-
-
Replying to @slightlylate
How do you get trusted path when you've only got one button and limited visual real estate?
1 reply 0 retweets 0 likes -
Replying to @mvsamuel
"trusted path"? And why is this friction there *at all*? Related:https://web.dev/get-installed-related-apps/ …
2 replies 0 retweets 1 like -
Replying to @slightlylate
Sorry for jargoning. "Trusted path" lets the user know which part of a system they're interacting with. E.g., Ctrl-Alt DEL provides trusted path on Windows; you know after you hit that that you're interacting with the OS account prompt, not a malicious user-space app.
1 reply 0 retweets 0 likes -
Replying to @mvsamuel @slightlylate
Unless SW is conspiring with a USB device that can impersonate a keyboard. Sigh, trusted path is hard.
1 reply 0 retweets 0 likes -
Replying to @mvsamuel
I get what Trusted Paths are; I just don't understand in this context. The UI being presented by the site is a way to trick users into installing their native apps for news. Or do I (continue to) misunderstand your point?
1 reply 0 retweets 1 like -
Replying to @slightlylate
Sorry for over-explaining. I'm probably the one misunderstanding. I thought a dodgy native app was masquerading as a high reputation web-site. In that case, effective TP would let the user know whether they're interacting with an app or browser/webview.
1 reply 0 retweets 0 likes -
Replying to @mvsamuel
Yeah, no, this is a (trustworthy, if we can use that word) site putting up UI to trick user into installing the native app. It's a dark pattern; the sort of thing we had to do this to prevent when they were interstitial:https://webmasters.googleblog.com/2015/09/mobile-friendly-web-pages-using-app.html …
1 reply 0 retweets 2 likes -
Replying to @slightlylate
Thanks for explaining. Sorry for the confusion.
1 reply 0 retweets 0 likes
oh, n/p! Could easily have been the other. I dread the day when "in app browsers" get widely exploited to do the sorts of bad things you're suggesting.
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.
& Web Standards TL; Blink API OWNER
Named PWAs w/
DMs open. Tweets my own; press@google.com for official comms.
