I'm not legally trained, so I hope they've thought of this and also have rules for these 3rd party app stores.
In the past I even had banks and even the public sector offices abusing Windows and macOS security and forcing me to install the equivalent of a rootkit in my computer. Without a sufficiently smart sandbox I bet this problem will come back.
On the other hand, that doesn't seem to have happened on Android, at least not in a wide scale.
If you like the App Store and want to continue using it, you’ll be fine unless it becomes less popular and loses some important apps. That could happen but seems unlikely in the near term.
(1) App deals with sensitive or linenced content — doesn't matter what, DRM, medical info, private chat, take your pick.
(2) App integrates 3rd party library to look for other apps that might be trying to steal your data and/or record the DRMed stream you're playing. This 3rd party library injects itself at the lowest level possible in order to catch anything injecting itself even lower.
(3) Bug in library (or supply chain attack in the app as a whole) means the phone is now less secure than if the app had not been installed.
The difference from the status quo is, the iOS app store won't let apps root the phone. (IDK if the Android store prevents or allows that).
(I know games aren't "must have" apps, but this has already happened with anti-cheat rootkits. And "has this phone been rooted" software already gets used, but doesn't yet need to preemptively root the phone itself, at least not so far as I've seen).
I guess that's possible, but seems a bit unlikely -- it's just a pretty big barrier to entry for your users.
Android technically allows this already, but how many major apps are not on the Play Store? (Apart from Samsung apps, which is slightly different case as their store is preloaded when you buy the phone. But there won't be a Samsung iOS phone any time soon.)
Fair point. The company I work for would 100% now require you to do that If you want to use our software, to make it easier to comply with Qt LGPLv3.
> I'm not legally trained, so I hope they've thought of this and also have rules for these 3rd party app stores.
Isn't the idea here that you do not need an app store to require external software?