Safari is now probably the influential wild card browser for user privacy
utcc.utoronto.ca
utcc.utoronto.ca
The fact that Apple refuses to implement basic features in mobile Safari that Firefox and Chrome have had for years now, and the fact that they refuse to allow other browser engines on iOS is the reason why we can't have nice things like progressive web apps.
I recently worked on a health app related to the COVID pandemic. The most common use case would be served really well by a PWA, and as such, there's no reason users would need to install an app on their phones to access the web app's full set of features.
Despite the web app working perfectly on Android and across Windows, Linux and macOS without native integration, we now must dedicate time and resources to develop an additional iOS app just so iOS users, which over half of Americans are, aren't left out.
This is an expensive endeavor time-wise and money-wise, during a pandemic where time is of the essence and resources are stretched thin. It shouldn't be this way, but it is.
Wikipedia says it does support it https://en.m.wikipedia.org/wiki/Progressive_web_application:
And I know I’ve written Progressive apps for iOS myself - manifests etc.
So I know it’s not as simple as you’re saying. What do you really mean?
[1] https://developer.mozilla.org/en-US/docs/Web/API/Push_API
[2] https://developer.mozilla.org/en-US/docs/Web/API/Notificatio...
Complaining a browser doesn’t support a progressive feature is a contradiction in terms!
If your app doesn’t work like that then it’s not progressive... so you can’t complain it doesn’t support your progressive app because it’s not progressive.
The only solution I see is telling users to "use the app", which doesn't exist yet.
Remember that we had real time webchat without JavaScript two decades ago, and a lot of other things that would probably turn into some sort of Chrome-only site if invented today.
Unless I'm misunderstanding something about the problem, I don't do iOS dev or any webdev complicated enough to require OS notifications.
As an iPhone user, this being difficult for developers is a highly desirable feature!
If the app really is a game changer, if it's that compelling, Apple will absolutely change its tune.
As an example, my girlfriend's a nurse, and they have a really bad paging system. Basically, the doctor calls the hospital reception who calls one person who is on call, who calls the second person on call. Of course, this breaks up regularly: the wrong person is called, or they call their boss because they don't know who is on call, and so on.
I thought I would do a PWA to help them out and learn some new things, but it's pretty much impossible on iOS. Now, if 50% of her team cannot use the app, it has no value. You would have to know who has the app or not and call the other ones. It's easier to just keep on calling directly.
This wasn’t true 10 years ago when Instagram launched, and was iPhone only for a considerable time.
Clubhouse seems to think it’s not true today either, also iPhone only.
iPhone users are, on average, higher earners than the median American [1]. Being iOS only means you get the vast majority of high-income Americans.
[1] https://www.statista.com/statistics/195006/percentage-of-us-...
So no, lack of push notifications are not holding back PWAs. They are holding back web developers which choose to aggressively require new features, then get upset when they only work in the browser they tested with (invariably Chrome).
I’m not against web notifications per se, but I’m not buying that most web applications are held back because notifications are actually crucial to them functioning.
I think apart from Gitter I’ve never wanted a notification, as a user.
Now do you see why "the average user" isn't useful to determine how to build something? Even if most people suck at using email, in my app it works well.
This experience is geographically or demographically unique.
Do you find that most users do authentication via phone number instead of email?
Please be kind and not sneer as the guidelines suggest.
https://news.ycombinator.com/newsguidelines.html
You could easily reword you comment to.
> In my experience the average user barely uses email.
Unless you know parent commenter personally I don't think you're competent enough to judge their experience in an online discussion.
Push notifications are subject to the same HIPPA rules as sms. You can’t included sensitive info.
Spammy notification requests should be mitigated with better browser guards for requesting them. The fact that there is spam does not somehow invalidate that there are legitimate use cases people want them for.
This includes what vaccine I received, the lot number of its production, plus information from v-safe[1] and reminders to check in telling the government how I feel on days after the vaccine.
I use them for some local forums to notify me of replies. Don't want to fill up my inbox for this.
Mobile is already bad enough where if you swipe a notification away, well I hope you remembered the icon and the bit of context that was on that notification. Browser notifications just make this worse.
And then there's the whole "will I get a notification if the browser app is closed? What if I get a notification in the middle of the night, will I receive it in the morning? Will it continue to receive notifications if I restart my phone?" kind of questions. Maybe it all just works but I am very untrusting of the whole feature.
These are only the ones that I remember right now, but I know there is more
Safari has had add to home screen for the best part of a decade. Giving web pages the ability to spam users to add it is an anti feature.
On Chrome you can trigger a add to home screen prompt from your own UI, making it a two touch experience. On iOS IIRC it only works on Safari and not in Chrome, but I could be wrong.
> no one wants notifications from random websites
I am not talking about random websites, but rather web applications that you interact with on regular basis, if Apple cared about the user experience they could have just moved the notification prompt behind a user interaction.
> shared worker ... They burn battery life
If you are building more demanding websites shared workers are a great way to share state and computing resources across and thus saving battery life. Spawing a Worker per tab is more demanding.
Firefox unfortunately has no choice but to be dragged along by Google.
Also websites have realized that I am going to click No in the browser, so now they popup first asking if I want to allow push notifications in JavaScript so when I click no, they can ask me again later, vs if they popped up the browser and got a "No" there they could never ask me again.
