On iPhone sideloading: it’s ok, I’m changing my mind
numericcitizen.me
numericcitizen.me
I don't have an answer for this. I'm all for people being able to get around the garden walls. I just hope and pray that no one in my "you use computers so you're my de facto tech support" circles does it.
I. I do want to be able restrict what they can install on their phones and it gives me a small peace of mind that nothing they install would outright steal their bank app’s credentials or all their passwords.
I think you're missing something important, which is that the App Store is part and parcel of Apple's (mostly successful) layered security model.
Why do we pretend that social engineering scams don't exist outside of installing anti-viruses? There are thousands of vectors of attack, many of which can and have been done on iPhones (bank accounts, gift card scams etc.)
The solution to this problem is EDUCATION, not letting companies monopolize a market just because we're too scared and stupid as a society to teach the elderly and vulnerable about security and privacy.
Nobody is pretending that.
> The solution to this problem is EDUCATION…
Nope. Educated, tech-savvy people fall prey to scams all the time: https://www.cnbc.com/2021/08/10/tech-savvy-teens-falling-pre...
I was reviewing a computer class curriculum for a younger cousin who is in high school. All they're doing is learning how to format documents and use spreadsheets. Being able to use an office app suite does not equal being tech-savvy or being educated about computer security.
[1] https://www.theverge.com/22684730/students-file-folder-direc...
https://www.techtarget.com/searchsecurity/news/252495750/How...
My kids (who go to a public school) have received what I consider thorough instruction on avoiding online scams and other kinds of danger. It sounds like YMMV, unfortunately.
But the main takeaway is that education doesn't make people scam-proof. The link at https://www.bbbmarketplacetrust.org/story/39089233/research isn't working as I type this, but Cracking the Invulnerability Illusion: Stereotypes, Optimism Bias, and the Way Forward for Marketplace Scam Education is a really interesting research paper on this. (I've pinged the author and will post a working link when she responds.)
That's was an example, but only an except. I think equally plausible is "my bank called and told me my app was broken and that I needed to redownload it. I tried logging into the new app with my bank username and password, but it didn't work. What's wrong with my phone?" Now, Apple doesn't have a perfect track record for catching and blocking these things. Their security controls are definitely better than not having them, though.
> The solution to this problem is EDUCATION
No, no, no. One of the things drilled into your head at security engineering and management conferences is not to ever trust the human factor. Education is a good thing to have in addition to all your other controls, but is a terrible first line of defense. People make terrible choices all the time. Maybe they're sick, or they've had a drink or three, or they're worried about something that happened at work, etc. etc. etc. Even smart people who've completed security training still make dumb mistakes.
This problem isn't solved by the centralized App Store--even if it were good at blocking any app with functionality that would let it be used as a scam (which it is not)--as it is just as if not even easier to tell the person "your app is broken and you will need to use our website" and then give them the wrong URL.
Like, I don't understand what you are trying to accomplish here: you think your elderly parents are going to go through a number of steps to install software via a different process but won't go to a website? I bet going to a website would even be a prerequisite to sideloading, so why would the attacker bother adding even more steps?
You are thereby helping Apple do something bad for both society and large numbers of other people and you didn't even manage to get the one thing you wanted out of it :(.
> my "you use computers so you're my de facto tech support" circles
and you hate it. Stop doing that.
How many apps per week does your grandma need to install? It would be better if you set her up a phone with the apps she wants, and then disabled all app installation.
Because if someone is in that position, the unfortunate reality is that the official app store isn't safe either. The article gets into this in more detail, but there's enough malware on the official Apple Store to make it dangerous to randomly install apps. There are apps where their whole design is to set you up with big subscriptions in the background that you don't notice, there are malware apps that slip through Apple's review process, there are phishing apps.
Really, you should install the apps your grandma needs, and if she needs more later, then she can ask you about them (or someone else who's an expert). I think people look at the Apple Store as if it's perfectly safe and that opening it up would suddenly let in malware for the first time. But while the Apple Store might have comparatively less malware than Android, that's not the same thing as being perfectly safe, and it doesn't mean you can let a young kid or a naive adult go wild on it and install whatever they want. That's a recipe for disaster.
I've set people up on Linux and had zero support calls or malware problems with them, not because Linux has good security or perfectly curated software sources, and not because there aren't dangerous ways to get malware on a command line, but because they don't open the command line in the first place. Some people are safer and thrive in a computing environment that's set up to do the things they want and that doesn't change after that point -- but I don't think that has much of anything to do with alternative app stores, that's really a question of whether app stores should be allowed at all for those people.
