EU antitrust: Apple shouldn't use privacy and security to stave off competition
appleinsider.com
appleinsider.com
I'm glad this is being pointed out, as Apple has long subverted (and done damage to, IMO) the privacy conversation by telling users that privacy can be obtained by giving up their privacy. The main aim has not been privacy, it has always been to lock users into their ecosystem with carefully controlled images, misleading advertising campaigns, PR spins, and their analogues/equivalents to "think of the children".
Realistically, I do not have any hope of anything being done as there is far too much support for, and normalization of, the current jail. This isn't the same landscape that punished MS many years ago - who have been relatively harmless when compared to FB, Apple and Google - these three companies have been playing a slightly more clever game with their EU ties and I fully expect them to get away with little more than a slap on the wrist, while relaxing in their tax haven.
If you listen to the interview, the actual message from Cook is "privacy and security go hand-in-hand", which is plainly obvious and supported by history and data.
Maybe I'm missing something from a different source. Where has Apple said, "privacy can be obtained by giving up privacy"?
iCloud supports storage if encrypted data and disabling unencrypted backups.
It's fine that you reject the legitimacy of government, but unreasonable to expect huge organizations to do the same while serving hundreds of millions of users.
Offering services to fully anonymous counterparties is fraught with challenges.
Android is extremely vulnerable to third party attackers via apps.
> I can't only build apps and platforms that only work for half the potential users.
Are you sure even close to half of your potential users use (exclusively) iOS? I severely doubt that.
Exactly for the reasons you mention, people who want self-managed security don't use iOS.
And what apple is doing is not giving their customers and users a choice other than an extremely radical one of abandoning the platform completely.
FWIW, though: 1) even if you expected the vast majority of people to be using one system instead of the other, you can't build a communications platform or payment system or ecosystem generally at all that simply cuts them out as it causes problems for the people and companies trying to adopt it... if you build a platform for decentralized apps that doesn't support iOS or a chat system that doesn't support iOS or a payment system that doesn't support iOS, well, you now have to convince everyone else in the world not to support iOS: your hands are frankly tied here.
I call complete bullshit on this. I want the same thing, and so so many other people. The only reason we don’t have it is that it’s a lot of work and nobody has done it yet.
Blaming Apple for their business standing in the way of network effects is just an excuse.
If the software was built, we’d find a way to run it.
Nobody has built anything like the whole stack needed for a secure distributed App Store with private payments.
It’s obvious you can’t build such a thing on top of Apple’s store, it’s just not credible to claim to be trying and being stopped by Apple.
You could build one for Linux or Android. If you actually made it work, then it would be existence proof that a centralized model is not needed for a private and secure store.
That hasn’t been proven and the way to prove it is clearly to build it where it can be built, not to make arguments about Apple’s bad faith.
They sell the idea that Apple is the only "trustworthy" entity capable of handling and protecting your data, so you can trust them with your data and you should ignore how they are datamining it (because they are "trustworthy").
[1] https://www.idownloadblog.com/2019/03/13/apple-maps-navigati...
This doesn't seem to be true. Privacy here means "user privacy" whereas security means the security of the systems holding the user data.
Almost any system that hold large amounts of user data is a counter example. Such systems are typically highly secured but are antagonistic to user privacy.
Think about this in the extreme: imagine your computation platform is a virtual machine on a hypervisor controlled by your adversary. There would be no way to use this platform to safely interact with your private data.
A good example, since we are talking about Apple is "the fappening". A massive leak of celebrity photos, including nudes, coming from compromised personal iCloud accounts. It is an obvious attack on privacy, made possible by poor security.
Now, you can tell me that the best way to respect privacy is not to store user data, and it certainly helps, but if your software is insecure, it may be used to harvest passwords or do all sorts of nasty stuff. In other words, maybe you don't store anything but hackers will.
You can't guarantee privacy without security. And even for companies with poor privacy practices, with security, only authorized people can spy on you, without it, anyone can do it.
When are they going to allow us to opt out of the baseline telemetry that we cannot opt out of as per their EULAs?
When are they going to make their own ad targeting network opt-in instead of opt-out?
When are they going to give us the option of full E2EE for our iCloud data?
What you have just described sounds like a really good product to me since Apple themselves are not a vector in my privacy threat model.
Mostly the same here.
But, when their ad-targeting goes fully online?
When they hand over your data due to a lawsuit you didn't expect?
Apple products are exploited near weekly, then run ads for Security.
