Chrome 81: Near Field Communications, Augmented Reality, and More
blog.chromium.org
blog.chromium.org
> This version of Chrome removes TLS 1.0 and TLS 1.1. TLS (Transport Layer Security) is the protocol which secures HTTPS.
Even when you do know how to use it, it is just too easy to make a mistake. If there were 5 options already selected and you want to add a sixth, so you click it but you forgot to hold down the right key. Now the 5 previously selected options are gone with no way to get them back.
In general I like using native widgets because mobile browsers do a lot of work to make native widgets usable on phones, but <select multiple> is so bad on the desktop that I always replace it.
With the webnfc.app, you can only write a single NDEF message with single record of either URL or Text, during single interaction.
for (i=0, i<10, i++) writer.write(i)
does it write ten times the tag? overwriting every number?
That's fundamentally wrong and insecure
If you are suggesting browsers shouldn't offer access to webcams etc at all, that would not make the world more secure because the web would just die and we'd all be back to running native code.
Web apps, if built correctly, are probably more secure than desktop apps. Especially considering that you completely remove the need for user updates, since the website is updated by the developers.
Plus, webbrowsers implement a proper permissions model unlike native apps, especially on Android, used to do.
Whereas most kernels are easy to understand (even relatively modern ones like seL4), also many parts of a browser are at the frontier of "applied CS".
If I were to build something relatively small today, I don't think I would feel safe if it had to run in a browser due to the enormous complexity of a browser. I just don't think it is possible to secure them fully.
Writing everything myself at least gives me a false sense of security in the sense that I at least believe I understand what is running :)
You as a software developer know how your system works. You know what components you used, how to compile and install and how to secure. Your average user (depending on the target audience) doesn't know anything like this. Most users are happy when their current installation works, they often don't want to update, without realizing that this comes with the cost of their security.
I feel like webapps are the easier way to keep users with no experience secure.
Have you taken a look at Linux?!
What's fundamentally insecure about it? The permission model of the browser is better than that of desktop operating systems.
You can argue that it's more opportunity for exploits, but then again many (if not most) exploits are found in processing and rendering text.
And yet, sites exfiltrate enormous amounts of behavioral information. Whereas with a desktop app, I can just put it in a sandbox without network access and I am 100% sure that no data gets uploaded to anyone.
I think we tend to focus too much on security as in whether some application can be exploited to get UID/ring 0 access (which is undeniably important) and not so much as in whether the application's creators can extract all kinds of personal information.
While unfettered access has larger consequences, it is a relatively rare occurrence, whereas unwanted extraction of personal/behavioral information happens continuously.
I don't see how that has anything to do with the security of the platform itself. Sure, some desktop apps can be sandboxed. Others don't work without some form of network connection. It's up to the developers what to (not) do here.
> While unfettered access has larger consequences, it is a relatively rare occurrence, whereas unwanted extraction of personal/behavioral information happens continuously.
A website or web app can not access any personal information that you haven't entered into it or its "partners". If cross-site tracking is your concern, there are ways to mitigate that.
Nobody said that. The point I'm making is that it is not "fundamentally insecure and wrong", especially compared to native applications.
As for security, there's some nuance there, but legacy desktop applications that are exploited can certainly do more harm than anything running in a web sandbox.
On the other hand, people are scared of 'hackers', who are rarely presented accurately in media, taking control of their devices and spying on them or stealing whatever personal garbage is on their machine.
From that perspective there's almost zero reason to iterate in the direction you've suggested. Especially since, even if you got people to listen, they'll most likely just argue that if Microsoft, Google, Apple (who will probably keep doing their own thing) can't secure their data then no one can.
And from a company perspective this is similarly great, designing for a future where the OS is just a middle-man between the user and the browser means that you have more ability to wall out third parties and users who have problematic update needs/demands suddenly become much less problematic. Sure, the small fry will fight to prevent themselves from getting boxed out and succeed for a time. but you're a Megacorp who has bottomless resources to throw at development, you're looking at the long game. Eventually the cost to compete will simply be too high to be practical and when that happens you have a thoroughly cemented position in the future of the market and all it cost was forming a small alliance with other Megacorps.
Who else is there to object? China rolls their own way, Europe is trying a little but have yet to demonstrate the ability to overcome the obstacles that prevent them from being competitive, and when the American Fed does decide to take an interest it's for wildly exotic problem spaces (looking at you Ghidra and Tor).
I'm confident that soon enough there won't be such a devision as web app and mobile app anyway. That's why imo.
[0]: https://www.flurry.com/post/157921590345/us-consumers-time-s...
Lets say we have https://dynalist.io/. If you are going to open their web app in Safari and then open their iOS app - you will notice that UI is identical. Because it is the same UI! In one case you have to access it via a browser and the app is just the same frontend delivered to you as an iOS app.
PWA or something similar - is the future. Hence all those APIs in browsers.
We were moving too far into a world where anything connected required a mobile companion app that inherently has a lifespan because of how averse to legacy apps the mobile ecosystem is.
Because Google delivers its services through web browsers.
That's the only update I'm watching out for because I'll have to switch to another browser at that point.
I was going to start using Edge everywhere but now probably Brave after reading this - https://www.zdnet.com/article/brave-deemed-most-private-brow...
Hope they open it up a bit in the future. Just like they did with webUSB and webBT.