Live data from Hacker News

Apple’s tightly controlled App Store is teeming with scams

washingtonpost.com

241–250 of 261 posts

Re: Apple’s tightly controlled App Store is teeming with scams

#241

Earlier quoted context omitted.

Something does not have to be perfect to be useful; a filter that throws out 50% or 90% of malicious trash is very useful even if a lot of malicious trash gets through. The appropriate metric for safety of an app store is not whether you can get attacked, but rather how many users - proportional to all users - get attacked every year.

This filter is useless and misleading. Compare to F-Droid or GNU/Linux repositories.

So why would someone release malware in f-droid, when the user base is not your average joe and would likely know how to counter or detect any attacks?

This is the second person in this thread to think using an open source repo as an example carries weight. There are less users, therefore less malware is released here in the first place and then there’s less load for the malware filters for that that does get through.

Re: Apple’s tightly controlled App Store is teeming with scams

#242

Earlier quoted context omitted.

> Why aren't you afraid today? Their gatekeeping is clearly useless. You're not perfect at anything you do. Does that make you useless? Of course not.

That's why I don't gatekeep anyone.

So if we followed this logic, and reversed everything that wasn’t 100% perfect, so you realize how far back in human history we’d be propelling ourselves? There is not a single gov program, law, corp, anything on this planet that is perfect, except maybe the planet itself.

Re: Apple’s tightly controlled App Store is teeming with scams

#243

Earlier quoted context omitted.

Their PR lets them have it both ways.

Their users too, as shown in every other comment here.

So, enlighten me, how does another app store increase safety if Apple is writing the APIs used by the other app stores? clearly it doesn’t, it just provides options for more of the same. so then I wonder what the point to all of this is, and the only idea that comes to mind is a bunch of tech savvy android users really want to use iphone but can’t/won’t until there’s additional gatekeepers, err i mean app stores.

Re: Apple’s tightly controlled App Store is teeming with scams

#244

Earlier quoted context omitted.

The problem isn't that Apple should be responsible and isn't, the problem is Apple is extremely paternalistic but in a way where it gets all the powers but skirts all the responsibilities. If the responsibility is too impossible (and I'm fine saying that it is), then their paternalism shouldn't be called out and their reputation knocked down a rung or two. Instead, they get to keep a reputation which is far better th…

> their paternalism shouldn't be called out Totally off topic: that phrasing made my brain skip a beat. I've always seen "called out" used to convey confrontation, especially in a public manner like "He called out Apple on Twitter for their paternalism." Turns out a similarly common use is the more general "to bring attention to" in a positive way.

No I just meant "should" and wrote the exact opposite! :(

Re: Apple’s tightly controlled App Store is teeming with scams

#245

Earlier quoted context omitted.

The problem isn't that Apple should be responsible and isn't, the problem is Apple is extremely paternalistic but in a way where it gets all the powers but skirts all the responsibilities. If the responsibility is too impossible (and I'm fine saying that it is), then their paternalism shouldn't be called out and their reputation knocked down a rung or two. Instead, they get to keep a reputation which is far better th…

> Instead, they get to keep a reputation which is far better than the other megacorps'. I think this is what having strong marketing gets you. You can see from the defence on HN/Twitter where most people would be fine with Apple having a control over all their devices and aren't afraid of the growing dominance of a single company.

https://locusmag.com/2021/01/cory-doctorow-neofeudalism-and-... is a sad example where Cory only points out Apple nefariously undermining the guarantees, as opposed to shear technical failure not intended to appease anyone.

Re: Apple’s tightly controlled App Store is teeming with scams

#246

Earlier quoted context omitted.

Nopes, they also earn $99 / year - https://developer.apple.com/support/purchase-activation/ ...

Of course, but I was responding to the specific claim that Apple "gets 30% for it." Arguing about the $99/year developer fee is a pointless rabbit hole. You might as well also accuse Apple of selling the developers an iPhone and a Mac for developing the scam app. And then don't forget to accuse the electrical grid operator of selling electricity to the scammers.

    Arguing about the $99/year developer fee is a pointless rabbit hole.
No, it isn't - till Apple instituted this practice developers never paid any company for the privilege of creating software and adding value to their platform. Whether the app is free or paid, Apple still makes money when a developer wants to distribute the app on their platform and this acts as another incentive for them to be lax.

Re: Apple’s tightly controlled App Store is teeming with scams

#247

Earlier quoted context omitted.

> I'm not blaming Apple for not stopping these scams Why not? You should blame them. They have positioned themselves as the gatekeepers. Why? To extract profit from application developers. However, such a powerful position also comes with expectations and responsibilities. They should absolutely not be allowed to get away with gross negligence. We absolutely must blame them every single time they fail to keep malicio…

I agree, I think they should help him, but I also think it would open a whole can of worms. The fact is, no matter how much time/energy/effort they spend, they will never eliminate all scams, scams would just become more and more sophisticated. This doesn't mean, they should just give up, but having been through the review process, they are already doing quite a bit. So that would mean, they will make it much harder…

Censorship is also easier when you have an AI to blame the "mistake" on.

Re: Apple’s tightly controlled App Store is teeming with scams

#248

Earlier quoted context omitted.

Nah. If you're gonna set yourself up as the ultimate arbiter of what I can run on my device, you are absolutely to blame for any harm that comes as a result. Protections? Encryption is protection. Address space randomization is protection. This Apple review process? This is just humans failing to do what's expected of them. Also known as negligence.

there’s a lot of faulting apple here, when you point out it’s a “humans failing”. Does this mean you understand the process completely and you can do better?

Probably not,

which is why he hasn't placed himself in the position of "arbiter of what's right and wrong on phones", the way Apple has with their App Store.

Re: Apple’s tightly controlled App Store is teeming with scams

#249

Earlier quoted context omitted.

This filter is useless and misleading. Compare to F-Droid or GNU/Linux repositories.

So why would someone release malware in f-droid, when the user base is not your average joe and would likely know how to counter or detect any attacks? This is the second person in this thread to think using an open source repo as an example carries weight. There are less users, therefore less malware is released here in the first place and then there’s less load for the malware filters for that that does get through…

Your argument does not hold for GNU/Linux repositories. There are plenty of good targets there.

Re: Apple’s tightly controlled App Store is teeming with scams

#250
I remember how one person spent just a little time and uncovered one scam after another. It wasn’t even necessary to dig deep in every case (e.g. sometimes it was just “look at top grossing charts”). That is why almost any excuse Apple gives is just not good enough: clearly if Apple had even one person working on this full-time, they should have caught this. Who cares about fancy analysis tools or machine learning until they can catch the big, obvious stuff?

We also know from trial documents that they decided ~500ish people was enough to review the millions of apps and app revisions in existence. I don’t even have to do the math and I know that is nowhere near sufficient. Apple clearly is either clueless about this, or does not care, and either one of those is a huge problem. It also means that almost everything they claim about the security of the App Store itself is not true (rather, a substantial portion of the security comes from the OS and device, not necessarily the review).

Post reply on HN