Live data from Hacker News

App Store Rejection of the Week: Dark Hours

daringfireball.net

241–250 of 255 posts

Re: App Store Rejection of the Week: Dark Hours

#241

Earlier quoted context omitted.

> Children are either not allowed to have devices, or they have them but locked down with parental controls (hopefully). How many children have you met lately?

Who is at fault for allowing children unlimited access to their devices? Their caregivers or Apple?

Society as a whole, to some extent, and the various industries involved.

Why should children be punished with a lifetime of shitty ingrained behaviors just because they were born to shitty parents who wouldn't do the right thing? I'd rather not create the Eloi and Morlocks from HG Wells.

Re: App Store Rejection of the Week: Dark Hours

#242

Earlier quoted context omitted.

Look up "wireless printing" in the App Store sometime. As best I can tell, one or two actors have spammed the entire category with dozens, perhaps hundreds, of subscription-heavy repackagings of CUPS drivers as iOS apps. They all have very similar blue line-art icons of a printer, similar preview images with similar typography, and are all crammed full of subscription options. They are probably making a killing on pe…

> the App Store will be the one real stain on his legacy Well, and the Apple Car. And the Butterfly Keyboard and that horrible i9 16" MBP. Plus the Airpower, and the Vision Pro, and he cancelled the entire Mac Pro lineup too. Also the $1,000 VESA monitor mount and goofy desktop wheels, and we should probably also mention his meetings with Donald Trump and eventual White House dinner with Bin Salman. Tim also failed t…

> Well, and the Apple Car.

How is the Apple Car a stain on his legacy? They worked on something, and decided not to do it. Who cares? Apple’s management of the App Store has ruined mobile apps. Nobody gives a shit about the car.

Re: App Store Rejection of the Week: Dark Hours

#243

Earlier quoted context omitted.

That's great until your device is weaponised against others (see: open HTTP proxies, open DNS resolvers, open SMTP servers, several billion IoT devices, and countless other examples)

Those issues could be diminished if ISPs actually handled abuse requests and shut down people's connections until they removed their malware.

> shut down people's connections until they removed their malware.

Yes, in an ideal world, that might work but most people don't actually know they have malware. That's the point of the malware! And it's not like you can say "no internet for you until you replace your TV[0]" because that's an extremely quick way to the courts and a customer reputation below the toilet.

(Ignoring the "who pays for that?" question because that is a whole 'nother can of worms.)

[0] https://www.ibtimes.co.uk/fbi-google-disrupt-proxy-network-a...

Re: App Store Rejection of the Week: Dark Hours

#244

Earlier quoted context omitted.

> If you give a toddler a butcher's knife to play with and they get hurt, you'll likely get in trouble for child endangerment. Right but granny is not a child, she is kind of the opposite of a child. You're essentially saying we should child proof the entire world, right. Appeal to the lowest common denominator and DO NOT offer back doors. But that's a plainly ridiculous notion and everyone knows it. This argument on…

> Right but granny is not a child, she is kind of the opposite of a child. The failure modes are often quite similar - cognitive/motor issues and lack of experience with the tools offered. > Appeal to the lowest common denominator and DO NOT offer back doors. Back doors accessible by scammers are bad for the same reasons back doors accessible by governments are. > This really is "no sale of knives" type stuff. That s…

> The failure modes are often quite similar - cognitive/motor issues and lack of experience with the tools offered.

Okay but again we cannot form all technology to only work for people with cognitive issues and nobody else. Again, this is ridiculous, there's no other way to describe it. It's just not a reasonable viewpoint and I feel it's a bit insane I even have to argue against it.

Look, it's great if we have the option to lock these phones down for more vulnerable people. What we CANNOT do is make the entire world locked down. It's not reasonable.

> Back doors accessible by scammers are bad for the same reasons back doors accessible by governments are.

My mistake, these are front doors. Not back doors.

> Apple's more like a shop that declines to sell knives. There are other shops that will sell you one.

