Instagram can track anything you do on any website in their in-app browser
krausefx.com
krausefx.com
Let websites framebust out of native apps - https://news.ycombinator.com/item?id=32418679 - Aug 2022 (37 comments)
Honestly I thought all other methods had been deprecated and had no idea apps could still make use of the less secure (for the user) options. Trust me, as a developer I've wanted to reach inside a SFSafariViewController many times to make my life easier but in the end I've just grumbled and assumed it's not possible and worked around it.
I wish there was a privacy-safe way to get the best of both worlds but due to bad actors I doubt that will be possible. I need to look more into App-bound domains but I don't think even that will give me what I really wish for (a way for the page loaded in SFSafariViewController to tell my app something). Something like postMessage support for SFSafariViewController would be amazing and be safe privacy-wise I think since the contained page would need to support sending/receiving messages instead of just having code injected against their will.
One thing about both webviews is that there are callbacks with these implementations that developers can choose to open a link in the embed webview or not. It might be useful for privacy/security for Apple/Android to force developers to allow-list a domain (like iOS's Associated Domains) or such that an embedded webview can load (besides local html and files). It might be something in addition to the developer's callback.
iOS WKWebview: https://developer.apple.com/documentation/webkit/wkwebview Android Webview: https://developer.android.com/guide/webapps/webview Associated Domains: https://developer.apple.com/documentation/Xcode/supporting-a...
However after reading this article what I will be doing is intercepting any links from my WKWebView to domains outside of my forums and opening them in an SFSafariViewController. I have no intention of tracking anyone, but neither do I want the responsibility or reputation for domains outside of my control
I'd be happy to put a Safari button on the WKWebView sidebar version, but as it is a coding app and the forums are full of helpful code snippets, having it appear alongside the code editor seems like a valuable proposition.
The big advantage of using WKWebView is that when a user posts a zip file containing their project you can simply tap on the link to run the project and see the results. You can also easily share your code to the forum by tapping a button in the app's UI to post it to the thread.
These sorts of native<->web integrations are not possible with SFSafariViewController. However I would not want these integrations on any outside domains, and so would push the user back onto SFSafariViewController if, for example, they opened a discussion and tapped a link to an external blog or article.
Edit: perhaps I am not explaining this well. Here is an example of what is happening in my app https://twitter.com/twolivesleft/status/1557378008495058944
That said, in general, never, ever use in app browsers for surfing the web. We use them for specific pages on our website that should interact back to the app, otherwise we tell the system to open the URL in the user's browser
There are a couple apps where we are using SFSafariViewController but WKWebView would make our lives easier so I need to go back and look at switching those out.
> ITMS-90809: Deprecated API Usage - App updates that use UIWebView will no longer be accepted as of December 2020. Instead, use WKWebView for improved security and reliability. Learn more (https://developer.apple.com/documentation/uikit/uiwebview).
We don't have many web views anymore, we still use a couple for signup and for the user to change their privacy settings because we need to change some behaviours based on the results, so we inject something to know if the user made changes and close the view. But there's no way for the user to navigate out to the greater web from the pages. Anything else and we instruct the os to open URLs
How is that possible that Google Play and Apple store allow apps like this to get published?
> ITMS-90809: Deprecated API Usage - New apps that use UIWebView are no longer accepted. Instead, use WKWebView for improved security and reliability. Learn more (https://developer.apple.com/documentation/uikit/uiwebview).
Regardless, i don't consider it to be acceptable behaviour by Instagram to inject their tracking into all web pages i access through their app just because they can.
Except they didn't give it to me, my partner/sibling/parent/friend did, in a message sent through their app. We should expect that kind of interaction, to not be tracked; should expect, but obviously can't expect it today, these news are not surprising.
This is just one more aspect of their tracking that may be non-obvious, and that it's good to know about.
Android has a nice universal "back" button which can close an opened tab and return you the app that spawned it. iOS tried a similar option with a "go back to App" link at the top left, but it doesn't fully close out browser tabs spawned by the app. Safari has gotten smarter about this, with browser "back" buttons closing spawned tabs in many cases, but not all.
So, in all those emails where I click to launch a browser to "read more" but see no reason to keep it around, the embedded browser actually plays a maintenance role: no need to get rid of those tabs that were just a funny comment I wanted to see but never need to keep.
Yes, the tracking is disappointing, but the UX of not having a zillion tabs open (and in old iOS version, hitting tab limits) makes my life easier.
Anyone can potentially steal your wallet, so we shouldn't point out when someone actually does? Especially when there's hard evidence in article?
Installed system wide ad blockers ages ago and got on with my life.
I am not sure what the solution here is. Maybe only allow injection to sites you control (via apple association file).
If your app uses the JavaScriptCore[3] framework to run JS in a VM in-process directly, you have even more options for interfacing between JS and native code.
Note that this has to be explicitly hooked up by the app (i.e., none of this applies within, say, Safari).
[1]: https://developer.apple.com/documentation/webkit/wkuserconte...
[2]: https://developer.apple.com/documentation/webkit/wkuserconte...
[3]: https://developer.apple.com/documentation/javascriptcore
With the appropriate libraries you can use JS to call Swift and Obj C code.
