iOS 17 app sideloading might only be available in Europe
techradar.com
techradar.com
Like a lot of Apple and huge company stuff in general, it's a flimsy reason to change something and introduce many limitations the huge company thinks will make them more money. It sure as hell is not about reversible connectors.
But please, reference a USB2 or USB3 standard over a type A connection that enables fast charging too. This will be fun.
And Lightning has been charging my iPhones pretty fast
"Many different standards" means "no standard".
> that apple just ignored.
Apple ignored them because none of them were standards until very, very late
USB Power Delivery 1 was a disaster, launched years after Apple had moved beyond 7.5W charging. Android phones typically also ignored it, using Qualcomm's proprietary charging tech.
If you want fast charging, use the bundled USB-C cable to charge your iPhone rather than the USB-A ones from years ago.
To flip it around, what advantage do you think one gets with official Apple iPhone chargers? Do you know of any evidence that Apple promotes their chargers working better than others? And if none exists, why would they sabotage customers who were never educated that hypothetically only Apple chargers charge fast?
So not fast charging, charging at all. They work on some of the iPads, so they do work.
Why do the phones refuse to charge then? Not fast charging, which I can sort of understand, charging at all.
This situation is different. Apple and others are completely unable to upgrade to USB-D when it comes around.
Similar to the switch from microUSB-B to USB-C. Budget phones kept using the cheap option for awhile, but eventually costs came down and people settled into the new standard.
Not sure how it's done in the EU, but their legislature could delegate authority to make such decisions to an executive agency if the process of passing an amendment or new law is too slow.
That's how it's done, is my understanding. The actual articles of the "usb-c" law[0] doesn't even mention usb-c. Here's what Article 1 states:
> With respect to radio equipment capable of being recharged by means of wired charging, the Commission is empowered to adopt delegated acts [...] in order to ensure a minimum common interoperability between radio equipment and its charging devices, as well as to improve consumer convenience, to reduce environmental waste and to avoid market fragmentation, by:
> (a) modifying, adding or removing categories or classes of radio equipment;
> (b) modifying, adding or removing technical specifications, including references and descriptions, in relation to the charging receptacle(s) and charging communication protocol(s), for each category or class of radio equipment concerned.
> [...]
> The Commission shall submit a report on the assessment referred to in the third subparagraph to the European Parliament and to the Council, for the first time by 28 December 2025 and every 5 years thereafter, and shall adopt delegated acts pursuant to the second subparagraph, point (a), accordingly.
So the Commission (which is part of Europe's executive branch) can enact delegated acts to add new technical specifications for wired charging. USB-C is not "hardcoded in law". What's hardcoded in law is the Commission's authority to mandate the use of certain ports.
[0] https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CEL...
For example the cookie law has made most websites significantly less enjoyable and everybody hates it and yet it has been stuck for years, no hope of improvement in sight.
When it comes to overbroad laws like the cookies thing, lazy malicious adherence is the name of the game. Simply block JavaScript from domains like "cookielaw.org", and you'll never see the dialogs.
Is it legal that the website doesn't ask for your consent if you block random third parties from executing code on your machine? Who cares!
It's been a decade since a new port (lightning was 2012, usb-c is 2014). So apparently, they are doing pretty well!
I think my answer here would "enjoy the next decade of benefits and worry about it then?"
And the same arguments were made at the time. "Stifle innovation" and "what innovation, this connector is perfect. No need for improvement."
Well, it's a good thing they UPDATED the bill that eventually became law, right? I guess they could probably do that again, if necessary!
I like USB-C way more, and frankly don't like Apple that much at all, but let's not pretend lawfare doesn't have collateral damage.
But somehow we have decided that small computers (aka phones) must only have 1 port.
Because, you guessed it, they are small. And any port you add requires a not insignificant amount of space
At a certain scale of adoption/societal impact, having a common set of agreed standards is much more important than fragmented "innovation". I would argue having a general and common way to charge devices qualifies for that level of importance. The incentive on Apple's side to stay off of USB-C can only be one of profit driven customer hostile design... as there's really zero technical or otherwise reason to have stayed on lightning this long.
One of the biggest annoyances in my daily life is having to swap back and forth between USB-C and lightning cables. These lightning cables being sold today are effectively trash to be thrown away in a year or two. Completely unnecessary, and hard to have any respect for the intelligence of people who defend it. There is no slippery slope here. If Apple wants to build a next gen port, then they do it alongside other industry players rather than monopolizing the technology so they can charge 10x markup on cables/accessories/licensing... which imparts zero benefit to the consumer.
And as it is it seems extremely unlikely that Apple wasn't already planning Lightning for iPhone...
Now, not everybody works in or near a metal shop or a saw mill, but all the people I know with phones wear clothes, which sometimes has lint, especially in pockets where phones are kept, and so aren't totally immune from this problem.
Thankfully there's wireless charging, and it's decently powerful/quick these days, so the whole port can be taped off - when you remember before you go into the workshop, which hopefully is every time.
It's called being pragmatic
> will have to allow for more flexibility in what apps are allowed to execute
Of course it won't. There will be 1% of apps that do something that HN crowd will perhaps care about.
The rest will be apps that try to circumvent privacy and security, and/or chase their own goal. Note how much speculation there is about Meta going the side-loading route.
That lightning cable on iOS is stupid, it only benefits Apple.
Both changes are more than welcome, although I don't use iPhones (precisely for this reasons - closed ecosystem, lighting)
We both can both underestimate and overestimate the size
> That lightning cable on iOS is stupid, it only benefits
Apple has had exactly two connector types.
USB has 14 connector types. On top of that USB didn't even have a power delivery standard until after Apple shipped lighting, and didn't have things like fast charges etc. until USB-C.
And USB-C is in itself a big mess of a standard where you can't even be sure if a cable support features you need.
So, no. Lightning benefited Apple's customers immensely.
Lightning was introduced in 2012. So you're trying to say that it was competitive for just a year?
Of course that's bullshit.
> High power charging standards were around since 2012 at least.
And those standards (multiple) are? You're probably referring to Power Delivery which was finalised the year Lightning was released? Or the finally upgraded versions of Power Delivery that only appeared with USB-C (that mess of a standard where you don't even know if a cable is capable of doing anything)?
There is no way for me to disable marketing push notifications on any device.
I can’t tell Facebook to remove Reels because it’s too addicting.
Firefox is my primary brower, but 5x per week I have to switch to Chrome because a website won’t let me login or is acting funky.
We have lost control of our devices
I have used firefox and adblock/ublock since literally 2007, and have NEVER experienced this. What websites have given you trouble? What functionality doesn't work in firefox? What functionality is even different in firefox? Is it just servers reading your user-agent and saying no?
A documented gap is my SSO provider (JumpCloud)'s Device Trust Certificate only works in Chrome and Safari on MacOS.
https://support.jumpcloud.com/support/s/article/supported-we... https://support.jumpcloud.com/support/s/article/understandin...
Apple made their app store incredibly restrictive and took a massive cut of any profits that anyone was making. Not just app sales, any profits. (This happened to hey.com, they wanted a cut of the subscription that users were getting outside of their app). Sometimes apple would just outright steal developer's apps by making their own version, then blocking the original developers by claiming that they were making rip offs of Apple's apps (you'll find a few stories of that happening here on HN).
Then to really rub salt in the wound, they started telling developers in essence: "If you don't like the way we run our app store then you can always make a web app", despite the fact that they had purposefully hampered web functionality on their devices to force developers to use the app store.
It's really strange how their browser only started getting better all of a sudden when they were getting sued for their anticompetitive behaviour and the EU said they were drafting up legislation to break their monopoly.
It is directly due to the efforts of the EU that Apple has been dragged kicking and screaming to add functionality to their own ecosystem that is objectively demonstrably superior to what was available before.
As soon as you have sideloading, you have developers who can't get kicked off the app store for not giving a 30% cut because they're not on the app store.
The amount of fines that Apple wants to choose to pay is up to them. Either they cave, or they pay as large of a fine as for however long they keep fighting.
The EU has squeezed telcoms on roaming charges which created a lot of howling. The EU also has rather strict regulation concerning gas use of cars, ICE emissions and so on, probably second only to California. The EU approach to food and pharma security is fundamentally different to that of the USA, and it impacts EU companies. Regulations around green GMOs are so strict they basically killed the European market for GMOs.
In both cases, Germany had to accept rules they would have never accepted if they were outside of the EU - even if they sadly were able to soften them up.
Like yeah, Germany likes to keep the EU as a consumer of their shit, basically.
France likes to play along 2nd I guess
Last month: https://www.nytimes.com/2023/03/28/business/france-bank-raid...
A year ago: https://www.theguardian.com/business/2022/apr/29/deutsche-ba...
A few years ago: https://www.theguardian.com/business/2019/apr/17/deutsche-ba...
Panama papers: https://www.theguardian.com/business/2018/nov/29/deutsche-ba...
This was Germany the government, not the car companies. We're not perfect here in the EU either. But indeed the interests do seem more balanced than in the US in general.
The ability of computers to control the vehicle should be proportional to their perceptive abilities. No output without input.
But even strict limiters without intelligence are commonplace, here in the EU most trucks are fitted with them. Which can be annoying because it causes trucks to overtake each other ridiculously slowly sometimes. It's not something that causes major safety issues though.
Before we can mandate software to observe the limits, we need proper software-readable signage.
Sometimes signs are placed between two roads running in parallel, and apply to the other one. Humans understand that subtlety in sign position, but computer vision doesn't. Signs can also be obscured by trees, etc.
My car's GPS-based speed detection doesn't understand height, so on crossings with bridges/overpasses it picks one at random. When I drive on a highway it can briefly flip to a speed limit of some ramp, and I wouldn't want this to cause phantom breaking.
That we can pass e-bike speed limit in short time without even asking people if they want it while we can't limit cars, which actually cause hundred of thousands of deaths and injuries per year tells you all you need to know about the state of things.
It's either "let's make everyone look at me by making a lot of noise" or "nobody's looking, I'll ignore the speed limit"
Not arguing particulary in favor of AI here. I just happen to hate the perception of private vehicles as extension of one's individual freedom. The restrictions imposed on e.g. pedestrians caused by this thinking tend to be ignored.
Public transit for everyone, cars for goods, services and emergencies, that would be my utopia.
I know this is a fringe position.
The smallest party (FDP) in the coalition went on a solo power trip against their partners. The partners relented because they need the FDP to fall in line with more important stuff.
Also worth noting that the FDP is currently getting voted out of more and more state parliaments because people are not happy with their work.
The thing is most regulation is happening where people actually get hurt. Hey, I am not super pro regulation person, but in comment above, I just tried to disprove something that seemed false. I am not going steelman pro-regulation arguments any more :)
[1] https://assistance.orange.fr/objets-connectes/installer-et-u...
On the flip-side, T-Mobile has an app to add an eSIM to "test drive" their service on your phone for free, and I look forward to the day I can buy travel SIMs in advance on my couch at home.
I’d argue that in theory, new upstarts ought to be able to enter the market and satisfy the demand if it exists. However, in many fields, there are substantial barriers to entry that prevent this. For instance, in the auto industry, it takes huge amounts of capital to reach the necessary scale, gain enough experience and reputation, etc., to be able to compete with existing companies. Similarly, it would be a monumental engineering effort to produce “iPhone with USB-C” due to the amount of intellectual property, goodwill, Silicon deals, integrations, etc., that Apple provides. It would be impossible, really, due to iMessage and FaceTime being proprietary. There could be new cable providers that don’t run ads, but they wouldn’t be able to compete on cost, and they would have trouble dealing with the regulatory environment for infrastructure, striking deals with networks, etc.
Banning companies from engaging in practices that benefit them once they become sufficiently adversarial to consumers isn’t a scalable solution. There are many instances of this across many industries; regulating them all would be like playing Whack-A-Mike. It also provides no recourse to the group of market participants who don’t care if their phone has Lightning or USB-C, and probably prefer Lightning since they already have a charger. It also leaves less room for innovation since companies will have to comply with standards, possibly preventing superior technology from being developed (that’s how we got Lightning to begin with).
I’d love to hear other/better solutions. I’ll throw one idea/observation out myself. A lot of these misalignments are because providing a better consumer experience today reduces the likelihood they will be a customer tomorrow. Either they will leverage the lower switching cost to switch, or they will be more loyal but purchase less in the future due to the increased quality. What’s a way to manipulate company economics to favor shorter-term views of the company, and disregard higher-growth plans? Higher interest rates. Maybe a higher interest rate environment could mitigate some of these issues by ensuring companies care about the business they have today, more than the one that they could have tomorrow.
what's the migration process for eSIMs?
You can transfer the sim but it needs to be activated on the other phone. I have even seen reactivation charges of €5.
Oh, you do? It's still a single point of failure. Customer support servers down? Should have gotten a physical SIM.
Unbeatable servers? Good luck swapping eSIMs when you want to sell/throw away your phone abroad, out of range of internet. Should have gotten a phyical one.
Never out of range? Wonder what you do when your phone breaks and you have no one to babysit you through the process. Should have gotten physical.
Etc.
That's what an additional sigle point of failure means: less control over your own infrastructure.
New technologies often improve things in some way while introducing concerns and potential drawbacks in other ways. The question is whether, on balance, the new way is worth the risk.
My experience so far is that it is — it’s very convenient to be able to use a service like Airalo to order prepaid eSIMs for data service in foreign countries in advance. It makes traveling a joy now, and my wife is irritated a whole lot less by the prepaid SIM hunt I used to go on when traveling abroad. Plus no more tools or risking losing your SIM tray (or the SIM itself) when you swap it out on an airplane tray table.
My experience says that it will get steamrolled and the 1% left hanging, looking at significantly worse solutions, or none altogether.
I know we all hate telcos and mobile phone carriers -- and a lot of their mistrust is quite frankly deserved -- but this seems like an edge case that most customers won't even run into. First they need to switch devices, which eliminates most customers, and then second, they need to experience some kind of failure on switch. If the failure rate is any higher than before, I would be surprised. But let's wait to see the data before we all go up in arms.
https://support.apple.com/en-us/HT212780
eSIMs also have the advantage of an activation card can be sent instantly from almost anywhere (it’s a QR code) which is great if your phone (and physical sim) are lost or damaged.
“Some” is true afaik. It’s at the providers discretion.
AFAIK it’s also only possible if you’re moving from iPhone to iPhone, not if you’re moving to an Android. I’m not certain moving back and forth between multiple phones is easily supported.
I like e-sims in general, but this is a downside for some use cases.
Now, we‘re on a business contract and we have a responsive team on the other side, so the comfort of this hinges on the provider obviously.
One operator even charges 10€ for a new QR code for your eSIM (same price as getting a new physical SIM card).
I recently bought a temporary SIM in the US during my holidays (StraightTalk) and was surprised that you can only use the physical SIM after you register online with you IMEI. I haven't checked, but I imagine that after that the card would only work with that IMEI.
