Live data from Hacker News

Apple: Person-to-person experiences do not have to use in-app purchase

developer.apple.com

481–490 of 492 posts

Re: Apple: Person-to-person experiences do not have to use in-app purchase

#481

Earlier quoted context omitted.

My hardware does serve me. I won’t install Zoom or Dropbox on my Mac for instance because they are essentially malware. Zoom was installing a web server in the background on Macs where even if you uninstalled it, it would reinstall itself. DropBox does all sorts of invasive stuff when installed on my Mac. On the other hand, my iPad has a strict sandbox, I can restrict apps from using cellular on an app by app basis (…

Sure, but Google or Apple approved apps also have issues, if I remember right Microsoft updates lost user data, I think some Apple updates destroyed some users backups, Steam had a bug where it deleted all the user files. So I think the focus should not be in locking users but in locking the apps in strong sandboxes. Thank you for all your replyes but I notice you are ignoring a category of developers, you are only c…

Apple released a version of the iTunes installer that erased users files if the hard drive had a space in the name. Of course I don’t believe either Apple or Google were being intentionally malicious.

As far as the hobbyists, I had another proposal in another thread. Free “self signed certs” that are tied to your device. You can compile from source an app and keep it on your phone. You are free to share source code. This would also be keeping within GPL2, GPL3.

Apple making money on in app purchases is just as unethical. I think that’s the purpose of Apple Arcade.

Re: Apple: Person-to-person experiences do not have to use in-app purchase

#482
post #473

Earlier quoted context omitted.

"This user just gave a third party their entire contact list" certainly does harm other people. "This user just had their entire camera roll exfiltrated" certainly does harm other people. These are social devices. Their users are, by and large, non-technical and incurious. Expecting them to not just click past the "scary sign", and so condition to do it again and again, so they can play Fortnite is a level of lack of…

...neither of those attacks you gave are unique to smartphones. Someone can leak personal information through any number of other channels - for instance, entering someone else's personal information into a website that send out emails for a group party invitation. > Expecting them to not just click past the "scary sign", and so condition to do it again and again, so they can play Fortnite is a level of lack of under…

They did fix the actual problem here: the complete intractability, to the point where your dismissal reads as at best impossible optimism, of expecting users to secure their devices when given the opportunity to get a sick screensaver or a game.

I appreciate the fix. And I don’t want to be hectored by bad actors to fuck up my phone for their profit margin.

Buy Android if you do. That “freedom” is right there for you. I used to buy Android when I thought I cared about sideloading; I don’t, so I don’t. Do likewise!

Re: Apple: Person-to-person experiences do not have to use in-app purchase

#483
post #480

Earlier quoted context omitted.

I mean, is it really that far out there if you look at the past two decades of history of malware on Windows and particularly Android? Sandboxing has not prevented the proliferation of malware on Android, why would it be any different on iOS? Sandboxing also doesn't really address the other major risk which is theft of personal information by supposedly "trustworthy" apps.

Malware is less of a problem for Android now than any point in Windows' history except for possibly the past few years, so I think that sandboxing has succeeded rather well, given that Windows has had 34 years to evolve defenses and Android has only had 11. Even early on in its life, Android was still better off than Windows at the time, and what do you know - Android has allowed sideloading and alternative app store…

That's not exactly a ringing endorsement, is it? Sure, the malware situation on Android is better than Windows. It's still far worse compared to iOS.

https://arstechnica.com/information-technology/2020/02/resea... (Note the date. This is an ongoing problem.)

https://www.theverge.com/2019/7/10/20688885/agent-smith-andr...

https://securelist.com/skygofree-following-in-the-footsteps-...

https://arstechnica.com/information-technology/2016/07/virul...

Don't you think there's a direct correlation between the ability to install APKs from random shady internet sources and the spread of malware on Android? Even macOS has a worse malware situation than iOS for the exact same reason.

If you believe this has "worked out well" for Android, you and I must have very different definitions of the phrase.

You also didn't address my other point, which is sandboxing is only meant to address operating system level security, not developer abuse of legitimate APIs.

Re: Apple: Person-to-person experiences do not have to use in-app purchase

#484
post #473

Earlier quoted context omitted.

"This user just gave a third party their entire contact list" certainly does harm other people. "This user just had their entire camera roll exfiltrated" certainly does harm other people. These are social devices. Their users are, by and large, non-technical and incurious. Expecting them to not just click past the "scary sign", and so condition to do it again and again, so they can play Fortnite is a level of lack of…

...neither of those attacks you gave are unique to smartphones. Someone can leak personal information through any number of other channels - for instance, entering someone else's personal information into a website that send out emails for a group party invitation. > Expecting them to not just click past the "scary sign", and so condition to do it again and again, so they can play Fortnite is a level of lack of under…

> If this behavior is normal, then we need to make it not normal, not continue to compensate for their ineptitude. Fix problems, don't avoid them.

This sounds great in theory, but two decades of history of malware on Windows have already taught us it is hopelessly impractical.

Re: Apple: Person-to-person experiences do not have to use in-app purchase

#485

Earlier quoted context omitted.

