40 ms·
Apple's claim is that it bans other browsers for security
- Razengan 4y agoHow would you enforce device-wide content restrictions or parental controls in other engines?
- ThatPlayer 4y agoBy not installing apps that don't support those features. Do all social media apps from TikTok and Reddit to Twitter and Facebook support parental controls? Or video streaming like YouTube or HBO Max?
- Razengan 4y agoValid point, but you also know that a browser goes beyond any of those.
- iasay 4y agoIt depends how you look at it and this twitter post takes only one perspective. Mine is different. The security I'm interested in for my use case is that there is one egress point from the operating system as far as a browser goes. That means I don't have apps shipping their own browser engines to circumvent the system block lists and screen time whitelist controls. Also comparing CVE rates is pointless as that's exploits and vulnerabilities that were identified and patched, not ones that are in active exploit or publicly unknown which is a metric you cannot measure. And of course if every app ships a browser or you change it, how many CVEs do you have from unpatched browsers shipped in apps? This twitter post feels like the old political adverts: "vote for us because the other guy is shit" (not because we have a better solution).
- causi 4y agoThat means I don't have apps shipping their own browser engines to circumvent the system block lists and screen time whitelist controls. The mechanism for banning third-party browsers is rejection by the App Store reviewer, correct? Supposing Apple allowed third-party browsers but disallowed embedded browsers in non-browser apps, how would this security model change at all?
- mtomweb 4y agoFor In-App Browsers we'd advocate for implementing a system similar to CCT which means that it just uses the user's default browser. For WebViews for native apps we'd advocate for simply using the system browser (every other solution seems too complicated).
- btilly 4y agoComparing CVE rates is NOT pointless. The bad guys have basically the same toolset as the good guys. Therefore the rate at which vulnerabilities are being discovered by the good guys is indicative of how fast they are being discovered and exploited by the bad guys. Second the thread pointed out that many iPhones remain vulnerable and unpatched to openly disclosed security holes WITHOUT an option to update them. One must assume at that point that they are being exploited. The fact that alternate browsers don't have this problem is a significant version. But you do have a good point that it is bad for third party apps to bundle their own browsers to bypass controls, and then leave them vulnerable.
- mtomweb 4y agoOP here. The point of the post was not that Safari's security is bad (browser security in general is pretty excellent), the point is that Apple uses security as an excuse to block competition and has no evidence that it's browser is more secure than Firefox/Chrome/Edge etc. As for system block lists and screentime whitelist controls, that sounds like something any browser could plug-in to via a OS provided API. I'm in somewhat agreement with you that you can't identify the number of security flaws by vulnerability count, but when you combine that with the big delay in patching + patches not being delivered to the current (most popular) version of the OS it brings a lot of doubt to Apple's claims of both being able to patch faster and have better security. We're not advocating that apps should not be allowed to ship a browser unless they receive a browser entitlement which should be subject to some approval process / vetting etc. i.e. Browsers with strong security track records should be allowed to bring their browsers along with the engines with some affordance given to browsers that run from soft-forks of those engines.
- _kbh_ 4y agoShould browsers that ship to iOS have to raise their security profile to be the same as safari in your scenarios?.(afaik no browsers have the same exploit mitigations that safari does on M1/iOS because nothing else has the hardware to support these mitigations).
- mtomweb 4y agoIMO, Only browsers with dedicated security teams should receive a browser entitlement (which includes a small team for soft-fork browsers) who are committed to keeping their browser secure. All browsers have vulnerabilities, and it's hard to measure. Although it's easy to spot browsers that aren't patching known vulnerabilities fast enough. Negligent browsers should be warned and then have their entitlements revoked. As for hardware protections like APRR or Pointer Authentication Codes (PAC) Apple should be forced to provide access to the third party browsers. I would steer clear of mandating exactly how the browsers should keep their users secure because that can be a point of debate and can be done both at a software layer or a hardware layer. Firefox has also introduced Site Isolation, Chromium has proven that adequately staffed security teams are able to mitigate hardware level security issues like Spectre & Meltdown with novel, system-level mitigations and these mitigations reached users before OS and hardware updates were able to fully remove the vulnerabilities.