Long answer: no
All it really means is that the JS and Swift/Obj C can pass data between each other and the library is set up to parse that data and call the appropriate code. It's just an automatic RPC.
A domain verification would be a huge hassle for me, since I provide an app builder that allows my non-technical customers to build an app (which includes a webview). Asking them to do domain verification would be tricky.
It's also frustrating that on an android device you can't simply disable in-app browsers globally.
I turn it off in every app I can and miss the old version of Firefox that had the option to disable them altogether.
But I think I prefer that because if I click around a bit I can switch back to the app that spawned the tab directly instead if hitting back a load of times.
e.g. Apollo by iamthatis here on hn does this and I very much doubt he is doing it for tracking reasons.
“How do I protect myself?” should be point number one.
Does apple require that developers allow users to open these links in safari—- w/o tracking? Or do developers feel this is the only moral way they can agree to this user-hostile behavior?
Better analytics = better product*.
* for the true customers, i.e. marketing & communication firms, governments, etc.
Is anyone under the impression that they are a customer of a service they don’t pay for?
People would readily identify as a “Twitter user” instead of a “Twitter customer”
Maybe not on a technical forum like this, but I think the distinction between a "customer" and a "user" is sufficiently fuzzy among non-technical people.
Because otherwise, an app can totally fake the interface of a security dialog. The only way you know, these days, is that password managers and cookie jars work with the "approved" sites, but they can simply show you a site that doesn't require those, and then fool you into entering your passwords!
Steve never replied to me. And Apple never implemented it.
[0] https://www.w3.org/TR/permissions-policy-1/ [1] https://scotthelme.co.uk/enabling-coop-and-coep-reports-on-r...
But developers continue to use them as HTML + CSS + JS is the easiest way to develop a graphical dynamic UI, for a newbie. Many schools & colleges even teach basic HTML, CSS & JS, so the barrier to entry is very low.
I am not sure what a good solution here would be, but maybe we could start by limiting access. Or another way could be to have some way to convert the rendered UI to compiled binary code
I never made the connection until you brought it up, but yes, Electron apps are just like using Webkit on iOS. Abstracting UI/UX to a browser engine which has identical security pitfalls to a browser but with far less control and inspection capability.
The war on control of data continues on.
Can go way more into other ways but too tired, also most who are surprised by this just need a starting point.
Btw, Apple and Mozilla are no privacy guardians out to protect you. These days they do just as bad.
What would be nice here is a permission requirement if you're injecting code into a browser view.
In many cases I'd like to stay within the app. Those in-app Safari Webviews allows that. And if it is a website I'd like to browse in my usual, more permanent browsing evironment I always have th eoption to do so.
This two step approach is more useful to me than always opening links in the browser.
and i'm not talking about bad phones here — htc one s, nexus 4, nexus 5, nexus 5x. admittedly, degradation of shitty NAND is still a factor in higher-end android phones, so it's not all about the android ecosystem being a free-for-all
an iphone xr will still run everything fine, including the latest version of ios. hundreds of dollars saved and a whole set of problems avoided over the life of the phone. i only replace my phones when they're smashed to bits now
anecdote: someone in my family just had to replace their android phone because a software update caused the radio to stop working for calls. so the ecosystem issue is not just a userland thing
Which honestly does not surprise me, what surprises me is that Apple allows this. I think there was a time where certain Javascript capabilities were present in Safari but not in Safari Webview and there was certain outrage.
Perhaps a solution would be to run the webview through Safaris content blocker engine?
But then how do you differentiate when the app is rendering its own view rather than another website? You could apply some restrictions like <iFrame> has nowadays where you need extra security privileges (I think) to render pages / execute scripts not on the same domain
Otherwise you can always open safari from all of these in-app browser views and they could implement a toggle which forces all of them to be opened in Safari automatically
Honestly it is pretty fascinating how these cross-platform frameworks work.
and no, not all apps do this. tiktok does not offer an escape, and instagram hides it behind two clicks.
Simple example: try to use "Login with Google" from within one of those in-app browsers and you will notice Google had to actively detect them and block the attempt because otherwise the app could spy on the login credentials without anyone noticing.
Instagram, Twitter, Facebook Messenger, TikTok.... the list goes on and on.
I am very confident that these companies are breaking GDPR laws left and right on an absolutely massive scale. They are spyware at this point.
That said, it's a huge UX failure that navigating between the web and an app is so broken. That doesn't mean that it's motivated to break the fundamental models of the web. Long term it does much more harm than good. How do you teach non-technical users good practices if developers circumvent these barriers anyway? "Trust us, we won't steal your Google account" is not exactly reassuring, but ok say that you trust a reputable app to do that. What happens when the user normalizes this behavior and a less reputable app does the same thing? Obviously many users will have no idea of the risk.
Continuing to enrich them, even by your reachability via their DM messengers, makes them more attractive to your friends and family.
Delete your Facebook and Instagram accounts. Stop giving them positive feedback (via continued usage and content donations) after they make clear choices to abuse you.
Edit: meant why Google wouldn’t do this. I guess what I really mean, is what are the chances they don’t do this?