Everyone acts like
1. For some reason it has to be some sort of pop up, it could easily be a small icon in your bar
2. Apple couldn’t/wouldn’t design this so that it was unobtrusive
3. If the way they did design it was still too annoying, they wouldn’t make it less so, or make it easy to turn off
Why do so many on HN argue from “if it existed it would obviously be in form X that already exists and therefore be bad and therefore I never want it and will oppose it vehemently” it’s a total lack of capability of even the most incremental innovative thinking.
It is a popup right now... it is in your face and requires immediate action.
An example:
Using:
https://www.bennish.net/web-notifications.html
> 2. Apple couldn’t/wouldn’t design this so that it was unobtrusive
It is obtrusive in that it is a full-window popover and you can't go to any other tabs until you have completed the action.
> 3. If the way they did design it was still too annoying, they wouldn’t make it less so, or make it easy to turn off
You can currently disable it browser wide in Preferences -> Websites => "Allow websites to ask permission to send notifications".
However, that doesn't stop various websites from displaying their own JavaScript based popups and requests before even attempting to use the Web Push Notifications API to see if the user wants to grant access using the native API's.
This way they can nag the user over and over to enable notifications whereas if you deny it once in the browser you need to take a bunch of manual steps to remove the website and grant them access.
On Firefox, it just puts a little message window icon in your address bar if you didn't trigger the Notifications API permission via a control on the website. When you do trigger the permissions through user interaction, and unobstructive widget shows up[2] that can be promptly hidden without ever actually interacting with it, unlike in your Safari example.
[1] https://developer.apple.com/notifications/safari-push-notifi...
[2] https://support.mozilla.org/en-US/kb/push-notifications-fire...
Honestly, HN is a cargo cult of native only, anti web app sentiment. It’s frustrating.
Your opinion isn’t held by other people, some of whom disagree with your opinion and are expressing that.
The other opinion seems "notifications cannot be disabled, therefore notifications are bad".
If you don't want to see notification requests, you never will. Granted: you need to be able to change settings, in a very restricted environment or with a custom clone of some browser you might not be able to.
For most users, that's not a problem. I'm one of them. I don't see notification requests on my desktop or phone. Neither do I see requests for geo-location, even though the browser is fundamentally capable of providing my geo-location to websites through an API; I've disabled it.
If I were on the Mobile Safari team, I'd propose bundling notifications into the bookmark workflow. If a user chooses to bookmark a site, prompt them at that moment (as an option in the modal) to subscribe to notifications if the site offers it. Because the user is expressing an interest in returning to the site, it's now appropriate to ask them to enable notifications, versus their first visit.
(For sites accessed through a synced iCloud bookmark, however, I would show a notifications prompt for the first visit on that device.)
I don't like notifications. I never get any notifications requests, unless I'm in a private window trying because some site wouldn't work with adblockers etc. Life can be so simple.
I don't want your phone calls. Your conversation is not important enough that I'm willing to be interrupted by you. The lack of phone calls is a desired feature. Please stop using phone calls. If I want to talk to you I will write you a letter. You don't have to nudge me into it.
The problem with not implementing notifications is that when they are useful (instant dispatch software), they are not implemented. But honestly I’d just spin up a telegram or email bot, if clients were not brainwashed with tekhnology. Messages and email are notifications. It is also a matter of minutes, opposed to creating a stupid service worker client-server-like runtime and trying to get things right without any test mode (long story short, implementing and debugging webpush requires publishing every change to a certified https host). There is even an entire company that sells you a properly configured webpush as a service. That’s just stupid.
This would have made it possible to offer notifications without being in-your-face about it, which would have made them more amenable for sites that were concerned about brand image and user feedback. The paradigm might not have become unavoidably tainted, and we'd just name-and-shame the bad actors.
It also makes it clear that the notification consent shouldn't be a one-way street-- you should be able to discontinue notifications through the same UI and in an obvious manner, rather than treating it as a consent you can easily offer, but not easily retract.
https://en.wikipedia.org/wiki/Inner-platform_effect
All in all, building out applications using cross-platform frameworks seems to be a far better solution for end users, and not significantly worse in terms of developer velocity, but I think there are other reasons they are not adopted, primarily that the web makes it far easier to invade privacy and deploy dark patterns, while that behavior typically is checked by the app store approval process for "native" or cross-platform applications.
Disagree. One reason sites want me to use their app is because I can’t block trackers. I wont use native apps if there is a web alternative BECAUSE i value privacy.
Why not? Web browsers are not just for reading text based articles. Most use a calendar, email, perhaps some kind of chat app through their browser. Aren't these and other similar use cases good reasons for notifications to exist?
Firefox as much as I love it, and has been my main browser linage since the Netscape days, doesn't stand a chance.
Specially when everyone is now packaging Chrome as Electron, while praising it for GNU/Linux desktop apps.
99% of Electron stuff could be done as pure Web application, and if native support is required, running as daemon.
With Firefox I don't see any issues related to the marketshare. All add-ons I want are available and all websites work just fine except one or two that just block it outright just out of spite (Apple Business Manager - business.apple.com being one)
As far as I know Mozilla doesn't have that many sources to keep it running, and the latest round of layouffs was kind of a signal of what is yet to come.