I mean, presumably the people who really cared about side-loading decided to buy alternative phones instead. So, of iPhone buyers, you're left with two remaining groups: 1. People who care a little bit about side-loading but not enough to choose a difference device. 2. People who don't care about side-loading at all.

The assertion was that there is a group that values the lack of side-loading, which your post doesn't really address, so I'm not sure why you've responded to me. In any case: > the people who really cared about side-loading > 1. People who care a little bit about side-loading but not enough to choose a difference device. This is not a useful model. If I choose feature X over feature Y, all you can really tell from th…

I'm not sure that group values the lack of side-loading specifically. I think what they do value is the additional security and privacy benefits provided by a platform that strictly controls the distribution of its apps.

To the extent that the lack of side-loading helps prevent the spread of malware and shady apps stealing user data, I think they value it indirectly.

Android has serious malware problems. Even Epic's attempt to distribute Fortnite off the Play Store has directly led to fake APKs being distributed to unsuspecting users.

I don't see how you can open up iOS to side-loading without exposing it to the exact same malware problems Android has.

Re: Apple: Person-to-person experiences do not have to use in-app purchase

#486

Earlier quoted context omitted.

What features does iOS have that Android doesn’t have that are deal breakers for most people?

Of course questions like this get buried instead of answered. Buried by the people supposedly championing for everyone’s voice to be heard.

Not sure why you are throwing accusations of burying the question. Any post 3-4 comments deep will look 'buried' on HN.

I didn't down-vote the Question but I did choose not to answer it because it's a "Gotcha" question. Different users have different preferences on what they want out of their device or OS. Sure you can come up with a laundry list of features that exist on platform X or Y but it doesn't really answer the issue, because any given user will have their specific preference values for each, and talking about them starts pointless discussions of how one can approximate the same functionality on some other platform.

I can speak for my personal preference. I don't use iPhones so I will speak for Macbooks, but the idea is the same.

I like Macbooks for the quality of their touchpad (best in the market), their general look and feel (they don't feel plasticky), I like some UX polishes MacOS has, and I am a programer so I like that MacOS is a UNIX-based OS because I spend a lot of my time on the terminal.

Note that most or none of these have to do with Apple's software choices (such as locking down their OS much more compared to Windows) and in the future, if Apple makes MacOS closer to iOS in terms of their vice grip on what can and can't run on it, it will effectively be adding features that I not only don't appreciate, but actively find annoying. They are NOT what I own a Macbook for.

Re: Apple: Person-to-person experiences do not have to use in-app purchase

#487

Earlier quoted context omitted.

I personally couldn't care less because I don't have an iPhone but users can't realistically choose a device based on the cross product of all the features they want. There are always compromises. Some of these problems have outsized impacts, such as the way Apple extorts money from its App Store, which isn't a place most App developers can simply choose not to be on, any more than they can simply choose not to live…

What features does iOS have that Android doesn’t have that are deal breakers for most people?

Please see my reply to Razengan

Re: Apple: Person-to-person experiences do not have to use in-app purchase

#488
post #189

Earlier quoted context omitted.

Which is such a lie, because going to the press is exactly what gets a lot of apps re-evaluated and accepted.

Eh, it _can_ be a lie. This is some form of the quandary “if you owe the bank a million dollars, you’re in trouble; if you owe the bank a billion dollars, the bank is in trouble.” 99% of app devs will not benefit from “running to the press.” Those that will will know it for certain.

I've seen apps get their decisions reversed simply due to a post becoming popular on HN or Reddit. You don't have to be a major player for public shaming to work against apple.

Re: Apple: Person-to-person experiences do not have to use in-app purchase

#489

Earlier quoted context omitted.

When you allow additional app stores, you encourage companies--like, say, Epic Games--to convince people who do not understand the ramifications or the threats involved with opening up past a rigorous review process to do so. And Epic isn't going to be following behind for the newly-credulous when they pick up another one and it's full of dangerous shitware. Somebody who wants to not use the App Store can buy an Andr…

Possible credulous users cannot be the one-size-fits-all excuse for blocking the freedoms of everyone. There are many ways to mitigate any conceivable concern without abrogating the freedom of a phone owner to run the software they wish on their own device.

You have a perfectly viable platform that lets you run whatever you want on it in Android.

Go do that if you feel the need. Nobody's stopping you.

Re: Apple: Person-to-person experiences do not have to use in-app purchase

#490
post #317

Earlier quoted context omitted.

I do not want these apps and average Joe doesn't want them either. Why is it so difficult for people to imagine how insanely powerful and datapacked your phone is? Allowing sideloading to average people means they will get hacked and ransomwared left and right. Your entire life is on the iPhone. While I agree with you about sideloading apps for enthusiasts and hackers , but the world is far different than you and me.…

Android allows sideloading and I’ve literally never heard of anyone even doing that, much less getting hacked by it. I think you massively overestimate how many people would use that functionality.

Possibly ability of sideload makes Play Store not to restrict apps hardly like AppStore.
Post reply on HN