Whether Chrome tracks how you use it...
Nearly every app, even "safe apps" including children-rated apps, allow access to an in app browser. Even when iOs has locked down all access to Safari, a parent has removed access to all the "apparent" unsafe sites, there are still ways to access the unfiltered internet inside of these safe apps.
How? Usually buried in App Settings. Almost all apps use some instance of an in-app browser to (lazily) reference thier privacy policies, EULAs, or TOCs. A buried link leads to a homepage, leads to an instagram link, leads to an unfiltered internet. Yes they are long, inefficient paths to reach the internet, but curious (or motivated) individuals or children will use almost any app to reach the internet. Even boring apps like MS Teams or adding a Gmail account to iOS mail uses a secret in-app browser.
This obviously presents a problem: should developers restrict any and all app access to in-app browsers, or leave policing to individuals/parents? An easy approach is to disable the in-app browser functionality in iOs, but obviously with grave cost to developers. At the same time, at what cost is in-app browser functionality being implemented.
I recall noodling with a huge interactive display on the side of a bus stop that had an embedded map, and surely enough the TOS link launched a browser, and from there you could use the Save As dialog to get to anything to execute
One of my favorite ones was in a museum where I was with a friend, and there was a PC. We were bored and wanted to play some flash game, but we only had access to a mouse, and clicking links inside the locked fullscreen browser. With enough clicks we got to google and managed to copy/paste letter by letter the name of a game site in the search field and play some games.
I'm sure there's like 100 different ways to break these bad Windows kiosks so that you'd eventually end up being able to access the accessibility settings, but it wasn't directly accessible to us.
Seriously, using the internet/computers should be treated with the same level of caution as grown-up scissors or fillet knives; powerful tools, but they need training to avoid hurting yourself with them. If this is what you're worried about, why are you even giving them a small computer in the first place? Your kids will always be more cunning than your security policy (a hard pill to swallow for HN users), so control their access to technology unless you're ready to have a serious sit-down discussion about the internet, personal privacy, and all that jazz. Put yourself in their shoes; if you're given a small black brick with an indeterminate number of capabilities, wouldn't your response be pushing it as far as it can go? I know that was my reaction when I was a kid, after buying a Pentium desktop at a garage sale.
All the mechanisms of the past that were geared for this no longer exist.
For example: Drive on the road, get to a toll, don't have a Transponder to pay the bill? No problem - just call a phone number. Uh, what if I don't have a cell? This literally never even occurred to them, there is no alternative way to pay the bill.
That's life today, and it applies to children as well. Want to go to some sports place that only caters to teens and above? Load this website on your phone and fill out an application. Don't have a phone? Borrow a friends phone.
And no, constant supervision is not an appropriate answer. Teens will want to research some things without their parents’ knowledge. That’s normal.
But it doesn’t mean that we should throw our hands in the air and make no effort to protect the majority of kids from the worst of the internet. Yes some bright sparks may find ways to circumvent the controls, but it at least makes it harder for them to send a disguised goatse link to their friends.
At one point, "tak[ing] part in the modern world" included smoking, and lots of kids wanted to do it. Just saying.
Children don't exist in a neat subservient bubble. They have peers, social pressures, see advertising, consume television and movies.
Our kid's school had everyone buy an iPad. Already, at pre-phone age, so much socialisation has moved into the digital space. FaceTime, iMessage, Roblox, etc.
I was going to say banning phones would be like a kid in the 80s without television. But really it would be like being a kid in the 80s who wasn't allowed to have a TV, listen to the radio, have a phone line, and wasn't allowed to socialise outside of school.
I pray you never have kids because from your other comments it seems like you had painfully low self esteem in school and now you've tricked yourself into believing that that's the norm.
Your child would be the only one at school with no phone and probably be pretty embarrassed about it.
Kids being embarrassed at school is unavoidable, being embarrassed is practically the job description of a teenager and younger students often have their own insecurities. There's an interesting debate as to whether these embarrassments are good or bad for us in the long run but we can side step all of that... not having access to a smartphone is important - it's important enough to warrant the slight amount of embarrassment.
There are many useful instances for the in-app browsers and I don't think they should be removed because of some bad actors. It's similar to how Android has had password managers making use of autofill tools via accessibility tools. Android was butchering that access, but luckily started adding some official autofill support.
I don't think removing capabilities in the favour of "safety" is usually the right approach in my opinion.
As an aside, is giving parents the option to disable in-app browsers removing a capability or adding one?
That would be an additional capability. But having to force a website to give specific apps permission to display them in-app seems like a removal. Some people are also suggesting removing in-app browsers which also seems silly.
Kiwi on Android is a Chromium fork that re-enables extensions on mobile. Works well for userscripts/extensions, though often times those UIs don't scale well to mobile.
[1]: https://apps.apple.com/us/app/torn-pda/id1510138514 [2]: https://play.google.com/store/apps/details?id=com.manuito.to...
One of my first freelance jobs was for that game, fixing some bug or other in the website. This must have been 15 years ago ish?
It's pretty neat how long this game has been going for and how they still keep hiring more devs to work on the site! I'm sure if you checked out the game now it would look a bit different from when you worked on it 15 years ago! Though I'm sure some elements would still be a bit similar.
