Live data from Hacker News

Epic direct payment on mobile

epicgames.com

231–240 of 371 posts

Re: Epic direct payment on mobile

#231
post #29

This puts Apple in a very tough spot. Last week, Tim Cook was questioned in an antitrust hearing re: Apple's anticompetitive practices (along with Jeff Bezos, Mark Zuckerberg, and Sundar Pichai). The spotlight is already pointing right at them, so any move they make here is going to be noticed by lawmakers. If they remove Fortnite from the App Store, Apple will probably be seen as the bad guy. After all, Epic is not…

I bet that Epic execs also talked behind the scene with other execs in the industry to garner support in case Apple cracks down hard on Epic and removes Fortnite from the app store. If more studios/developers join the cause, they can definitely apply big pressure on Apple.

Fortnite is popular enough to count as "big pressure" all on its own. I couldn't find recent numbers, but as of 2018 they had over 100M installs and were doing over $1M/day in revenue[0] and by early 2019 they'd already done more than half a billion[1].

[0]: https://venturebeat.com/2018/07/30/fortnite-clears-100-milli...

[1]: https://www.gamesindustry.biz/articles/2019-02-08-fortnite-i...

Re: Epic direct payment on mobile

#232

This puts Apple in a very tough spot. Last week, Tim Cook was questioned in an antitrust hearing re: Apple's anticompetitive practices (along with Jeff Bezos, Mark Zuckerberg, and Sundar Pichai). The spotlight is already pointing right at them, so any move they make here is going to be noticed by lawmakers. If they remove Fortnite from the App Store, Apple will probably be seen as the bad guy. After all, Epic is not…

As a user, I'm torn. I want to see enough pressure put on Apple that their app store cut is reduced, and ideally (though somewhat unrelated to this) the store experience for users improves. But I definitely don't want to see more stores or payment methods for digital goods on my i-devices.

I have no problems paying through a wide variety of payment processors on the web: Shopify, Stripe, PayPal, Braintree, Amazon, whatever.

What’s the concern? All cards are zero liability, and you should be checking your statements anyway due to fraud risks.

Re: Epic direct payment on mobile

#233
post #168

Earlier quoted context omitted.

All Apple has to do to fix this is allow sideloading. They don't need to change the App Store's rules—they can make them more stringent, actually—and you can set up your child's phone to block non-App-Store installations. Heck, Epic would probably cave and accept the cost to keep Fortnite in the App Store; they tried to go around Google Play, and it seemingly didn't work out.

The problem with that is that it is all or nothing. The milder approach I had in mind was that apps require you to register an account outside the app (like amazon) but the purchase is initiated inside the app and outside Apple api. At the beginning that will be easy to simply not register and not use games that require registration. But well, micro-transaction started that way and nowadays all the major player do it…

If i'm not mistaken, Apple doesn't even have a "separate wallet" requirement like Consoles do where, if you have a cross-platform game with virtual currency, you have to keep currency purchases made on one platform separate from currency purchases made on competitor's platform - Eg. in Fortnite, purchasing $10 of VBucks on the Nintendo Switch means you have to spend those VBucks in the in-game store while on the Switch, you can't go to your PC and spend them or combine them with VBucks you've purchased from Epic directly.

Re: Epic direct payment on mobile

#234
post #3

My money is on Apple cracking down hard on this. It looks clearly as if Epic remotely activated this direct payment option, thereby bypassing Apple's App Review. Apple will not take kindly to this. Best case scenario for Epic (and Fortnite players): they invite Sweeney in for some hard negotiations. Worst case: Fortnite ends up getting removed from iOS for this.

It’s possible Epic are baiting the app stores, betting that the current anti-trust questions around Apple and Google support a change. Either Apple and Google capitulate to this move by Epic, and Epic wins. Or Google and/or Apple come after Epic, creating a public scene that emphasizes their monopoly-like behavior, and failed lawsuits or government action mean a win for Epic. The third option—the big guys come after…

Google at least can argue that if you don't like their rules, you're free to distribute the app yourself. Whether that will convince lawmakers who knows.

Re: Epic direct payment on mobile

#235
post #226

Earlier quoted context omitted.

> I want an ecosystem that works and I can rely on including knowing that little to no one can side load a malicious application onto the device. I don't understand this, can you explain why? As long as you don't sideload on your own phone, why would having the option be a problem?

Presumably because app developers might choose not to go through the curated App Store route and in turn, cut corners or do shady things just because they can. Imagine if Tik Tok was only available to side load -- they'll scrape whatever they want/can and teens aren't going to risk FOMOing for that alone.

I don't think that would happen. You can sideload into Android but as far as I know no one sideloads Tik Tok, you just get it through the store. I'm not saying it can't happen, but I just don't see it as a reason for not owning a device that allows sideloading (unless you mean that one could oppose sideloading in principle and boycott devices that allow it?)

Re: Epic direct payment on mobile

#236

Earlier quoted context omitted.

Epic doesn't pay Sony and MS 30% for console purchases, as both companies negotiate arrangements with big studios that lowers the rate.

