Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Yes, I'm planning to make a library for it. It won't be quite install-and-forget, because the developer has to 1) push to GitHub or another public log before every deploy and 2) somehow let the Service Worker know where to find the latest version on GitHub. But it's definitely possible.

A TWA hub sounds interesting. I think that if you have a list of web apps that

1. are a Transparent Web App

2. have had a security audit

you could then add some UI in the browser that says "this web app keeps your data private". That would be useful not just for apps that use client-side encryption, but also very simple web apps, like say word counters. It's very useful for users to know whether the word counter sends their data to the server or not.

Of course, step 2 would be quite expensive, although for simple web apps it would be manageable. It would have to be financed by either the web apps themselves, or some big entity like Mozilla (which for years has had volunteers manually check browser extensions for things like this, too).



The JavaScript trust issue will always be a concern when webcrypto is used, and webcrypto is a web Api expected to be made broadly available across browsers (desktop and mobile). If somehow the concept of TWA can be made easy for developers to adopt and you pivot to handle/streamline the heavy lifting, I think you may have a much more lucrative nitch. Think of this as VeriSign for TWA. Wouldn’t that be cool? Someone (i.e you or Mozilla) should do this. This really promotes the open web.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: