Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
noir
searching Neon…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
4 ms
·
1.
▲
by
noir
11y ago
Well that's just silly. There are plenty of high profiles apps out there with many users who have a set of known domains that their app will need to connect to. As an example, Facebook, will never push a config update that points their
2.
▲
by
noir
11y ago
The exception is specified in the app's Info.plist. You won't be able to tell just by looking at the app on your iOS device, but you can download and unzip and IPA, and directly look at its plist to see if it has the NSAllowsArbit
3.
▲
by
noir
11y ago
ATS is configurable to allow arbitrary loads, but specify which domains you wish to keep secure. The author of the above post failed to document or mention that. Most developers will have known domains that they wish to keep secure, and the
4.
▲
by
noir
11y ago
It's a lazy recommendation. The first 2/3ds of the post are fluff to try and compensate for the fact that their recommendation in the end is "turn off this security feature". ATS is configurable to disable or enable for
5.
▲
by
noir
14y ago
That's fair. The reason I put their email response in my post is so user's could evaluate for themselves how they felt about. The response so far has been mixed. Some are bothered by it, others, like yourself, aren't really worried. And tha
6.
▲
by
noir
14y ago
Glad the app was able to see the light of day. It's a wonderful app and it's great that it was able to be used for a network, and people worthy of it.