Live data from Hacker News

Apple’s tightly controlled App Store is teeming with scams

washingtonpost.com

221–230 of 261 posts

Re: Apple’s tightly controlled App Store is teeming with scams

#221

Earlier quoted context omitted.

They don't trust their users to not install pirated apps. It's part of their revenue scheme - if you could install third party IPAs, you could download cracked versions of Apple Arcade apps or apps that bypass the in-app purchase system and don't give apple their 30% cut of digital content. It's the same reason Xbox and Sony restrict you to their stores, Apple's revenue model is just set up to extract more money over…

Just to be clear about your argument, you’re saying that’s a bad thing? Is it wrong for a company to protect revenue—and remember 70% of revenue goes to the developer—from loss due to piracy? There are plenty of valid reasons to object to Apple’s revenue model, but the avoidance of piracy seems like a bridge too far.

I'm saying that's how it is, I agree with you on that Apple should be allowed to do this to protect their revenue model, even if it comes at the expense of users not being able to run unsigned code/other app stores on iOS.

Re: Apple’s tightly controlled App Store is teeming with scams

#222

Apple themselves seem to be intentionally breaking the App Store at times. From the article: > Apple used to have a button [1], just under the ratings and reviews section in the App Store, that said “report a problem,” which allowed users to report inappropriate apps. Based on discussions among Apple customers on Apple’s own website [2], the feature was removed some time around 2016. Why would they remove the ability…

Not sure about other newer "force-touch" devices but on my iPhone 6s (which is running the latest iOS 14.6), I am able to force touch a review and get a "Report concern" option along with "Helpful"/"Not-helpful":

https://i.imgur.com/gaLH26P.png

Tapping the report concern option gives me ability to report it:

https://i.imgur.com/JHLC4Hp.png

I am curious if the newer devices are able to long press a review to get the same option.

Also not sure if something similar is available for apps?

Re: Apple’s tightly controlled App Store is teeming with scams

#223

Earlier quoted context omitted.

The issue here is that Apple is facilitating wire fraud, which is extremely illegal in the United States. The bad actors who created that app are committing wire fraud on an Apple platform, which is of course colloquially known as the App Store. The problem is that if you are associated with a crime committed in the United States in any way (besides being a very distant third-person witness with no associations whats…

> The issue here is that Apple is facilitating wire fraud Not just facilitating. They get 30% for it.

Yes, except this scam app was free. Apple earned 30% of $0.

Re: Apple’s tightly controlled App Store is teeming with scams

#224

Earlier quoted context omitted.

Privacy and security are not the same thing. Also, an app can follow all the privacy and security guidelines and still use dark patterns to mislead and get something from you that you wouldn’t otherwise give up or outright defraud you. I’m sure Apple makes a good faith attempt at preventing that as well but they can’t catch everything.

The words "strict" and "rigorous" do a lot of heavy lifting in setting user (and market) expectations. We programmers are pre-inclined to think in terms of Boolean logic, but the law frequently splits hairs on qualitative value judgments; there is no simple rubric for what counts as "reckless endangerment" or "gross negligence", for instance. I think it's a given that no one expects any QA or security process to perf…

In my opinion, this anecdote is enough reason for Apple to reject any app that purports to be a cryptocurrency wallet or in any way be a secure mechanism for cryptocurrency. There's no practical way for Apple to prove that any app won't betray the user.

Or in the alternative, Perhaps Apple should create a different tier of app review for any apps which claim to facilitate financial transactions (other than purchases, game currencies and microtransactions). This would encompass all apps for banking, investment and crypto. This tier should require a much higher verification of the developer's identity. The iOS sandbox should be further locked down to limit communication only to whitelisted IPs/domains which must all be under the control of the verified developer. And hey, you know what, let's even require the developer to submit the app in source code form.

Re: Apple’s tightly controlled App Store is teeming with scams

#225

Earlier quoted context omitted.

Why aren't you afraid today? Their gatekeeping is clearly useless.

> Why aren't you afraid today? Their gatekeeping is clearly useless. You're not perfect at anything you do. Does that make you useless? Of course not.

> You're not perfect at anything you do. Does that make you useless?

As a gatekeeper? Yes, yes it does; hence why there shouldn't be any gatekeepers.

