Live data from Hacker News

Apple: Person-to-person experiences do not have to use in-app purchase

developer.apple.com

471–480 of 492 posts

Re: Apple: Person-to-person experiences do not have to use in-app purchase

#471

Earlier quoted context omitted.

This argument doesn't hold water because it applies as much to the choice of phone as the choice of app store. There have been phones that come with malware preinstalled : https://www.zdnet.com/article/more-pre-installed-malware-has... A user who acts without knowledge or advice buys that phone and is infected. A user who acts without knowledge or advice buys an app from a store operated by the people who made that p…

> This argument doesn't hold water because it applies as much to the choice of phone as the choice of app store. That's silly. The number of people who might buy a specific no-name budget brand of phone with this problem is much, much smaller than the number of people that search for "how to install Fortnite" on Google or Youtube and end up clicking on a fake installer instead of the real one, because they can't find…

> The number of people who might buy a specific no-name budget brand of phone with this problem is much, much smaller than the number of people that search for "how to install Fortnite" on Google or Youtube and end up clicking on a fake installer instead of the real one, because they can't find Fortnite in the Play Store like they can with all their other apps.

If you search for "how to install Fortnite" then you get this:

https://www.epicgames.com/fortnite/en-US/download

Which is actually how you install Fortnite and not a fake installer.

People end up with the fake installer in the same ways they end up with the malware phone.

> Oh, you might accidentally buy a phone pre-loaded with malware, so we might as well give up and not bother taking any other steps to prevent the spread of malware on our phones?

There are a hundred ways to prevent the spread of malware without prohibiting multiple app stores. Allow third party apps but scan them for malware first. Get your apps from another app store, but that store checks it for malware. The only thing we give up on is the thing which is anti-competitive.

> So the fact that Windows has never had a single dominant app store means Windows users must be particularly experienced in how to be safe in installing apps from other sources? This does not match reality.

Have you used Windows lately? It comes with built in virus and malware detection for free and which doesn't expire. People are increasingly getting their software from stores like Steam and EGS which evict malware, which they can do even when they have competitors. Or getting it directly from well-known developers who they trust, like Mozilla or Adobe. Things that have no reason not to be web pages, are web pages. It works fine, even though you can still technically click through five warnings and run random garbage from the internet, because people have actually learned not to do that.

The people who haven't aren't the majority, they're the same people who buy the malware phone.

Re: Apple: Person-to-person experiences do not have to use in-app purchase

#472

Earlier quoted context omitted.

> This argument doesn't hold water because it applies as much to the choice of phone as the choice of app store. That's silly. The number of people who might buy a specific no-name budget brand of phone with this problem is much, much smaller than the number of people that search for "how to install Fortnite" on Google or Youtube and end up clicking on a fake installer instead of the real one, because they can't find…

> The number of people who might buy a specific no-name budget brand of phone with this problem is much, much smaller than the number of people that search for "how to install Fortnite" on Google or Youtube and end up clicking on a fake installer instead of the real one, because they can't find Fortnite in the Play Store like they can with all their other apps. If you search for "how to install Fortnite" then you get…

The problem is not everyone clicks on the right link. Non-sophisticated users looking for Fortnite don't even know what Epic is or whether or not they're the official place to get it.

https://blog.malwarebytes.com/cybercrime/2018/06/fake-fortni...

> There are a hundred ways to prevent the spread of malware without prohibiting multiple app stores. Allow third party apps but scan them for malware first. Get your apps from another app store, but that store checks it for malware.

The App Store review process checks for more than just malware. It also enforces privacy restrictions and ensures that developers aren't abusing legitimate APIs for malicious purposes. Malware scanning isn't going to prevent third-party apps from slurping all your friends phone numbers and selling that data to advertisers.

> People are increasingly getting their software from stores like Steam and EGS

Which is why we now have malware floating around masquerading as the Epic Games Store.

https://www.zdnet.com/article/new-lokibot-trojan-malware-cam...

I think you're making the same fallacy as the person I originally replied to, which is taking the experience of a highly technical user and assuming everyone else knows how to do the same things you do. I use all four platforms (iOS/Android/Mac/Windows) regularly. I've personally never had problems with viruses/malware on Windows, even back in the XP days before Windows Defender was a built-in thing. But simultaneously I don't believe my experience is typical of the majority of users on those platforms.

