[HN Gopher] Apple confirms it's breaking iPhone web apps in the ...
___________________________________________________________________
Apple confirms it's breaking iPhone web apps in the EU on purpose
Author : M2Ys4U
Score : 267 points
Date : 2024-02-15 20:22 UTC (2 hours ago)
(HTM) web link (techcrunch.com)
(TXT) w3m dump (techcrunch.com)
| givemeethekeys wrote:
| It's news like this that makes me want to trade my iPhone for the
| closest Android phone.
| Fizzadar wrote:
| Honestly Apple's response to the DMA changes is pathetic, they're
| acting like a petulant child. I really hope the EU throws the
| book at them. Will believe it when I see it, fingers crossed.
| Fizzadar wrote:
| I say all this as a MacBook, iPhone and AirPods user (:
| addicted wrote:
| I don't think Apple's pettiness is gonna work in their favor.
|
| I am not in the EU but my next iPhone is almost certainly not
| gonna be an iPhone despite me having used a non iPhone for about
| 6 months in the last 15 years.
|
| Their throwing their customers under the bus just to throw a
| tantrum in the EU does not bode well for how they would treat
| their customers in other situations.
| JadeNB wrote:
| > I am not in the EU but my next iPhone is almost certainly not
| gonna be an iPhone ....
|
| Next _phone_ , right?
| shaan7 wrote:
| Thats just parent's way of playing around with all the AI
| models reading this page xD
| toyg wrote:
| They're desperately hoping that their fanbois will howl so
| much, that MEPs will relent.
| akmarinov wrote:
| Whatever they manage to eek out in the EU, is the future of
| what iOS will be in the US and worldwide eventually. If they go
| with fully fledged PWAs that the other browser engines will
| enable - there's little reason to use the Appstore, hence Apple
| losing their 30% commission.
|
| From their perspective it's not so much throwing a tantrum but
| clawing and screaming their way into giving up as little
| revenue as possible.
| jkestner wrote:
| And as a developer, I see how I'm going to be collateral
| damage, and am less likely to do anything that gives Apple
| more power over me and my customers. If that means a
| bookmarked web app, so be it.
| Zagitta wrote:
| I hope EU comes down HARD on them for trying to pull this shit
| deminature wrote:
| In combination with the 'Core Technology Fee' that financially
| cripples any developer that tries to release a popular app
| outside the official app store, this is pathetic behavior.
| Hopefully the EU smacks them down for this temper tantrum at
| being forced to adhere to the DMA. They are trying to flex their
| market power and should be reminded they operate within a system
| of laws that doesn't bend for anyone, regardless of their size.
| SllX wrote:
| I'm going to be level with you: there is nothing so great about
| PWAs that they're worth mandating or protecting by law in any
| jurisdiction and the EU doesn't owe it to you to try.
|
| Web developers like them. That's it, and their PWA advocacy
| completely disregards what a privacy and security nightmare
| they can be without proper safeguards, because this little
| device I carry around in my pocket is 1) always with me and 2)
| stores a lot of information about me 3) has a full sensory
| array installed within it.
|
| Every new feature browsers add for better hardware access gets
| immediately disabled on any system I manage: cameras, mics, USB
| access, sensors, location, notifications, local storage, the
| whole works because the alternative is letting every website
| access those or getting spammed with access requests on every
| site I visit and the more crap that is added, the longer it
| takes me every time I setup a new browser install from scratch.
| Why disable them at all? Because 99% of these new features are
| primarily used to build a better supercookie to track and
| profile people without their consent. The actual marketable
| reasons are a secondary use at best.
|
| So if it's not on Apple's priority list to build out whatever
| they need to support and allow other browsers to support PWAs
| in a secure and privacy conscious manner, good for them. Web
| developers who want to circumvent Apple's fees entirely don't
| need to be anywhere near their top priority and can wait. For
| Apple: users come before developers, and App developers before
| web developers.
| deminature wrote:
| I'm not a fan of PWAs either, but disabling them instead of
| allowing them to continue to run is an incredibly bad faith
| response to the DMA.
| SllX wrote:
| Not if the alternative is allowing other browsers to
| install them without a privacy and security architecture in
| place first.
|
| Even if Apple thinks it's worth doing, that takes time, and
| web developers aren't worth prioritizing for them when they
| have a lot of other ground to cover building out a new
| system of APIs and entitlements to comply with the DMA's
| other requirements.
| deminature wrote:
| The user is warned already on the App Store that
| installing apps from third-parties comes with certain
| risks via 'scare screens'. There's no reason they can't
| do the same for PWAs.
| SllX wrote:
| They probably will if they ever re-enable it in the EU,
| but they also built out over 600 new APIs and an
| accompanying system of entitlements to go with that scare
| sheet such that even if it's "riskier", they're not just
| throwing up their hands and saying "alright devs, we
| scared them a little, so now go do whatever the hell you
| want".
|
| EDIT: I should also add that of those 600, that includes
| APIs Apple built out specifically for third-party
| browsers.
| deminature wrote:
| I think PWA developers are going to be pretty
| unsympathetic to 'your PWA is going be available again in
| the EU at some unspecified time in the future, when some
| Apple product manager decides to prioritize it for a
| given year's roadmap and it's all in the interests of
| protecting users from unspecified privacy and security
| threats that nobody seems to be able to define'. Most
| importantly, the EU may feel the same way.
| SllX wrote:
| Well to correct you, my position is more "Apple might re-
| enable this" more than "will", which from their
| perspective I'm guessing is even worse and they will be
| more unsympathetic to it.
|
| Personally I think Apple will, but I have enough doubts
| that I don't want to make that claim.
|
| > Most importantly, the EU may feel the same way.
|
| That's the rub. The EU has been arbitrarily writing new
| laws which mostly target foreign tech companies that
| don't quite read "show me your bellies so we can pick out
| the choice cuts" but they're pretty close. So the EU
| might do a lot of things, but if there's an argument
| against them doing that, it's what I said in my first
| comment above: it's not worth any jurisdiction's time to
| do so. That includes the EU.
|
| You might need to support some technologies to get
| government contracts, but nobody ever mandated you had to
| support POSIX or J2ME or whatever to sell a computer or
| phone to regular people. That would be asinine, and a PWA
| mandate would also be asinine.
| deminature wrote:
| The arbitrary laws that the EU has been writing are the
| one of the last bulwarks consumers have against the
| creeping power of tech giants and these companies are
| making more money than ever in spite of regulation, so it
| doesn't seem to be affecting them too adversely.
| SllX wrote:
| The biggest abuses in tech come down on the adtech side
| of things where in order for them to make money, they
| need to know who you are, and they will do everything
| within their power to make sure that they do with or
| without your consent.
|
| Telecoms companies (in which I am including carriers)
| also often fall within this because they are often
| envious of adtech companies and want what they have and
| can theoretically make better guarantees about who
| somebody is.
|
| Not supporting PWAs isn't in the same league, but I would
| also add to that: running a popular messenger, running a
| popular search engine, and controlling distribution of
| software on a popular phone platform. Spinning up new
| laws around terminology designed to have bad PR
| ("gatekeepers") is pretty damn arbitrary as far as
| lawmaking goes.