No one says iOS can't implement similar parental controls for sideloading; they already have parental controls to prevent installing any new apps. Or add a similar phishing prevention systems like Google and Firefox has.
I do favors for my friends and family, and vice versa: they help me, and I help them. That doesn't mean I can't dread them going to great lengths to make it harder for me to do so.
[1] https://www.theverge.com/2021/2/8/22272849/apple-app-store-s...
Bad solution: disallow this entirely.
iOS developers are sideloading their apps hundreds of times each day...
(Accounts that were inactive from publishing apps/games to the store. The accounts may have well been “active” for side loading/dev work)
Why isn't it free, or a nominal one-time $20 fee like the Microsoft Xbox developer program? Very good question.
Exactly. Want to sideload MAME? It's not a big deal. Go to https://github.com/yoshisuga/MAME4iOS and follow the "Building / Installation / Sideloading" instructions.
(And what if you don’t own a Mac? Create an entire macOS VM just for the purpose of installing an app on your phone?)
Compiling source on anything other than MacOS (at least was - not looked into it in a while) a PITA.
And to take the argument more broadly: how many of us here on HN became interested in computing because they screwed around on their PC as a child? What about today's children, who get a smartphone, a tablet and maybe a Chromebook? What are we teaching them?
I am for hassle-free side loading on every platform (Even on games consoles). I also dislike how most smartphones and tablets have become "Internet consumption devices".
I'd still put that as a bad solution. It is necessary but not sufficient for the owner of a device to be be able to run arbitrary code. It also must be the case that nobody can prevent the owner from running arbitrary code on their own device. The infrastructure required for Apple to be the intermediate for enabling such a feature would mean that Apple could also block the authorization from going through.
In effect, Apple must not be in a position to perform a man in the middle attack between an owner and the owner's device.
The real thing keeping people safe is the operating system itself. The App Store is just a revocation mechanism for when something defeats those platform protections. That is what Developer ID is about on macOS: a revocation mechanism, only activated when platform security is breached.
People think that sideloading means Apple can’t scan for malware… Apple signs every single notarized binary
That is also to say that if Apple does open up the platform to alternate stores, I imagine they will still control the security portion.
Ultimately, though, someone needs to maintain a database of malware. When this malware is attacking the platform, it kinda makes sense for the platform maintainer to maintain the database. Microsoft maintains the Defender database, which does have false positives, and we thank them for it. If you want to override it, you can. Notarization works the same way on macOS.
That said, the neutrality of the database (malware only!), and the ability to override it are both key components.
You have to go through the settings and find your build number, then tap it 7 times. Super easy for someone knowledgeable to intentionally do, but basically impossible for someone to do accidentally / get tricked into.
Android manufacturers for some unknown reason always reorder/rename their setting menu randomly. And I seldom see any phone that have exact the same setting menu from different oem.
I'm scared that some of these people won't let their relatives answer the front door unless they are present, lest a man with a clipboard empty their savings account.
Today, iOS has a strong sandbox where apps can’t access data of other apps unless explicit permission is granted (eg. access your location/contacts/photos), and apps can’t access or modify system files at all.
Also consider that sideloaded apps does not mean allowing unvetted apps - Apple could still mandate macOS-style app notarization to prevent malware:
> Notarization is a malware scanning service provided by Apple. Developers who want to distribute apps for macOS outside the App Store submit their apps for scanning as part of the distribution process. Apple scans this software for known malware and, if none is found, issues a Notarization ticket. Typically, developers staple this ticket to their app so Gatekeeper can verify and launch the app, even offline.
> Apple can also issue a revocation ticket for apps known to be malicious—even if they’ve been previously notarized. macOS regularly checks for new revocation tickets so that Gatekeeper has the latest information and can block launch of such files. This process can very quickly block malicious apps because updates happen in the background much more frequently than even the background updates that push new XProtect signatures. In addition, this protection can be applied to both apps that have been previously and those that haven’t.
https://support.apple.com/guide/security/protecting-against-...
AKA, a "computer."
My computer.
That absolutely destroys interoperability, and is not a good thing. If the program that generated a file must give permission for it to be accessed, then a proprietary program can prevent interoperability simply by not actively enabling it.
Passing information between programs must be in the control of the user, not a program.