Fortunately, I don't think this is a practice in Europe.
I really hope that it's because they are awful and this is not the typical American mobile phone experience.
eSIMs are incredibly user-hostile because they switch the ownership of a SIM card from the customer to the provider, so you're completely at their mercy if you need to transfer over your SIM card from one device to another. And Apple facilitates this.
It's probably intentional. I was reading an article in the French press the other day [0] on the subject. Some head of something or other in the industry said they were weary of mostly Apple, Samsung, and Google starting to like playing the providers and removing the actual carriers from the users' psyche. "The SIM card is the last physical link between the carrier and the client".
I've also checked my carrier's site for getting an esim. Apparently I'd have to pay the same amount to get one as for a physical one (minus delivery costs). But at least, contrary to some other commenters' situation, they seem to allow you to move it from phone to phone as long as you hold on to your qr code. They, of course, don't offer the option of storing it in the "secure" client area.
[0] https://www.lefigaro.fr/secteur/high-tech/avec-l-esim-la-car...
Yes, but what does that tell us? How is that useful? All you've done is point out a situation where the happy path works. If you have a great carrier whose systems are working correctly then it's going to be fine. That's what you'd expect. No one really cares about the cases where things go right. They're boring. They should be boring. The problem is never what happens when it works, but what happens when it doesn't work.
I've spent the past two and a half decades learning that the happy path is the least interesting part of any system. Building a working app is about 10% of the work of building anything. The other 90% is error handling, designing processes to get things back on track, and managing when things change. If you focus on the bit that works, and you assume that things will work, and that any human part of the system works (where code is written by humans) it is bound to break at some point.
The issue here is that taking a physical sim card works and dropping it in a different handset has far fewer moving parts and it's all stuff that's been proven over the past 30 years. There is less to go wrong. As soon as you start adding carriers and their shitty websites into the mix things will screw up for a non-trivial number of users.
All indications so far are that eSIMs work quite well. Plus it’s pretty awesome to be able to purchase prepaid service through a company like Airalo when traveling abroad and to be able to use it instantly. Same goes for switching carriers.
Generally speaking, leaving something to see if it'll work means it's too late to change things easily if doesn't work. Managing change is one of the hardest things to do in any company, let alone industry, so finding the problems during the testing phase is really important. If it gets to the consumer and things aren't working (which happens a lot) that means people screwed up.
Buying a local sim card and putting it in your phone when you're travelling works fine, and instantly, so eSIMs aren't offering any advantage there besides not needing to go to a local shop.
When your phone breaks, that's not a easy task.
https://support.apple.com/en-hk/HT209086
Personally I'd love for eSIM to be there in ADDITION but not replacing the nano SIMs.
Now you might retort aha! See! In a very narrow set of circumstances.. let me cut you off, look, you're going to need to remember to bring a paperclip or sim tool to do it the old fashioned way anyhow. So you're remembering something. If you're an amnesic lost in the woods you got bigger problems.
Besides, those are 2 grams of weight savings in my ultra light backpacking setup!
My old phone is still logged in to Apple, still works, still holds a charge. I'd like some eSIM system that was as convenient as "phone dies, pull SIM, put in old phone, boot".
If we disregard the fact that many older but still usable phones don’t support e-sim (which was the original point), what do you mean ”just” download the e-sim?
At least in my country, getting an e-sim is a pretty involved process which requires secure authentication, and specifically in my case that authentication would be gone with the now-broken phone if one didn’t have the foresight to have a backup (which many people do not).
If you have a physical sim, you can move it to almost any (unlocked) mobile phone in existence (at least in Europe) and at most you’ll need the PIN/PUK.
Of course, this goes the other way as well if you drop your phone in the ocean for example, provided you have alternate authentication and a compatible phone, e-sim will have you up and running again much faster.
Password to Flex itself is in my 1password db. If that gets compromised I'd have way bigger problems than cloned phone number.
Carriers are the real problem here, not letting you easily switch between a physical SIM and an eSIM in case that happens. Some do, but you usually have to call up, there are delays, etc. Ideally it would be an easy switch in their web admin panel.
I couldn't imagine them jumping on the esim train in any useful way in the near term.
It’s actually the scenario that finally convinced me that eSIM was a good idea.
Yes, you can get service for that price. It has paltry data allowances compared to what OP is describing.
In plenty of countries if you try buying straight from a local provider you can’t buy low amount of data or have to get voice with it. Meanwhile Airalo allows you to buy 1, 5 or 10GB for very cheap and topping up is pushing a button in their app.
I meant it when I said it was insanely more convenient.
Easier to get online in a new country if you don’t have to first seek out a physical SIM card. Plus you keep your home SIM secure in the phone where there’s no danger of losing it.
Instead, just get on WiFi when you arrive, take your pick of cheap offers, and download the eSIM directly to your phone.
> ”I couldn't imagine them jumping on the esim train in any useful way in the near term.”
Depends on the country. Thailand, for example, is very eSIM friendly. But there’s plenty of “developed” countries in Europe where eSIMs are almost unheard of.
Or before you even get there.
When I landed I made a one off 400 yen payment, like tree fiffdy or something, and immediately had data working right at the airport for the rest of the month. Apple Pay, one off, no contracts, no queues, no diligent service people. It saved probably 1 hour of my life! And it is somehow significantly cheaper (depends on the country, ymmv).
Frankly I pity people who get off a long flight and wait in line to get an overpriced piece of plastic to stick in their phones like it is 1823.
Also moving a eSIM from iOS device to non-iOS device (for example to plug into my secondary Android) is a massive PITA. I always have to re-issue the SIM which I often can't do and need to jumps through customer support queries and hoops. My current provider back home doesn't even give me the option to do it while abroad and support told me to come back for a day, then finish the eSIM reissuing application, so I'm stuck with the physical SIM anyway.
eSIMs will be great one day, but that day is not now. I much rather pop the SIM out of phone 1 and move it into phone 2, or iPad when I want, than wait hours (or sometimes days) to get a new eSIM approved, and repeat that process every single time I want to move a connection to another device
Now? People can switch carriers while in their living room. Takes a matter of minutes. Absolutely frictionless.
(Distributing software is not always easy, as game companies that have 100GB game downloads on launch day will tell you. But, for most apps, it will be easy enough.)
That is what it looks like will be very undesirable because it will be fragmented and competing with an all-world app store that is bundled with iOS. If you were a developer you would prefer 1000 sales at 30% cut, vs 5 sales with a 0% (supposedly still 30% if the chatter is right on Apple charging for sideloading) cut, so that would kind of feedback loop and make less people list on those app stores, which in turn makes them undesirable.
It would be struck down by the courts and version 2 of this regulation but for a few years it would be there.
I'm hoping apple doesn't do that but at this point I think they'll try anything they can to protect their golden goose (aka app store) even from minor competition.
The biggest problem with Apple's revenue model is that they want the 30% for people that aren't really benefiting from the App Store. Spotify built their brand without Apple, and if you want their app, you just click the link they email you.
You are speaking of licensing agreements to get access to the Apple SDKs, not to distribution. These are different things. Side loading on its own does not mean an end to contractual agreements to give Apple a revenue cut.
Isn't that what developers pay for to get access to?
> In addition, developers may have to pay extra if they want their apps to be available outside of the iOS App Store, Gurman says.
The statement is a bit ambiguous. Is it pay Apple extra or pay extra to the 3rd party to have their app listed in the 3rd party app store?
The former doesn't sound right; It is probably FUD.
Logically, a 3rd party app store could compete on significantly reduced fees relative to Apple (as one of the strategies). Those conscious of the quantum of current fees then have options of listing their app on both the Apple app store and the 3rd party store as part of their distribution strategy. Customers who trust the Apple appstore would get their app from there and those who like a 3rd party app store would get it from there. The app developer would have reduced their total fees (for distribution). Even if there are signup fees, the share of revenues that Apple is today taking away from the developer would go down in absolute terms with a 3rd party store.
As far as the consumer is concerned, this becomes an OS setting like 'default browser/default text editor etc.,'.
Apple sticking to only the Apple App Store stance is only raising the cost for consumers. Consumers in other geographies will also wake up. Eventually.
Or, it might mean Apple will charge higher rates for apps that are also available on other app stores? Not sure if that's entirely legal, but since when have pesky things like the law stopped companies as big as Apple?
If I release my next version update and post it to just the 3rd party app store, I could then theoretically move the 120k customers to download the update from the 3rd party store and then save $72k/mo.
That is what Apple is afraid of. I think.
- For figurative developer moving 120k customers saves $72k/mo
- For figurative customers on $3/mo subscription it means ~$0.65/mo savings
- Such scenario doesn't take into account amount of work required for switch (5 minutes of form filling on $15/h is $2.5 - gain starts at 6th month)
- Neither it does UX around subscription management (right now it's very comfortable to manage Apple's subscriptions)
As a counter, anecdotal, point - I, myself, pay >$5/mo overhead on subscriptions and I'm completely aware that I can save money. My reasons:
- I'm too lazy to set up full account on provider's website
- Apple is VERY verbose about subscriptions, even if I forget about one, they e-mail me about it
- It easy to manage all my subscriptions and thus I only have subscription for things I use
While it is true that inertia might stop many customers from changing the default, it does give an additional degree of freedom for devs.
Also, in price conscious geographies like India (where Apple just launched their first two retail stores this past week), we have alternate payment mechanisms like UPI (Unified Payment Interface) that are zero cost. So, why should a dev be forced to use only the payment mechanisms offered by Apple?
I don't see a problem with that.
If a producer grants exclusive distribution rights to a seller, the typical consequence is that the seller gives the producer a greater profit share in return.
On ending those terms, the seller may rightfully reduce the profit share, in my opinion.
I don't get why anyone should be paying Apple a rent for using a 3rd party app store (lets say exclusively).
As a hypothetical, lets say Epic Games or Steam launches an Alt App Store for games that can be installed on ios. Why does any gamedev using those stores have to pay Apple any transaction fee?
Just doesn't make any sense and would just be rent-seeking on Apple's part.
Putting up anticompetitive defenses for the app store in the garb of security, censorship etc., while hamstringing alternatives for app installation -- It is a matter of time before the antitrust (or equivalent) units of different governments come after Apple.
For reference, Competition Commission of India penalized Google INR 1337 crores (INR 13,370,000,000 ~ $161M USD) for abusing its dominant position. [1]
From that link:
> For this purpose, the CCI delineated following five relevant markets in the present matter:
> - Market for licensable OS for smart mobile devices in India
> - Market for app store for Android smart mobile OS in India
> - Market for general web search services in India
> - Market for non-OS specific mobile web browsers in India
> - Market for online video hosting platform (OVHP) in India.
The second bullet point is pertinent for Apple's current behavior relating to App Stores.
Apple's market share in India is miniscule. But they have just opened up Apple retail in India this week with stores in Mumbai and Delhi. So, with local customers increasing in the next couple of years, this will be something Apple has to contend with.
[1]: https://pib.gov.in/PressReleaseIframePage.aspx?PRID=1869748
I guarantee you Apple will find a way to still make the same money.
Just like how in the Netherlands dating apps don't have to use IAP, but the apps need to pay Apple a 28% royalty on all in app purchases that don't go through them.
Thanks, really interesting
How I read this is that they are basically creating a 3rd category of apps. Up until now you could sideload apps on an iPhone via an enterprise cert (though it carries some major restrictions that would make it unsuitable for general distribution). With this they are likely creating something like that enterprise cert but for all app developers.
There is a great tool to increase security: the browser and its sandbox. You don't need to install anything fishy on your phone, and the sandbox rights coukd be sufficient for many apps.
But as an example, Apple denies the full screen feature for websites and even PWA... only installed ones. There's no good reason except favoring apps/appstore. For security? Works great on Android.
And you cannot use a third party browser, since they forbid that (all are Safari based)
Thank you, EU!!
I think this has turned out to be the current barrier in preventing Google from completing taking over the web standards space.
And then when they do implement similar browser standards, they don't follow any web standards, they instead make their own proprietary bespoke web standard for Safari[1].
And they also did other fun things like wait until nearly 2021 to support WebP and let Safari be the the #1 source of one-click exploits on iOS.
It's weird to see Safari trotted out in defense of web standards of all things.
[1] https://developer.apple.com/notifications/safari-push-notifi...
The commenter was not even saying that their point justifies Safari being the only browser engine available on iOS. They were making a specific point. If you don’t want to talk to that point, maybe try another thread.
No matter what Apple itself does Safari being major non-Chromium browser helps Firefox a lot just by existing and having huge marketshare.
How does Apple releasing proprietary web standards just for Safari, like Safari Push Notifications, help in anyway with the purported problem of companies stamping out web standards without consensus? It seems like it's only a problem when Google does it, but when Apple does it, it's Safari "helping Firefox just exist".
And so I will be looking forward to the magical era of PWAs replacing all mobile applications because clearly push notifications was what was holding them back all these years.
Even though a tiny fraction of mobile apps use them but I guess we will ignore that.
Oh, definitely. But if they do (and don't at least give me a way to immediately opt out of that) the app is gone from my phone – and they have no other way of reaching me. Beats the absolute nightmare that is SMS notifications and spam, in my view.
Are you saying that Android has third party filters that surveil all your notifications in the name of blocking ones you might not want to see?
He was right and still is. Not that it's impossible to implement a good PWA, all you have to do is manage your state and interface in a way that no interaction takes longer than 50ms to compute. But most developers are not able to deliver than, most don't even think about UIs in this sort of way.
And V8 GC behaviour is still terrible and an unbelievable battery hog.
In June 2020, Apple declared a bunch of APIs they will not implement (https://www.zdnet.com/article/apple-declined-to-implement-16...), in a big press blitz trying to make it look like they were some noble hero. Web MIDI (incredible fun), Web USB (very useful for Arduino using folk for example, who have excellent web-based tools), Magnetometer/Ambient Light/Battery/Proximity sensors, WebHID, Device Memory, and that's just the half. A week latter Mozilla put out a similar PR using the exact same Fear Uncertainty and Doubt (FUD) to try to make themselves look good, to declare themselves virtuous non-implementors.
Sure, I agree, not every site should have access to these sensors/capabilities. There are privacy risks of turning them on. But they're also excellent capabilities, that really help users do interesting things. Making users use less-secure less-sandboxed native apps is a downgrade. There should be some security regimes where these web techs can be permitted.
For a while Mozilla wasn't even reviewing a sizable chunk of web standards (tracked via the excellent https://mozilla.github.io/standards-positions/), just declaring them unsafe & leaving the convo. They've at least started going back to old Request for Positions & reviewing a good number of them, even if they don't intend to implement. And there's a good number of standards they have about-faced on, have accepted as real asks. In general, I'm encouraged in seeing a much more interested & engaged & progressive Mozilla emerge quite recently, within the past year or so.