| zadokshi wrote:
| No one meads "scare screens".
|
| I'm. It sure what I think about this yet, but I'm pretty
| sure I'm going to land on "allowing less privacy aware
| browsers to run web "apps" with heightened privileges
| seems like a recipe for disaster.
|
| Maybe in the long term ther is a way to do it well. But
| for now I'm not sure.
| deminature wrote:
| Every app on iOS is sandboxed and the damage they can do
| is very limited. There's risks involved in opening up to
| third-party apps, and PWAs are only marginally more
| dangerous. Non-WebKit based browsers don't even exist
| today, this is not a real problem and won't be for some
| time.
|
| The obvious solution for now is to enable WebKit PWAs and
| turn on PWAs for other as-yet uninvented custom browsers
| as they release, testing for privacy as they get
| released.
| WirelessGigabit wrote:
| There is little difference on iOS between a PWA and a website
| which has a WebKit view and hosts a website.
|
| The only reason PWAs were interesting on iOS was to get an
| app on iOS, while feeling relatively native, without paying
| Apple.
| kryptiskt wrote:
| Yeah, this isn't a parlor game, I have no idea why they think
| the antitrust pressure will abate by such bad faith nonsense
| moves. Next step for the EU is to make Tim Cook choose whether
| he wants to be CEO of the device side or service side of the
| broken up Apple. It's clear that fining them is useless.
| lannisterstark wrote:
| Ah yeah man EU is totally gonna break up apple.
|
| Some of y'all need to be reminded to be realistic.
| deminature wrote:
| The DMA has potential fines of 20% of global annual revenue
| for non-compliance. Apple is playing with fire here. Laws
| like GDPR and DMA are designed to be just as scary for big
| entities as small.
| robertoandred wrote:
| This IS adhering to the DMA. Every browser engine is treated
| the same.
| impossiblefork wrote:
| I think that's very unlikely.
|
| I interpret 6 (a) as basically requiring you to be able to
| install whatever software you like and to provide no
| mechanism whereby any fee can be demanded for such
| installation to be possible.
|
| Apple tries to get around this by this core technology stuff,
| but APIs aren't even subject to copyright protection, and
| it's also basic interoperability stuff. I don't think the
| courts will see it the way I interpret your comment.
| LeoPanthera wrote:
| Since the article doesn't actually repeat what Apple has said,
| here's what Apple says:
|
| == Begin quote ==
|
| The iOS system has traditionally provided support for Home Screen
| web apps by building directly on WebKit and its security
| architecture. That integration means Home Screen web apps are
| managed to align with the security and privacy model for native
| apps on iOS, including isolation of storage and enforcement of
| system prompts to access privacy impacting capabilities on a per-
| site basis.
|
| Without this type of isolation and enforcement, malicious web
| apps could read data from other web apps and recapture their
| permissions to gain access to a user's camera, microphone or
| location without a user's consent. Browsers also could install
| web apps on the system without a user's awareness and consent.
| Addressing the complex security and privacy concerns associated
| with web apps using alternative browser engines would require
| building an entirely new integration architecture that does not
| currently exist in iOS and was not practical to undertake given
| the other demands of the DMA and the very low user adoption of
| Home Screen web apps. And so, to comply with the DMA's
| requirements, we had to remove the Home Screen web apps feature
| in the EU.
|
| EU users will be able to continue accessing websites directly
| from their Home Screen through a bookmark with minimal impact to
| their functionality. We expect this change to affect a small
| number of users. Still, we regret any impact this change -- that
| was made as part of the work to comply with the DMA -- may have
| on developers of Home Screen web apps and our users.
|
| == End quote ==
|
| Source: https://developer.apple.com/support/dma-and-apps-in-the-
| eu/#...
| sccxy wrote:
| TLDR: We did not want to give other browsers too powerful apis
| to compete with Safari & App Store.
| LeoPanthera wrote:
| I think this is an extremely cynical interpretation.
| akaij wrote:
| I think any other interpretation is extremely naive.
| rimunroe wrote:
| Could you explain why?
| fsflover wrote:
| Because accidentally this move will make more money for
| Apple. (Follow the money.)
| dylan604 wrote:
| naive people accept at face value PR speak. unwilling to
| look past that and look for other ulterior motives even
| less charitable ones would pretty much be textbook
| naivety to me.
| rimunroe wrote:
| I didn't ask because I think someone should take a
| company's word at face value.
|
| I asked because the thing this company said in this
| particular instance aligned with what I'd heard from
| other (independent) parties and I wanted to know why this
| person seemed so sure about that being wrong.
| dylan604 wrote:
| Naive people also forget the best lies have some truth
| woven in.
| akaij wrote:
| I don't think believing why the most valuable company in
| the world with the highest and thickest walls around its
| garden, and a track record of not playing nice with
| others, is doing this, requires much explanation except
| that they want to kill the possibility of anyone
| bypassing the toll gate to the said garden.
| shuckles wrote:
| Apple could support PWAs and enforce the same Core
| Technology Fee they do on them as they do for 3p
| distributed apps, so this argument makes no sense.
| rimunroe wrote:
| From the (admittedly little) I know about how iOS handles
| security and the speed at which they responded this sounds
| like a pretty credible explanation to me. What makes you
| think it isn't?
| foobarchu wrote:
| Have to agree (disclaimer, haven't been an iPhone user
| since the 4). Suddenly allowing all browsers to have those
| kinds of native permissions, even with massive testing,
| sounds like a security nightmare. You're introducing an
| entire extra dimension for security holes, given how much
| trust people place in their phones.
|
| This doesn't sound at all the same as allowing other
| engines for use inside browsers, based on both apples
| defense and the take-downs on them.
| trothamel wrote:
| Browsers support PWAs on the desktop platforms without
| there being a security nightmare, and while I'm sure
| there are some permissions that could be a problem,
| things like the camera and microphone are managed on the
| desktop without issue.
|
| Is there some flaw in iOS that makes it harder to secure
| than the desktop?
| sccxy wrote:
| They know that giving too powerful apis to other browsers
| will kill their marketshare and competitors will build a
| better product in free environment.
| veeti wrote:
| Because that's literally what it says when you really read
| into it? They acknowledge that 1) Safari already has all
| the integrations required to support PWA securely and that
| 2) they can't be bothered to provide the same API's for
| third party browsers because it's not "practical".
|
| They built their PWA support in an anticompetitive manner
| assuming App Store & WebKit would be a monopoly forever,
| and now as a result the baby is going out with the
| bathwater.
| rimunroe wrote:
| > Because that's literally what it says when you really
| read into it?
|
| I know it's used as an intensifier, but this feels like a
| particularly bad place to use "literally" that way.
|
| > They acknowledge that 1) Safari already has all the
| integrations required to support PWA securely
|
| Not really sure how to respond to this. An airliner
| already has all the controls required for being piloted.
| Why am I not allowed to pilot my next commercial flight?
