3 ms·
OP here. The point of the post was not that Safari's security is bad (browser security in general is pretty excellent), the point is that Apple uses security as
by mtomweb 4y ago
OP here. The point of the post was not that Safari's security is bad (browser security in general is pretty excellent), the point is that Apple uses security as an excuse to block competition and has no evidence that it's browser is more secure than Firefox/Chrome/Edge etc.
As for system block lists and screentime whitelist controls, that sounds like something any browser could plug-in to via a OS provided API.
I'm in somewhat agreement with you that you can't identify the number of security flaws by vulnerability count, but when you combine that with the big delay in patching + patches not being delivered to the current (most popular) version of the OS it brings a lot of doubt to Apple's claims of both being able to patch faster and have better security.
We're not advocating that apps should not be allowed to ship a browser unless they receive a browser entitlement which should be subject to some approval process / vetting etc. i.e. Browsers with strong security track records should be allowed to bring their browsers along with the engines with some affordance given to browsers that run from soft-forks of those engines.
- _kbh_ 4y agoShould browsers that ship to iOS have to raise their security profile to be the same as safari in your scenarios?.(afaik no browsers have the same exploit mitigations that safari does on M1/iOS because nothing else has the hardware to support these mitigations).
- mtomweb 4y agoIMO, Only browsers with dedicated security teams should receive a browser entitlement (which includes a small team for soft-fork browsers) who are committed to keeping their browser secure. All browsers have vulnerabilities, and it's hard to measure. Although it's easy to spot browsers that aren't patching known vulnerabilities fast enough. Negligent browsers should be warned and then have their entitlements revoked. As for hardware protections like APRR or Pointer Authentication Codes (PAC) Apple should be forced to provide access to the third party browsers. I would steer clear of mandating exactly how the browsers should keep their users secure because that can be a point of debate and can be done both at a software layer or a hardware layer. Firefox has also introduced Site Isolation, Chromium has proven that adequately staffed security teams are able to mitigate hardware level security issues like Spectre & Meltdown with novel, system-level mitigations and these mitigations reached users before OS and hardware updates were able to fully remove the vulnerabilities.