Re: Apple: Person-to-person experiences do not have to use in-app purchase

#473
post #441

Earlier quoted context omitted.

This is a really easy problem to solve - add a scary sign and/or void the warranty when a user decides they want to use an alternative app store. Then they at least have the option - and if they take it and suffer, they're the only one to blame. There's absolutely no collateral damage among users, and this feature would not meaningfully weaken security (if implemented properly) - "the user could do something dumb tha…

"This user just gave a third party their entire contact list" certainly does harm other people. "This user just had their entire camera roll exfiltrated" certainly does harm other people. These are social devices. Their users are, by and large, non-technical and incurious. Expecting them to not just click past the "scary sign", and so condition to do it again and again, so they can play Fortnite is a level of lack of…

...neither of those attacks you gave are unique to smartphones. Someone can leak personal information through any number of other channels - for instance, entering someone else's personal information into a website that send out emails for a group party invitation.

> Expecting them to not just click past the "scary sign", and so condition to do it again and again, so they can play Fortnite is a level of lack of understanding that borders on incredible.

That's not an excuse. This is bad behavior. It doesn't matter if it's common, or expected - it's wrong, and their responsibility for correcting - not Apple's, and especially not at the freedom of other users who have nothing to do with these idiots. If this behavior is normal, then we need to make it not normal, not continue to compensate for their ineptitude. Fix problems, don't avoid them.

Re: Apple: Person-to-person experiences do not have to use in-app purchase

#474

Earlier quoted context omitted.

I don't see that at all. The value Apple supposedly provides is safety. If consumers want the safety that Apple offers, they can continue to limit themselves to Apple's App Store offerings, while those who don't value safety as highly can use a different app store. Just because you value something in a certain way does not mean everyone else should be forced to adhere to those same values.

When you allow additional app stores, you encourage companies--like, say, Epic Games--to convince people who do not understand the ramifications or the threats involved with opening up past a rigorous review process to do so. And Epic isn't going to be following behind for the newly-credulous when they pick up another one and it's full of dangerous shitware. Somebody who wants to not use the App Store can buy an Andr…

Possible credulous users cannot be the one-size-fits-all excuse for blocking the freedoms of everyone. There are many ways to mitigate any conceivable concern without abrogating the freedom of a phone owner to run the software they wish on their own device.

Re: Apple: Person-to-person experiences do not have to use in-app purchase

#475

Earlier quoted context omitted.

> If third party App Stores are ever forced onto iOS devices, that market vanishes completely. Crashes, slowdowns, battery drain, malware, and information theft will become the norm. Go no further than your gaming PC to witness the nightmare that is multiple app stores all competing for CPU and control/surveillance of your system, all needing to bring their own flavors of information-harvesting/exposing DRM. I am sor…

There is literally malware spreading by masquerading as the Epic Games Store: https://www.zdnet.com/article/new-lokibot-trojan-malware-cam...

I still fail to see how this will apply to iOS.

iOS doesn't magically lose it's sandboxing and become Windows just because 3d party stores are allowed.

Re: Apple: Person-to-person experiences do not have to use in-app purchase

#476

Earlier quoted context omitted.

There is literally malware spreading by masquerading as the Epic Games Store: https://www.zdnet.com/article/new-lokibot-trojan-malware-cam...

I still fail to see how this will apply to iOS. iOS doesn't magically lose it's sandboxing and become Windows just because 3d party stores are allowed.

Sandboxing didn't prevent fake versions of Fortnite and other serious malware from spreading on Android, nor does it generally prevent information theft and privacy violation through malicious use of legitimate APIs.

Re: Apple: Person-to-person experiences do not have to use in-app purchase

#477
post #440

Earlier quoted context omitted.

The reason why developers want to make apps for iOS is because there's a large market. That market exists because Apple has done a great job prioritizing the protection of their customers' privacy and payment information. If third party App Stores are ever forced onto iOS devices, that market vanishes completely. Crashes, slowdowns, battery drain, malware, and information theft will become the norm. Go no further tha…

> If third party App Stores are ever forced onto iOS devices, that market vanishes completely. Crashes, slowdowns, battery drain, malware, and information theft will become the norm. This is a wild projection. Having alternative app stores on iOS, especially if gated behind a hard-to-find switch with a scary warning sign, will be totally different than any PC experience, partially because iOS has a sandboxed architec…

I mean, is it really that far out there if you look at the past two decades of history of malware on Windows and particularly Android?

