are bullshit.
         | 
         | They simply could ask browser vendor to follow strict rules,
         | that they can check themselves. This is not like they would
         | have to verify dozens of browsers every day. Only a few per
         | months, top.
        
           | jeremyjh wrote:
           | They are not saying it is impossible, only that they have not
           | done it. How long do you think it will take to spin up such a
           | review and certification program? How much will it cost, and
           | how many sales will they lose because of the lack of this
           | feature in the EU?
        
             | veeti wrote:
             | There will already be a review and certification program
             | for third party browsers that want the required
             | entitlements
             | (https://developer.apple.com/support/alternative-browser-
             | engi...), so why don't you ask Apple?
        
           | TheGlav wrote:
           | Browsers need to run javascript to be competitive browsers.
           | It would be practically impossible to check even simple
           | "strict rules".
        
         | benguild wrote:
         | The "low usage" comment is going to be more ammo against Apple
         | unfortunately. The whole reason they are low usage on PWAs is
         | because of a lack of investment from Apple and a lack of
         | parity, yet for the longest time Apple has played both sides by
         | saying PWAs are a viable alternative to the App Store, all
         | while channeling people to App Store for actual app downloads
         | and not providing similar marketing or anything for PWAs
        
           | thimp wrote:
           | Are you sure this isn't a tech industry viewpoint? I don't
           | know anyone who knows what the difference between an app and
           | a PWA is. I don't think I've seen anyone outside of the tech
           | industry with a PWA active.
           | 
           | In context 99% of the users I meet don't even know what USB-C
           | is.
        
             | tester89 wrote:
             | The only PWA that I think gets any use on i(Pad)OS is that
             | for the Financial Times.
        
             | anakaine wrote:
             | Fair call on your first point about PWA knowledge level in
             | users. Regarding your users knowledge of what USB-C is: are
             | you sure your user group are not potato's? Most people I
             | know, including the teenage daughters and their friends,
             | all know what USB-C is these days.
        
               | thimp wrote:
               | One of them was going to buy a new phone because it took
               | a long time to charge. This was because she had a crap
               | charger and crap cable. I am unsure if they are potatoes
               | or not but I suspect they might be :)
        
             | benguild wrote:
             | Correct on it being a tech industry viewpoint-- people
             | think "apps come from the App Store" and therefore anything
             | else that's clunky requires a fair amount of education and
             | payoff for users to adopt.
             | 
             | It's off balance, and it shows now that the tech has to be
             | removed since it wasn't actually at parity despite it being
             | an argument for it unfortunately.
             | 
             | The worst part? This has been the case for 15 years. It's
             | not like there wasn't enough time to fix it. That's plenty
             | of time to hire and develop solutions, yet now look at the
             | reasons for it being taken away.
        
         | glenjamin wrote:
         | Am I missing something?
         | 
         | Couldn't they allow you open PWAs in Safari, or fall back to
         | opening a URL in another browser?
         | 
         | Is there some part of the DMA which demands full feature
         | parity?
        
       | 5evOX5hTZ9mYa9E wrote:
       | The good news is that DMA contains private right of action. Might
       | as well start drafting the responsive court filings already,
       | March 8th is just around the corner.
        
       | gargs wrote:
       | This is the courageous Apple we've all been waiting for. One that
       | doesn't think twice about antagonizing its users just to throw a
       | tantrum.
        
       | johanneskanybal wrote:
       | As a European dev I want apple to fail super hard and implode.
       | They used to be so cool and make slick hardware for their nische
       | but now I'm happy to use worse hardware as long as they disapear
       | from the face of the earth.
        
         | gear54rus wrote:
         | They ain't never been cool. The shit practices they are trying
         | to defend were there from day 1 and are baked into their DNA.
         | Treating their users like stupid animals that don't know what's
         | good for them is what they do. And they will fight tooth and
         | nail to continue to do it. Even as EU tries to kick their
         | predatory ways out of them.
         | 
         | To think there's a hardware thing in 2024 that does not allow
         | its owner to compile and install arbitrary software while still
         | calling itself a smartphone is just laughable.
         | 
         | It's a good thing people are starting to wake up to this even
         | on legislative level.
        
           | amelius wrote:
           | > Treating their users like stupid animals that don't know
           | what's good for them is what they do.
           | 
           | The problem I have with that is that they are selling a
           | ContentFilter as an integrated part of their OS, when it can
           | be a separate, optional part, and even offered by a third
           | party.
           | 
           | Also, they equate AppStore == ContentFilter, which are
           | clearly two separate concepts.
        