Actually android do exact the same thing these days. So you sometimes see 'XXX app want to access your photos', or a file explore to select which directory you grant for app to access.
There used to be a loop hole that any app can read sd card. But it is also sealed since android 10. Now every app see different rootfs.
> then a proprietary program can prevent interoperability simply by not actively enabling it
These doesn't really matter, a proprietary program can always break interoperability as long as they want. Did you see the old ms word .doc format? Even other version of ms word can't read it correctly, let alone any third party programs.
On iOS this can’t happen, regardless of whether an app was downloaded from the App Store or elsewhere.
It isn't 2002 anymore, systems have been hardened since the Windows XP days.
Would you feel the same way about handing your older relatives a Mac in 2022? They'd be able to install stuff from wherever on Mac.
I have tons of older relatives using Macs and Windows computers, and the days of Bonzi Buddy and 20 addon toolbars for IE are over. Some of them even have Android phones where sideloading has been a thing for over a decade, and the sideloading apocalypse bringing hordes of malware has yet to occur.
Truthfully, I believe your worry doesn't apply in our current computing era.
I absolutely feel this way about my grandparents and their Mac Mini. They've fallen victim to a few scams involving software installation that would have been much harder to pull off on iOS.
That's not a given, given the multimillion dollar scams on the iOS App Store[1].
[1] https://www.theverge.com/2021/2/8/22272849/apple-app-store-s...
Are you really saying that ransomware is not a problem? There is nothing stopping anyone from downloading anything on Macs and Windows.
The Mac preference pane included in the article implements this. My parents aren't going to change that setting unless I tell them to which I won't.
And don't be ageist: my pre teen kid wouldn't either, having already rendered his computer unusable a couple of times in other ways. Once he became a bit older things were different, but by then it didn't matter to me and wasn't really any of my business.
It should be added to iOS and tvOS.
It should have never been a valid reason against restricting everyone’s freedoms.
If you don't know what is sideloading. Without toggle the hidden browser setting, open a apk in browser will just say `the app can't be installed correctly`.
If you know, you just know you need to open the info of browser, and toggle the __Allow this app to sideload other apps__ option.
??? macOS does have a real Unix shell. It’s called zsh. And it’s not that hard to get whatever compilers you want.
Shells are not the entire UNIX environment, they’re just one part of it. (And I don’t think you meant it this way, but please don’t say it’s not a “Unix shell” because it doesn’t have GNU extensions.)
This is key: because individual centralized actors are imperfect and even corruptible--whether due to intrinsic motivations or extrinsic application of force--it isn't acceptable to concentrate so much power onto them; in a talk I gave at Mozilla Privacy Lab a few years back, I covered a lot of these failure cases throughout our industry with real-world "this actually happened" examples, including (as this would of course be one of my focuses) looking at numerous ways in which Apple's App Store moderation has been the problem instead of the solution.
Even if Safari turns the ship around & decides to support fun & interesting new platform capabilities that make the web interesting, like WebMIDI, WebUSB, the mere fact that Safari is the gauntlet for innovation, that Apple & Apple alone gets to say what parts of the web will work, is highly poisonous to the web. iOS users having no choice, having a centralized actor now & forever gating progress is untennable, is wrong, prevents healthy emergence & discovery. However good they are today, they may drift tomorrow, and having no fallback, no options is a technocratic fascism that society should recognize as structurally sick.
B) That laws are different in different places and that even in the US there are exemptions to laws should not be casually ignored by assuming one narrow interpretation of a set of laws as you have: Apple controlling the distribution model with cryptographic locks hard-codes in a subset of American IP preferences around the world.
C) Even if we ignore these details and take your argument at the face of it and accept that for "choose how to distribute Fortnite" you merely are deciding between one of two centralized actors, you seem to be carefully trying to perform not one but two sleight of hands on the moral discussion at play.
It isn't like Epic doesn't have legal control over how Fortnite is distributed regardless: if Epic doesn't like Apple's terms for their App Store in the current model, they can choose to just not give you the software at all. You are just hoping to play a super dangerous game by assigning a single negotiator between your community of users and Epic in order to try to convince them to develop their software differently, for which you are apparently willing to pay 36% more for your software (which means you must value it a lot: like, for whatever benefit you think Apple is getting you here you are willing to dig into your own pocketbook and pay multiple extra dollars you otherwise wouldn't have to pay on every purchase or subscription) and--and this is where the tradeoff is unacceptable and the subject of the following #2--give Apple a large amount of control over all software in all jurisdictions... control which they lie about the benefits of, which they have routinely abused, and which can and is take advantage of by external actors.