Apple makes everyone use the same app store and web browser, then run ads saying "Think Different"
Apple runs on doublethink, merging the latest psychology tricks with their marketing department so their product departments can cut corners. Accounting and Finance departments love it.
Ironically, in the case of web engines specifically, mandatory WebKit on iOS is the only remaining substantial resistance against a Chromium monopoly. Safari/WebKit sits at ~18% while Firefox/Gecko has dwindled to ~3%[0]. If third party web engines were allowed on iOS, WebKit's share would almost certainly plummet to match that of Firefox with Chrome and other forms of reskinned Chromium taking its place.
It gets contributions from Google, Facebook, Microsoft, Opera Software, Adobe, Intel, IBM, Samsung, etc... It is not controlled by one company.
So, not nearly the "browser monopoly" as it was with Internet Explorer at the time.
Blink didn't become a "monopoly" because of pressure from Google... as it was pressure from Microsoft with IE. It became widely adopted because it's actually the superior engine.
I hope you're not trying to drawl parallels with what happened with Microsoft by calling it a "Chromium monopoly." I'd argue it'd be disingenuous to do so.
If the only thing keeping Apple's spin of Webkit alive is its own anti-consumer practices of keeping it as the only option within its own walled garden, that's hardly a statement of confidence for the engine itself. Perhaps it should die.
I like Safari because it uses less power and my battery lasts far longer than when using Chrome. Google’s software in general eats up a lot of battery.
The former statement is true. The latter is incredibly false given that Google drives the engineering direction in pretty much every sense.
Citation needed?
Add to this the fact that they only really started this campaign more than a decade after they launched the iPhone just compounds Apple's loss of credibility on this.
Something like a Chromebook would have absolutely failed decades ago. A lot of things done today would have failed decades ago and vice versa.
Just because you have the ecosystem lock-in to force something new down the throats of users doesn't justify doing it.
We can write 100 things for Linux but it means Jack nothing to a consumer who will never do that to the Chromebooks. I.e School IT’s for student use.
Sideloading apps on MacOS, Android and ChromeOS all require taking a few additional steps. It's unlikely that most average consumer will ever take these steps, but it is easily doable for those consumers if you follow online instructions (and so some do.)
iOS really is unique in the level of difficulty involved in sideloading apps.
Video game consoles existed decades ago, were locked down systems, and succeeded tremendously… starting all the way back in the 1970s with Atari 2600.
> because that’s how computers have always been
Phones before the iPhone allowed any app to be installed. J2ME. There was no precedent to do what Apple did with a lockdown like that, as far as I remember. Glad to be corrected but don’t forget to include the J2ME landscape in your analysis.
It’s not unreasonable to argue that a smartphone requires more security than a laptop.
It's difficult to rationalize Apple's stance on this as anything but anti-competitive. They invented a new term they can use in their scare tactics that would obscure their goal of being the only company to profit from software sales on their platform.
Apple loves to market the iPad as the "modern computer", yet the ecosystem is so controlled and locked down that it can barely function as anything other than a media consumption device.
Good on the EU for pushing back on this.
[1]: https://www.lunduke.com/2021/06/apple-sideloading-is-the-dev...
The iPad is an incredible device for creating digital art (Procreate + Apple Pencil) and electronic music (Korg Gadget and literally hundreds of great synth, DAW, and effect apps.)
So, yes, you can do some creative work in this limited environment. But it's nowhere near the flexibility a real computer would offer. And that's a shame given how powerful the actual hardware is.
Where the real threat, in my opinion, lies is with third party app stores. It's easy to imagine Facebook for example launching its own app store where rules for information gathering are lax or nonexistent and then forcing its success by making the powerhouse apps it controls exclusive to it - a lot of people wouldn't think twice about installing a questionable app store if that were the only way they could get Instagram, WhatsApp, Facebook Messenger, etc. There's also no shortage of unscrupulous developers who would jump aboard their platform for the anything goes policies.
One could argue that users have a choice in that situation, but that's not really true, particularly where network effects are concerned. Most people are not going to switch to Signal for example if WhatsApp becomes a Facebook Store exclusive - they're just going to install the Facebook Store and get on with life, because the energy involved in getting entire social groups moved over just isn't there.
Technical solutions to this privacy problem like sandboxing sound good on paper, but there will always be holes, and if the gatekeeper is happy to look the other way when developers use said holes (as Facebook themselves have in the past), those protections may as well not exist. Even if Apple puts maximum effort into closing off these holes, it'll be an endless cat and mouse game with user information dripping out the whole way.
