10 ms·
> However, iOS has a different situation. Due to Apple's App Store and sandboxing policies, other browser apps are forced to use Safari's JavaScript engine. Tha
by Flockster 3y ago
> However, iOS has a different situation. Due to Apple's App Store and sandboxing policies, other browser apps are forced to use Safari's JavaScript engine. That is, Chrome, Firefox and Edge on iOS are simply wrappers on top of Safari that provide auxiliary features such as synchronizing bookmarks and settings. Consequently, nearly every browser application listed on the App Store is vulnerable to iLeakage.
This should be a reason to lift this policy and allow different engines on these devices!
- fsflover 3y agoBut it's for your security! Not joking: https://news.ycombinator.com/item?id=21587191 https://news.ycombinator.com/item?id=21587191
- paulmd 3y agounironically, having three browser engines is three times the attack surface, what's the problem with that claim? uarch "multiculture" hasn't saved us from architectural attacks, actually it probably increases the total number of vulnerabilities, and browser multiculture won't magically make them all perfectly secure and perfectly implemented either. if each browser is only 99% secure now you have 0.99^3 total security, you have ~tripled your odds of a vulnerability existing in at least one of your apps at a given time. there are other arguments in favor of sideloading, but, I don't really see how multiple browsers is a security improvement, actually it seems unironically much worse on that front, since now you are depending on three teams of engineers (two of which are not even at your company) to execute perfectly and never have a vulnerability, in what is one of the highest-privilege applications (essentially the canonical "full control" app). People want their browser to have access to location info (thus bluetooth/wifi settings), camera, camera roll (thus long-term location history), microphone, everything. The fewer applications that exist like that the better you are. I can't fathom anyone saying that they should, for example, run three different high-privilege pieces of software in their production systems, when one would do fine - f.ex you wouldn't run nginx, apache, and keycloak all mixed into your environments. That would obviously inflate the risk of being subject to at least one attack. Why is the browser different?
- bratwurst3000 3y agoMaybe three times the browser engine, three times the chance to have a safe engine at the end?
- geekteq 3y agoAs far as I understand, The attack surface will be reduced in the end. Here is why: The amount of processed content is the same, no matter if you use one browser engine on single device or many. So if we assume that browser is 99%, the chance to _not_ hit the vulnerable page is 99%. However, by segregation of browser data between engines, the exposure of confidential information is reduced in case of breach
- Veserv 3y agoBecause you are not running all of them at the same time, you are only running one of them. The one you choose to run can be better than the current one you are forced to use and thus your attack surface has decreased because you are not using the worse ones. Having options does not reduce your security except in-so-far as exposing the underlying mechanism allowing choice increases your attack surface, and even then that does not inherently reduce your security. A mechanism allowing multiple implementations requiring more available attack surface, but which is used by a high quality application to provide a highly secure implementation is still better than a reduced mechanism designed to only allow a single application when that application provides a low quality implementation. Also, the argument you just proposed could just as easily be used to argue that we should disallow any other operating system other than Windows 3.1 since having more operating systems just increases the attack surface. That is patently absurd for the reasons I just stated above and is why your argument is fatally flawed.
- planb 3y ago> Because you are not running all of them at the same time, you are only running one of them This is not true. The moment Apple allows different browser engines, my Gmail app would use blink. As a browser, I’d maybe use Firefox/gecko and all Apple apps would still use the embedded WebKit. Yes, this is my choice and I would do it knowing I’m increasing my attack surface, but apple‘s reasoning is not false…
- walterbell 3y agoBrave on iOS can disable Javascript on all web pages except those you trust by opt-in.
- HatchedLake721 3y agoWhat next? iOS security vulnerability? This should be a reason to lift this policy and allow different operating systems on these devices! /s
- smoldesu 3y agoIf Europe's governments weren't so reliant on Apple's surveillance, maybe their regulators would demand that.
- HatchedLake721 3y agoLol what? You can't just drop a bomb `Europe relying on Apple's surveillance` without any details
- smoldesu 3y agohttps://en.wikipedia.org/wiki/Five_Eyes https://en.wikipedia.org/wiki/Five_Eyes > In early 2014, the European Parliament's Committee on Civil Liberties, Justice and Home Affairs released a draft report which confirmed that the intelligence agencies of New Zealand and Canada have cooperated with the NSA under the Five Eyes programme and may have been actively sharing the personal data of EU citizens. The EU report did not investigate if any international or domestic US laws were broken by the US and did not claim that any FVEY nation was illegally conducting intelligence collection on the EU. For reference, this is the same NSA that has boasted about having inroads at companies like Google, Microsoft and Apple. The same FIVE EYES that recently "somehow" found the damning evidence to accuse India of conspiring to kill a foreign dissident. Europe relies on America's surveillance network, and America's surveillance network relies on ___________.
- saagarjha 3y agoEurope's surveillance network. They're all sharing information with each other.
- frizlab 3y agoBecause increasing the attack surface would somehow increase the security?
- HideousKojima 3y agoIn exchange for decreasing the amount of affected users and application? Absolutely. No one would be forced to use a non-Safari browser. A software monoculture means that a bug for one is a bug for all.
- frizlab 3y agoBut you’d also get apps that decide to use chromium for whatever reason outside of the user’s control, thus making these users vulnerable to chromium flaws… In short, you increase the possibilities, you increase the attack vectors. There is no way around it AFAIK.
- HideousKojima 3y ago>outside of the user’s control Using the app at all is in the user's control. The current state of iOS is that they don't have any control whatsoever.
- zimpenfish 3y ago> Using the app at all is in the user's control. Not if it is mandated by work, home, family, government, etc.
- wyldberry 3y agoIf it's mandated then they never had the control there to begin with.
- frizlab 3y agoHere’s an example: I know I have the control of not using youtube because I really dislike gougle. Would any of my family member? Absolutely not. Would they use their browser if they could in the youtube app? Most definitely yes. So no, it is most definitely not in the user’s control.
- deleted 3y ago[deleted]
- jmull 3y agoThey should allow different engines, but this isn't a reason. Different browsers have different vulnerabilities, but aren't substantially more secure as far as I'm aware.