7 ms·
I would welcome if this global legislative push would end up in a more open app ecosystem for iOS overall. BrowserEngineKit is a thin wrapper over XPC and iOS'
by HHad3 1y ago
I would welcome if this global legislative push would end up in a more open app ecosystem for iOS overall.
BrowserEngineKit is a thin wrapper over XPC and iOS' extension system. The system would be so much better to develop for if XPC was an open API, and JIT for isolated sub-processes was permitted without Apple's blessing.
* Messengers could have separate sub-processes for preprocessing untrusted inputs -- iMessage already does this, third-party messengers are single-process and cannot.
* Applications could isolate unstable components for better user experience and crash recovery.
* Emulators, e.g. for retro systems, would benefit from speedy emulation.
* WASM would become useful in iOS.
* Browser could use XPC without special-purpose API wrappers such as BrowserEngineKit.
But alas, all of this would make it easier to load code that runs at native speed into an iOS app after a store review happened, and as we all know that'll be the end of the world.
- yupyupyups 1y ago>and as we all know that'll be the end of the world. I'll enjoy seeing all the accounts on MacRumors clawing their eyes out when that happens. It would be naive to think that Apple isn't funding sites and narratives on the internet to serve their economic interests. One of the most outlandish one being that freedom to use your phone however you want would necessarily compromise security and privacy for everyone. It's such a bizarre and indefencible take, and yet it's repeated over and over again on those Apple-worship platforms.
- loa_in_ 1y agoFreedom to use your phone however you like would make bug tracking on Apple's side more complicated and therefore more expensive and therefore it damages their profit bottom line. They would happily freeze development altogether if it was a feasible option.
- nuker 1y ago> ... freedom to use your phone however you want I want to use my phone locked down hard and apps reviewed by Apple. I sleep better with things as they are. I suspect 99% of normal users are in the same boat.
- zakki 1y agoApple must provide opt-in or opt-out for the lockdown.
- philipallstar 1y agoThe market provides these options already.
- nuker 1y agoThen Facebook will grant its app all permission entitlements, and will direct all users to opt-out lockdown for the app to work.
- input_sh 1y agoAre they doing that on Android right now?
- GeoAtreides 1y agoOP, nuker, please answer, i'm genuinely curious what you think about this
- nuker 1y ago"Former Facebook insiders explain why the company is making such a big fuss over Apple's upcoming privacy change" https://www.cnbc.com/amp/2021/03/11/why-facebook-is-so-upset-about-apple-idfa-change-insiders-spill.html https://www.cnbc.com/amp/2021/03/11/why-facebook-is-so-upset... I have not heard similar tantrum from FB over Android. Makes sense as it is made by an Ad company.
- GeoAtreides 1y agothat was not the question the question was: You: >Then Facebook will grant its app all permission entitlements, and will direct all users to opt-out lockdown for the app to work. input_sh: > Are they doing that on Android right now? So is Facebook granting its app all permission entitlements, and directing all users to opt-out lockdown for the app to work on Android?
- fennecfoxy 1y agoThe security thing is BS anyway; Apple aren't perfect at security and having only one option can make this worse. Google's Project Zero uncovered quite a few 0 days in Apple's "perfect" operating system. They're not magical wizard cult gods over there, they're just a buncha developers same as 'em all. And given the quality of what's been coming out of Apple _and_ Google recently sometimes I wonder if someone's dug a pit under their supposedly high bars they held in the 2010s. Even just Youtube is a disgustingly buggy app nowadays.
- thewebguyd 1y ago> One of the most outlandish one being that freedom to use your phone however you want would necessarily compromise security and privacy for everyone. I suppose in a round-a-bout way, it could, more specifically around iMessage, which is Apple's baby in the US and a big part of their lock in effect for US users. Right now, you can reasonably assume that using iMessage with another iPhone user that both ends are reasonably secure and private. Break open the walls of the garden and now you could say that you can't trust that the other end you are communicating with hasn't installed some random crapware or malware that's scraping their messages, or recording the screen during a facetime call, thereby compromising your own privacy by interacting with a bad devices. In that instance, Apple is correct - but what Apple doesn't tell people is that all other forms of digital communication are open to the same risks so they aren't special.