The internet is the internet if you want to restrict what people can see on the internet the only solution is to not have access to it at all
Children aren't prisoners.
These days, the amount of utter idiocy is just unimaginable, "eternal september" style. You join some random online game discord and whoops half the talk is about rape fantasies, n-bombs and other kind of sickening behavior. Let it slip you're a girl and you'll get flooded with wiener pics, "cum tributes", disgusting fantasies, doxxing attempts, or flat out hate for standing in the way of someone. Go on Youtube, watch a couple of videos and your suggestions have antivaxx bullshit or "shocker videos". Games for children are filled with barely disguised pedos and "moderation" doesn't do shit. Not exactly an environment many people want to expose their children to.
It's been out there since the beginning; the problem is not the access to it, it's relationship with the internet. Back in the day, you were told to never give your real name online, now you're expected to type it into forms three times a week, while you have a public profile of all of your picture that anyone can look up while an algorithm serves it to the whole world. And yes, some of it is because kids are getting access to this world as toddlers when we weren't able to get there until early teens or the end of grade school at least. Kids need to be taught digital safety more than we need to continue the losing fight about securing access. Kids are smarter and more motivated than you are, they'll find a way around it.
I totally agree. When the reports of how school-issued Chromebooks will monitor texts from any phone plugged into them came out last week, I was tweeting about how we need to do more to teach kids opsec and digital safety/rights. I got some pushback from people who either think that it’s common sense stuff (it isn’t) or that the solution is to legislate something, but I live in reality and reality, as you say, means fhaf kids are smarter and more motivated and will find ways around things.
We need to teach them to protect themselves from prying eyes and how to circumvent the systems their own way.
We also need to stop holding people hostage to stuff they said/did on the internet as literal children, but that’s a separate issue.
Yes, it is absolutely worse in some ways now, not just because some stuff has become desensitized and de-rigeur, as well as the aforementioned algorithm, but let’s not create a hagiography around the halcyon days of “online” that never actually existed.
Like Bane, I grew up in this pit of darkness and was molded by it, and I have true love and affection for it, but like, this element has always been here. Always.
I don't think access to 4chan is going to fundamentally change who your kids are.
Unless they are under constant supervision, they will find a way to access what you're hiding from them. And if they are, well then you don't need technical blocks in the first place, do you?
I'm not telling not to worry about your kids' safety. I'm telling you not to worry about them dying from a lightning strike because they walk to school next to a 6-lane road full of drunk drivers every day. If they're going to get hurt, it won't be through the most complicated and least-likely way possible.
Before someone accuses me of being a conservative religious zealot as tends to happen when anyone denounces porn, I'll say that I'm far from a puritan and am extremely liberal in my social views. That said, I firmly believe that easy access porn is one of the worst things happening to the young men and women today. I (23) know many men around my age who suffer from chronic porn addictions to the point that it severely impacts their ability for form real relationships and median age of first exposure is getting lower and lower.
It's an absolutely crucial issue that no one seems to be talking about or taking seriously.
Regardless, it's a feedback loop. People who deal with depression/anxiety are more likely to develop drug addictions. A "normal" person can usually try a given drug once and be fine. Someone with a predisposition to addiction can't do the same.
Likewise a lot of people can casually use porn without much of an issue, but some people allow their consumption to develop into an addiction that negatively impact their life.
[0] - natural like how we crave sugar for our health, yet harmful like I eat candy all day
1. Do you find yourself craving it?
2. Do you continually feel the need to increase your intake? (i.e. developing a tolerance)
3. Would you be embarrassed if a like-minded friend knew about your habit?
4. If you were suddenly cut off from it for a few days, how would it make you feel?
Most men communities talk about it in one form or the other. However, most men communities on the internet are usually close in one form or another to the right politically.
It is a shame that any group which advocates men's issues tends to get labeled as right-wing or incelish, which then attracts those types and makes those labels a reality. And of course many were admitedly that way from the start.
Edit: And to add to this, being right or left leaning isn't inherently bad. And maybe this is my personal bias coming into play here, but I find that people are much quicker to associate right-leaning movements/communities as "bad" than they are left-leaning ones. Again I accept that could be personal bias and it isn't a hill I'd die on.
The incel label is a good example of how bad men are treated sometimes. If you treated poor people like this by saying they're involuntarly not rich and then proceeded to say that it's mostly their fault because they don't work enough, think they can just show up to work, do their job and become rich, shouldn't expect money to be given to them, most people would react by saying that you're wrong. And when some parts of the population have trouble having sex/companionship like some trans people, it's called discrimination. But the same rules don't apply to incels it semms.
As to whether or not that group is popular... this is an interesting one since the bonding factor is a lack of relationship success (which is closely related to, but not the same as, popularity) in the first place. But if you look at a lot of how the group that has gathered under that label interacts with the rest of the population... it's hard to say it's just something like mocking them for not being able to get laid. There are a lot of frankly offensive and violent theories pushed by people out there.