- fbanon 4y ago
- amelius 4y agoSo they are saying that they can't make a secure sandbox? Why is running other applications somehow secure?
- xrisk 4y agofwiw: the App Store also prohibits JITed code or in general code pulled in after app publishing. I guess the idea is that (at least in theory) that Apple sees all code that an app runs.
- brundolf 4y agoNot all code pulled in after app publishing; it's very common to push at least JS code to an app after the user's installed it, without going through the App Store But I think they draw the line at native (read: unsafe) code, which, is not totally unreasonable
- JamesSwift 4y agoIts always been a sort of wink-wink agreement, never allowing exceptions as far as I'm aware. Its much more common to do post-release updates of JS than native, but I think every native dev has done some form of dynamic code at some point. In one app we did, we ended up disabling the dynamic update but still ran a handrolled VM with dynamically interpreted code files which we baked into the app. Its all manually reviewed in the end, so no guarantees they would even catch it anyways.
- brundolf 4y agoInteresting. I'll admit I don't have much first-hand knowledge of the process > but I think every native dev has done some form of dynamic code at some point This is a little ambiguous; theoretically a VM - even a custom one - would still be above-board because the native code is static. My understanding was that the main problem with third-party browsers is third-party JS engines, but only because any modern JS engine has to JIT in order to perform the way people expect; the app developer takes responsibility for generating unsafe native code, which has the potential to wreak all kinds of havoc on the user's system in a way that dynamically-updated JS code for example can't It would be interesting to try and submit a fully-custom browser with a non-JIT JS interpreter to the App Store. I bet they'd allow it; just, nobody would use it because it would be slow as mud
- theandrewbailey 4y agohttps://threadreaderapp.com/thread/1541318055636369409.html https://threadreaderapp.com/thread/1541318055636369409.html
- mccr8 4y agoComparing CVE counts is a bit nonsensical. For instance, Chrome and Firefox don't individually assign CVEs for internally reported vulnerabilities. For instance, in these patch notes Chrome lists "Various fixes from internal audits, fuzzing and other initiatives" and doesn't even look to have a CVE: https://chromereleases.googleblog.com/2022/05/stable-channel-update-for-desktop_24.html https://chromereleases.googleblog.com/2022/05/stable-channel... Or for Firefox, there's a dozen or so bundled together in a single CVE under "Memory safety bugs fixed in Firefox 101": https://www.mozilla.org/en-US/security/advisories/mfsa2022-20/ https://www.mozilla.org/en-US/security/advisories/mfsa2022-2...
- capableweb 4y agoI agree, measuring "security" by counting CVE counts is a bit like measuring developer productivity by counting git commits, it simply doesn't make sense. But in the grand schema of things, who cares how many CVEs a project has, when it can take almost 2 months for the project to ship updates fixing exploits that happen in the wild already? That's just out of control and unbelievable.
- LMYahooTFY 4y agoI seem to remember the CVE database search utility on Mitre's web site stating something along the lines of "comparing the number of CVEs by platform shouldn't be used to draw conclusions". Possibly a CYA-esque liability statement, but the principle seemed sound.
- coryfklein 4y agoAnd do we have reason to believe the vulnerability/CVE process for Safari is different from Chrome or Firefox?
- MBCook 4y agoI’m going to ignore the security angle and post my big fear. Chrome has dominance similar to IE at the height of its popularity. Whatever you think of their decisions, Apple is the only thing stopping a 90%+ Chrome web. (Note: not why they’re doing it, just a side effect) People keep arguing Apple is being anti-competitive. But no one seems to recon with the possible consequences of what they’re asking for. And I fear we may get a pyrrhic victory if these groups/governments keep pushing. No, I don’t know a good solution. But I don’t think letting Chrome totally own the web is a good outcome.
- mtomweb 4y agoSafari still has around 60% on MacoS and all the normal users believe that there is browser competition now. At best it's speculation, but we can compare that to the very real harms of Apple's browser ban. We've written about the harms in detail here: https://open-web-advocacy.org/files/OWA%20-%20Bringing%20Competition%20to%20Walled%20Gardens%20-%20v1.2.pdf https://open-web-advocacy.org/files/OWA%20-%20Bringing%20Com...
