Live data from Hacker News

Russia presses Apple to install Kremlin-approved apps

economist.com

81–90 of 92 posts

Re: Russia presses Apple to install Kremlin-approved apps

#81
post #76
post #14

Earlier quoted context omitted.

Give enough money and they will mark US as Zimbabwe. It is a corporation that exists to make money for shareholders, duh. What are you worrying in particular anyways? Do you really think that Apple installing the mandated apps or refusing to do so is going to sway Russian lawmakers. I do not think they give a hoot. Neither Apple marking Crimea as Russian will affect what Merkel, Macron, US senate will do about Russia…

It's more about the entertainment and seeing what Russian politicians will do without their iPhones and Apple Watches if Apple were to decline and stop selling in Russia. Because if they do comply it will be boring. No fun here.

They'll use Samsung, Huawei, Whatever. I am not sure how politician's mind works but I doubt they will perform collective seppuku.

Me personally I would not give a rat's a$$ if any of major brands has gone out of business (except of feeling sorry about employees). But then again, the only things I use my phone for are actual phone calls, GPS (off-line software mind you), bike computer and occasionally camera.

Re: Russia presses Apple to install Kremlin-approved apps

#82
post #80

Earlier quoted context omitted.

The difference is that on the iPhone, when they see a class of bad actors or a real threat model that they didn’t see before, they can tighten the sandbox much easier than they can on the Mac. The zoom fiasco could be prevented on Mac entirely just by clicking on an option that restricts apps from running in the background.

So what? - nobody has yet created an unassailable sandbox, and so these tools are needed. Saying ‘it’s Apple’s responsibility to make the sandbox secure, is magical thinking’, which is why they need these tools. As to the Zoom fiasco - who should have clicked on that option?

I’m not saying that the tool shouldn’t exist. I’m saying that the tool isn’t enough. I If Russia found the same hypothetical security hole and released the app to the store and Apple found out that a non privileged app could track your location without you giving it permission, it should fix the hole.

Re: Russia presses Apple to install Kremlin-approved apps

#83

Earlier quoted context omitted.

If Apple imposes the same restrictions as any other app - that an app doesn’t get location data without the user’s consent - it’s not different than what any other app on the store can do.

If the law requires to install some software, the law certainly requires to install them in a "working" fashion. Maybe lawmakers miss this in the first iteration. Second iteration however will contain this.

And then Apple could put up a huge warming “This app tracks your location. You can delete this app by doing X”. The proposed law will allow an app to be deleted by end users. Apple puts all sorts of scary warnings on certain apps - they did that for a year to 32 bit apps.

Re: Russia presses Apple to install Kremlin-approved apps

#84
post #80

Earlier quoted context omitted.

So what? - nobody has yet created an unassailable sandbox, and so these tools are needed. Saying ‘it’s Apple’s responsibility to make the sandbox secure, is magical thinking’, which is why they need these tools. As to the Zoom fiasco - who should have clicked on that option?

I’m not saying that the tool shouldn’t exist. I’m saying that the tool isn’t enough. I If Russia found the same hypothetical security hole and released the app to the store and Apple found out that a non privileged app could track your location without you giving it permission, it should fix the hole.

Of course it should. So what? We know that won’t make it unassailable, so they still need the other tools.

Re: Russia presses Apple to install Kremlin-approved apps

#85

Earlier quoted context omitted.

> wasn’t there just a case where Google gave our location data of anyone who was in a certain area. "Google first provided location data, but no identifying information, for 19 devices in a 150-meter radius around the bank for a one-hour period that included the robbery. Police then picked out nine of those devices for more information, and Google gave location data on those devices covering two hours. Finally, polic…

I don't see the difference, either way it's a government overreach.

In one case, the government doesn't actually know all the people who were there. In the other case, the government knows all the people who were there and everywhere else.

Re: Russia presses Apple to install Kremlin-approved apps

#86

Earlier quoted context omitted.

I don't follow..pray tell, what are these arbitrary rules?

What rules ? Has Apple ever made a technical change to iOS that made it less secure in response to a government request?

> Has Apple ever made a technical change to iOS that made it less secure in response to a government request?

Yes. https://www.bleepingcomputer.com/news/security/chinese-censo...

Re: Russia presses Apple to install Kremlin-approved apps

#87

Earlier quoted context omitted.

The entire premise of the article is to highlight the fact that a government has expressly requested Apple into allowing pre-approved apps to be installed and make use of the ecosystem, on their terms. I ask once again, where is the separation or distinction being made between the political and technical, in this case?

The difference is that if an app that has to be installed by mandate only has the same rights as any other apps that can be downloaded from the App Store, it doesn’t change the security of the underlying system. If the app is restricted to the same permission and sandboxing model. Heck, Apple could theoretically make the sandbox more restrictive. On top of that, changing the name of a country is a server side change…

> Heck, Apple could theoretically make the sandbox more restrictive.

Only by breaking other apps.

Re: Russia presses Apple to install Kremlin-approved apps

#88
post #71
post #47

Earlier quoted context omitted.

We all know that so far nobody has ever created an unassailable operating system. A key tool Apple uses to mitigate the risk is the ability to remove those binary blobs from distribution and to prevent them from running.

According to this presentation, xbox 360 is the closest to be unassailable. https://www.youtube.com/watch?v=U7VwtOrwceo

Do you mean the Xbox One? It’s 360s are easily softmoddable now.

Re: Russia presses Apple to install Kremlin-approved apps

#89
post #77

Earlier quoted context omitted.

There’s an interesting mix here though. As a nerd with a passing interest in politics, I don’t want to call Crimea lost. But at the same time, there needs to be a healthy dose of reality - if I’m on the ground, and crossing this imaginary line is going to mean russian soldiers with guns pointed at me - I think I’d prefer my map to render that line, imaginary or not.

Agreed, I'd definitely have to 1-star an app if it led me into a DMZ or military blockade.

As I understood, when viewed from Ukraine, Western maps show Crimea as a part of Ukraine.

Re: Russia presses Apple to install Kremlin-approved apps

#90
post #77

Earlier quoted context omitted.

There’s an interesting mix here though. As a nerd with a passing interest in politics, I don’t want to call Crimea lost. But at the same time, there needs to be a healthy dose of reality - if I’m on the ground, and crossing this imaginary line is going to mean russian soldiers with guns pointed at me - I think I’d prefer my map to render that line, imaginary or not.

Agreed, I'd definitely have to 1-star an app if it led me into a DMZ or military blockade.

Haha - this is exactly what happened to me when Maps.me app (formerly OpenStreetsMap) led me to UK military base in Cyprus (it made a route which skipped border checkpoints to occupied Turkish part of the island)
Post reply on HN