Live data from Hacker News

A top-grossing scam on the App Store

twitter.com

111–120 of 285 posts

Re: A top-grossing scam on the App Store

#111
post #108

Apple has just engineered the worst possible situation for themselves by being the only way to get apps on the store and by simultaneously incessantly marketing the store as "Safe and Secure". The former encourages them to maximize the number of apps on the store, while the latter encourages them to shoot first and ask questions later. If side-loading or alternative ways of getting apps onto the iPhone existed, then…

How would the security model work with side loaded apps. How would they get access to OS resources, services and share data with other apps, e.g through the clipboard? Who would verify them against malware, or ensure they didn’t violate security constraints? It’s not like Apple could disavow all responsibility for any data leaked from the system, a lot of users simply wouldn’t see it that way. There’s a lot wrong wit…

“Sideloading Apps Would ‘Break’ the Security and Privacy of iPhone”, said Tim Cook.

But instead of gaslighting us, Apple could let us sideload notarized apps. This means:

- Automated scan for malware

- Remote kill switch, just in case

They already do this for macOS [1]:

> “Notarization is not App Review. The Apple notary service is an automated system that scans your software for malicious content, checks for code-signing issues, and returns the results to you quickly.”

They could give users a choice, much like they're doing with the new App Tracking Transparency prompt. But when pressed on why Apple should have control, Cook said "Somebody has to."

That's… not a very convincing argument.

[1]: https://developer.apple.com/documentation/xcode/notarizing_m...

Re: A top-grossing scam on the App Store

#112

Apple has just engineered the worst possible situation for themselves by being the only way to get apps on the store and by simultaneously incessantly marketing the store as "Safe and Secure". The former encourages them to maximize the number of apps on the store, while the latter encourages them to shoot first and ask questions later. If side-loading or alternative ways of getting apps onto the iPhone existed, then…

The real issue is that "AppStore" and "ContentFilter" are two orthogonal things (which Apple conflates). We can have multiple instances of both. And we probably should.

Yeah: and for anyone who doesn't immediately see how this is possible, a curator merely needs to have an allow/deny list of apps--possibly specific reviewed binaries--not actually host them or be the bottleneck for obtaining them: you just want the (hopefully federated) store app(s) to be able to refer to the (hopefully federated) curator(s) to limit the display and prevent installs.

Re: A top-grossing scam on the App Store

#113

Apple has just engineered the worst possible situation for themselves by being the only way to get apps on the store and by simultaneously incessantly marketing the store as "Safe and Secure". The former encourages them to maximize the number of apps on the store, while the latter encourages them to shoot first and ask questions later. If side-loading or alternative ways of getting apps onto the iPhone existed, then…

I think it would still poison the “Apple experience” to have many AppStores all competing with their own closed ecosystems. The Apple Experience of not being able to install some apps sucks, but its always been easy for me to help someone with an iOS device. That’s not true with Android or Windows. A walled garden ecosystem isn’t for everyone, but it does have value. Instead, I’d like to see Apple be forced to provid…

> I think it would still poison the “Apple experience” to have many AppStores all competing with their own closed ecosystems.

I actually think Apple could find a way to navigate it. They already allow one prominent alternative choice on iOS: non-iMessage SMS. If Apple allowed third-party stores, I could see them using their product, UX, and branding mastery to create the equivalent of the blue-bubble and green-bubble dichotomy for App Store vs. 3rd party downloaded apps. Creating a social stigma without technical restrictions, so to speak. So allowing an alternative while at the same time encouraging users not to partake in it.

Re: A top-grossing scam on the App Store

#114
post #108

Earlier quoted context omitted.

How would the security model work with side loaded apps. How would they get access to OS resources, services and share data with other apps, e.g through the clipboard? Who would verify them against malware, or ensure they didn’t violate security constraints? It’s not like Apple could disavow all responsibility for any data leaked from the system, a lot of users simply wouldn’t see it that way. There’s a lot wrong wit…

“Sideloading Apps Would ‘Break’ the Security and Privacy of iPhone”, said Tim Cook. But instead of gaslighting us, Apple could let us sideload notarized apps. This means: - Automated scan for malware - Remote kill switch, just in case They already do this for macOS [1]: > “Notarization is not App Review. The Apple notary service is an automated system that scans your software for malicious content, checks for code-si…

Yeah, the whole "there is no alternative to the App Store" argument completely falls apart in the face of the existence of the Mac, and how the Mac isn't constrained by the Mac App Store.

Re: A top-grossing scam on the App Store

#115
post #10

Earlier quoted context omitted.