It's deeply ironic actually - "I'm not having sexual success, I'm going to start listening more to other men who also have the same problem, they're the ones who will be able to tell me about women." Back when it was a more ironic, non-violent "foreveralone" meme I was in the club... it wasn't increasing my exposure to men that eventually got me out of it.
If I were to accept (purely hypothetically) that it is significantly more difficult for many people to form relationships today then how do you suppose to show that this change is due to porn instead of, say, the prevalence of dating apps such as Tinder? Or any number of other factors including things like job stability, housing prices (and thus perceived security of living situation), and where people choose to spend their free time (for example going out on the town in the past versus perhaps doomscrolling twitter and watching netflix).
> Those are both very socially conservative viewpoints and I have yet to find scientific data (or anything else I'd consider even remotely reliable) that back either of them up, particularly the second one.
but then go on to yourself list many probably reasons why that's the case:
> how do you suppose to show that this change is due to porn instead of, say, the prevalence of dating apps such as Tinder? Or any number of other factors including things like job stability, housing prices (and thus perceived security of living situation), and where people choose to spend their free time (for example going out on the town in the past versus perhaps doomscrolling twitter and watching netflix).
Completing a study to prove GP's claims is a herculean effort that may not even be possible due to ethical concerns. (i.e. you'll have to take a person who has never been exposed to porn and then get them addicted, so you can see if it ruins their life).
Any claim without data should definitely be looked at skeptically (including in this case), but it's also important to remember that absence of evidence is not evidence of absence.
Also there's a lot of life experience out there of people who will tell you that they have a porn addiction that is causing them problems with relationships. One of my friends just got divorced from his wife of 20 years because he has developed a porn addiction and won't give it up or get any treatment (his wife is not ok with it).
I'm about as socially liberal as they come, (and I would never support a ban on porn nor pretty much anything, but that's a topic for another day), but I've seen and heard way too many anecdotes about the devastation that porn can have on a person to ignore it.
I don't think there's a big difference between a social conservative (who typically want to use government force to restrict access to "bad things") and someone who sides with liberty and tolerance but would advise friends and family not to do "bad thing."
Anecdotes are worth crap all, because people will bring up examples for either side thus cancelling each other out.
But your last sentence irked me.
If you side with liberty and tolerance and advise friends and family not to do "bad thing", they can say they appreciate your advice, tell you to GTFO and do it anyway.
Once government steps in and makes such things illegal, there are much bigger stakes at play.
To me, that is a big difference.
> I don't think there's a big difference between
But I meant:
> *I DO think there's a big difference between
It gives me a little bit more faith in humanity when I agree with a random stranger on the internet. :-)
I have the opposite life experience.
His wife not being okay with it is her right, but speaking personally I would never want to be in a relationship so fragile that one or both partners looking at legal pixels on a screen could compromise it.
I have been in relationships in a conservative universe where adult content was consumed in secret or restricted... and it is toxic. Not everyone is in the mood all the time and other outlets can be healthy when paired with honesty and moderation.
Way better for all to learn to be honest about their needs and curiosities without judgement. That is how stronger relationships are built. Happily married to my best friend for a decade.
> I don't think there's a big difference between a social conservative (who typically want to use government force to restrict access to "bad things") and someone who sides with liberty and tolerance but would advise friends and family not to do "bad thing."
The socially conservative part is baselessly attributing various ills to porn. Admittedly anyone can commit such an error in logical reasoning but (in my personal experience) this particular one exhibits a very high correlation with being socially conservative.
> I don't think there's a big difference between
But I meant:
> I do think there's a big difference between
> I firmly believe that easy access porn is one of the worst things happening to the young men and women today. I (23) know many men around my age who suffer from chronic porn addictions to the point that it severely impacts their ability for form real relationships and median age of first exposure is getting lower and lower.
Porn(at least in it's current, easily accessible, form) didn't exist in the past. Since you claim that porn use severely impacts the ability to form real relationships it follows naturally that in the past it must have been easier. Since you don't mention any factors that impacted the ability to form real relationships in the past it follows quite directly that your claim is also that it was easier to form real relationships in the past.
In addition if it wasn't easier in the past how can you even know porn use is to blame? Essentially a variable is introduced which you claim has an extreme impact, yet you also don't claim there is change between pre- and post introduction. That makes no sense. Either it has an extreme impact which means it should be trivial to see a pre- and post introduction difference, unless there are other extreme factors that weigh in the other direction. Or there is no (extreme) impact.
> but then in the next breath make the assumptions that difficulty forming relationships today is significantly greater than in the past
The implication being that I made the claim that it was broadly more difficult for most people today. I didn't realize that me adding "everyone" would so drastically change the meaning of their sentence. Please give me your interpretation of that if it isn't basically what I said.
Am I crazy? I say that people with chronic porn addictions have a hard time forming relationships and all of a sudden I'm accused of making blanket statements about how difficult it is for people to form relationships today compared to the past.
A pedant would say that a extreme impact on a subset of a group means there is also a significant impact on the average of the entire group. But that's not the point.
This statement calls back to your claim that (excessive) porn use severely impacts their ability form relationships. It's not a blanket statement you now make it out to be. Someone doesn't need to repeat back to you word for word the entire context of the conversation.
