Currently, I can go to the App Store, install any app, and be about 99.9% confident that the app will do me (or my technologically illiterate mother) absolutely no harm.
This is something I value highly, and am happy to pay the “Apple premium” for.
Currently, I can go to the App Store, install any app, and be about 99.9% confident that the app will do me (or my technologically illiterate mother) absolutely no harm.
This is something I value highly, and am happy to pay the “Apple premium” for.
That's fine for you to want it, but don't impose it on me.
I want freedom and liberty to do what I want with the devices I own. I want to develop without fear that these two megacorps can shut me down on a whim for developing something against their ideology.
The web isn't like that. Windows wasn't like that.
Today we live in a Fischer-Price future land where everybody has to wear gloves because we might get burned. I hate what we've become. I want to go back to the world before smartphones and Apple and app stores. The open web. Before Facebook and Google became big brother surveillance operations.
Yeah, we get it, you're smart. I'm smart. Most people here are smart. But protections still matter.
What you're saying is I don't want to wear a seatbelt when driving my car. Sure that is your choice - but I think it is a very foolish one.
here’s an article from 2016: https://9to5mac.com/2016/03/27/how-to-create-free-apple-deve...
Average people don't care. If you tell 'em to do so or so, they will do.
Not at all. What he is saying is "I don't want my car to refuse to start if I am not wearing a seatbelt."
I don't think that is a good analogy in this case. It's more like he's trying to do a repair on his car, and he wants to be able to use some cheap parts sourced from elsewhere but the manufacturer has made it so only their parts will work. Sure, maybe the parts that don't come directly from the manufacturer will blow up my car, but I'd still have the freedom to choose than be locked down by some massive corporation because they say they're keeping me safe.
If you want to stay with cars, it’s like Google saying when you buy their car, you are only allowed to go to 6 pre determined destinations in their vehicles.
Some people find comfort in the lack of choice, since they know the drive won’t be “dangerous”, but for the rest of us, we want to make the choice of destination ourselves.
We simply want the choice to open our options without these companies punishing the consumer over making a choice with a very expensive piece of hardware we own.
This scenario still doesn’t prevent Apple and Google from providing their tightly controlled closed garden of choices for those that want it that way, but for the rest of us, we get our freedom back.
It's more like, when you buy a car, you are only allowed to go to Google-approved destinations. You are allowed to submit a new destination for consideration, but ultimately google can decide if you are allowed to go there or not.
Almost noone buys a phone because it's super locked down and some company decides when it's too old and can't install apps from the app store anymore.
As others have said there may be more apt analogies...sticking with the car theme, it may be closer to a market where you buy a Ford and then you can only fill your Ford up with Ford gas from a Ford gas station.
That market doesn't exist for clear cut reasons, but if it did you can bet Ford and other car manufacturers would claim the same thing, that limiting Ford owners to using Ford gas is for their safety, if Ford owners started putting gas into their Ford from a 3rd party, there could be all kinds of harmful additives or other quality issues with the gas that will damage the Ford. Of course Ford won't mention on their tax to "Ford gas suppliers" (of 33%) for access to the Ford car market.
As it relates to printers/cartridges unlike my car manufacture/gas hypothetical or the app store, I could potentially see certain IP (from patents to trade dress) rights that may actually help the printer companies argument (but again I think they backed down anyway).
A company takes for granted that they are good actors, and that their customers' interests are perfectly aligned with their own. With those assertions, increasing their control can only mean a better ability to make things good/safe/simple for their customers.
But that is an authoritarian delusion. Because real difficulty arises out of cross-party emergent complexity - illegible and unmanageable by any single entity. And the road to hell is paved with good intentions. This is blatantly obvious when you, as an individual actor, eventually end up at odds with whatever authoritarian scheme they've implemented - wishing to do something simple that you've personally judged as good/safe, but it's impossible to convince that centralized controller to understand / approve it.
In the real (multi-actor) world, we acknowledge that interests diverge on either side of a transaction. Someone who has bought a printer is then an individual participant in the ink market. Someone who buys a pocket computer wants that computer to act for their own interest - not for it to be beholden to the whims of the company who made it.
