Live data from Hacker News

App Store doesn't accept “too simple” apps

notes.alinpanaitiu.com

261–270 of 364 posts

Re: App Store doesn't accept “too simple” apps

#261

Earlier quoted context omitted.

I have my entire life in my phone: bank accounts, private keys/passwords/2fa/crypto, pictures/videos of personal life moments, messages between family/friends/business, etc. I want the "thing" that holds all this to be as closed and reliable as possible. I know that I can just simply not side load, but the smallest attack surface the better.

1. There are OSes that are “open” and still reliable. 2. OP was talking about loading apps on his/her OWN phone. Apple could offer some “OS variant” or some settings for people like OP while the default is closed for people like you. This doesn’t seem mutually exclusive technically — it’s probably just not in apple business best interests.

As past threads on this topic have shown, iPhone users prefer Apple be the controller of the device than the device owner itself. It is somehow understandable, but it is position I've often seen espoused.

Re: App Store doesn't accept “too simple” apps

#262

What really galls me, and I know I have ranted about this here before, is that you can't even really load an app ON YOUR OWN PHONE without paying for a developer account, not to mention that I can't side load something someone else made. I get that iPhones are nifty and all, but I don't see how people can spend that money on a device that locks the owner out of basic functionally. Android is not perfect, but at least…

I have my entire life in my phone: bank accounts, private keys/passwords/2fa/crypto, pictures/videos of personal life moments, messages between family/friends/business, etc. I want the "thing" that holds all this to be as closed and reliable as possible. I know that I can just simply not side load, but the smallest attack surface the better.

You can have those things while still being given an opportunity to generate your own executable signing key upon first boot of your device.

It's not increasing the surface area in terms of system complexity; the OS is already checking signatures to create this barrier to general purpose computing in the first place.

If you don't want the additional key, you skip the step, to be never asked again until you factory wipe+reset the device.

Your listed wants and the freedom to run your own software are not mutually exclusive.

Re: App Store doesn't accept “too simple” apps

#263

What really galls me, and I know I have ranted about this here before, is that you can't even really load an app ON YOUR OWN PHONE without paying for a developer account, not to mention that I can't side load something someone else made. I get that iPhones are nifty and all, but I don't see how people can spend that money on a device that locks the owner out of basic functionally. Android is not perfect, but at least…

I have my entire life in my phone: bank accounts, private keys/passwords/2fa/crypto, pictures/videos of personal life moments, messages between family/friends/business, etc. I want the "thing" that holds all this to be as closed and reliable as possible. I know that I can just simply not side load, but the smallest attack surface the better.

help me understand this better. you are afraid that someone may access your private content if Apple allows side loading of apps? How is it any different than what's on macOS today? you can run any apps (after clearing it in System preferences) on your laptop but suddenly it's a security risk on your phone?

Re: App Store doesn't accept “too simple” apps

#264
post #10

Apple, by walling their garden, have essentially used their hegemony to steal billions of dollars in potential revenue from developers. Think of how much innovation has been blocked by them intentionally gimping iOS Safari to prevent web apps from competing with native ones. Remember this when reviewing job applications, folks. Apple, Google, and Facebook employees, current and former, are morally derelict and have p…

I agree with your first paragraph. However, I can't agree with your second. Most people who work there are just regular people, they are not "morally derelict" sociopaths. Indeed, the main reason they work there is money and prestige, which is not necessarily a bad thing. Blame the executives who make the decisions, not the workers who implement them.

Would you say the same about workers at Philip Morris or Shell? If the money and prestige is ill-gotten, I’d say those workers are complicit.

Re: App Store doesn't accept “too simple” apps

#265
Weirdly a few years ago (7?) I made the most stupid app for a friend. The app was really bad and coded with my feet as I never did a mobile app. It was based on Ionic and just had one screen. It was a feeding calculator for horses for a brand of horse feeds. You input the weight of the animal, the age and it's level of activity and it calculated how much feed to give daily and what type of feed. The app was clunky, outright bad. It got approved on the first try. I was surprised.

Re: App Store doesn't accept “too simple” apps

#266
post #230

Earlier quoted context omitted.

Except what you just said isn't true. Yes, Apple charges for developer accounts that lets you publish to the AppStore or even privately. But you can get a free version that lets you push to devices locally. So if you want to distribute your app not in the store you can do so as long as you release the source so other people can build it on their free account.