Well originally you used wording that would imply a significant subset of the population. But even ignoring that it remains a completely baseless claim. How are you eliminating all of the other potential explanations that exist? And how are you arriving at the conclusion that the porn addiction is the cause of the problem as opposed to one of the effects?
> I firmly believe that easy access porn is one of the worst things happening to the young men and women today.
"one of the worst things happening" is clear enough on its own. "young men and women" refers to the population at large. "today" is in contrast to historically
> I (23) know many men around my age who suffer from chronic porn addictions to the point that it severely impacts their ability for form real relationships
"many men" is not describing a rare phenomenon. "to the point that it severely impacts" is a clear attribution of cause and effect.
> median age of first exposure is getting lower and lower
Obvious meaning in context: things are getting worse over time.
> it exposes your implicit biases more than it does anything about myself
No, you are resorting to disingenuous semantic games because I pointed out the inconsistencies in what you wrote. Namely that you have provided absolutely no evidence for the things you are claiming and I see no obvious reason that they should be the case.
People who have difficulty forming intimate relationships will often turn to habitual pornography viewing.
Isn't addicting content a force that's trying to manipulate them? Porn, certain kinds of games, online gambling, etc can all get their hooks in someone. Prevention is better than having to fight the addiction in the first place, is it not?
-Targeting- children with content for profit should be banned, regardless of content. If the content is neutral and presented to all the same way then they get to choose to put in the work to find what they want to consume. When it is not neutral then it is the job of a parent to help tip the scales back to neutral with conversation or partially supervised device use.
Nudity for instance is only taboo in some countries, where others are whatever about it and will see women topless at the beach. Trying to censor things or target things is what does the most harm and creates closeted behavior IMO.
News flash to parents... when your kid is old enough to be horny they -will- find an outlet to see nudity be it in person or on a screen. On a screen is probably the safer default.
Think of the addict is a new one, but I am automatically suspicious any time someone cites child protection.
Last time I checked, WKWebView will follow the parental control settings set on the device.
I'm currently going through HTB Academy and once you mentioned unsecured in-app browsers, the first thing I thought of was either a Web Shell[2], or better yet, directing the in-app browser to a malicious website to download additional software to better exploit the phone. If the in-app browsers aren't filtering explicit content, I have to assume they aren't filter malicious content either.
If this isn't already a well-known route of exploitation, I'm interested to see how that might change in the near future. It sounds surprisingly easy to exploit, provided you can get momentary physical (remote?) access to the phone for a short time.
[1] https://www.youtube.com/watch?v=1UfNlRe-goY [2] https://en.wikipedia.org/wiki/Web_shell
I don’t think this can be overstated. How many people tell you stories of watching signal-scrambled porn on TV when their parents are asleep? How many of us waited until our parents are asleep to play video game late at night? How many millions covertly downloaded Napster/Kazaa/etc. and downloaded 30 versions of a song before they finally got the one they wanted?
Being “motivated” as a kid or a teen is a low bar.
"2.5.6 Apps that browse the web must use the appropriate WebKit framework and WebKit Javascript."
If apps can use their own in app browser, why can't say Brave for example, create an app that does very little, except it browses the web with its own in app browser?
Not if you never have/ don't use them.
WKWebView can indeed be used to spy on users - clicks can be intercepted, URLs sniffed, and custom JS injected (including a way to call back to the app’s runtime via a WebKit message passing mechanism). Considering all other iOS browsers (ok maybe some still run UIWebView) have been made using this component (because App Store reviews enforce this), it’s clear that it has to provide extensive control over displayed contents.
But it hasn’t been enforced yet for big apps like Yelp and Instagram.
In app browsers that display content unrelated to the app itself (like links from creators) serve zero purpose to the user and offer a horrible user experience. So why is the browser in-app then? I thought the answer was obvious: to track you.
Maybe some people prefer in-app browsers?
This of course is a different case for corporations with a dedicated legal team.
And second the browser manufacturer (usually) doesn’t make any money by tracking their users. They provide them with a tool, a browser.
There is the browser Brave, that replaces ads on websites (and makes some profit with that), and there are some serious legal issues coming with that.
The right you seem to be claiming is “you can’t render my website in your app if I don’t like your app”, and that’s not how it works.
I think we can see whats really going on here. Any chance to drop or mention Brave, after not being active for weeks or months, suddenly congregate to push Brave browser
Dang really needs to do something about this type of astroturfing
And why are you suggesting i'm an "inactive user"?
Don't they? Google, Apple and Microsoft are all in the ads business.
They do it in some way, but not directly on the browser. More with settings sync, their search engines, ...
The thing about the law is, that some specific things are forbidden. And if you achieve the same goal, in another legal way, it is fine.
For example saving taxes: If you make a fraudulent report and save 1000$ this is illegal. But if you find a way to save 1000$ on taxes, by declaring something legal, the same 1000$ are fine. But in both cases you save exactly the same amount.
User agents are expected to be empowered to transform the data they receive to suit the rendering requirements of the end user. Having a third party perform part of the transformation by supplying supplementary code executed by the user agent doesn't change anything.
Coincidentally the only apps I have that don't use the OS supplied web view are from Meta.