Unfortunately, always-on communication, the difficulty of reverse engineering, and overbearing copyright law have allowed these companies to double down on overarching control rather than allowing reasonable demarcation points. Apple could straightforwardly create an app sandbox that would allow running fully untrusted code with fine-grained capabilities, unilaterally design it to not have the vulnerabilities that the Web continues to have (eg fingerprinting), and allow sideloading after appropriate warnings. And lest you think I'm being partisan here, the same exact thing applies to Google's general insistence that sideloaded apps are less safe.
But it's much simpler and more lucrative to double down on authoritarian control until they're forced to create those demarc points, either by direct legislation or by consumer demand - eg if this recent censorship trend eventually pushes them to prohibit secure communication apps in their central stores.
Bad intentions are not necessary to build an authoritarian system. All it takes is enough good-intentioned people being unaware of the system they are building and their role in it.
I've been using a little multifunction brother laser printer and convinced my sister to do the same in college and those are the only printers I've used in a long while that don't give me issues.
The only other printers I used that never gave me issues were the high end laser printers at University.
You give complete access to a licensed dealer, that can be trialed, if abused.
Or you go to Brasil to pay 1/10th of the price and give them a copy of your password and address.
Something like that
In what world do I want a transit app listening to my microphone?
There isn't anything that precludes security in an app store-less world. If we sat for an hour, we could whiteboard a number of technical solutions that could be engineered.
- apps still require signing
- implementing a stricter permissions / ACL model
- continuously scan devices for malware or bad heuristical behavior
- publish a list of misbehaving apps that can be subscribed to and automatically scrubbed
- semantic sets of app permissions. Gallery apps don't get microphone, contact, or location data.
We could easily engineer for a distributed world. The problem is that Apple and Google want complete control. Playing gatekeeper gives them authority, and they get to take a large rake of any money being made.
Don't make excuses for their model. They're bad actors that have abused their monopoly powers.
This is about personal freedom. Not wearing a seatbelt can put others at risk for injury liability. Installing an app will not do that. Let's stay on topic. And while we're at it, you and I both know that majority opinion has never been strongly correlated with truth.
Ever seen a botnet?
Wow, I'm surprised that has never occurred to me before. I guess that to most people, such as myself, the trade-off is so obvious from a personal safety point of view that we don't think too deeply over it. This is a great point.
Who imposes this onto you? I have a great idea for you if you dislike the App Store: Don't buy an Apple Device. Turns out Apple doesn't owe you shit. Oh, also the same "get off my lawn" libertarian viewpoint of yours can be claimed by Apple. They might want the same liberty (to do as they like with their platform).
I recall Microsoft using that defense once upon a time.
IF you don't like Explorer or Netscape, don't buy a PC. Turns out Microsoft doesn't owe you shit.
However, it turns out Microsoft does owe consumers something, the Settlement is available for anyone who cares to know what that something is.
Like the fact that Microsoft had 90%+ desktop market share and was using it to shoe-horn an unrelated inferior product with powerful network effects into dominance.
Whereas Apple has no monopoly and in fact their overall smartphone market share is falling.
Let Apple compete how they want to compete, as long as there are viable competitors. Of which there are several.
To look at the smartphone market and how far it’s come in the last 10 years and decide this is a space which needs anti-competitive enforcement action from the FTC is abusing monopoly law to obtain a political outcome.
Who are the viable competitors? It is Apple and Google/Android right? Everything else is the equivalent of Bing competing with Google Search. Keep in mind another MS defense was there is Mac and MacOS, we even build a IE for MacOS, therefore, we can't be a monopoly.
>To look at the smartphone market and how far it’s come in the last 10 years
Maybe there is a thriving competition in the smartphone OS market I am unaware of, but I thought maybe in the last 10 years the market went from MS, Blackberry, Apple, Google/Android...to more a consolidated market and effectively Apple and Google/Android.
The political outcome is interesting, I haven't heard that before, what exactly are the politics involved with wanting Apple to allow a 3rd party app store?
Agreed.
> Of which there are several.
I count one (Google). Who are the others in the smartphone space that are viable competitors to Apple in either company's home market (USA)?
I'm not sure "home markets" are really relevant for global entities like multinational companies.