I don't know what to do about web standards. Google takes a lot of flak, but who is there to work with? Edge, a Chromium fork, has some pro-web attitude, and indeed drives some new features for Chromium & participates. But there's largely no one but Google+Edge to deal with left in the web standards implementer world. The other browser vendors are broadly against a lot of features, for reasons of malicious-self-interest. Meanwhile Chrome continues to have one of the most open, progressive, interactive, review-seeking, concensus-desiring, most mature & responsible feature-lifecycle processes the world has ever seen. There is nothing else on the planet that gets shipped with such a high bar, such a socially pro-active, such a well planned & democratic process for how the feature gets developed. It's the gold standard of standards. https://www.chromium.org/blink/launching-features/#launch-pr...
Really? I believe that they want to control the web.
Which of these Standards do you think Google will use to "control the web"? https://mozilla.github.io/standards-positions/
There's been an unmitigated use of Fear Uncertainty & Doubt, played with great effectiveness, against the top player. People keep ascribing to Google the role of platform-controller, like literally everyone else in history has done: IBM, Apple, Microsoft, all of which have used OSes to maintain control & dominance. Google is a search engine; they benefit from a rich healthy powerful competitive web. If Google did have "control" over the web, what would they do? What's the evil mastermind plan here?
Everything Google does goes through the Technical Architecture Group (TAG) and Security review. It's all open process. The checks are very real; even if no one can prevent them from implementing it would look very bad to disregard feedback, and thusfar they have not. Thusfar there seem to be extremely few examples of actual real scary things done. Web MIDI shipping without permissions was the most "egg on face" thing Google's done, and I have a hard time interpreting that as malicious. It has the hallmark of naively hopeful to me, and was easy enough to address.
The desire to see the browser teams as the enemy, as a foe, is a greatly harmful & reductive and alas popular outlook in my view. I don't think it's warranted, I don't think there's real evidence for it, and I stress again, Google has so far set the gold-standard for web standards accountability. They wouldn't have done that, they wouldn't continue that process, if they wanted to take control. The case here for taking-over seems absurd, has no clear outcome & only risk. Taking control is an existential risk, would jeopardize the web's success, could easily kill the Golden Goose that has made Google so wealthy & wise. People's fear here does not make business sense.
Might be they'll replace actual websites with Google own version to keep people in Google controlled ecosystem?
Or change APIs in their own nearly-monopolistic browser to make ad-blockers less efficient?
Or not implement extensions in their own browser so there are no ad-blockers at all?
Or push their user tracking system disguised as solution to increase privacy?
Or degrade quality of Google services when using competeting browsers?
This just shows that you don't understand AMP. Apple News replaces websites with only Apple News. AMP allows anybody to host the article.
> Or change APIs in their own nearly-monopolistic browser to make ad-blockers less efficient.
Only one browser has done this so far. It's Safari.
Google might not be a good actor, but trading it for a worse actor who won't let you use any other web clients is just cutting off your nose to spite your face.
Google has been putting profit over users’ best interests for a very long time now.
Make money? That's what companies do. When they get too big and too powerful (at the point where governments don't really have serious leverage over them), a third-party should probably split them.
> Taking control is an existential risk
Why do you think big companies open source code? To help humanity? If Android (AOSP) was not open source, OEMs would probably not take the risk of depending on it. But the Play Services are there for the lock-in. Protobuf being open source is better for Google than having to integrate with other systems out there. Why is Chromium open source? Well most "alternative" browsers are based on it, and Google controls it. And so on. Open sourcing code is a strategic decision. And the strategic decisions in a company are there to make more money, not to help the world. It's all about control.
> What I see is a lot of very sincere dedicated engineers coming up with helpful & rich ideas.
Sure. Because you work for Evil Corp does not mean you are not sincere and dedicated. Many good people work for Philip Morris, for many reason (maybe they have an interesting job, maybe good conditions, whatever the reason). The difference with Google is that most Philip Morris employees probably realize that their company is not a non-profit aiming at making the world a better place.
They did support me in Google Summer of Code before that (2005). I believe they gave me $5000 for the summer. I am still working to ship open source software pursuant to those ends, on my own personal time, to this day.
[Citation needed]
> Magnetometer/Ambient Light/Battery/Proximity sensors [...] Device Memory,
I don't have words to describe what a shockingly bad idea this is.
> A week latter Mozilla put out a similar PR using the exact same Fear Uncertainty and Doubt (FUD) to try to make themselves look good, to declare themselves virtuous non-implementors.
Maybe because it's a really fucking stupid idea, and the criticism of those APIs is not FUD.
Web Extensions for an example have all been pushed into stores for auditing purposes, because otherwise their functionality can and has changed via automatic updates, going from useful functionality to horrible privacy trainwrecks.
> Sure, I agree, not every site should have access to these sensors/capabilities. There are privacy risks of turning them on. But they're also excellent capabilities, that really help users do interesting things.
Sure, but they are still harmful. For instance, there is no body that says which websites are allowed to manage USB because they are Arduino Maker sites dispatching firmwares, and which ones are not allowed to because they'll attempt to zero day some mobile phone OS while it charges. And there is no technical protection against the former site suddenly becoming the latter via acquisition or exploit.
This is why the native app security and privacy models are fundamentally different from the web models - a store can require entry into a private contract by a real-world entity who is accountable (potentially criminally), of software under audit control.
Websites can be by random people outside any legal accountability.
On iOS, one of the major differences is that there is no expectation that people will doing ongoing management of granted permissions to a website. For this reason, things like geolocation access have to be re-granted periodically. This is also a reason why push notifications (as a more durable permission) require the PWA to be "promoted" to an app on the Home Screen on iOS.
That is incorrect because Apple has prevented and still prevents Firefox from properly implementing Gecko on iOS. Apple also restricts Firefox and browsers other than Safari from implementing full WebExtensions. Even though Firefox and browsers other than Safari are required to use WebKit on iOS, they are not allowed to access many of WebKit's iOS-integrated features including content blockers and Safari extensions.
All of these Apple-imposed handicaps make Firefox a much less competitive browser on iOS than it could be, and in no way helps Firefox because users generally prefer to use the same browser across their devices. The EU's upcoming browser choice legislation will prohibit Apple's anticompetitive restrictions to put Firefox on a more level playing field with Safari on iOS.
newsflash: many users hate pwa, they prefer native apps
I hate PWAs because I like good native apps, and PWAs give an opportunity for developers to replace their native app with a cross-platform web app. And in my experience, cross-platform generally comes at the cost of app quality on a single platform. Instead of hiring developers who know iOS, you now hire web developers who debug their web app on many platforms they don't really know well.
It's also ironic to bring up Apple's hindering of web standards as evidence of anti-monopolization of standards, considering the fact that the lack of PWA support forces users to use the proprietary App Store monopoly to install apps instead.
IMHO, that's very naive. Look at ElectronJS apps. I hate ElectronJS, still the most used apps on my Desktop computer are ElectronJS. Why? Because I don't have a choice, because it's cheaper for the developers.
Before ElectronJS, I actually had real desktop apps. So yeah, I see the case against PWAs.
Then you should support PWA as an alternative. It's lighter weight, both lower memory and download size, compared to electron.
PWAs would be cheaper to develop overall than building 2-3 separate code bases. Which would mean more software available generally, particularly from bootstrapped companies.
I don't think anyone is suggesting that native go away.
But that's my point: that's exactly the promise of every single cross-platform system out there. But in my experience, that's generally not true for non-trivial apps (ever heard "write once, debug everywhere"?). And second, it usually makes for worse UX on all platforms.
I feel like many people consider PWAs as a totally new thing, but at the end of the day, it's a cross-platform system. There are tons of those; just look around, cross-platform is not a silver bullet.
Every non web cross platform system doesn't have nearly the investment as browsers do for quality and compatibility. It's not even close. Like, orders of magnitude. I don't like the cross platform toolkits either.
Let's not pretend the web as a platform is the same m'kay? People use it every day from all of these devices, like billions of people. This isn't some unknown, where this speculation is reasonable either. There are issues, but it's not equivalent.
And that's most certainly because Apple enforces more UX consistency on iOS apps.
Until the issue is fixed and the goal posts are moved once again.
Because PWAs have been available in one form or another for 14 years.
And it's always because that the UX is terrible that makes them not viable not anything Apple has done.
Obvious counter points.
Lots of people use websites. Which have an identical UX experience to PWAs.
A significant percentage of the app store is web view based apps that are near equivalents to PWAs. Been that way for years.
If people love native so much, why do sites like Reddit and LinkedIn heavily push mobile web users to the app? Seems it's not a universal opinion.
Because that's how sites can avoid the privacy features that are inherent to browsers.
What proportion of visitors to the LinkedIn site use the app? I'm guessing it's pretty small.
For people who just want the best possible app/phone experiences, PWAs are awful.
The real differentiator with native vs pwa is their ability to track the user.
Heavens no. I do not want to be forced to install an app for every single little thing - it's wasteful, detrimental to my security and privacy. Small examples from a recent trip: in Andalusia, there's a bunch of cities with very interesting old buildings (cathedrals, castles remaining from the Muslim era converted by the Spanish monarchs later on, etc.). Each and every one has a different app for their audio guide, map, etc. to help you navigate and understand them. It's just stupid, it's a one time thing and it could easily be served by a website; instead you have to download a 30-40 MB app for each one, and then remember to delete it afterwards.
I don't know if this is substantially true. When I hear of PWA features that people complain about, they are almost always things that Google Chrome as its own app with its own web engine can't add to the underlying OS, such as:
- robust background processing
- background push notifications
- new video codecs (on a power-constrained device)
- system-wide protocol handlers
- web bluetooth/webUSB/webNFC
- adding their own new synthetic "app" representing the PWA to the Home Screen.
Many of the things people talk about with PWAs are not anything close to a web "standard" or even a recommendation - Google implemented them, because they were pressured internally to make a web-based programming environment for Chromebooks.
> [1] https://developer.apple.com/notifications/safari-push-notifi...
Both macOS and iOS have honest-to-goodness push notification support now.
"I used the monopoly to destroy the monopoly."
Actually I believe you're wrong: if people actually preferred Apple's way of doing it, Apple would have no reason to restrict other ways.
They restrict it because people prefer the other way, and that would harm Apple's profits.
You're saying this like there isn't any trash on the Apple App Store? Come on... Beyond the top lists or other discovery models, the Apple App Store contains bunch of things that will never even be downloaded by anyone...
It was more exclusive in the beginning, I give you that. But today, it has as much trash as any other app store.
And that's one of the values of Apple: this vertical integration that makes the overall thing look more polished (and probably easier to use to some extent).
Of course, they are happy to keep the restriction because they can take 30% commission on the paid apps, I'm not saying they are perfect and that there is nothing to improve. But I am not completely convinced that forcing them to lower their standards of integration (by allowing any kind of apps) is necessarily beneficial for the users.
After all, why do developers want PWAs? Probably mostly because it is cheaper for them, not because it's better for their users, right?
Wrong, PWAs can provide better services for users, and the lack of PWAs and enforcement of the App Store monopoly can hurt them[1]:
> The fact that Apple refuses to implement basic features in mobile Safari that Firefox and Chrome have had for years now, and the fact that they refuse to allow other browser engines on iOS is the reason why we can't have nice things like progressive web apps.
> I recently worked on a health app related to the COVID pandemic. The most common use case would be served really well by a PWA, and as such, there's no reason users would need to install an app on their phones to access the web app's full set of features.
> Despite the web app working perfectly on Android and across Windows, Linux and macOS without native integration, we now must dedicate time and resources to develop an additional iOS app just so iOS users, which over half of Americans are, aren't left out.
> This is an expensive endeavor time-wise and money-wise, during a pandemic where time is of the essence and resources are stretched thin. It shouldn't be this way, but it is.
Seems like you do confirm my points.
I am not saying that users can never benefit from PWAs. I am saying that globally, I am not convinced that PWAs will improve the life of iOS users. Just like I don't feel like Electron is improving my life. Slack would maybe have to make a proper app if they did not have Electron, it's not like Salesforce doesn't have the money. I could even go further: if it was actually expensive for such companies to write apps for the platforms they need to support, maybe they would open their APIs. Slack/Discord are glorified IRC messengers, I would love to have a lightweight client to use them (instead of getting a full copy of Chromium for each).
A yet there are a ton of low effort and literal fart apps on the App Store[1].
They don’t even see difference between PWA and apps.
If everything becomes PWA, there is no transparency for the apps. No indication what data they collect. No control for the quality of the apps. No moderation over malicious apps.
PWAs need more permissions to provide the functionality people need, it is not just website.
The point is the experience, not the name of it.
The problem with statements like that, aside from the loftiness, is that you end up with a world where people who think they know better get to decide. I worked in the public sector digitalisation, and while I’m a programmer we were bundled with the rest of IT so I experienced what the supporters had to deal with. This included a lot of employees who genuinely couldn’t tell if the device they needed help for was an iOS or Android device without some guidance. So I’m not going to dispute the claims you make about how it’s nice to protect the “average person” from themselves, but I don’t think any of us will like the what that sort of thinking creates. Well, maybe some people will, but a lot won’t.
I recently wanted something for my two-factor keys and the best all I could find was for Android but not iOS. I ended up filming over a few $ for a Bitwarden subscription, but there are just a lot of little stories like that. I mean, I’m not in the audience for Fortnite, but I’m sure a lot of people were sad when it left iOS. A of which can be avoided if we stop giving all the power to the tech companies.
I’m not sure Apple really has anything to fear from it either in terms of security or usability. Part of the reason they sell so well, at least to me, is that they have the ease of use and tech that works out of the box. It’s very rare that I need side loading. I’m not a huge fan of the Safari enforcement, but it doesn’t really bother me either as I can still use FireFox and the sync. I think Google might have more to fear from it, since they need to peddle commercials inside apps like YouTube, and you can block that if they allow you to side-load app blockers, but for Apple I think almost everyone will just keep on trucking. It will of course hurt their control over payments, like the original poster points out, but that’s not really “my” or the “average persons” problem.
Sideloading will hit hard for Apple's pro-privacy brand.
You lose transparency and quality control for the apps. They don't need to tell you about their data collection practices. They don't have to do actually anything at all, since you can't ban those apps anymore.
Phishing is still a problem of Android and that will become a problem on iOS too. On Android there is still business for anti-virus engines because of the sideloading and Phishing. On Apple devices, there isn't really need for anti-virus but it will become relevant again.
If the sideloading will become very easy, big players who make money with data collection, will leave the platform. You won't find Meta apps soon from the App store. They are so big that people will download these apps regardless.
If that happens, how many fake Instagram apps we will see after that? And you can't ban them from the App store anymore.
So it appears the non-average person doesn't have a clue what's right for the clueless masses either.
Liberty, choice, community and respect. That's all that is needed.
Respect, as you say, is important. Leaf by example.