And really, that is the most important thing in all of this and what I'd hope you would appreciate if you watch my talk: by giving Apple control over all software on the App Store you give them the power to affect what kinds of software is allowed to be built by anyone anywhere while creating a centralized chokepoint for the enforcement of whatever rules that bad actors want (such as the inclusion of end-to-end encryption carbon-copy features in applications or whatever). Giving Epic control over the distribution of Fortnite can't usher in a dystopia.
X) BTW: note that Fortnite is attempting to be some kind of massive metaverse service with a centralized set of servers attempting to provide an ecosystem of content that they would then have centralized control over. If the issues with Apple weren't so dominating and glaringly dangerous today maybe we could be having an argument about whether what Epic is building is moral and whether laws need to exist to stop it (and instead force--either directly or indirectly--such technology to come into existence in a way that is itself decentralized).
Not exactly. I'm hoping that at least one popular smartphone platform exists that exerts some leverage against software developers on behalf of users, so that users who value that feature can choose that platform. But it's also crucial for customers to be able to choose that platform (in this case, iPhone) for that reason, and to also have viable alternatives if they're not interested in this feature of a smartphone platform. I don't want Apple to do monopolistic things, and I absolutely wish there were more viable smartphone platforms, and I condemn Apple for the things it does to attempt to lock people in to the iPhone platform.
It turns out that with the current rules around monopoly rights of creators, many rights holders actually prefer to widely distribute, so I wouldn’t say that this makes it “even more concentrated” as the majority of content would be.
Some content will probably only be available in a first party store, but just the fact that there are competing stores is good for the consumer.
Assuming it works out the same as on Android, I very much doubt that sideloading would ever be mainstream or popular, but the existence of the option would serve as a constraint on how user/developer-hostile Apple can be.
(And I entirely agree with the article that Apple eliding over the entire internet-sales era of software is highly disingenuous...)
They could also just offer direct app downloads from facebook.com, instagram.com, etc.
So what? This feels like a nothingburger to me. Given how sideloading is a much less pleasant experience on even Android (and we can expect Apple to do worse), Facebook wouldn't leave the main App Store without an earth-shattering reason.
And no, entitlements mean nothing without enforcement.
I expect that to be a operating system feature that works regardless of how the application was developed or installed.
You pay 40% extra for that. The creator gets $100, Apple gets 40, you see $140 sticker price. It is a nice feature, but how many would pay 40% extra for that? And if many wanted to pay 40% extra for subscriptions to have them cancellable, I'm sure there would already be companies doing that.
[0]: https://hothardware.com/news/facebook-claims-10b-revenue-hit...
There's an inherent trade off here where adding safeguards to protect users will make the life of developers more difficult. Balancing these two concerns is hard.
I find that Apple mostly strikes the balance right, and so I choose to be their customer. People who disagree have other options available on the market today.
The argument that Apple provides more safeguards is a bit flimsy in my opinion. I honestly don't know what people think Apple is protecting them from, especially when Apple's own features have led to people being stalked (air tags).
Also, most iPhone users that I know tend to have bought their iPhone for cosmetic/style related reasons, or the camera. They don't seem to be all that privacy conscious, especially when their phone is loaded up with every social media app on the planet, including Tiktok!
We've not seen iOS ransomware yet.
https://www.wired.com/story/android-ransomware-worrying-evol...
Although we have seen things that impersonate iOS ransomware.
https://medium.com/macoclock/ransomware-on-ios-a-clever-tric...
Note that this is another area where you have this user vs. developer trade off.
- GPL or other copyleft licenses will put the user's rights above the developer's.
- MIT or BSD-style licenses will favor the developer rights above the end user's.
"open and unrestrictive as possible" is all relative depending on whether you are a user or a developer.
> The argument that Apple provides more safeguards is a bit flimsy in my opinion.
My point is that this is a market where people value different things. I value the safeguards Apple is putting in. I find they do a better job at it than their competition. But I fully understand that other people do not think so, or that they value other things more.
What I don't particularly like is some of these people turning to the State to force Apple to do things differently.
https://www.fsf.org/news/2010-05-app-store-compliance
Maybe? Might have changed since then.
https://opensource.stackexchange.com/questions/9500/is-apple...
