3 ms·
It's far worse than "Apple is slow at implementing". I've spent most of the last 10 years with Safari iOS as my primary target platform. I'll try to break down
by mtomweb 5y ago
It's far worse than "Apple is slow at implementing". I've spent most of the last 10 years with Safari iOS as my primary target platform. I'll try to break down the major issues as unless you are intimately involved with Safari iOS development it can be hard to see the issues by simply using the browser.
1. Bugs
Safari is the the most buggy browser with application breaking bugs crossing into every aspect of development, whether your using WebRTC, Audio, Scroll/UI, LocalStorage/IDB... Safari is the most buggy browser.
Examples:
* LocalStorage / IDB has broken many times over the last 10 years, including breaking for months in production. Normally gets fixed in webkit pretty quick, but takes a month to actually make it to an iOS release.
* Viewport/Scroll/UI/Zoom Bugs - As a collection of issues also related to hiding the header on body scroll, zoom etc.. To fix we had reimplement ALL of user scroll including momentum scrolling, bounce etc in userland js. A mammoth 210 hours of hardcore engineering just to get around bugs that have existed for 5 years.
* bugs.webkit.org is useless as a bug tracking tool, stuff just doesn't get triaged properly, or is hidden away in radar or whatever Apple is using internally and worst of all it just does not get fixed.
Why? It's not the Safari's teams fault, their engineers are all super smart, work hard, care about the web, and some have been building it from the days when Safari was the best browser by far... but you can't build an A class browser with a team that small.
The reason they are so underfunded is Apple simply doesn't care about the web, in fact they see it as competition to the AppStore. Funding and Staffing decisions don't happen within the team. Underfund the team for 10 years and this is what happens. Even Eddy Cue as far back as 2013 knew Safari was slipping and said so in internal emails.
2. Critical Functionality never gets built
The AppStore and its 70b of revenue built on extracting money from a tiny % of addicted mobile gaming whales (70% of all AppStore revenue comes from free to play games), is a rapidly growing core part of Apple's business.
The web competes with that and Apple knows it. Native Apps got notifications in 2009, 13 years later, thousands upon thousands of requests from developers and Apple has deliberately avoided implementing it on iOS. Why? because it's critical to lots of Apps and if they had it, they wouldn't need to distribute to the AppStore. Install Prompts, Background Sync, proper integration with settings, bluetooth, the list goes on. The combination of not wanting to build the features and underfunding means that Safari lags the competition by years.
3. Privacy
Apple likes to blame not developing features on privacy (specifically fingerprinting) but never outlines their specific narrow scope privacy concern so that we can reply in a meaningful way to offer potential mitigations. They like to push the image that privacy is their foremost concern but are quite happy to hand over raw access to 10's of millions of icloud accounts including the encryption keybags when they are concerned it will affect them financially. You combine that with the hopeless protection the AppStore review process offers (nobody is reading every line of code, AppStore is full of scam, data theft apps) and extensive data access native apps are provide compared with private by default web apps, the entire privacy angle starts to seem like a trick.
3. Security
Safari has had 7 0-days (possibly 8 as of writing) this year, with the largest patch gap because Safari releases are tied to the OS. Safari makes heavy use of OS functions for everything, so currently it is not possible to have separate installs of Safari. This also rules out running canary/beta/alpha along side a the current version meaning you need separate devices on different versions of iOS for testing.
This in turn makes Apple have a larger patch gap than the other browsers, since the other browsers can just silently update whereas Safari requires a full system update. This arguably makes it less secure than the other browsers as users are exposed for a longer period. Now this is speculation and very hard to demonstrate as there are a lot of factors in play, iOS is likely a bigger target for researchers/hackers and there are no solid statistics on how many devices get exploited with the browsers being the primary cause.
I'm suggest reading:
https://infrequently.org/2021/08/webkit-ios-deep-dive/#apple's-security-argument https://infrequently.org/2021/08/webkit-ios-deep-dive/#apple...
4. Security and Other Vendors
Given the amount of resources that Microsoft/Google/Samsung/Intel invest into chromium based browsers, it's unlikely that they would be less secure than Safari. However obviously Apple would not be able to open the door to ALL third browsers and offer low level access for JITs. There are workable solutions to this which involve Apple introducing additional security protections at the OS layer and having requirements to be able to gain these special privileges.
In terms of a "App Review" process, we all know it's joke and that anyone could slip code past "reviewers", Apple has the ability to "prioritize" App review for designated browsers or skip it all-together, so any delay in rolling out emergency fixes could be blamed on Apple.
5. In-App-Browsers /
Embedded browsers are mostly terrible for users regardless. I wouldn't recommend giving them special privileges.
6. Use "XYZ" Browser Instead
Here are some realistic messages:
"We recommend "XYZ" browser because Safari has broken all localstorage for the 8th time"
"Want basic tools like being able to print via bluetooth and notifications? Use XYZ browser"
"Want to have a PWA that actually works? use XYZ browser"
- feross 5y agoThank you for the incredibly thorough post.