Now, again, OS vendors are doing a ton to try to fix webviews...but the model is just busted. The attack surface area isn't just the web platform, it's every API the host app bolts on or intercepts. Disaster in the making.
More to the point: if y'all wanna be a browser, *make a browser*. Stop freeloading and breaking a huge fraction of the platform for developers.
-
-
And *until* then, stop MITM-ing user traffic!!!!
-
At an absolute, bottom-of-the barrel security minimum, CCT out when you detect an out of date WebView. For the love of every thing good, at *least* don't be complicit in that shit.
- 1 more reply
New conversation -
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.
& Web Standards TL; Blink API OWNER
Named PWAs w/
DMs open. Tweets my own; press@google.com for official comms.