The allegation isn't that Instagram can do this but that they are.
Settings > Advanced > "Open links in apps"
https://support.mozilla.org/en-US/kb/set-firefox-android-ope...
Not sure if open-links-in-apps is comparable to that, never tried it (I rather prefer multitasking than doing it from within the app anyway).
However, the developers do have options to incorporate SFSafariViewController since iOS9.0 and that gives the user full Safari experience with Autofill and everything and without giving access to its contents to the app developer.
It actually makes a lot of sense from users perspective when the context is that the app temporary needs to take you to a webpage for something with the intention of you going back to the app. With SFSafariViewController this is done securely and with good user experience but unfortunately most apps business model revolves around tracking everything you do and as a result, most developers would use UIWebView/WKWebView instead of SFSafariViewController just to be able to track you.
The UIWebView/WKWebView has legitimate uses like letting you sign in from a web interface and transfer the session into the app but I kind of feel like we would be better off to depreciate it in favour of using alternative methods to do the web/app connection and improve privacy significantly.
Personally, I would never do anything sensitive from within a browser that is in an app. It looks like very obvious attack vector to me.
I realize that doesn't address the appeal FOR USERS, but it is why we did it as developers.
My browser would get littered with old tabs and coming back to the app for a small click became a hassle
On the off-chance I do want to save a link, I know I can just open it in my browser anyway
So I much prefer in-app browsers as a user and a developer
AFAIK iOS supports something similar, but only for authentication use cases.
What mobile browsers actually have tabs that look like tabs? Honest question, I've only ever used firefox on android. If the others handle tabs anything like firefox does tabs are way more intuitive on a PC.
It's like putting a toilet in every room because people can't find the bathroom when maybe the bathroom shouldn't have been hidden down in a hatch under a rug. But you can't easily rebuild your house, and now there's shit everywhere, so what is one to do?
This opens Safari, but makes it appear like it's an in-app browser. Best of both.
1. Nothing you visit gets saved in your history. So many times I'm looking through my history thinking "I could have sworn I read an article about this..." only to eventually discover (if I'm lucky) that it was in Twitter's stupid in-app browser. But oh well, never going to find that article again! The irony of the APP knowing everything you visit but you never getting to remember what you visited.
2. All your logins are gone! I actually pay a bunch of stupid newspapers just to click on links in Twitter and STILL be told I can't read the article because of course I'm not logged-in in the in-app browser. UGH.
You could imagine a world where iOS tried to balance the desire of an app to not bounce you out with a more "integrated experience" by providing an "in-app" browser that was completely controlled by the OS, modifying your history, keeping you logged in, running out of process, and being able to be "adopted" as a tab in Safari, but instead they just made "SFSafariViewController" which does none of these things and instead just makes it really really easy for all apps to incorporate these infuriating in-app browsers.
Actually, SFSafariViewController acts as a full Safari without giving any ability to the developer to inject scripts or receive data to track you(except for ad taps through Private Click Measurement). It's actually a nice solution, it shares cookies(non-session ones) with Safari.
For example, write only access to history will also mean SEO-consultant-type people paying app developers to write certain websites to the users history. When Safari does suggestions on the address bar, browsing history is a major source.
> In iOS 9 and 10, it shares cookies and other website data with Safari.
I was also also disappointed that they removed it in iOS 11. But it's still a step-up from other even more horrible in-app browsers like in Instagram, which are implemented with WKWebView. I refuse to read anything in those in-app browsers; I always manually open them in Safari.
> If your app lets users view websites from anywhere on the Internet, use the SFSafariViewController class. If your app customizes, interacts with, or controls the display of web content, use the WKWebView class.
I'm quoting straight from the documentation. https://developer.apple.com/documentation/safariservices/sfs...
You get a bump in engagement and time spent in the app at the cost of UX.
I think all of the various bad things people talk about here must happen sometimes, but it's mostly just retention I'd guess.
Is there any way to turn that damn functionality off? I can’t tell you how many times I’ve been navigating some newfangled web UI and had a swipe go “back”.
That and disabling pinch to zoom backing out to the tabs UI. I wanna zoom out dammit. Is hitting a back or tab button really so hard that you have to break basic pan/zoom mechanics?!
I know I’m putting off “old man yells at cloud” vibes here, but come on
Much worse than the tracking and spying is how Meta does everything to make people addicted to their slot-machine like services and thereby destroying their mental health. Especially harmful for kids.
The world would be a much better place without it.
and it forgets everything when you close it.
[1] https://www.businessinsider.com/well-these-new-zuckerberg-im...
lol. and this is why companies can be hesitant to run bug bounty programs. it's not a place to complain about things you don't like. Meta/instagram has made a design decision here. just because you don't like it, doesn't mean it's a vulnerability.
Personal user browsing or communications leaking in plain text to private companies without explicit and obvious user consent puts users at risk, and is a vulnerability. It just so happens to be one arising from malicious profit seeking behavior that happens to be the status quo.
Not having https was once the status quo, and a boon for corporate spying, but we call that a vulnerability now because the abuses became too big too ignore.
Consumers have a payment-avoiding behaviour as a status quo.