Some will point out that third party app stores and sideloading have been possible on Android since forever and the above described outcome hasn't occurred, but the incentives are quite different in the case of iOS/App Store, both financially (iOS user eyeballs are worth a lot more) and from a policy standpoint (the App Store, historically, has been much more strict than the Play Store). It could also still happen in the case of Android, and is perhaps even likely given how Google has been tightening the bolts on the Play Store's policies.
So, my thought is that any legislation that forces the ability to sideload and install third party app stores must be accompanied by parallel legislation that effectively takes the App Store's privacy policies and codifies them as law, and potentially even criminalizes abuse of platforms to gain personal information without the user's explicit consent.
As it stands, if any app wants access to your contacts, your camera, your microphone, your photos, etc, it must ask first. Allowing sideloading removes this protection, and apps installed that way could simply siphon all your data silently.
You even describe how that can be the case, but you couch it as being with third-party app stores. While what you say is not false, it is also not limited to that case: the removal of both privacy and security protections happens as soon as you stop having the App Store be the sole source for iOS software.
Yes, of course, a hypothetical "Facebook App Store" with all Facebook apps being exclusive to it would have a higher chance of getting nefarious data-siphoning apps onto users' iPhones than any old random sideloaded app, but it's hardly a necessary part of the threat to privacy. It's just a way of guaranteeing much more widespread compromises of privacy.
Some good examples are:
* Exorbitant subscription pricing (3-day free trial, then $20 per week)
* Misusing in-app purchase dialogues. There are some apps that dim the screen down to zero brightness when the in-app payment prompt pops up, and tells the user to rest their finger on the home button
* Ensuring data collection practices match the claimed data collection practices in the privacy policy / "nutrition label"
I don't know whether Apple is any good at enforcing those. We can only see the ones that slip through the cracks, and there are many. But not enforcing them hurts trust in the App Store and decreases revenue for all legitimate developers. I know two people who refuse to accept any free trials due to being burnt by subscription scams on iOS. And I personally have an app in the App Store with a free trial (no subscription, just a once-off lifetime purchase!) and constantly get one-star reviews claiming I run a subscription scam
Lack of enforcement of the above is directly hurting my revenue. So I worry that allowing side-loading opens up the above channels to all sorts of scammy behaviour, and that then reflects poorly on the official App Store (many users won't know the difference, doesn't matter how many dire warnings / official dialogs you pop up)
The same argument could have been used by microsoft a long tjme ago to lock machines to windows and kill linux. It would not have worked then, it should not now.
What apple does is basically avoiding competition. That's not fine when you have 50+% market share
A better comparison is if MS banned installing apps not distributed by MS.
Microsoft used to tax OEMs on all pcs with x86 sold as having windows pre-installed on them (otherwise OEMs wouldn't be allowed to sell windows at all). This got them into anti-trust issues. By the same mechanism they could have asked OEMs to lock machines to windows.
Anti-trust lawsuit could have lead to Microsoft being broken up into separate companies.
It would be funny if Microsoft avoided that only for Apple to be broken down into separate companies. (one for app store, one for iphone, etc)
> A better comparison is if MS banned installing apps not distributed by MS.
If they did this what would be the consequences?, are potential anti-trust lawsuits going to appear again?
Also see what happened with bundling internet explorer in europe.
Microsoft has hardware certification requirements for machines that ship with Windows, and these certification requirements mandate whether or not a machine will be locked to Windows. On traditional x86, these requirements mandate that it must be possible to both disable SecureBoot and enroll the owner's keys; on ARM, Microsoft changed these requirements to forbid both options (https://softwarefreedom.org/blog/2012/jan/12/microsoft-confi...), so that these machines would be locked to operating systems signed by Microsoft.
If manufacturers want to be able to ship machines with Windows, they have no choice but to follow these hardware certification requirements; and it's not hard to argue that Windows is a monopoly, such that manufacturers have no choice but to ship machines with Windows.
> A better comparison is if MS banned installing apps not distributed by MS.
Isn't that what "S mode" does?
By contrast, third party app stores could open an entire one-click universe of privacy abuse. Even if individual apps can't do as much damage, the overall footprint is much larger as the information that's accessible is scattered across a far wider spread of companies/developers by giving them access to users who don't possess the technical aptitude to get themselves in trouble with sideloading.
This is similar to the argument made for censorship - we should also censor newspapers, books, television, movies and the internet to ensure that people get the right information and values, and are not influenced by "harmful" content.
