I don't have an answer for this. I'm all for people being able to get around the garden walls. I just hope and pray that no one in my "you use computers so you're my de facto tech support" circles does it.
I don't have an answer for this. I'm all for people being able to get around the garden walls. I just hope and pray that no one in my "you use computers so you're my de facto tech support" circles does it.
Why do we pretend that social engineering scams don't exist outside of installing anti-viruses? There are thousands of vectors of attack, many of which can and have been done on iPhones (bank accounts, gift card scams etc.)
The solution to this problem is EDUCATION, not letting companies monopolize a market just because we're too scared and stupid as a society to teach the elderly and vulnerable about security and privacy.
Nobody is pretending that.
> The solution to this problem is EDUCATION…
Nope. Educated, tech-savvy people fall prey to scams all the time: https://www.cnbc.com/2021/08/10/tech-savvy-teens-falling-pre...
I was reviewing a computer class curriculum for a younger cousin who is in high school. All they're doing is learning how to format documents and use spreadsheets. Being able to use an office app suite does not equal being tech-savvy or being educated about computer security.
[1] https://www.theverge.com/22684730/students-file-folder-direc...
https://www.techtarget.com/searchsecurity/news/252495750/How...
My kids (who go to a public school) have received what I consider thorough instruction on avoiding online scams and other kinds of danger. It sounds like YMMV, unfortunately.
But the main takeaway is that education doesn't make people scam-proof. The link at https://www.bbbmarketplacetrust.org/story/39089233/research isn't working as I type this, but Cracking the Invulnerability Illusion: Stereotypes, Optimism Bias, and the Way Forward for Marketplace Scam Education is a really interesting research paper on this. (I've pinged the author and will post a working link when she responds.)
That's was an example, but only an except. I think equally plausible is "my bank called and told me my app was broken and that I needed to redownload it. I tried logging into the new app with my bank username and password, but it didn't work. What's wrong with my phone?" Now, Apple doesn't have a perfect track record for catching and blocking these things. Their security controls are definitely better than not having them, though.
> The solution to this problem is EDUCATION
No, no, no. One of the things drilled into your head at security engineering and management conferences is not to ever trust the human factor. Education is a good thing to have in addition to all your other controls, but is a terrible first line of defense. People make terrible choices all the time. Maybe they're sick, or they've had a drink or three, or they're worried about something that happened at work, etc. etc. etc. Even smart people who've completed security training still make dumb mistakes.
This problem isn't solved by the centralized App Store--even if it were good at blocking any app with functionality that would let it be used as a scam (which it is not)--as it is just as if not even easier to tell the person "your app is broken and you will need to use our website" and then give them the wrong URL.
Like, I don't understand what you are trying to accomplish here: you think your elderly parents are going to go through a number of steps to install software via a different process but won't go to a website? I bet going to a website would even be a prerequisite to sideloading, so why would the attacker bother adding even more steps?
You are thereby helping Apple do something bad for both society and large numbers of other people and you didn't even manage to get the one thing you wanted out of it :(.
Bad solution: disallow this entirely.
iOS developers are sideloading their apps hundreds of times each day...
(Accounts that were inactive from publishing apps/games to the store. The accounts may have well been “active” for side loading/dev work)
Why isn't it free, or a nominal one-time $20 fee like the Microsoft Xbox developer program? Very good question.
Exactly. Want to sideload MAME? It's not a big deal. Go to https://github.com/yoshisuga/MAME4iOS and follow the "Building / Installation / Sideloading" instructions.
(And what if you don’t own a Mac? Create an entire macOS VM just for the purpose of installing an app on your phone?)
Compiling source on anything other than MacOS (at least was - not looked into it in a while) a PITA.
And to take the argument more broadly: how many of us here on HN became interested in computing because they screwed around on their PC as a child? What about today's children, who get a smartphone, a tablet and maybe a Chromebook? What are we teaching them?
I am for hassle-free side loading on every platform (Even on games consoles). I also dislike how most smartphones and tablets have become "Internet consumption devices".
I'd still put that as a bad solution. It is necessary but not sufficient for the owner of a device to be be able to run arbitrary code. It also must be the case that nobody can prevent the owner from running arbitrary code on their own device. The infrastructure required for Apple to be the intermediate for enabling such a feature would mean that Apple could also block the authorization from going through.
In effect, Apple must not be in a position to perform a man in the middle attack between an owner and the owner's device.
Today, iOS has a strong sandbox where apps can’t access data of other apps unless explicit permission is granted (eg. access your location/contacts/photos), and apps can’t access or modify system files at all.
Also consider that sideloaded apps does not mean allowing unvetted apps - Apple could still mandate macOS-style app notarization to prevent malware:
> Notarization is a malware scanning service provided by Apple. Developers who want to distribute apps for macOS outside the App Store submit their apps for scanning as part of the distribution process. Apple scans this software for known malware and, if none is found, issues a Notarization ticket. Typically, developers staple this ticket to their app so Gatekeeper can verify and launch the app, even offline.
> Apple can also issue a revocation ticket for apps known to be malicious—even if they’ve been previously notarized. macOS regularly checks for new revocation tickets so that Gatekeeper has the latest information and can block launch of such files. This process can very quickly block malicious apps because updates happen in the background much more frequently than even the background updates that push new XProtect signatures. In addition, this protection can be applied to both apps that have been previously and those that haven’t.
https://support.apple.com/guide/security/protecting-against-...
AKA, a "computer."
My computer.
That absolutely destroys interoperability, and is not a good thing. If the program that generated a file must give permission for it to be accessed, then a proprietary program can prevent interoperability simply by not actively enabling it.
