Live data from Hacker News

Rethinking the App Store

stratechery.com

191–200 of 350 posts

Re: Rethinking the App Store

#191

The most important changes Apple needs to make would not cost them a single line of code- they just get rid of their policy to require consistent pricing across all platforms, and allow promotion/linking of external (i.e. not on iOS) payment sources. If Spotify could charge +30% for a subscription purchased through the App store, and include a link to their main sign up page where subscriptions are regular price, eve…

I agree, but Apple will never go for this unless forced to for obvious reasons.

As a cross-platform developer, the degree to which Apple has scrutinized our app and made sure there's not so much as a hint of the fact that you can buy the product on the web is totally nuts.

Re: Rethinking the App Store

#192

Earlier quoted context omitted.

Look MacOS They do block "unidentified" apps by default but you still have the option to run it anyway (after a series of warnings maybe) But you can still run them And I think it can be a start

And that worked out really well for Vista and UAC. People have become blindly accustomed to just clicking ok.

That’s the point, in macOS it never runs by just clicking ok. The selected button is “Move to Trash” and the second button is “Cancel”

To run those apps, you have to open System Preferences or right-click them (which I don’t remember if it’s still allowed)

Re: Rethinking the App Store

#193

Earlier quoted context omitted.

At a micro level I can understand this point, but the proper functioning of markets requires competition. You likely wouldn't advocate one supermarket, one car company or one hardware manufacturer. Even if you would prefer to use Apple's Store it's wrong to deny others (both producers and consumers) free choice.

I am looking at with a different perspective: I am thinking Apple is like a union for their users. And they are regulating developers and they have huge negotiating power because they are gateway to user’s phone. I don’t see them as market participant, I more likely see them as market regulator.

> I don't see them as market participant

But they are. There are competing apps to Apple's own apps on the App Store. Apple Music is an obvious example, but there's also web browsers, email clients, calendar clients, cloud storage, etc. Through their "market regulation" and using privileged APIs, they can artificially hold competitors back from reaching or surpassing parity of said competing apps.

Their "regulation" has forced all web browsers to use Safari on the backend without the benefits of things like content blockers. Their "regulation" has forced all apps to not be able to cut off a trial if they cancel the subscription renewal while hypocritically doing just that for things like Apple Arcade and Apple TV if you cancel the subscription before the trial is over. Their "regulation" has blocked out any competition to Apple Arcade like xCloud or Stadia. Their "regulation" has, until iOS 14 (still in a limited fashion), kept any other app from being a default and if those stock apps are deleted, annoy users to the point of reinstalling them due to popups when tapping an email address, date/time, or street address.

These are all ways that they secure their spot above the competition on their own devices and hold progression back until they're ready to implement competitive features (read: probably when competition starts poaching users from them despite the disadvantages they impose on said competition).

A participant in the market, which they most certainly are, should not be regulating that market and also profiting off of that regulation. This is how a manufacturer of only 3 types of devices is the most valuable company in the world. I can't think of any other company that has an entire market, or at least the size of App Store market, completely enveloped under their reign.

Re: Rethinking the App Store

#194
post #146

Earlier quoted context omitted.

> Without review, publishing an app with a sandbox bypass, or simply abusing entitlements, becomes trivial. I would _love_ a 3rd-party App Store that hosted jailbreak apps/apps that abuse private APIs/etc, so long as it was clear what I was getting.

I suspect a large portion of Apple’s users value the fact that they can’t break their phone by accidentally installing the wrong app or clicking the wrong button. To them it might not be clear what they’re getting from this no-rules App Store.

I think people using Cydia had a pretty good idea of what they were doing.

Re: Rethinking the App Store

#195
post #71

Earlier quoted context omitted.

> Without review, publishing an app with a sandbox bypass, or simply abusing entitlements, becomes trivial. I don't think this would be trivial either. Given that iOS security has historically been rather good, I guess an attacker would need a reasonably new exploit or even zero day. Assuming an attacker has access to something like that, I'm 99.8% certain he'd be able to sneak past the review process as well. As For…

Fortnite has also demonstrated how sloppy third party developers are with respect to security. https://arstechnica.com/gadgets/2018/08/fortnites-android-vu... And at least Epic wasn’t purposefully installing back doors. Unlike Zoom. https://www.zdnet.com/article/zoom-defends-use-of-local-web-...

