Live data from Hacker News

Apple’s tightly controlled App Store is teeming with scams

washingtonpost.com

201–210 of 261 posts

Re: Apple’s tightly controlled App Store is teeming with scams

#201

Earlier quoted context omitted.

Yes and likewise, car manufacturers should remove seatbelts and airbags. They simply encourage reckless driving, and by giving the false sense of security / assuming the gatekeeper role, they should be liable for any accident.

Weird, I can flash whatever code I want to on my car's ECU. There's even an entire subculture dedicated to modding ECU firmware.

Flashing your car's ECU is illegal. Or more specifically, federal and state laws make it illegal to operate an automobile on the open road or highway after you've altered a vehicle's emission control devices (which includes the ECU).

In contrast, it's legal to jailbreak an iPhone.

Re: Apple’s tightly controlled App Store is teeming with scams

#202

Earlier quoted context omitted.

> I'm not blaming Apple for not stopping these scams Why not? You should blame them. They have positioned themselves as the gatekeepers. Why? To extract profit from application developers. However, such a powerful position also comes with expectations and responsibilities. They should absolutely not be allowed to get away with gross negligence. We absolutely must blame them every single time they fail to keep malicio…

I agree, I think they should help him, but I also think it would open a whole can of worms. The fact is, no matter how much time/energy/effort they spend, they will never eliminate all scams, scams would just become more and more sophisticated. This doesn't mean, they should just give up, but having been through the review process, they are already doing quite a bit. So that would mean, they will make it much harder…

> they are already doing quite a bit.

They must be focusing on the wrong things then. Certain categories are filled with scam apps at the top ranks, including scam subscriptions.

Re: Apple’s tightly controlled App Store is teeming with scams

#203

Earlier quoted context omitted.

The reason I disagree with this argument is that it boils down to "tons of scams are better than a few sophisticated scams because users are more wary." Users themselves have various levels of sophistication, and unsophisticated scams have plenty of victims.

The only reason I disagree with your disagreement is because Apple is making money here, and they have every incentive to turn the other cheek. Their entire business model is based on driving user interaction and spending, so I don't think they're the most trustworthy party to audit the App Store. That would be like if we let the President decide which news channels were allowed to broadcast at the beginning of their…

Apple doesn’t make money from free apps, so they have no financial incentive to turn the other cheek with respect to them.

Re: Apple’s tightly controlled App Store is teeming with scams

#204

Earlier quoted context omitted.

That's a strawman. I'm not criticizing Android here, we're talking about Apple's responsibility to the consumer. As someone who owns several Apple devices, I can truly and honestly say that my life would be unequivocally better if I could install custom IPAs to my phone. Furthermore, Apple trusts the user to decide if Facebook can steal their data: why can't they trust the user to install third party apps? If they do…

They don't trust their users to not install pirated apps. It's part of their revenue scheme - if you could install third party IPAs, you could download cracked versions of Apple Arcade apps or apps that bypass the in-app purchase system and don't give apple their 30% cut of digital content. It's the same reason Xbox and Sony restrict you to their stores, Apple's revenue model is just set up to extract more money over…

Just to be clear about your argument, you’re saying that’s a bad thing? Is it wrong for a company to protect revenue—and remember 70% of revenue goes to the developer—from loss due to piracy?

There are plenty of valid reasons to object to Apple’s revenue model, but the avoidance of piracy seems like a bridge too far.

Re: Apple’s tightly controlled App Store is teeming with scams

#205

Earlier quoted context omitted.

If Apple gave up the gatekeeping position, I would be afraid to use my phone for the things I do today.

Why aren't you afraid today? Their gatekeeping is clearly useless.

Something does not have to be perfect to be useful; a filter that throws out 50% or 90% of malicious trash is very useful even if a lot of malicious trash gets through.

The appropriate metric for safety of an app store is not whether you can get attacked, but rather how many users - proportional to all users - get attacked every year.

Re: Apple’s tightly controlled App Store is teeming with scams

#206

Earlier quoted context omitted.