I was referring into technical implementations and what risks are included. It requires deep undertanding how these things work. Average user does not have it. Many aspects are invisible to the end-users, like the war against malware in App Store.
The end-user knows what they want in terms of end-result. How to to get the job done with a tool (app). They can compare end-results.
Sometimes, however not all results all there to be compared. Because, they don’t understand what kind of tools can be actually created. They are happy with the current one because they think it is the best what can be.
Or, what else the tool can do besides their advertised functionality. Which can be malicious or harmful to user in another way.
Or tools could work in a better way, but are currently hindered for monetary gain.
All this requires specialised knowledge.
If PWA is cheaper to make, companies will go there. Whether or not it's better for the users. Companies want to make money, not help users.
Yea but Apple is a company too…
If I don't like PWAs but WhatsApp stops supporting anything else, how can I use WhatsApp without the PWA?
What would be great would be for them to have some kind of API to let people write their own clients. Maybe there are big downsides with that (Loss of control? Having to keep backward compatibility?) but I don't really see them.
Apple is the market here. If people wants to have PWAs they do not buy Apple products.
But in reality "the market decide" is not common sense - that is why we have regulations.
On the other side, if users want standard UI and that's a factor in adoption, wouldn't people making PWAs then just make the apps in such a way - there's nothing stopping them, and there's no lack of UI libraries enabling that.
I'd say look at popular cross-platform frameworks, and tell me if you think that cross-platform apps generally look native. I don't.
It should be my choice
Nobody, least of all oneself, knows what one wants (except in the moment; I want some peanuts) so we have to be told. And you certainly do have a choice, so long as it’s the right one.
You have a choice, if you don’t like it buy an Android phone. Or a Sailfish phone, or a KDE phone our one of the other open source phones where the only “apps” are low quality PWA crap. Look how successful they are.
Do you think that's because of PWA UX being inherently crappy and not, say, the fact that those projects don't have billion (or trillion) USD companies behind them? I think you're mistaking the effect for the cause.
PWAs are a way of lowering the barrier of entry for new devs and that's important if you want to achieve any scale.
> You have a choice
It's kind of a like a thug saying that I have a choice between being slapped in the face, kicked in the butt or subscribing to his Twilight fanfic podcast. Yes, I do have a choice, but neither of the choices is really something I'm looking forward to. Betamax vs. VHS comes to mind too.
I think the line of thinking in the parent comment is a bit naive. There's nothing inherently wrong with PWAs from the UX pov if we take monopolies and FUD into account. That's the reason it is harder to build a PWA with really good UX now (harder but not impossible).
A bad native app can require the gps permission, but a bad PWA app will be able to do the same, right?
I really don't think that sandboxing is a good argument in favour of PWAs, honestly.
Gaming on mobile friggen sucks and that is primarily because Apple wants to retain control and the biggest piece of the pie.
Gaming in mobile browsers, in 2023, should be as easily accessible as it were in desktop browser in the Flash days. Apple just won’t come to the table to facilitate a decent gaming experience in Safari.
Let’s also not forget Steve Jobs was all for web standards in his letter against Flash. Apple should make good on what was promised in that letter instead of dragging their feet.
https://newslang.ch/wp-content/uploads/2022/06/Thoughts-on-F...
UX isn’t half bad either. It actually feels pretty native most of the time.
Even on your run-off-the-mill desktop web browser, push notifications do not come “for free”. You need a service worker. You need a specific server implementation. It’s not just the Notification API.
(Plus I don't want to actually deal with full Outlook because I have zero interest in accessing my work mail privately, whereas I do need to take a look at my work calendar in order to avoid accidentally double-booking myself.)
It doesn't need Apple to white Knight on behalf of their poor, dim, uninformed users.
Because they're not.
A lot of viruses (and jailbreaks on iOS amongst others) are distributed via this browser / sandbox; it's only secure in theory and it took decades to get to that point.
Sure (before the Rust evangelists swoop in), part of that was due to using unsafe languages; part was due to extension frameworks that had too much power (ActiveX, which was even used to update your operating system, I can't fathom why they thought that was a good idea). But it'll take many more years of zero incidents, jailbreaks, etc before I'd trust the browser over Apple's app sandboxing and app review and distribution approach.
Chrome and Firefox are as secure as Safari, if not more, banning them is a commercial choice not a technical one.
iOS exploits still exist, there's no real advantage in Apple sandboxing apps, they are routinely leaking users data and being exploited as well.
OTOH Apple refusing to implement certain web standards is proof that they cannot guarantee a safe implementation, which is a reason more to allow better browsers on their platform.
This Apple native crud they force every app to use (up to the whole browser engine, like in the IE days!) is truly the ActiveX of our times. Only you can't even get rid of it.
You can exploit in both native and browser contexts. Most jailbreaks nowadays are assisted by a native application that you dev-sign to deliberately pwn yourself with. In the past we had websites that you could use to jailbreak with. Both are sandboxed environments with significant attackable surface area, so one is not necessarily more trustworthy than the other purely on measures of exploitability.
I think this plan will move forward because of consumer protections afforded in the EU (ie including sideloaded apps) not available elsewhere.
See the Xbox Cloud Gaming "app" for instance, which is outside the App Store, just launch then "Add to Home Screen", close, and run from Home Screen.
https://www.xbox.com/en-us/play
As for what can be done with browsers, see the venerable iCab but also Kagi's Orion browser which runs Firefox and Chrome extensions, even on iOS. Yes, it's WebKit based, but so was Chrome for a long time.
https://help.kagi.com/orion/browser-extensions/macos-extensi...
Given you can run Xbox games or arbitrary extensions from other browsers, it's clear the web app and WebKit limits are less restrictive than most discussion acknowledges.
For the last few features that used to be missing, like notifications or other native hooks, notice Microsoft has the sidecar native app for iOS that handles in-game chat, LAN discovery for Xbox setup, and notifications.
You and the OP are both right about fullscreen. There is a web fullscreen API, which Apple does not support. However, PWAs strip out the browser UI so you’re effectively fullscreen. Though you can’t do anything about the status bar, nor can you lock screen orientation.
But more to the original point, none of this has anything to do with security. Apple disallowed a native Xbox streaming app because they demanded a cut of the revenue and MS wasn’t willing to give it.
When home screen apps first came out we built some for clients and if I recall correctly, lack of browser UI was default.
(it actually isn’t by default, it requires specific flag, but it’s more or less what everyone considers to be a standard for PWAs)
It's the same with privacy. Forcing app publishers to state what user data is being sucked out of their phones was just a poor PR stunt.
Nothing has changed. Applications still require payments in form of contact lists (which is more or less illegal in Europe if you don't have permission of all people in your address book to share their names and phone numbers), disguised as helping users check if their friends are using a service, or to even allow user to use some app functionality.
Unimaginative accountant that currently leads Apple on one hand bullshits public opinion when disallowing Facebook to steal data from users' devices and, on the other hand, after blocking Zuckerberg's ability to do so, he disgracefully used children protection to announce that Apple will now inspect users' data under the pretense of looking for child porn.
Apple users are being deprived of OS control with most of updates and it's always done under the untruthful pretense of increasing security or protecting users' privacy.
When this little man finally pushes ads to core macOS, he'll state that it's to help users.
> Nothing has changed. Applications still require payments in form of contact lists
This is actually proof that users don’t make good choices when it comes to privacy and security even when they have the necessary information.
On the other hand, there's little non privacy-invasive apps of certain types and corporations make good use of users' inability to pick lesser evil.
App Store helps them a lot, too, because to see what invasive practices developer/publisher uses, one has to click on app title to see details, while having a very comfortable "GET" button as the only button and only thing that looks clickable on the list.
Cook's typical smoke and mirrors approach.
That’s an argument for stricter store policies, not eliminating the store.
What? It seems like you were trying to make a coherent argument but a list of contacts is in no way comparable to a paid subscription. Microsoft doesn't allow you to buy O365 with your contacts, do they?
[source needed] as GDPR doesn't apply to private individuals and private databases
To this day the browser is still a second-tier experience to native apps. But that's fine, because anything you get from the macOS and iOS app stores are sandboxed too. So are non-App Store apps on macOS that choose to run in sandbox.
However, they then bizarrely and deliberately refuse to actually police the store, to an alarming and almost cartooninsh level. We’ve seen this time and time again: scan apps remain on the store for months despite being reported. Take just last month when fake Authenticator apps flooded the AppStore to take advantage of Twitter getting rid of mobile phone based 2FA, and not only were those apps allowed on the store, but often managed to get top recommendation.
At least on the web the expectation is that it’s the wild west and you should be careful what you install. On the AppStore it’s as if Apple has purposefully invested effort into creating the perfect mark for von artists: convincing their customers that a shark infested pool is totally safe to swim in.
And this is the undeniably bad stuff, it doesn’t even touch on the “grey area” of these disgusting children’s casino apps that dominate the AppStore, and that Apple shares the profit on to the tune of 15-30%. The incentives are all broken. Apple profits when scam apps buy ad-placement using real apps names for keywords. Apple profits from apps that convince kids to buy garbage IAP.
It would be one thing if the AppStore actually lived up to its supposed principles, at the cost of hurting competition, innovation, and the occasional frustrating developer rejection. There’s actually be a trade-off to discuss, and we’d actually be arguing about principles, and whether safety matters vs. freedom blah blah blah. Hell, as a parent, there’s versions of a well managed AppStore that I’d probably begrudgingly accept.there be a “can’t argue with the results” thinking there.
But that’s not what this is, and I’m tired of pretending toy is in arguments that defend the AppStore. It’s been 15 years, the AppStore isn’t in beta, it’s not “a work in progress”, there’s no room for arguing about its vision vs it’s “current” reality. The AppStore has shown us what it actually is: a supremely lazy and un creative business cudgel that serves neither developers nor customers, and instead serves Apple first and ironically Apple competitors and criminals second. How does it serve Apple competitors you ask? Consider that companies like Amazon are offered special AppStore rates. Little developers don’t get that, big companies do. So not only does the AppStore exhibit monopolistic behavior, it also props up other monopolies.
Also, the search sucks and it’s ugly. It feels like a free samples booth at a Costco. No one at Apple has any taste anymore. Not really relevant to the argument, but just want to point out there’s zero to be proud of in that product.
Their motivation is most definitely money now. Maybe not in the start though. Whatever their motives are though I’m super satisfied as a customer that they haven’t went down the android path of version calamity, an app store that I have zero trust in as an app buyer. Also tell me an android flavor the supports devices purchased 6 years ago? It’s a package deal. Having the wealth that is generated by the things that the EU has mandated will cause cuts in other areas of device support and/r&d. The option is making less profit or bumping prices to offset. In time we will see.
I think it would be great of Apple to just stop selling devices in the EU as a thanks to politicians who voted for this ill advised rule. I’d like to see how long it would take for them to roll it back because you know they would eventually buckle to the people.
To you and those of like thinking just assert your freedom of choice and go buy an android device along with the shit show it is and leave us to our relatively safe walled garden.
wait, so it wasn't money before? when they ran all those ads and did all of that 'we're the only privacy company' marketing? i guess it worked really well. when some of it was kinda just, reframing of lacking features and capabilities, and their 'closed ecosystem/walled garden' structure, as 'more secure'.
If you don’t like IOS in it’s current form don’t buy it but don’t knowingly buy it knowing it’s not what you want. Don’t be the noisy spoiled 1% of our society and try and make the rest conform to your ideals. Go choose something else to ruin.
If enough consumers vote with their wallet Apple will take notice. In this case that is the correct way to pursue change.
I'm not sure how they are motivated but in a report Apple cited:
>In Nokia’s 2021 threat intelligence report, Android devices made up 50.31% of all infected devices, followed by Windows devices at 23.1%, and macOS devices at 9.2%. iOS devices made up a percentage so small as to not even be singled out, being instead bucketed into “other”.
I personally use iOS and got it for my mum and aunt etc as it seems to suffer much less from malware in normal usage. I'm not sure if there is any evidence to the contrary?
Genuinely looking for evidence of this counterpoint you're making. As the evidence for the security angle is proven. iOS takes less than 1% of malware, Android takes nearly 50%, in between we have Windows, IoT devices and even MacOS taking more malware than iOS.
So where's the data that this strategy isn't working to protect iOS devices? I want to see it.
IMO, https://zerodium.com/program.html is a good indication of "what would it cost to hack me using a never-before-seen exploit".
It's not a technical change in who distributes the software, it's a radical change that results in developers being able to give apps to users without being in a contractual relationship with Apple period.
The sideloading of apps will technically be an apple approved app but enforced by another app store. To put it another way you would not be able to randomly download an unsigned app.
European DPAs aren't getting enough funding to take on this problem, but they haven't been sitting still either.
I assume this was how it was intended to function, but the kind people that run internet websites intentionally made it more difficult.
Lots of smaller players still do it, though, so maybe this is not the most effective enforcement style.
While possible, it should be more rare. When working on massive platforms it is typically the goal to minimize metrics like malware installs as opposed to trying to make them 0. The relative probabilities are important.
Compared to an antivirus (macos, windows, android, all have protection built-in), that could detect a malicious app, or receive a report about a malicious app and then block it from being run, having an app store in the chain might not even be that much help or be at all different in that process.
If anything, giving potential malware apps a chance to be published on an app store, get that scale, visibility and access to an audience outright, and hang there even if for a little bit before getting taken down, could be kinda worse than if malware apps were distributed across smaller venues. Where, through what channel could a malware app get access to biggest amount of people? Through a centralized app store. (especially if it's the only one on the platform, and the only way to install apps*, forcing all users of the platform to be there.) An app store gives potential malware makers access to an existing audience, ready to be exploited, and a centralized app store ensures that it's the biggest audience possible.
(yes yes this is satire)
A few years ago this was an issue, when millions of macOS users found that they couldn't launch any apps at all on their Macs, because Apple's OCSP servers were down[1].
Of course if one's smart enough to only download apps from reputable websites, then the only worry will be privacy issues which are probably not important for most people
Properly stated this story title is, "Installing applications on iOS 17 might be allowed Europe" which highlights the absurdity intrinsic in the practice of users not being able to install applications on their own computers as a default.
If security really mattered, every OS would run applications in a proper sandbox, but why bother with that when you can just point your Web browser at a program running on someone else's server? Oh, but consent to these tracking cookies first.
The huge difference is that's only a warning, and not a cryptographically locked-down system unlike Apple's.
And for most users that security warning is as good as a cryptographic lockdown anyways.
On the other hand, I find it ironic how a lot of "security professionals" will complain constantly about users accepting security warnings with no thought anyway (and they usually use this argument to justify their increasingly authoritarian measures of controlling them.)
Apple does the same thing with Notarization and Gatekeeper on macOS. If they choose to revoke your signing certificate, Gatekeeper will prevent your software from running on macOS.
That means if you do, say or compete with something that Microsoft or Apple doesn't like, they can prevent your apps from running on their platforms.
