Taking Apple at their word here, I still don't get it. Can anyone explain the argument they're trying to make? As written it just sounds so ridiculous (but I'm still trying to understand it).
Taking Apple at their word here, I still don't get it. Can anyone explain the argument they're trying to make? As written it just sounds so ridiculous (but I'm still trying to understand it).
If Facebook removes their app from the App Store (or cripples it), and says you have to side load this app, most Americans will do so. Even if that app violates a number of user-friendly policies. The OS, of course, could enforce that at a technical level, which weakens the argument significantly.
Also lots of people will click links and side load spam apps, but that’s par for the course.
The primary reason for this is that Facebook itself has a dominant market position (network effect) and is deserving of antitrust scrutiny. "We need this evil monopoly to protect us from that evil monopoly" has a better solution in smashing them both.
Notice that this argument doesn't work anywhere else. If your tetris app which is in competition with many others decides it wants to go out of Apple's store so it can spy more, nobody is following you. They'll just install one of the hundred others.
To gain anyone's trust for any app that isn't a monopolist, an alternate store would have to have a similar reputation for rejecting bad apps. But then the scammers wouldn't be able to make it into any of the stores people trust. The advantage is that some of the non-scammers that Apple rejects for illegitimate reasons, would. (Or competitive pressure would cause Apple to get better at not rejecting them in order to prevent it.)
Especially when the reason for the move is obvious. If Facebook leaves the app store, and Facebook is completely free and makes money from advertising, everybody knows why they're doing it and it's to screw you out of your privacy. But you can't say no because Facebook is the only way you have to talk to your grandparents, hence the need for antitrust.
If Epic Games moves Fortnite to another store because the other store charges lower fees but still has a good reputation for not allowing bad apps, likewise the reason they moved is obvious. It's to have lower fees, because Fortnite makes money by selling things in the game. Many users will be fine with that, as well they should be, because that's the point of allowing other stores.
But a game doing it for the same reason as Facebook, well, they're going to lose most of their users. Because nobody needs a game that much, so the company doing it for an adversarial reason will cause large numbers of customers to tell them where to go.
I don't think that's true.
Google publishes malware stats on the on-play and off-play ecosystems and the malware rates differ. Famous examples like malicious versions of FortNite make news headlines. Play policies also enforce various security-relevant action like updating to near-recent targetSdkVersions and fixing a variety of automatically detectable security vulns. No such enforcement exists in the broader off-play ecosystem so it will be easier to install an app with trivial security flaws.
Whether this is a justification for banning sideloading completely? That's another question.
But yes, there have been such cases. Epic successfully forced a massive number of Android users to sideload Fortnite to get around Google's policies, and Google wasn't happy and tried to undermine that attempt.
The OS, in iOS' case at least, does already do this. So the case is weak right now.
The #1 reason for the app store is to take that sweet cut. The #1 reason to sideload is so those apps can bypass the store's cut. Follow the money.
Google puts software downloadable outside of Google Play at a disadvantage, through technical and business measures such as scary, repetitive security pop-ups for downloaded and updated software, restrictive manufacturer and carrier agreements and dealings, Google public relations characterizing third party software sources as malware, and new efforts such as Google Play Protect to outright block software obtained outside the Google Play store.
It can't be sandboxing, as the entitlements and/or existence of sandboxing for an app is enforced by the App Store, and we've just said we're not using that.
It also removes privacy protections: Facebook is required to ask permission to track you on iOS. It's only required to by platform policy in the App Store license agreement. They're not using that any more, so goodbye opt-in tracking.
> App Sandbox is an access control technology provided in macOS, enforced at the kernel level.
https://developer.apple.com/library/archive/documentation/Se...
The App Sandbox enforces the sandbox rules that are a signed component of the app. The App Store ensures that the entitlements that an app has are valid, necessary, and safe.
If you remove the App Store, a binary can have any entitlements or policies it would like, including not to have one. For example the Facebook, TikTok, or Google apps can give themselves the appropriate permissions to access all your data. The kernel will enforce those sandbox rules, and ensure that the app never accesses more than all of your data.
WTF good is a sandbox if this is the level of sandboxing it does? The app store is not great at catching things before they get released to the public, so this seems like a good reason to not trust apple exclusively if they're the only line of defense.
Why can't the calls to internal APIs still require auth'ing? Sandbox running software from accessing data outside of a specific internal API (via socket, etc), and require a handshake process or something before it returns data via that channel. The user can still get an OS-level prompt to approve use of API. You can literally still require a signed key in this step to identify apps. If an app tries to go around that... sandbox keeps it from seeing the rest of the system.
