Apple is twisting the truth

I don’t want my whole life to be writing blog posts and podcasting about Apple’s changes for the EU’s Digital Markets Act, but this latest developer update from Apple feels like an insult to developers, playing us for fools.

Let’s start with how Apple keeps mentioning all the new APIs that are part of this rollout:

To comply with the Digital Markets Act, Apple has done an enormous amount of engineering work to add new functionality and capabilities for developers and users in the European Union — including more than 600 new APIs and a wide range of developer tools.

They said the same thing in the initial news announcement:

The changes include more than 600 new APIs, expanded app analytics, functionality for alternative browser engines, and options for processing app payments and distributing iOS apps.

Apple repeatedly talks about these “600 new APIs” as if it is a favor to developers, but it was Apple’s choice to handle it this way. For example, to comply with the DMA’s requirements on sideloading or marketplaces, Apple could’ve chosen a system similar to installing apps from TestFlight. This would require zero new APIs for developers, just as TestFlight itself has no new APIs when building a beta version of your app.

Apple created the new APIs — a significant number in MarketplaceKit alone — so that they would have control over distribution. By both reviewing marketplaces and requiring that marketplaces use new APIs to install apps, Apple can track app install numbers, allowing them to invoice developers the new €0.50 Core Technology Fee. The new APIs help Apple, not developers.

Moving on to the web browser update, there is going to be universal concern from web developers about Apple disabling PWAs in the EU. On letting web apps use browser engines other than WebKit, Apple writes:

Without this type of isolation and enforcement, malicious web apps could read data from other web apps and recapture their permissions to gain access to a user’s camera, microphone or location without a user’s consent. Browsers also could install web apps on the system without a user’s awareness and consent.

Was this statement from Apple written by a hallucinating AI? All mainstream web browsers have a strict security model for JavaScript. Cookies and local storage cannot be accessed across web apps. It’s even difficult or impossible to make certain web requests from JavaScript because of cross-site scripting and CORS limitations. The only way this could be circumvented is with a rogue web browser engine that did away with these standard constraints, but Apple already has this scenario covered because they approve every browser engine:

To help keep users safe online, Apple will only authorize developers to implement alternative browser engines after meeting specific criteria and committing to a number of ongoing privacy and security requirements, including timely security updates to address emerging threats and vulnerabilities.

Users want to run Firefox and Chrome, popular browsers that are trusted by users. The DMA was created to allow this kind of choice. No one is asking Apple to blindly let browser engine malware take over home screens.

Some have argued that the DMA is poorly written, or at least too vague and open to interpretation. It actually gives gatekeepers like Apple significant leeway when it comes to security. Quoting from section 6.4:

The gatekeeper shall not be prevented from taking, to the extent that they are strictly necessary and proportionate, measures to ensure that third-party software applications or software application stores do not endanger the integrity of the hardware or operating system provided by the gatekeeper, provided that such measures are duly justified by the gatekeeper.

Apple has clearly jumped on this to give themselves an out, ignoring the spirit of the law. When it benefits Apple, they take the DMA requirements much further than intended. When it doesn’t benefit them, they lean back on the “integrity” of iOS and barely comply at all.

Wrapping up, Apple writes:

EU users will be able to continue accessing websites directly from their Home Screen through a bookmark with minimal impact to their functionality. We expect this change to affect a small number of users. Still, we regret any impact this change — that was made as part of the work to comply with the DMA — may have on developers of Home Screen web apps and our users.

It is hard to take this seriously after Apple’s bad-faith effort to comply with the DMA. I’m sure WebKit engineers regret this change, but Apple leadership doesn’t. By limiting PWAs just as PWAs are starting to be competitive with native apps, Apple ensures that native apps have no real competition on iOS, strengthening Apple’s hold on app distribution.

@manton the cool mom of tech? saying something to please the crowd? huh? lol

Vincent

real shame about PWA’s 😕

ChrisLTD

@manton right on. As you note, Apple is approving the 3rd party browsers, so why can't they be trusted to run PWAs?

Bruce

@manton « this latest developer update from Apple feels like an insult to developers »

Yes. Just when Apple wants developers to get excited about Vision Pro. Fool me once, shame on you...

Denny Henke

I've asked before but is there any chance micro.blog will have support for PWA added anytime soon? As of now it just opens a tab in Safari.

The native app on iPad is lacking in a few things. For example, viewing an image is pretty terrible as it requires scrolling to view the image rather than it being scaled and centered. And scrolling through posts on the timeline doesn't work with the keyboard. When making new posts it lacks adding categories, no option to set as a draft. Those are a few of the more notable and frustrating for me. By comparison the website is a better experience, would be great to be able to save it as a PWA.

Oh, and on the subject of the website, is there a reason why spell check does not work in text fields like comments or new posts?

Jan Erik Moström

@Denny For me the most important feature missing is that there are no command-XX shortcuts ... except command-A. Would be really nice to be able to use command-N for example.

Manton Reece

@jemostrom @Denny Thanks. More keyboard shortcuts will be in the next iPad release. I was working on them recently. For PWAs, I'd like to look into this. Spell-check only works in desktop browsers right now, but that's something I want to fix too.

Denny Henke

@jemostrom Thanks! And for what it's worth, Loura's Lillihub works as a PWA, using it right now!

Manton Reece

@Denny Excellent! Lillihub is great.

Blue
@manton

@robb @manton on the other hand, if developers is not happy to post on  App Store and pay, then they can go to Android. It is open and you do what you want. The people who want those apps can then buy Android mobiles. Anyways, I don’t really trust any non-Apple apps for they all collect something from me - $$$
I buy my device and ecosystem that works and are safe.

Jan Erik Moström

Great

Manton Reece @manton
Lightbox Image