Let Google close the money stream and lets see what happens.
I hope to be wrong.
I would pay a lot though to keep it going. Like 100 a year or so (for me that's a lot :) )
You might not, but our users requested desktop and mobile notifications. The notifications let sick patients know when their prescriptions are ready, facilitate care-provider check ups, etc.
Personally, this is how I feel about downloading apps to my phone for every individual service and product. I see no need to download a separate app for each individual service I'm interested in, as the potential for abuse is higher than getting the occasional notification from my browser app and visiting their website.
However, it sounds to me like the focus should be on minimizing the potential for any avenue of information delivery to be abused, not to remove or decline to add features for fear that they will be. From the user side, I'm not interested in being told by a developer, "download my app if it's so important to you." I'd probably never discover how useful a service can be if I would have to download another app to try it. From the developer side, I'm not interested in telling potential users, "you actually don't want that feature."
However I routinely deny notification requests in Firefox so this is not a problem. I also routinely deny the permission to use canvas image data. Firefox warns it can be used to fingerprint browsers https://support.mozilla.org/en-US/kb/firefox-protection-agai...
Sadly Apple does its best to make more money. If they allow other browser engines they'd end up selling less apps. IMHO they'll care about privacy only until it positively correlates with making money. If it will ever cost them more than it gains, they'll find a way to weaken privacy without losing face.
An example, Apple ruthlessly enforcing in app payments for small companies but bowing to Netflix, Amazon and the like. They know they would sell less phones if those apps won't run on iOS.
And that's expected. Why would a company care about you and me in this age? No more than what you and me would care about ants.
Removing this feature from all users though is not a good solution either. Chrome allows you to block notifications from all sites so you don't have to dismiss requests anymore which seems like it would suit your needs and at the same time allow others to use this feature.
The whole discussion is about it being unnecessary resource use to develop said "simple app" due to Apple's restrictions on mobile Safari..
> Despite the web app working perfectly on Android and across Windows, Linux and macOS without native integration, we now must dedicate time and resources to develop an additional iOS app just so iOS users, which over half of Americans are, aren't left out.
> This is an expensive endeavor time-wise and money-wise, during a pandemic where time is of the essence and resources are stretched thin. It shouldn't be this way, but it is.
The end result is that, right now, some sick patients are punished for their wrong choice of phone or tablet because the native app doesn't exist yet, while others don't have a problem.
It would be reasonable to allow notifications only to installed PWA, and not just any website you visit.
They'd get to claim privacy/user safety (no drive by permissions grab)
But, this eats into their walled garden money pit, so yeah it's not going to happen..
Then there would be people who are trying to make you "install" their PWA at any cost, then sell their install base and the buyers will simply rename the app/website to anything they want.
It can actually be another golden age for the web while making users hate their phones.
What would be different?
Getting asked to enable a browser feature is not more annoying than getting asked to exit the app and install a brand new native app with worse sandboxing and privacy. It's at most the same level of annoying.
The app experience is almost always better because you always have more screen real estate, higher performance, better persistence and the developer has more opportunities to monetise you which eases the need to shove all the adds technologically possible into your face before you leave and never come back.
Visiting a new website in 2021 has the following installation process:
0) click a link
1) download the website. Websites are bloated these days, things jump around until you download and execute a few MB of JS, CSS, HTML and so on.
2) accept/deny tracking(usually designed to trick you into accepting)
3) accept/deny subscribing to newsletters(usually the skip button is obscured)
4) try to figure out what is this all about, trying to distinguish site element from ads
5) if you still want to continue you probably will need to create an account for anything that's beyond an article. Many times, you will need to create an account even for an article
6) after all that jazz you can actually try out the app/website or consume the article
7) if you like what you see, you need to bookmark/add to home screen
An app experiance is something like this:
0) click a link
1) see screenshots and explanation of what this app is all about, accompanied with reviews and ratings
3) if you like what you se, tap install, make a fingerprint scan or a face scan to download and open the app
4) try out the app. if you like it, it will be on your homescreen to use again. if you don't like it, you can delete it from the same place.
For both cases, any use hardware or system API you will get about the same popup asking you to give access to location/microphone/camera/bluetooth. For the mobile app the experience of managing it will be easier since it will have standardised settings in the device settings and you know the permissions are revoked when you delete the app.
For web apps you don't have an uninstall process. You need to dive into browser settings to remove history, cookies etc.
> The app experience is almost always better
Strong disagree. Even on iOS native apps are more invasive and have fewer privacy controls than a website does. That's why all of these websites want you to install apps. Facebook isn't asking you to install their app because it'll be a better experience for you, they're asking you to install their app because then they can request contact permissions.
> 0) [...] 1) [...] 2) [...] etc...
This is just nonsense. You're arguing that configuring a browser to default-deny permission prompts is a worse experience than getting badgered to install a completely separate application every single time you visit Reddit.
And to your point on advertising, this is a good reason to have an app environment that supports competent adblocking. Neither Safari nor iOS provides APIs to do that for websites or for native apps.