- MBCook 4y agoIt may be 60% on MacOS but that’s a very tiny market. Overall Chrome is quite dominant. Numbers I found say on desktop Chrome is at 70%. Include the 7.75% for Edge (because it’s basically Chrome) and that’s almost 80%. FF at least exists and is similar to Safari. On mobile it’s at 65%. Safari is the only other browser above 5%. Chrome is dangerously close to total monopoly.
- mtomweb 4y agoMacOS is the only market Safari actually competes in and has the same advantage by being the default. I would actually expect the most likely outcome is Apple would fight hard to build a better browser to stem any losses to other browsers. They'll have at least 2 years to do it, so they can catch up in that time with enough investment.
- 4y ago
- jeffwask 4y agoI don't recall that argument working for Microsoft visa vi Windows and IE
- scarface74 4y agoActually it did. Nothing changed. No there was no browser choice mandate in the US
- Spivak 4y agoEvery discussion about this seems to have people cutting themselves on Occam's razor left and right. The idea that there can only every be one true motivation for someone's actions isn't even true for the individual, much less a massive organization. It can be simultaneously true that Safari being the only browser on iOS is enjoyed by the business side of Apple and the engineering side of Apple for different reasons. And good lord this line of argumentation is extremely disingenuous even if you think the actual analysis is good (counting CVEs is not exactly the best measure). One because no one except nerds are going to switch browsers in response a random CVE and two because it doesn't even establish what Apple actually means by security and instead goes off on a rant "well if Apple really cared about [my personal view of] security you would blah blah" -- literally zero effort to understand the opposing view or evaluate other possible ways of addressing the security concerns. But ya know, "Safari lags behind other browsers in RCE mitigations and mean time to patch" doesn't grab headlines and doesn't prescribe a single solution that is also motivated by more than just security ;)
- bogwog 4y agoIIRC, every video game console that ships with webkit has been jailbroken due to vulnerabilities in webkit. Off the top of my head at least, I know the following have been exploited that way: * PS4 * PS Vita * 3DS/New 3DS * Wii U * Wii Also maybe PS3/PSP and likely also PS5 will get the webkit exploit treatment at some point.
- judge2020 4y agoiOS as well - JailbreakMe[0] and TotallyNotSpyware[1] use a WebKit exploit to get out of the sandbox to then trigger other exploits that allow full system compromise/control. Note that, while earlier JailbreakMe exploits were patchable if you installed a patch[2], the readme in the TotallyNotSpyware repo explains that, in general, there's not a patch for the exploit post-jailbreak, so you could still be pwned by a third-party website should they deliver this exploit with a spyware payload. 0: https://en.wikipedia.org/wiki/JailbreakMe https://en.wikipedia.org/wiki/JailbreakMe 1: https://github.com/JakeBlair420/totally-not-spyware https://github.com/JakeBlair420/totally-not-spyware 2: https://www.idownloadblog.com/2011/07/06/pdf-patcher-2/ https://www.idownloadblog.com/2011/07/06/pdf-patcher-2/ (use an ad-blocker, this website is super ad-infested)
- mccr8 4y agoAre the versions of WebKit that ship on those consoles patched regularly and kept up to date? Probably not, so I don't think it is too relevant to how secure Safari is. There have been plenty of zero days for Chrome, but that doesn't mean it is somehow the least secure browser.
- adrr 4y agoIf you can break out the app sandbox on IOS, that is a flaw with IOS. These flaws could be exploited with any app that is using file parsing like the adobe photoshop app. The jailbreakme app wasn’t exploit on WebKit. It was iOS native pdf rendering Library. WebKit was used to deliver the exploit.
- babypuncher 4y agoThat is not a fair comparison. An entire browser engine has way more surface area for attack than a JPEG decoder.
- aaomidi 4y agoThen put it behind a switch and let the user take responsibility. Based on how apple has responded to security issues before, I don’t really think they have much of a leg to stand on. Also, a security issue with safari is far more devastating if you don’t have other browsers. 1. You have to wait for apple to release a system update, not just update the app. 2. You now have no safe browser to use while you wait for #1.
