Google and Mozilla don't like Apple's new iOS browser rules
arstechnica.com
arstechnica.com
Of course we are still waiting to see if the EU accepts Apple's proposal. Anyone that's ever submitted an app for review (to Apple or Google, but let's be honest more-so for Apple) know this feeling of uncertainty and it's a bit a schadenfreude in that for sure. As much as I like Apple's products I can't but hope they get a few bad "reviewers".
[1] https://9to5mac.com/2024/01/26/ios-17-app-stores-and-more-ip...
Personally I highly doubt this trick will work in court; moreso than any other Apple product, iPad and iPhone are running the same software and the stores have enough overlap that you can find iPhone apps in the iPad store.
Or perhaps I'm misreading you and your post is just in agreement?
I don't think this is some big gotcha - this has always been clear.
Seems like there's just one rule they don't like, that it's EU only. Which is fair enough.
Personally, I don't see why this is the hill Apple's dying on. They seem to have put in a fair amount of effort into creating a problem and APIs to allow for other browser engines to exist as peers to Safari (allowing JIT, multi-process, hooks into Lockdown Mode etc), but then restricted that all to the EU. This one seems more ideological than financial (like the other DMA-forced additions Apple is doing).
But really - its not really clear to me what benefits users get from this. Safari (on iOS or Mac) hasn't stagnated and is a highly performing browser, better than Chrome and Firefox in some regards. It supports some APIs first that others lag on, while it lags on others. I am a web developer, and I really do not agree with any claims that Safari is somehow worse than other browsers.
Meanwhile, people are shipping 'new web browsers', that users seem to like, by using the webkit engine under the hood. UI, features, sync, etc are what actually matters to users.
The more I look at this, the more I am convinced that Apple is trying to use the EU as a testbed before agreeing to apply these rules in more places. Third parties can make a browser, but they'll do it on Apple's terms - in a safe way, that doesn't eventually become a nightmare to maintain. Crucially, access to hardware will be mediated through API's and certain things will probably never be supported because of security or privacy concerns - so don't bother asking.
Glares in the general direction of WebUSB...
I really want to use a browser with uBlock Origin and NoScript, because the web is a fucking nightmare without them. To my knowledge, Firefox is the only browser that supports those on mobile, but it's Android-only, and I'm currently on iOS. Being able to use "real" Firefox on iOS would let me use the extensions I want.
Personally I hate web apps, so I am fine with Safari.
I'm not sure I'd agree entirely with this, and regardless you're beholden to Apple on whether they will deem it necessary to add standards. They prevented web notifications for a long time so PWAs couldn't send notifications, just to push you to their app store.
I'll let you connect the dots as to why Apple doesn't want other browsers to be able to beat Safari outside the EU.
One, as long as it’s a land with the rule of law, it can’t. Two, this would constitute starting a trade war over…browser engines. Good luck getting people who depend on popular votes to back you up on that.
It's so insane you'd be forgiven for forgetting that it already happened (with bipartisan political support): https://en.wikipedia.org/wiki/United_States_v._Microsoft_Cor....
And to the point of the discussion, there are no "limits" to what jurisdiction governments have. Governments--the United States especially but many others--does it all the time, especially as concerns financial matters. Many countries have declared that they have jurisdiction over crimes against humanity committed any time, anywhere, by anyone. China has penalized American companies for activities involving Americans in America.
However the EU probably has self-imposed limits (or imposed by the member states) and as a practical matter only large or powerful states can get away with it.
A more analogues example would be e.g. if the EU would have said "Hey Adobe, if you launch this feature in the US, you can't do business in the EU".
> China has penalized American companies for activities involving Americans in America.
What are you referring to?
> Many countries have declared that they have jurisdiction over crimes against humanity committed any time, anywhere, by anyone.
This is a whole different topic, stop moving the goal posts.
Apart from financial crimes the US imposes US law on foreign companies all the time--e.g. companies that do business with embargoed countries.
Also the US considers things like "a transaction was conducted in dollars" as a hook for US jurisdiction.
(Also, guess what happens if you copy Hollywood movies a bit too much? Jurisdiction goes out of the window... https://en.wikipedia.org/wiki/Kim_Dotcom#High_Court )
I kind of see the EU legislation similar to California. After CA passes laws, eventually, the other states do as well. I'd imagine that the EU hopes that their legislation will influence others at some point too.
