This difference runs deep, but the most important thing to understand is that users choose browsers. That's an intentional preference that should mean something.
-
-
Attacks against WebViews aren't just attacks against the pages, they're attacks against *the host app*. Everything you trusted it with.
Show this thread -
Now, again, OS vendors are doing a ton to try to fix webviews...but the model is just busted. The attack surface area isn't just the web platform, it's every API the host app bolts on or intercepts. Disaster in the making.
Show this thread -
WebViews for non-app content are a choice that apps make. Other, better, more respectful and secure choices are available to them. Apps that insist on not taking you out to your browser when you tap on links, but also do not take advantage of CCT/SafariViewController are *bad*.
Show this thread -
Cannot stress this enough: the only reason this happens is because apps are jealous of your time. They build these upside-down "browsers" because they don't want you to go to your real default browser. They want to keep you in-app. They *worked* to break this.
Show this thread -
The default behavior for navigation intents is to launch your default browser. Many apps felt this wasn't in their interest, so they put your privacy and security at risk. Demanding they adopt CCT is the *least* we can ask.
Show this thread -
So when companies start taking about taking privacy seriously but still default hundreds of millions of users to this dog's breakfast of a broken, privacy violating web experience, don't believe a word of it.
Show this thread
End of conversation
New conversation -
-
-
What does the Facebook app do on Android? (I don’t have a device to check on.)
-
This Tweet is unavailable.
- 1 more reply
New conversation -
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.
& Web Standards TL; Blink API OWNER
Named PWAs w/
DMs open. Tweets my own; press@google.com for official comms.