- CodeWriter23 4y agoAnyone have a clue for me what the 'CMA' is? I assume it's not CMA China Shipping, nor the Country Music Association, nor a Certified Management Accountant certification. (I did try to figure it out on my own before asking) Thanks in advance.
- mtomweb 4y agoThe Competition and Markets Authority (The UK Regulator). You can read more here: https://www.gov.uk/cma-cases/mobile-ecosystems-market-study https://www.gov.uk/cma-cases/mobile-ecosystems-market-study And their new market investigation here: https://www.gov.uk/cma-cases/mobile-browsers-and-cloud-gaming https://www.gov.uk/cma-cases/mobile-browsers-and-cloud-gamin... or our tweet thread summary here: https://twitter.com/OpenWebAdvocacy/status/1539503509078388737 https://twitter.com/OpenWebAdvocacy/status/15395035090783887...
- aeyes 4y agohttps://www.gov.uk/government/organisations/competition-and-markets-authority https://www.gov.uk/government/organisations/competition-and-...
- CodeWriter23 4y agoThank you both.
- UIUC_06 4y agoI'm actually writing this on Brave on MacOS. I also have Chrome. I practically never use Safari. (I don't have an iPhone, though.) So they don't have it on the AppStore? Who cares?
- corrral 4y agoOn iOS, the only browser engine allowed is Safari's. There are other browsers, but they have to use the same engine. I'm pretty sure that approximately zero normal users are bothered by this, but a lot of webdevs really, really want to be able to use things like web push messaging on iOS.
- TheDong 4y ago> I'm pretty sure that approximately zero normal users are bothered by this I think many normal users are bothered by this and don't realize it. The restrictions on browser engine are the main reason that Firefox can't ship addons for iOS (like it does for firefox on android). I bet a ton of iOS users would appreciate being able to install firefox addons, like uBlock origin, on their iOS firefox.
- Delphiki 4y agoWeb push notifications will be available (in some capacity) in iOS 16 this fall. But that's beside the point.
- jacooper 4y agoApple claiming security as a reason for monopoly, how classic. The EU's digital markets act bans the only Safari lock on IOS, so this is gone whether apple likes it or not. (1 - sorry couldn't find a better source) Safari is the new IE, there is a difference between a monopoly while still being able to use a competing product (like chrome in other platfroms), and forcing Safari(WebKit) while hindering the web because of Apples interests.(2-3) 1. https://www.fudzilla.com/news/54763-apple-loses-out-in-the-digital-markets-act https://www.fudzilla.com/news/54763-apple-loses-out-in-the-d... 2.https://www.theregister.com/2022/05/23/opinion_column/ https://www.theregister.com/2022/05/23/opinion_column/ 3.https://www.theregister.com/2022/06/14/telegram_safari/ https://www.theregister.com/2022/06/14/telegram_safari/
- mtomweb 4y agoSource was the DMA final text: https://twitter.com/OpenWebAdvocacy/status/1527101988256722944 https://twitter.com/OpenWebAdvocacy/status/15271019882567229... Also many have now spoken up against it: ### Electronic Freedom Foundation (EFF) Apple’s restrictions on third-party browsers, and the limitations it puts on Safari/WebKit (its own browser tools) have hobbled “web apps,” which run seamlessly inside a browser. This means that app makers can’t deliver a single, browser-based app that works on all tablets and phones - they have to pay to develop separate apps for each mobile platform. That also means that app users can’t just switch from one platform to another and access all their apps by typing a URL into a browser of their choice. ### Mozilla Mozilla believes that major platforms should be under an on-going duty to: Stop practices that distort competition on the merits and inhibit consumer choice, such as: ● interfering with consumer selection of alternative browsers and use of those browsers to access the internet from links and queries on their devices; and ● dictating or controlling browser components, such as browser engines, which prevent consumers from accessing and using their preferred browser across all operating systems and devices. ### Google By contrast, PWAs—and the web writ-large—receive a small fraction of this support on iOS. This is primarily because of Apple’s requirement that all browsers use its proprietary WebKit browser engine. Not only does this prevent browsers from differentiating from Safari—Chrome is unable to access the user’s camera, preventing users from using products like Google Lens—it also harms user security. A recent study from Google’s Project Zero security research team found that WebKit is significantly slower than other browser engines to fix reported bugs. ### Microsoft Apple requires that any mobile browsers on iOS, including those offered by Apple’s competitors (e.g., Google’s Chrome app), use Apple’s own WebKit browser engine. This restriction harms competition and consumers. ### Meta Apple requires all web browsers on iOS to use WebKit, a degraded version of Apple’s Safari browser, to render web pages. Apple thus sets Safari as a functionality ceiling for mobile browsers on iOS. The restrictions on Safari’s and other iOS web browsers’ capabilities prevent web pages and web apps from providing consumers with robust, cross-platform experiences that would lower switching barriers ### Telegram We suspect that Apple may be intentionally crippling its web apps to force its users to download more native apps where Apple is able to charge its 30% commission
- deleted 4y ago[deleted]
- strofcon 4y agoTl;dr - "Profitable company makes reasonable decision to stay profitable." I don't really understand why the walled garden seems to still surprise so many people.
