> So you compared the absolute numbers, knowing it would be misleading.
I gave the absolute numbers thinking you were smart enough to convert 0 proportionally. I certainly didn't know that it would confuse you.
> You’d expect malware authors to put their efforts where the money is.
That would be a good point if the stores were incompatible. However, it is possible to write an app that you can publish to the Amazon App Store, the Google Play Store, F-Droid, and the hundreds of Chinese app stores. Despite this, F-Droid has had zero infections. Despite the Play Store having far more users than the App Store, it has infected far fewer users.
> This is complete bullshit. Apps are signed by developed and by Apple. Were you not aware of that?
You are clearly not aware that the package submitted to Apple is signed by the the developer, and the package delivered to the user is signed only by Apple. Apple (or China) determines what app actually gets to the device. https://developer.apple.com/forums/thread/12880
> Doesn’t seem remotely true - here’s just one recent example:
Your example is a vulnerability in an app that can be exploited to access that app's data. It is not a malware app, and there is no evidence that any users had malware that attacked that app, let alone that any such malware was being distributed by any of the stores. By that standard, 100% of iOS users are exploited because Safari is so bugridden.
Half billion was an external estimate for xcodeghost. Apple's internal estimate pegged the number of users infected by just half of the identified malware apps at 125 million. https://www.vice.com/en/article/n7bbmz/the-fortnite-trial-is...