How do you think the kernel knows what an application is allowed to do? Seriously, I want you to think of a way that the kernel of any platform could know what facilities an app should have access to.
A realistic example: today if your iOS app wants to track users, it must go through AppTrackingTransparency.framework, which allows the user to opt-out, and use the device’s advertising identifier which the user may reset.
Of course this cannot be enforced by the kernel; it's enforced by App Store review. Sideloaded apps would presumably not be subject to this rule.
Apple claims that security would be impacted. They implied that sandbox=app store. Its all FUD marketing, of course, but they heavily implied that the app store review was the safety method for customers.
> if your iOS app wants to track users, it must go through AppTrackingTransparency.framework, which allows the user to opt-out, and use the device’s advertising identifier which the user may reset.
No reason you can't make access to the ATT DeviceID a call to OS. It'd return 000000 in generic case, and prompt the user at OS level to approve. If no approval, then it'd return 0 to app. You can't guarantee what they're doing with the number in-app, but apple barely does that now with review so probably not much loss. Sure some apps could try to access restricted memory or file paths that they aren't supposed to... but thats what the sandbox is for. BUT maybe apple should just kill DeviceId for everyone since im sure most people opted out.
The real loss to apple is that first party apps may have to play by their rules, and lose access to privileged APIs, or open them up to sideloaded apps (since the trust boundary is moved from source of app, to OS calls). They don't want to have to play by their own rules.
Even if you do want to do that, what do you ask the user? Even the basic entitlements often require some amount of knowledge a regular user simply doesn't have. Then the law itself has rules prohibiting restrictions, and I would bet someone will claim dialog based security counts as a restriction.
The law even makes it hard (impossible?) for a platform to protect even a modicum of user privacy. Section 2 (b) 3&4 explicitly prohibits a platform owner from placing restrictions on collection and use of user data.
And once again, that's on Apple to implement. If they choose to continue to keep entitlements in the same format, that's on them to explain it to the user. See Android, they handle permissions fine.
That section doesn't place restrictions on the generation of user data, only access to generated data. So don't generate it. In my opinion that's to prevent the platform holder from getting an unfair advantage by keeping the data for themselves. If the user doesn't give permission, the device doesn't generate the data, you're not restricting access to data because it doesn't exist.
As for the second bit, the "generated information" is things like device ids, location, etc. The stuff that is necessary for a phone.
But clearly you're of the view that requiring malware, people having to give CC information to innumerable other companies, is a good thing, so I doubt we're ever going to agree on this.
I would rather not have to worry about software installing a persistent crypto miner in the background, and not having to worry about software invading my privacy, than installing whatever mysterious apps aren't currently permitted on the App Store, but you do you.
Exactly that's your choice. You can choose to continue being on Apple's App Store where they do check for all of these if you want. No one is forcing you to install give that credit card info. Don't take away my choice to choose otherwise. If I want to pay for something with credit card, shouldn't I be allowed to? Or if I wanted to run background processes on my devices?
You want the android experience, but rather than getting an android, you want to force that on the people who prefer the iOS model. They like not having to worry about malware. Currently an iOS user can get all the software that they want from the iOS AppStore, and they don’t have to give random companies their CC#, they don’t have to worry about the app subverting their privacy, because they know apple kills software that does that whenever they find it. This law means they have to deal with multiple different stores, that have no incentive to maintain platform security or user privacy. In fact they’re incentivized to abuse user privacy.
As an iOS user I do not want the android experience. This law basically forces ios to have that. Malware and all.
The only things this does is reduce user security, and give scummy publishers the ability to bypass AppStore rules the protect users (like “you must make discounting if subscriptions trivial”, “you don’t get to run a cruptominer in the background”, etc).
Again, if you want to have the android experience, use android. Literally no one is stopping you.
Or epic: another company that has a novel approach to use privacy
Or Facebook
Etc, etc
The only option goes “the AppStore with its various restrictions and protections” or “miscellaneous parties with a vested interest in destroying your privacy and/or complete lack of any review”
They can have either the same level of control, less, but never more. As it stands right now, Apple and pretty much all Android manufacturers have more control (Yes, I said Android too. Good luck trying to mod the bootloader itself or gaining access to the TEE)
This would be a great thing because that way you don't force any company to modify their app plattform or change their normal user-facing software in any way, yet those who wish so can do with the device whatever they want in the same fashion the manufacturer could before (and even after) the sale.
> an iOS user can get all the software that they want from the iOS AppStore,
> apple kills software
Which is exactly the problem. That Apple has monopoly power over iOS apps.