That argument doesn't make sense, because Apple isn't going to lower the sandboxing requirement for anyone, it's just going to provide an API to install an IPA. (Actually, that API already exists of course, they'll just remove the check that makes sure you're Apple when you call it.) Third parties' security practices have no bearing on how secure Apple makes their own platform–the parent comment is literally saying "Without review, publishing an app [that ships with a zero-day exploit for iOS] becomes trivial"

Re: Rethinking the App Store

#196

Earlier quoted context omitted.

I think it is. I have the best of both worlds. Most of the time I download apps from a store that is roughly as safe as the Apple store. (Maybe not quite as high, but I don't think that this changes the argument). However if there is some software that Google doesn't like I can install it myself. Or I can run a patch that some developer posted on GitHub and test it before it has been merged and published. It shows th…

95% of the public don’t even know what GitHub is. The vast majority of people aren’t going to run patches a developer posted there. Anyway, the argument was that the Apple app store was stifling app development. In your reply you yourself say the apps on the Google store are “Maybe not quite as high” quality.

That quote was in reference to security, not quality.

Re: Rethinking the App Store

#197

The most important changes Apple needs to make would not cost them a single line of code- they just get rid of their policy to require consistent pricing across all platforms, and allow promotion/linking of external (i.e. not on iOS) payment sources. If Spotify could charge +30% for a subscription purchased through the App store, and include a link to their main sign up page where subscriptions are regular price, eve…

The consistent pricing requirement was removed years ago. This is an article from 2011 about it: https://appleinsider.com/articles/11/06/09/apple_backs_down_...

For reference, YT Premium is $16 on iOS[0] but $12 directly[1].

0: https://lh3.googleusercontent.com/pw/ACtC-3dznQemACWzb2tbYfd...

1: https://youtube.com/premium

Re: Rethinking the App Store

#198
post #163

Earlier quoted context omitted.

Ultimately giving users choice is the best way forward. Apple shouldn't be allowed to block competing app stores (or sideloading) on their platform, in my view that's monopolistic. Imagine if Microsoft had restricted the ability to install and use third party software on Windows, it would of slowed digital transformation dramatically.

> Ultimately giving users choice is the best way forward. OK, but right now as a user I have a choice: I can choose an ecosystem supported in part by a 30% tax on apps, or I can choose an ecosystem supported mainly by advertising. If Apple is forced to allow other stores, I lose that choice. Furthermore, a lot of the things Apple forces on apps really are for my benefit: Take the way they banned Facebook for working…

>OK, but right now as a user I have a choice: I can choose an ecosystem supported in part by a 30% tax on apps, or I can choose an ecosystem supported mainly by advertising. If Apple is forced to allow other stores, I lose that choice.

I'm not sure that follows. Can you elaborate on why you would "lose that choice"?

Re: Rethinking the App Store

#199

Earlier quoted context omitted.

Access to private APIs is also impossible to prevent in screening since it’s trivial to obfuscate

Not sure if it's impossible but from experience it's very difficult to bypass Apple's screening process. They can class-dump the Mach-O binary, disassemble and inspect the performSelector: calls or even just run the apps in an ARM emulator and watch for alarms whenever the reviewer manually goes through the app.

> from experience it's very difficult to bypass Apple's screening process

From experience, it is trivial to bypass review. Trivial.

> They can class-dump the Mach-O binary, disassemble and inspect the performSelector: calls or even just run the apps in an ARM emulator and watch for alarms whenever the reviewer manually goes through the app.

The vast majority of apps don't go through anything close to this. At most, Apple runs a class-dump equivalent on every binary, nothing more–and you can even see it catch legitimate selectors every so often! If you think about it, this isn't surprising, because you need to have a (large) team of actual reverse engineers do this kind of thing or set up a good automated malware analysis platform, both of which Apple is fairly behind at.

Re: Rethinking the App Store

#200

Earlier quoted context omitted.

Part of Apple's security does in fact come from the curation process. Access to private APIs for example is not preventable at runtime due to the way Objective-C works. And the ability to change payment screens etc at runtime has always been possible. But Apple simply bans the developer and so instances of this happening in the wild have been basically non-existant.

> Access to private APIs for example is not preventable at runtime due to the way Objective-C works. That's on Apple side to fix this, you can compare that to the browser which has a proper sandbox model without private APIs.

Apple's browser sandbox uses iOS-private APIs to work, plus it runs in a separate process which again is not something normal apps can do. Nor can Apple–UI frameworks all but have to be in-process and there is nothing you can do to prevent people from calling into it in unintended ways.
Post reply on HN