|
| But my more serious point:
|
| > 2) they can't be bothered to provide the same API's for
| third party browsers because it's not "practical".
|
| Why are you glossing over "practical" there and putting
| it in sarcastic quotes?
|
| This sounds like a huge change in the security model
| given how tightly Safari is integrated with the rest of
| iOS. Heavily restricting permissions and sometimes
| functionality to prevent security threats is very
| consistent with what I've seen from Apple in the past
| (and is one of the reasons I prefer them).
|
| Even if they intended to open this stuff up, I can't
| imagine this is a change which wouldn't require massive
| changes to iOS and a long review and testing process.
|
| > They built their PWA support in an anticompetitive
| manner assuming App Store & WebKit would be a monopoly
| forever, and now as a result the baby is going out with
| the bathwater.
|
| They built their PWA support for the architecture they've
| had since the iPhone's release. Why should they have
| wasted time building affordances for a world in which
| they were forced to support other browsers?
| gkbrk wrote:
| > An airliner already has all the controls required for
| being piloted. Why am I not allowed to pilot my next
| commercial flight?
|
| Flying a plane badly risks the lives of your passengers,
| the lives of people on other planes, and people in the
| nearby area.
|
| Doing whatever you want with your phone doesn't risk
| other people's phones.
| veeti wrote:
| > Not really sure how to respond to this. An airliner
| already has all the controls required for being piloted.
| Why am I not allowed to pilot my next commercial flight?
|
| What kind of ridiculous "argument" is this? Am I putting
| hundreds of other people in risk by installing Firefox on
| my iPhone? The fact remains that the EU in fact does
| intend to put you in front the airliner's controls. You
| can of course choose to turn on autopilot and keep using
| Safari.
|
| > Why should they have wasted time building affordances
| for a world in which they were forced to support other
| browsers?
|
| Guess what, "tight integration" of Internet Explorer into
| Windows for whatever technical reasons was not a
| favorable argument for Microsoft in front of the European
| Commission either. Lack of foresight to design open
| systems is not an excuse in front of the law.
| rimunroe wrote:
| > What kind of ridiculous "argument" is this? Am I
| putting hundreds of other people in risk by installing
| Firefox on my iPhone?
|
| Certainly it's an extreme example, but yes, giving people
| the ability to install other browsers and app stores _is_
| increasing their risk. This ruling makes it possible for
| some companies to decide to only allow their app to be
| installed through an alternate app store, which won't
| necessarily restrict malicious code in the same way.
| Elidrake42 wrote:
| This is why I purchase iOS devices - ultimately their
| closed garden provides a smaller attack surface, clearly
| evidenced by the comparative (to Android) cost of
| exploits on the black market.
|
| I cannot see this as anticompetitive. If you want open,
| you have that choice in Android.
| rimunroe wrote:
| This is exactly my feeling too. I don't want the platform
| to open up more. I left Android because I wanted to make
| _fewer_ decisions about my device, and to just think
| about it less in general.
|
| Also, Safari is a non-Chromium-based (though still
| related) browser which developers are forced to support
| because it's the only thing allowed on iPhones. Most
| users aren't going to install Firefox on their iPhone,
| they're going to install Chrome, which is just going to
| make Chrome's market dominance worse.
| veeti wrote:
| I'm sorry to say the EU regulators disagree with you on
| that.
| rimunroe wrote:
| We noticed! I'm not thrilled about the decision.
| TheGlav wrote:
| They built their PWA support with assumptions about how
| the application, OS, and WebKit were going to run. That's
| like saying, "Oh, Microsoft didn't build an API layer
| into Windows to support running X11 apps side by side
| with Win32 apps, so they were being monopolistic." No,
| you have limited engineering time and you make
| engineering tradeoffs. You don't need to design an
| interface layer and API and hooks between system
| components if your design doesn't call for it or doesn't
| need it.
|
| > They built their PWA support in an anticompetitive
| manner assuming App Store & WebKit would be a monopoly
| forever, and now as a result the baby is going out with
| the bathwater.
|
| They built it in such a way that it was sustainable and
| sensible for the time it was made (iOS 2.0). That's a
| really long time ago in the software world. More than a
| dozen versions of the OS have been built on top of this.
| Saying "they should have just figured it out back then"
| is completely ignoring the reality of what was offered by
| the OS and the mobile space entirely at the time.
|
| Now laws have been passed that say "you must provide
| alternatives." OK. They can choose to spend an ungodly
| amount of time refactoring the OS to undo 16 revisions of
| the OS of assumptions for zero benefit for the company,
| or they can say "Sorry we can't comply with that for your
| market."
|
| It sucks. But it's a result of reasonable business
| decisions and their evolutions from a significantly
| different era.
| sigmar wrote:
| tbh, I thought the summary in techcrunch was much easier to
| read and concise.
|
| >Browsers also could install web apps on the system without a
| user's awareness and consent.
|
| Couldn't this be entirely solved with an OS permission-like
| prompt "are you sure you want [progressive web app name] added
| to home screen?"
| npunt wrote:
| You don't want random processes firing off permissions
| prompts, you want them to remain meaningful to users on a
| platform else they'll get prompt fatigue. Think of all the
| prompts users see and just press 'ok' to.
| sigmar wrote:
| Heard. But we're going to entirely eliminate all PWAs
| because there might be an additional prompt added? Seems
| excessive/specious to me.
| npunt wrote:
| It's not one additional prompt, it's a class of prompts
| that could be exploited over and over again. A single
| site could trigger hundreds by sites popping up in the
| background each which trigger it, and then the user's
| home screen is full of fake PWAs with names like 'save
| money' 'in debt?' 'casino cash bucks' etc. Next you're
| developing mitigations, spam cleanup, etc. We've gone
| through this kind of thing before.
| sigmar wrote:
| The user would get rid of the app/browser that is doing
| this, no? The same way they would have to for any
| malicious app that persistently requests a special
| permission?
| samatman wrote:
| I'm guessing you've never had to clean up a relative's
| Windows machine. I wish I could say the same.
| npunt wrote:
| Yeah ideally. Given there are nearly 1.5 billion active
| iPhones tho, a lot (100s of millions) of users aren't
| going to understand the relationship between the prompts
| and the browser and/or know (/know how) to uninstall the
| browser and/or have desire to do it at the moment they
| experience the problem, especially if the browser has
| other qualities they like. Many more would just blame it
| on themselves, ignore the problem, etc. These users may
| make up a plurality or majority of iOS users, and have a
| totally different experience from a technical user
| working on a desktop OS (HN crowd).
| anakaine wrote:
| Are you sure we can't have additional plugin toolbars for
| Safari? Maybe have one or two that tell us that we can
| get paid to surf the Web, and a couple of others that
| definitely don't show popups?
| lxgr wrote:
| "Yes, allow install (this time)" / "No, don't allow install
| (this time)" / "No, and never prompt me again"?
|
| iOS has been doing something very similar and it's arguably
| worked pretty well.