One could imagine that if the platform was opened to side-loading, the first third party app store to gain popularity would not be one from Meta or Google, but an F-Droid analogue for FOSS hobbyists and purists.
iOS has a lower-cost of support, with lower fragmentation and higher churn.
With enough profit on the line, more companies would be willing to suffer the lower user acquisition rate that would come from side-loading.
Wouldn’t Twitter, Facebook etc in turn demand that those third-party apps be taken down from the App Store?
And even if they didn’t, how is any third party going to keep up with Twitter/Facebook/etc API changes.
And what about push notifications? Those would not work with a third-party app installed via the App Store unless Twitter/Facebook/etc explicitly made it so that they supported that on their end.
For example, here’s a blog post from 2016 about how the Riot app for iOS is able to get push notifications when you self-host a Matrix server. https://thomask.sdf.org/blog/2016/12/11/riots-magical-push-n...
No? Why would they? Third-party clients are alive and well on the App Store today, and have been for years.
> And even if they didn’t, how is any third party going to keep up with Twitter/Facebook/etc API changes.
They've done a fine job of it so far.
> And what about push notifications? Those would not work with a third-party app installed via the App Store unless Twitter/Facebook/etc explicitly made it so that they supported that on their end.
It does? Check out Tweetbot or Apollo for Reddit. Both have push notifications that work fine.
Twitter has been gradually killing their APIs.[0] Reddit doesn't offer APIs for the newer features, like polls.
[0] - https://blog.twitter.com/official/en_us/topics/product/2018/...
This is a key feature stopping 3rd party apps being competitive.
https://developer.apple.com/documentation/xcode/allowing-app...
Apple has no incentive to let other companies get away with bad behavior. And so far, their own bad behavior has been much better than other companies.
Here's a question though: isn't that also a reason for Apple to hobble web browsers? Everything you're saying about app security and developers refusing to follow Apples rules also applies to progressive web apps unless Apple commits to making its browser meaningfully less powerful than native apps, and (importantly) meaningfully less powerful in ways that Microsoft/Amazon/Facebook actually care about.
That means you've kind of got to commit to the idea that web apps on iOS never get notification support, they never get intent support with other apps or the ability to handle opening resources, they never get support for good background audio or timers/alarms, they never get reliable clientside storage for offline usage without accounts. It's not just that you can't do low-level complicated sensor/GPU stuff, Apple has to hobble browser capabilities that make it good for reading news or setting timers.
Is that a world you're comfortable with? I know a reasonable number of people on HN are comfortable with that idea, just because they don't want the web to have application capabilities in the first place. But a lot of other people bring up the web as an alternative to the app store (Apple itself is fond of making that argument), and it makes me think -- if the web ever is a viable alternative for good apps on iOS, then the situation you're worried about already exists, doesn't it? Instead of the NYT distributing a native app that you subscribe to with Apple's system that gives you easy cancellation, instead you would get a PWA reader app that you pin to your homescreen and you subscribe through their web interface. The only way that doesn't work is if the experience of reading the NYT and getting notifications about new articles and saving your account details is a worse experience inside of a browser.
If what you're describing about companies removing user choice or forcing users to accept worse alternatives -- if what you're describing is an inevitable result of any serious, alternative user-facing app platform on iOS, then the only way Apple avoids that situation with the web is if it consciously commits to Safari being perpetually behind on standards and perpetually systemically and deliberately made worse as an app platform. That could either be through making sure the browser always lacks features or it could be achieved through other UX designs like blocking PWAs from showing up in app lists, making them unreliable to install, blocking their installation entirely in some cases, etc...
Is that an outcome that Apple users are comfortable with?
I have push notifications disabled on my phone for (almost) literally every single app except my email client and Element/Signal.
I don't get why the web is special, push notifications in native apps are just as abused as they are on the web. Even built-in apps abuse them. We could just as easily make an argument that native apps should have them disabled as well.
But regardless, this kind of goes back to my point. Okay, let's say that every web app abuses push notifications. What we're saying is that we're not going to have progressive web apps. Any app that needs push notifications is going to be a native app, even if it's something as simple as a messaging client or a reader app.
There was a really strong movement around phone platforms a while back where people were asking, "why is this an app in the first place, why isn't this a website?" Well, you can't have that if you don't trust alternative app stores to some degree, because the answer is that any version of the web that is powerful enough to provide meaningful substitutes for native apps is an alternative app store that's outside of Apple's control/moderation.