- saurik 4y agoJust because something isn't surprising doesn't mean it is necessarily legal or ethical; meanwhile, Apple refuses to admit that "tl;dr" in public--quite likely because they appreciate the practice might not be legal and certainly isn't ethical--and so are attempting to instead claim it is justified, and so it is important to refuse to allow Apple employees that cop out and instead call them out for what we know to be the actual truth here.
- IshKebab 4y agoIt's not surprising; it's frustrating.
- ssd8991 4y ago[flagged]
- freediver 4y ago@dang The title is misleading. Apple is not banning other browsers (there are over 100+ browsers on iOS). Apple is restricting iOS browsers to using the WebKit rendering engine which is an entirely different matter. Edit: Apple is also not claiming what the title suggests (source would be needed), the author of the tweet seems to just interpret it this way.
- cromwellian 4y agoThis is misleading because the Rendering Engine is the browser. Everything else is a skin. The rendering engine determines pretty much everything related to we standards. Third party iOS browsers are little more than third party themes/skins.
- freediver 4y agoI understand how it may appear to look like that to someone who never tried to build a browser. See this comment https://news.ycombinator.com/item?id=31897294 https://news.ycombinator.com/item?id=31897294
- mtomweb 4y agoIt's not misleading. Firefox, Edge and Chrome have all been banned on iOS. Instead Apple has forced them to produce separate browsers around a locked WebView that they exclusively control. Mozilla, Microsoft and Google have all spoken out against the ban in regulatory submission, and browser engineers at each vendor consider it a ban. The REAL browsers have been banned.
- CharlesW 4y ago> Firefox, Edge and Chrome have all been banned on iOS. https://apps.apple.com/us/app/firefox-private-safe-browser/id989804926 https://apps.apple.com/us/app/firefox-private-safe-browser/i... https://apps.apple.com/us/app/microsoft-edge-web-browser/id1288723196 https://apps.apple.com/us/app/microsoft-edge-web-browser/id1... https://apps.apple.com/us/app/google-chrome/id535886823 https://apps.apple.com/us/app/google-chrome/id535886823 https://apps.apple.com/us/app/brave-private-web-browser/id1052879175 https://apps.apple.com/us/app/brave-private-web-browser/id10... https://apps.apple.com/us/app/duckduckgo-privacy-browser/id663592361 https://apps.apple.com/us/app/duckduckgo-privacy-browser/id6... https://apps.apple.com/us/app/opera-browser-fast-private/id1411869974 https://apps.apple.com/us/app/opera-browser-fast-private/id1... Etc.
- aquanext 4y agoFortunately, there's user choice in phones. So get an Android device if you want to run Google's stuff? I mean, security is one angle, but let's talk power and memory usage. You're asking for Apple to allow Chrome's engine (because their app is on the App Store today right now) -- the giant well-known resource hog routinely toasting MacBook Pro users' thighs -- onto their fanless hyper-performant devices. Setting aside privacy and monopolistic concerns, I just don't see how that's a great idea.
- jensensbutton 4y agoYes, that's what I want. It turns out a phone and a web browser are different products. This isn't rocket science.
