3 ms·
Apps are not always more secure. I have a baby monitoring app that is always using my mic on Android, even though i have "only when I'm using the app" enabled.
by mattwad 4y ago
Apps are not always more secure. I have a baby monitoring app that is always using my mic on Android, even though i have "only when I'm using the app" enabled. I can close a website, and it's gone. I cannot just close an app - those little suckers are running 24/7 doing god knows what
- smcleod 4y agoFor sure - I didn't say they're always more secure. But in general - the majority of (maintained) applications that have less dependencies tend to be. Just have a look at the insane number of NPM packages a node application includes - good luck running (timely) automated analysis across all of those let alone maintaining the dependency tree.
- h0l0cube 4y ago> the majority of (maintained) applications that have less dependencies tend to be As a mobile dev (and sometimes web dev) I can tell you that dependencies (implicit and explicit) are numerous in even the most basic of apps. > good luck running (timely) automated analysis across all of those let alone maintaining the dependency tree `npm audit fix`? There's nothing even like this on Android or iOS.
- dmitriid 4y ago> `npm audit fix`? There's nothing even like this on Android or iOS. Because you don't need anything remotely like this for any proper app platform. I know of a complex web app that has more than half a million entries in its yarn.lock file. Five. Hundred. Thousand. Dependencies (of dependencies of dependencies of...) Because there's literally nothing on the web that is suitable for app development, and you have to build the entire world from scratch, one dependency at a time, every single time. And of course npm audit fix will not fix it because in true npm fashion even a minor update can trigger cascading failures across large swaths of the code you didn't even know were pulled in.
- h0l0cube 4y ago> I know of a complex web app that has more than half a million entries in its yarn.lock file. Five. Hundred. Thousand. Dependencies (of dependencies of dependencies of...) I can't say I've seen anything like that in practice. I don't know why the app has that many dependencies, or of an analogous mobile app of similar scale and complexity to the nameless example you've cherry picked. > Because there's literally nothing on the web that is suitable for app development, and you have to build the entire world from scratch, one dependency at a time, every single time. Bit exaggerated, but I take your point. The point of TFA, if we go back to that, is that ideally more functionality should be folded into the browser to reduce this redundancy. The undermining of web browsers by vested interests is precisely what makes web apps insecure in the manner you've described. And here you are defending the status quo – so it's mission accomplished from the perspective of Apple and Google. The unseen dependencies on any mobile device are the operating system libraries, which vary from vendor to vendor, and have far greater privileges than a web app. > And of course npm audit fix will not fix it because in true npm fashion even a minor update can trigger cascading failures across large swaths of the code you didn't even know were pulled in. I call `npm audit fix` quite regularly and without issue. If you let it go stale, you're going to spend quite some time upgrading everything, irrespective of package management system. Can't tell you how much time I've wasted on upgrades with Gradle/SPM/Cocoapods/Carthage. So my gut says unless you either haven't spent much time in the mobile app development world, or you're being a bit disingenuous to make your point.