           | pb7 wrote:
           | Most users are stupid though. Reminder that a US congressman
           | once grilled Google's CEO about whether Google was tracking
           | his iPhone's precise location. And this one was smart enough
           | to con his way into Congress.
           | 
           | "I have an iPhone, and if I move from here and go over there
           | and sit with my Democrat friends, which would make them real
           | nervous, does Google track my movement?" -- Ted Poe
           | 
           | https://www.cnet.com/tech/mobile/google-ceo-pichai-
           | grilled-o...
        
             | jeroenhd wrote:
             | > "I have an iPhone, and if I move from here and go over
             | there and sit with my Democrat friends, which would make
             | them real nervous, does Google track my movement?" -- Ted
             | Poe
             | 
             | The thing is, if this was a real life situation, and he
             | would seek out and politically collaborate with/stalk and
             | listen in on his Democrat friends, there's a good chance
             | Google would know. Not because of a digital AirTag Google
             | installed on his phone, but because of the tracking and
             | data analysis Google has access to.
             | 
             | The indirection and hidden mechanisms Google (and other
             | data trading companies) use are impossible to comprehend
             | for normal people, and they're banking on that to continue
             | being allowed to do that.
        
               | pb7 wrote:
               | The point was that he has no idea where the boundaries
               | around between Apple and Google and what is within the
               | realm of possibility of abuse and what is strictly
               | impossible without him tapping "accept" via a system
               | prompt. It is not possible for Google to track his
               | location without him granting permission to do so on his
               | iPhone. It is not possible to get precise location data
               | without a prompt and a blue system indicator. It is not
               | possible to get repeated location data without iOS
               | eventually notifying you of the background activity (even
               | the stock Weather app is not immune to this). All of this
               | is because Apple has fine control over the system.
        
         | amelius wrote:
         | Yes, that's the way I feel too. I learned to program on an
         | Apple ][ that I loved, before Jobs started his nefarious
         | business practices. Woz's Apple was cool. Jobs' Apple makes me
         | feel like they want to enslave developers, or at least milk
         | them to the last drop.
        
       | whatsthatabout wrote:
       | Wanted to try an android phone for some time again anyways,
       | thanks apple :)
        
       | akmarinov wrote:
       | Since iPadOS doesn't get alternative stores and alternative
       | browsers - I wonder whether PWAs will still work on iPads in the
       | EU. That'd be funny.
        
         | hardcopy wrote:
         | They still work on iPadOS
        
       | brikym wrote:
       | I'm actually thinking of switching back to Android because of
       | this bullshit. There are a lot of niche web apps I use,
       | particularly for local things, that just won't be developed into
       | an iOS app because it's not viable.
        
         | tonoto wrote:
         | Android user since ~2010 (before that, Symbian).. I tried one
         | of Apple's "Pro" phones with IOS 2021, last year I went back to
         | Android and back to freedom even if it is Google's walled
         | garden. Still, being able to control many aspects of the phone
         | (choice of browser, do I need to mention different volume
         | controls, can compile own stuff, automation) is unbeatable. To
         | me using iPhone left me with the same crippled feeling that I
         | would have if someone forced me to use Windows on a computer.
         | On the plus side, my screen time was actually lower during
         | those two years..
        
       | smeagull wrote:
       | Seems like a very unreliable platform to me.
        
       | ttarr wrote:
       | These kind of news make me feel happy that I'm Apple, Microsoft
       | and Google* free.
       | 
       | Phone is ungoogled Android.
        
       | ivan_gammel wrote:
       | Very questionable argumentation. This can be seen from two
       | different angles:
       | 
       | 1. PWA is a native wrapper for a web application, not a browser.
       | It is supposed to be limited to the app website. DMA does not
       | tell Apple that every app with embedded WebView should offer
       | users possibility to switch the engine. Why PWA should be treated
       | differently here? I'd rather clarify this with regulators first,
       | before harming end users.
       | 
       | 2. There's no browser engines currently supporting PWA on Apple
       | mobile devices. Apple has enough resources and time to figure out
       | how to sandbox PWAs on other engines together with the first
       | browser vendor that decides to offer such support and commit
       | engineering resources to this project. In the meantime current
       | solution could stay simply because it does not hinder any
       | competition.
       | 
       | I'm not a legal expert, so maybe I miss something here. But Apple
       | statement does not look convincing to me.
        