- smiddereens 4y ago
- ar_lan 4y agoI'm really confused. I actively use Firefox as my default browser on my iPhone running iOS 15.5. I don't think Apple has banned other browsers at all.
- 2OEH8eoCRo0 4y agoIt's basically a skin for Apple WebKit because Apple doesn't allow browsers to use their own engine.
- ar_lan 4y agoI guess the question becomes are Firefox and Safari (on iOS) the same browser, or different? I would still argue that Firefox is different (in the same way that Brave and Chrome are different), and that this title is misleading.
- alexklarjr 4y ago
- imchillyb 4y agoWell duh. They're '...doing it for the children!' Mmmhm.
- shreyshnaccount 4y agoIsn't this anti-competitive? Wasn't Microsoft fined for doing a less aggressive version of the same with IE?
- petmon 4y agoMicrosoft got in legal trouble for coercing OEMs like Dell to ship IE. The OEMs, not Microsoft, should decide what ships on their own hardware. Here Apple is the OEM and is being coerced.
- tambourine_man 4y agoA few random thoughts: • There's a place for closed platforms if open ones are a reasonable choice. A closed platform must not be the only choice available to the customer, but it should be allowed to exist given a healthy market. It's hard to argue that iOS is a monopoly, and if so, than a browser engine and JS interpreter with access to the open web is a very powerful thing that the owner of the platform may deem too powerful for its own good. • Chrome's dominance of the Web is very scary. Not as scary as IE's, since it's open source, but still, it's such a huge beast that it's almost proprietary through complexity. I don't know if there's an easy solution out of this. • The time it takes Apple to patch security flaws is not the main issue here and should not be the core argument. What if Apple steps up its game and gets really good at this? The issue is the strategic decision Apple is making and the discussion should be if a company that powerful should be allowed to make such decisions and impose them to the user. • Apple could avoid this discussion by giving the user a one time only toggle switch to sideload any binary. It should be buried under many menus and preceded by lots of scary dialog boxes. It could even void battery warranty or something. Maybe keep a constant orange menu bar as a reminder that you are on your own and can't blame Apple for anything.
- hinkley 4y agoApple gets the battery performance they do by being very opinionated about who gets to chew on the CPU. Safari is equally opinionated, but third party browsers aren't. I don't like that Firefox on iOS is a shadow of what it is on other platforms, but at least academically I understand why it is the way it is.
- smoldesu 4y agoIf Safari is truly objectively better than other browsers, then it should have no problem competing with the likes of Chrome and Firefox. They can even keep pre-installing it too, as long as they give people the choice of other browsers then I'm happy.
- hinkley 4y agoI don't know what logical leap you're trying to make but I'm not following it. Safari makes the iPhone a better device. They don't sell Safari. They sell devices. If you have a way to effectively and efficiently blame the bad behavior of your ecosystem on a third party, then there are whole industries waiting for you to sell them consulting services. If the king of Reality Distortion Fields couldn't figure it out, probably nobody here has either. Nobody is going to notice that Chrome is eating their battery. They barely notice on desktop. The tools are even less grandma friendly on mobile.
- enos_feedler 4y agoThe first claim when you visit their home page: "Apple's ban of third party browsers on iOS is deeply anti-competitive, starves the Safari/WebKit team of funding and has stalled innovation for the past 10 years and prevented Web Apps from taking off on mobile." Anti-competitive? Perhaps? Yes? Starves the Safari team of funding? I don't know what this means. Stalled innovation for the past 10 years? Maybe. Prevented Web Apps from taking off on mobile? whoah. These are some pretty loose claims.
- ArcVRArthur 4y agoIt's funny to hear Apple talking about how mandatory Webkit is a feature when iOS 1 ran Safari as root.
- KerrAvon 4y agoWhy? You mean the original version in 2007? It wasn't even called iOS yet. It was obsolete in 2008.
