4 ms·
I've always been somewhat confused by chrome apps. How do (did) they differentiate themselves from extensions? Even Google seemed unsure about that as Hangouts
by laksjd 10y ago
I've always been somewhat confused by chrome apps. How do (did) they differentiate themselves from extensions? Even Google seemed unsure about that as Hangouts has been available as both an extension as well as an app for quite some time.
As a user I'm really glad to see this move, along with the move towards android apps on Chrome OS since I'm hoping it will unify the Google-driven ecosystem a bit more.
- kzahel 10y agoChrome apps can have extensive permissions that web platform does not provide. - Full TCP/UDP socket support (AFAIK this is never coming to the web platform) - Bluetooth support (Web platform is getting this, though) - Filesystem support (e.g. get persistent read/write access to user selected directory. Web platform probably won't get this) Notably the socket and filesystem permissions are not available to extensions. Most of the other permissions though are available in extensions. https://developer.chrome.com/apps/api_index https://developer.chrome.com/apps/api_index
- runn1ng 10y agoI will add HID API support, that apps have and extensions don't. https://developer.chrome.com/apps/hid https://developer.chrome.com/apps/hid
- onlykey 10y agoWe placed a bet on chrome apps because of the USB HID API - https://chrome.google.com/webstore/detail/onlykey-configuration/adafilbceehejjehoccladhbkgbjmica https://chrome.google.com/webstore/detail/onlykey-configurat... We would have done an extension but there is no USB HID support. Obviously a web app would be a bad idea. Anyone know if there are plans to make the chrome.hid api available to extensions any time soon?
- JoshTriplett 10y ago> - Full TCP/UDP socket support (AFAIK this is never coming to the web platform) While it could never be allowed unconditionally (because it allows scanning internal networks), I don't see any reason it couldn't be allowed with a permission request.
- fabrice_d 10y agoAsking a end user if foo.com should be allowed to open a TCP connexion to host:port makes no sense. 99.999% of users can't make an informed decision, and they just want the damn to work so they choose "allow". Never ask users questions that they can't reasonably answer, ie don't do what android did for a long time (looks like this has been improving since N). Maybe the case of TCP/UDP could be improved by showing a human readable version of the prompt for some well known ports. So a browser would ask "Do you allow webmail.com to use a secure IMAP connexion to mydomain.com?" when webmail.com requests access to mydomain.com:993
- seanwilson 10y ago> Maybe the case of TCP/UDP could be improved by showing a human readable version of the prompt for some well known ports. So a browser would ask "Do you allow webmail.com to use a secure IMAP connexion to mydomain.com?" when webmail.com requests access to mydomain.com:993 Such prompts are going to be super confusing to the majority of users. What is IMAP? What does secure mean? What's a port? I don't have a solution; I think it's really difficult and interesting problem. For example, you might think a game shouldn't require any permissions, but then it might need internet access to upload scores, access to your address book to invite your friends to play etc. I can't see any easy solutions how you can check the app isn't using these permissions in a malicious way.
- JoshTriplett 10y agoYou can't reasonably limit access to a specific host anyway, because DNS allows you to point a hostname to any IP; once you have permission to access a hostname that you control DNS for, you can connect to any arbitrary IP address, including LAN addresses. (You could slightly mitigate that by blocking RFC1918 private addresses and localhost, but then you couldn't build clients to talk to such servers.) As another alternative, which would allow applications like mail clients, SSH clients, VNC clients, and similar, you could treat Internet connections like the web treats file-pickers today: ask the browser to prompt the user for one, and get handed a connection, without the ability for the site to set the target. Combine that with persistence ("allow the site to connect to this host again in the future without prompting?"), and you could easily connect to the handful of servers a user wanted to connect to. That wouldn't let you build a web-based BitTorrent client or similar, but it'd solve many of the problems people want arbitrary connections for.
- weaksauce 10y agoAt least on Firefox there is a design decision in the works for that... https://bugzilla.mozilla.org/show_bug.cgi?id=1247628 https://bugzilla.mozilla.org/show_bug.cgi?id=1247628 And you can have a web extension that natively connects to a local program if you need more power. Not self contained but it's possible.
- Gaelan 10y agoAFAIK, A Chrome app is a glorified bookmark + offline support. An extension can add buttons to the toolbar, manipulate web pages, etc.
- anderber 10y agoActually, Chrome Apps are different because they are offline by default (you need to ask permission to get anything online), have access to system APIs, and have certain rules to keep users safe from cross script attacks, etc.
- kzahel 10y agoThere are "hosted" chrome apps, which are indeed glorified bookmarks. The "packaged" chrome apps are actually offline by default. Two separate things, with the same name...