I do not update to the latest-and-greatest when it first comes out. I typically wait a bit for everyone else to 'beta test' it for me.
If my bank is saying 'no, seriously, go fix this' maybe I should change my stance.
Anybody can put code out there that you'll run on your device?
2) The reason is, they know that the moment they allow all the stuff you're talking about, we'll all be in the wild West again, with God knows what fucking version of Chrome being run, and it will be a nightmare to support, and a nightmare environment in which to protect privacy and security
3) Users have conclusively voted for it to be this way. We know it's this way and we're still buying iPhones instead of Android. What's annoying to me is that people like you, a lot of people, are still unable to summon any respect for the legitimacy of THAT choice. You can only think of the choice that YOU want.
That's like saying that every voter in a democracy approves of every policy implemented by the politician they voted for (especially if they re-elect that politician). The world is not as simple as that, and I think the general term for this erroneous line of thinking is "the fallacy of division".
I'm pretty confident that you'll need to interview a lot of iphone users from the general population before finding one that even knows about browser implementation internals in iOS, let alone who cares enough to have voted with their wallet for this particular reason.
So no, users have not voted conclusively for it to be that way.
I think Apple fell down the design flaw that Microsoft went down of bundling the browser so tightly into the OS.
As ios16 isn't out yet, I don't expect the features to be functional. They may not even ship full functionality for the .0 release, although they have added small allusions and options here and there.
They haven't talked about it much, although I expect we'll see a bigger announcement in the next few weeks.
I personally would prefer if I could make the choice to do this, but I can also see the issues with that from Apple's perspective.
With Firefox, your extensions like adblockers and NoScript also run in webviews.
Well why didn't you say so this sounds great
I bought my phone, I own it. I know that disabling JS breaks some things, but I don't want random fly-by-night app developers injecting code into my web browser.
It is great.
It's up to the app developer to choose which of the two implementations to use.
[1] Though some apps still used to (or still do?) hard-code Chrome there.
A webview can't, and in my personal view, shouldn't, be under the control of the user. It's a tool for the developer. If you want to be safe in navigating to your links, you should paste it into a program you trust.
No, it doesn't. There's an additional API ("custom tab") that allows an app to launch any browser that supports that API in a reduced UI/webview-like mode, but that's not the same thing as a classic webview, which on Android is always powered by Chrome/Blink.
but "antivirus" for iOS is typically focused on network-side interception and blocking
Was there any additional context or comments provided in the email? Both the initial post and this comment are pretty vague on what was communicated beyond the phrase, "Update your iPhone".
"Update your iOS software and Safari® browser to keep your device(s) secure
We noticed the iOS software version you’re using on your mobile device and/or the Safari browser on your computer may need to be updated. <Instructions on how to update>"
but I wonder if I’m becoming like you or others, where there was some other arbitrary technological progress and lack of interest in trends and suddenly 10 years went by and people are like “what is that device why are you using that”
An update might break the feature I need, or change something my workflow depends on (more common). I'd rather wait for blog posts with workarounds/fixes. As it tends to be extremely time consuming to fix it myself (as it's often outside my domain).
Sounds pretty serious, has active exploitation like this happened before in the Apple ecosystem or is this like most zerodays; edge cases and state level exploits that don't target broadly?
From Apple's Lockdown site, it's hard to tell the extent of what is locked down.
> Web browsing: Certain complex web technologies, like just-in-time (JIT) JavaScript compilation, are disabled unless the user excludes a trusted site from Lockdown Mode
This is allegedly the fix for this exploit for webkit: https://github.com/WebKit/WebKit/pull/3023, it appears to at least somewhat related to the JIT, but I don't know enough about the exploit, or webkit to make that determination.
Either way its always a good idea to keep things updated!
Apple has today shared some information in relation to a security issue. This has the potential to allow others to gain access to information on your device if security updates are not up to date.
We are contacting you as you have previously accessed your Starling account from an iOS device. We would strongly recommend that you ensure the security updates on your device are up to date to ensure that your device and information remains secure.
To update: Go to your device Settings > General, then tap Software Update.
If you are in need of further help updating your device, head to Apple Support.
...and my phone is up to date (15.6.1).
#fail
But...
If someone is using BoA and they have an issue related to this, are they going to blame BoA or are they going to blame Apple?