> "...unfortunately, it's impossible to do all the complex engineering to comply with the Commission's current interpretation of the DMA..." There's nothing complex and impossible about removing some "if" statements responsible for code signature enforcement.
On the surface, it's easy to do. But that is also based on the assumptions where they had to maintain some first party apis vs now having to create and maintain them so that third parties could use it. If they are committed to security which apparently DSA mandates, they have to devote many resources on it to ensure there are no threat vectors. Plus, there is no set guidelines on how much the APIs need to offer, it will be another session where competition asks for more and they will be asked to do that too.