4 ms·
A native app could leak/abuse information like a web app, but in general the surface area is way smaller for that to happen on iOS (which is what I'm most famil
by IBM 8y ago
A native app could leak/abuse information like a web app, but in general the surface area is way smaller for that to happen on iOS (which is what I'm most familiar with). Everything is sandboxed and Apple strictly controls how apps behave in iOS with the types of APIs that are available and the design of those APIs (there's a reason why Google is desperate to have you sign-in when you use their apps on iOS). And when something is being abused Apple can do something about it [1]. You could put some third party "analytics" framework in your app that happens to be a bad actor (or compromised) that sucks up data in some way, but at least Apple can remove misbehaving apps because they control the App Store.
So there might be technical reasons why native apps are more privacy preserving than web apps, but I think that pales in comparison to having an actor that actually follows the principles of Privacy By Design running the platform [2]. If the platform owner doesn't actually want to vet what goes in their stores beyond "machine learning" [3], had a useless permission model until recently, or does dark pattern bullshit [4], I doubt there's much of a difference between native vs web apps.
At the end of the day the only thing that matters is incentives, and that informs how these actors will behave.
[1] https://www.theverge.com/2013/3/21/4133288/apple-to-finally-stop-accepting-apps-that-use-outdated-udid-device-identifier-may-1st https://www.theverge.com/2013/3/21/4133288/apple-to-finally-...
[2] https://en.wikipedia.org/wiki/Privacy_by_design https://en.wikipedia.org/wiki/Privacy_by_design
[3] https://gizmodo.com/google-boots-fake-ad-blockers-from-chrome-web-store-1825362470 https://gizmodo.com/google-boots-fake-ad-blockers-from-chrom...
[4] https://qz.com/1131515/google-collects-android-users-locations-even-when-location-services-are-disabled/ https://qz.com/1131515/google-collects-android-users-locatio...
- thekingshorses 8y agoIt's way easier for the developer of the app to steal data in the native app. Trick user to open FB or any site. Open the requested site in the built-in browser. Let user login to the site, and then scrap all the information. Apple and Google can't stop that. You can't do that in the browser. > A native app could leak/abuse information like a web app, but in general the surface area is way smaller for that to happen on iOS