Live data from Hacker News

Russia presses Apple to install Kremlin-approved apps

economist.com

51–60 of 92 posts

Re: Russia presses Apple to install Kremlin-approved apps

#51
post #31

This very worrying, particularly because Apple recently caved in and marked Crimea as Russian...

Crimea only appears as Russian if you're viewing it from within Russia, which recognizes Crimea as part of Russia, not Ukraine. If you're viewing Crimea from Ukraine, it will appear as Ukrainian, because Ukraine recognizes Crimea to be part of Ukraine. That seems fair, doesn't it?

That means that American companies like Apple have admitted that Crimea is a part of Russia, not just an occupied territory of a foreign country? Despite the fact that there are no international treaties that would confirm transferring this territory to Russia?

Re: Russia presses Apple to install Kremlin-approved apps

#52
post #47

Earlier quoted context omitted.

There are millions of “binary blobs” written by third parties on iOS. Its Apple’s responsibility to write an operating system that can run in hostile environments.

We all know that so far nobody has ever created an unassailable operating system. A key tool Apple uses to mitigate the risk is the ability to remove those binary blobs from distribution and to prevent them from running.

But that’s still after the fact and after the damage has been done. I’m not aware of any time that Apple has a removed an app from devices instead of removing it from the App Store v

Re: Russia presses Apple to install Kremlin-approved apps

#53

Earlier quoted context omitted.

From the article, it will be able to be deleted just like any other app. I doubt that Apple is going to let the Russian government create the image or use some type of nationwide MDM or Enterprise. certificate. It could go through the same app review process. On the other hand, this should be an excellent test of Apple’s security and review process....

>I doubt that Apple is going to let the Russian government create the image or use some type of nationwide MDM or Enterprise. >On the other hand, this should be an excellent test of Apple’s security and review process.... In between your two contrasting comments, lies the rub of how much further Apple is willing to capitulate to the demands of nation states ─ who demand nothing less. https://www.nytimes.com/2019/11/2…

And that’s political not imposing technical changes on their devices.

Re: Russia presses Apple to install Kremlin-approved apps

#54

If Apple trusts the security of its own operating system, it should be able to sandbox the apps just like any other app. While the US doesn’t force companies to install apps, it does force companies to support E911 and the system used for Amber alerts and other mandated alerts.

It's not only about integrity of the phone. Imagine a state requested application tracks location and sends that up (yeah, need is little as devices can be tracked over cell towers relatively good) when installing they'd certainly require permissions to be set accordingly. Also from Apple's perspective it's about the brand. They don't want to have preloaded crap on a fresh device, where the user can't distinguish whe…

If Apple imposes the same restrictions as any other app - that an app doesn’t get location data without the user’s consent - it’s not different than what any other app on the store can do.

Re: Russia presses Apple to install Kremlin-approved apps

#55

Earlier quoted context omitted.

It wasn’t stated that Russia was mandating device management. And just like if a regular app can cause security issues, it’s the fault of the operating system and should be fixed, if your data on the cloud can be read by an adversary, instead of only having the private keys on the device, that’s a flaw in the implementation that Apple needs to fix. Yes si realize that everything stored on iCloud is not E2E encrypted.…

> That’s the real issue, not that the data is in China. In the US, data requests have to be for individual accounts and go through a judge and sent to the company, who might file an appeal. This is not the case in China. The government can simply get the data it wants without any company appeal. > It wasn’t stated that Russia was mandating device management Nor was it stated that it isn't. My point was that the sandb…

You trust government transparency more than I do. But wasn’t there just a case where Google gave our location data of anyone who was in a certain area.

I would much rather that Apple designer a system where it couldn’t give out the information because it didn’t have an unencrypted version of the data in the first place.

Re: Russia presses Apple to install Kremlin-approved apps

#56
post #47

Earlier quoted context omitted.

We all know that so far nobody has ever created an unassailable operating system. A key tool Apple uses to mitigate the risk is the ability to remove those binary blobs from distribution and to prevent them from running.

But that’s still after the fact and after the damage has been done. I’m not aware of any time that Apple has a removed an app from devices instead of removing it from the App Store v

https://www.theverge.com/2019/7/10/20689644/apple-zoom-web-s...

https://www.theverge.com/2019/7/16/20696529/apple-mac-silent...

Re: Russia presses Apple to install Kremlin-approved apps

#57

Unpopular opinion. Putting all the conspiracy theorists aside the intent of the law is actually to gain what western countries have a new phone that has localized apps that non-English speakers can use. For some apps, like twitter, translation of the ui is enough for some others local apps are just better. Knowing how laws are being implemented in Russia it is hard to tell what this will turn out into, most operators…

> a new phone that has localized apps that non-English speakers can use

Apple localizes their operating system.

Re: Russia presses Apple to install Kremlin-approved apps

#58
post #56

Earlier quoted context omitted.

But that’s still after the fact and after the damage has been done. I’m not aware of any time that Apple has a removed an app from devices instead of removing it from the App Store v

https://www.theverge.com/2019/7/10/20689644/apple-zoom-web-s... https://www.theverge.com/2019/7/16/20696529/apple-mac-silent...

Well, since the discussion was about iPhones that both have a tighter security model and where every app has to go through the App Store, I fail to see the relevance.

Re: Russia presses Apple to install Kremlin-approved apps

#59

Unpopular opinion. Putting all the conspiracy theorists aside the intent of the law is actually to gain what western countries have a new phone that has localized apps that non-English speakers can use. For some apps, like twitter, translation of the ui is enough for some others local apps are just better. Knowing how laws are being implemented in Russia it is hard to tell what this will turn out into, most operators…

> a new phone that has localized apps that non-English speakers can use Apple localizes their operating system.

Most of those apps are still made with USA/Western Europe customers in mind and their habits so just translating text in the ui will not add a ton of relevant content in case of a social app.

Google assistant just doesn't work very well outside of USA for example.

Re: Russia presses Apple to install Kremlin-approved apps

#60

Earlier quoted context omitted.

> That’s the real issue, not that the data is in China. In the US, data requests have to be for individual accounts and go through a judge and sent to the company, who might file an appeal. This is not the case in China. The government can simply get the data it wants without any company appeal. > It wasn’t stated that Russia was mandating device management Nor was it stated that it isn't. My point was that the sandb…

You trust government transparency more than I do. But wasn’t there just a case where Google gave our location data of anyone who was in a certain area. I would much rather that Apple designer a system where it couldn’t give out the information because it didn’t have an unencrypted version of the data in the first place.

> wasn’t there just a case where Google gave our location data of anyone who was in a certain area.

"Google first provided location data, but no identifying information, for 19 devices in a 150-meter radius around the bank for a one-hour period that included the robbery. Police then picked out nine of those devices for more information, and Google gave location data on those devices covering two hours. Finally, police asked for — and received — subscriber information for three devices, including one that was in the bank during the robbery, left immediately after it, and followed a path matched by witness sightings."

https://www.nbcnews.com/news/us-news/police-used-google-loca...

In China, the police would simply access the location history of all iPhone users in the area, complete with identifying information, without Apple's involvement.

Post reply on HN