At some point, you have to start treating adults like adults, rather than mollycoddle everyone as some immature and / or innocent being.
With third-party app stores and even apps themselves, it's very easy for users to get more than they bargained for at mass scale. As I noted in my original comment, it's very likely that an app store run by the likes of Facebook would operate in such a way, and the worst part is that many users wouldn't have any choice but to go along with it — they're forced to install the Facebook Store and accept all that it and the apps on it (WhatsApp, Messenger, etc) entail in order to continue to connect with their friends and family. Malicious app stores can effectively hold parts of users' lives hostage to force access to data.
Which is why I'm not against third party app stores, but rather third party app stores without regulation that makes foul play a costly mistake on the part of the developer.
I don't have any iDevices, but are you suggesting that any iOS app has access to all of your files if the code makes it through the app store review? Because that would be a major issue in Apple's sandboxing in my opinion. I don't think you're right about how the OS security policies work, at least I hope so.
There's no reason that the OS can't implement sandboxes and enforce protections for such data. There's literally decades of research on operating system security.
Besides, when we forgo system safety in favor of corporate gatekeeping, that isn't security. In fact, such a scheme is responsible for mass distribution of malware. Apple's App Store is responsible for distributing over half a billion copies of Xcodeghost to iPhone and iPad users[1], and that's just one piece of malware.
[1] https://www.vice.com/en/article/n7bbmz/the-fortnite-trial-is...
For example: I might be okay with granting a messaging app access to my contacts to make it easier for me to send messages to people, but that doesn't mean I'm okay with that app exfiltrating my contacts to build a shadow graph of my social network to sell to advertisers.
Putting a permissions dialog in front of my contacts only solves the problem of whether an app is allowed to access my contacts in the first place, there are zero restrictions on what can be done with that data once access is granted.
> Putting a permissions dialog in front of my contacts only solves the problem of whether an app is allowed to access my contacts in the first place, there are zero restrictions on what can be done with that data once access is granted.
There's no reason that sandboxes have to be so lenient that this is possible. Permissions can be fine grained, and network connections can be filtered, restricted and denied. Contact access doesn't have to be black or white, either. On systems that work for the user, you can even feed dummy data to apps if you want to.
The most recent privacy win is their much-lauded "App Tracking Transparency" policy. This policy does have a technical component (it blocks the app from reading the IDFA) but it would be trivial for developers to find other ways to match up users if they wanted. Ultimately the policy is enforced by threat of penalty by Apple.
This could be (theoretically) replaced with a threat of penalty by Government, but entities like Facebook wouldn't treat this nearly as seriously as they do the threat of being kicked out of the only means of app distribution on iOS.
I am personally conscious and wary of the fact that Apple has extensive control over a platform which is increasingly defining the way many people interact with the Internet. But for now I'm fine with it—and I will be so long as there is strong competition from a more open platform.
It's not as if laws and regulations don't already exist for other industries, and governments haven't enforced them. I'd trust my democratically elected government over a corporate that only cares about its self-interest than mine. (And no, I do not believe that Apple's self-interest are aligned with their consumers, and will never be under the current form of capitalism we have, however much they like to sell that idea).
You don't need to believe that Apple's self-interest is aligned with their customers; that's an entirely valid view which you can exercise in the free market. Eliding the inferred red herring of perfect alignment, there are many people who would consider Apple's corporate interests to be more in line with their own when compared with their government's, or with Apple's closest competitors.
One of my favourite quotes is by P. J. O'Rourke who said: "There is a simple rule here, a rule of legislation, a rule of business, a rule of life: beyond a certain point, complexity is fraud. You can apply that rule to left-wing social programs, but you can also apply that rule to credit derivatives, hedge funds, all the rest of it."
Beyond a certain point, complexity is fraud.
Nothing captures the dirty truth of modern life more succinctly than that, in my opinion.
I think that Government has too much complexity to assertively claim that it is more aligned with my interests than, say, Apple is. For all of its (many) faults, one redeeming quality of Apple is that their corporate interest is brutally simple—almost nostalgically simple. They make a useful product, they convince me that it's worth a certain price, they sell it to me for that price.
You make a very good point.
And that point is exactly why apple shouldn't be allowed to editorialize their app store byond security and privacy controls. Blocking apps that compete with their pre-installed apps, blocking apps that don't allow apple to make money off of them, blocking apps that apple disagrees with morally (adult/porn apps, forcing discord to block joining adult servers on ios) etc.
Apple really fucked themselves here and they will lose this battle for side loading because they weren't good custodians of the app store platform, and it's a battle they didn't have to lose.