NO, there are not, because Apple chooses to only allow their app store. The market we are talking about here is not "all smartphones". It's "the market of software available for iPhones", in which they hold 100% control over. This should be legislated against.

Re: App Store Rejection of the Week: Dark Hours

#245

Earlier quoted context omitted.

I think the bigger question is whether this is even worth solving. If people really want to give someone root access and do it willingly, maybe we just say this is out of our purview and allow it. And then, slowly, people will learn. They will be hard lessons but evidently baby proofing the entire world is not really working, so we might just abandon ship on that idea.

Tell me that when it’s your relative that is out thousands of dollars because they were scammed.

I'm not going to argue we should close all banks or whatever ridiculous argument people come up with just because someone lost money.

The only way to 100% prevent scams is to remove the potential entirely. There are scams, infinite actually, right now, on iPhones. Do you support that? Surely not, so we should lock iPhones down more no? Ideally, we ban smartphones altogether, to prevent scams. Oh you don't support that? Well come back when one of your relatives loses 1 million dollars.

Look, we can take steps to prevent scams, and we do. What we should NOT do is go so extreme that people cannot even use their devices the way they want that they paid for. This is anti-consumer. If I want to install some software, I should be able to. It is not Apple's responsibility to baby me, baby you, and baby the entire world and say "no no you can only use our approved software!"

Especially when some of that approved software is... wait for it... malware! Yes, there is quite a lot of malware on the Apple App Store and the Play Store. But I can't install open-source software I've audited myself on my iPhone? How strange.

It appears to me this has nothing to do with scams, and everything to do with control, censorship, and profiteering.

Re: App Store Rejection of the Week: Dark Hours

#246

Earlier quoted context omitted.

I think the bigger question is whether this is even worth solving. If people really want to give someone root access and do it willingly, maybe we just say this is out of our purview and allow it. And then, slowly, people will learn. They will be hard lessons but evidently baby proofing the entire world is not really working, so we might just abandon ship on that idea.

> And then, slowly, people will learn I hope you're right, but I'm not sure they will. The less locked-down WinXP and early Android era was ... really really bad in terms of nontechnical people getting hacked/scammed. And bad actors are also innovating, so the target of what people have to learn is moving: now we have synthetic AI voice scams, easy-to-create full clones of popular websites that harvest credentials, a…

On the sliding scale here where the left is "full anarchy" and the right is "goo goo ga ga baby proof the world", Apple is about 95% to the left. Here's how that looks:

Anarchy |--------O-| Goo Goo Ga Ga

And people are arguing we should be moving further right. It's ridiculous, we all need to be candid and recognize this will not work

Re: App Store Rejection of the Week: Dark Hours

#247

Earlier quoted context omitted.

> And then, slowly, people will learn I hope you're right, but I'm not sure they will. The less locked-down WinXP and early Android era was ... really really bad in terms of nontechnical people getting hacked/scammed. And bad actors are also innovating, so the target of what people have to learn is moving: now we have synthetic AI voice scams, easy-to-create full clones of popular websites that harvest credentials, a…

On the sliding scale here where the left is "full anarchy" and the right is "goo goo ga ga baby proof the world", Apple is about 95% to the left. Here's how that looks: Anarchy |--------O-| Goo Goo Ga Ga And people are arguing we should be moving further right. It's ridiculous, we all need to be candid and recognize this will not work

Fortunately, it's not a linear scale. All sorts of technical and political options exist which don't fall cleanly into the anarchy or baby-proofing spectrum. Random incomplete examples, in no particular order and off the top of my head:

GGP's idea of making it more commonplace to have a "Johnny" helping people with their tech needs to prevent accidents could work socially, if there are ways for communities to create more people willing to do that.

Worldwide legal penalties for spamming/scamming could grow more teeth, increasing the likelihood of bad outcomes for people that make malware or questionable apps.

Software distribution systems could standardize on better systems of provenance and ownership handoff to further technically harden against "good extension sold out to an evil maintainer" or "github credential leak let a bad guy publish an artifact"-type attacks.