Sandboxing has not prevented the proliferation of malware on Android, why would it be any different on iOS?

Sandboxing also doesn't really address the other major risk which is theft of personal information by supposedly "trustworthy" apps.

Re: Apple: Person-to-person experiences do not have to use in-app purchase

#478

Earlier quoted context omitted.

>I wouldn’t buy a Mac. I run Linux but I am the only one that I know in my family and friends and if the hardware would be DRM and locked down you could not get an older windows machine and put Linux on it. Don you think that the hardware and software you bought should serve you the owner? Like if it is my own OS it should execute what I tell it to do(maybe I would need to enable something to exit the "kid mode")

My hardware does serve me. I won’t install Zoom or Dropbox on my Mac for instance because they are essentially malware. Zoom was installing a web server in the background on Macs where even if you uninstalled it, it would reinstall itself. DropBox does all sorts of invasive stuff when installed on my Mac. On the other hand, my iPad has a strict sandbox, I can restrict apps from using cellular on an app by app basis (…

Sure, but Google or Apple approved apps also have issues, if I remember right Microsoft updates lost user data, I think some Apple updates destroyed some users backups, Steam had a bug where it deleted all the user files.

So I think the focus should not be in locking users but in locking the apps in strong sandboxes.

Thank you for all your replyes but I notice you are ignoring a category of developers, you are only consider the ones that do it for making lot of money and ignoring people that do it for passion, as I said I see plenty of free stuff that is made for passion and shared with the community (like a small game, or a mod, or a "save cleaner/editor" tool), this communities are small and probably not that vocal but they exist - a strong sandbox and a giant warning when you install such an approved tool should be enough for this people.

If I may add, Apple allowed Fortnite and games with lootboxes or skins purchase, Apple gets 30% cut so they will not block this as long as they make big money. I know they are making some arcade but that is to handle teh case of games that have ads. it is a good way of Apple making more money and it will not stop the lootboxes, let me know if I missed something and Apple is blocking lootboxes or skin.gem,coin purchases.

Re: Apple: Person-to-person experiences do not have to use in-app purchase

#479
post #5
post #2

Relevant section: 3.1.3(d) Person-to-Person Experiences: If your app enables the purchase of realtime person-to-person experiences between two individuals (for example tutoring students, medical consultations, real estate tours, or fitness training), you may use purchase methods other than in-app purchase to collect those payments. One-to-few and one-to-many realtime experiences must use in-app purchase. This is huge…

> One-to-few and one-to-many realtime experiences must use in-app purchase. WUT?! This is so arbitrary and petty. So we're supposed to feel thankful that the all mighty Apple is allowing 1 on 1 personal fitness trainers and tutors but not build something that is scalable?

I’m in the process of building an app for massage services to the home. There are formulas like 1 on 1, 1 on 2 and 2 on 2. This change would mean that I could make all of this happen without any in app purchases as long as the purchases are independent and Then linked together. Am I getting this right?

Re: Apple: Person-to-person experiences do not have to use in-app purchase

#480
post #440

Earlier quoted context omitted.

> If third party App Stores are ever forced onto iOS devices, that market vanishes completely. Crashes, slowdowns, battery drain, malware, and information theft will become the norm. This is a wild projection. Having alternative app stores on iOS, especially if gated behind a hard-to-find switch with a scary warning sign, will be totally different than any PC experience, partially because iOS has a sandboxed architec…

I mean, is it really that far out there if you look at the past two decades of history of malware on Windows and particularly Android? Sandboxing has not prevented the proliferation of malware on Android, why would it be any different on iOS? Sandboxing also doesn't really address the other major risk which is theft of personal information by supposedly "trustworthy" apps.

Malware is less of a problem for Android now than any point in Windows' history except for possibly the past few years, so I think that sandboxing has succeeded rather well, given that Windows has had 34 years to evolve defenses and Android has only had 11. Even early on in its life, Android was still better off than Windows at the time, and what do you know - Android has allowed sideloading and alternative app stores this entire time. That is, Android is doing now what we're discussing what Apple might do, and it's worked out pretty well for them.
Post reply on HN