Epic had (/has?) this with Android and gave up because... reasons?
Epic had (/has?) this with Android and gave up because... reasons?
So Epic wants both Google and Apple to abandon their security models and allow direct installs of apps.
Phones have been an enormously popular computing platform in significant part because of the security model. Non-technical users can use them easily and reasonably trust the apps they install. Epic is asking for a rather radical shift.
>and reasonably trust the apps they install.
That seems like an illusion though to me.
https://www.cvedetails.com/top-50-products.php
Android comes in at #2 for number of distinct vulnerabilities and iOs at #8 both in the top ten and both above windows of all things. Which rings in at #10 for 7 and #13 for 10. OsX sits at #4.
1. How much less secure would Android be without even the play store’s security measures?
2. How much harder would people work to find vulnerabilities on such a ubiquitous platform used by non-technical users if any app could be installed?
You would likely get more malware and more app hesitancy.
More malware, possibly, though android has plenty of that even with the play store. But, app hesitancy, maybe from a small subset of people, but i feel like those same people already show app hesitancy.
Only from my own experience, but i treat apps from the app stores about the same as i do random apps from the internet and do the same thing to verify in both situations, look at reviews and information about the app and make my judgement based on those. It's the same either way. All app stores do in my mind is aggregate reviews to one place, whether it's the play store, the apple store or the steam store, etc. I trust each of them about as much as something such as apk mirror, in all cases, i'm relying on the opinions and information provided by others that have used the app, if no such information is available, i consider it suspect and avoid.
The method acquire an app isn't what invokes trust, it's other user verification, no matter whether that app came from a store, a repo, a random website or any other method software can be delivered and it always has been, since the days of floppies.
You still need to exercise caution with permissions, but an individual app itself has pretty strict limits. Most of the security flaws are tied to the OS itself.
Which was the point of my original comment, that phone OS's provide the illusion of being more secure, while being about as secure as any other platform.
From what I can tell, computers are about as secure as they've ever been, whatever the kind, which is, alright depending on the user. It's always been like that and still is.
App stores and sandboxes haven't changed that.
Is it 100% secure? No. Is the user experience that I desire available due to app stores and sandboxes? Yes.
The point of the single-source App Store is that the app review creates a line of defense against such trickery, on behalf of the user.
Android has always been a shitshow,so the gnu link is unsurprising - however I did not find an example of iOS malware.
But it does highlight the problem here.
Let's say I take epic at their word, that this is not okay (and I'm tempted, this whole judge jury and executioner thing is ridiculous. Apple has now said that they regret that they can no longer spend time with Epic on making sure the Unreal engine runs well on mac hardware. That is so close to 'nice house you got there. Would be a real shame if something happened to it' it makes the hairs on my neck crawl).
What then? Sideloading with security measures is something google has but that's according to epic not good enough (and I'm again tempted to agree).
But clearly some free for all fiesta is no good for the users. And I don't think governments, certainly no the US government and probably not the EU either, are capable of defining the playing field, this stuff is too complicated.
So... what then?
I would hope that Apple (and Google) realize that this fight has only users, and the name of the game is to walk the line so that nobody is pissed enough that you end up with exactly what just happened. And it looks like apple has decided they like the hole they are in, as it sure looks like they are frantically digging.
They probably listed in the Play Store in order to get standing to sue Google.