| madeofpalk wrote:
| I guess that's why they say that "would require building an
| entirely new integration architecture that does not currently
| exist in iOS and was not practical to undertake given the
| other demands of the DMA and the very low user adoption of
| Home Screen web apps"
| crazygringo wrote:
| Thanks for posting that. I'm no iOS expert but it actually
| sounds like a pretty reasonable explanation. It's at least good
| to hear Apple's side here, and more knowledgeable commenters
| here can weigh in as to whether it really does seem genuine.
| candiodari wrote:
| Sure it's reasonable ... because of course all these browsers
| don't have a security model and just allow web apps to do
| whatever they want.
|
| This is essentially saying no-one can build a secure browser.
| MrDarcy wrote:
| No, it's saying they're being forced to support at least
| one insecure browser which would affect the security of an
| obscure feature so they're removing the feature.
| bee_rider wrote:
| Nobody can build a secure browser.
| shuckles wrote:
| Truer words have not been spoken! Maybe only second to
| nobody can build a secure baseband.
| dividedbyzero wrote:
| Security is well achievable, absolute security is not.
| Somehow almost everyone seems to grasp that intuitively,
| but a subset of IT keeps pretending they're the same
| thing.
| nozzlegear wrote:
| Nobody but Apple has experience building a secure browser.
| [1]
|
| [1] On iOS.
| weberer wrote:
| I know at least Firefox has per-site permissions for
| location, webcam, and microphone access. Is it a correct
| interpretation that Safari on iOS does not have this
| feature?
| manmal wrote:
| Safari has those features.
| shuckles wrote:
| Their argument was they want the system (iOS) to enforce
| those permissions, not browsers on behalf of apps they've
| added.
| dividedbyzero wrote:
| I don't think they're saying that. I read their statement
| more like "someone might build an insecure browser", which
| isn't that invalid a concern I think. I'd like Apple to be
| a bit more daring and just open up those APIs too, but I
| kind of get their incentives point the other way. Apart
| from some landmark design decisions, Apple is an extremely
| conservative company, and stalling on an issue like this is
| just what such an org would do.
| secondcoming wrote:
| > malicious web apps could read data from other web apps and
| recapture their permissions to gain access to a user's camera,
| microphone or location without a user's consent.
|
| How is this even possible? It's shocking that these APIs even
| exist for any browser to use.
| zer00eyz wrote:
| >> How is this even possible? It's shocking that these APIs
| even exist for any browser to use.
|
| https://www.theverge.com/24054329/microsoft-edge-
| automatic-c...
|
| Ask MS, they already did it.
| veeti wrote:
| This is completely irrelevant to the discussion, there is
| no sandboxing on PC.
| cqqxo4zV46cp wrote:
| iOS and Windows' security models are not remotely
| comparable. I can't imagine that you'd be making such
| intellectually lazy comparisons if it wasn't in the context
| of some perceived holy war.
| amelius wrote:
| I didn't read the article, but to me it sounds like Safari's
| security mechanisms need more work.
| MBCook wrote:
| Safari is fine.
|
| Other browsers would have to be trusted, Apple doesn't have
| a mechanism to ensure that they do what they're supposed
| to.
|
| So until they have time to add one (remember they already
| had to create all the API's for third-party browsers to
| use), they're not allowed to give Safari preferential
| treatment. So they had to remove the feature.
| kemayo wrote:
| I assume you mean the "read data from other web apps" part.
| That'd be because there's (presumably) not a system-level way
| to launch a third-party browser in "web app mode", with all
| data siloed off per-PWA. Thus the only way they could
| currently make web apps work would be to launch the third-
| party browser and trust that it silos everything adequately
| itself internally.
|
| Apple _could_ add a bunch of new APIs to support this case
| for third-party browsers. Presumably there 's something
| equivalent that's being done for said web apps currently in
| Safari. But they're not wrong to say that there's not an
| existing system in place that said third-party browsers are
| already written to use. (And, you know, they're clearly not
| invested in trying to make this law _succeed_.)
| zer00eyz wrote:
| Without this type of isolation and enforcement, malicious...
| camera, microphone or location ... Browsers ...
|
| 30 some million lines of code in chromium browsers.
|
| Thats bigger than the linux kernel.
|
| The HN crowed might not LIKE apples response but they have a
| very defensible position.
|
| Edit: Its not like we haven't seen this play out on the desktop
| recently: https://www.theverge.com/24054329/microsoft-edge-
| automatic-c...
| cma wrote:
| But the plain browser already can request camera permissions,
| in a bad security situation a site that didn't request it
| still receives it from the browser's system level request.
|
| This is just Apple wanting to avoid people being able to
| develop a platform on top of their platform without paying a
| tax.
| zitterbewegung wrote:
| That's not the point though because WebKit is already
| secured by Apple but if you have multiple blink related
| apps like Microsoft edge or brave or Firefox apple will
| have to audit those too and be on the hook if something
| breaks and then Apple will have to take the blame over a
| security oversight they aren't responsible for.
| spaceribs wrote:
| That assumes that Apple would be blamed for
| Edge/Brave/Firefox's security oversight.
| etchalon wrote:
| They would absolutely be blamed by users for it.
| ChilledTonic wrote:
| Why wouldn't they be? Especially considering their
| existing reputation in consumers minds for security and
| reliabilty?
| shagie wrote:
| If you add a PWA (with Safari) a year ago to your Home
| Screen and then change your browser to Firefox, and that
| PWA breaks out and steals some other application data...
|
| Will you blame the software maker that you used to
| install the icon on the screen? or the one that is
| seemingly unrelated to the icon on your Home Screen?
| seszett wrote:
| I would probably blame the "the software maker" for
| silently switching the engine used by previously
| installed PWAs. Why do that?
| rickdeckard wrote:
| You think this uneducated me would know that this was a
| PWA and no app and also remember that it was installed by
| Safari, an app I apparently don't own anymore at this
| stage...?
|
| Why wouldn't Safari remove all its PWA icons when I
| uninstall it, considering that it anyway cannot transfer
| the data to another browser...?
| Ajedi32 wrote:
| So extending this logic to other platforms: if Chrome has
| a security bug on Windows... you believe people will
| blame Microsoft? And you think that would be valid
| justification for Microsoft pushing a "security update"
| that uninstalls all competing browsers and replaces them
| with Edge?
| Gigachad wrote:
| Browsers can still do that. It's more that PWAs look like
| entirely separate apps which the user would expect to be
| sandboxed. While a tab in a browser is clearly part of the
| browser app.
| anon373839 wrote:
| This is not a meaningful distinction. Users ALSO expect
| ordinary websites' data to be sandboxed. Users trust that
| pornhub.com won't be allowed to read data entered into
| irs.gov.
| summerlight wrote:
| Why should we trust Apple for security in that context? Apple
| also provides all those functionalities via their proprietary
| API, which is not even audit-able. If Apple really believes
| in that argument, they should disable their own API as well.
| M4v3R wrote:
| You have to trust someone if you're using a computing
| device connected to the Internet. The point of being in
| Apple ecosystem is that you trust Apple, and then
| (supposedly) you can not trust anyone else. To many that's
| a very strong proposition.
