4 ms·
Fair points. I think it's more nuanced. Native apps are great and necessary for many scenarios. However, there are a ton of native apps that could be just as fu
by benlower 11y ago
Fair points. I think it's more nuanced. Native apps are great and necessary for many scenarios. However, there are a ton of native apps that could be just as functional as a responsive web site. Sure there were issues with discoverability which the app stores helped with in the beginning (now I think it's just as hard to get noticed in the store as it is on the open web).
I don't think "web apps are the future of mobile". But I do think there is a better separation of native apps and mobile/responsive web apps.
- wwweston 11y agoWhat's more -- a significant number of apps ARE a wrapper around a UIWebView or something like it.
- adamdoupe 11y agoWe've studied this and found that ~85% of the free apps on the Google Play store use a WebView (I like the term "mobile web app"): http://adamdoupe.com/publications/large-scale-study-of-mobile-web-app-security-most2015.pdf http://adamdoupe.com/publications/large-scale-study-of-mobil...
- nodamage 11y agoThere's a big difference between an app that 'uses a WebView' to render specific pieces of content or clicked links, and an app that is basically a thin wrapper around a WebView. Can you clarify whether your ~85% number is referring to the former or the latter?
- adamdoupe 11y agoSure! The short version is that I don't know. We were looking for instances of insecure WebView usage, so from a security perspective small piece vs. entire app doesn't matter too much (and is difficult to measure, especially when looking at 1.1M apps). However, some of the other numbers from our analysis can be useful to draw a picture of WebView usage. We statically looked for uses of WebView, and 85% of the 1.1M apps used a WebView. Of those 998,286 apps: - 97% enable JavaScript (which is off by default) - 36% use the JavaScript Bridge Interface (which is a fairly good indicator of heavy WebView usage) - 94% implement a shouldOverrideUrlLoading method of the WebView (another good indicator that the developer is using the WebView for something non-trivial) - 27% implement an onReceivedSslError method of the WebView (indication that the developer is using the WebView for something non-trivial). (Sadly, 29% of the apps that implement onReceivedSslError intentionally IGNORE all SSL errors.) So I guess the takeaway is that 85% is an upper bound, the real number of WebView-only apps is absolutely lower, however it's clear that WebViews are significantly used in mobile apps.
- ori_b 11y agoAs far as I'm aware, mobile doubleclick ads need a WebView with Javascript and shouldOverrideUrlLoading(). I'm not sure about others. How do you account for apps that only use the WebView for showing ads with the various ad toolkits out there?
- adamdoupe 11y agoIn our study we didn't differentiate (from a security perspective, if you are vulnerable because you use a WebView when showing ads, then you are still vulnerable), so I don't have data for that. It would be interesting data, although determining WebView for ads statically might be tricky.
- wvenable 11y ago> there are a ton of native apps that could be just as functional as a responsive web site That is probably true but most would require 10x the development effort at least and be obsoleted much sooner. And then users don't want generic lowest common denominator applications; users want software to make the best use of the platform.
- denniskane 11y agoIf we turn the web itself into an actual developer (and user) friendly platform, then we could probably start making better use of it as an application delivery vehicle. To enable this, I've been furiously working on this OS-in-a-browser concept for the past 3+ years: https://linuxontheweb.appspot.com https://linuxontheweb.appspot.com
- wvenable 11y ago"This site relies upon cutting-edge web technologies that only Chromium-based browsers have implemented." This might as well be Java.
- efes 11y ago> This might as well be Java. Chromium specific certainly isn't as good as open standards, but it isn't as bad as Java. Once chromium is ported to something it doesn't face legal uncertainty.
- pjmlp 11y agoEveryone that follows the Java license never had any issues. Only the two companies that tried to screw Sun had any issues with it.
- efes 11y agoIf you write a free application that runs on Java on the raspberry Pi you (probably) owe Oracle nothing. If anyone builds a console around that raspberry Pi, Oracle probably is owed money because the device is no longer a general machine. That is very different than chromium or anything else that is license compatible with your typical Linux distribution. Whether or not someone owed damages is immaterial to the problem of trying to get everyone an appropriate license who might want to run your software in contexts you haven't imagined yet.