The real solution I see would be to charge money for listing apps in the store. And not small money, but significant, non-refundable fees. Enough to actually check and verify the software by competent humans and also just to make scams more expensive (you would need to pay $5-10k upfront, like Google requires for certain Gmail apps). But I don’t like that kind of approach, so therefore I would be careful in demanding…

A solution is to make systems secure enough that any user-level code or app either can't do malicious things, or needs to be explicitly granted fine-grained permissions to access a user's resources. Sandboxing is a step in the right direction, as are various levels of things like code signing and even Windows Defender-esque systems that maintain lists of known malicious apps, authors etc and prevent them from running…

So… your solution is no mobile wallets, then?

Re: Apple’s tightly controlled App Store is teeming with scams

#207

Earlier quoted context omitted.

> I'm not blaming Apple for not stopping these scams Why not? You should blame them. They have positioned themselves as the gatekeepers. Why? To extract profit from application developers. However, such a powerful position also comes with expectations and responsibilities. They should absolutely not be allowed to get away with gross negligence. We absolutely must blame them every single time they fail to keep malicio…

I agree, I think they should help him, but I also think it would open a whole can of worms. The fact is, no matter how much time/energy/effort they spend, they will never eliminate all scams, scams would just become more and more sophisticated. This doesn't mean, they should just give up, but having been through the review process, they are already doing quite a bit. So that would mean, they will make it much harder…

I think what Apple _could_ do is insure that there is a real person that can be held accountable by law enforcement in the users jurisdiction. That way a user has some legal recourse in the event they are wronged.

Nobody wants Apple to be judge and jury, we have judges and juries for that, but it would be nice if they could tell us who to go after when we have to.

If they can't do that, I don't think its unreasonable for us to ask Apple to be responsible any losses, then let Apple seek compensation for their losses from the app publisher.

Re: Apple’s tightly controlled App Store is teeming with scams

#208

Earlier quoted context omitted.

Yes and likewise, car manufacturers should remove seatbelts and airbags. They simply encourage reckless driving, and by giving the false sense of security / assuming the gatekeeper role, they should be liable for any accident.

The big difference between "Apple's app review process" and "seatbelts and airbags" is that car companies acknowledge the latter are fallible. It's not about adding layers of protection or not; it's about being transparent with your customers about how effective those layers actually are.

I don’t think any one of my less technical friends has any belief that the App Store is infallible or even mostly secure. Apple doesn’t advertise it much, and if they did I’d be happy to call that a mistake.

Re: Apple’s tightly controlled App Store is teeming with scams

#209

Earlier quoted context omitted.

I have sympathy for the person in this story, but I think shifting the blame to Apple in this case is ludicrous. I'm still somewhat shaking my head that someone went through all of the trouble of using a hardware wallet, and then entered his key words into the first app he downloaded. If anything I think this story is just a prime example of why irreversible crypto transactions are an absolute nightmare for the gener…

The issue here is that Apple is facilitating wire fraud, which is extremely illegal in the United States. The bad actors who created that app are committing wire fraud on an Apple platform, which is of course colloquially known as the App Store. The problem is that if you are associated with a crime committed in the United States in any way (besides being a very distant third-person witness with no associations whats…

> The issue here is that Apple is facilitating wire fraud

Not just facilitating. They get 30% for it.

Re: Apple’s tightly controlled App Store is teeming with scams

#210

Earlier quoted context omitted.

I have sympathy for the person in this story, but I think shifting the blame to Apple in this case is ludicrous. I'm still somewhat shaking my head that someone went through all of the trouble of using a hardware wallet, and then entered his key words into the first app he downloaded. If anything I think this story is just a prime example of why irreversible crypto transactions are an absolute nightmare for the gener…

There is a well established principle that retailers bear some responsibility for what they sell. I doubt Home Depot would get away without liability if they sold a dryer that caught on fire and burned down a house if it was found they had acquired the dryer from a dodgy criminal syndicate.

That’s an interesting parallel, while Home Depot buys their product, in a market place it works differently. As of now Amazon for instance bears no responsibility of what happens with the vendor’s product as long as they have plausible deniability (“paperwork looked good”).

That’s exacerbated when products are counterfeits and legit brands get pissed off, but it would got the same for unsafe products as well I’d guess.

Amazon getting their provisions corrected could make a positive precedent for digital goods as well.

Post reply on HN