This all kind of boils down to, you have an environment with less sandboxing, less privacy, less granular permissions, and a longer install process (visit a site, switch apps, download and install a new app, switch apps again, then uninstall and clean up when you're done); but it's OK because the process of building an app is so cumbersome that a lot of businesses won't bother? This may not be the persuasive argument you think it is.
I mean, you can tell me all you want that notification prompts are worse than the current system of websites constantly asking to exit the website and install a new thing that gives them native file access to my phone, but... I browse the mobile web. I know what the mobile web is like from day-to-day experience, notification prompts are not the reason that the mobile Reddit website is annoying to use.
Instead, I see a lot of "enable notifications to prove you're not a robot" scam fake-CAPTCHAs and a lot of newspaper/TV/media sites asking for it. Just because I want to read one article doesn't mean I'm naturally after an update every time you post anything else.
This is a feature that Chrome has had for about 6 years. The fact you haven't discovered it shows Chrome's UX could be better, but the fact you haven't searched for it might alsp show that the popups aren't quite such a problem for you after all.
Chrome should default not to prompt. Safari estimates that no one wants this, and I suspect they’re right.
It absolutely should. Making the default "never prompt" would lead to websites prompting users to modify their preferences and change security settings. We do not want to normalize that behaviour. It would be a security nightmare. The defaults might be a little annoying for users (who can switch it to never prompt if they want to) but keeping average users who do want email or chat notifications safe online should take priority.
And I don’t think web sites would prompt this as they don’t on Safari and that works out ok.
I think Chrome defaults stuff that Google thinks makes advertisers more money and Google more money. Safari defaults stuff that Apple thinks users want.
If you turn notifications off for Chrome everywhere you won't see Chrome web notifications anywhere.
If you're talking about some other way websites can send notifications to your phone then I don't think that has anything to do with Chrome. And I can't think of what mechanism you're talking about.
That is true, but not really relevant to what he said. He didn't say "I wish there was a way to configure my browser to not send notifications to my phone".
You then followed up with a snarky line telling them the thing that bothers them doesn't actually bother them, and that wasn't great either.
He said he doesn't want chrome to be able to push notifications to his phone. Having an option to disable that feature means it is has to be possible in the first place.
Maybe I am being overly pedantic, but to me the distinction matters.
If you want it for yourself, you can make it happen. If you change a setting that disables ALL notifications for Chrome in your Android phone, your condition is satisfied. Chrome is not able to send notifications, unless the developers find a workaround :)
I want selected websites to be pushing notifications to me through Firefox. For example ebay-kleinanzeigen. Why should I install an app for that purpose?
>Chrome is not able to send notifications, unless the developers find a workaround :)
Yes, it is able to send notifications. It won't (or shouldn't, at least) but it is still capable of sending notifications.
If I put my manual transmission car in first gear, it's never going to shift to second, but it still able shift to second.
Lets say I told you your showerhead has the capability to live stream your showers on youtube, but that feature has been toggled off. I'm sure you would understand if some people didn't want that to be possible in the first place, whether or not you agree with them.
> Why should I install an app for that purpose?
I'm not saying you should! I'm not arguing the merits of the original opinion, I'm simply saying there is a difference between whether an application can do something, and whether it will do something.
Is that really a cleaner, less intrusive UX for you then it would be to have an easily ignorable button next to a website's address bar that would allow you to turn notifications on or off for each website with maybe three or four clicks at max?
I can always chose not to install an app.
> Is that really a cleaner, less intrusive UX for...
Imho it's a security question. I don't care if it's clean or less intrusive, the browser should be a sandbox.
Sure, but I can also choose not to use a website or service. If a set of features is only available in a specific medium (whether that's a website or an app) your choice is the same -- you either use it in that medium or you don't.
> the browser should be a sandbox.
This is an interesting point, because I do get where you're coming from, but I almost draw the opposite conclusion from the same data. The browser is a sandbox, so I want to put things in it. I refuse to install a native app to check my bank balance or post on social media, I don't trust those companies with that level of access to my phone.
The browser is a better sandbox than my native device, and notifications don't really break the browser sandbox in any significant way. So if (as heavyset_go suggests) notifications are the difference between having an app built in the sandbox or out of it, then I want notifications, because I want the app to be built in the sandbox.
If having notifications could make it feasible to use Twitter without installing an app, then great, we should do that. Or if notifications are enough that I don't need to have an email app or Matrix client installed... it's a pretty substantial win for security if I can get rid of those apps on my phone and use them as mobile progressive websites instead. Having email notifications on my phone is mandatory for me, I can't drop that feature. But is that alone a good reason to install a completely separate application that's requesting filesystem access or contact access?
Who are you? And why does only your absolute opinion matter, when others are asking for a choice?
We are the the 99%
I'm not defending stupid notification popups from some website you'll only ever visit once. Those are annoying. I'm saying you can't tell what users want unless you specifically measure exactly that. Maybe you're right and 99% of users don't want notifications, but that's not what your cited numbers show. You're drawing a conclusion from the data that isn't there.
And besides, for something to be spam you need to actually see it. In the case of notifications if you deny the permission on a site you don't see the notifications. That's the perfect spam filter. Imagine a world where people could only send you email if you explicitly said you accepted it from them. Or if robocallers could only call you if you agreed first. Spam would be over. There would be no spam. That sounds fantastic.
