Live data from Hacker News

iOS 17 app sideloading might only be available in Europe

techradar.com

101–110 of 1001 posts

Re: iOS 17 app sideloading might only be available in Europe

#101

Earlier quoted context omitted.

iPhones been hacked for ages already.

Perhaps "has it ever been hacked" is not the best metric, unless you prefer to keep your devices under armed guard, encased in several meters of concrete, without an internet connection. IMO, https://zerodium.com/program.html is a good indication of "what would it cost to hack me using a never-before-seen exploit".

You wrongly assumed that zero days are single-use. Pegasus used the same exploits in dozens or hundreds of targets.

Re: iOS 17 app sideloading might only be available in Europe

#102
post #85

I wonder if they considered an "iPhone Europe Edition" - USB-C, side loading, physical SIM cards. Sounds like a good phone!

What’s good about physical SIMs? I do like apple for daring to improve the status quo there, so I want my European Edition with only e-simsz

That I can just take the SIM out and put it in a different phone?

what's the migration process for eSIMs?

Re: iOS 17 app sideloading might only be available in Europe

#103

Earlier quoted context omitted.

The App Store is a poor line of defense, because it isn't about user security, it's about securing Apple's billion dollar app distribution monopoly moneyhose. User security is just a rhetorical afterthought. When we forgo real system safety in favor of gatekeeping corporate revenue, that isn't security. In fact, such a scheme is responsible for mass distribution of malware. Apple's App Store is responsible for distri…

As a further separate but distinct response: You are justifying why a monopoly app store is bad by showing a hack that resulted from downloading an app (xcode) from a source other than the app store. Security firm Palo Alto Networks surmised that because network speeds were slower in China, developers in the country looked for local copies of the Apple Xcode development environment, and encountered altered versions t…

This just shows that the App Store model is insufficient for user security, as the the security model was supposed to prevent malware from being distributed to users in the first place, no matter what malicious developers upload to the App Store. If Apple treats Xcode as App Store blessed because it believes it came from blessed sources like the App Store, instead of using real security measures, exploits will continue to be shipped to users. Similarly, if OSes don't implement real security that's independent of the App Store model, users will continue to be exploited in this way.

> I think you are also ignoring that apples app store position made it possible to authoritatively reach out to all who were effected as well as enact other remediation efforts.

Microsoft is able to do the same thing with Windows Defender without using the App Store model at all.

Re: iOS 17 app sideloading might only be available in Europe

#104

Earlier quoted context omitted.

Actually, in a way, it is. All Microsoft has to do is revoke your application's signing certificate and Windows Defender will prevent it from running on Windows computers. Apple does the same thing with Notarization and Gatekeeper on macOS. If they choose to revoke your signing certificate, Gatekeeper will prevent your software from running on macOS. That means if you do, say or compete with something that Microsoft…

You can just turn off defender. And being specifically put in the malware list isn't the same and if clearly false could be used in court.

Stuff like this happens, and it tends to not get legal attention: https://news.ycombinator.com/item?id=27914752

I learned long ago, and keep it clearly in my mind, that what AV considers "malware" and what the user considers malware are not entirely the same.

and if clearly false could be used in court.

I do wonder if Windows becoming adware, but then the built-in antimalware detecting possible "competitors'" adware and removing it, could be challenged in court as anticompetitive behaviour.

Re: iOS 17 app sideloading might only be available in Europe

#105
post #47

Even if this is small progress the headlines and framing of the story are still doublespeak. Installing applications on your computer is the normal state of things. Walled gardens and not having control of your computer is the new weird thing. The word "sideloading" is a feudal concept and it's unquestioned use is dangerous for society. Properly stated this story title is, "Installing applications on iOS 17 might be…

I used to think the same way, but not anymore. The amount and variety of attacks on the devices have increased too much in the last years. The device could be encrypted, money could be stolen, some malware could sit silently and do surveillance for who knows. I always wanted to install software on my iPhone without the manufacturing company deciding what I can and can not have (according to californian standards!), b…

I used to think that way, but then I realized the Android/iOS stores are absolute cesspools. I would not trust young kids on there either.

Others are right, sandboxing is the real saving grace (and only if apps dont ask for a bajillion permissions which users will just click through so it will work). Apple is slowly trying to isolate apps even more, like they were in the early iOS days.

Re: iOS 17 app sideloading might only be available in Europe

#106

Even if this is small progress the headlines and framing of the story are still doublespeak. Installing applications on your computer is the normal state of things. Walled gardens and not having control of your computer is the new weird thing. The word "sideloading" is a feudal concept and it's unquestioned use is dangerous for society. Properly stated this story title is, "Installing applications on iOS 17 might be…

From a personal-computer-user point of view, installing an app from any source is normal.

For pre-iPhone cellphone users, your cellphone network operator controlled access to what apps were available for installation. This is was the most common, if not the only, method for cellphone app distribution. App makers (mostly java games) paid to get on that first page of downloadable apps. I'd add some references but Google seems to have amnesia about anything cellphone app distribution pre-iPhone.

Apple didn't have an app store initially. How Apple convinced cellphone network operators to cede app approval/control, I don't know. Perhaps it was "apple's way - take it or leave it".

Re: iOS 17 app sideloading might only be available in Europe

#107
post #85

Earlier quoted context omitted.

What’s good about physical SIMs? I do like apple for daring to improve the status quo there, so I want my European Edition with only e-simsz

That I can just take the SIM out and put it in a different phone? what's the migration process for eSIMs?

You need the carrier to offer eSIM, of course, but then you can just store a bunch of eSIMs on your iPhone and switch which one is active in the Settings app.

Re: iOS 17 app sideloading might only be available in Europe

#108
post #33

Duh? The EU has no jurisdiction over the US. So there will be no legal need for Apple to allow it here. Just like they don’t allow alternate payment methods for dating apps in the US like some other countries required and Apple had to comply with. The App Store is too critical to the way Apple sees things, they’re not going to just say “oh well”. I bet things are only open for EU residents with EU purchased phones. B…

> there will be no legal need for Apple to allow it here. The point is that since Apple had to do the work to allow sideloading at all, most if not all of the lies they came up with for why they can't allow it for everyone won't work anymore.

I don’t believe they ever claimed that it was not possible. The position has always been that it is a compromise in security controls. The counter position to that has never been that it is not a compromise in security controls. I only hope they continue to sell devices that don’t allow it, because that’s what I would choose every time, unless that choice is taken away from me.

Re: iOS 17 app sideloading might only be available in Europe

#109
post #62

Earlier quoted context omitted.

This is incorrect. Apple doesn’t force you to buy iphone, and there is plenty of alternatives. Personally, I’d like to take full control over my iphone. And create apps for myself the way I see fit. But I’m afraid that with sideloading allowed, most software vendors will go sideloading-only. That means, nobody will have any control over their app’s privilege requests, behavior and other security related things. Basic…

> But I’m afraid that with sideloading allowed, most software vendors will go sideloading-only. That means, nobody will have any control over their app’s privilege requests, behavior and other security related things. There is no reason why side-loading means "not sandboxed". Apps still need to use Apple SDKs to interface with the OS, so there is still an opportunity to request permissions and for the user to deny pe…

…and for an app to refuse to work without this irrelevant permission. This is my exact experience with an android phone and a quest of searching a ruler app. Ended up on lifehacker and a direct link to the app. Play store only suggested the most dark patterned apps in existence.
Post reply on HN