Earlier quoted context omitted.
> You used to think otherwise. You claimed that the package sent to the device was signed by the developer. False. If I claimed that, you’d be able to quote me. > … (or China) works as a MITM who can modify the package however they like Seems like this is total bullshit. Do you have any evidence that China can modify the packages? > Are you suggesting that China gets to re-sign software going to devices either a) ins…
> False. If I claimed that, you’d be able to quote me. Here you go: >> People using an iOS device can never be sure they are installing the secure app they wanted to install or some switcheroo. >This is complete bullshit. Apps are signed by developed and by Apple. Were you not aware of that? If you are now going to claim that when you said apps were signed by the developer, you didn't mean the apps sent to the device…
It makes perfect sense. The apps are signed by the developer and uploaded to Apple. Apple signs them for delivery to the device. Importantly. Both paths are protected.
Nothing I said before or after contradicts that.
> I interpreted your response as charitably as possible.
No. You misrepresented my response.
> Seems like this is total bullshit. Do you have any evidence that China can modify the packages?
> 1. The package sent to the device is not signed by the developer but by Apple or China.
This is a false statement. There is literally no evidence anywhere to support the idea that China is signing iOS packages delivered to devices.
https://www.quora.com/Is-iMessage-encrypted-in-China 2. China's firewall sits between users and servers outside of China. https://en.wikipedia.org/wiki/Great_Firewall
3. The Great Firewall routes the app store download request to a proxy that injects malware and resigns the package with their own key, which is trusted by the device.
None of the links you have supplied substantiate the claim that iOS devices trust a key from the great firewall. If you have a link that does, I would be interested to see one, otherwise I think we can safely call this a lie. You know it’s not true, but you are saying it anyway.
> Interesting that you seem unworried that Apple's own privileged MITM position allows it to insert malware, which governments can request.
I’m not unconcerned about that, but your claim is that China can sign iOS packages without Apple’s knowledge, which is a very different issue.
>> Your claim about aggregate Android malware numbers being lower than iOS was false:
> My claim was about malware from the Play Store and the Amazon App Store.
Yes and it is false.
> Please stop calling claims bullshit (you've done this five times now) just because you are unwilling to follow the logic and want me to spell it out. If you need help understanding an argument, just ask for it.
I will continue to call out lies and bullshit when it’s clear that is what is being presented. You have so far not substantiated the facts you have been challenged on, and your arguments rely on claims which you can’t support.