Users are given the choice to accept risks that are buried on page 7 of privacy policies only a lawyer could understand the tricks in.
Services knowingly endangering unknowing users for money should be like cigarettes and be forced to say on the signup page in big bold text they can and will sell user data to anyone, including law enforcement.
Users largely think free services are like public libraries and do not default to expecting they are being exploited for money. Element, Wikipedia, and duckduckgo exist for free without selling user data so it is not a given that exploitation is always present in free services.
They were served a warrant. I'm no friend of Facebook/Meta, but any company served a warrant is going to turn over what they have.
Even Signal or Google/Apple could ship a bad Signal app update to targeted devices to dump convos if ordered. If you use Matrix with a client from an F-Droid build or a reproducible build from debian etc, then the Matrix developers literally could not comply with orders to obtain your plaintext content.
Technical Vuln or Business Vuln?
To completely hijack the discussion here, I believe that Apple is actually one of the strongest forces for anti-privacy in the world, because of their long-term, successful push for the convention of app > website (not fully supporting PWAs, disallowing web push, etc). A website may spy on you, but it can only do so in ways constrained by the browser, which has to serve many "masters". Mobile apps are completely unconstrained in their spying, and in-app browsers are just the logical extension of that pattern.
Thanks largely to Apple, we've conditioned ourselves to expecting that you can't have good mobile UX without a mobile-native application, and it's hard to imagine ever escaping back into the relatively open web now that we're this far down this path. Most people will never question the privacy implications of installing the Facebook app, and most of Apple's privacy-directed efforts on iOS are basically playing walled-garden whack-a-mole on problems that are better solved at a societal level with web browser standards.
Yes, it's quite likely that I'm scapegoating here, but it's the way I see it.
While you're right that the Facebook/Instagram app can spy on links opened within the app, it can't plant cookies in your web browser - so those go both ways.
Safari View Controller keeps the users cookies from Safari and prevents this behavior. For most apps, keeping users logged in without leaving the app is preferred, so they give up the ability to inspect the contents of the page.
It does not, because apps decided to abuse it for fingerprinting.
Which are increasingly user hostile, if not down right impossible to view on mobile. Go try using Reddit or Twitter on your Mobile browser.
https://play.google.com/store/apps/details?id=com.andrewshu....
For those of us who can't go to the bathroom without reddit.
What I miss is the multi-container extension on fennec/firefox mobile. I keep using those sites in incognito mode but that mean I can only use one at a time.
Within 3 days of registering a new account they will prompt you 'for a phone number, because we detected security issues with your usage'. Don't know how having a phone number helps with security issues like that, but again -user hostile-.
I'm not creating a Twitter account just to read their public site, because they are user hostile and privacy invasive.
Reddit on the other hand is absolutely hostile and basically none of what I said above is true of their mobile web UI. I refuse to install their app simply out of spite for how aggressively they nag for me to use it. I’ve said no like 500 times at this point, will I change my mind on the 501st prompt?
I wonder if it can solve this problem since reddit/twitter/tiktok won't stop.
Those URLs also mask origination when they point to other sites, so that site logs don't provide any real specific data on where traffic to them is coming from.
The most Internet/user hostile era ever is probably going on right now. Will be interesting to see where this all goes.
Having said that I find Twitter to be quite usable in a mobile browser, it's one of the few that isn't awful
Facebook is by far the worst, image posts overlap the edges of the screen, terrible for anything with text overlaying[1]. You can use the mobile version instead but then you can't use FB messenger at all
[1] e.g. https://img.imgy.org/-7p8.jpg
Nothing's stopping you. There is no such message on old.reddit.com.
This gets amplified when using ad/tracker blockers at DNS level (NextDNS).
You have to give apps permission to get your contacts, right?
Does this script injection break Apple's ToS?
I thought Apple required Safari/Webkit for all in-app browsers?
Zuckerberg has no shame.
PS. I hate in-app browsers. They don't sync with my main browser states such as authenticated sessions.
Doesn't apply to special companies.
They are still using Safari/Webkit, but just injecting a script into every page.
Seems like that's probably a good thing :)
Under what circums do you want this?
Click on "Sign In/Up with Google". Opens in app browser. Not logged in even though I'm with Safari. Type email. Type password. Get password wrong. Type password again. Get text/email with 2FA code. Every single time.
Or Gmail app. Click link. Open in-app browser. Not logged in.
And this is exactly why Apple gives them their own cookie jar. The alternative would be [more of] a security nightmare.
> Comparing this to what happens when using a normal browser, or in this case, Telegram, which uses the recommended SFSafariViewController:
> As you can see, a regular browser, or SFSafariViewController doesn’t run any JS code. SFSafariViewController is a great way for app developers to show third party web content to the user, without them leaving your app, while still preserving the privacy and comfort for the user.
Custom Tabs always have a title bar and a small writing "Powered by <browser>" at the end of the menu.
Ive been told by a very destinguished person (Judge) that "if its too good to be true then its not (i.e. something expensive is rediculously cheap, its obviously stolen), and anyone with a highschool education +, could determine that."
why would a judge say that if its not true = must be true
when thats the way the law sees it, then its kind of hard to argue. "nothing in life is free"