Android trivially lets you sideload apps downloaded from anywhere on the internet you wish. Apple not so much, but that's Apple.
The vast majority of customers want an app store with tighter controls, and both Google and Apple provide it. There are a hell of a lot more complaints about these app stores not being locked down enough than those in your camp saying that they don't want it locked down at all.
The vast majority of users are perfectly fine with the Windows experience of dodging fake download button ads, unticking bundled McAfee installs, having no automatic update mechanism, etc (which is still more or less the default even on Win10).
They only start caring when they can't do something they want to do. They rarely think about the "how".
Ignoring the windows store, this is really more of a "let developers handle their own updates" situation. The vast majority of modern windows software updates itself directly or through a loader (steam, etc). Windows developers can easily tie into distribution services that offer update mechanisms. The default user experience is not 'no automatic updates.'
Tell that to the millions of people who installed Fornite mobile outside of any app store.
Most people don't care where their software comes from at all.
The reason there are complaints about the app store is because both Apple and Google are capricious and inconsistent with their application of their rules, and have no problem pretending their strict rules need to be enforced, but then allow apps that break their rules with adware or spyware on their app stores.
this got me thinking. how is that handled by a democratic system of government? with an independent judiciary, of course. we need an independent, third party App Court! we need a powerful organization that can referee and literally force Google and Apple to put an app back in their stores.
Customers choose from the options that have been marketed at them.
What the "vast majority of customers want" is a lazy, pessimistic, terrible way to invent the future. Where's your imagination and ambition for the way things could be? Have you forgotten that we have choices far beyond just "what Apple and Google give us" and "nothing"?
Do you think we would even have Apple and Google if everyone had your "take what the market gives you and like it" attitude?
Most people I've talked to don't even realize you can allow apps to be sideloaded on android. Most people don't even really look at their settings menu other than to change backgrounds and stuff.
I mean, at least on the latest phone I bought, I had to go to the build number, tap on it a bunch of times to get to the developer options, scroll down through a bunch of options that likely look terrifying to the average user until I found the option allow apps from outside sources.
When I tell people they can do this, or I tell them about f-droid or show them things on there, they tend to be kind of shocked that you can do that and usually want me to teach them how.
I've noticed a lot of people for the most part are kind.of scared to really dig into their devices without being told it's ok, but as soon as they know it's not going to destroy everything, they usually start trying to dig deeper.
The easy walled garden approach I find really stops people from wanting to learn more about what their devices can do and gives kind of a false sense of security, there's plenty of garbage and unsafe stuff in app stores and honestly, I use almost as much diligence downloading from there as I do from random places on the internet. A lot of people don't read reviews or bother even looking at permissions before the get something from the store and end up filling their phones with garbage anyway.
The real problem is that Google’s been unable to either secure Android or prevent malicious apps from showing up even given their locked-down store.
Windows wasn't like that.
Yeah, and it was an absolute disaster. Until very recently (Win7, roughly, or perhaps Vista) near every Windows install -- unless it had been locked down by an administrator, or maintained by a power user -- was an absolute cesspool of malware and outright spyware. The average Windows machine was literally unsafe to use. That's fine for you to want it, but don't impose it on me.
Essentially what you're asking for is a return to the world where some of the most common consumer devices in the world could only be safely operated by power users. Except it would be even worse today, since smartphones are so much more essential and offer so much more information about us (biometrics, location services, mics, cameras, etc) that can be harvested and exploited.I (a power user!) sort of miss those days too. It's not like I ever had malware.
But in general, that wasn't working.
What do you think about compromises (like macOS, and Android) where non-blessed software is disabled by default, but can fairly easily be sideloaded?
If people don't get the opportunity to fuck up, you arrest their development. Stupid software users then becomes a self-fulfilling prophesy. Users will become dumber than they ever were before, and therefore more and more reliant on software developers to do/make everything for them. In my cynical moments, I suspect this is all intentional... Imagine if the fast food industry were throwing their weight around to promote the idea that children should be kept out of kitchens.
I believe the same is the case with limited control over technology. Most users do not care to learn, and would opt to actively avoid the opportunity to learn if the associated danger was removed for them.
In my opinion the best option is to remain in the current state by default and have a more obscure 'power user' option that could be enabled within the OS itself.
