Earlier quoted context omitted.
Usually when you fire a customer they can go to one of your competitors. This just proves Epic's argument. There is no competing App Store on iOS because it's not allowed. If Apple "fires" you then your users can no longer install the app onto their own phones. Imagine if Microsoft "fired" Adobe and as a result nobody could install Photoshop on Windows anymore.
Microsoft can fire game developers from Xbox.
Apple to kill Epic’s accounts on Friday the 28th
541–550 of 996 posts
Re: Apple to kill Epic’s accounts on Friday the 28th
#542Earlier quoted context omitted.
Myself. If not for IME, I could have a computer under my control, running software guaranteed to be free from the Trusting Trust attack, right now .
I respectfully disagree in my case. I don't consider myself a security expert at anything, especially at computers. This is probably 99.999% of the Apple customers. People like yourself can probably manage their own security, have a secure NAS, multiple firewalls, etc. Do you see it from the perspective of average Joe (or me)?
I usually choose to trust them, because it's convenient and because they probably know better than I do. But my trust in Debian is completely voluntary, non-exclusive and revocable.
Re: Apple to kill Epic’s accounts on Friday the 28th
#543Can someone give me compelling reasons for disallowing side-loading of applications on iOS? Hypothetically, if side-loading were to be allowed it could be buried under a configuration+confirmation flag for security reasons just like with Android or Windows 10. Thinking more abstractly about this, I already do "sideload" iOS applications when I sign them with enterprise/developer certs and perform OTA installs from sy…
If I see an app in the App Store that I might be interested in trying then I can download it and be pretty sure it's not malware, it does roughly what it's advertised as doing, and I can see from its price and the IAPs listed in the store whether it's reasonable value. By contrast every time my mum clicks a Facebook advert and downloads an app on her Android phone it makes her phone noticeably worse to use. Apple is…
If the ability to side load an app is not enabled by default, how would novice users accidentally install apps they may not have intended to?
Re: Apple to kill Epic’s accounts on Friday the 28th
#544Earlier quoted context omitted.
Stallman is a difficult person to like and he is wrong about many things, but not about this, the central issue of his career.
What do you find him wrong about?
Re: Apple to kill Epic’s accounts on Friday the 28th
#545From a preliminary statement of Epic's motion: > Just over two weeks ago, Apple’s CEO Tim Cook was asked during a Congressional hearing whether Apple has “ever retaliated against or disadvantaged a developer who went public about their frustrations with the App Store”. Mr. Cook testified, “We do not retaliate or bully people. It’s strongly against our company culture.”
Some might see a difference between "a developer who went public about their frustrations with the App Store" and a developer who deliberately violated the policies and then filed a lawsuit and started an extensive PR campaign.
Re: Apple to kill Epic’s accounts on Friday the 28th
#546Earlier quoted context omitted.
>In Windows world, you can just pick a new certificate vendor I mean if they really wanted to they could blacklist your CN or O value in the certificate, or add you to the windows defender/smartscreen detection list, which will effectively kill your app for a good segment of the windows userbase.
Which is why this certificate system is completely useless, making people expend a lot of effort to prove nothing.
Having to pay money introduces a money-trail and a paper-trail. If a payment for a certificate is made with stolen CC details then the certificate gets revoked. This also effectively stops opportunistically-written malware taking advantage of current events (click bait email subject lines) to spread via email attachments.
The value from code-signing isn’t just the (I agree: very weak) attestation of the software’s author’s identity - but because it introduces a revocation mechanism and a reputation system - and creates barriers-to-entry that burden malware authors more than legitimate software vendors.
It’s not perfect, but don’t let perfect be the enemy of good.
Also remember that the only proven successful alternative to the current open PKI/CA system is the closed walled-garden approach favoured by Apple. I don’t think any Web-of-trust system has ever really been demonstrated as being feasible long-term without some WoT nodes evolving into pre-trusted/super-trusted nodes with the same power that CAs have today.
And at least with PKI+CAs you can add your own trusted root certificates and remove those you don’t trust.
Re: Apple to kill Epic’s accounts on Friday the 28th
#547What took me aback was the withdrawing permission to notarise their apps for Mac. That was only meant to be a check for known vulnerabilities/malicious software. Apple was more within their rights to kick Fortnite until the dust has settled from the iOS store, that was the retaliation, but now a mechanism supposedly for security has been repurposed as punishment. That's a pretty nasty move and I feel the mask has sli…
And you thought it wouldn't be used as punishment... I wonder, why people are so naive? I'm pretty sure that any kind of software that is not deemed good for the guardian's business(i.e. Apple in this case) will be blocked/suspended. DMCA related suspensions are the first that come into my mind.
Re: Apple to kill Epic’s accounts on Friday the 28th
#548Earlier quoted context omitted.
You can bypass it: https://support.apple.com/en-us/HT202491
You can also disable AMFI, the component that enforces signatures and entitlements, altogether, but you have first to disable SIP completely by either booting into Linux of by patching the kernel and then setting the requisite NVRAM variable directly. (`spctl` does not, in fact, disable it completely.)
I don't think thats an option on newer MacBook Pros any more.
Re: Apple to kill Epic’s accounts on Friday the 28th
#549Earlier quoted context omitted.
Someone looked at how much money they are making on iOS and multiplied it by 0.3 Imagine getting X% of everything you sell going forward without adding any extra features - just by complaining
I saw somewhere that Epic earned $500MM from the iOS version of Fortnite alone in 2019 -- so Epic was looking at potentially $150MM USD/year.
Re: Apple to kill Epic’s accounts on Friday the 28th
#550Earlier quoted context omitted.
It's important to note that you can still run unsigned Mac apps. Apple isn't preventing users from running a tool they want to run, it's just showing them a big scary warning and making them jump through some extra hoops. It's incredibly scummy and inappropriate, but I would put it more along the lines of an attack-ad than an outright ban. Edit: Now, one thing that isn't totally clear is whether or not devs who have…
IMO, it’s about the moral equivalent of using dark UI patterns to trick users into performing actions they don’t want to do. The scary warning and convoluted workaround for running un–notarized apps is ostensibly to prevent non–technical people from compromising their computers. Now Apple is abusing that security mechanism for Business Reasons that have nothing to do with protecting users. The fact that users can tec…