| summerlight wrote:
| > The point of being in Apple ecosystem is that you trust
| Apple,
|
| This seems to be over-generalization? Users are using
| Apple devices because those are good products, not
| because they want to delegate every single trust problem
| to the Apple ecosystem. That might be a great proposition
| for people like you, but there is a significant number of
| people who consider it a compromise rather than a value.
| chongli wrote:
| Users trust Apple because Apple is ultimately accountable
| for security breaches on iOS devices. If a 3rd party app
| causes a data breach it does not matter if the breach was
| made possible by compliance with regulations like the
| DMA, Apple will still take the blame.
| summerlight wrote:
| > Users trust Apple because Apple is ultimately
| accountable for security breaches on iOS devices.
|
| As a long time user of Windows which historically had an
| incomparably large amount of security incidents, I can
| assure you that Apple won't get blamed that much for 3rd
| party data breach unless it involves Apple's own service
| and user data.
| chongli wrote:
| Since you're a commenter on HN I'm going to assume you're
| a tech person. I'm not talking about tech people, who
| through their discussions try to find the correct
| person/company to blame for issues.
|
| I'm talking about the general public. If a story about a
| data breach in a 3rd party app -- affecting iOS users --
| hits the news cycle, Apple will take the blame and their
| brand reputation and sales will be impacted. It doesn't
| matter whose fault it really is, Apple is the face of the
| iPhone and through their walled garden they have accepted
| final responsibility for everything that occurs on iOS.
| Wowfunhappy wrote:
| I don't see how this matters to the GP's argument.
| Windows was a virus hotbed for decades and that does not
| appear to have affected its reputation in a meaningful
| way.
| chongli wrote:
| That's because Windows' reputation was already mud.
| Microsoft made their business on corporate users anyway.
| Apple is a consumer brand. A data breach on iOS is like
| nudity in a Disney movie: utterly brand-destroying.
| Wowfunhappy wrote:
| Windows was both. If you were buying a computer in the
| early 2000s, it was almost certainly a Windows PC.
| anon84873628 wrote:
| >there is a significant number of people who consider it
| as a compromise rather than a value.
|
| I suspect that from Apple's perspective, it is
| definitively _not_ a significant number.
|
| For Apple, ownership of the "trust problem" is an
| intrinsic part of "making good products".
| summerlight wrote:
| > For Apple, ownership of the "trust problem" is an
| intrinsic part of "making good products".
|
| Yes, this might be true. And the majority of elected
| officials in EU fundamentally disagrees with that
| statement.
| geodel wrote:
| > And the majority of elected officials in EU
| fundamentally disagrees with that statement.
|
| Well, EU can and will force, fine, or ban US companies as
| they see fit but there is not some fundamental
| correctness to their viewpoint
| paulmd wrote:
| Yeah, as I've said before: the root problem here is that
| the EU wants to outlaw apples business model.
|
| People don't think of it that way, they tell themselves
| all the reasons why that's a good thing, but that's
| ultimately what it is - a legislative solution to end the
| "android vs iOS" debate for all time.
|
| The argument is walled gardens shouldn't exist, so the
| solution is to either legislate requirements that apple
| destroy the walls, or that they exit the market. That is
| a statement that most android advocates would agree with.
|
| And the EU will largely just keep ratcheting up the
| legislation until that happens. Driving apple out is the
| point - walled gardens are (in the EU sense) unacceptable
| and the option for a walled-garden business model needs
| to be removed from the market.
|
| Apple is (correctly) perceiving this and pulling out of
| the market, first by dropping the affected features, and
| I'm sure there will be a "next compliance requirement"
| before many years too.
| dingle_thunk wrote:
| Because of course elected officials without any
| expertise, representing a very small minority of
| humanity, are the best arbiters of reality.
| geodel wrote:
| > Users are using Apple devices because those are good
| products,..
|
| For general populace good also include secure by default.
|
| "every single trust problem to the Apple ecosystem." is
| rather technical point that very few people would even
| understand meaning of it.
|
| > significant number of people who consider it a
| compromise
|
| How significant compare to iPhone user base?
| cqqxo4zV46cp wrote:
| If you truly have this view then I all but guarantee that
| you aren't using iOS in the first place. This is a thought-
| terminating bad-faith argument.
| summerlight wrote:
| Your argument might be only applicable to some sort of
| fundamentalists. Most people in the real world make
| informed decision based on lots of different factors. I'm
| pointing out that Apple speaks like a security
| fundamentalist but doesn't act like such. They should
| choose either one of being fundamentalist or realist, not
| cherrypicking whatever traits that work in favor of
| themselves.
| Wowfunhappy wrote:
| I share the GP's view and I use an iPhone because I must
| have access to iMessage and there is no alternate way to
| do that.
| zaphirplane wrote:
| Apple's business model excludes Clickjacking, stealing
| personal Information, stealing passwords, commissions from
| redirects, commissions from gambling sites redirects. Those
| in that business use browser plugins to get inside your
| security boundary so your argument maybe over my head or
| baby bath water thing
| thimp wrote:
| We don't entirely trust Apple. We just trust them more than
| other vendors.
| rickdeckard wrote:
| Who is "we"?
| thimp wrote:
| Probably the folk upvoting my comment.
| Retric wrote:
| Using an Apple device requires trust in Apple even if you
| run a 3rd party operating system let alone a 3rd party
| application on their OS.
| thimp wrote:
| As an end user who has been fucked over by the other side
| (MS/Google/crappy app vendors), I am behind their decision.
|
| If I was not I can choose to leave.
|
| I know this is a divisive comment. Please see my further
| extrapolation in a child comment.
| circuit10 wrote:
| How does removing web apps help anything? To me it seems
| like part of a ploy to create backlash against this law by
| removing features
| thimp wrote:
| It's a move against the third party browser engines which
| have been the bane of my existence from a security
| perspective on other platforms. For example, the about
| box in an Android app bundled a whole different browser
| engine which circumvented device policy entirely and
| allowed data to be exfiltrated. This app change was
| delivered in an update by clueless or lazy developers.
| This is not possible on iOS due to the platform
| restrictions.
|
| In this case they have to change the integration and
| sandbox model to allow the security policy to remain
| intact for people who want and need it. That breaks a few
| things but it stops the integration from being used for
| exfiltration among other things.
|
| Note that they're not completely breaking it, just
| ensuring that the security model stays intact when
| browser engines have to coexist on the same device. That
| means sacrificing some convenience for security.
| anon84873628 wrote:
| I know it is not en vogue to be charitable towards tech
| companies, but it seems fair to assume that some teams
| are making a good faith effort to follow the law, and may
| be forced to accept imperfect design tradeoffs. Like they
| say, it affects a relatively small number of users, there
| is a sufficient workaround, and the technical fix would
| require major investment.
|
| Not everything is a conspiracy.
| anon373839 wrote:
| > The HN crowed might not LIKE apples response but they have
| a very defensible position.
|
| You and Apple both are ignoring the fact that these
| permission APIs exist even if the website isn't being
| displayed in standalone/full screen mode. The modern web is
| built on them, and third-party browser engines WILL provide
| access to these APIs in Europe.