- Dig1t 4y agoI'd argue that there are legitimately decent reasons that Apple is doing this, besides the selfish, monopoly-protecting, reasons that are also nicely aligned with it as well. Besides the security thing mentioned elsewhere, I think performance and battery life are a huge concern as well. A big reason that Apple products (usually) work so well is that the vertical integration of both hardware and software can lead to compounding gains WRT performance and battery life. i.e. iPhones have excellent battery life and are pretty snappy for most of their life. A web browser is such a core (frequently used) experience for a smartphone that any tradeoffs made in the browser engine in favor of faster performance at the cost of power efficiency can have a big overall effect on the battery of the device. The vast majority of users don't know or understand why they see decreased battery life when they do, they just see that their phone doesn't last as long. Google has such a complete monopoly in the browser market that one can argue that there's a pretty good incentive for Google to make tradeoffs in Chrome that decrease battery life on the iPhone to hurt the iPhone's battery life, and most people would not realize or understand that its not the iPhone's fault but Chrome.
- the_gipsy 4y ago> iPhones have excellent battery life and are pretty snappy for most of their life Not really. Maybe in the early days they had an edge with ObjC when hardware was primitive and java slow, but nowadays it's the same or buried behind synthetic slowdown animations. The battery life isn't especially good in my personal experience.
- max51 4y agoevery single year single the early iphones, they have had equal or better battery life than competing androids with larger batteries. They consistently have 500 - 1000 mAh less than their close competitors.
- ibigb 4y agoMy TV appliance does not support other browsers; must every appliance be open and support multiple competing browsers? Is there some rational boundary where the appliance can be shipped and just work as it was designed, and not have to support everybody's choice of software? If there exist too many limitations without work arounds, why buy it?
- irae 4y agoI like your point and I smiled while reading it. I don't think this regulation is good either. But not for this particular reason. The iPhone is a general purpose smartphone, and your TV is not. The "smart" part of the smartphone makes it useful without Safari. See apps that integrate with health devices or simpler uses like offline Google Maps. Neither are functioning as a "phone" but instead as a general use computer. With the exception of the iPhone, no other general computing device is currently enforcing a single browser. (And the "smart" in the "smart tv" does not get even close, as their apps can do almost nothing in comparison.)
- tobi1449 4y agoIt‘s also surely only for „security“ that all the neutered adblockers only work with Safari itself and not on any other apps using the Webkit Rendering …
- fuu_dev 4y agoThe iphone is over a decade old and safari should have been established as the default choice for users by now. Still the majority of comments points out that a open platform will lead to users switching away from safari. I think its not a legit concern if a product fails to meet the users requirements in that time period.
- SalimoS 4y agoI know it’s pessimistic but the moment google search add a banner for chrome with a shitty UX (like now clicking the text field search box will bring it full screen and suggestions the rest of the screen) so any change in the chrome version will push all the users to it
- fuu_dev 4y agoThis also dismisses that apple controls the platform and hardware what means it can easily and does use this position to their advantage.
- irae 4y agoVery few said people would use Chrome because it is better. The reason Chrome would take over would be market pressure and advertisement. And after they have like 50%, they won, as they will inexpensively make their market dominant products (search, meet, etc) worst on Safari, by just neglecting to fix issues due to higher cost of making it work on two browsers. We've seen that before. I am posting this from Brave because many sites in Brazil neglect Safari on desktop, so I got used to alternatives.
- fastaguy88 4y agoWhat a misleading argument. Yes, Apple believes that restricting IOS browsers to Safari improves security. This is NOT the same as saying Safari has fewer bugs, or fixes bugs faster, than other browsers. I suspect Apple's argument is that by allowing other browsers, and their plugin management system, the other browsers (or their plug-ins/extensions) will be able to bypass the App store and do things that are insecure. And it is hard to see how counting numbers of bugs has much to do with the severity of the bugs. Not every bug allows a jailbreak, but the ones that do are of much greater concern.
- SheinhardtWigCo 4y agoThe claim is laughable because this policy makes it impossible for external developers to step in and address fundamental, inexcusable problems with WebKit, such as the fact it's written in C++ and therefore produces a consistent supply of memory corruption bugs year after year. Also, I'm skeptical of the notion that every type of app except web browsers can be meaningfully screened for security. How can one not interpret this as a tacit admission that the screening process is close to worthless?
- acdha 4y ago> inexcusable problems with WebKit, such as the fact it's written in C++ and therefore produces a consistent supply of memory corruption bugs year after year. Are you under the impression that Chromium and Gecko are not written in C++? Mozilla has been using _some_ Rust but the modern browser engines are some of the largest, most complicated C++ codebases in existence and your statement applies to all of them.