- mock-possum 1y agoIs iMessage really that big a deal to people, for privacy / security particularly? Practically speaking I can’t even tell the difference, apart from text messages sometimes failing to send, and getting the option to retry as SMS. If I want something private / secure, I use Signal.
- Barbing 1y agoFolks do like renaming group chats, typing indicators, perhaps scheduled send (though too new to say without asking around). And it feels a little better, personally, sending an innocuous iMessage—even though I won't get in trouble if a stingray happens to pick up “gm” “Happy birthday!” “Kevin forgot the biscuits again!” over SMS. Self-destructing Signal for the most personal messages for sure. But SMS just feels dirty. Too exposed even if I’d shout the same message contents in a public square.
- jandrewrogers 1y agoYes, people use iMessage to securely share/collaborate on many objects in iOS, like a shared Apple Note. It is used for much more than just sending text messages back and forth. I use Signal but it leaves much to be desired relative to iMessage for a lot of uses.
- Arainach 1y ago>freedom to use your phone however you want would necessarily compromise security and privacy for everyone. For a large enough definition of "everyone", it would. "Everyone" has a Meta app installed. We've seen them pull evil tricks over and over to suck up data 24/7 - most recently running a local server on Android that their websites could talk to to bypass anonymization - and the moment a crack appears in the walled garden Meta will say "go install the FB/Instagram app from our app store with no privacy policy reviews" and a large enough definition of everybody will be much the worse for it.
- skeezyboy 1y agoi take it you dont use desktops or laptops then?
- Arainach 1y agoI don't see the relevance of this question. Neither what I do nor whether I own a desktop/laptop impact the overwhelming trends of how society interacts with technology.
- didacusc 1y agoMost people on desktops / laptops interact with these services via a web browser, which has very limited permissions on the system. Not sure how you could control that tightly on a fully open iOS.
- Angostura 1y agoYou know what I got my parents an iPhone? To avoid having to worry about stuff. Now I have to worry about the inevitable phone call from ‘Apple Technical Support
- resource_waste 1y agoI remember when HN would literally shadowban you for suggesting they do this. Now with 'troll farms'/'reputation management' being so ubiquitous, we'd call Apple irresponsible to not be doing this.
- didacusc 1y agoOn iOS, I can trust that pretty much everyone in my family won't download something silly that then creates a security hole in their devices. Not sure how you could guarantee that if you could load code post-review. What would be the point of the review, then? Wouldn't the App Store be littered with trojan horses in waiting?
- troupo 1y ago> Wouldn't the App Store be littered with trojan horses in waiting? It already is littered with outright scams, apps pretending to be other apps etc.
- devinprater 1y agoNot only speedy emulation, but more efficient too, since it doesn't have to struggle so much through interpretation. That would help battery life and keep phones from heating up just playing a game from 2008.
- skeezyboy 1y agothank fuck i dont have to deal with that shit
- sneak 1y agoThis also shifts a tremendous amount of the burden for preventing system-level malware onto the app sandbox, which today is only one component of a multi-layered defense-in-depth system of notarization, entitlements, app review, etc. To be clear I support letting people run whatever apps they want, but let’s not pretend that this won’t make the median iPhone more prone to have a malware infection (like Android). There are reasons other than anticompetitive greed that Apple does things this way (although I am sure greed is the primary motivator).
- mathiaspoint 1y agoApple doesn't instrument apps when they review them. That burden is already there, they've just convinced you otherwise.
- sneak 1y agoI think it depends on the app and the entitlements. I would assume apps that request entitlements for system-level VPN apis are scrutinized more than calculators.
- mathiaspoint 1y agoAll they do either way is poke at the GUI and maybe watch the HTTP requests. The real goal of the review process is to maintain control over the UX, not prevent malware. If you want to see a review process that stops malware read a Linux distribution mailing list.
- troupo 1y agoAnd Facebook spies on users and competitors for years despite all the "reviews": https://www.bbc.com/news/technology-47281906 https://www.bbc.com/news/technology-47281906 Apple doesn't review apps the way people think it does.
- sneak 1y agoThe rules for Facebook, Instagram, and WhatsApp to get kicked out of the App Store are not the same as the rules for other companies’ apps to get kicked out of the App Store.
- prmph 1y agoThe browser itself is some kind of app store, and we run app from it all the time without Apple's review. Given this, I'm not sure why Apple and its fanboys make so much of this supposed security of the AppStore