Earlier quoted context omitted.
Not Dolphin Smalltalk :-(
Yup, sad -- that's EXACTLY what I thought it was as well.
Temptation of the Apple: Dolphin on macOS M1
371–380 of 390 posts
Re: Temptation of the Apple: Dolphin on macOS M1
#372Earlier quoted context omitted.
> I am well aware of the sizes of the stores. So you compared the absolute numbers, knowing it would be misleading. > Are you aware that the relative amount of malware is is not merely proportionally less? You wouldn’t expect them to be merely proportionally less. You’d expect malware authors to put their efforts where the money is. > People using an iOS device can never be sure they are installing the secure app the…
> So you compared the absolute numbers, knowing it would be misleading. I gave the absolute numbers thinking you were smart enough to convert 0 proportionally. I certainly didn't know that it would confuse you. > You’d expect malware authors to put their efforts where the money is. That would be a good point if the stores were incompatible. However, it is possible to write an app that you can publish to the Amazon Ap…
It doesn’t matter. Your claim: “Google's and Amazon's app stores are not open source but built for an open source platform, together have far more users than the Apple App Store and far fewer malware installations.” is still bullshit.
https://www.pandasecurity.com/en/mediacenter/mobile-security...
> I gave the absolute numbers thinking you were smart enough to convert 0 proportionally.
We’ve established that this the targets are not proportionally attractive.
> I certainly didn't know that it would confuse you.
This is a public conversation, I’m sure you didn’t expect It would confuse me, but it would obviously mislead casual readers. Have you considered this?
> That would be a good point if the stores were incompatible. However, it is possible to write an app that you can publish to the Amazon App Store, the Google Play Store, F-Droid, and the hundreds of Chinese app stores. Despite this, F-Droid has had zero infections.
That still doesn’t mean it’s worth targeting f-droid. Unless you have numbers on attempted malware that has been blocked from the f-droid store, and similar numbers for the other Android stores, this like of reasoning is complete bullshit.
> Despite the Play Store having far more users than the App Store, it has infected far fewer users.
How do you know?
>> This is complete bullshit. Apps are signed by developed and by Apple. Were you not aware of that?
>> You are clearly not aware that the package submitted to Apple is signed by the the developer, and the package delivered to the user is signed only by Apple.
What makes you think I’m not aware of this?
> Apple (or China)
Are you suggesting that China gets to re-sign software going to devices either a) inside and/or b) outside China?
Everyone knows that all governments can legally require Apple to block apps. Unless you are claiming that China can do more than this, this is another obviously misleading statement.
> determines what app actually gets to the device. https://developer.apple.com/forums/thread/12880
Yes, Apple determines what app gets to the device. Who in the world would think otherwise? - it’s part of their marketing for the iPhone.
Re: Temptation of the Apple: Dolphin on macOS M1
#373Earlier quoted context omitted.
True, and more specifically it was AT&T making their early Android phones into Android iPhones. This was still pretty close to the era when the iPhone was an AT&T exclusive. It was terrible and I believe they sold pretty poorly. My point is that the mumblemumble seemed to think that Google had no choice in the matter. I think they clearly did and for the most part clearly opted to keep the third party door open at th…
My point wasn't exactly that they had no choice, so much as it was a choice they quite understandably weren't going to make. The AT&T analogy is kind of weak here because they weren't operating in the same business environment. AT&T was doing it in a B2C context, Google's Android business at the time was 100% B2B. It's easier to take this kind of risk as a major telecom operating in a B2C context, because consumers,…
Obviously having it for themselves was a key selling point.
Re: Temptation of the Apple: Dolphin on macOS M1
#374Earlier quoted context omitted.
> So you compared the absolute numbers, knowing it would be misleading. I gave the absolute numbers thinking you were smart enough to convert 0 proportionally. I certainly didn't know that it would confuse you. > You’d expect malware authors to put their efforts where the money is. That would be a good point if the stores were incompatible. However, it is possible to write an app that you can publish to the Amazon Ap…
>> Doesn’t seem remotely true - here’s just one recent example: > Your example is a vulnerability in an app that can be exploited to access that app's data. It is not a malware app, and there is no evidence that any users had malware that attacked that… It doesn’t matter. Your claim: “Google's and Amazon's app stores are not open source but built for an open source platform, together have far more users than the Appl…
> Yes, Apple determines what app gets to the device. Who in the world would think otherwise? - it’s part of their marketing for the iPhone.