Still, it does create a bit of a contradiction. We don't know what Sony and Microsoft charge, but we can reasonably assume it isn't zero, and it's also probably more than whatever Epic pays for their internal payment processing. Epic could still turn around and say "well, the price would be even lower if not for Sony and Microsoft," but I'm not sure how much they want to piss off the console manufacturers, who—all th…

> The other elephant in the room, IMO, is that V-Bucks don't actually cost Epic anything. They're just bits, and Epic could set the price to whatever they want without much consequence.

Can't you argue this about any software? A copy of an expensive, downloadable software is always "just bits", and the marginal cost of selling one more copy is ridiculously low, but that doesn't mean the software itself is free. In order to sell those V-Bucks, Epic had to spend millions in order to develop, market, run and support a game that people actually want to play.

Re: Epic direct payment on mobile

#237

Earlier quoted context omitted.

The App Store review process stops it. To dispute charges that were indeed made by a member of your household, you usually have to file a police report against them. The method of paying for things online by shared secret numbers is insane. Phones permit much more reasonable payments architectures, since they can sign transactions with their TPMs instead of spraying your credit card number everywhere. We should see p…

> We should see phones replace credit card entry even for transactions started on desktops. The two banks I use already have this, as many other banks. I already have to trust my bank, they literally have my money. I pay my taxes and sign them thru my bank, I do transfers, I pay subscriptions, etc. everything with my bank signature. Apple is what is stopping more apps to use my bank signature to pay directly thru it.…

> Even malware, that should be way easier to detect and stop , way easier than to stop a pop-up asking for your credit card, pass thru their system

Ah yes, one of the scarier trojans to hit your phone: click-jacking for ad fraud.

> The apps communicate with a known command and control (C&C) server to simulate user interactions in order to fraudulently collect ad revenue.

I'd download this malware any day over the actually-malicious Android malware that's out there: https://forensics.spreitzenbarth.de/android-malware/

Re: Epic direct payment on mobile

#238
post #171

This puts Apple in a very tough spot. Last week, Tim Cook was questioned in an antitrust hearing re: Apple's anticompetitive practices (along with Jeff Bezos, Mark Zuckerberg, and Sundar Pichai). The spotlight is already pointing right at them, so any move they make here is going to be noticed by lawmakers. If they remove Fortnite from the App Store, Apple will probably be seen as the bad guy. After all, Epic is not…

If Apple removes Fortnite from the app store, it'll become a class action lawsuit in my opinion. Kids have spent hundreds, maybe thousands, of dollars on vbucks on their phones. If you just take that away..... you owe some people some money.

If it’s deleted from the App Store it will still be on their phones.

Either way I don’t think there’s a legal precedent for a class action

Re: Epic direct payment on mobile

#240
post #215

Earlier quoted context omitted.

The main reason I use an iPhone is that it doesn’t allow side loading out side of development applications and has a curated closed store. I want an ecosystem that works and I can rely on including knowing that little to no one can side load a malicious application onto the device. I’m also very well aware of the fact that while Apple scalps developers it’s also the reason why my devices get security updates for 6 ye…

Sorry but I'm not sure you understand how sideloading works on Android. You have to enable it explicitly for any app you want to sideload from (eg. your browser for a downloaded app, or an alternative app store like F-Droid). Afterwards, every app installation still needs to be manually approved and thus cannot be done hidden in the background. Seems pretty safe to me while still allowing more freedom to power users.

...and then a ton of apps decide "screw the app store, I'm going solo!" and people start enabling sideloading so they can try those apps, then sideloading becomes normalized and malware starts to spread without Apple having the ability to prevent it. Users who have issues with apps start hitting up Apple's support lines, and they start getting pissed off when Apple says "Sorry we can't help you, go talk to the developer. Not that we know who they are, and maybe you actually don't either, but either way you're on your own."

Plus, developers lose access to a lot of Apple's functionality, like the fact that XCode can upload LLVM bytecode so that Apple can re-optimize through new or updated LLVM backends to deliver optimized versions for new platforms, etc.

Suddenly, all the goodness that's "baked in" to the iPhone experience is gone, and the whole system starts looking like an inconsistent mess compared to the way it was before.

I wonder if some kind of hybrid approach would work; for example, a workflow like this:

1. Developers develop locally as usual 2. Developers upload to Apple via XCode as usual 3. Apple does its standard automated checks (private APIs, etc) 4. The developer can file for that app to be held "off the store"; this is rejected by Apple for some reasons (like private API usage, malware, etc.) but generally approved. Apps which do this likely lose access to some system APIs (e.g. iCloud storage, IAP) but it's a tradeoff. 5. The developer can now get an App Store link which they can give to users to find their app on the store. This is the only way to find the app; it doesn't appear in lists, search, "top paid", features, or anything of the sort. 6. Users get an app that isn't (overtly) malicious and won't definitely break in future OS updates, developers get the infrastructure benefits and automatic updates, Apple can wash their hands of any downstream issues because they know for certain that the user arrived via the developer and can make that clear to the user ("if you have problems, go talk to them. If they're misbehaving, come talk to us.")

This would make the value proposition for most developers pretty clear, but for huge entities like Epic or Microsoft, they can just bypass the system because people can come to them directly.

Post reply on HN