Some CA laws only have an effect outside California because the state has so many people (with money). So if you are designing a physical product to sell, it is cheaper to just make one that complies with California.
There are non-physical product laws as well. CA was a leader on medicinal cannabis, minimum wage, etc
Ex: China, Russia, KSA, EU? No, they cannot dictate rules world-wide. Each market can dictate market requirements but they can't have them imposed in other jurisdictions they have no control over.
Others have already noted the risk of a trade war following from that, but that doesn't preclude the EU/US/China/.. from still doing it. It's just a matter of how important they think the rule is.
It’s an entirely expected outcome for wanting to enact one-of-a-kind laws that force a foreign company into doing something they’ve obviously wanted to avoid.
Microsoft is making their compliance with the DMA an option the user could pick during the OOBE. I assume Apple will use the region choice at the start of configuring iOS to do the same thing.
I can only think of one device maker that actively tries to region check the originating IP for legal compliance and that's Nintendo (who just start tracking you more if you're an EU citizen in say, the US.)
Nope! New countryd process uses Apple ID address, course-level location/carrier country and device region to determine DMA region locking, unfortuantely.
If one thing's been clear though the Apple DMA stuff so far, it's that Apple will go to lengths to maintain their status quo in all aspects.
https://9to5mac.com/2023/04/25/ios-16-restrict-features-base...
https://9to5mac.com/2024/01/25/apple-check-iphone-eligible-s...
Wouldn't be surprised if that's going to get smacked down - tying "requiring an Apple ID" to being able to exercise your rights doesn't seem like something the EU would be happy with, considering the GDPR 'n such.
(I genuinely believe both of those statements, and don’t mean either of them as trolling. Boy howdy, does it ever have the same end result though.)
Only if they ensure that they have no EU-based users [0]. So yeah, unless you actively block "data subjects who are in the Union", it does apply to someone living in and running a server in the US. It's part of what makes GDPR so great for us citizens, the beauty that is the Brussels effect.
[0] Article 3(2) of the GDPR
Imagine me saying a US law applies to someone in Prague because the US law said it did. I’d be rightfully laughed at.
No, you wouldn't be laughed at for stating that fact, nor would that be "rightful".
I like the GDPR. For the most part, I think it's a good law. It has problems, like it's impossible to comply fully with GDPR and HIPAA at the same time, but I'm glad a major government is pushing so hard for something I support.
And yet I still give it the side-eye for claiming jurisdiction over non-EU citizens living and working in non-EU countries without having a realworld presence in the EU.
No, not to "everyone", only processors handling data that is covered as part of GDPR, which again, you are free to exclude if you desire.
So, to stay with US laws, what about, as one of a few examples, FATCA [0] in the case of US citizens being served by, e.g., EU financial institutions? Very much comparable to GDPR and non-EU processors handling data covered by GDPR. Both apply outside their government of origin for processors handling something connected to the government's citizenry, and both do not "apply to everyone around the globe"; simply don't handle US financials/EU data.
Again, GDPR is not unique in regard to extraterritoriality, nor is this something only the EU engages in. It is accepted, established and has been part of US legislation for an extended period prior to GDPR. And, just like with GDPR, FATCA applying beyond US based institutions is a positive attribute of that legislation, neither would work if only applicable within their respective territory.
[0] https://www.law.cornell.edu/uscode/text/26/1471 https://www.law.cornell.edu/uscode/text/26/1472 https://www.law.cornell.edu/uscode/text/26/1473 https://www.law.cornell.edu/uscode/text/26/1474
That happens all the time. E.g., US tax laws.
For instance, financial institutions in Europe have special reporting and KYC requirements for the accounts of American citizens, even if they're long-term residents in European countries and dual-citizens, because of FATCA.
Extraterritoriality is not unique to the GDPR and the EU, nor is it new.
Usually they just straight up ban americans from registering banking services.
That shift happened after the huge fine they got because of that.
My personal bet: Apple will relent and roll out "browser engine choice" globally within 1-2 years.
They'll argue some customer beneficial reasons for it, but it all just comes down to Apple wanting control; it's what permeates every component of their software ecosystem, especially on iDevices; they control app installs, they control what kinds of apps can and can't exist on the iDevices and so on and so forth. This is the company that famously recommended anyone who wanted to view NSFW content to "buy an Android"; it's safe to assume that the wish for control is the endgoal in and of itself, given Apples clear desire to play a byzantine morality police in other areas.
Apple is the most textbook definition of a platform gatekeeper.