- georgia_peach 4y agoIf they banned all browsers, I'd believe them.
- lynguist 4y agoI have a small question: Can I anyhow sideload the real Fifefox on iOS?
- easton 4y agoNo, I'm guessing (outside of it costing dev time) it's because it would require the JIT private entitlement, making it not sideloadable by developers or with enterprise accounts.
- shmerl 4y agoFake excuse to avoid coming under anti-trust fire. No one should fall for it.
- dwaite 4y agoThe assumption people seem to make is that third party browsers will get the sort of system-privileged access that they have on desktops: - Always-running daemons to perform internal bookkeeping tasks, provide network access, which are not reaped by lack of user focus or the needs of other applications - Ability to download, generate and run arbitrary native code (for running Javascript and WebAssembly) - Ability to register arbitrary URLs, see installed third-party applications and execute them arbitrarily - Ability to modify the Home Screen to install additional applications (such as native-wrapped PWAs) Without full system level access, Apple's store restrictions don't matter. You are not going to see resourcing to port Gecko or Blink to iOS if it means the javascript and webassembly engines are interpreted, push notifications only work when the browser is in the foreground, SPA applications can't be added to the Home Screen, etc. And by full system access, I mean _more_ access than Safari currently has. After all, many of the features people complain about MobileSafari not shipping are features that are also not supported by the underlying OS.
- irae 4y agoBrilliantly said. This is a way better argument than Apple itself is presenting. But it does boil down to the same thing: Security. If you allow Chrome to be installed as a regular app (even if Apple allows JIT), it will not work. Therefore for a viable Chrome Browser Apple would have to provide APIs they probably stripped from the OS itself and putting it back will for sure hinder security.
- standardUser 4y agoI'm confused, what platform does Apple ban other browsers on?
- geoffeg 4y agoiOS, where Apple only allows WebKit-based browsers, so basically Safari.
- standardUser 4y agoAs a lifelong android user I had no idea! Eek.
- lttlrck 4y agoIf I could run Safari on Linux I'd switch from Chrome and make it my primary browser... if I could run Firefox on iOS, I might consider making that my primary - but I trust Apple to optimize battery/performance more than Mozilla or Google and I'd probably still stick with Safari. I wish they'd open up just a little. Plus iMessages.
- asdff 4y agoJust stick to firefox on linux. Safari is honestly slower on my macbook than firefox, the font rendering looks worse imo and more for the farsighted, plus all the advertisement and tracking and the adblockers are anemic compared to ublock origin on firefox.
- adesanmi 4y ago> Note that this graph doesn't even include the time it takes the user to update the OS since Safari updates are tied to the operating system (an antiquated practice). Is this true? I could have I sworn I’ve updated Safari many times without needing to update macOS.
- slategruen 4y agoThe answer's pretty obvious: Apple just like dumbing down their devices and people would still flock to their products because buyers are inherently stupid. Apple users seem to follow this mindset that just because they paid a premium price for their phones, it's a more solid and secure product (it is not). My mother has an iPhone and you'd be surprised how she'll assume it's a better phone even though she doesn't even know what half of the buttons in the Control Center does. The same goes for browsers in iOS. Most users would just outright defend Apple for their actions because it aligns with their beliefs that it is a better security model and has better UX (of course in a layman's jargon). When you ask them how is that so, most of them couldn't point out how they got to that conclusion.
- pers0n 4y agoThey want to control it because the real web can destroy their app market. Oddly enough their clamp down, may destroy it anyway as game streaming is going to make strides to get past it. It may take time but it will happen and then they will lose their money maker, because it will all be web based and they will have not offered anything else so they will miss out.
- akagusu 4y agoiOS is a closed platform owned by Apple so I think they can do whatever they want in their platform, including ban other browsers for whatever reason they want to. And this is not different from Google creeping their services in other browsers, Microsoft imposing limits on Windows or any other company doing whatever they want with their products.
- fennecfoxy 4y agoLying through their teeth; if security was the concern, they wouldn't allow users to install applications from the internet, either.