Sure, you may not install them. You may be perfectly meticulous with what you install on your devices. But not everyone is.
The only people who should be concerned are those over-exposed to Apple stock, but they're not getting any sympathy from me.
If a friend or relative wants a phone, for now I can recommend them an iPhone and be free of the drama that would ensue if (when!) they installed any of those sketchy things you mention, which not only would for instance spy on their messages, but also get anything I send them in addition to my contact data. And then I’ll have to do technical support to mitigate the consequences.
Other situation when this freedom will be a problem would be peer/boss pressure to install some crap that they like to use for messaging for instance.
Unfortunately, others installing garbage in their computers/devices affects me too. That’s a social problem, and there is no simple solution for it.
I’d still choose freedom.
Also if Apple is so secure, why is there a celebrity iCloud hack almost every other day?
You already have Siri for that. All voice assistants are spyware.
If anything, only cloud void assistants.
I'm not legally trained, so I hope they've thought of this and also have rules for these 3rd party app stores.
In the past I even had banks and even the public sector offices abusing Windows and macOS security and forcing me to install the equivalent of a rootkit in my computer. Without a sufficiently smart sandbox I bet this problem will come back.
On the other hand, that doesn't seem to have happened on Android, at least not in a wide scale.
Fair point. The company I work for would 100% now require you to do that If you want to use our software, to make it easier to comply with Qt LGPLv3.
> I'm not legally trained, so I hope they've thought of this and also have rules for these 3rd party app stores.
Isn't the idea here that you do not need an app store to require external software?
If you like the App Store and want to continue using it, you’ll be fine unless it becomes less popular and loses some important apps. That could happen but seems unlikely in the near term.
(1) App deals with sensitive or linenced content — doesn't matter what, DRM, medical info, private chat, take your pick.
(2) App integrates 3rd party library to look for other apps that might be trying to steal your data and/or record the DRMed stream you're playing. This 3rd party library injects itself at the lowest level possible in order to catch anything injecting itself even lower.
(3) Bug in library (or supply chain attack in the app as a whole) means the phone is now less secure than if the app had not been installed.
The difference from the status quo is, the iOS app store won't let apps root the phone. (IDK if the Android store prevents or allows that).
(I know games aren't "must have" apps, but this has already happened with anti-cheat rootkits. And "has this phone been rooted" software already gets used, but doesn't yet need to preemptively root the phone itself, at least not so far as I've seen).
I guess that's possible, but seems a bit unlikely -- it's just a pretty big barrier to entry for your users.
Android technically allows this already, but how many major apps are not on the Play Store? (Apart from Samsung apps, which is slightly different case as their store is preloaded when you buy the phone. But there won't be a Samsung iOS phone any time soon.)
Exactly, I should be able to buy another iPhone and mess about on it.
While I sympathise with your overall sentiment, I have no reason to believe Firefox or Chrome would have any more RCE vulns than Safari does, and their respective engines not being deeply integrated with the OS potentially means one less vector for a hypothetical RCE to escalate privileges.
Correct. Malware and trojans, everywhere will be unleashed on the average user and will make the crypto wallet an obvious target for scammers and criminals to take payment with and steal the users crypto.
Wallets will be drained via modified, cracked apps or hack tools connecting to dodgy smart contracts, and payment providers will be using anonymous cryptocurrencies like Zcash, monero, mobilecoin (used in signal messenger) etc.
I can only see nothing but the same security issues on the desktop, but now made worse on phones enabling side-loading or alternative app stores.
You already can on e.g. iOS but you get a slow implementation if you use your own engine. Does this account for that?