Put it behind 10 hidden menus inside settings and facebook will not be able to explain to your average user that they have to enable this shady looking setting to download facebook. They can of course choose to ignore half of the US market, but that’s hardly a sane decision.
Apple's weak privacy stance is a farce, especially when ios lets any app have unfettered network access.
Additionally its own software does a lot of not-good-for-me things I'd like to prevent.
You should be able to restrict apps from any network access, not just local. Like contacting graph.facebook.com
put another way: Little Snitch for iOS.
I don't need sideloading often, but in those cases I really need it. As an example I'm in a part of Mexico where a local app is more used than Uber, but it's not in the Swiss app store that I'm registered in. I just sideloaded the app using the Huawei app store. I'm not sure what's the Apple way to solve these kinds of problems, as I don't have an iPhone.
"Even if Apple allowed sideloading, I don’t trust Apple to come up with an elegant solution, though. They will put every warning they can to discourage users from sideloading applications. It could make the user experience miserable, worse than it is on macOS. Why? Money is at stake here. A lot of money, actually. Because Apple seems to be run by lawyers and greedy people, we can expect everything."
They could then warn users their battery life would be worse, cos 2 persistent connections, and make it scary. Meanwhile I, as an Android user would happily take up the offer.
I'll tell you why: money.
The hidden challenge is tracking connection tracking timeouts in stateful firewalls and NAT gateways, so you can keep connections alive with the minimun of data exchanged. This is like if ISP A has a clean network, you only need to ping once an hour, but any packet sent will be recieved without delay; but ISP B needs a ping every 60 seconds or further packets will be dropped without notification. This isn't that hard either.
Bandwidth of push messaging is nothing compared to app downloads, and probably more of the effort would be on attracting quality applications and vetting applications and maintaining business relationships.
All that said, Google lets non-play apps use Google push, as long as the phone has play services, not sure why Apple would do it differently.
Cannot have it both ways. If it will be possible, FB will use it, and write a detailed sideload instructions.
F Droid is only possible because of side loading
At the center of each is a CPU, GPU, and storage. Software is the primary differentiator.
Whatever might happen to that binary between Apple signing it, and the iOS installer getting hold of it DOES NOT MATTER — if the signature is still good, then it’s no worse off than if it was put in the AppStore.
The security argument is total BS.
It would still use the same sandpit, still use the same permissions system, still able to be disabled by Apple, etc, etc.
Without the argument that "it's less secure", it becomes obvious that the only motivation is commercial.
That's the only reason they even created it.
But it doesn't indicate that the application has undergone Apple's review process. For that, you'd need a separate signature, signed by an Apple-owned private key rather than a developer key.
I'm not actually advocating this, just pointing out that it would provide the same security as the review process does now, without the need to download apps only from the AppStore. And so ... Apple's "but the security" argument is rubbish.
I really like the word disillusioning here. And this isn't the first time we caught Apple outright lying. Cases on Qualcomm, Imagination, Ericsson, Nuvia / Gerard Williams and possibly many others over the years.
And it is not a surprise Apple is acting that way. Software developers are a minority, and not every dev agrees with sideloading. If you look at macrumors and 9to5mac comments from users, you will see
"Apple should pull out of a small country like Netherland, it is Apple's IP no government should be allowed to touch it." or
"Apple should threaten to pull out of those state or countries that try to make them open up their platform and steal their IP."
"Apple spend $8-10bn per year on App Store for Xcode, hosting, reviews and delivery. Software developers are just greedy AF."
Yes I am not making any of these up.
It is the reason why for the first time in nearly 15 years of using an iPhone. I watched the Samsung Galaxy Unpack Event live yesterday. And...... it wasn't very good to say the least. But at least I am now looking, hopefully I could switch away from Tim Cook's Apple soon.
I really like the Steve Jobs video [1] "Steve Jobs on the greed and outlandish profits that ruined Apple", from Apple product Repair, Apple Retail Store investment, Apple Store employee KPI, I could go on and on. The is sort of the reason why having a product CEO is so important. So we dont have to wait 4-5 years before a fix on the Keyboard fiasco.
And I didn't even mention China.
"Sideloading is dangerous. Just look at Windows."
But please allow it already or I’m out of the apple bandwagon on my next purchase.
I suppose I can understand the appeal of that argument, since it does resolve apparent hypocrisy and lying in Apple's statements about its policies, but crucially this argument doesn't actually address whether allowing sideloading will be good for users, despite the author indicating that they think it will be ("Until today, I thought forbidding applications sideloading on the iPhone was good for users. But…").
