How malware gets into the App Store and why Apple can't stop that
habr.com
habr.com
This is systemic problem derived not only from bad management and absence of responsibility.
This is "business as usual" with any big corporation. There is no problem until perception of the problem affects sales directly.
And in the case with Apple, reality is professionally managed toward "reality distortion field" of uneducated masses who are addicted to "latest tech" and "social validation psychology".
I don't know any other corporation which can comfortably keep silence on issues like NSO/Pegasus or just "postpone" intrusion on user privacy as CSAM.
People love their shiny toys. This is exactly the dynamic with tobacco companies in the past. People believed in one point in time that cigarettes are "healthy things, recommended by physicians". https://edition.cnn.com/2017/05/24/health/gallery/tobacco-he...
It is always psychology first, technology second. Or sales and shareholders first, services and tech appliances second.
You can thank "geniuses" like Edward Bernays and his contemporaries for this.
https://www.inquirer.com/business/law/london-grenfell-highri...
https://www.reuters.com/article/us-britain-fire-lawsuit/u-s-...
Rather: if Apple enforces a monopoly on selling fire extinguishers, these should better be really reliable.
Terrible analogy, are you really company operating in 'free market' setting T&C to a sovereign nation passing laws?
Firstly the causality is the same even if the ultimate power and available sanctions are different. The nations can “just ban hacking” the way they can “just ban arson”, and then go “oh no it’s still happening” while locking up hackers and arsonists; or they can say “fire safety on all domestic products” and then it’s harder to set fires, which isn’t much different in causality than a big box store making exactly the same requirement for all the products they sell.
Secondly, sovereign nations have been mostly fairly relaxed about the businesses creating and enforcing Ts&Cs, and can always overrule those Ts&Cs as and when they change their minds.
There are limitations. The signature on the binary is only valid for 7 days I believe, so naively you'd have to rebuild/reload every week, however there are certainly automations that do this for third party apps with a little daemon running on your Mac in the background, and I suspect there are equivalent automations for your own apps/open source codebases to reduce the hassle.
That’s a pretty silly thing to say [1] and a non-argument. Whether or not you’ve personally heard about security problems with android doesn’t mean they don’t exist or aren’t widely known to others.
[1] https://www.cvedetails.com/vulnerability-list.php?vendor_id=...
It should also be noted that the #1 vector for malware installation on Android is the Play Store itself[3].
The issue isn't Apple or Google's mobile app distribution implementations themselves. The issue is that the app store model was only adopted because of its profitability, and security was an afterthought. Despite this, the companies' PR departments try to paint the app store model as necessary for "security" and then fall short of actually securing things because that might cost money or decrease revenue. There's no competition, so who is going to stop them or force them to improve?
[1] https://www.theregister.com/2020/05/14/zerodium_ios_flaws/
[2] http://zerodium.com/program.html
[3] https://www.zdnet.com/article/play-store-identified-as-main-...
On the other hand if your iPhone is vulnerable it will get an update. Can you say the same thing about Android?
[0] https://www.appbrain.com/stats/top-manufacturers
[1] https://www.statista.com/statistics/271496/global-market-sha...
[2] https://arstechnica.com/gadgets/2021/02/samsung-now-updates-...
That’s a big deal because their manufacturing last years model S20 and many people are buying not realizing it’s apparently got 1.5 years of full support remaining.
Samsung's support pledge isn't perfect but it is an improvement that will hopefully lead to other Android OEMs stepping up their game.
Thanks for all the work.
Does Linux/BSD sandboxing system offer such protection?
Do Duo, Otka, or Microsoft Authenticator have the special notification entitlement? These notifications never seem to be delayed no matter what internet climate i'm in unless i'm literally in the middle of nowhere.
Did I do that one right?