A generic answer to your question is that the software was signed by whoever compiled or distributed the software, which can include your own machine. Your own key might be in your trust store or your app distribution method might put their key in your trust store. Both macOS and Windows will treat software compiled on the same system it is run on as blessed to run without strict signing checks.
On macOS, ad-hoc certificates can be used, but the OS will treat those binaries as if they're radioactive. If you compiled code on macOS, the system will treat that software specially on that specific system and allow you to run it[1]. On Windows, certificates can be added to trust stores. Chocolatey, for example, has their own signing certificate for all of the compiled open source software they have in their repositories, so Windows allows their software to run.
The biggest issue is what comes with software distribution itself, where your code isn't blessed by default by the system it was compiled on, or doesn't have signing certificates in the users' trust stores, and Gatekeeper and Windows Defender go out of their way to stop your users from running software with signing certificates they don't like.
Every browser I know uses the Mark of the Web to tell Windows that a file came from the internet. You'll have to store the file on a FAT32/exFAT drive to get rid of it. If a file comes from the internet, smart screen kicks in.
When a file is unsigned, smartscreen essentially prevents you from running the file. You can work around it, but I had to look up a tutorial myself.
If the file is signed, metadata will be extracted and submitted to Microsoft. If that fails or the exact binary hasn't been run on a certain amount of computers, smart screen will show a big scary warning despite your $500 a year digital signing certificate. This is something developers just have to deal with every time they update their applications, but most people won't be the first x to download the executable and applications using auto updaters download updated in the background can the necessary flags to work around smartscreen.
The restrictions are there, but they're not there for (most) development environments and for most users of popular software.
This is true and annoying, but only with regular certificates. The more expensive EV certificates bypass this “well known” check.
I learned long ago, and keep it clearly in my mind, that what AV considers "malware" and what the user considers malware are not entirely the same.
and if clearly false could be used in court.
I do wonder if Windows becoming adware, but then the built-in antimalware detecting possible "competitors'" adware and removing it, could be challenged in court as anticompetitive behaviour.
You, personally, can turn off Windows Defender, but your users probably have no idea why the app they're trying to run doesn't work when they double click it. They're also probably shown multiple scary warnings that discourage them from using the app and trick them into thinking it's broken or malicious.
It's a hurdle just to convince users such an app isn't malware, and then it's an entirely other hurdle to help them actually run the software by bypassing Defender.
Are there examples of Microsoft actually doing that?
Ability to prevent known malware from being run in the majority of PCs after detection seems like a useful feature from the Internet health point of view.
iOS has a full sandbox which would apply even to "side loaded" applications, which makes the arbitrary constraint even more ridiculous as a "for your own good" measure.
these OSes were designed decades ago, before we really had a good grasp on security. there were other significant concerns as well, such as performance
also, modern OS toolkits, such as on macos and windows 11, are moving towards a permission and API model that will allow sandboxing. In fact, macos is moving quite quickly towards this.
And lastly, there is a widely deployed OS that runs all applications in a proper sandbox: chromeos
I think it's understood at this point by everyone in the industry that sandboxing is the future, but it's taking a while to get there.
Not just that, but before we realised just how many people there would be trying to claw their way into any gap for all manner of dark purposes.
Early networked OS and protocol designers thought that people would, largely, cooperate with each other and share resources for the greater good.
I wish to live in their naively optimistic future, instead of the one with real humans :/
They realized that they need to change the platform for distribution, and hence this is why the web (post-chromium) is now what it is...with all its absurd redundancies of APIs and bloat.
Only because Microsoft can't keep their shit together.
Apple is more complicated, because despite the absolute control they've established (no other browser engine / JIT compiler process allowed for whatever made up reasons) they did not face the European courts that forced Microsoft for the exact same thing to allow to install other Browsers.
And now we are stuck with Safari, repeating the loop, because Apple can't keep their shit together.
It really wasn't. It wasn't normal to install arbitrary applications on the computers in your fridge, dishwasher, game consoles, flip phones, washing machines, etc. Platforms have varied over time in how open they are to having other people developing for them. iOS is an example of a more closed platform and has shown that closed platforms can be successful. You can see Windows as a more open platform in comparison which was also successful. How open a platform is comes with different trade offs.
For example, a smartphone replaces a PC for a lot of people. I even know some people in their 20s that don't own a "normal" laptop/desktop and they do most of their general purpose computing on their phones. In the meantime, nobody uses a Nintendo Switch or their dishwasher to do a quick edit of an excel sheet or access their bank account even if they are technically capable of doing so.
It is successful despite being closed, not because of it.
First search in Google.
https://source.sheridancollege.ca/cgi/viewcontent.cgi?articl...
Also, from my own discussion over the years with different people, security topic popped up only when iOS fans tried to diss Android users.
It does mention that "perceived security" was a factor.
It's trivial to get something past app review (eg. look at casino apps that were disguised as games)
On the Mac, staying on the Mac App Store makes sense because it is the easiest way to enforce you only install sandboxed apps.
On iOS, that's not going to be necessary, because every app on iOS is sandboxed.
As an aside, I do believe you can use sandboxd with apps outside of the App Store, someone just has to write security policies for them.
This page suggests that Apple might want to deprecate use of sandboxd in favor of just the App Store[1], though.
Yes, you can, it's trivial to do so. However, Apple does not make it easy to find out if an app is sandboxed or not, or what permissions it has.
The warning that macOS shows when opening an app not from the Mac App Store does not differentiate between sandboxed and non-sandboxed apps.
When we forgo real system safety in favor of gatekeeping corporate revenue, that isn't security. In fact, such a scheme is responsible for mass distribution of malware. Apple's App Store is responsible for distributing over half a billion copies of Xcodeghost to iPhone and iPad users[1], and that's just one piece of malware.
[1] https://www.vice.com/en/article/n7bbmz/the-fortnite-trial-is...
If apple's billion dollar app distribution monopoly money hose results in security problems for people, then their billion dollar app distribution monopoly money hose will be in jeopardy since it's justification comes into question.
So what you see as a problem is what makes me feel the best about it. Apple is aligned with only secure apps on their store and apple is very unaligned with insecure apps.
To apple security is not just a cost center, but a pillar of the justification for their monopoly position.
Maybe part of it is this security alignment issue, but upon scrutiny it's clearly a small and solvable piece of the puzzle. Imagine if Keurig tried using user safety to justify a 30% cut off every K-cup sold. Such an ecosystem is doomed to fail, especially at-scale and with completely arbitrary enforcement.
I don’t think the world got better because we got more channels on Tv, and I even think some of them might be dangerous and harmful to life…
People like me.
You are literally talking about stealing my money. To me.
And this doesn’t seem strange to you?
Did you ever publish to appstore ? The amount of bullshit you have to go through so that an alternative payment method isn't reachable from mobile is insane, and they want % of a lot of things, not just sales/subscription - a lot of business ideas are unviable because of the policy.
Not to mention that your competitors don't have to pay the same, big players get special deals and exemptions, and Apple has first party advantage on the platform.
Yes.
> The amount of bullshit you have to go through so that an alternative payment method isn't reachable from mobile is insane, and they want % of a lot of things
You say insane, but you don't say why. Revenue-sharing is the best for content producers; I would definitely not want to go back to the retail model. What exactly are you trying to do?
> a lot of business ideas are unviable because of the policy.
A lot of business ideas are unviable without slavery! So what? I don't want that, and I hope you don't either! So what is it you actually want?
> Not to mention that your competitors don't have to pay the same, big players get special deals and exemptions,
I don't compete with "big players". If Apple didn't make an iPhone and I didn't make an app to put on it, I wouldn't get that money, and pretending otherwise won't make it so. The people I am competing with are in the same situation I'm in, and if they're getting success and I'm not, I think I should worry about what I can do.
Did you just compare freedom to choose alternative payment method to slavery? What a bizarre world, I don't know why I've even bothered to reply to your comments, lol.
> I don't compete with "big players". If Apple didn't make an iPhone and I didn't make an app to put on it, I wouldn't get that money, and pretending otherwise won't make it so. The people I am competing with are in the same situation I'm in, and if they're getting success and I'm not, I think I should worry about what I can do.
You're dictators wet dream.
"Don't care about unfair system, dig within yourself! If competitor is doing good under dictatorship it means the problem is within you!"
Not at all. I said some businesses should not be viable and gave the simplest possible example I could think of.
And you did not agree.
Shame on you.
> You're dictators wet dream. "Don't care about unfair system, dig within yourself! If competitor is doing good under dictatorship it means the problem is within you!"
You're still not saying what you want to do and why it is good for society, just that the "dictator" is stopping you from doing it. "Alternative payments" can mean all sorts of things from money laundering to easier-to-steal, and I can't support those things.
There's a Ukrainian saying
> Хрін з ним, що своя хата згоріла, головне у сусіда корова здохла
Which literally translates to "Who cares if house is burnt down, the most important is that neighbors' cow is dead" - that's you. Ever thought that maybe you and/or your comptetitor shouldn't have to pay in the first place or that shares are unfair?
No actually. I won't ever enter any other kind of business-relationship with a larger company unless they have real competition that affects price because my experience is that larger company will try to mess you up if there's any chance at short-term gain. A joint-venture is ideal protection, but with Apple my size makes that unlikely. Revenue-sharing is a fine alternative to me, and if my product becomes worth more than my share I can always renegotiate, even with a big company like Apple, because we both want the revenue to continue. That's the point.
The pure-play alternative is much harder for small companies and individuals because they need cash up-front to get into the market, but I do understand the advantages for big pockets who don't create value though -- I just don't have any intention of being a company so big that my only purpose in life is to group-together smaller companies that aren't good enough to survive on their own.
It only comes under jeopardy, if there are reasonable alternatives the Apple app store (not move to Android).
Otherwise, it's easy for Apple to say - we are now taking step x, y and z, and "trust us".
You are justifying why a monopoly app store is bad by showing a hack that resulted from downloading an app (xcode) from a source other than the app store.
Security firm Palo Alto Networks surmised that because network speeds
were slower in China, developers in the country looked for local
copies of the Apple Xcode development environment, and encountered
altered versions that had been posted on domestic web sites. This
opened the door for the malware to be inserted into high profile apps
used on iOS devices.
I think you are also ignoring that apples app store position made it possible to authoritatively reach out to all who were effected as well as enact other remediation efforts.> I think you are also ignoring that apples app store position made it possible to authoritatively reach out to all who were effected as well as enact other remediation efforts.
Microsoft is able to do the same thing with Windows Defender without using the App Store model at all.
I think the app store is a tool and I think it is a powerful and useful tool. Can the tool be used for good? of course. Can it also be used for bad? most definitely. Can it be wielded poorly? yes.
I've used windows, linux, apple, and android, and I like Apple's environment the best. That environment is a consequence of apples choices. Apple limits my choices and I like that. I like having less choices. I don't want to have to think about software security, I want to think about how to spend time with my friends, and apple is a an environment that lets me think about how best to spend time with friends instead of thinking about software security.
Apple's restriction of my choices benefits me. I want apple to restrict my choices. I want there to be only one way to get apps on my device. That simplifies my life. I will pay more to have a more simple life. I will pay someone else to make better choices than I can make with my limited time. I want to do that.
If you don't like that, then don't use Apple. There is a perfectly working alternative to apple that you can use if you want to experience other choices. Apple has a monopoly on apple devices, but apple by no means has a monopoly on smart phones. I'm not sure there are even any major apps exclusive to apple. Apple is better because apple has more money to spend.
> Microsoft is able to do the same thing with Windows Defender without using the App Store model at all.
If apple scanned the apps I side-loaded and reported information about them to their servers that would upset me, that feels like a privacy violation.
Apple's bullying of companies with monopoly power to force privacy labels won me over greatly. They have a lot of good will for that. If apple continues to do things like that, I will continue to support an app store monopoly.
How does this conflict with other users having a developer mode? Because you want Apple to have more unilateral authority over what other businesses are and aren't allowed to do?
It sounds like you have left the domain of "what's right for the market" and headed into the realm of "what I prefer". That's fine and decent anecdata, but completely useless to regulators who's job is to save the market. If Apple is stifling innovation or competition, even for a good cause, then we must codify the goodness and end the monopoly. That's progress, arbitrary corporate grudges are not.
If you like Apple telling you what to do, fine. Choose only from their menu.
Apple products are the consequences of Apples decisions, you want what Apple produces but reject their decisions.
What if Apple's phone is better because it is a closed ecosystem?
But not for a lack of trying. Windows has tried to retrofit their App Store, just less successfully. One good example is the code signing racket, where it’s pay to play to avoid useless warnings that scare off people who don’t know better.
Look, you can somewhat reasonably prove the origin of a piece of software, but a domain name x509 cert would be better (only difference is validity needs to handle longer time ranges). The issue is all the “trusted” yadda yadda. Doesn’t matter if it’s an App Store, a holy enterprise certificate trafficker or the pope himself doing the blessing, it just doesn’t hold up. Maybe they could have a herd-protection like VSCode extensions: “50M+ users” so when I see an executable called “Facebook” with “35 users” I can stop and make my own judgment that it looks fishy. But that’s about UX for checking the vendor matches who you think it is, not blessing it.
> Similarly, if OSes don't implement real security that's independent of the App Store model, users will continue to be exploited in this way.
Spot on! Here’s the thing: sandboxing software on any of the big operating systems wasn’t there from the beginning, and that’s the billion dollar mistake. Sandboxing is the only real game changer in end-user security with iPhone/android over desktop, not the monopolistic app stores. Tbf, Apple at least has tried really hard to bring sandboxing to desktop but even they are not there yet. These mega corps should imo have seen it coming a decade earlier, when the web became vastly popular platform, much thanks to sandboxing.
I don't care about 'regular users'. I care about myself.
If you own an iPhone, it's actually very practical to also have a Mac.
> run a specific software at least once a week, and limited to like 3 apps.
What?
The most common way to make all this signing a bit more bearable is to have AltStore installed on your mac, which will automatically re-signs the select few apps you want in some hacky way (needs your Apple id and password).
Don't you find it ridiculous that the "common" way to run software written by you on a $1k device that you bought is via buying $2k machine and paying 99$ yearly?
As much as you and I don’t like it, what Apple is doing is perfectly legal. And as much as you or I might support a change in the law, you’re not going to get my support if the legislation is truly universal and not just a narrow-band targeting of a single company for developing an ecosystem which resonated with a large number of people. Write some legislation which applies to ALL platforms which run software and maybe I’ll take it seriously.
> what Apple is doing is perfectly legal
Not in the EU starting this summer!
Although I agree with the second point: game consoles being general purpose computers should be treated the same.
That's a great argument. I have even a better one:
Don't dictate what and how people use their devices that they paid for with their hard-earned money.
All software effectively "dictates" how a device works, whether you're talking about an OS or an app. If you buy an app, you don't get to decide how it works. You don't like it? Don't buy it. I don't see a big push for people crying to the government to stop Activision from dictating how to play Call of Duty.
