[flagged]
Meanwhile, Apple is likely still going to require sideloading to have a valid Notary certificate, which is bound to a root CA, meaning that Apple can handle some amount of validation of certificates and revocations.
311–320 of 1001 posts
[flagged]
Meanwhile, Apple is likely still going to require sideloading to have a valid Notary certificate, which is bound to a root CA, meaning that Apple can handle some amount of validation of certificates and revocations.
Apple being motivated by improving security are BS, and it pains me te see people in this forum falling for it or reapeating this. There is a great tool to increase security: the browser and its sandbox. You don't need to install anything fishy on your phone, and the sandbox rights coukd be sufficient for many apps. But as an example, Apple denies the full screen feature for websites and even PWA... only installed on…
Earlier quoted context omitted.
Can't the banks implement some measures so that only their own apps can do transactions?
Believe me they’re trying. They’re now mandating biometric authentication, and I don’t mean on device, I mean implemented by the banks app / backend. If you read the articles you’ll see. Each year the central banks up the ante on security protocols to implement to stop the fraud. I should know I used to work for a finance app here in Thailand. We have to go through strict security audits, and procedures that costs a…
Guess what happens currently on iOS instead? Instead of installing a custom app, you are sent a link to log in to a dodgy bank page with all your details with the exact same result.
>>Disabling sideloading reduces so much costs downstream and made things simple and secure for the lay man.
I don't believe this is the case, and I really believe any arguments otherwise are made in bad faith to maintain the status quo because obviously apple could never do any wrong.
[flagged]
> Most of the cases are found to be on android devices. Do you have some relevant sources about banking fraud? Android devices make up more than 70% of Thailand's market share [0], so it's not a surprise. [0] https://www.statista.com/statistics/814490/market-share-mobi...
Also, the government mentions that the scams affect users of both platforms, because the scams propagate via calls, web links and emails that ask for personal information[2].
[1] https://www.bangkokpost.com/tech/2487659/phone-users-warned-...
[2] https://www.bangkokpost.com/business/2499931/online-scammers...
Ingenious! What if a security incident happens just in Europe but not elsewhere? Then it becomes instantly clear that Apple’s argument against sideloading was not a strawman.
Earlier quoted context omitted.
Or usability of this feature would be so frustrating, that no one will use. Constant security popups on every start, very limited available API for apps, etc...
There is law and there is the spirit of the law. The ECJ can be pretty fast when they feel someone is taking the piss.
[flagged]
No. Preventing people from doing something "for their own good" is never the right solution. Instead, we should strive to educate people on proper online safety measures so that they don't fall victim to fraudulent attempts.
Sometimes it's a good idea to don't let people do something for their own good.
Hasn't Apple always said the reason they don't allow sideloading was that it'd be impossible without compromising security? So are they claiming their European iDevices won't be secure anymore, or are they admitting they were lying before and that the real reason was nothing but greed?
How they will do it likely is they will charge to install the App store app and assign it a CA and require it to sign the apps downloaded from that app store. The sideloading of apps will technically be an apple approved app but enforced by another app store. To put it another way you would not be able to randomly download an unsigned app.
It's going to be interesting when some sideloaded app starts becoming popular and e.g. americans miss out on it. I can already imagine a lot of AI and nsfw stuff in that category
[flagged]
I absolutely disagree with your conclusion. It's like forbidding people from working on their own cars because some people are stupid and kill themselves through their work(and that kind of thing is neither rare nor unusual). And it's not like people with iOS are resistant to being scammed - there are hundreds of ways criminals can dupe you to sending them money, the invoice scam being the simplest example and it doe…
[0] https://www.nationthailand.com/thailand/general/40024972
Also your comparison of people 'working on their own cars' is a bit off here. Most people buy cars to drive, and give the car to the mechanic to 'work on'. It's much much harder to repair your own car than to click a link that can scam you.