         | Someone wrote:
         | > DMA does not tell Apple that every app with embedded WebView
         | should offer users possibility to switch the engine.
         | 
         | I don't see how that's related to the issue being discussed.
         | 
         | > In the meantime current solution could stay simply because it
         | does not hinder any competition.
         | 
         | Why do you think "you can install a third party browser, but if
         | you do, you can't add PWAs to the Home Screen" doesn't hinder
         | competition?
        
           | ivan_gammel wrote:
           | >I don't see how that's related to the issue being discussed.
           | 
           | PWA is not a browser, it is a native app using a browser
           | engine to render a specific website.
           | 
           | >Why do you think "you can install a third party browser, but
           | if you do, you can't add PWAs to the Home Screen" doesn't
           | hinder competition?
           | 
           | I literally explained it in my comment you are replying to,
           | but I can repeat. Competition does not exist yet. Browsers do
           | not offer PWA support out of the box, it is a feature to be
           | implemented separately from rendering engine. See Firefox on
           | Windows for an example -- it doesn't support PWA out of the
           | box. This feature has to be built: if Apple were to hinder
           | the competition, they would resist it by not offering the
           | APIs. But they can offer them through the cooperation with
           | vendors, even if those APIs do not exist yet. Say, Mozilla
           | comes and asks for APIs: Apple starts negotiating and
           | proposes the compatibility requirements and a reasonable
           | timeline. They both work on their part and eventually Firefox
           | is released with PWA support. Who would fine or sue them if
           | it worked this way? How the violation of DMA could be proven?
        
       | pierrebai wrote:
       | Come on now, if it was /that other company/ you'd be saying it
       | without a pause.
       | 
       | FUD
       | 
       | See? Not hard to say, even when it is Apple and not Microsoft.
       | The concept that browser allow one web site to read the storage
       | of other sites is ludicrous. SuuuuuUUUuuure Apple can't
       | /guarantee/ that the browser has no bug... which assumes Apple
       | can somehow prove their own browser is bug-free. Plus, what
       | prevents Apple from launching separate instances with separate
       | data permissions for WPA? That's is 99% certainly what they did
       | with their own WebKit-based solution.
       | 
       | FUD FUD FUD
        
       | 23B1 wrote:
       | AAPL's recent behavior has really degraded the brand for me
       | personally.
       | 
       | Like I won't be buying the Vision Pro because I'm not really sure
       | I want to get further locked into their ecosystem if they're this
       | hostile towards the will and rights of the people who buy their
       | products.
        
       | Alifatisk wrote:
       | Bummer, so all these recent news about Apple allowing push
       | notifications and PWAs to iPhone was for nothing?
        
         | sccxy wrote:
         | I guess they realized that if they opened up too much of their
         | walled garden, there was no going back.
        
         | mnau wrote:
         | If you are ouside of EU, it wasn't for nothing.
         | 
         | EU is only sixths of world GDP and shrinking.
        
           | Alifatisk wrote:
           | That's a big if
        
       | malermeister wrote:
       | https://www.youtube.com/watch?v=VtvjbmoDx-I
       | 
       | Apple has become the IBM in their famous 1984 ad. "A garden of
       | pure ideology", indeed.
        
       | dontdoxxme wrote:
       | Probably easier to leave the EU than get Apple to listen.
        
       | hardcopy wrote:
       | Sigh. This is a huge headache for me.
       | 
       | https://lemmy.world/post/12001569
       | 
       | (I develop https://github.com/aeharding/voyager)
        
       | nonrandomstring wrote:
       | Said it before and it seems clearer every day, that we're in an
       | era reminiscent of the 1920s with big mobs fighting it out. One
       | of the old games back in town is _protection rackets_ [0],
       | digital forms of ransacking, vandalism, threats and  "tax"
       | collecting are all the rage dontchyknow.
       | 
       | Everyone's got their "security" to give you. But it ain't your
       | security, and it ain't compatible with noone else's.
       | 
       | Nice app store you got here. Shame if anything might 'appen to
       | it!
       | 
       | [0] https://en.wikipedia.org/wiki/Protection_racket
        
       | torartc wrote:
       | Is there anything we can actually do to push back on this? I get
       | we can long term just not buy their products, but it feels like
       | there needs to be more urgent action then that.
        
