Safari on iOS can overlap multiple full-screen videos
mmazzarolo.com
mmazzarolo.com
You literally have to race the video popup, and sometimes I just have to memorize the location on my phone's screen where the "download linked file" button will appear and have my finger ready over the spot because there's not enough time to scan over all the menu items.
Is it possible that this is related to the iOS link preview feature?
When you long-press a link, do you get the full destination page preview? That might explain why the phone renders the page, including the video taking over.
Long-press on another page link (like one here on HN), and you have a tiny option at the top-right for "Hide preview," select that. Then try another link that has a take-over video, and see if it no longer does that.
If you hate video takeovers more than you like link previews, this might solve your problem.
I don't recall ever using link previews very much. I suppose if I really need it I can toggle it on for that specific instance, but as it is it's not worth it for the video hijacking
You can fix this bug by installing a Safari extension called Vinegar which will convert non-standard video containers to standard HTML5 video elements. As a bonus, this also prevents content injection by the malicious code that google sends to your browser to render content from third party advertisers on your device without your consent.
I checked, Sponsor block is available as well!
Yeah SponsorBlock is the only reason I still have Firefox installed on my Air. YouTube is horrible without it. I already pay for Premium, I refuse to put up with more ads.
On the other hand, Apple wants to incentivize developers to build apps, and they have a history of gatekeeping features from the browser to force certain use cases into the App Store. So hopefully they’re not omitting this setting to encourage app developers to create apps where they can run their “safe ads” without content blockers.
Having said that, they now enabled Picture-in-Picture on iOS (though last check it's still in beta I joined the beta a while back) and one of Apple's requirements is you cannot but OS features (such as Picture in Picture) behind an app paywall. So they could only do this by making it available to everyone including free users. Not sure what got them over the line but its there now.
So makes me wonder if that will go away - or whether they still enforce that requirement on Android, or what.
You’re kidding right?
Deliberately watching videos on a freely provided service supported by ads, makes the ad script “malicious and non-consensual”?
It’s my device, so I can choose what code executes on it. If I choose to block code from executing, that must mean I did not consent to its execution, because otherwise why would I need to block it?
I owe no debt to Google, especially since YouTube is often a non-consensual venue, in the sense that content I want to watch, which Google did not create, is only available on Google’s website.
I was not an active participant in the economic conditions that led to Google’s monopolization of the video hosting market. So if I am only watching a video on YouTube because it’s only hosted on YouTube, but I would have watched it if it were hosted elsewhere, then I am only passively responsible for the choice of watching it on YouTube.
I do not owe anything to Google in this case, because it implies I benefit from the existence of YouTube, but any benefit I derive is actually from the content, not the host of it.
The suggestion that I benefit from Google’s monopoly on video hosting presupposes the idea that free-to-watch video hosts cannot exist without serving advertisements. I don’t believe that, and I always choose alternative hosts over YouTube in the rare case where a video is hosted on both, or banned from YouTube.
I don’t use SponsorBlock, although I do manually scrub past promotional content.
- Creators use YT for ease of hosting, earnings for their effort, widespread dissemination
- Users choose YT for ease of watching, content discovery, non-bloated UI/UX
Google uses Ads to cover significant hosting and bandwidth costs, as well as to build quality features to help both creators and users alike.
If this logic doesn’t make sense to you, so be it. But your tirade is both entitled and ignorant.
Edit: I just opened weather.com on mobile and I rest my case.
The tracker has videos accompanying each of of the stages the order goes though. When viewed on the mobile site it just starts playing them all.
Or at least it used to. I just started using the desktop site when I need to track my orders, they might have fixed it since.
If a web page can do something that stops the browser responding or locks it up, the browser vendor won't fix it. They'll just say "well don't visit webpages that do that then".
https://bugs.webkit.org/buglist.cgi?chfield=%5BBug%20creatio...
Even if they fix it. It will take years to land in new iOS update.
Safari cannot update without iOS update...
But I think you're absolutely right. A bug report will serve no purpose, because this is definitely not a bug, i.e. not a flaw in code that causes the software to crash or explode. It is instead leveraging a quirk of interface design in order to garner attention for an otherwise unremarkable blog.
For picture in picture mode, I don't think multiple fullscreen videos should be a valid configuration of picture in picture.
This is a bug. These are unexpected results! And as the article notes, "sometimes this behavior makes Safari crash."
So a website can make your browser crash by getting it to do something nonsensical (opening 30 overlapping full screen videos), without your forewarning that this could happen.
You can quibble and say it's a "misfeature" or similar, but I'm not sure that means much.
Yes, he absolutely is, and the proof is
> So here’s a tiny web page I created to play with it.
What OP is reporting is more accurately described as a possible memory overflow exploit. The software appears to be operating as designed, but a malicious attacker might be able to exploit the behavior to do bad things, though this is not exactly necessarily true, and we won't know until we see it happen.
If this is intentional behavior, I don't understand the point. A full-screen video should be the only one playing IMO. Playing multiple (windowed) videos is one thing, but having 30 of them overlap full screen is quite another. And with no affordances to mass-terminate them, the result is unwanted behavior.
So: not a bug in the "off-by-one" or "use-after-free" sense, but damn if it ain't a close cousin.
