https://mashable.com/2017/06/12/apple-app-store-subcription-...
https://9to5mac.com/2019/10/25/malware-iphone-apps/
https://www.techtimes.com/articles/235985/20181204/apple-rem...
https://www.wired.com/2015/09/apple-removes-300-infected-app...
They get so much wrong, so often, you have to wonder if they really look at the apps at all or just have some checklist, screenshots and a quota to hit. They explicitly approved all the garbage practices that Apple Arcade's billing protects users from.
From my own app review experience, this is all they do.
A shady developer tricking people and a shady website tricking people result in bad things.
To get this trojan I'd need to go into settings and tick this box:
https://q3fb03rfy3f4ahuzu2uy6e11-wpengine.netdna-ssl.com/wp-...
Then go to the dodgy website, then download the apk, then install it then pikachu face when I get a trojan.
And you can talk about how great Apple's security is but to fix this issue all Google has to do is remove that tick box in settings so no more sideloading apps.
But that also comes back with drawbacks that I assume an Apple user like yourself wouldn't know about, because all you know is a walled garden. Sort of like how Chinese people love the fact their internet is censored. So safe, so secure.
Yes, truly... because there's no way that someone who uses an iPhone might know about the existence of Android/Windows/Linux/macOS or any other system that allows for sideloading and/or installing un-certed apps.
The point is, even if Apple allowed sideloading, there's no way that the iOS sandbox model would allow for what's being described here. The comparison wasn't accurate.
Your condescension and ignorance doesn't help that argument at all.
And yet, they don’t.
> But that also comes back with drawbacks that I assume an Apple user like yourself wouldn't know about, because all you know is a walled garden.
Funny how Android users keep saying that. I’m an Android developer by profession, which is why I use an iPhone as my personal phone and would never recommend an Android device even to my worst enemy. I’ve seen how the sausage is made and it isn’t pretty. The best thing you can say about Android is that it’s free, which correctly reflects what it’s worth.
Apple's capricious app store review policy aside, iOS is so locked down that even a completely malicious sideloaded* iOS app can't dig itself into the system like this. Without a local privilege escalation exploit there's just no way to set up a persistent background service and no way to escape the sandboxing to allow an app to leave a mark on the system after your app is uninstalled.
(*a developer can basically sideload any app on their iOS device with an Apple developer license)
> According to Malwarebytes, the source of these infections is "web redirects" that send users to web pages hosting Android apps. These sites instruct users on how to side-load unofficial Android apps from outside the Play Store. Code hidden in these apps downloads the xHelper trojan.
https://www.digitaltrends.com/mobile/google-play-store-malwa...
While they were live, they didn’t steal data or gain control of a victim’s device, ....And while the worst effects you’d feel as a victim in this case would be a quicker battery drain and a higher data bill, this latest wave of iOS malware is most notable not for what it does but for how it got there.
Which is a far cry from an unremovable app. It didn’t even get outside of the sandbox and wasn’t an escalation of privilege attack.
In general really wonder why people still defend Apple these days. Even if you overlook a combination of stuff like infinite attempts for icloud logins that led to the Fappening, their role in HK protests, and of course their pretty terrible labor practices that go so far as even to supposedly break the Chinese labor laws (which is a feat in itself), there is still issues with stuff they produce. Their hardware and software quality has been on a hard decline, especially if you compare it to alternatives rather than on its own merit. They don't really innovate despite opposite marketing claims, and they still participate in this "technology as a jewelry" thing with their $1000 monitor stands.
Do you also suggest defragging and do you have any tips for editing my himem.sys and config.sys files so I can play Doom?
It's basically how linux systems work, most stuff comes from the package manager which has been pretty good at keeping out malware and users can install whatever they want from elsewhere.
There are already many legitimate apps distributed outside of Google Play for various reasons, such as weird Google policies or simply being booted out with no or spurious reason & the developer not being able to ever reach a human to fix this.
So be careful what you wish for.
I think Apple's desktop solution to unverified developers is a good way to split the difference. Deny by default but allow whitelisting. They go even further under the privacy tab and only allow certain applications permission to access accessibility features or full disk access, etc.
Maybe it's a good idea to hide the "Allow sideloaded apps" under the developer menu in Android or something, or generally to display a scarier message.
This and it's ability to survive factory reset may indicate, that xhelper can gain complete control over device (probably via improperly built firmware or unpatched root exploits). No amount of sandbox enhancements can stop this kind of priviledge escalation.
That's not to say in any way ANDROID BAD or anything like that, it's just a broader attack vector that you're up against with Android unless you're a very careful experienced customer. Most people aren't. :/
It's incredibly frustrating to read these pro-walled-garden-arguments. By the same argument you could say that the people in Hong Kong or elsewhere should just shut up and accept that their leaders will know what's best for them.
I worry about a future where these locked-down devices will be the norm for all of us. Don't defend Apple for locking you in. That's ridiculous.
My objection is that it's not that useful to only look at whether a party wants to restrict freedom. Personally, I don't think that's a very useful dimension at all -- I don't consider the existence of a road limiting to my freedom to drive wherever I feel like it.
Of course, you can always use another road or go completly off track. Like living in the woods?
Fundamentally, the problem exposed by this particular piece of malware was the ability for it to persist across removals and device resets, not that it was "sideload-able" by the user. Malware persistence should not be possible on a well-designed system, especially one where applications are generally untrusted and sandboxed. Had this been malware that requires sideloading but could be removed when noticed, it wouldn't even have made the headlines at all.
The problem with making the walled-garden argument here is like saying nobody will get sick if we just put everyone in isolation all the time. Like, sure, it is _a_ solution, and assuming the isolation is perfect, it _does_ achieve the goal... But this merely sidesteps the problem, and anything that slips through the wall (which as pointed out by other commenters, does happen on iOS too) will be just as dangerous as before.
The real solution is to "buff up everyone's immune system" and make it easy to restrict and treat malware apps when they inevitably end up on a device, walled garden or not.