Whatever might happen to that binary between Apple signing it, and the iOS installer getting hold of it DOES NOT MATTER — if the signature is still good, then it’s no worse off than if it was put in the AppStore.
The security argument is total BS.
Whatever might happen to that binary between Apple signing it, and the iOS installer getting hold of it DOES NOT MATTER — if the signature is still good, then it’s no worse off than if it was put in the AppStore.
The security argument is total BS.
It would still use the same sandpit, still use the same permissions system, still able to be disabled by Apple, etc, etc.
Without the argument that "it's less secure", it becomes obvious that the only motivation is commercial.
That's the only reason they even created it.
But it doesn't indicate that the application has undergone Apple's review process. For that, you'd need a separate signature, signed by an Apple-owned private key rather than a developer key.
I'm not actually advocating this, just pointing out that it would provide the same security as the review process does now, without the need to download apps only from the AppStore. And so ... Apple's "but the security" argument is rubbish.