| jensensbutton wrote:
| Seems like an OS problem. They should fix that.
| lannisterstark wrote:
| Or they could just not.
| agust wrote:
| They could develop APIs to support alternate browser
| engines but could not allow them to install sandboxed web
| apps on the system? Like all other OSes do, including
| macOS?
|
| How surprising.
| kmbfjr wrote:
| Are not some of the changes in the EU so that people
| won't have to rely on Apple's APIs?
| bobbylarrybobby wrote:
| The whole point is that doing so would privilege safari
| over other browsers, which is illegal.
| luuurker wrote:
| What's the benefit for you as a user to side with Apple on
| things like this?
| moogly wrote:
| A seat at Steve Jobs' table in the lunch cafeteria in
| he...aven?
| vdaea wrote:
| He's not necessarily siding with Apple. He's pointing out
| they don't have to do that.
| gretch wrote:
| Apple has a decade+ track record of making devices that i
| really like. (At several points I've compared solutions
| across the market).
|
| Instead of siding with Apple, why would I side with
| anonymous and random internet commentators who have never
| made devices I want to buy?
| cqqxo4zV46cp wrote:
| Please drop the tribalistic vitriol and be an adult about
| this. The statement is "or they could not". It's factual.
| It's what Apple did. It's not a religious stance.
| masto wrote:
| The question was "What's the benefit for you as a user to
| side with Apple on things like this?". There's no vitriol
| there. Jumping to the defense of a trillion dollar
| corporation seems religious or at least tribalistic to
| me.
|
| And lest I be dismissed as a hater, I currently own five
| Apple computers, an iPhone I've upgraded every year since
| they came out, an iPad, a watch, and a virtu^wspatial
| computing heads^wdevice. But that's because of the
| transactional value they provide, not because I believe
| Apple loves me and has my best interests at heart. They
| love my money and that's where it ends.
|
| I use several PWAs and I will be very disappointed if
| this is the stick Apple uses to close the window on this
| short period of time where we had a reasonably
| interoperable standard for making "apps" using web
| technologies. I can run Elk in a browser, but it's
| suboptimal.
| pb7 wrote:
| Pretty simple: I like the way Apple does most things. I'm
| rarely disappointed by the culmination of all of their
| decisions. I'm _frequently_ disappointed with how other
| companies do things therefore I don 't want their disease
| to spread to things I'm perfectly content with.
| shuckles wrote:
| The sides in this debate are: Apple, Chrome advocates
| (with a little bit of separation), and the EU. It's not
| that perplexing to choose the first.
| robertlagrant wrote:
| > What's the benefit for you as a user to side with Apple
| on things like this?
|
| Looking at these things as sides is a mistake. Instead of
| just being tribal, it's better to look positions on their
| merits.
| TheGlav wrote:
| Of course they could. They looked at the cost of rewriting
| the entire integration and framework for running PWAs and
| said, "eh, nah."
| jeroenhd wrote:
| They'll have to allow some kind of app installation API to
| allow for alternative app stores. If Google implements some
| kind of WebAPK technology on iOS, they may just be able to
| launch a Google Play for iOS to work around these PWAs as a
| workaround, and Safari will be down a feature.
|
| I have the feeling Apple is betting on Google not caring
| enough about the PWA platform to try to compete. Maybe
| they're right, but if they're not, they're only making the
| browser wars worse for themselves.
| carlosrg wrote:
| Didn't Apple made a comprehensive list of requirements for
| alternative web browsers and web browser engines so they are
| secure and don't compromise the user's security?
| (https://developer.apple.com/support/alternative-browser-
| engi...)
|
| I'm a little confused. So that long list of requirements is
| useless for PWAs?
|
| Some people will actually believe this. I'm utterly disgusted
| by Apple and their arrogance regarding the DMA, and the way
| they've managed all of this. My perception of them has
| completely changed. However, they seem very obedient when China
| asks them to censor apps or, for example, limit AirDrop when
| there's a protest going on.
| agust wrote:
| Repeating Apple's lies is really not useful. Probably why the
| original article didn't do it, and instead provided an analysis
| with diverse sources.
| lambdas wrote:
| That's ridiculous. It's the antithesis of RTFA; you have to
| read an argument for yourself else you're just parroting the
| opinions of others.
| shmerl wrote:
| _> Addressing the complex security and privacy concerns
| associated with web apps using alternative browser engines
| would require building an entirely new integration
| architecture_
|
| Translation from Apple talk to real talk: allowing competing
| browser engines will undermine our grip on the market through
| lock-in to the engine we fully control. We don't want to lose
| power. As control freaks, we'll do all we can to sabotage it.
| sgift wrote:
| so, tldr: Apple tries to bullshit the EU again. EU commission -
| get them.
|
| They say themselves it would be possible to be compliant with
| the DMA without removing what is obviously competition they
| don't like. But they try to take the road which - just by
| chance, obviously, the security is the real reason - helps them
| to keep more people away from competition. I don't buy it.
| stephc_int13 wrote:
| The technical justification are bullshit.
|
| They simply could ask browser vendor to follow strict rules,
| that they can check themselves. This is not like they would
| have to verify dozens of browsers every day. Only a few per
| months, top.
| jeremyjh wrote:
| They are not saying it is impossible, only that they have not
| done it. How long do you think it will take to spin up such a
| review and certification program? How much will it cost, and
| how many sales will they lose because of the lack of this
| feature in the EU?
| veeti wrote:
| There will already be a review and certification program
| for third party browsers that want the required
| entitlements
| (https://developer.apple.com/support/alternative-browser-
| engi...), so why don't you ask Apple?
| TheGlav wrote:
| Browsers need to run javascript to be competitive browsers.
| It would be practically impossible to check even simple
| "strict rules".
| benguild wrote:
| The "low usage" comment is going to be more ammo against Apple
| unfortunately. The whole reason they are low usage on PWAs is
| because of a lack of investment from Apple and a lack of
| parity, yet for the longest time Apple has played both sides by
| saying PWAs are a viable alternative to the App Store, all
| while channeling people to App Store for actual app downloads
| and not providing similar marketing or anything for PWAs
| thimp wrote:
| Are you sure this isn't a tech industry viewpoint? I don't
| know anyone who knows what the difference between an app and
| a PWA is. I don't think I've seen anyone outside of the tech
| industry with a PWA active.
|
| In context 99% of the users I meet don't even know what USB-C
| is.
| tester89 wrote:
| The only PWA that I think gets any use on i(Pad)OS is that
| for the Financial Times.
| anakaine wrote:
| Fair call on your first point about PWA knowledge level in
| users. Regarding your users knowledge of what USB-C is: are
| you sure your user group are not potato's? Most people I
| know, including the teenage daughters and their friends,
| all know what USB-C is these days.
| thimp wrote:
| One of them was going to buy a new phone because it took
| a long time to charge. This was because she had a crap
| charger and crap cable. I am unsure if they are potatoes
| or not but I suspect they might be :)
| benguild wrote:
| Correct on it being a tech industry viewpoint-- people
| think "apps come from the App Store" and therefore anything
| else that's clunky requires a fair amount of education and
| payoff for users to adopt.