Apple doesn't dictate what software runs on your iPhone, any more than a toaster manufacturer dictates whether you can use it as a space heater, or Toyota dictating whether your car can function as a boat, or Epic Games dictating whether Fortnite can be used to prepare your taxes.
It's true that Apple doesn't make the process of running your own software easy, but you are legally entitled to break whatever barriers you like and replace the OS with a Linux distro. Have at it. It's great. I support it. And if you want legislation that requires hardware manufacturers to provide documented paths for installing alternative operating system software, I'd support that legislation eight days a week.
Then don't enable side loading.
And what Apple is doing is actually not perfectly legal. That's the entire reason they're changing their policies. It's not like they enjoy having to compete with app stores that offer other payment providers or allow things like emulators.
Sure, maybe Epic can be trusted. But perhaps Meta decides that the latest/most desirable versions of Facebook, Instagram and WhatsApp have to be side-loaded. Now it's commonplace. Now everyone's phone has sideloaded apps installed.
Sure, maybe Meta can be trusted. But perhaps some new future TikTok-esque craze besets the mainstream, and it's in the form of a sideloaded app, made easy because sideloaded apps aren't unusual, and the company who makes this viral app is dodgy as f***.
But sure, it's always the user's choice.
It's us asking our democratically elected government to stop a giant corporation from telling us what to do with our own devices.
Yes it's your device, but it's not your software. You don't own the software. And it's the software which is stopping you from doing what you want.
Really though I'm just saying that I resent arguments that fail to provide anything resembling a modicum of consistency around this. As far as I'm concerned, as long as Sony is allowed to keep the PlayStation locked down, Apple should have equal right to keep the iPhone locked down. And if you, the consumer, doesn't like it, don't buy a PlayStation. I realise this comes across as a trite, throwaway thing to say, but I absolutely mean it. It is, in my opinion, a slam dunk argument.
What you're proposing is not really ownership of the device in any meaningful way, but just a license to use it on somebody else's terms.
I don't want a world in which I don't own the device I pay for, so neither Sony nor Apple should be able to dictate what I do with them.
It's like selling you a screwdriver and then saying you can only use it with one specific brand of screw.
Ownership of software is clear-cut under the law: unless you hold the copyright, it's not yours. You have been granted permission to use the software under the restricted terms of a license. In practice though, the legal perspective isn't a useful one. It's another bad analogy, useful only because it's the one backed by law. What actually matters is what you can do.
It doesn't matter who "owns" it, you don't have the code needed to recompile the OS from source. Much less than sideloading apps, there are thousands of nominally trivial aspects of the OS which you cannot change without source code and a working build environment. Without this you don't have any ownership over the software in any useful sense.
You do own your piece of physical iPhone hardware, and it's yours to muck about with as much as you wish. But don't expect schematics or the ability to manufacture your own parts, or the ability to sideload more processing cores into the A14 chip, or replace the camera with a different module.
I'm sure that now that the EU has finally woken up, gaming platforms will be under scrunity too. Mobile phones are a much more critical part of people's lives than game consoles, so it made sense to target them first.
Well, not in EU now
So you think it's better asking companies to save us from our own choices? And that doesn't strike you as even more ridiculous?
Most of the noise in the community is from people who just enjoy seeing Apple squirm and probably aren't even an Apple customer anyway. Meanwhile the entities spending real money to lobby governments on this issue actually only care about getting around Apple's increasingly consumer-protecting app review process — they tolerated the 30% fee right up until the very same month that Apple started forcing developers to inform users if they were tracking users between apps.
They want side-loading so they can track you, not so they can extract more money from you. Because they know they won't. Yes, entities like Epic might be able to sell apps with a lower marginal cost (not a lot lower, as they'll be handling stuff like fraud and refunds themselves, and Apple is still entitled to a software license fee) but the simple act of requiring consumers to enter their credit card number into an app is going to reduce transaction completion rates. I'd be willing to bet by at least 30%.
AppStore checking is waaay overhyped as anything meaningful.
Others are right, sandboxing is the real saving grace (and only if apps dont ask for a bajillion permissions which users will just click through so it will work). Apple is slowly trying to isolate apps even more, like they were in the early iOS days.
Uhuh, sure.
"Shut your mouth, pay and be happy"
This is pure nonsense... giving user more choices is never a bad thing.
For one thing they might think of a phone as a fundamentally different thing from a 'computer' with a different role. In fact I strongly suspect this is the majority view.
Within that people probably think of an 'application' as fundamentally a pre-screened, pre-approved, piece of software to enable some function specifically on the phone and within the phone's ecosystem. Not as any arbitrary piece of software. In fact that might all be seen as a feature, not a limitation, in the majority of people's eyes. Again I strongly suspect that is the case.
I also prefer to be able to do whatever I want with my own devices, but pretending like it’s an inalienable right, or a natural state, or has no disadvantages is disingenuous and not helpful to the debate.
You can absolutely disagree with the trade off, but pretending like it’s purely greed is obviously disingenuous.
Is that so? https://lifehacker.com/great-now-the-apple-app-store-has-mal...
When was the last time you asked the builders association if you could remodel your kitchen?
When was the last time you asked Honda if you could put new mags on your car?
This whole idea that devices aren't owned when you purchase them is asinine and and insult to humanity.
Your counter arguments that it's new in the industry is simply due to the fact they thought they could get away with it. Not because they thought it was their right.
You don't see Klein putting limits on what nails you can use with a hammer but you can bet your ass they would if they could.
i’m sure you can find an o. s. that lets you do whatever you want. but will it be updated regularly with security fixes? will it support the latest connectivity technology like 5g? will it have built in support for the latest compression formats to take high res pics and videos? will it work anywhere in the world?
if it does sure. go use it. i don’t think this exists and i’m happy to pay apple for a new phone that does this and upgrade every 5 years
Er. Yes? To all of those? Trivially? Heck, Android does those, with the FOSS ROMs typically doing better than the closed vendor solutions.
I agree. But that's not the same as the right to install whatever you want. It's not illegal to jailbreak a phone if you can and want to, but it's also not illegal for Apple to lock it down if they can and want to. That is and should be the default state. And it's the same for everything else, your car, washing machine, game console, etc. If you want general computers to be explicitly defined to include smartphones and uniquely regulated to force more requirements on manufacturers and more rights to users, then that's great—I agree with that—but at least admit it's a new and unique regulation and not the default state.
It's weird you chose houses and cars as your examples since they're both highly regulated in the opposite direction you’re asking for computers. You're heavily restricted to what you can modify in either of those and, as far as I know, there are no regulations that specifically require manufactures to allow users to modify anything. You can swap out parts on your car if it complies with regulations, but there's no law that you have to be able to install software; it's locked down harder than smartphones. And just like smartphones today, you do own it and can do what you want (excluding other regulations), but there’s no right to installation; it's just a lockdown/jailbreak competition between you and the manufacturer.
I’ve jailbroken my phones for years and love to do all sorts of personal modifications to my computers and other devices. I think regulations to protect device freedom are a great idea; I just want people to be intellectually honest about the debate.
That's the problem, it should be.
> It's weird you chose houses and cars as your examples since they're both highly regulated in the opposite direction you’re asking for computers. You're heavily restricted to what you can modify in either of those and, as far as I know, there are no regulations that specifically require manufactures to allow users to modify anything. You can swap out parts on your car if it complies with regulations, but there's no law that you have to be able to install software; it's locked down harder than smartphones. And just like smartphones today, you do own it and can do what you want (excluding other regulations), but there’s no right to installation; it's just a lockdown/jailbreak competition between you and the manufacturer.
That's what OS is for, it prohibits your from installing bomb instead of kitchen appliance. Repeat after me: Store. Does. Not. Dictate. Your. Usage. Of. Device.
Which industry? The very earliest computers ran software written by end-users.
of course I can't install any other software on a CAT scanner, that's the equivalent of what computers were at the beginning, they were single purpose machines, but they could be programmed by the owners almost immediately after being invented.
The computer industry started with microcomputers in the 70s, by the mid of the decade they were cheap enough that individuals could own them and write software for them.
But starting from the 60s students had the chance of sitting at a computer station and programming them to do whatever they wanted them to do, according to their at the time limited possibilities.
I own the freaking thing.
What people are asking for isn’t the right to do whatever they want with their device—they already have that—they’re asking for the law to force Apple to design their OS in a certain way.
And again, maybe that law is the best idea and should be passed—there are certainly a lot of apparent advantages. But I’d ask people to be honest about what they’re asking for. It’s not granting the user any new freedoms; it’s taking away freedom from manufacturers.
It’s like copyright; most people (or at least a lot of people) consider it a good law that encourages more creative work and supports a healthy industry, but it too is a law that removes freedom rather than grants it.
Sad that it has to come to this messy stage where the law has to be enforced. But then Apple isn't the same Steve Jobs Apple.
Also, your proposed rewording isn’t correct either because installing applications is already allowed. You can debate the App Store all you want, but it definitely does let you install apps.
On topic: This is silly and Apple should allow sideloading. I don’t buy the security argument because the security comes from the sandbox, not Apple’s poorly-run approval process.
I have no idea how you came to this conclusion. It's obvious that I'm criticising the idea of "sideloading" not the word. You can call it some other arrangement of letters and the concept is still very dangerous.
And in this case it is also definitely true that apple does not let you install applications without someone paying them $100+ and their continued approval. The "let" is the key here.
The way I came to that conclusion is I read what you wrote, which primarily discusses the language, not the idea. See your references to “doublespeak”, “framing”, “headlines”, and “the word sideloading”.
You claimed “Installing applications on iOS 17 might be allowed in Europe” would be a more accurate headline. It wouldn’t be, because you can install applications via the App Store. If you wanted your headline to be both accurate and to discuss the approval process and fee, you would need to include that, as the original headline does by mentioning “sideloading”, the word that you take issue with but does at least actually raise the issue you’re concerned with.
For pre-iPhone cellphone users, your cellphone network operator controlled access to what apps were available for installation. This is was the most common, if not the only, method for cellphone app distribution. App makers (mostly java games) paid to get on that first page of downloadable apps. I'd add some references but Google seems to have amnesia about anything cellphone app distribution pre-iPhone.
Apple didn't have an app store initially. How Apple convinced cellphone network operators to cede app approval/control, I don't know. Perhaps it was "apple's way - take it or leave it".
I think other manufacturers allowed that as well, but I could only use the "free wap browsing trick" on Nokia phones, so I never explored that.
Finding a .jar file that works on your phone was the biggest. Games often only supported a single screen resolution and so there were multiple .jar files for each game and you had to find the right one for your phone. Also sometimes even if you had the right screen resolution the .jar just crashed when you started it without any clue as to what's wrong (probably they needed more RAM or some platform specific code, but I was in high school back then so I didn't know much more about it)
In the early days, there was also the issue of how to get that .jar file to your phone. I distinctly remember old Nokia phones could download them through WAP (which was paid) or receive them through IrDA/Bluetooth, but themselves couldn't send applications through IrDA/Bluetooth (I think Sony Ericssons were the ones which could also send them....), This issue was later solved by microSD cards and USB cable transfers from PC.
Pirated JAR/JAD files were definitely hit and miss, but I don't think those are a great example.
Then the first Android devices arrived, with the Android Market (long before Google Play) that did allow you to download apps. But most people again maybe they didn't have internet, or more simply wanted pay apps but didn't want to pay for them, just exchanged .apk like it was the norm. (Pirating by the way was much more present than these days, for example I don't recall a single person having a PlayStation without the modchip, and burned PS1/PS2 games where the norm).
It's only with the arrival of the iPhone that this was no longer possible. In fact I recall that the criticism of the first iPhones, till the iPhone 4, was that it was an overpriced device and that it did lack of the possibility to install applications and exchange files with bluetooth, like everyone was used to do. The iPhone was a niche product that was not diffused (when I was at high school I recall maybe 1/2 people having iPhones, all other one Android devices).
The thing on cellphone operators is maybe an US specific thing, I don't recall having anything like that in Europe, more specifically in Italy. Quite frankly till 10 years ago using the cellphone network for internet was unthinkable, because the prices where so high. Then arrived the contract that give you 100Gb of data a month for 10 euros, but back in the day internet was expensive, to the fact that just by pressing the internet button on a phone it did consume all your credit. This is probably also the reason why WhatsApp become so popular (you could chat with your home internet connection that now everyone had without consuming expensive SMS)
Apple has been for example putting limits on data collection and tracking. The main mechanism is to kick apps out from Apps store if they don't play by the rules.
I'm worried that side loading will be a step back here. Strong players, like Facebook, may just take their app away from the official store and distribute it through other ways. With their strong position I don't have much choice - it's not like there would be five competing apps serving the same purpose (connecting to the people and communities on Facebook).
I hope I don't come across as snarky -- I am genuinely curious -- but why don't you have a choice? Are you unable to contact friends, family, etc. any other way outside of FB? The phrasing seems so strong, I am second guessing if I am just privileged/lucky (location, friend/family circumstances, etc?) to be off of social media but still have friends and family that I stay connected to.
EDIT: fixed grammar
https://support.signal.org/hc/en-us/articles/360007059792-Si...
You just tell your friends that you are not reachable on Facebook anymore and how you can be reached.
You don’t have to "convince" anyone.
Your real fear is that people will stop reaching you if they don’t want to install another app, send you an SMS, send you an email or to call you on the phone.
Well, if your friends stops reaching you because you uninstalled an app, honestly it looks that they are more acquaintances than real friends. And it’s ok. But it’s also ok if they are just an entry in your contacts list.
I say this as someone who despises facebook but this is the reality we are in. Similarly, in most nations outside United States, you really cannot get rid of WhatsApp. If you don’t use WhatsApp, you are missing out on how much of your society operates.
It’s only worth it to app makers to have side loading if they can do it for large numbers of users, bypass the app store’s rules, and bypass apple’s take. I’m expecting apple to set it up in a way they can do none of those things, by making it cumbersome to sideload, not giving entitlements to apps not published through the store, and by taking a cut for sales from sideloaded apps.
But it does allow for niche applications such as NewPipe and F-Droid, for technical users who know the risks.
The malicious PDD app is really, actually, published to the alt stores by PDD Holdings itself. It loads the exploit config and post exploitation modules from PDD's own CDN.
It's not the same repackage-with-malware shit plaguing China/SEA market since forever. It's first party.
And the Google Play version contains the same exploit delivery codes, though no real evidence that it was activated.
If you feel compelled to use a product with policies you don't agree with then now you understand how many of us feel about iOS.
If you mean you feel compelled to sell in their store which requires a laptop, a business relationship with Apple, and realistically a phone because emulator only sucks then that's a business decision if the juice is worth the squeeze.