Personally on Android I have enabled notifications from a total of 2 sites and I find the experience quite good. I actually think its better than having to install an app for something that you rarely use just for that one time you will need to receive a notification from it.
> the reason why we can't have nice things like progressive web apps
I.e. implying that progressive web apps are only possible if a specific set of features are supported everywhere. It’s like saying that accessibility is only possible if no users have disabilities.
Your confusion comes from your personal definition of "Progressive Web App"
For sure the confusion starts from their name, but in short «A progressive web application (PWA) is a type of application software delivered through the web, built using common web technologies including HTML, CSS and JavaScript. It is intended to work on any platform that uses a standards-compliant browser, including both desktop and mobile devices.»
Emphasis on any platform that uses a standards-compliant browser, in this case Safari is not standard compliant.
A Progressive Web App (or PWA in short) is not the same thing of "progressive enhancement" or "graceful degradation" for regular Web Application.
Those are just some of the features, but it doesn't stops there.
Some of the fundamental charateritics of a PWA include being
- App-like — Feels like an app to the user with app-style interactions and navigation
- Re-engageable — Ability to use push notifications to maintain engagement with the user
As you can see being able to notify the user is a key feature of a PWA.
Which is not possible if some vendor refuses to implement the standard features that narrow the gap between Web and Native, like Apple is deliberately doing with Safari.
It's not too hard to make them work without those features, that's not the point, the point is it's impossible to have the same feature set on every platform because one vendor in particular doesn't want you to, they want you to develop native applications which is vastly more costly and it feels like wasting effort and money on something that should have worked with almost the same capabilities on all the major platforms with little or no modifications. It's true everywhere, except on Apple mobile devices, where you can't even chose the web rendering engine.
1: https://infrequently.org/2015/06/progressive-apps-escaping-t...
It is almost Electron level bad.
But Safari will never be a serious option for me. I want the same browser on all my systems and I use a lot more than Mac and iOS. So Firefox it is.
Is that against the App Store guidelines? Or is that a programming limitation? I am aware all the iOS browsers are just a wrapper around WKWebView but am curious why another engine can't be implemented.
As a browser Safari is beautiful (loving the look of it on Big Sur), efficient, lightweight and has a lot of little creature comforts that other browsers can’t or won’t implement because they are Mac specific (keychain, Touch/FaceID, native share sheet, 2fa code reads direct from Messages, etc). But it’s also hard to see a future in a browser that is still stuck in a Web 2.0 philosophy.
The author’s point is good though: Safari is becoming the final bastion of hope against a purely Chromium landscape just by virtue of being an Apple product with an immediately large market share. I hope Apple will use this position of power wisely and help drive browser behavior rather than just being comfortable to exist in their own little world. Wishful thinking, I’m afraid. For Apple Safari seems to be little more than a talking point when advertising MacOS/iOS. It’s just another feature.
For what it’s worth I’ve been really enjoying Vivaldi of late (I have no affiliation with the project, just including for context on my day to day browser).
Today, the iPhone has 66% market share in the United States, 75% of U.S. App Store revenues, and over 80% of time spent on the mobile internet.
And even if you do, it is still 25%+, hardly a minority.
Very good, none of those webCVE features deserve to be potentially accessible from malicious scripts on the web.
That’s a rabbit hole of DLC, plug-ins and vulnerabilities they don’t want to go into.
With regards to vulnerabilities, they are mitigated as much as possible by making sure the JIT runs in separate, unprivileged processes. And anyway it is easier to secure one Javascript engine that is included in OS updates than it is to keep a multitude of engines up to date which came with apps most people don’t even think of as a browser.
Moved to AdGuard, seems good for now.
Also, try Hush on iOS, I don’t know the magic behind it but it seems to be much more potent at killing nagging questions.
Hush looks excellent. Thanks for the tip.
Hard to tell without looking if these things are real or a parody!
I think that Apple don't implement these features because they want to make more money and have developers make apps for their platform for free (and actually collect a fee from the developers that are improving the Apple ecosystem).
And I don't want to download your 200Mb native app that I will only use once. Besides that, the average webpage size is 2Mb which IMO is still too big, where as the average iOS app size is 34.3Mb.
As a user I have never needed or wanted web bluetooth or web usb, and I have never seen a person in real life that uses these either. For all I know, it's just mythical users mentioned in HN comments that want those.
Web Bluetooth: A Chrome only feature. Not a standard or standards track. Firefox and Safari both said that they will not implement due to the security issues.
Web USB: A Chrome only feature. Not a standard or standards track. Firefox and Safari both said they will not implement due to the security issues.
One additional thing: over use of devices is also a problem. Apple tracks use for you and I find the weekly reports useful. Apple does not need us to be addicted to social media and marginally useful stuff on the web, their business model doesn’t require it.
I don’t want many apps on my devices and I don’t want every web site to effectively be an app on my device. If I do spend time on a digital device, I either want to be doing something useful, or working on a book project that hopefully some people might find useful. It takes some care to not waste time, and since I am approaching my 70th birthday, I have stronger feelings about not wasting time than I had when I was younger.
What happened with Edge? I've been out of the loop with MS stuff for years, and last I heard you had to select a browser in the EU or something, but was this also made mandatory worldwide?
I'd imagine still being bundled with Windows means their usage is not insignificant...