All the arguments that preventing sideloading protects users still apply, and haven't actually been addressed in this article.
I'd say the main argument of the article is that the situation with the App Store in actual reality is so far from ideal that arguments about what happens in an ideal situation are irrelevant.
Speaking personally, the only thing I want to sideload is Mame (assuming an iOS version exists).
It does, and you can sideload it by following the "Building / Installation / Sideloading" instructions at https://github.com/yoshisuga/MAME4iOS.
1. Should Apple allow iPhone users to build their own software (or third-party open source software) and deploy it to their iPhones? The answer here is a resounding yes; in fact it's already possible! Just register a developer account, and you can sign your own apps and deploy them to your phone.
2. Should Apple allow predatory 3rd party vendors (Google, Meta, TikTok, spyware developers, etc.) to circumvent the AppStore review process and deploy their opaque blobs to other people's iPhones? The answer here should be no in my opinion. (unless iOS gets rewritten in Rust with a capability-based ultrasecure watertight microkernel, where accessing dangerous "private" APIs and thus privacy violations are provably impossible - in this hypothetical utopic vision the AppStore review process would become moot from a security point of view, although there are other aspects of the review process that cannot be formalized that easily, c.f. "I know it when I see it")
(of course, the predatory 3rd party vendors love it when people conflate the two issues)
Wouldn't sideloading make it possible for one sideloaded app to somehow impersonate another sideloaded app, and thereby trick the PKA/SKP into signing a message with a private key that the imposter shouldn't have access to? And might we even see vulnerabilities whereby a slideloaded app could impersonate an app downloaded from the app store?
If there is no way to securely distinguish between two sideloaded apps, such that one app could impersonate another in getting access to OS- or hardware-level cryptographic services, then that could be a real problem, no? And if you have downloaded an app from a third-party app store, what is stopping that app from somehow getting access to OS resources that it could to use to impersonate another app?
Does anyone know how this issue is dealt with in MacOS?
Come to think of it, how did another massive everyday consumer OS - Windows - survive all these decades with _most_ apps installed via sideloading (of sorts)? But iOS is somehow totally different?
Sideloading is part of it, and I can also mention JIT compilation.
You can load adhoc distribution apps through itunes onto your phone. Or, you can download Xcode build and run apps onto your phone. You just can’t distribute the app in binary form to a large group.
Seems like this is about alternate app stores, not side loading.
By allowing sideloading, a new attack vector opens up which reduces the liability on Apple, which is no different to what Microsoft and Google already do.
Facebook/Meta are sort of excluded in some ways because theirs app store runs online on their servers and not on your device which is considered private property and brings different Govt legislations into play.
Of course, the MAS is a pile of shit, Apple has utterly fucked up on basic great software business things like "upgrade pricing", and there are lots of examples of fantastic decent small/med size software devs doing their own Mac software same as always. Apple certainly has perverse incentives they have abused, primarily around service integration (can't aim backups at any storage provider for example). Also, it all breaks down when there is an entity MORE powerful than Apple like a major government. Then Apple becomes a single point of failure for censorship and control, and indeed that ties right back into the former. We don't have E2EE encrypted wireless backups for iDevices because of Apple caving to "security" agencies.
But still, it cuts both ways and I really appreciate that less technical (but still very smart!) users, including vulnerable members of my own family and friends, can have a platform in iOS which has much stronger guardrails that they cannot physically be talked into bypassing. I think giving those who ask for hardware, software, or both root cert access that access is enough of a release valve (these are probably all the same people who would jailbreak which is much worse) to help check Apple and bypass the big failing points while still accommodating the hundreds of millions of users whose threat models involve worse from other corporations. And it'd help nudge Apple's incentives in a good direction even for those staying fully within the walled garden by making them balance a bit on keeping them there.
Hrm. I don't think that actually would be as effective on iOS, reset/wipe is essentially setting up a new phone or a recovery procedure that is meant to be quite easy and near fully automated if time consuming. Which means the bar to social engineering is either very low because it follows the existing workflow and restores from backup ("click this before going to bed that's it"), or if it wouldn't allow restoring a non-root backup to a root device then it really screws the utility for all of us who want root ownership over our normal hardware (me included). This would not at all be a "dev mode" after all, it'd be a more normal Windows/Mac/Linux/BSD use mode including for people who never intend to ever write a single piece of software but do want stuff that Apple doesn't allow/enable.
