That’s probably “Family of Apps” instead, referring to the family of apps that Meta owns (e.g. IG, FB, WhatsApp, etc)
The claim that malware "makes a ton of money" for Apple definitely needs a citation. I certainly don't believe it.
Obviously, Apple understands that the reputational damage from malware is more costly than any cut they might get from the miniscule sales of it. Apple might be evil (for some definition of "evil"), but they're not dumb.
Occam's Razor and Halon's Razor are aligned here. Apple would prefer this app not exist, but somehow it slipped through the review.
I’m guessing the urls in that db were either generating a ton of backend load, so they were pushed to devices, or perhaps are customized on a per user basis for some reason
So I find it fascinating how there's always the odd typo, the old logo, the impossible combination of iPhone needing an antivirus, etc and I refuse to believe is incompetence.
Many people also claim this is the real reason behind grammatical errors in nigerian prince email scams.
Even in the unlikely case that they get paid for achieving some later payoff, the "work" on the way there is almost certainly 100% automated so there is no harm in spraying the attack more widely (as opposed to Nigeria scams where pre-AI, pre-slave-farm, the scammers would have to invest significant amounts of a very limited resource - their time - on each victim).
CORS? sec-fetch-dest, sec-fetch-mode and sec-fetch-site ?
If storage.googleapis.com weren't operated by Google, the domain would be blocked by Google's "Safe Browsing" long time ago.
While this probably works, you should also add a restrictive CSP (using the sandbox directive).
Forcing the download (via Content-Disposition header) would likely be even better, but it is annoying for users.
Serving HTML source as text/plain is safe. No browser capable of understanding CSP is going to be at risk of anything that CSP would actually protect against in this case.
Not true. You just need to make it an eTLD by adding it to the public suffix list. Only subdomains of domains on the PSL can be marked by Google’s Safe Browsing.
Should HN allow links to sites that break the back button, like all Meta sites (Ig, Fb, etc)?
Facebook was known to aggressively filter URLs too if posted too often.
Sorry, Zuck. Not signing up for Insta, though you probably made a shadow profile of me
should App Store platform fees fund getting this stuff banned?
Waiting for the next part!
It's actually interesting how often I end up seeing the uBlock 'blocked' page because of it. And how blind I end up being to the serp domains.
I of course can click the bypass button on a case by case basis.