Passing information between programs must be in the control of the user, not a program.
Actually android do exact the same thing these days. So you sometimes see 'XXX app want to access your photos', or a file explore to select which directory you grant for app to access.
There used to be a loop hole that any app can read sd card. But it is also sealed since android 10. Now every app see different rootfs.
> then a proprietary program can prevent interoperability simply by not actively enabling it
These doesn't really matter, a proprietary program can always break interoperability as long as they want. Did you see the old ms word .doc format? Even other version of ms word can't read it correctly, let alone any third party programs.
On iOS this can’t happen, regardless of whether an app was downloaded from the App Store or elsewhere.
The real thing keeping people safe is the operating system itself. The App Store is just a revocation mechanism for when something defeats those platform protections. That is what Developer ID is about on macOS: a revocation mechanism, only activated when platform security is breached.
People think that sideloading means Apple can’t scan for malware… Apple signs every single notarized binary
That is also to say that if Apple does open up the platform to alternate stores, I imagine they will still control the security portion.
Ultimately, though, someone needs to maintain a database of malware. When this malware is attacking the platform, it kinda makes sense for the platform maintainer to maintain the database. Microsoft maintains the Defender database, which does have false positives, and we thank them for it. If you want to override it, you can. Notarization works the same way on macOS.
That said, the neutrality of the database (malware only!), and the ability to override it are both key components.
It isn't 2002 anymore, systems have been hardened since the Windows XP days.
Would you feel the same way about handing your older relatives a Mac in 2022? They'd be able to install stuff from wherever on Mac.
I have tons of older relatives using Macs and Windows computers, and the days of Bonzi Buddy and 20 addon toolbars for IE are over. Some of them even have Android phones where sideloading has been a thing for over a decade, and the sideloading apocalypse bringing hordes of malware has yet to occur.
Truthfully, I believe your worry doesn't apply in our current computing era.
I absolutely feel this way about my grandparents and their Mac Mini. They've fallen victim to a few scams involving software installation that would have been much harder to pull off on iOS.
That's not a given, given the multimillion dollar scams on the iOS App Store[1].
[1] https://www.theverge.com/2021/2/8/22272849/apple-app-store-s...
Are you really saying that ransomware is not a problem? There is nothing stopping anyone from downloading anything on Macs and Windows.
> my "you use computers so you're my de facto tech support" circles
and you hate it. Stop doing that.
How many apps per week does your grandma need to install? It would be better if you set her up a phone with the apps she wants, and then disabled all app installation.
Because if someone is in that position, the unfortunate reality is that the official app store isn't safe either. The article gets into this in more detail, but there's enough malware on the official Apple Store to make it dangerous to randomly install apps. There are apps where their whole design is to set you up with big subscriptions in the background that you don't notice, there are malware apps that slip through Apple's review process, there are phishing apps.
Really, you should install the apps your grandma needs, and if she needs more later, then she can ask you about them (or someone else who's an expert). I think people look at the Apple Store as if it's perfectly safe and that opening it up would suddenly let in malware for the first time. But while the Apple Store might have comparatively less malware than Android, that's not the same thing as being perfectly safe, and it doesn't mean you can let a young kid or a naive adult go wild on it and install whatever they want. That's a recipe for disaster.
I've set people up on Linux and had zero support calls or malware problems with them, not because Linux has good security or perfectly curated software sources, and not because there aren't dangerous ways to get malware on a command line, but because they don't open the command line in the first place. Some people are safer and thrive in a computing environment that's set up to do the things they want and that doesn't change after that point -- but I don't think that has much of anything to do with alternative app stores, that's really a question of whether app stores should be allowed at all for those people.
No one says iOS can't implement similar parental controls for sideloading; they already have parental controls to prevent installing any new apps. Or add a similar phishing prevention systems like Google and Firefox has.
I do favors for my friends and family, and vice versa: they help me, and I help them. That doesn't mean I can't dread them going to great lengths to make it harder for me to do so.
You have to go through the settings and find your build number, then tap it 7 times. Super easy for someone knowledgeable to intentionally do, but basically impossible for someone to do accidentally / get tricked into.
Android manufacturers for some unknown reason always reorder/rename their setting menu randomly. And I seldom see any phone that have exact the same setting menu from different oem.
I'm scared that some of these people won't let their relatives answer the front door unless they are present, lest a man with a clipboard empty their savings account.
I think you're missing something important, which is that the App Store is part and parcel of Apple's (mostly successful) layered security model.
[1] https://www.theverge.com/2021/2/8/22272849/apple-app-store-s...
The Mac preference pane included in the article implements this. My parents aren't going to change that setting unless I tell them to which I won't.
And don't be ageist: my pre teen kid wouldn't either, having already rendered his computer unusable a couple of times in other ways. Once he became a bit older things were different, but by then it didn't matter to me and wasn't really any of my business.
It should be added to iOS and tvOS.
It should have never been a valid reason against restricting everyone’s freedoms.
??? macOS does have a real Unix shell. It’s called zsh. And it’s not that hard to get whatever compilers you want.
Shells are not the entire UNIX environment, they’re just one part of it. (And I don’t think you meant it this way, but please don’t say it’s not a “Unix shell” because it doesn’t have GNU extensions.)
If you don't know what is sideloading. Without toggle the hidden browser setting, open a apk in browser will just say `the app can't be installed correctly`.
If you know, you just know you need to open the info of browser, and toggle the __Allow this app to sideload other apps__ option.
I. I do want to be able restrict what they can install on their phones and it gives me a small peace of mind that nothing they install would outright steal their bank app’s credentials or all their passwords.