> This law means they have to deal with multiple different stores
And in the same way I can choose Android, you can choose to use to continue to use Apple App Store only. Do you think Apple should be the only smartphone manufacturers because you don't want to deal with multiple OSes? No, because you're not being forced to use all of them.
And if they opened up to additional stores or side loading, you would have a choice to stick with only using the Apple one. That choice doesn’t go away. In fact, the vast majority of Android users aren’t installing side stores because the Play Store has what they want. This is why companies like Spotify still distribute there despite fighting Google on fees.
I think they are require to ask permission to track you using iOS API. They still track you based on what you access on Facebook.
The App Store policies ostensibly also prohibit an app from tracking a user via any other means once that user has said no to tracking.
This is simply not true. An app can lie about what it does, and nothing at a technical level can prevent that.
You can measure just how big of a monopoly the iPhone App Store is by how many billions of dollars shift with simple changes to Apple policy.
As much as I hate ads and tracking, it's not Apple's right to be the sole defender of the American people. That's what laws are for. (And besides, Apple is already a direct beneficiary of all that tracking themselves. They're absolutely doing business and making decisions based on your behavior.)
Too much economic activity (50+% of American computing) is happening on iPhone for Apple to be afforded the monopolistic privilege of taxing it all. Apple makes so much money from sales of their remarkable hardware, subscription services, and other incredible and highly profitable business units that they won't be at risk by giving this up.
For the health of the broader industry and the enduring benefits of fair competition, Apple must relinquish the App Store monopoly.
Apple will be more than okay. And they'll shift efforts that used to be spent on protectionism into true innovation.
They're not. They are (and want to continue to be) the sole defender of Apple iDevice customers. The American people (and in fact anyone else), can choose a non-Apple device, and therefore non-Apple ecosystem.
To me it all boils down to - is the app ecosystem a public commons or a private commons subject to the owner's T&C's? (for clarity - the owner is not the customer. The customer owns the device, but they do not own the ecosystem).
In either case someone would have to make one first.
To be honest, I have been recently looking at trying out an Android phone that supports Lineage, but the 2FA issue would be a deal breaker. Is it just some 2FA, or most/all?
This is a silly statement that has nothing to do with reality.
Apple has the right not to be forced to work for Meta.
If people want Meta so much, they can choose an android device, or Meta can license Android themselves.
I was thinking of the tracking restrictions when I wrote this. The OS simply doesn’t give the app the data.
In any case the idea that you can achieve privacy and security solely through managing APIs is simply false.
I and other people I know have to use phone apps for work, mainly for authentication, meetings and integration with the work calendars, and then have to use more apps to access bank accounts (both business and personal), credit cards, and to authorize some payments in real-time. Some of those things don't exist in any form other than as a phone app. Even the desktop browser versions require the phone app for authentication. It is assumed you have one.
No, there is not a sufficiently free market from which to choose alternatives. For example, you may have to "choose" a job, phone-based bank, and credit cards, based on what is available in difficult times, not based on choosing what you'd prefer.
If those essential apps switch to sideload-only because they can, those people have to comply. Not because it's a free choice. The phone is not only a social device, and the constraints are no longer things like Facebook, they are things more like essential utilities which nowadays require a phone. Even an unlocked Android won't do.
In some countries phone apps are now required for access to government services.
Maybe side-loading is the future, and it has some benefits.
But it would be wrong to say there is no security and privacy issue if apps remain essential for access to services, stop being subject to app store curation, and can then require permissions to do whatever they like on the phone in future, such as turning on the microphone and location services, and reading photos, files and messages. Some of them already require too many permissions, and of course we already accept, uncomfortably, if we really need those services. The app store curation keeps this in check to some extent; it is not a technical problem.
But no one have suggested how they solve the current issue with App Store, Apple's power of Digital ( App ) distribution. Where it has 50%+ of Smartphone Market in US. When Apple's App Store practice and policy have been found to be Anti- competitive, Unfair ( while at the same time crying foul of 4G/5G agreement ) and inconsistent for years. Rent-Seeking in App Store fees. A Flat 30% on all categories. Did you ever see that in retail? ( The answer is no, considering 99% of HN dont know much about Retail )
Apple wield so much power, that politicians around the world are un-happy. But as far as we are aware, no body at Apple think it is a problem. They are still thinking about it as a money problem.
Could one sideloaded app somehow impersonate another sideloaded app, and thereby trick the PKA/SKP into signing a message with a private key that it shouldn't have access to?