|
| It's off balance, and it shows now that the tech has to be
| removed since it wasn't actually at parity despite it being
| an argument for it unfortunately.
|
| The worst part? This has been the case for 15 years. It's
| not like there wasn't enough time to fix it. That's plenty
| of time to hire and develop solutions, yet now look at the
| reasons for it being taken away.
| glenjamin wrote:
| Am I missing something?
|
| Couldn't they allow you open PWAs in Safari, or fall back to
| opening a URL in another browser?
|
| Is there some part of the DMA which demands full feature
| parity?
| 5evOX5hTZ9mYa9E wrote:
| The good news is that DMA contains private right of action. Might
| as well start drafting the responsive court filings already,
| March 8th is just around the corner.
| gargs wrote:
| This is the courageous Apple we've all been waiting for. One that
| doesn't think twice about antagonizing its users just to throw a
| tantrum.
| johanneskanybal wrote:
| As a European dev I want apple to fail super hard and implode.
| They used to be so cool and make slick hardware for their nische
| but now I'm happy to use worse hardware as long as they disapear
| from the face of the earth.
| gear54rus wrote:
| They ain't never been cool. The shit practices they are trying
| to defend were there from day 1 and are baked into their DNA.
| Treating their users like stupid animals that don't know what's
| good for them is what they do. And they will fight tooth and
| nail to continue to do it. Even as EU tries to kick their
| predatory ways out of them.
|
| To think there's a hardware thing in 2024 that does not allow
| its owner to compile and install arbitrary software while still
| calling itself a smartphone is just laughable.
|
| It's a good thing people are starting to wake up to this even
| on legislative level.
| amelius wrote:
| > Treating their users like stupid animals that don't know
| what's good for them is what they do.
|
| The problem I have with that is that they are selling a
| ContentFilter as an integrated part of their OS, when it can
| be a separate, optional part, and even offered by a third
| party.
|
| Also, they equate AppStore == ContentFilter, which are
| clearly two separate concepts.
| pb7 wrote:
| Most users are stupid though. Reminder that a US congressman
| once grilled Google's CEO about whether Google was tracking
| his iPhone's precise location. And this one was smart enough
| to con his way into Congress.
|
| "I have an iPhone, and if I move from here and go over there
| and sit with my Democrat friends, which would make them real
| nervous, does Google track my movement?" -- Ted Poe
|
| https://www.cnet.com/tech/mobile/google-ceo-pichai-
| grilled-o...
| jeroenhd wrote:
| > "I have an iPhone, and if I move from here and go over
| there and sit with my Democrat friends, which would make
| them real nervous, does Google track my movement?" -- Ted
| Poe
|
| The thing is, if this was a real life situation, and he
| would seek out and politically collaborate with/stalk and
| listen in on his Democrat friends, there's a good chance
| Google would know. Not because of a digital AirTag Google
| installed on his phone, but because of the tracking and
| data analysis Google has access to.
|
| The indirection and hidden mechanisms Google (and other
| data trading companies) use are impossible to comprehend
| for normal people, and they're banking on that to continue
| being allowed to do that.
| pb7 wrote:
| The point was that he has no idea where the boundaries
| around between Apple and Google and what is within the
| realm of possibility of abuse and what is strictly
| impossible without him tapping "accept" via a system
| prompt. It is not possible for Google to track his
| location without him granting permission to do so on his
| iPhone. It is not possible to get precise location data
| without a prompt and a blue system indicator. It is not
| possible to get repeated location data without iOS
| eventually notifying you of the background activity (even
| the stock Weather app is not immune to this). All of this
| is because Apple has fine control over the system.
| amelius wrote:
| Yes, that's the way I feel too. I learned to program on an
| Apple ][ that I loved, before Jobs started his nefarious
| business practices. Woz's Apple was cool. Jobs' Apple makes me
| feel like they want to enslave developers, or at least milk
| them to the last drop.
| whatsthatabout wrote:
| Wanted to try an android phone for some time again anyways,
| thanks apple :)
| akmarinov wrote:
| Since iPadOS doesn't get alternative stores and alternative
| browsers - I wonder whether PWAs will still work on iPads in the
| EU. That'd be funny.
| hardcopy wrote:
| They still work on iPadOS
| brikym wrote:
| I'm actually thinking of switching back to Android because of
| this bullshit. There are a lot of niche web apps I use,
| particularly for local things, that just won't be developed into
| an iOS app because it's not viable.
| tonoto wrote:
| Android user since ~2010 (before that, Symbian).. I tried one
| of Apple's "Pro" phones with IOS 2021, last year I went back to
| Android and back to freedom even if it is Google's walled
| garden. Still, being able to control many aspects of the phone
| (choice of browser, do I need to mention different volume
| controls, can compile own stuff, automation) is unbeatable. To
| me using iPhone left me with the same crippled feeling that I
| would have if someone forced me to use Windows on a computer.
| On the plus side, my screen time was actually lower during
| those two years..
| smeagull wrote:
| Seems like a very unreliable platform to me.
| ttarr wrote:
| These kind of news make me feel happy that I'm Apple, Microsoft
| and Google* free.
|
| Phone is ungoogled Android.
| ivan_gammel wrote:
| Very questionable argumentation. This can be seen from two
| different angles:
|
| 1. PWA is a native wrapper for a web application, not a browser.
| It is supposed to be limited to the app website. DMA does not
| tell Apple that every app with embedded WebView should offer
| users possibility to switch the engine. Why PWA should be treated
| differently here? I'd rather clarify this with regulators first,
| before harming end users.
|
| 2. There's no browser engines currently supporting PWA on Apple
| mobile devices. Apple has enough resources and time to figure out
| how to sandbox PWAs on other engines together with the first
| browser vendor that decides to offer such support and commit
| engineering resources to this project. In the meantime current
| solution could stay simply because it does not hinder any
| competition.
|
| I'm not a legal expert, so maybe I miss something here. But Apple
| statement does not look convincing to me.
| Someone wrote:
| > DMA does not tell Apple that every app with embedded WebView
| should offer users possibility to switch the engine.
|
| I don't see how that's related to the issue being discussed.
|
| > In the meantime current solution could stay simply because it
| does not hinder any competition.
|
| Why do you think "you can install a third party browser, but if
| you do, you can't add PWAs to the Home Screen" doesn't hinder
| competition?
| ivan_gammel wrote:
| >I don't see how that's related to the issue being discussed.
|
| PWA is not a browser, it is a native app using a browser
| engine to render a specific website.
|
| >Why do you think "you can install a third party browser, but
| if you do, you can't add PWAs to the Home Screen" doesn't
| hinder competition?
|
| I literally explained it in my comment you are replying to,
| but I can repeat. Competition does not exist yet. Browsers do
| not offer PWA support out of the box, it is a feature to be
| implemented separately from rendering engine. See Firefox on
| Windows for an example -- it doesn't support PWA out of the
| box. This feature has to be built: if Apple were to hinder
| the competition, they would resist it by not offering the
| APIs. But they can offer them through the cooperation with
| vendors, even if those APIs do not exist yet. Say, Mozilla
| comes and asks for APIs: Apple starts negotiating and
| proposes the compatibility requirements and a reasonable
| timeline. They both work on their part and eventually Firefox
| is released with PWA support. Who would fine or sue them if
| it worked this way? How the violation of DMA could be proven?