>There's always one Android user in the friend group that spoils iMessage and FaceTime
You can't be the "everyone else is one it" social network when every Apple user uses a 3rd party messenger and video chat app for at least one person. That app ends up being the winner.
And a lot of apps launch early on iOS or have better features on iOS or never even launch at all on Android. Less so these days but it's still a thing. I was just in Japan and you can use an iPhone to pay for mass transit but not a non Japanese Android phone, just as one recent example.
The prime example is that apple gives apps unfettered access to network connections. And YOU are unable to block this in any meaningful way.
What apple doesn't give you is the ability to manage your own phone. You cannot really manage what apps are doing yourself. You cannot even find out what apps are doing. And you definitely will not be able to manage apple apps, they get a free pass in all ways.
But yes, if there's a sideloaded facebook app, or a facebook store, you will be given more rope to do with as you want.
Settings -> Privacy & Security -> App Privacy Report
It shows you per application what data they are accessing, which sensors they are accessing and which domains the app is contacting. It also reports when they were doing this and how often. You can even export this data as a JSON file.
https://source.android.com/docs/core/permissions/runtime_per...
Man the amount of false shit that gets thrown around by these Android vs iOS mobs, usually by people who don't even know their own side.
The original poster asked about _fine-grained permissions_. Not about _runtime permissions_. Details matter.
Android did have very fine-grained permissions since first betas. Yes, they were install-time - a policy was generated at install time by the system, and the app itself was unable to change anything about it. Technically, it was a nice system, but users didn't understand that, they were asking for simplified model from iOS, so they got it in Android's 6.0 _runtime permissions_.
In the end, neither of these system (or: original Android did have it, but the simplified 6.0+ doesn't) has the most important permission: can an app talk to the network?
They weren’t really that fine-grained from a user perspective. You could not accept/refuse individual permissions, you either accepted everything or simply not install the app.
iOS always had fine-grained permission in that you could grant/refuse individual permissions. For example: you could allow an app to access the camera but refuse location services. Android only recently gained that capability.
Even more important, iOS always put the permission request in context. If I install an app and it asks for a ton of permissions I have no idea why it needs them and if it makes sense for that app to have them. Why would a chat client need access to my photos ? But on iOS, I get that request the first time I choose to send a photo to someone. I immediately see by the context why it needs that permission and I can make an informed decision.
They were fine grained: apps either had them in their manifest, or not. If not, they could not call the respective APIs without getting an exception.
Because there were so many, it would be a great burden to app developers to check for random mix of required permissions, whether it was granted or not. The complexity would shoot over the roof. When Android switched to runtime permissions, all the detailed permissions were grouped into fewer coarse ones; exactly because so much detail would be unbearable for both users (fatigue from the alerts) and developers (handling the enabled/disabled matrix).
As far as I remember, iOS originally didn't have any permissions. It got them once certain app was stealing users address books, so it got confirmation for accessing contacts, camera/photos and a third thing that escapes me at the moment (location?).
> But on iOS, I get that request the first time I choose to send a photo to someone. I immediately see by the context why it needs that permission and I can make an informed decision.
The app can also remember that it got the permissions and do the nefarious thing behind your back. While it may look better, it is really not; it also won't work if the permission system is fine-grained: too many types of permissions and users will get lost. Also, users accidentally pick the wrong choice and then wonder, why the app doesn't work like they expect, or how to change it.
Thank you for sharing.
nicehost.benigndomain.com IN CNAME creepy.domain.biz
(or other similar techniques)Apple has no commercial interest in breaking the users privacy and trust. Their business model is not to sell ads or work with 3rd party advertisers.
They track the stories you read on News & Stocks, and track your location to give you personalized ads.
This integrates with Google Ad Manager 360 as well. They work with 3rd parties. https://support.apple.com/guide/adguide/integrate-workbench-...
https://www.bloomberg.com/news/newsletters/2022-08-14/apple-...
Wrong. You CAN find out what apps are doing: Settings → Privacy → App Privacy Report
> And you definitely will not be able to manage apple apps, they get a free pass in all ways.
You can outright delete most Apple apps.
> Apple doesn't protect you.
said the wolf about the fence.
Unless I got it wrong when enabled it reroute all Apps trafic through this "limited VPN" to prevent tracking and access to local network.
Apps that require access to local network must ask that permission explicitly. Streaming service (Netflix, Disney+,etc) do that for obvious performance gain. I noticed Microsoft Teams did it also (and I just revoked that thanks to this thread, it's a work app I better keep that out of my home local network).
What about:
- Apple’s limiting of advertising identifiers and requiring permission to track users across apps
- increasingly fine grained location access including ‘Only allow once’ and warnings when an app is tracking you in background
- sandboxed photo access so apps don’t get access to all your photos
- requiring developers submit privacy questionnaires with their app updates and showing how data is collected in each app
- supporting creating private email aliases for signing up for services
Just to name a few in the last few years.
iPhone is THE hottest device on the planet, I can’t believe anyone can seriously consider Facebook challenging its position.
https://nakedsecurity.sophos.com/2023/02/27/beware-rogue-2fa...
They don't look at API calls made by the apps. How can they be your sure of the security then?
Only after this was published were the apps removed.
The same legislation that is requiring Apple to allow sideloading also requires other large players (like Meta) to open their communication platforms up to other service or application developers.
In this hypothetical case, there actually would be five competing apps, some even still distributed on the App Store.
Apple could have hidden the settings to enable it behind two levels of menu settings and anyone like you would never get to it. The only reason they have "strict" policies, as has been shown over and over again, is for their commercial benefit.
> Apple has been for example putting limits on data collection and tracking.
I want to be tracked by apps, because it leads to better ads for products that I am actually looking for (than some random garbage that I don't care about)... and better usability in general. Apple put those rules in place so that their ad business has the edge over competitors. If Apple was running in a country that was not corrupt, this would be seen as anti-competitive and they would be sued.
> Strong players, like Facebook, may just take their app away from the official store and distribute it through other ways.
And? If you want clear rules on tracking, go talk to your politician. Apple is blocking competitors from tracking users while it has access to all of users data and uses it for their $5 billion revenue business.
You know who's really putting limits on data collecting? F-Droid.
If that's actually your argument, that's what you should use. It's quite practical.
> Strong players, like Facebook, may just take their app away from the official
That argument really has to explain why this has not happened on every other operating system under the sun, including Android. They all suffer pretty strong monopolistic network effects.
https://www.cnbc.com/2022/02/02/facebook-says-apple-ios-priv...
It's going to be interesting when some sideloaded app starts becoming popular and e.g. americans miss out on it. I can already imagine a lot of AI and nsfw stuff in that category
The EU has no jurisdiction over the US. So there will be no legal need for Apple to allow it here. Just like they don’t allow alternate payment methods for dating apps in the US like some other countries required and Apple had to comply with.
The App Store is too critical to the way Apple sees things, they’re not going to just say “oh well”. I bet things are only open for EU residents with EU purchased phones. Buy an EU phone and activate with a US account? Bet it’s locked.
Also expect them to make hay over any security/scam issues with 3rd party stores/side loading. Something WILL happen and when reporters ask Apple they’ll be more than happy to point out how great the App Store is suggest users stick to it and blame bad regulations for making EU users less safe.
And at the same time not at all that uncommon. If you are in a market outside of the US I'm certain you will have experienced this first hand more than once. I have.
They’ve managed it for 15 years so far. It may be crumbling, but this isn’t a new restriction or something that wasn’t possible in the past.
The point is that since Apple had to do the work to allow sideloading at all, most if not all of the lies they came up with for why they can't allow it for everyone won't work anymore.
But one counterargument goes like this:
When you relax the rules, larger players will be able to leverage them against individual users.
For example, Meta would be able to release MetaStore, the app with exclusive distribution rights to Meta apps. Now you need a facebook account to install whatsapp.
Not sure its sustainable, however.
If Apple created a methodology for circumventing this process, all of a sudden it is something that I have to worry about, and it creates an attack surface that I’d rather not have to consider. It also weakens my ability to demand these standards from publishers. If a publisher has the ability to say “this app is only available outside the walled garden”, then they may refuse to publish it via the system that is designed to ensure my interests are upheld.
If the Apple curated experience happened to curtail the way I wished to use my device, then I would have more to think about. But it doesn’t, I can do everything on my iPhone that I want to do.
I do have sympathy for the developers who sometimes find themselves stuck in a Kafkaesque review process. But I consider my own interests to be much more important than theirs.
I have very little sympathy for the businesses who object to the revenue model. Apple’s system asserts my interests as a consumer above interests of business who frequently engage in anti-consumer behaviour. I don’t care if they have to pay to access me as a customer, this is something I’m intentionally opting into as an Apple user.
The only time I do object to Apple’s curation, is when they use it in a way that I view as prioritising some other agenda above my interests. Such as when Apple pulls and app, or refuses to publish one, for reasons such as it containing “objectionable” content. I view this entirely as them subverting my interests. If that started to interfere with they way I wanted to use my device, I would start to consider an alternative. But so far it hasn’t.
Excellent. Let me, the owner of the device, choose how to use it. If I want it to be "less secure" that is my choice.
>If Apple created a methodology for circumventing this process, all of a sudden it is something that I have to worry about
Then do not use side-loaded app stores if you do not want to. Your device, your choice.
My preference is to have a device where there are no technical means to side load apps (as that is a security control), and to have a device where a publisher cannot attempt to force me to use a side-loaded app store. I explained my reasons for having those preferences, and if you'd like you can respond to that. But this comment simply ignores all of that. You say "my choice", while ignoring all of the reasons I provided for why these changes could potentially undermine my ability to choose entirely.
The logic is simple: if you don't want sideloaded apps on your device, don't install them. There's no argument against this, which is why the the endless parade of facile handwringing about security is so preposterous.
You either didn’t read my comment, or you simply don’t understand how these security controls work.
No, if an adversary has physical access to your phone and can unlock it, you've already lost.
> It allows vendors to attempt to force users who don’t want to use 3rd party app stores, to use 3rd party app stores.
The refrain from defenders of this policy up until has been "just use a different device". Thus, I'm giddy that I get to turn this around: "just use a different app".
Think about what website you're on, and realize that you're fighting a lost battle.
However these opinions have no influence over the factual compromises that these changes make to security controls. Currently if I gave you my iPhone and my PIN code, and asked you to install malware on it, you wouldn’t be able to. The fact that you’re making some appeal to the opinions of the community rather than engage with these facts shows the strength of your argument (in addition to the general childishness of your comments).
They only made things different when they absolutely had two, like the radios. But software featured are really easy to differentiate in different countries.
The big risk, and I agree with you, is that this will prove that sideloading isn't the great evil they’ve been portraying and they’ll be forced to offer it in additional places by more laws until it becomes easier to just give it to everyone.
.) whether you buy a phone as a piece of hardware and then own that hardware - which gives you certain rights regarding the usage of that owned hardware
or
.) whether you are just paying some sort of admission fee to a tightly controlled service, and are basically "lent" a piece of hardware that you have no ownership rights over.
All the other stuff about walled gardens, monopolies and security is related - but still acts as a red herring when discussing what rights a person should get for a piece of hardware they bought.
You can sell your iphone without any issue, there are plenty of stores around me offering to buy used models to resell. I'm actually contemplating buying a used model. Can't do that with steam games.
I'm also pretty confident that if apple and their services disappeared tomorrow, my iphone would keep on working just like it does today. Sure, no more updates, no more new apps, it would be frozen in the state it's in.
Therefore, I think the question is whether an iphone is a "general computing device", or "an appliance". I can see the arguments for both, even though I tend to treat mine as the latter.
You can hardly call that "working like it does today". It doesn't. When features on it inevitably cease to work or be interoperable, you're screwed. And every day, you're probably more vulnerable to crime.
If I buy a house, I can learn to maintain it and keep it secured. I can't do that with my iPhone.
For the argument's sake, your ability to do things to your own house is restricted by zoning, by HOA and god forbid you from buying something of historical significance in Europe -- then you can't change anything inside or outside and you are responsible for it.
For pretty much every thing there are restrictions on what you can do with it - if I buy a phone, I'm prohibited from smashing it into my neighbour's face, and grinding it up and baking into the cookies I sell would be a violation of health&safety rules, but that's still full ownership.
Now, if the seller wants to impose extra restrictions above and beyond what the general society does, that's a different issue.
What an exaggeration. Do you think such hyperbole strengthens your point? At best it makes you sound ignorant.
The fact that you can't even imagine how that might work points to the real problem.
This is a red herring. What matters is your freedom to use, repair, modify, resell, loan etc the hardware you bought and own.
I think you're underestimating how much of the iPhone's functionality depends on Apple's servers being available beyond just installing & updating apps: Think push notifications, backups, iCloud, iMessage, no more Safari updates (shiver), …
How do I add my own apps to my iPhone, permanently?
Otherwise, stealing would be very easy - just connect to wifi without access to apple servers and voila: phone is yours.
When it comes to software, that's only possible to do with open source. With closed source you're only ever buying a perpetual usage license. (Unless you are a company buying out another company or it's assets, that is).
It's complicated, because software and digital data is inherently different from physical goods - and all those concepts of "selling" a "copy" are just rather ramshackle attempts at making digital goods compatible with laws designed for physical goods.
I don't know about the other one, but in the Steam store I see "Buy" buttons, not "Rent". "Buy <game name>" in the store page, then when you go a "Shopping Cart", where you can "Purchase" the game.
To me (and to the average people, I guess) it doesn't sound as a rental service at all.
I'm sure that their ToS says otherwise, but I wonder how it would fare in a court case...
Common usage of the word 'buy' also applies here - the term 'rent' would be confusing to a customer and would usually imply it being time-limited (often days).
And you do have ownership of the licence.
Also is GameStop allowed to use the term 'buy' in their shops? Because they are often selling a licence too, it's just in a box.
Under your definition you can't buy a ticket to a concert, or buy pharmacuticals if a doctor gives you a perscription, but most people would say that you could buy those things.
See pharmaceuticals as an obvious/trivial example - you can own prescription drugs without being able to sell/dispense them.
Of course you can own things that you can't sell anyway, you can own an extended warranty on your flatscreen television, or own non-transferrable bonds in a company.
Most things you own you can sell, but it's a mistake to think that ability to sell is a prereqesite to ownership, and a non-transferable licence is one of those things on the list of 'things you can own but cannot sell'.
And on the 'buy' point - Do you think you can buy a haircut, or buy a pedicure?
> And on the 'buy' point - Do you think you can buy a haircut, or buy a pedicure?
Those are services, not products.
If we are happy that you can buy services, I assume we are happy with Steam using “buy” to represent the purchase of the service and licensing offering they have?
Now, with software this is usually not a big issue because the mismatch is not huge. When you buy a retail software, you got not the same but at least similar rights that you get when you buy a physical book: you can use it, you can lend it, you can sell it, you cannot make copies. So, when you say "I bought a game", everybody understand what it means, even those that disagree with the term.