Take a look at the settings for IE, which actually improved with each new version, and you can clearly see which side MS used to be on. Then compare it with the useless dumbed-down "modern" UI of even pre-Chromium Edge.
Despite enterprise teams already finding Chrome's six week release cycle tedious, Microsoft immediately followed Chrome to announcing their four week cycle in the last week, and Edge also failed to protect ad blocking by rejecting the Manifest V3 changes for browser extensions designed to cripple ad blockers.
Basically, at any opportunity Microsoft has had to differentiate itself, it has decided to just do what Google does.
The Chromium Edge doesn’t support 3rd party cookies already and thus isn’t really subject to targeted ads like Safari or Firefox.
Now please continue with your reasoning.
And Chromium-based Edge has tracking prevention through filter lists, while Chrome does not. [2]
Microsoft is no one's privacy hero these days, I will concede that. But some of these specific claims are just wrong.
[1] https://www.linkedin.com/in/rajeshsu
[2] https://support.microsoft.com/en-us/microsoft-edge/learn-abo...
It is true Microsoft ported some of it's tracking prevention features over to Chromium Edge, but it certainly isn't a step above or beyond Firefox or Safari, and it's frustrating Microsoft continues to follow Google in places reasonable companies should not go.
As for Eric Lawrence, if Eric gets quoted a lot that's probably because he wrote the first versions of Fiddler, the debugging localhost proxy that many Windows developers use, so tech journalists that specialize in Microsoft have heard of him through their developer acquaintances. Plus his Microsoft email address is easy to guess: [his Twitter username]@microsoft.com
Eric left Microsoft after over 10 years, went through 2 companies including Google, then came back within about 6 years. I consider him closer to Microsoft in outlook than Google, though one could plausibly disagree given how rude he was about his old team's products IE and Edge while he was away.
As for "Principal Program Manager," that being misleading about scope is news to me, and if it is, that's on the journalists to clarify, because this kind of title is commonplace and implies very little. At any tech company "Program/Product Manager" is not necessarily a people leader. "Principal" doesn't change this. "Principal" at Microsoft and other tech companies is just a rank like "Senior," albeit a hard-to-earn and usually well-deserved one. If I say I am a "Principal Product Manager, HotTechCo BlahBlah," I don't think anyone in the industry will assume I run the entirety of that product.
Several pages say Sundaram's title is Technical Fellow and VP of Engineering. I assume you know what you're talking about. But you can't blame people for thinking it's an engineering role only.
Singling Firefox out by saying "even Firefox" makes me think you don't expect Firefox to "get it right." I am wondering why that is.
Chrome is sprinting ahead with new feature at a high pace, however, we should make sure the web only uses features that are widely available in all major browsers.
There's a browser that has almost absolute domination of the market, chooses what features become standards simply by shipping them, is aggressively anti-competitive, and yet you're complaining about safari?
With All due respect, this is a very Apple view.
Today, the iPhone has 66% market share in the United States, 75% of U.S. App Store revenues, and over 80% of time spent on the mobile internet. We can debate whether that fit anyone's definition of monopoly. But it is definitely not on a minority platform, nor a minority browser.
Safari's current features set doesn't have much problem as a Web Page browser. And wouldn't be a concern if it wasn't for App Store's policy. But when Apple is the majority or dominant platform in a market these can no longer be looked at as an individual case. And will very likely be used as a weapon in AntiTrust issue.
To be quite frankly honestly I dislike PWA and Chrome and I wish Safari stay the way it is and only Apps Store changes its policy. But right now Apple seems to be willing to fight that at all cost. And there are no middle ground to balance things out.
How is Safari not implementing standards seen as a good thing?
While I do acknowledge that there might be privacy concerns when it comes to Chrome, I do appreciate that Google is trying to push the Web forward, while Apple is trying to hold the Web back.
Safari truly is the worst browser, I fucking hate it. Apple is doing the bare minimum and pretends to "protect user privacy" when all they do is to prevent the web to compete with their app store. Apple pretends to care about the user experience when they are the only ones not implementing standards that would benefit the user.
Ohh and you are on Windows and wan't to debug something on Safari? Forget it.
One, “feature” isn’t the same as a standard. And two, standards aren’t standard. They’re adopted through a dubious process and then ignored by the most powerful companies.
Apple is really the only one these days ignoring these standards. Even if it a "dubious process", if there is consensus among the majority browser vendors I would call it standard.
“Consensus among the majority browser vendors” effectively means what Google does.
Ohh and you are on Windows and wan't to debug something on Safari? Forget it.
Yeah, this utterly baffles me. You'd think Apple, out of sheer self-interest, would offer some sort of "Safari for Developers" that runs on Windows/Linux. Even if it's some kind of klunky suboptimally-performant thing. Just make it really obvious in terms of it's branding and theming that it's devs-only.The issue that I have with safari being locked to a specific iOS version is that people on older model such as the iPhone 6 are being stuck with an outdated browser, even though the phone is still useable.
To be fair, Apple handles updating iOS a lot better than Android, but Chrome is not tied to the OS versions, this means I can update Chrome through the Play Store which means: 1) faster update cycle and 2) old android phones can still run the latest Chrome.