And by that, i mean i have, by getting only android ever since the "droid does" of the moto droid days.
It's great that consumers have this choice available to them.
What I personally think is a good way forward is to allow side-loading individual apps, but disallow them from managing other applications natively — that way apple’s precious walled garden will remain, while tech enthusiasts can use their devices to the fullest.
This will result in different phones for different markets. For example, iPhone in Japan must play a sound when the camera takes a picture. This is not true of iPhones sold in the US. iPhones in some markets also are not allowed to have active 5G modems while, obviously, iPhones in the US are.
I think splitting the market will be fine. However, I suspect many side-loading-capable iPhones are going to have many more security problems and privacy breaches.
We’ll have to wait and see.
Security and flexibility are always at odd with each other. But for side loading, I'm not really worried.
Users that are susceptible to security problems don't have the technical know-how to even do something as simple as sideloading. Those who are technical enough usually are not the entry point for malware.
Thanks to friendly YouTube and web tutorials, non- technical users are great at hacking themselves:
If sideloading is made too difficult for average users, it would totally negate the anti-trust (competitive) benefits of forcing the platform open in the first place.
Either governments make sideloading easy and approachable to the masses, and accept the UX/security/privacy risks involved, or they make it cumbersome, and accept the continuation of the App Store monopoly.
Confusing phrasing, but would I agree that security and privacy could in fact be reduced by using another app store or sideloading.
Consider an app that is removed from Apple's app store for violating Apple's privacy and/or security requirements (for example refusing to report, or inaccurately reporting, collection of personal information). There is no guarantee that the app would also be removed from third-party app stores, or that it could not be sideloaded.
Horseshit. Consumers will install anything from anywhere, all the time.
Having the ability to side load gives the ability to people to coerce you into installing things that wouldn’t fly under a single root model.
I do not feel that computing is headed to a good place in terms of privacy and I feel like giving the Googles, Facebooks, and spyware companies more levers to pull is going in the wrong direction. (Well, maybe the right direction under normal circumstances if the tech industry was more ethical)
Tell your employer to give you a work phone then. No way I'm going to install work-related sw on a private device.
On Android (and Windows/macOS, to a certain extent), the OS asks you if you let <app> access/use <feature> independently of how the app was installed.
Also, can apps monitor your communications on iOS? On Android you can replace the apps that control calls, sms, etc, but that wasn't possible on iOS last time I used it.
I know there are downsides if they allow sideloading, but iOS is very restrictive and Apple would still control iOS. They can add more restrictions and fix flaws if needed.
System permissions aren't tied to the App Store as far as I know (same on Android). You still need to give apps permission to access your camera, mic, location, etc.
While allowing sideloading would bypass Apple's review process (which can be bad), if someone has that type of access to your phone, there's nothing stopping them from installing tracking/spyware apps from the App Store right now.
What sort of backward country do you live in where that's even remotely legal?
Employers can already sideload through MDM. If anything MDM will give them more control than just an app.
Employers have enterprise certificates and ability to install custom apps on both iOS and Android, and they can do so while bypassing their respective app stores.
Earth's population shouldn't be forced to do something for your sake. If you have a problem like what you mention with your job, solving it for yourself is much better than wanting to force something on everyone. It's very egotistical to even think that another person shouldn't be able to sideload apps because you have a shitty boss or job.
It's pretty simple. Just don't sideload apps.
Or perhaps there could be a setting that you turn on, that disallows sideloading.
If you turn on a setting, that disallows sideloading, then in that case you would have a platform that does what you want.
If sideloading is available, there will be a nonzero number of developers who choose to provide their app only through sideloading, and eschew Apple's App Store.
Some of these will be doing so merely so they don't have to take the extra effort (or pay the extra money) to submit apps to Apple. No malicious intent, but they still won't be reviewed, so unintentional danger can still get through.
Others will be deliberately avoiding Apple's App Review so they can steal your passwords and spy on your banking apps, or hell, just install a rootkit if there's one available at the time.
And still others will be trying to create commercial-grade apps that provide full functionality, but can violate your privacy without asking permission because that's their business model (particularly Facebook and Google).
And some of these will replace apps that are currently available from the App Store, with all the protections that entails. Particularly Facebook and Google.
Sideloading and app permissions are orthogonal.
If we’re going to bring consumer choice into this argument, why can’t the consumer who wants sideloading just vote with their wallet? I’ve yet to read a good argument here for this separation. After all, “nobody is forcing you to buy iPhones except your own weakness and childness.”