You know, I was thinking last night about the parallels between this and the anti-trust investigation into Microsoft back in the 90s. Back then Microsoft was in a heap of trouble over the fact that they bundled IE and didn't allow vendors to bundle other alternative browsers. Users could still install other browsers, but the fact that the OS came bundled with IE was seen as an abuse of Microsoft's market position. Ye…

You said it yourself: > an abuse of Microsoft's market position Apple has no such market position to abuse. It's perfectly legal to put restrictions on your product. It's perfectly legal to be a monopoly. It's only a problem when you abuse your monopoly position to restrict competitors.

Do you actually believe this? I have a hard time thinking that anyone believes "Apple has no such market position to abuse.". It's absurd.

Re: A top-grossing scam on the App Store

#116

Earlier quoted context omitted.

> Google has an OS that is literally a browser engine It's not though. Chrome OS is literally Linux. You can install Firefox.

You may be able to install Firefox now, but originally it was literally a web-only affair. "Chrome OS is literally Linux" is about as accurate as "Android is literally Linux". Chrome OS is not just some rebadged Debian distro. Do all chromebooks support linux apps now? AFAIK that's not true, and only a subset of them support it.

Linux != a distro though.

Re: A top-grossing scam on the App Store

#117
post #108

Apple has just engineered the worst possible situation for themselves by being the only way to get apps on the store and by simultaneously incessantly marketing the store as "Safe and Secure". The former encourages them to maximize the number of apps on the store, while the latter encourages them to shoot first and ask questions later. If side-loading or alternative ways of getting apps onto the iPhone existed, then…

How would the security model work with side loaded apps. How would they get access to OS resources, services and share data with other apps, e.g through the clipboard? Who would verify them against malware, or ensure they didn’t violate security constraints? It’s not like Apple could disavow all responsibility for any data leaked from the system, a lot of users simply wouldn’t see it that way. There’s a lot wrong wit…

> How would they get access to OS resources, services and share data with other apps, e.g through the clipboard?

Through the same system APIs that exist right now. Why would that change?

> Who would verify them against malware

The distributor of the app, most likely. If you downloaded a game though Steam for iOS or whatever, and it had malware, that's Valve's fault.

If you went to virus.com and downloaded a virus, that's your problem.

> or ensure they didn’t violate security constraints?

You mean ensure they don't violate one of the operating system's security protections? That's called finding an exploit, and it's the developer of the operating system's responsibility. Exploits for iOS exist today, and they'll continue to exist in the future.

> It’s not like Apple could disavow all responsibility for any data leaked from the system, a lot of users simply wouldn’t see it that way

Of course not. A "leak" due to an exploit/vulnerability in iOS that Apple failed to patch would be their fault.

A third party app leaking personal info online would be the third party developer's fault. People didn't get pissed at Apple when Facebook leaked all that data a ~week ago.

> There’s a lot wrong with the current state of apps in the App Store, but right now at least I know who’s job it is to get it fixed.

It's their job to get it fixed. It's been their job for over 13 years, and they've failed at it again and again. It's about time they're fired.

Re: A top-grossing scam on the App Store

#118
post #112

Earlier quoted context omitted.

The real issue is that "AppStore" and "ContentFilter" are two orthogonal things (which Apple conflates). We can have multiple instances of both. And we probably should.

Yeah: and for anyone who doesn't immediately see how this is possible, a curator merely needs to have an allow/deny list of apps--possibly specific reviewed binaries--not actually host them or be the bottleneck for obtaining them: you just want the (hopefully federated) store app(s) to be able to refer to the (hopefully federated) curator(s) to limit the display and prevent installs.

Also, from my other comment, Apple could let us sideload notarized apps. This means:

- Automated scan for malware

- Remote kill switch, just in case

They already do this for macOS [1]:

> “Notarization is not App Review. The Apple notary service is an automated system that scans your software for malicious content, checks for code-signing issues, and returns the results to you quickly.”

They could give users a choice, much like they're doing with the new App Tracking Transparency prompt. But when pressed on why Apple should have control, Cook said "Somebody has to."

That's… not a very convincing argument.

[1]: https://developer.apple.com/documentation/xcode/notarizing_m...

Re: A top-grossing scam on the App Store

#119
post #21

Earlier quoted context omitted.

It's never been about quality. It's about control.

how did Nintendo save the video game market?

By killing competition and locking down their hardware so we couldn't get more open hardware? That's not "saving" anything but themselves.

Re: A top-grossing scam on the App Store

#120
post #62
post #5

So it's not just a scam, it's a scam pretending to be a medical app? The walled garden method has been proven a failure and needs to go urgently.

> So it's not just a scam, it's a scam pretending to be a medical app? The walled garden method has been proven a failure and needs to go urgently. It sounds like you are arguing that more medical scams would be better . App review fails sometimes, but removing it would be worse.

Who said remove them? Access to other app stores could just as easily let you pick one with more control and review instead of less. That should be up to the user. Not you, me or Apple.
Post reply on HN