well, you need to consider the whole thing, like how you get into the situation of no visible url.
-
-
Replying to @jaffathecake
: right. The PWA "install" step is basically the capability to run fullscreen for the origin in question.
1 reply 0 retweets 1 like -
Replying to @slightlylate @jaffathecake
: and if any of those properties are degraded, we bounce you back to browser or show security indicator (w/ URL)
1 reply 0 retweets 1 like -
Replying to @slightlylate @jaffathecake
I'm not talking about a "secure" site. I'm talking about malicious links - which can easily have an SSL.
1 reply 0 retweets 0 likes -
Replying to @Paul__Walsh
: yes, I get that, and you seem to have missed the multiple corrections I and
@jaffathecake have offered.2 replies 0 retweets 0 likes -
Replying to @slightlylate @jaffathecake
I'll read again. If I disagree or continue to see potential issues, it doesn't mean I didn't read your comments
2 replies 0 retweets 0 likes -
Replying to @Paul__Walsh1 reply 0 retweets 1 like
-
Replying to @slightlylate @jaffathecake
Got it. Thanks for the detailed response, much appreciated. I have a better understanding, thanks.
1 reply 0 retweets 2 likes -
Replying to @Paul__Walsh @slightlylate
\o/ always worth thinking through the steps before deciding everything's broken
2 replies 0 retweets 1 like -
Replying to @jaffathecake @slightlylate
I was poisoned by WebView and Chrome for mobile only integrating Safe Browser API in Dec 2015 ;)
#security1 reply 0 retweets 0 likes
: WebView fundamentally can't be secure for arbitrary content. "In-app browsers" that use it that way are bad news
-
-
Replying to @slightlylate @jaffathecake
I'm talking about secure from known, classified malicious URLs. WebView is used beyond expected use cases.
1 reply 0 retweets 0 likes -
Replying to @Paul__Walsh
: apps that do this deserve all the uninstalls that are coming to them. /cc
@jaffathecake2 replies 0 retweets 1 like - 2 more replies
New conversation -
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.
& Web Standards TL; Blink API OWNER
Named PWAs w/
DMs open. Tweets my own; press@google.com for official comms.