4 ms·
I can't wait for PWAs to be the future of apps. /s Apple should take the new Firefox Facebook extension and apply it by default to Safari. But also do Google a
by IBM 8y ago
I can't wait for PWAs to be the future of apps. /s
Apple should take the new Firefox Facebook extension and apply it by default to Safari. But also do Google and every other major ad-tech company. Not sure if this can be done without breaking the web though. Also not sure how different Firefox's extension is from Safari's Intelligent Tracking Prevention. It's possible they already do this.
- 908087 8y ago> Not sure if this can be done without breaking the web though. If that's the case, the web is already broken.
- Spearchucker 8y agoThey have a place but PWAs are no panacea. There are still things I want physical control of, like anything I need client-side encryption for. Fighting one extreme with another has been human nature, but isn't prudent.
- underwater 8y agoPWAs will do nothing to address this problem.
- IBM 8y agoI was being sarcastic but I realize now that I was probably getting upvotes from both camps.
- stareatgoats 8y agoSarcasm never works with a substantial number of people. And on the internet it escapes even more people, even if using emojis ;-P
- nozzlegear 8y ago> I can't wait for PWAs to be the future of apps. /s Genuine question, I don't do much mobile development: aren't native apps able to collect just as much information as a web app/site? Except with a mobile app you can't just open a Dev console and see what requests are being made? Again not trying to troll, I just don't know if I'm missing something here.
- cpeterso 8y agoThe difference, as I understand it, is that third-party code would not be able to snoop on user data in Facebook's native app. In this paper, the third-party JS is able to get itself loaded on the same page as the Facebook user data.
- chatmasta 8y agoTrue, but a native app can read (and inject scripts into) the DOM of any website in a WebView component within the app. The app can also read all cookies that are created from within the WebView (not cookies from Safari). Think how many apps use native "in app" webviews, e.g. reddit, facebook, etc. Now think about login pages, oauth flows, etc... There are lots of opportunities to slurp data from a native app.
- K0nserv 8y agoNo but if an app uses a Facebook login flow with the native Facebook SDK any third party analytics that the app developer has integrated should be able to do the same thing, at least in the case of Objective-C where powerful runtime meta programming exists. I'm not sure about Android, but maybe Java reflections could achieve it too?
- IBM 8y agoA native app could leak/abuse information like a web app, but in general the surface area is way smaller for that to happen on iOS (which is what I'm most familiar with). Everything is sandboxed and Apple strictly controls how apps behave in iOS with the types of APIs that are available and the design of those APIs (there's a reason why Google is desperate to have you sign-in when you use their apps on iOS). And when something is being abused Apple can do something about it [1]. You could put some third party "analytics" framework in your app that happens to be a bad actor (or compromised) that sucks up data in some way, but at least Apple can remove misbehaving apps because they control the App Store. So there might be technical reasons why native apps are more privacy preserving than web apps, but I think that pales in comparison to having an actor that actually follows the principles of Privacy By Design running the platform [2]. If the platform owner doesn't actually want to vet what goes in their stores beyond "machine learning" [3], had a useless permission model until recently, or does dark pattern bullshit [4], I doubt there's much of a difference between native vs web apps. At the end of the day the only thing that matters is incentives, and that informs how these actors will behave. [1] https://www.theverge.com/2013/3/21/4133288/apple-to-finally-stop-accepting-apps-that-use-outdated-udid-device-identifier-may-1st https://www.theverge.com/2013/3/21/4133288/apple-to-finally-... [2] https://en.wikipedia.org/wiki/Privacy_by_design https://en.wikipedia.org/wiki/Privacy_by_design [3] https://gizmodo.com/google-boots-fake-ad-blockers-from-chrome-web-store-1825362470 https://gizmodo.com/google-boots-fake-ad-blockers-from-chrom... [4] https://qz.com/1131515/google-collects-android-users-locations-even-when-location-services-are-disabled/ https://qz.com/1131515/google-collects-android-users-locatio...
- pornel 8y agoNative apps have the same problem. There are "SDKs" for analytics, social sharing, and "monetization" that are native equivalents of putting <script> in your app.