Behavior can be duplicated on any modern computer, i.e. you can have as many overlapping fullscreen windows as memory will tolerate, probably thousands and much more than that. Why would anyone want to do that? To cry "bug," I imagine.
It may not be intentional design, but my point is that this is not a bug, by the definition of what a bug is. There is no actual error here. The code is operating as expected. There may be issues with the interface design, but there also very well may not be.
I highly doubt this. When Apple rolled out multiple video support, they did not expect that a random website could—having gained permission to spawn one video player—reuse that blessing 29 more times.
The browser will prevent auto-playing videos from spawning absent a user interaction. This is a feature that prevents pop-up hell. With this change, they failed to update the "make sure user is cool with this" code.
It's a regression, and will be fixed in an update or I eat my hat.
Again, I know this isn't some "error found on line 384 of vid.cpp" or whatever, but it's definitely not the way Apple wants this to work.
My desktop browsers won't do this, nor any other browser I've used in the past 10 years.
mobile Safari is a little different than desktop browsers. It uses the same engine as desktop Safari, but I've always suspected the video player is not built-in to the browser, but instead a separate and discrete application. I suspect this because every other application appears to have an identical video player. Maybe they're all sharing code, but more likely the video player is system-available to any application. But running multiple instances of that video player on iOS is academic. Why you're not able to duplicate this in any of your desktop browsers in the last decade is anyone's guess.
Because it's a bug not an intentional design choice. If you can provide a legitimate use case for being able to open 30 overlapping fullscreen videos from a single user click on a web site then you might have a some sort of argument.
This doesn't work on desktop Safari thankfully, if it did you could make some argument they are sharing code and trying to make iOS more like a desktop OS with multitasking, but no again there is no reason to do this on any OS other than to crash users browsers.
There is no error here. The code works precisely as intended, thus, this is not a bug, because bugs are errors in code that breaks the program's execution. That is not happening! The program still works and keeps on working until OP makes mobile Safari crash by intentionally eating up all the memory.
A software bug is an error, flaw or fault in the design, development, or operation of computer software that causes it to produce an incorrect or unexpected result, or to behave in unintended ways.[1]
Please continue to review the first 6 words of the definition until it sinks in that a bug is an error in the code, and a bug is not a quirk of interface design that you don't care for. If there is no flaw in the code, then there is no bug.
What OP and you and everyone else that apparently doesn't understand what a bug is are complaining about is this particular facet of mobile Safari's interface design. So if there is a problem here, it is not a flaw in the program code. It is a weird behavior that occurs when and only when the user decides to make their browser do weird things by creating a webpage to intentionally cause it. It sounds pretty darn unlikely to be repeated by anyone, and afaict, no one seems to have duplicated the behavior and reported back. But this is beside the point because the code is executing precisely as expected, and the program or system is not crashing because of this behavior, if it is crashing at all.
Again, this is not a bug. It is an entirely different animal.
A software bug is an error, flaw or fault in the design, development, or operation of computer software that causes it to produce an incorrect or unexpected result, or to behave in unintended ways.
This behavior is a fault in the design of the browser code handling full screen video playback based on a user click, it produces an incorrect and unexpected result that can lead to breaking the programs execution (Safari crash).
You are doing some serious mental gymnastics over a single word "bug" that everyone else seems fine with. You still have not provided a legitimate use case for this behavior that would explain how this is expected and correct behavior as seen by the designers.
It’s provided in AVFoundation
Is this a useful distinction? The user expects something, the designer expects something different. Just the other day I read about Jeep's Monostable Shifter (https://www.youtube.com/watch?v=jD1-aQSO5Hg) and how it was attributed to people getting hurt or dying. It's operating exactly as designed and intended but was still recalled.
No they aren't there is a button that the user clicks that runs code to play multiple overlapping videos. This serves no conceivable purpose and can cause the browser to crash, it is a bug.
The reason it works is the code is run from a user action, the problem is after the first video play the browser should no longer consider the subsequent plays a user action, or it should only play the last video and cleanup the now overlapped previous video.
I think this is where you and I are talking past each other. I'm not saying that multiple videos shouldn't be allowed. That's not the problem here.
The problem is that Safari has a mechanism to ensure that the user wants a video to play. That mechanism looks for some UI action on the user's part before it will allow a site to launch the video player. With this new multiple-video feature, that mechanism is now broken. It'll say, "Hey you want to play this video? Yeah, ok, I will allow it, and any other video the site wants to spam you with now."
That italicized part is the bug. It shouldn't assume the UI action applies to an arbitrary number of separate videos.
The video player is fine. That's the design choice. The Safari code not accounting for that is the bug.
"Every time a try to click this link, my browser crashes!" <--- that sounds like a bug.
"I'm able to create a webpage that exploits a user interaction to create weird behavior" <---- not a bug! if a problem exists it is within the realm of User Interface Design and not software design or anything within the code itself. The design choices may cause a need to rework the code, but that doesn't make a bug magically appear in the code.
> Okay, so it may not be a software bug at all, but I'm gonna move these goalposts and insist this is a product design bug, or something.
It pops up an interface on the lower side of the screen asking “do you want to dial this number?” or something like that. This seems to be the relevant doc: https://developer.apple.com/library/archive/featuredarticles...