3 ms·
You can run other browsers. You can't run other browser engines. The way you win is that your uncle doesn't click a Google ad banner to install Chrome when he s
by spanhandler 6y ago
You can run other browsers. You can't run other browser engines. The way you win is that your uncle doesn't click a Google ad banner to install Chrome when he searches (in Safari) for golf club reviews and end up complaining to you that his iPhone suddenly has worse battery life because now his default browser is Chrome, and your 7-year-old doesn't accidentally end up on porn on their school-provided iPad because some kids' app developer put an entire browser engine in their app "to make cross-platform easier" and your kid accidentally found a bug that accesses the open web though this embedded browser, then clicked the wrong ad.
- saagarjha 6y agoI don't see how the second example has anything to do with which browser engines are allowed on the platform?
- spanhandler 6y agoIf the only embedded browser engine available, period, is Safari as provided by the OS, then it's much harder for app makers to introduce bugs (or features) that bypass Web content restrictions. Without the restriction app makers definitely would ship the equivalent of Electron apps—that is, apps embedding an entire browser engine, with the application built on top of it—to save a buck. [EDIT] and by Safari I mean Safari's webkit, of course. You can embed webviews! You can run JS! You can ship your own browser! You cannot ship your own browser engine, for a bunch of very good reasons, and I'm having a hard time in this case of thinking of any nefarious reasons for the rule. [EDIT EDIT] and then of course a browser engine is a giant attack surface. Better one version of one browser engine on your device than 20 versions of 3 browsers, most of which anyone but a turbonerd won't even realize are there because they're included with non-web-browser apps.
- fiddlerwoaroof 6y agoAnother aspect of this is that a JIT has to dynamically generate code to work: afaict, it's basically impossible to audit such a program to ensure that it only uses the public APIs it's supposed to use. Unless I'm wrong, the security of the Sandbox depends on such auditing being valid.
- darren_ 6y agoYour argument only makes sense if we grant that Webkit is always and forever the fastest safest most efficient and all round best browser engine there is. iOS users are denied the opportunity to have 3rd party developers even attempt to produce something better. (googler, but i work on and far prefer iOS. i care about the platform and i wish it had actual browser engine competition)
- spanhandler 6y agoI'd worry more about that being a problem if Chrome and Firefox weren't still noticeably lagging desktop Safari on power use. Yeah Firefox had that big announcement that they'd improved, but the news was that they'd... caught up to Chrome. Sigh. FWIW I like Firefox or Chromium a hell of a lot better than Safari, except that both drop my Macbook's battery life by an hour or more versus Safari, and both feel heavier in terms of their effects on overall system responsiveness (the feeling I get is that Safari is way better at keeping JavaScript from stomping all over everything). I do use Firefox on Linux, if I'm on something beefy enough to use a really heavy browser and still be able to multitask. For that matter, it'd be worth keeping other browser engines out if their integrations broke Apple's only-vendor-who-seems-to-give-a-shit accessibility features. I dunno, maybe iOS Firefox and Chrome already do, but I'd imagine forcing Webkit keeps people from embedding browser engines that screw with that. Which, again, wouldn't bother me if anyone else were half as good. Please, for the love of god, anyone, compete with Apple. No one is, right now.