4 ms·
The difference is, whether or not, when iOS user clicks an icon to open an ”app”, they can be confident whether or not the app is “secured” or not. Hypothetica
by cherioo 3y ago
The difference is, whether or not, when iOS user clicks an icon to open an ”app”, they can be confident whether or not the app is “secured” or not.
Hypothetically, without apple doing this, opening a PWA1 app can caused its data to be siphoned off by PWA2, up to isolation of the browser.
Whether or not that is a legitimate enough concern is up to each individual.
- bloppe 3y agoI just don't understand what PWA's have to do with any of this. There is nothing that a PWA can do that a regular Chrome window would not be able to do. Apple is being force to support the latter. What's wrong with continuing to support the former? If it all boils down to "Apple users expect Apple to have control over everything, and if that expectation is violated, it will be really bad", then I'm sure EU regulators will handle it. Is there anything I'm missing from a security perspective?
- dagmx 3y agoThe Apple FAQ itself answers the second side of this. If a browser can add PWA, they can claim they’re installing an app, and it would not be clear to a user that they have a web app, not an isolated app. Now, none of these pseudo apps are guaranteed to be sandboxed from each other but the user cannot differentiate between apps that do provide security.
- survirtual 3y agoPWAs adhere to the same-origin policy, and all browser security policies associated. This means isolated storage (indexed db & local storage), isolated permissions, etc. Every modern browser has support for this. One webpage accessing the resources and data of another webpage is among the most basic of things globally known to be disallowed. This sandboxing reasoning is extremely bad faith.
- dagmx 3y agoYour argument hinges on a browser being a good citizen. The DMA makes no such requirement.
- survirtual 3y agoApple could trivially audit browser apps and provide warnings if they do not adhere to basic security policies literally every browser has implemented. This is a basic, user friendly approach. Their behavior is akin to a small, bratty toddler throwing a little tantrum, but instead of being a small toddler, it is one of the largest corporations on the planet. Their "little tantrum" impacts lives and livelihoods, because they are upset a population has reps that actually represent them. I hope they get what they deserve.
- dagmx 3y agoDoes the DMA allow for that level of data security being required?
- hu3 3y ago> Now, none of these pseudo apps are guaranteed to be sandboxed from each other... Except they are! Any browser worth their salt have been doing isolation since the dawn of time. Or do you really think bing.com can manipulate google.com cookies and storage?
- dagmx 3y agoYour qualifier is the issue: “Any browser worth their salt” Yes, a good browser does. But you’re still leaving it up to each individual implementation, and the DMA rules that Apple cannot judge accordingly.