When did they change that? When I stopped doing iOS dev on ~2017 it was still true that you had to pay to deploy to your own phone.

They definitely changed it before 2017. I know it existed in 2016, but I don't know how early they did it.

It wasn't (and isn't) well publicized. But "side load to your phone is hard" is a way to lock it away from your grandparents and to power users only.

Re: App Store doesn't accept “too simple” apps

#267

Earlier quoted context omitted.

I have my entire life in my phone: bank accounts, private keys/passwords/2fa/crypto, pictures/videos of personal life moments, messages between family/friends/business, etc. I want the "thing" that holds all this to be as closed and reliable as possible. I know that I can just simply not side load, but the smallest attack surface the better.

help me understand this better. you are afraid that someone may access your private content if Apple allows side loading of apps? How is it any different than what's on macOS today? you can run any apps (after clearing it in System preferences) on your laptop but suddenly it's a security risk on your phone?

Whether you believe it or not, most people have sensitive information on their phone and not their ‘computer’ (I guess a desktop thing, if they have one!).

For most people, they couldn’t care what happens to their computer. Not everyone is the same, but it’s not an uncommon situation.

So security for the phone is more important for some people than computer security.

Re: App Store doesn't accept “too simple” apps

#268

Earlier quoted context omitted.

1. There are OSes that are “open” and still reliable. 2. OP was talking about loading apps on his/her OWN phone. Apple could offer some “OS variant” or some settings for people like OP while the default is closed for people like you. This doesn’t seem mutually exclusive technically — it’s probably just not in apple business best interests.

As past threads on this topic have shown, iPhone users prefer Apple be the controller of the device than the device owner itself. It is somehow understandable, but it is position I've often seen espoused.

Interesting. I understand what’s in it for Apple; but I don’t understand what’s in it for users? People can have their cake and eat it (i.e: a closed ecosystem with strong security and reliability guarantees but we let you leave for more freedom, but we promise you very little)

Re: App Store doesn't accept “too simple” apps

#269
post #230

Earlier quoted context omitted.

Except what you just said isn't true. Yes, Apple charges for developer accounts that lets you publish to the AppStore or even privately. But you can get a free version that lets you push to devices locally. So if you want to distribute your app not in the store you can do so as long as you release the source so other people can build it on their free account.

Do these side loaded installs expire or work indefinitely?

I have an app that I've now installed on 3 different cell phones as I've upgraded them over the years. It was given to me by the writer for feedback and comments, but then their professional life became such that they never finalized the app.

Thing is, I use the app a lot. It's very unique and has no competition because it fills an extremely narrow niche. Side loading it has worked for several years on several increasingly newer phones.

I'm not sure if that's exactly what your question is about, but I think it might be.

When we reach 128-bit architecture, that app will fail. But I don't expect that to happen any time soon.

Re: App Store doesn't accept “too simple” apps

#270

What really galls me, and I know I have ranted about this here before, is that you can't even really load an app ON YOUR OWN PHONE without paying for a developer account, not to mention that I can't side load something someone else made. I get that iPhones are nifty and all, but I don't see how people can spend that money on a device that locks the owner out of basic functionally. Android is not perfect, but at least…

I have my entire life in my phone: bank accounts, private keys/passwords/2fa/crypto, pictures/videos of personal life moments, messages between family/friends/business, etc. I want the "thing" that holds all this to be as closed and reliable as possible. I know that I can just simply not side load, but the smallest attack surface the better.

> I have my entire life in my phone...

And that is precisely why you need control of your device, and not hand it over to some third-party, especially a corporate who has a vested interest to make as much money as possible from you, with the very data that you seek to protect! Would you really even be happy if some other third-party, like your government, took over this role of acting as your device's protectorate and let them decide on locking / controlling your device to "protect" you?

This argument of "it's for your own good, because people are stupid" is quite weak even if we ignore how this so called "high security" offered by locking down hasn't prevented new jailbreaking techniques to keep surfacing. If you understand security concepts and attack surfaces, then you do know there are technical ways to lock down a device and still give complete control over this to the user.

Apple today has the ability to remote delete and wipe out all your personal data and lock you out of your device. There are no laws or regulations to prevent this. How is that in any way acceptable?

Post reply on HN