If there is no way to securely distinguish between two sideloaded apps, such that one app could impersonate another in getting access to OS- or hardware-level cryptographic services, then that could be a real problem, I think.
I don't yet know enough about how these crypto services are implemented to know whether this would actually be a problem in practice, however.
QED.
If Facebook says "we're going to put Facebook on a different store", now the majority of americans use Facebook, so now install the second App Store. This App Store fails to maintain the security rules of the real App Store, and now users devices a compromised.
A core part of the security model of iOS is the App Store. The App Store makes sure that all applications have a sandbox, and that the sandbox entitlements are safe.
The reason one app can't build a list of your other apps is because the sandbox prevents it. The reason it can't read your address book is because it lacks the entitlements to do so without your permission.
As far as privacy: The reason Facebook, or any app, is required to ask for your permission before violating your privacy is because of App Store policy.
This legislation explicitly makes restrictions on collecting user data unlawful.
Having just reinstalled everything because he had a ransomware attack on his computer, I can understand the argument…
They want the control over distribution via AppStore
There are at least three aspects to this: active attacks, negotiating power between various actors, and platform maintenance.
1. To the first, certain classes of attacks and malware are dramatically harder to execute on locked down platforms like iOS devices than on open systems. Remember, on the PC or Mac enormous amounts of real world risk isn't the result of 0-days but social engineering, pressure, user error or laziness, etc. On iOS, it's simply impossible to just give somebody root access. The user doesn't have it. It's even harder to have a persistent root kit, let alone go down below the kernel. When there are exploits, the owner community as a whole tends to see and have deployed upgrades faster. There are more barriers to the kinds of low effort mass adware and the like that plagued many non-technical (this does not mean stupid or undeserving) people before, like the classic of opening your relative's browser and discovering a hundred competing searchbar and ad injecting add-ons and such. And on and on.
Of course, there are security issues that can arise from this too. And if a player is more powerful than Apple is (like a major government) then the whole thing can go very bad, because now there isn't any way to bypass that either. On balance I think the long term risks are higher with no owner controlled root cert like the current situation, but we shouldn't be blind to the fact that Apple worked to solve a huge problem with computing that the tech community were really assholes about (me included to some extent in the 90s, I remember the BOFH type admin and jokes that went around hell desk quite well). There is some baby amongst the bath water.
2. To the second and per above, that Apple has a secured position as powerful player on the iOS platform shouldn't obscure that there are other very powerful players vs the normal user. Many people find certain things like Facebook effectively indispensable. And individually they lack the weight to negotiate. Facebook and the like do not give a single shit about you individually. If you tell them "you better stop XYZ tracking or no more service from me!" that likely won't even get a reply. But Apple's control means it acts as the focal point of hundreds of millions of very valuable users combined. Apple can say "thou shalt disclose privacy practices and formulate and obey a policy" or "thou shalt not have persistent device traction" and attach an OR ELSE to it and actually have it stick. But if a player of Facebook's scale could then just say to everyone "you must go and sideload Facebook Store and grant it full permissions to keep using our product" that power might well completely dissolve. In principle government could be dealing with some of this, but government is often pretty slow, heavy handed, and faces its own problems with corruption, lobbying etc.
3. To the third, while Apple is obviously making plenty of profit and some of their resources are obviously going into irritating bikeshedding UI-cycle stuff, that shouldn't disguise that upkeep of a modern networked platform isn't free. There really is a major cost to keeping up security, to developing and maintaining system frameworks, infrastructure etc, and then keeping up with that for years after a product has been sold. How that is paid for also has implications for effectiveness. It's not necessarily feasible to build all of it into hardware pricing. If users are asked to pay (remember, paid OS upgrades were once the rule in the proprietary world), lots of them won't, which means the platform becomes more fragmented and more people miss out on critical security updates sooner or later. Having it be part of developer prices might be a least-bad way to do it. There is some link between those who benefit most and those who pay most, and it doesn't create the same negative incentives for users.
People mock the "Apple Tax" but honestly paying taxes for infrastructure isn't always a bad idea. If anything I wonder if Apple shouldn't actively lean into that and announce they're going to make it more progressive, with 0% fee for the smallest fish rising to the highest amount for the biggest ones. But it too depends on some level of enforcement, same as taxes IRL.
----
Again, none of this is to say there aren't major, obvious downsides to the level of control Apple has too. Their accountability is limited, and their incentives certainly aren't all aligned with their customers. Their control has been used for anti-competitive ends and moving into other services that should be more competitive (backups being a simple example) with negative effects (not just money, but lack of E2EE encryption). I do think there is room for legislative improvements. But it's not entirely simple.