Cooldown periods for users trying to grant questionable access patterns could be imposed, though that might feel too baby-proof for some.

On-device permission boundaries could be modeled in an "XOR" way: apps distributed from Apple's walled garden could be disallowed from approving data sharing with apps users install from other repositories. That's Apple's prerogative (they own the distribution and vouch for at least some of the quality of the app store apps), but doesn't prevent users from installing parallel ecosystems if they want.

Something that's very paternalistic, but doesn't involve baby-proofing what's possible, is the idea of credentialing users. You need a driver's license to operate a car. In the US, you need a (much easier to get) food handling license to commercially process food. The latter's a short briefing and test of comparable effort to those mandatory corporate anti-phishing trainings that already-technical people hate. Perhaps some users could benefit from that as a prerequisite to installing non-trusted software.

For vetted walled gardens like the App Store, further improving the granularity of and required justifications for permission requests as providers have been doing might help. "This poker app wants to access all of your saved contacts and photos" becomes "this poker app wants you to select a single profile photo and up to 5 contacts a day to add as opponents, after which access is revoked" or whatnot. This only works if App Store reviewers get serious about rejecting apps for overbroad permissions requests and explain their rationale to app developers, which would require Apple and friends to spend a lot of money to enable. Fortunately, they have insane margins. Less fortunately, their shareholders wouldn't go for this unless forced by regulation or similar.

Anything that helps with threat attribution. If Grandma can install an app from a random URL, and then gets hacked 6 months later, it'd be great if something got in her face that loudly indicated that the decision to install the untrusted app was the root cause of her compromise and some "do you want to disable the ability to do this in the future/require a phonecall to $provider to turn it back on?"-type hint.

For apps that spend money, further integrating pattern-aware anti-fraud and spend caps with payment APIs so that e.g. a microtransaction app that got hacked can't suddenly spend $100 where the user typically spent $5/month. Banks are already starting to get proactive/argumentative about unexpected transaction patterns a la "sir, are you sure you want to send $5000 in your first overseas money wire? Can you tell us more about that transaction? Are you aware of this common fraud?"

...and so on.

Re: App Store Rejection of the Week: Dark Hours

#248

Earlier quoted context omitted.

Tell me that when it’s your relative that is out thousands of dollars because they were scammed.

I'm not going to argue we should close all banks or whatever ridiculous argument people come up with just because someone lost money. The only way to 100% prevent scams is to remove the potential entirely. There are scams, infinite actually, right now, on iPhones. Do you support that? Surely not, so we should lock iPhones down more no? Ideally, we ban smartphones altogether, to prevent scams. Oh you don't support tha…

The comparison to banks is actually pretty interesting.

Unlike app developers, banks are by default directly liable for fraud that happens on their system. In many cases, even when someone gets their bank to send money to a scammer, they can still get that money back. Since the bank doesn't want to risk regulatory reprisal, they have a lower threshold for spending money to make customers whole. Exceptions and subtleties abound here, but the underlying incentive structure is very different: the broker of the sensitive resource (money, for banks) is often held responsible for mis-use of that resource. How would we do that for e.g. apps that store your password in plaintext and then get hacked?

Relatedly, banks have thus started adopting the practice of blocking and calling/talking to customers about suspicious transactions. You can still authorize it if you really push, but you have to talk to someone with expertise about fraud risk, and have to spend some time doing it (which helps a lot with the "urgency" dimension of scams). Most permission approval prompts on phones/computers have no such human intervention or time-delay option, even if you might want them to.

> The only way to 100% prevent scams is to remove the potential entirely. There are scams, infinite actually, right now, on iPhones. Do you support that? Surely not, so we should lock iPhones down more no?