Safari on Windows was left alone in time Chrome was in the process of being bundled with various software installers as an additional option - which is the way how this browser become popular. I doubt it will be ever pushed forward with development, simply because Microsoft and Windows it's not Apple's subject of interest. Sure, they do offer iCloud services for Windows but it's a rather basic stuff that allows to use different platform from time to time, not on everyday basis (as in, you aren't buying just to remove OSX and install Windows).
Of course, would be great to have more options but we're living in almost homogeneous web browser world - it's all about Chromium/Blink, even Microsoft abandon their engine and took Chromium. There's of course Firefox but honestly, I don't think it's gonna last long - not will all these decisions that has been made and how Mozilla treated its (power)users. We're all dependent on Chromium, its devteam and what Google decides is "best" for the whole world and the Internet. Which I believe, is certainly a bad thing.
I think it's because at some point they start to rely on features solely available in OSX
This is the only answer that really makes sense to me. I think it tightly couples with MacOS stuff like sandboxing, whatever codec stuff they're doing, and whatever perf stuff they're doing to make Safari "feel" so fast on the Mac. I think they feel that replicating all of that in Win32 would just be impossible/unsustainable. Still, I wish they'd just make it some kind of "developer edition" thing. It could be a bit janky, even... as long as it was clearly labeled "for developers" or whatever I don't really see it giving the company a black eye. We're all dependent on Chromium, its devteam and what Google
decides is "best" for the whole world and the Internet. Which
I believe, is certainly a bad thing.
I agree wholeheartedly, and Apple seems to agree! That's what's so f'ing baffling to me.Clearly they feel that Safari is an extremely important project; the only thing standing between Google utterly 100% owning the web in every sense that matters. A thing that would clearly be bad for Apple.
Accordingly, Safari on Mac gets a ton of investment from Apple. And clearly Apple feels Safari is so important that it's the only browser engine allowed on iOS.
But, I can tell you from experience, a hell of a lot of B2B stuff and stuff cranked out by small shops is just never tested on Safari. And one reason is that a lot of small shops just don't have a Mac sitting around. And experience tells us that this is the death of a browser. Nobody wants to stick with browser XYZ once some percentage of their stuff stops working. They don't want to run multiple different browsers. It's a pain. They eventually follow the path of least resistance and just use the browser where 100% of their stuff works.
What percentage of that is possibly due to folks buying Macs just to run Safari? Pure speculation on my part but I don't believe it can be more than a percentage of a percentage.
Was there a sudden increase when the Windows version of Safari was discontinued in 2010? It's hard to say exactly, because there are an awful lot of factors involves in sales numbers, but I don't see any evidence to suggest that's the case.
Also: think about your average dev or dev shop that buys a Mac just to make sure their stuff works on Safari. Are they buying a shiny new high-margin Mac? Oh heck no. They're buying the cheapest possible new Mac or, more likely, they're getting some cheapo preowned Mac. Or perhaps even more likely, they're using a service like Browserstack.
They wouldn't shoot their entire web strategy in the foot just to sell some negligible additional amount of Macs per year.
"push the Web forward" is Googlespeak for "gaining control". It gets to decide what the "standards" are and churns them to discourage any competitors while at the same time operating a massive "developers developers developers" style propaganda campaign to gather supporters and help increase its monopoly.
I don't use Apple products and disagree a lot with what it does, but this is really a "enemy of an enemy is a friend" situation.
Related article: https://news.ycombinator.com/item?id=9961613
Because I give them money.
"Meet Face ID and Touch ID for the Web" https://webkit.org/blog/11312/meet-face-id-and-touch-id-for-...
Safari may support Face ID and Touch ID, but I doubt it would be in anybody else's best interest to also support it.
Not that it matters anyway, since on iOS they all use Safari...
Apple isn’t just lagging behind. They very intentionally do not want web APIs to become a viable app development platform on their hardware ecosystem.
Other hardware vendors are rapidly catching up to Apple in terms of hardware quality, so the main remaining differentiator for Apple becomes quality of software experiences. This is, of course, precisely the arena in which Apple currently dominates, owing to their investment in making their app dev stack the best in the world. More than anything else, they do NOT want to lose that advantage.
So, a non-proprietary app dev platform which matches or exceeds the quality of their own? Yikes. If they allow Safari to become a gateway to such a platform, it would truly be an incomparable existential threat to their app development and distribution model.
I personally think it’s inevitable, but... you can better believe Apple will fight it as hard as they can, for as long as they can. My money’s on their next CEO slipping up and allowing a full glorious Web implementation to be built. There goes any advantage to developing software experiences for the proprietary Apple platform, and that’ll be the true beginning of the end for the modern successful Apple.
On desktop I'm all FF, of course.
Firefox Klar/Focus also isn't bad, if you don't mind losing some of the functionality of the full version.
Ah yes... such as push notifications. Firebase would be so much more useful if Safari supported push notifications...
> Co-Founder of NodeBB Inc., modern forum software for the modern web.
So I assume they want notifications for forum software.
It's just entirely broken on iOS, but them's the breaks.
Isn't a notification receiver of the most important uses of a phone?
Mozilla literally studied this and essentially 100% of "let us spam you" requests were denied.