You used to think otherwise. You claimed that the package sent to the device was signed by the developer. It is not. Apple (or China) works as a MITM who can modify the package however they like with no way for the user to verify that malware hasn't been inserted. F-Droid allows the user to verify that the package contents hash the same as what they would build locally.
> Are you suggesting that China gets to re-sign software going to devices either a) inside and/or b) outside China?
Yes. Because the App Store has this MITM vulnerability and China gets to MITM all US services (with blessed MITM status for iCloud that even defeats Apple's "E2E" encryption for their other services), they can replace the Signal package with a compromised one.
>> Despite the Play Store having far more users than the App Store, it has infected far fewer users.
> How do you know?
Unlike Apple; F-Droid, Google, and Amazon allow security researchers to analyze apps on their respective stores instead of blocking their access. Lower case count despite higher test rate isn't a guarantee that fewer people have been infected, but it is strong evidence for that conclusion.
Re: Temptation of the Apple: Dolphin on macOS M1
#375Earlier quoted context omitted.
It’s just a cat and mouse game. I see your address book and verify that the entries aren’t in your friends list and I ask again until you give me the real stuff. And then your ROM devs figure out how to make the data more convincing. And then I start running AI algorithms on it. It’s like captcha - there’s no end to the competition. And in the meantime you can’t see your timeline until you give me the real stuff. Or,…
I don't keep contacts in the standard app so I wouldn't be allowed on Facebook anymore then. At some point they can just tell you to upload your contacts and drivers license via email or a web form if you want to use the app, WTF do you plan on doing then?
Probably for the best. Social media is poison.
At some point they can just tell you to upload your contacts and drivers license via email or a web form if you want to use the app, WTF do you plan on doing then?
I'm really trying to help you understand why Google and Apple can't rely on OS-level caps and perms. If you don't understand how app devs can cheat you blind regardless of what system-level perms you set, you're clearly not an app dev. I can ID your device and send it encrypted back to my server. I can find your non-standard address book and read it off the user partition by nicely offering you a utility service like backup. It's gzipped and encrypted and sent back to my db and forget about your privacy. I can do a lot more on your ROM'ed android device than you expect, and I can do it all with permissions and a bit of social engineering.
Now just imagine what I can do with your grandma.
Re: Temptation of the Apple: Dolphin on macOS M1
#376Earlier quoted context omitted.
I don't keep contacts in the standard app so I wouldn't be allowed on Facebook anymore then. At some point they can just tell you to upload your contacts and drivers license via email or a web form if you want to use the app, WTF do you plan on doing then?
I don't keep contacts in the standard app so I wouldn't be allowed on Facebook anymore then. Probably for the best. Social media is poison. At some point they can just tell you to upload your contacts and drivers license via email or a web form if you want to use the app, WTF do you plan on doing then? I'm really trying to help you understand why Google and Apple can't rely on OS-level caps and perms. If you don't un…
No amount of careful OS design could fix that and the two companies running App Stores are unwilling to perform the curation required to fix it.
At this point the only safe curated app store is F-Droid.
Re: Temptation of the Apple: Dolphin on macOS M1
#377Earlier quoted context omitted.
I'm sure you know but Firefox on the iPad uses Apple's rendering engine Webkit and not Mozilla's Gecko -so arguably it's more like Safari than desktop Firefox.
Why should I care? It works beautifully… I have zero concern for what rendering engine Firefox on iPad uses.
And also you might care because we're on a forum full of developers knee deep in a thread and walled gardens and their relation to customer architectures, and it might be relevant to that thread that code that's common to every other Firefox platform target isn't as common on iOS.
Re: Temptation of the Apple: Dolphin on macOS M1
#378Earlier quoted context omitted.
>> Doesn’t seem remotely true - here’s just one recent example: > Your example is a vulnerability in an app that can be exploited to access that app's data. It is not a malware app, and there is no evidence that any users had malware that attacked that… It doesn’t matter. Your claim: “Google's and Amazon's app stores are not open source but built for an open source platform, together have far more users than the Appl…
> What makes you think I’m not aware of this? > Yes, Apple determines what app gets to the device. Who in the world would think otherwise? - it’s part of their marketing for the iPhone. You used to think otherwise. You claimed that the package sent to the device was signed by the developer. It is not. Apple (or China) works as a MITM who can modify the package however they like with no way for the user to verify that…
False. If I claimed that, you’d be able to quote me.