| pierrebai wrote:
| Come on now, if it was /that other company/ you'd be saying it
| without a pause.
|
| FUD
|
| See? Not hard to say, even when it is Apple and not Microsoft.
| The concept that browser allow one web site to read the storage
| of other sites is ludicrous. SuuuuuUUUuuure Apple can't
| /guarantee/ that the browser has no bug... which assumes Apple
| can somehow prove their own browser is bug-free. Plus, what
| prevents Apple from launching separate instances with separate
| data permissions for WPA? That's is 99% certainly what they did
| with their own WebKit-based solution.
|
| FUD FUD FUD
| 23B1 wrote:
| AAPL's recent behavior has really degraded the brand for me
| personally.
|
| Like I won't be buying the Vision Pro because I'm not really sure
| I want to get further locked into their ecosystem if they're this
| hostile towards the will and rights of the people who buy their
| products.
| Alifatisk wrote:
| Bummer, so all these recent news about Apple allowing push
| notifications and PWAs to iPhone was for nothing?
| sccxy wrote:
| I guess they realized that if they opened up too much of their
| walled garden, there was no going back.
| mnau wrote:
| If you are ouside of EU, it wasn't for nothing.
|
| EU is only sixths of world GDP and shrinking.
| Alifatisk wrote:
| That's a big if
| malermeister wrote:
| https://www.youtube.com/watch?v=VtvjbmoDx-I
|
| Apple has become the IBM in their famous 1984 ad. "A garden of
| pure ideology", indeed.
| dontdoxxme wrote:
| Probably easier to leave the EU than get Apple to listen.
| hardcopy wrote:
| Sigh. This is a huge headache for me.
|
| https://lemmy.world/post/12001569
|
| (I develop https://github.com/aeharding/voyager)
| nonrandomstring wrote:
| Said it before and it seems clearer every day, that we're in an
| era reminiscent of the 1920s with big mobs fighting it out. One
| of the old games back in town is _protection rackets_ [0],
| digital forms of ransacking, vandalism, threats and "tax"
| collecting are all the rage dontchyknow.
|
| Everyone's got their "security" to give you. But it ain't your
| security, and it ain't compatible with noone else's.
|
| Nice app store you got here. Shame if anything might 'appen to
| it!
|
| [0] https://en.wikipedia.org/wiki/Protection_racket
| torartc wrote:
| Is there anything we can actually do to push back on this? I get
| we can long term just not buy their products, but it feels like
| there needs to be more urgent action then that.
| jeroenhd wrote:
| I don't think so. Either the EU takes action (assuming what
| Apple does is illegal, though I doubt it) or you'll have to
| vote with your wallet.
|
| Perhaps your best bet would be to loudly proclaim Apple's user-
| hostile behaviour as the reason you're switching to another
| brand of phone, so non-tech people also learn about Apple's
| hissy fit, but I doubt it'll do much to their bottom line.
| pseudony wrote:
| On the point of trusting (big) Apple to keep us safe.
|
| This was linked in a similar discussion today. Either they
| knowingly provide backdoors for state actors or they are being so
| incompetent that it is laughable. Zero interaction remote exploit
| of hardware features designed to circumvent their own security
| measures? Why ?
|
| Seriously, find someone worthy of your trust, because that isn't
| Apple
|
| https://www.kaspersky.com/about/press-releases/2023_kaspersk...
| Ajedi32 wrote:
| Honestly this doesn't bother me as much as some of the other
| malicious compliance Apple has been doing. It sounds like Safari
| had a pretty tight level of integration with the operating system
| in order to allow PWAs, and creating secure APIs to allow other
| 3rd party browsers to achieve the same thing would have been
| expensive. So in order to avoid giving preferential treatment
| Safari over competing browsers without incurring that cost they
| had to remove PWA support.
|
| Obviously long-term what should happen is that Apple should build
| out those necessary APIs, then re-introduce PWA support to Safari
| and 3rd party browsers, but I personally feel like the EU trying
| to legislate an entirely new platform feature into existence like
| that would be a step too far.
|
| Some of the other concerns with Apple's recent moves (like them
| trying to charge developers for installs that don't go through
| Apple's App Store, and that Apple therefore has nothing to do
| with) are a far bigger issue.
| niutech wrote:
| Bad move from Apple. It's time to boycott iOS and move to FOSS
| alternatives, such as: AOSP, Ubuntu Touch, GNOME Mobile, KDE
| Plasma, Sailfish OS. Personally I am using both UBports and
| Sailfish OS and I appreciate the privacy they provide.
|
| As a possible workaround to fullscreen PWAs in iOS in the EU, I
| propose a convention to append some hash to the Web App Manifest
| start_url, e.g. #__pwa__, then set the default iOS web browser to
| e.g. Firefox, then add the PWA to the home screen from it with
| this special hash. When a user clicks on a PWA icon in the home
| screen, it would open in the default browser (e.g. Firefox), the
| browser then checks if the newly opened tab is opened from
| external source and its URL ends with #__pwa__ and if so, then
| hides the UI providing a fullscreen viewport for the opened PWA.
| dbtc wrote:
| What's a good device to replace my iphone 13 mini?
| anon373839 wrote:
| It's disappointing to see that Apple's spin job is apparently
| working (based on some of the comments here). While it sounds
| superficially plausible, it's actually quite deceitful.
|
| For example, the argument that one web app could steal the
| permissions of another web app is predicated on the assumption
| that a non-Apple browser engine will fail to sandbox the apps.
| But *the exact same* threat vector will exist for non-Home Screen
| web apps accessed through third party browsers. That's because
| ordinary websites ALSO have the ability to request access to
| microphones and cameras, and it will be up to the developers of
| the browser engines to ensure that these permissions are properly
| sandboxed. Apple won't be able to eliminate this risk without
| breaking vast numbers of sites that people use every day.
|
| In truth, a PWA is no different from a website. It's built using
| the same technologies and APIs. The main difference is that it
| can run in full-screen mode like an app, and it has its local
| storage cleared less often. These are nice extras that benefit
| users who choose to "install" such apps, and they carry no
| special security risks.
| macinjosh wrote:
| Apple ducking sucks.
| w4 wrote:
| I'm primed to be upset with Apple at this point, but this doesn't
| seem like an unreasonable position. The EU is forcing them to do
| a bunch of work to support alternate browser engines, this
| creates a bunch of additional work if Apple wants to fully
| support PWAs, PWAs aren't really in Apple's financial interest to
| begin with, so eff it. We're not supporting PWAs in the EU.
|
| That doesn't seem that unfair. Apple isn't a charity, so why
| spend resources on extra work they didn't want to do in the first
| place, and that is not required for legal compliance.
___________________________________________________________________
(page generated 2024-02-15 23:00 UTC)