I mean, I do it for a living and I'm glad I know.
But I don't really know how bridges, or electric guitars, or cars, or genetic engineering, or oil paintings work.
It's awfully gatekeeper-y to insist that computers should be these totally wide-open, unsafe spaces.
I mean it's almost exactly like saying people should know how to rebuild an engine if they want to drive a car.
It's certainly good to know how to rebuild an engine, but surely many people should be able to use cars without knowing that...
As a further point, drivers are (with edge case exceptions) not kept away or locked down from performing any work on their vehicle, yet in most cases they would still prefer to pass the responsibility on to a trusted professional.
Recently, I fixed a number of small (non-drivetrain) things on my car and I wish I knew more.
- Network access
- Direct hardware access (such as games accessing the GPU)
- Sharing data to other software
- Consuming data from other software
- etc.
As we've seen, we wind up needing to turn a bunch of these on for most software, and while it's certainly better than giving them carte blanche over the entire system, a handful of these permissions are enough to work some skullduggery.
Most software does not "need" network access, it just ends up being used for telemetry, serving ads, and checking for updates you probably don't need anyway.
> Direct hardware access (such as games accessing the GPU)
"Direct", meaning they need a context handle and some shared memory to get composited by the OS. Still, I'm honestly not sure why this isn't a solved problem today. Why are GPUs not virtualizable the way CPUs are?
> - Sharing data to other software > - Consuming data from other software
Software can be grouped together and allowed to talk among eachother within a certain context without giving any given piece of it the ability to burn the world down.
You'll have a hard time convincing me that taking control away from users is a better solution.
I agree that users need full control. I also think a few decades of personal computing have shown us that the defaults should be pretty safe and therefore restrictive.
Users should have to jump through a hoop or two (perhaps as simple as `sudo enable-expert-mode` in a terminal, or some such) before being able to shoot themselves in the foot.
As a result, all users are imperiled.
I mean, even with an App Store, IE would have been pushed hard, just like Edge is now. And it still would have been a buggy mess, and people would have still been infected...
I can't believe I just defended Windows here...
I fixed hundreds, maybe thousands of machines infected with malware back in those days. Switching users to Firefox and a safe e-mail client nearly eliminated all of their issues.
Here's [1] over 1000 CVEs in Windows 10 alone, many of quite critical nature and not related to IE or OE.
Here's [2] another 1200+ for Windows 7.
Here's [3] 741 for the "back in the day" Windows XP.
[1] https://www.cvedetails.com/vulnerability-list/vendor_id-26/p...
[2] https://www.cvedetails.com/vulnerability-list/vendor_id-26/p...
[3] https://www.cvedetails.com/vulnerability-list/vendor_id-26/p...
I wasn't a computer person back then. But I quickly learned about SMB file and printer sharing being wide open.
I think that's exactly what the vast majority of people advocating for sideloading are proposing. At least it's what I'd propose.
* webapps -- we tried this (iPhone v1) and they were awful. The web keeps improving but apps have consistently been years ahead.
* native software -- still too difficult to secure reliably.
We haven't really been suffering from fragmentation. We've essentially consolidated down to two platforms. You can also develop for the web or use a cross-platform framework.
Not really sure what you see as flawed. The app model has been wildly successful.
* It's only imposed on you if you want an iPhone * That said, I'm generally sympathetic to caveat emptor, as well as the idea that the provider of the OS should be spending gobs of resources on proactive protection against apps they don't even know are malicious yet. I also don't see why there can't just be a secondary app store where apps don't get the same level of scrutiny and that fact is made very, very explicit. Call it Caveat Appstore
That's the problem though. That last 0.1% is difficult, and Facebook (which, if your technologically illiterate mother doesn't have it installed, many others do) has been repeatedly shown to do harm to their users. Yet they're still on the apple app store.
What is needed is a big red button that makes it easy to sideload an app (download a file and run it) and explains the implications to the user.
The app was indeed a scam by a random chinese dev impersonating a company he was not related to by using their brand as app name and their logo as app icon.
a: Let me install from elsewhere if I want, like Android does (and I love)
b: have more transparency in the back end processes of the store and better appeals. Right now it's very arbitrary and capricious. Yes they have a published set of rules, but they're enforced and interpreted in a very unpredictable way.