Re: Apple’s tightly controlled App Store is teeming with scams

#226

Some relevant Apple marketing statements [1]: "The apps you love. From a place you can trust." "For over a decade, the App Store has proved to be a safe and trusted place to discover and download apps." "Every day, moderators review worldwide App Store charts for quality and accuracy.” "Dedicated to trust and safety.” "Apps must adhere to our guidelines.” "From more videos to rankings and reviews, there are loads of…

So does that mean that you can sue Apple if an app fails at any of these? Of course not, because lying for Apple is common business practice nowadays.

> because lying for Apple is common business practice nowadays.

To be scrupulouly fair, the "for Apple" is 100% redundant.

Re: Apple’s tightly controlled App Store is teeming with scams

#227

Earlier quoted context omitted.

There is a well established principle that retailers bear some responsibility for what they sell. I doubt Home Depot would get away without liability if they sold a dryer that caught on fire and burned down a house if it was found they had acquired the dryer from a dodgy criminal syndicate.

That’s an interesting parallel, while Home Depot buys their product, in a market place it works differently. As of now Amazon for instance bears no responsibility of what happens with the vendor’s product as long as they have plausible deniability (“paperwork looked good”). That’s exacerbated when products are counterfeits and legit brands get pissed off, but it would got the same for unsafe products as well I’d gues…

I feel like the difference should be that if you are merely providing a market, then the customer must "belong to" to vendor: at bare minimum, the vendor must know who they are; Apple, however, insists that the customer belongs to them, that the vendor will learn nothing about the customer, and that the vendor is merely providing software to Apple under a license that allows Apple to sell copies of it to their customers... they absolutely should have full responsibility for the things they choose to sell in this scenario. Apple also certainly isn't just checking "does the paperwork look good": they are carefully examining the product, vetting it, and then claiming on their website and in all their marketing materials that customers can feel safe using all of the apps they sell because of this curation, for which they take a handsome cut of the profits. It is all simply ridiculous, really.

Re: Apple’s tightly controlled App Store is teeming with scams

#228

Earlier quoted context omitted.

Disagree, they seem very reasonable. But also no one is reading those terms really, they aren’t being pushed in ads or shown at the store.

Do you have any ties to Apple? That is the most ridiculous implication. 'We did not expect anyone to read the terms of the product, so we shouldn't have to deliver on what we promised.' That is not resonable. Apple is using weezle-words like "should" which gives them wiggle room, but I guess it will be up to a court to decide.

I have no ties, other than owning a few of their devices. I think you should up your prior that there exist people who generally think this is ok.

I think about 0 out of the first 100 people I know that I think of have heard any version of those claims (maybe 5 now since a few read HN). It’s probably not even a top 10,000 trafficked page on their site.

Do you have any ties against apple or for a competitor?

Re: Apple’s tightly controlled App Store is teeming with scams

#229

Earlier quoted context omitted.

> The issue here is that Apple is facilitating wire fraud Not just facilitating. They get 30% for it.

Yes, except this scam app was free. Apple earned 30% of $0.

Nopes, they also earn $99 / year - https://developer.apple.com/support/purchase-activation/ ...

Re: Apple’s tightly controlled App Store is teeming with scams

#230
post #2

The worst thing is, people have this belief that Apple is somehow protecting them, so they offload the critical thinking to Apple and lower their own guards. For example, a person thought he was getting a legitimate Bitcoin wallet app, but turns out it was a fake and he lost his life savings [1]. edit: to be clear, I'm not blaming Apple for not stopping these scams, at their scale, it's just practically impossible to…

This makes me wonder, can such thieves easily convert the stolen Bitcoin or are these blacklisted everywhere?

The whole idea behind crypto currencies is that there is no central authority behind it. And so there is no blacklist / whitelist because you need such an authority, trusted by everyone, to create such a list.

All cryptocurrency transfers (between digital wallets) are recorded in a public ledger (the blockchain).

Anybody can read it. But only those with the correct encryption keys to a wallet can write to it (add a record). Once someone steals the encryption key of your wallet A, it can be used to access your wallet and add a record to the public ledger that all the cryptocurrency of wallet A has been transferred to wallet B. This record cannot be changed by anyone.

But since every transaction on the ledger is a public record that anyone can read, one can theoretically track where the cryptocurrency goes from one wallet to another. This can be used to catch a thief by the police. Anyone can create a digital wallet anonymously, but to convert it into real currency you need to provide your real life identity and bank account to a crypto-exchange. This is the point where someone becomes exposed and loses their anonymity, and hence can be identified by the law.

Post reply on HN