Still an interesting different potential path.
Yes, Apple is too big and too powerful, and yes, we should to everything we can to take (at least some) power back.
That’s pretty huge, alone.
1. The fear of the other big tech giants creating their own app store, forcing users to migrate there to use Facebook/GMail/Amazon/Outlook etc., and then siccing invasive tracking on them for the purposes of serving ads and selling user data.
I think this threat is easily more conceived than realized. While the motivation exists to have easier access to user data, I don't think users will necessarily bite. Having to join a new third party app store just to be able to use Instagram or WhatsApp would alienate, and anger, most users. It's yet another account one would have to manage and keep track of. It breaks the seamless nature of iOS and mobile experiences in general. Everyone would know why they're really doing it.
And these companies are big and old. To create a competing app store takes a lot of effort. Not just on a technical level but on a product and business perspective. To convince users that this added friction is worth experiencing. Based on the anemic state of the Amazon Appstore or the Samsung Galaxy Store app stores on Android, tech giants only end up investing in alternate app stores if it's already tailored for the devices they make, which is a moot point with iOS. And those stores aren't even dynamic, nor contain app exclusivity as far as I know.
Not to mention, running a third party app store means that Meta will have to start wooing other third party developers so it doesn't just end up being the Facebook/Instagram/WhatsApp show. That means they have to start creating their own pocket ecosystems and manage their own platform communities as well. It's a lot of hassle and effort for something that won't necessarily pay off. Just ask Microsoft how their Windows Phone store fared. Or heck, just take a look at the current state of Facebook apps.
Maybe ten years ago when mobile apps were still a fairly new category of products, when there was a lot more room to grow and these companies were less entrenched and nimbler, there was a chance that rival stores could pay off. But nowadays? Sure from a technical perspective they're all capable of building their own cloud gaming service or Clubhouse clone or Snapchat stories knock-off, but how many of those actually stick?
I think the only companies that will want to heavily invest in their own third party iOS app stores will be video game publishers.
https://news.ycombinator.com/item?id=30204012
2. Installing random app binaries. Dubious files, email attachments, malware, random scripts, all common vectors for viruses and computer problems.
This fear on mobile is overblown because Apple still controls the operating system, and can carefully set the flow to prevent easy access to sideloading. They can enforce all sorts of OS and app binary-level restrictions even without needing to go through the App Store.
https://news.ycombinator.com/item?id=30199125
Though now that I've laid out the two topics, I suppose one potential worst case scenario is the tech giants act greedily and stupidly, force essential apps to be downloadable only on their third party app store, so users resort to sideloading those apps from shady sources.
But on the other hand, maybe people will use resort to mobile web instead. Or just quit using those apps altogether. We're already see Facebook adoption drop precipitously.
I see this highlighted all the time. When people agree with how something works then there's no comment. When it doesn't work how they want they believe they're being forced into a novel love-it-or-leave-it scenario, when the reality is they are in those scenarios all the time (daily/hourly even) and support them as well. Don't believe me? Ok I want less battery life on the iPhone and for it to be cheaper. Now what? You'll say "cost is important to you there are cheaper alternatives like X, Y, and Z". Same song.
tl;dr yea just buy an Android phone if sideloading apps is the killer feature for you. If I want the best battery life or the best camera I can base my purchase decision off of those product features. Sideloading apps is no different. That's a fact. Jack.
If side-loading is the only feature you care about, Android is for you. If it's one of many, you may have to make a trade off or pick between different mixes of features. This is just how the world works and always will work.
Not all get to have a market specifically for them.
Situations and therefore opinions are allowed to change over time. I could argue they pulled the rug out from under me when they removed Fortnite from the store, or started blocking apps I want such as Stadia. It's not like it's advertised on the phone "Hey we'll remove any app from the store that we don't like".
If I'm gonna be ruled by an authoritarian mobile OS that constantly tries to "engage" me, I might as well go for a nicer one that still cares about UX and being less buggy.
iOS is straying further and further from that path with every release, though. It's not Android-level, but it's far from what it used to be.
The fastest Android SoC is as fast as the A12, a three year old chip.
Android phones are lucky to get 1 major version upgrade in it's lifetime and that's usually 6-12s months after the latest version is released.
This is all done using the excuse that they are curators that want to give you the best possible experience. It has worked wonders too because now we debate not with these companies and their hired help but with others who have been screwed over just like us but are thankful for the experience.