         | jeroenhd wrote:
         | I don't think so. Either the EU takes action (assuming what
         | Apple does is illegal, though I doubt it) or you'll have to
         | vote with your wallet.
         | 
         | Perhaps your best bet would be to loudly proclaim Apple's user-
         | hostile behaviour as the reason you're switching to another
         | brand of phone, so non-tech people also learn about Apple's
         | hissy fit, but I doubt it'll do much to their bottom line.
        
       | pseudony wrote:
       | On the point of trusting (big) Apple to keep us safe.
       | 
       | This was linked in a similar discussion today. Either they
       | knowingly provide backdoors for state actors or they are being so
       | incompetent that it is laughable. Zero interaction remote exploit
       | of hardware features designed to circumvent their own security
       | measures? Why ?
       | 
       | Seriously, find someone worthy of your trust, because that isn't
       | Apple
       | 
       | https://www.kaspersky.com/about/press-releases/2023_kaspersk...
        
       | Ajedi32 wrote:
       | Honestly this doesn't bother me as much as some of the other
       | malicious compliance Apple has been doing. It sounds like Safari
       | had a pretty tight level of integration with the operating system
       | in order to allow PWAs, and creating secure APIs to allow other
       | 3rd party browsers to achieve the same thing would have been
       | expensive. So in order to avoid giving preferential treatment
       | Safari over competing browsers without incurring that cost they
       | had to remove PWA support.
       | 
       | Obviously long-term what should happen is that Apple should build
       | out those necessary APIs, then re-introduce PWA support to Safari
       | and 3rd party browsers, but I personally feel like the EU trying
       | to legislate an entirely new platform feature into existence like
       | that would be a step too far.
       | 
       | Some of the other concerns with Apple's recent moves (like them
       | trying to charge developers for installs that don't go through
       | Apple's App Store, and that Apple therefore has nothing to do
       | with) are a far bigger issue.
        
       | niutech wrote:
       | Bad move from Apple. It's time to boycott iOS and move to FOSS
       | alternatives, such as: AOSP, Ubuntu Touch, GNOME Mobile, KDE
       | Plasma, Sailfish OS. Personally I am using both UBports and
       | Sailfish OS and I appreciate the privacy they provide.
       | 
       | As a possible workaround to fullscreen PWAs in iOS in the EU, I
       | propose a convention to append some hash to the Web App Manifest
       | start_url, e.g. #__pwa__, then set the default iOS web browser to
       | e.g. Firefox, then add the PWA to the home screen from it with
       | this special hash. When a user clicks on a PWA icon in the home
       | screen, it would open in the default browser (e.g. Firefox), the
       | browser then checks if the newly opened tab is opened from
       | external source and its URL ends with #__pwa__ and if so, then
       | hides the UI providing a fullscreen viewport for the opened PWA.
        
         | dbtc wrote:
         | What's a good device to replace my iphone 13 mini?
        
       | anon373839 wrote:
       | It's disappointing to see that Apple's spin job is apparently
       | working (based on some of the comments here). While it sounds
       | superficially plausible, it's actually quite deceitful.
       | 
       | For example, the argument that one web app could steal the
       | permissions of another web app is predicated on the assumption
       | that a non-Apple browser engine will fail to sandbox the apps.
       | But *the exact same* threat vector will exist for non-Home Screen
       | web apps accessed through third party browsers. That's because
       | ordinary websites ALSO have the ability to request access to
       | microphones and cameras, and it will be up to the developers of
       | the browser engines to ensure that these permissions are properly
       | sandboxed. Apple won't be able to eliminate this risk without
       | breaking vast numbers of sites that people use every day.
       | 
       | In truth, a PWA is no different from a website. It's built using
       | the same technologies and APIs. The main difference is that it
       | can run in full-screen mode like an app, and it has its local
       | storage cleared less often. These are nice extras that benefit
       | users who choose to "install" such apps, and they carry no
       | special security risks.
        
       | macinjosh wrote:
       | Apple ducking sucks.
        
       | w4 wrote:
       | I'm primed to be upset with Apple at this point, but this doesn't
       | seem like an unreasonable position. The EU is forcing them to do
       | a bunch of work to support alternate browser engines, this
       | creates a bunch of additional work if Apple wants to fully
       | support PWAs, PWAs aren't really in Apple's financial interest to
       | begin with, so eff it. We're not supporting PWAs in the EU.
       | 
       | That doesn't seem that unfair. Apple isn't a charity, so why
       | spend resources on extra work they didn't want to do in the first
       | place, and that is not required for legal compliance.
        
       ___________________________________________________________________
       (page generated 2024-02-15 23:00 UTC)