3 ms·
Let's not forget that the in-app browser page can be injected with whatever javascript the owner of the app wants. FB/Instagram use this for tracking. There is
by borbulon 3y ago
Let's not forget that the in-app browser page can be injected with whatever javascript the owner of the app wants. FB/Instagram use this for tracking. There is a more comprehensive list of what apps do this somewhere; I do not remember where it is. But for FB/Meta, you can find the info here: https://krausefx.com/blog/ios-privacy-instagram-and-facebook-can-track-anything-you-do-on-any-website-in-their-in-app-browser https://krausefx.com/blog/ios-privacy-instagram-and-facebook...
- kitsunesoba 3y agoWorth pointing out that not all in-app browsers are created equal, however. A huge number of apps, probably the majority, on iOS use SFSafariViewController for theirs, which is basically an isolated Safari tab that runs out of process and app developers have no access to. Furthermore, SFSafariViewController instances are unique per-app, each with their own separate set of cookies so apps can’t trick you into visiting a link to gain access to full Safari’s cookies. IIRC Android has something similar that opens an isolated Chrome tab within apps but I have no idea how common usage of that is in Android apps.
- danaris 3y agoThe question is, is there any way for the user to tell the difference just by looking? Or is that something you have to be able to examine the binary to be able to determine?
- antgiant 3y agoYes, the one that is “clean” has the open in Safari icon. However, as soon as that becomes common knowledge I’m guessing the malicious apps will be adding that icon
- tuukkah 3y agoOn Android, when you have the WebView open, go to the app switcher and the title will tell you which app provides the view: the original app, or your browser.
- Aulig 3y agoThey look significantly different on both platforms, so it's easy to notice if you know how ewch one looks
- ascagnel_ 3y agoYou are correct; however, in the case of some of the biggest apps (Reddit's official app among them), they use the old WKWebView specifically for the ability to inject code. The more user-centric third-party apps that Twitter/Reddit have targeted lately used SFSafariViewController.
- fennecfoxy 3y agoCan't always do that, though. Apple gets especially angy if you're injecting necessary stuff into the page, we found as a general rule they'll fail your app approval for anything like that (unless you're a big boi like FB I guess).