You mention how Android isn’t better in that regard, but it’s still an option.
In other words: pay for your tools. Configurable tools for pros cost more.
Some people recognize their weaknesses and pick tools accordingly. You want to take this choice away. Please fuck off.
But one point that is very clear. You belong to a group of users that enjoy the leverage Apple has on developers, and you want it to stay that way
Oh ok. So this has nothing to do with your phone and your choices.
Instead, what you want to do is force other people to do certain things with their own hard work.
Not really sure why you think you should have domain over what other developers do with their own apps.
If you don't like those apps, then don't use them. Problem solved.
Every corporate IT department configures windows this way
"I think privacy and security is of paramount importance to everyone," Vestager said. "The important thing here is, of course, that it's not a shield against competition, because I think customers will not give up neither security nor privacy if they use another app store or if they sideload."
Spot on! There is a point of no return for us consumers too when the manufacturers use the argument of "security and privacy" to take so much control away from us. At that certain point, can you really say that you own the device you have paid for?Forced updates, walled gardens, mandatory online accounts, all of it has been pushed down the throat of users with the justification that it is necessary to protect users against themselves.
And in most cases it's pretty easy to see it wasn't primarily in the interest of those users, since they weren't given the opportunity to make an informed decision.
Power users like the majority of HN users are different, but they're not the majority of the market.
Society may find that it is worth mandating sideloading nonetheless and that the competition gain is worse the privacy loss. But it is senseless to argue there is no tradeoff.
For me the most secure medium right now is the web (much more than any appstore) and it's designed to run code on demand.
We have plenty of examples where opening things up caused issues. For example the minimum quality of NES games massively declined after Nintendo opened the floodgates.
The web is currently orders of magnitude safer than the appstore and is designed to run code on demand.
It’s not even a question of adoption, iOS is a huge target and the App Store actually provides meaningful benefits for the general public.
If you are really worried about security, the answer today is still to avoid using native apps, they have more permissions and are harder to investigate than web apps.
But we all know this talk about "security" is just an excuse for corporate control, especially when the web just runs code on demand and is more secure.
The Internet Explorer 11 desktop application will be retired and go out of support on June 15, 2022 (for a list of what’s in scope, see the FAQ). The same IE11 apps and sites you use today can open in Microsoft Edge with Internet Explorer mode. https://docs.microsoft.com/en-us/DeployEdge/edge-ie-mode
Beyond that even Linux users have faced zero days. The web is inherently unsafe which in practice is rarely a issue for the cautious, but that’s only so useful.
> Beyond that even Linux users have faced zero days. The web is inherently unsafe which in practice is rarely a issue for the cautious, but that’s only so useful.
Go ahead and try to find me an exploit working right now to access your local files, they are so rare I can't remember seeing one in a long time. If you are going with zero days, Apple also had an exploit not that long ago where every app could snoop into the data of any other app as well, pretty scary and that also happens to them.
Not talking about security exploits but just security design, the permission system is broken by design on native apps. On the web, you do indeed need a zero day to access user files, on a native app, you just need to go ahead and follow the documentation, pretty big difference.
Apple's marketing department might disagree with me but hey, that's just the marketing and they are free to say what they want.
There's no reason that the OS can't implement sandboxes and protections for user data like that, either.
> There's no recourse against misuse of data you grant permission to use, but in the main App Store Apple can kill a deceptive app
Apple can also distribute malware via the App Store, like it did with 500 million copies of Xcodeghost[1].
Other mobile app distribution methods can be more secure than the App Store, as well. Users can enjoy the increased efficiency and lower costs that free markets and competition in app distribution, security, and payments can bring.
[1] https://www.vice.com/en/article/n7bbmz/the-fortnite-trial-is...
But instead Apple uses privacy and security to flat out deny any wrong doing.
I have often thought the advice Steve gave to Tim Cook, "Dont think What he would do, do what you think is right" was all good intention but turns out to be possibly the worst advice ever.
Steve Jobs was deeply anticompetitive and anti user control since 1980 or older. Wozniak fought him to get the tiniest bits of user freedom into the Apple computer.
I also think people often mistaken some of those design choices as anti user freedom. Where the results of those decision might seems that way, the starting point were different. Things like integrated hardware design.
Steve was an empathic and also a hash person. People often seems to read everything as if he was an asshole and very little about his empathic side of stories.
The security comes from the sandbox, not from the app stores. This is why it's secure to use the web even though the websites are not individually approved by Apple.