Nobody here has the goal of preventing 100% of scams. The ideal amount of fraud on these platforms is not zero (https://www.bitsaboutmoney.com/archive/optimal-amount-of-fra...). Rather, fraud is still extremely common and difficult to disincentivize. We want to reduce that as much as possible while not imposing overly-onerous restrictions. The discussion is about what counts as "as much as possible" or "overly-onerous", not whether we should ban phones or banks.

> I can't install open-source software I've audited myself on my iPhone

I hope you understand you're in a very tiny minority of people who can do that, using a device designed for people who cannot do that, and whose behavior if permitted to do what you're after has a proven history of causing significant damage to individuals (who lose their savings) and shared resources (sites DDoSed by end-user-device malware, hospitals that can't provide care because someone let ransomware onto a computer, and so on).

Re: App Store Rejection of the Week: Dark Hours

#249

Earlier quoted context omitted.

> Right but granny is not a child, she is kind of the opposite of a child. The failure modes are often quite similar - cognitive/motor issues and lack of experience with the tools offered. > Appeal to the lowest common denominator and DO NOT offer back doors. Back doors accessible by scammers are bad for the same reasons back doors accessible by governments are. > This really is "no sale of knives" type stuff. That s…

> The failure modes are often quite similar - cognitive/motor issues and lack of experience with the tools offered. Okay but again we cannot form all technology to only work for people with cognitive issues and nobody else. Again, this is ridiculous, there's no other way to describe it. It's just not a reasonable viewpoint and I feel it's a bit insane I even have to argue against it. Look, it's great if we have the o…

> Okay but again we cannot form all technology to only work for people with cognitive issues and nobody else.

We can take their needs into consideration, just as we legally require businesses to put wheelchair ramps in.

> NO, there are not, because Apple chooses to only allow their app store. The market we are talking about here is not "all smartphones". It's "the market of software available for iPhones", in which they hold 100% control over. This should be legislated against.

Should Gucci have to sell Coach handbags? Should Ford have to sell Toyotas?

Re: App Store Rejection of the Week: Dark Hours

#250

Earlier quoted context omitted.

> The failure modes are often quite similar - cognitive/motor issues and lack of experience with the tools offered. Okay but again we cannot form all technology to only work for people with cognitive issues and nobody else. Again, this is ridiculous, there's no other way to describe it. It's just not a reasonable viewpoint and I feel it's a bit insane I even have to argue against it. Look, it's great if we have the o…

> Okay but again we cannot form all technology to only work for people with cognitive issues and nobody else. We can take their needs into consideration , just as we legally require businesses to put wheelchair ramps in. > NO, there are not, because Apple chooses to only allow their app store. The market we are talking about here is not "all smartphones". It's "the market of software available for iPhones", in which…

> We can take their needs into consideration

Yes, I agree, and I said exactly that.

> Should Gucci have to sell Coach handbags? Should Ford have to sell Toyotas?

If Gucci was a Walmart, then yes. If Walmart claimed to be a grocery store, and exclusively served only Walmart goods, that's a problem.

There's a difference between a brand and a marketplace. Apple is a brand. The App Store is a marketplace. The marketplace should be relatively free, in the market sense.

In addition, these are general computation devices. Some people disagree, I don't care, they're obviously wrong. It's not like a washing machine. These are supposed to be for general software and computing purposes, much like your PC. But they aren't, because unlike your PC, they are nonfree.

The bigger thing that I'm kind of hinting at is: we are not trapped into some make believe structure we have to live by. You think Apple shouldn't open their app store. That's just a belief, and one I reject. We can, and should, force their hand. We do it ALLLL the time with corporations, it's very common.

Just because things have worked one way, doesn't mean they should continue to work that way. We can change things at any time, if it is for the better. If we decided we should pass legislation to force Guccie to also sell Prada, then sure. I say why the fuck not? If that's what consumers want, then we should do it. The consumer is king. I give less than zero fucks what Apple wants. If it hurts Apple's bottom line, I still don't care. In fact, I'd argue that if we're hurting Apple's bottom line then we're probably doing something right. I will always side with the consumer 100% of the time.

Post reply on HN