Your mom always uses the App Store, everybody else is happy.
We got my wife's grandmother an iPad because she kept getting fleeced by Geek Squad after opening email attachments. Smooth running for years now.
A lot of people don't have any need for a full-on computer.
I've considered something like Solus-based laptops for them, but I haven't gotten around to testing out a configuration yet.
They're happier as their technology always works the way they expect. I'm happier as I don't get any more tech support calls.
Please don't take that away from me.
What is this nebulous "damage"? If an app escapes the sandbox and totally hoses the operating system, the fix should be basically plugging the phone into a cable at home and waiting say 24 hours to prevent evil maid attacks. If the malicious app manages go further and screw up the "hardware", then that implies a serious security vulnerability and so should be covered under warranty.
A security model based around every bit of code on a device being vetted is fundamentally unscalable. The cracks are really starting to show, with increasing false positives and false negatives.
Now imagine people downloading all sorts of scam apps, having personal data uploaded, ransomware, you name it. And they are going to take that sucker straight to the Apple store if they don't have friends/family to fix it.
Aside from that, I personally view the Apple App Store as a feature and a benefit to me. I don't want another App Store even if it were available.
> people downloading all sorts of scam apps, having personal data uploaded, ransomware, you name it
Obviously if you just get rid of Apple's current solution and don't replace it with anything, then those things will happen like the jungle that was Windows. But that does not make for an argument in support of Apple's current solution.
The answer is to address those problems for arbitrary code (eg isolation and fine grained capabilities), rather than simplistically asserting that any code on the device must be "good" and then enforcing a singular top-down regime to assure that.
> I don't want another App Store even if it were available.
See if you still hold this opinion in ten years when large companies have been pushed to ban secure communication tools in the interest of "public safety". The writing is already on the wall.
(My current support load mainly consists of needing to help my dad because app UI elements are designed to be invisible. This is a problem caused by centralized control - banks create their own decommodified apps and want to look hip in the "design" world or whatever, as opposed to publishing a standardized API that would allow creation of independent apps for old people. And the same vacuous "security" FUD gets dragged out to justify that state of affairs as well)
Aside from that, the iPhone app ecosystem is perfect for me. Maybe it’s not perfect for you but I like it how it is and don’t want it to change and I don’t want more people in my family bothering me with tech stuff. If you want custom stuff why can’t you use Android and a Pixel 3 or something? Plenty of other options out there.
I’m not saying Apple is wrong to make as much profit as they want. But to say any more than a 10% take at most (likely less) is a tax to have the ecosystem running can’t be true. Not with the $100 a year on top as well.
The $100/yr developer account fee is an anti-spam measure, not an actually significant revenue source.
Apple and Google App Stores combined currently generate almost $100 billion in revenue per year. This is the biggest and best revenue source available on the planet for smaller developers.
Easy end-user side loading, and third party app stores is a direct attack on this ecosystem and will damage the livelihoods of developers who will have no way to fight against massive increases in piracy that will result.
Windows developers seemed to be doing pretty well, even without an app store...
But I am pretty sure the vast majority of applications on the App Store in the $1-$10 range would simply not have been possible to monetize in the Windows XP era.
Remember shareware? What percent of people actually paid for that? You think the market was even 1% the size it is now? CompUSA’s best annual revenue was $2 billion and only a fraction of that was software, and only a fraction of a faction of that was anything but enterprise software and big studio games.
And the market for apps on phones was a fraction of 1% of what we have now from the App Stores.
I'm saying the end result winds up being the opposite of the ideal scenario OP's setting up - the people least prepared to evaluate the dangers of side-loading stuff are the most likely to go and do it.
Free kids apps are the worst, because young children try to play the game and constantly end up steered towards ads that they don’t know how to navigate away from.
They'd be small enough and focused enough that their only option for survival would be trust.
If you make network effects harder (e.g. it extremely easy to submit apps to all of them), I don't see this not becoming a competition over price. And security is expensive. You'd have to prevent people search some nice apps on your store, then downloading the same on a different store with lots of shit tier apps as well, if it saves them your 30% tax.