Comment by SpacePortKnight
15 hours ago
I think it is one of the reasons why I am always hesitant to install any software on my windows pc. Web versions are often more than good enough.
15 hours ago
I think it is one of the reasons why I am always hesitant to install any software on my windows pc. Web versions are often more than good enough.
Yes. I'm constantly annoyed by the dark patterns Zoom and Slack use to trick you into downloading their desktop apps. The web experience is practically indistinguishable and much more secure.
> The web experience is practically indistinguishable
The web experience is actually better, as eg there I can do web searches when right clicking sth with my default search engine without slack highjacking the options to force me onto google.
What is “sth”?
1 reply →
For me I just refuse to run another damn browser for each app. You can have a tab. That is it.
Slack web app experience on mobile phones is abysmal.
They are talking about desktop apps.
1 reply →
> Web versions are often more than good enough.
Except when you want actual end-to-end encryption, in which case web versions fundamentally cannot guarantee it today (and there are no plans to get there).
People using Telegram don't care so much about end-to-end encryption, so there maybe it makes sense to use the web version indeed.
You should be more specific about what you mean here because you can absolutely do E2EE in the browser.
E2EE fundamentally exists for situations where we don't want to trust the server. That's the whole idea of E2EE, right?
Of course it's not black or white, security is a gradient. But if you want to check today that you are running the legit client of ProtonMail in your browser, you do not have a practical way to do it. It is theoretically feasible, I guess (?), but far from practical. But I can walk you through the steps needed to do it today with Signal, for instance.
I think I put my limit there: it's not enough to run cryptography. Verifying the client has to be practical for the user. The way ProtonMail works in the browser is a nice way for Proton to minimise the data they collect, but it's not E2EE, because even as an advanced user I cannot practically verify the client they serve me. In other words, E2EE means (to me) that there can be some kind of guarantee if you put a reasonable amount of effort into verifying it. The browser doesn't provide that at all.
Interestingly, shipping a webapp in ElectronJS (which is terrible in terms of software, IMO) is different: you can have E2EE in an ElectronJS app.
And I'm assuming that's why Signal has a Desktop app (which I believe is ElectronJS) and not a web (as in, "loads in the browser") version.
Not OP, but: You can definitely do encryption in the browser, no problem.
What you can’t do is make sure the server giving you the code that does the encryption doesn’t change it out with code that also sends your secret messages to Siberia. Unless you control the server giving you the web page. And you trust DNS.
At that point your trust model is simpler with an auditable local application. It could even be an Electron app - so almost exactly doing E2EE in the ‘browser’.
19 replies →
Why couldn't they?
Because when you load a page in your browser, you fundamentally trust that the server is giving you what you expect. And the whole point of end-to-end encryption is that you don't trust the server.
If you download an install a program on your OS, you can e.g. check the hash of that downloaded archive and compare it to others, ideally making sure that you are running an audited version of the program. You don't have that guarantee when loading code in a browser: the server could totally serve you a modified version of the code, and you don't have a practical way to check that. Not that the laws of physics prevent it; it's just not how a browser works.
6 replies →
The lack of TOFU in browsers is an extreme pain point.
I'm going to go out on a limb and say that it is on purpose, and not a good purpose. The trust model of the web is fundamentally broken.
The way I see it, it's just different.
IMHO, the web should be to load websites (obviously) and small webapps that don't require E2EE or any kind of auditing. As soon as those are desirable, it shouldn't be a webapp anymore.
I find it nice to be able to load websites in my browser, instead of installing one program per website.
But sometimes I want a program.
When I really need to run an app on my Linux laptop, it always gets its own bubblewrap container.
This, especially commercial apps like Zoom, Steam and others. Sometimes a separate user profile is easier though.
Don't let yourself be fooled into thinking this is enough. Plenty of examples of, especially through wasm, being able to reach far beyond what they're supposed to.
It gets buttoned up fast and is always getting better, but its absolutely not a silver bullet.
If you enable lockdown mode on your iPhone and Mac, WASM is disabled through Safari. If absolutely needed, an alternative browser like Firefox can be used for those sites.
Don't most things people use day-to-day for both work and entertainment require use of the actual app these days, or at least make it very difficult to do so?
Even on Mac, where apps like Dropbox showed you a FAKE DIALOG to STEAL YOUR ADMIN PASSWORD:
https://news.ycombinator.com/item?id=12463338
Look at who is on the board of Dropbox and ask yourself what the value of a file syncing service having accessibility (and previously kernel extension) privileges on your machine are.
Not to mention that Dropbox has never been E2E protected and had that Lenovo credential free access bug on web not too long ago.
Dropbox should be considered untrustworthy at this point, especially since iCloud Drive offers E2E encryption and so do other competitors.
Is this a fake dialog, or just the standard system sudo dialog, which used to allow app developers to show an arbitrary reason string?
If it was the standard macOS dialog, an app wouldn't have been able to snoop the password
2 replies →
Something about reading this blog post knowing every letter and screenshot done manually with no LLM gave me the chills
You can't be sure. Maybe an AI from the future went back in time Skymet-style and wrote everything there