> … (or China) works as a MITM who can modify the package however they like
Seems like this is total bullshit. Do you have any evidence that China can modify the packages?
> Are you suggesting that China gets to re-sign software going to devices either a) inside and/or b) outside China? Yes. Because the App Store has this MITM vulnerability and China gets to MITM all US services (with blessed MITM status for iCloud that even defeats Apple's "E2E" encryption for their other services), they can replace the Signal package with a compromised one.
The seems like bullshit. There is no indication of an MITM vulnerability between the developers and Apple, nor is there one between Apple and users. China cannot MITM packages based on what you have said so far.
Yes, Apple can change package contents. Numerous App Store features make use of this to deliver partial packages and device specific binaries.
Nothing about this mechanism gives China an MITM.
>> Despite the Play Store having far more users than the App Store, it has infected far fewer users. > How do you know? Unlike Apple; F-Droid, Google, and Amazon allow security researchers to analyze apps on their respective stores instead of blocking their access. Lower case count despite higher test rate isn't a guarantee that fewer people have been infected, but it is strong evidence for that conclusion.
So you misled people by claiming this as fact, when it’s actually just speculation.
How do you know the case count is lower, and the test rate is higher?
Your claim about aggregate Android malware numbers being lower than iOS was false: https://www.pandasecurity.com/en/mediacenter/mobile-security...
Re: Temptation of the Apple: Dolphin on macOS M1
#379I wonder if there are any gains to be had on the M1 because it uses shared memory between the CPU and GPU - much like the actual Gamecube architecture. From reading this blog, Gamecube games often made heavy usage of the memory-sharing capability of the hardware - which made emulation on PCs a performance challenge.
You most likely still need to do all the work to manage texture caches because first of all, you need to create texture objects in the host graphics api based on what's essentially just memory. On top of that, GC/Wii texture formats might be different from what the host can support. From my understanding it's not that useful for reading back either as the main bottleneck there is the fact that you need to sync gpu an…
Re: Temptation of the Apple: Dolphin on macOS M1
#380Earlier quoted context omitted.
> What makes you think I’m not aware of this? > Yes, Apple determines what app gets to the device. Who in the world would think otherwise? - it’s part of their marketing for the iPhone. You used to think otherwise. You claimed that the package sent to the device was signed by the developer. It is not. Apple (or China) works as a MITM who can modify the package however they like with no way for the user to verify that…
> You used to think otherwise. You claimed that the package sent to the device was signed by the developer. False. If I claimed that, you’d be able to quote me. > … (or China) works as a MITM who can modify the package however they like Seems like this is total bullshit. Do you have any evidence that China can modify the packages? > Are you suggesting that China gets to re-sign software going to devices either a) ins…
Here you go:
>> People using an iOS device can never be sure they are installing the secure app they wanted to install or some switcheroo.
>This is complete bullshit. Apps are signed by developed and by Apple. Were you not aware of that?
If you are now going to claim that when you said apps were signed by the developer, you didn't mean the apps sent to the device, that quoted response makes no sense in that context. I interpreted your response as charitably as possible.
> Seems like this is total bullshit. Do you have any evidence that China can modify the packages?
I explained how app distribution works and assumed you could work it out. It looks like my assumption was mistaken, so here it is step by step: 1. The package sent to the device is not signed by the developer but by Apple or China. https://www.quora.com/Is-iMessage-encrypted-in-China 2. China's firewall sits between users and servers outside of China. https://en.wikipedia.org/wiki/Great_Firewall 3. The Great Firewall routes the app store download request to a proxy that injects malware and resigns the package with their own key, which is trusted by the device.
Interesting that you seem unworried that Apple's own privileged MITM position allows it to insert malware, which governments can request.
> There is no indication of an MITM vulnerability between the developers and Apple, nor is there one between Apple and users.
Once again, the biggest MITM is between the developer and users, which F-Droid's reproducible builds prevent.
> Your claim about aggregate Android malware numbers being lower than iOS was false:
My claim was about malware from the Play Store and the Amazon App Store.
Please stop calling claims bullshit (you've done this five times now) just because you are unwilling to follow the logic and want me to spell it out. If you need help understanding an argument, just ask for it.