I agree users don't want notifications from web pages, but the web is much more then just web pages and I would argue that on web applications users are much more likely to allow push notifications if they get a clear benefit.
The web does not have that gate. The web has "I went to the apps website to see if it did what I wanted. it did/didn't, and then asks to send me update notifications"
I would say it's not so much optimizing for good websites vs bad websites, as optimizing for real-world websites.
Real-world websites are overwhelmingly shitty, push dark patterns, invade users' privacy, abuse any APIs they are given access to, etc. Limiting the amount of things they can do is an enhancement to the user experience, even if it's worse for you as a dev.
It's a lot like having to have laws. Why do we have to have laws, isn't that "optimizing for bad people" instead of maximizing the freedom of good people?
For instance, you could forbid websites from requesting the notification permission, but the user could manually go and allow it. It would probably cut 99% of the spam while allowing people that really want notifications to have them. As for the 1% left, we're not talking life and death scenario here, at that point the good outweighs the bad I would say.
This is the thing I don't understand about some Apple advocates these days. Even the idea of having a choice is unacceptable.
All part of Apple's plans to enforce their one and only apps store for use on the iOS platform. Wouldn't want those pesky webapps being able to sidestep Apple's walled garden.
As a result it's free to make whatever choices make sense for the user as long as they aren't related to that. I wouldn't call it "humanist" because of that just a different revenue model.
The same is true for the rest of Apple, it didn't get to a 2,000,000,000,000 market cap because it's humanist it got there with unique ways and focus on how to make money. Probably less bad than how Google does it though I don't consider that the bar for doing good.
(Sorry Apple fans, it does and while their marketing tries to hide it as much as possible, their privacy policies don't lie : https://www.apple.com/legal/privacy/en-ww/)
It's funny how quickly one can get downvoted for criticizing Apple's misleading marketing. Apple is a data hoarding company like every others, and no “not being worse than their competitors” isn't good enough.
The intent of the spying should also be considered. Apple does not have a significant targeted advertising business which reduces/removes the incentive to hoover up as much personal data as they can.
Would I prefer something that doesn't spy at all? Absolutely, but this means rolling your own computing environment using Linux and giving up a lot of features that are considered a given in macOS, and yet there's only 24 hours in a day and I no longer have time for that.
What exactly are you referring to when you claim Apple ‘spies on its [sic] users’?
Every bit of data Apple has about me is a) made explicitly clear, b) used for a specific purpose or feature, and c) isn’t sold to or used in any adtech bs. That all sounds good to me…
What makes you think so? Because the privacy policies you agreed on allows them to (in the the Apple’s Sharing of Personal Data section):
>Partners. At times, Apple may partner with third parties to provide services or other offerings.
Yes, that's it (there is an “Example” section following, but this is non-binding). Any kind of partner, for any kind of “other offering”. Partnering with any ad tech for selling ads complies with this clause.
Also, as I'm not a native speaker, what's wrong with “spies on its[sic] users“? (Note that the original sentence was “operating system that spies on its users” not “Apple spies on its users”)
There's no evidence that they have done anything like this yet, but they at least considered it and their privacy policies allows it as soon as they decide it's worth it. And you wouldn't necessarily know it.
Just because a company's marketing says they respect your privacy doesn't mean they do, especially when their privacy policy says they can.
[1]: https://www.numerama.com/magazine/30323-apple-approche-les-m...
[2]: https://www.bloomberg.com/news/articles/2014-08-21/wear-this...
Sorry, no. Did Apple consider it? Possibly, in fact it almost a certainty. More importantly, did the act on it? No. Nothing wrong with exploring options.
Let's not engage in slippery-slope hypotheses.
> Just because a company's marketing says they respect your privacy doesn't mean they do, especially when their privacy policy says they can.
You still haven't shown us where it says they can. I'll take your word for it...
Yes I did a few comments above, but no problem I'll repeat it :
> (in the the Apple’s Sharing of Personal Data section):
> Apple may share personal data with […] Partners. At times, Apple may partner with third parties to provide services or other offerings.
Service Providers. Apple may engage third parties to act as our service providers and perform certain tasks on our behalf, such as delivering products to customers. Apple service providers are obligated to handle personal data consistent with this Privacy Policy and according to our instructions. They cannot use the personal data we share for their own purposes and must delete or return the personal data once they've fulfilled our request.
Partners. At times, Apple may partner with third parties to provide services or other offerings. For example, Apple financial offerings like Apple Card and Apple Cash are offered by Apple and our partners. Apple requires its partners to protect your personal data.
Others. Apple may share personal data with others at your direction or with your consent, such as when we share information with your carrier to activate your account. We may also disclose information about you if we determine that for purposes of national security, law enforcement, or other issues of public importance, disclosure is necessary or appropriate. We may also disclose information about you where there is a lawful basis for doing so, if we determine that disclosure is reasonably necessary to enforce our terms and conditions or to protect our operations or users, or in the event of a reorganization, merger, or sale.
I think you are clutching at straws, based on shoddy information. The above seems unambiguous to me.
That's it. No other limits or restrictions.
So yes, partnering with a insurance company is allowed by their privacy policies.
If you want to have faith that Apple will never do evil things with your data and that their is nothing to worry about, that's up to you. I have plenty of friends who thinks the same about Facebook or Google you know…