Hacker News new | ask | show | jobs
by somebear 5504 days ago
You should be able to check whether it actually launches safari, e.g. by pressing the home button and the actually launching safari, should look the same as the screen you just left.
3 comments

On Linux, even if the Twitter app on your desktop launches a browser, it can still do a very effective job of sniffing your password simply by asking the desktop environment for the relevant events. It only works in the browser because everything is sandboxed, with a particular focus on sandboxed-by-domain. See http://theinvisiblethings.blogspot.com/2011/04/linux-securit... , for instance. There are ways to do that on all the desktop environments, I presume, with varying degrees of officialness and popping up administrator password dialogs.
Most of us here would be, but most of us out there wouldn't. It isn't secure if it only works for the techie folks.
Because that's convenient and obvious...
I didn't say that it was either, just that it was possible.