The battery life/heat thing is big though, Safari is much better in that category and it seems like that property extends to WebKit browsers on Linux too in my limited trials with GNOME Web, so it’s not just a case of Apple using private APIs to gain an advantage or whatever. It’s a difference in architecture and likely dev culture — efficiency simply doesn’t get prioritized to the same extent by the dev teams of the other two engines. With Blink especially there seems to be more interest in coming up with APIs to give devs access to the contents of the user’s fridge or whathaveyou.
Now this is a true gem.
security. browsers are famous for escaping their sandbox.
this is from November 2023: https://www.theverge.com/2023/11/30/23982296/google-chrome-b...
To give an example: A single Safari engine bug could compromise all iPhones, but if the market share was say 50/50 with Chrome, then the impact of a security vulnerability would now be halved.
Online dev world is so wonderful, cannot wait when money would be fully digital. So many opportunities
Completely unsurprising that Apple is not going to throw in the towel when a single region mandates necessary changes.
Safari N/KN anyone??
If this were found to be a violation of DMA, they could fine them for absurd amounts of money. If Apple paid the fines but didn't fix the underlying issue, they'd be fined even more. After suffient repeat offenses the EU would force Apple to make structural changes such as break up their businesses. If Apple chose to not pay the fines, break up, etc, they would need to stop operating in the EU, or run the risks of their assets being seized, their employees arrested, etc.
It's only at the point where Apple left the EU that there's no more leverage on them. And this is Apple, they're not going to leave a market with money. They didn't even leave China.
(But the real key question is whether there's a reasonable interpretation of the DMA where the companies need to comply even outside of the EU.)
They already do something analogous for taxes purposes.
But the EU can definitely take into account the entirety of Apple when deciding what to do. For example, when Apple gets fined for violating the DMA, the maximum penalties are going to be based on their global revenue, not just the EU revenue going through their Irish subsidiary.
If you're proposing a fully independent public company rather than a subsidiary of Apple, it's true that the separate company wouldn't actually be able to fix any of their possible DMA violations. But that just means they'd not be complying, not that they wouldn't be breaking the law or that they're somehow immune.
Just like the US couldn’t have jurisdiction over a company that only operates in the EU.
Apple could easily not make a subsidiary. But make it a fully independent legal entity that resales in the EU.
Apple can choose not to operate in the EU. That's a totally legit and acceptable outcome. But that means they have to actually give up that revenue. Any attempt at laundering it will just mean that the penalties apply to whatever entity they try to use for the regulatory evasion.
(Or I guess shrink their presence to do small that the DMA no longer applies. But again, this is Apple. They'll rather hand out user data to the Chinese government than leave China and all their juicy money.)
If the EC decides to interpret the rules as requiring compliance globally rather than just within the EU, and the courts were to uphold it, it would be irrelevant that Apple's sales are being done via some shell company. If anything, it would probably be considered worse, since it'd be a clear attempt at circumventing the law. The products that the shell company would be selling would be found illegal, and one way or other the operation would stop. And the effect would be that Apple would have left the EU.
If your plan were actually a thing, every American company would already be doing it just to shield themselves against GDPR (which has fines based on global revenue, not EU revenue). But they don't do it, because it wouldn't work.
What they aren't doing is trying your plan of creating a shell company to break the laws on their behalf.
Not clear though whether they have any interest in doing that.
https://www.nato.int/docu/review/articles/2023/07/03/defence...
https://thehill.com/opinion/healthcare/529049-america-is-sub...
> considering it’s the GDP of all these evil tech companies that’s paying for their national security and health care
I find the logic of the article you linked highly questionable.
> Certainly it is more difficult than what drug companies do now, which is to set a high U.S. price, assuring profitability, no matter how thin the profit margin on European sales.
So there is a profit margin, right? Otherwise drug companies wouldn't sell their products in Europe. It seems that this article and the MFN legislation is worried about the high drug prices in the US. Fair enough, I suppose, but how exactly is that "subsidizing the European health system"?
> The goal of the MFN concept is to deliver fair prices to Americans without diminishing drug company profits.
So you are specifically protecting the drug companies' massive *profits*. Not research or production costs, profits.
> Since the introduction of the Medicare Part D prescription drug benefit, Medicare has been prohibited by law from using its volume-purchasing power to negotiate prices for the drugs it covers, while government-run European health authorities have used such volume-purchasing power to obtain drastically low prices.
That seems very dumb.