It should be illegal imo
There should also be a name for ostensibly public social media sites that webhostage you into signing up. Instagram comes to mind.
It’s a reprehensible dark pattern.
The industry term is "web-to-app conversion" by the way.
Appholing Appstunting Nativebaiting
Has both web and app in it, and it says what it does. Could also be webcrapping as verb.
It's so clever I think I'll start using it, and also telling people I came up with it by myself.
[1]https://www.reddit.com/r/changelog/comments/6xfyfg/an_update...
But Chromebooks are sometimes a little bit special. I'm working on a app right now which is designed for tablets and wanted to check if I could run it on my Chromebook, because of the bigger screen (13" compared to Samsung S5/S6 with ~10") and I couldn't install it from the alpha channel. The thing was, it has a camera, a front camera, but the Manifest.xml required the default camera permission which was missing and this prevented me from even finding the app in the PlayStore.
And Slack as app is basically only the website. All the "native" apps seem to just render it (Linux, MacOs and Windows are Electron apps, the Android version feels like a WebView)
Then they decided you should need the app to message people.
Then they decided you should use a completely separate app to message people versus browse Facebook.
Now I have to use mbasic.facebook.com to message people. The quality of the experience dropped so much because, but I'm glad they don't have access to my contacts, text messages, location, etc. They get enough info about me from other sources.
Some forum software allows the owners to create an app then prompts you to install their app. Not sure which it is, but it's super annoying.
Over the last couple, reddit has significantly limited their mobile website utility, requiring login (like Instagram) and nagging you to download the app.
Marketing metrics seem to have overcome usability in terms of relative importance. It's really frustrating to see what the movie computing environment has become.
No shed picture. But no compromises here either.
Also I find it totally hilarious that I'm 42 and I have never even seen WhatsApp's interface yet my 80 year old father is a social media expert in a lot of ways.
If you send a link to padenot@mozilla.com I can have a look, I'm on the media team at Mozilla (that includes WebRTC).
Thanks!
I should note that it's not a "crash" -- it's just that I get immediately disconnected from the meeting when I have my video + audio on and then someone else joins. I'll try to get some repro steps and send to you!
I have no love for Zoom but at least they have a desktop app so I can screen share without bogging down my whole machine
The future is just tragic.
So if you want real data privacy, you need a native app, despite the drawbacks you point out.
And there are already encrypted media streams but I don't know if that counts as E2E?
A lot of these 'native' apps are just web browsers anyways...
So running WASM wouldn't make any difference if you're relying on a server to deliver you that WASM on every request. A compromised (or subpoenaed) server could simply ship you a compromised WASM payload for a single request and you'd be extremely unlikely to ever find out. If Signal wanted to add a backdoor, otoh, they'd need to ship it as a signed update to all their users, with all the reputation risk that entails.
Whether a native app is simply a browser underneath doesn't matter, just how the code gets delivered to the user. Even a browser extension or chrome app could work, since they are run from a signed, static bundle rather than from a server.
Encrypted media streams seem like a DRM feature? I don't think they have any relevance to end-to-end encryption.
One particular video conferencing software asked for permission to read key strokes from any process! A very weird request. The only non-nefarious use case I can think of is that they want to allow keyboard shortcuts to work even when their app isn't in the foreground.
On the other hand, you might be able to do it with some key or combination that is less commonly used?
I'd rather have a browser that cannot access these things at all. Now I've to hope that the permissions work and the implementation is bug-free (my trust in that is quite low, browsers are too large).
But you can put your computer behind Pi-hole or add some of Pi-hole's lists to your hosts file, which would prevent them from communicating with tracking domains completely... unless they also bundle some sort of a proxy or a VPN.