Now in case of something like Steam, not only you get a license, but you cannot lend it, you cannot sell it, one day you may not be able to use it anymore because the DRM servers are taken offline (not Steam's fault this), or Steam may decide that you are a "bad guy" and remove access to your whole library.
At this point, the difference between "buying something" and "buying a license to something" becomes more marked, and in my opinion should warrant a different term on the store.
Probably a bad example - lots of property deals are structured as purchasing the 'leasehold' where you only get the right to live in it and do not own the physical property/land.
Most times when people buy an apartment/flat for example, you aren't actually buying an apartment, you are buying a right to rent an apartment.
This is very common in the UK, and does happen in the USA too (e.g. in New York).
This is distinct from buying a freehold property where you are buying the land and structure, rather than just buying a right to rent for a particular term.
To my layman's ear the two terms sound almost contradictory.
> An “irrevocable” license, on the other hand, cannot be terminated, although there is some divergence in authority regarding whether this means that the license cannot be terminated for any reason or only that the license cannot be terminated for convenience, but still may be terminated for breach.
https://casetext.com/analysis/the-terms-revocable-and-irrevo...
You instead need a judge or jury or law that says: "No, fuck you, this is confusing and we don't care what's in your ToS, you will treat this as a product which has had its ownership changed in return for money".
What do you mean by that? The steam ToS (which are enforceable by law) make pretty clear that Valve can revoke your access to any game at any time. Further, your access is dependent on Valve's continued existence. The argument that you are "buying a license" is like saying you "buy a rental contract" at a car rental place. The contract you have with Valve to play the game allows you to play the game for an indefinite period of time, but crucially only while Valve is still in business and while they let you play the game. This is in the ToS and in the USA there is no reason (IANAL) that I see to think the courts won't enforce this contract.
> If things are different in your jurisdiction, please do share how and why
Which law in your jurisdiction makes the Valve ToS feel more like a purchase and less like a rental?
Since you're not a lawyer (your words) and seem to care about US laws (I don't), I am not sure what's the point of this response to a topic about digital purchases in the EU.
In the US it is legal to have a "buy" button that actually purchases a longterm revocable license. I don't like it, but thats how it works on this side of the pond.
Rental contracts have defined time periods. Perpetual licenses don't. That's a massive difference.
Now, some, or even many, new games may refuse if they are somehow extremely dependent on the service. The ones that I have tried run fine. Most old stuff, though.
The vast supermajority of games on steam require steam itself to be operable in order to even run. Valve absolutely can break or turn off steam and (legally!) revoke access to most games on most steam user PCs that way.
How would I know if I own a device or not?
If you buy an iPhone, but don't think you own it. Why don't you think you own it? If your response is "because I can't run the software I want to on it," is that a problem with the perception of what you bought or is that a violation of the idea of ownership? If that's a violation of the idea of ownership, why?
One test for "full ownership" is the contractual restrictions that come attached; i.e. whether the law is the only thing that limits what you can do with the thing, or whether there are some extra conditions (which are not that rare in e.g. real estate deals for as long as we have recorded history); that's generally considered ownership but a restricted one. On the other hand, if you aren't prohibited to do that thing but simply aren't capable of doing it, that would still be considered unrestricted ownership.
But something that is a key part of ownership - especially with respect to various "buying" of e.g. games - is the ability to transfer it to others. If you can't give or sell the thing you've purchased to someone else, that clearly indicates that you don't own it.
Here's the concept of ownership for private property in German Law. It's broadly defined as 1) Exclusive Rights, 2) Transferability, 3) Protection against Unlawful Interference, 4) Compensation for Expropriation and 5) Inheritance and Succession.
People would still buy cars if seatbelts weren't a standard feature. They'd still by deodorant if it put holes in the ozone.
Vote with their money only works if companies make a product you can buy. Where's the iPhone "unlocked edition" that costs $20 more that I can buy? They don't make it.
I don’t buy iPhones because I like being unable to side load apps. I miss it a lot.
The point is that when I make my list of pros and cons of buying Android vs iOS, I still prefer iOS because, as much as I dislike Apple commercial policies and artificial lock-ins, I just loathe Google for what they are.
And don’t even call me some sort of "fanboy", I’ve used and loved Android as an OS since basically the first versions.
It’s just that iOS have a quantity of advantages I’m not willing to lose by going back to Android and that there are basically no alternative platform to run apps on.
What are these?
The integration with Apple desktop computers is pretty compelling as well. It’s part of the reason I wish Microsoft would buy Android from Google. I think they would do something similar for the rest of us.
My whole point was that you are limited to only two platforms. So choosing one doesn’t mean that you accept all of its disadvantages.
For instance, when purchasing a music subscription through an apple device, they receive 30% and the developer 70%. Apple have their own competing service where they make 100%. This makes it impossible for others to compete on equal terms, hence you as a consumer probably see less choice than you could have.
Well, no, actually they don’t. The EU just passed a law mandating competition on platforms when it comes to store because as often in a duopoly the ability of people to vote with their money is significantly limited. That decidedly solves this question.
What if I actually want to pay a fee to a tightly controlled service? Like what if I do the math and determine that that benefits me more than actually owning the device? Should a regulatory agency be able to come in and tell this tightly controlled service they aren't doing it right when I am a happy customer?
> when discussing what rights a person should get for a piece of hardware they bought.
You already pre-decided that the first answer is correct without actually asking if anyone prefers the second.
I think the default should be protection. Just like it is okay for a BDSM-scene to exist where people inflict consensual pain onto each other — the default must still be to protect the individual's right to bodily autonomy and protection from harm — even if some people, sometimes opt to waiver these rights
Signing away those rights should always remain a special case and not the default. Same for ownership rights, because if the only choice is leasing, ownership ceases to exist. While when ownership exists you could still easily enter a lease.
I pay a monthly fee for internet - and that's the admission fee I have to pay to access the service. And I get sent a modem/router - a piece of hardware - that I don't own, but that's only being lent to me.
Absolutely nothing wrong with that.
By default yes - but I can switch that to only allowing devices I whitelisted through the web interface. It's not full admin rights - but for my purpose it's sufficient.
> If your want to rent your modem, that's your perogative. But I don't want to rent my modem. And AT&T being a convicted monopolist set precedent that means they actually are not allowed to stop me from using my own hardware. And if I'm using my own hardware, I don't need to rent their modem, which means I don't need to pay their modem rental fee.
I agree that "bring your own modem" should be fully allowed (and obviously free of any rental fee - not that I'm paying any, the modem/router comes pretty much free with the contract).
So if apple accepts returns for their products for a reasonable amount of time, you don't really have a problem?
You definitely wouldn't buy a second iPhone either since now you understand what an iPhone is, when you didn't before?
What you're saying is your core problem with an iPhone is not structural, but semantic?
Nothing I am saying is intended to dissuade anyone from engaging in the transactions that we currently label as "buying" these devices; I would love the EU to force the companies to more clearly label what they're selling instead of pretending that you get ownership when you enter a restrictive walled garden, but consumers can and should still be able to knowingly and freely choose a restrictive walled garden if the labelling as such is clear.
However, the "freely" part of "knowingly and freely" is complicated in some cases - people who want to communicate with businesses, groups, and friends that rely on Facebook or WhatsApp may not truly be free to decline to sign up with Facebook or WhatsApp, since those walled gardens have very strong network effects that can unreasonably restrict those who don't wish to opt-in. If the EU forces services like Facebook and WhatsApp to support interoperability with open-source and commercial alternatives, this issue will be mitigated.
I don't think this is a strong restriction on free choice when applied to gaming consoles, since those walled gardens don't have much of an impact on daily life activities, unlike Facebook and WhatsApp in many countries/contexts.
The idea that a CPU is going to come out of reset and start executing instructions that you provide at the reset vector is thirty years out of date.
ref. https://doc.coreboot.org/northbridge/intel/haswell/mrc.bin.h...
... plus Intel's microcode.
Looking at Linux and all the devices it powers (including most of the internet infrastructure) - it would seem that it is possible to do pretty good security on very open software that's as separate from the hardware as can be.
Don’t conflate user freedom with just…being salty that not every product is for you.
iphones act as social signaling for alot of people
Maybe a smart phone was a status symbol 10 years ago, they are just commodities today.
In my own communities (work), I'm one of the few with an iphone, most have Android.
A subset of Kindle users who want “real” google apps?
I very much doubt it’s billions.
I don't want to download Instagram from Meta store where anything goes. (And yes, perhaps someone is going to tell me to simply not use Instagram. But I _want_ to use Instagram, I just want to do it on terms that Apple negotiates for me.)
*ofc I don't agree with 100% of their rules (especially the way they split revenue), but I'm mostly happy with them.
While listening to feedback is not a bad thing, design by focus group rarely works out well. You risk ending up with things like this https://i.imgur.com/IoPkza2.png! While this is obviously a joke, it does contain grains of truth.
The other problem with this argument is how the question is framed? Are the majority of users armed with all the facts and details? While I'd agree many are overstating the issues, there are equally as many dismissing any issues out of hand. IMHO, it behooves any one suggesting what "the majority" want to at least do a thought experiment around the pro's and con's and be honest about what they are. We cannot have this here, sadly. This should extend to any government that are enforcing something like this to transparently lay out the pros and cons and maybe accept some of the liability. That though, is asking too much of politicians...
The pros and cons are already quantifiable on Android.
The main demand in these "sideloading" discussions is therefore that Apple ought to make installing unlisted Apps easier. Personally, I don't understand why this should be of Apple's concern though. They already present a choice to app developers: Either go through their walled garden or impose a technical process on your (non-technical) end-users. Interestingly, there are already projects like AltStore that try to make the latter easier, which should be taken as proof that the whole "sideloading is impossible" argument is not really truthful.
Why this rose up to the highest ranks of the political system is beyond me.
PS: The existence of Jailbreaks further undermines the argument that you cannot control the software on your device.
How? It's like saying car manufacturers aren't really locking down their cars to hardware that only official dealerships own, because after all you can just buy a coding tool from some random AliExpress seller so it's fine. What are people complaining about.
>> in other examples, in the case of iPhones it was always possible to push custom software to your own device for development purposes.
Sure, which is still a process 100% controlled by apple and which they can pull out at any moment. Also let's not pretend it's anywhere near as easy as installing Galaxy Store on android and instantly getting out of Google's restrictions on the play store. Hopefully we'll get legislation that removes that possibility entirely.
>>The main demand in these "sideloading" discussions is therefore that Apple ought to make installing unlisted Apps easier.
I have no idea where you've seen such demands, because it's not true. No one wants apple to host apps which would otherwise be unlisted or outright banned. That wouldn't make any logical sense and would be an unjust cost on apple. I do however want to be able to install an alternative app store and install apps from it without apple butting their nose into it. Like courts have ruled in the past already - if I make some software for iOS and a person wants to buy that software, why should apple control whether I can sell them that software or worse - get a cut of the sale[0]. Because they made the platform? Well, you don't pay anything to Mercedes for making mercedes-compatible wipers, and I really struggle to see how this is any different.
[0] assuming you don't use the app store of course in which case they should absolutely be paid.
Most people using Android or Apple's very own macOS today use their device as if they're in the second situation with not a care in the world.
Anyone's walled garden experience isn't meaningfully dependent on anyone else's sanctioned sideloading or not.
Apple’s walled garden is most of my digital life, and at least for now, that is good enough. I can imagine switching to a Samsung foldable phone with a good docking story, but that will probably not happen.
EDIT: another things that keeps me from caring about being in a walled garden is that so much of my Intellectual life is serviced by the cloud: Colab Pro for most deep learning experiments, the web based Leanpub authoring system, etc. Choosing devices and operating systems seems less important. When I travel, it does not matter much if I grab my smallest Linux laptop or my iPad Pro to take on a trip.
It’s either fully under my control or I have nothing!
For most people the ownership aspect is covered by being able to buy and sell the devices freely, and decide what apps to put on them.
They are (and before I’m accused of being patronising, I am in this group) happy with a device that is capable but more or less on rails and has the sort of security provided by third party vetting. And we don’t care at all that it’s the device vendor doing it.
I get the arguments about monopolies and the whole thing being damaging to business, which is in the end damaging to consumer choice.
But honestly “I should be able to do whatever I want at all layers of the stack on my phone” is waaaay down the priority list compared to “I want a secure device that does bank stuff, generates tokens and whatever else without me having to be vigilant like I am on an open system”.
So to me the rights argument is the red herring.
And yes, “choice” quickly becomes an avenue of exploitation for the less tech savvy.
But I don’t think it’s right to call this binary thinking. It’s just incorrect thinking.
No, the iPhone and iPad are appliances, not general computing, forcing division between hardware, firmware, and software is a technical design decision that prevents users from choosing a fully vertically integrated appliance device.
People who choose consoles over building PCs, and pick iPhones over tinkerable Android, have a right to that choice, and corporations have a right to market to them.
I do, and it's easy, look: I believe Apple should let me install DOOM on the bootloader and make it easy for me to do so. If I had time to waste, I'd send emails every day, go protest in front of their HQ until I get what I want.
Apple's allowed to not do anything about it, and I'm allowed to lobby my legislators to force Apple to do so. Because Apple's wishes are not law, not in any functioning country that I know of.
In the same way, they cannot force Apple to write me a new, alternative app store, but they can force Apple to open the existing APIs to others. Also, making you write software has absolutely nothing to do with free speech.
Especially thanks to other options and the small share Apple has by volume, it's no more appropriate to crack apart this appliance than it is to force PS5 or Xbox Series X to run PC games or support Steam.
Those platforms should also be opened up, yes.
- usus, the right to enjoy the thing,
- fructus, tge right to reap the fruits from the thing
- and abusus, the right to sell, alter or destroy the thing.
To "own" something generally means all of the above, althought it might not always be the case: https://en.m.wikipedia.org/wiki/Usufruct
Well, they failed in that.
Not the same at all. You can install whatever you want on the Steam Deck.
I'd fine with Apple just curating their App Store; I am not fine with them deciding what software I can run on "my" device.
>I'd fine with Apple just curating their App Store; I am not fine with them deciding what software I can run on "my" device.
Yea that's horrible, that's why Microsoft and Windows are great when speaking about PC industry and comparing it to the iOS and iPhones.
I personally only use Android for the same reason why I only use Windows and that is Android and Windows are open operating systems and I can install whatever I want.
Really iOS is the outlier in the major computing platforms in how much of a walled garden it is.
Then there is little friction to get people to install more (because the hard part is already done), and they could even merge Android and iOS into a single marketplace for mobile apps.
Who even cares about Chrome on iOS?
https://gs.statcounter.com/browser-market-share/mobile/north...
I think the biggest category is alternative stores.
Like NVIDIA Geforce Now or Steam.
[edit] Ultimately, they have almost no incentive. They can install their apps just fine and they don't make their money by users paying them. Epic care because players do pay them directly.
Words that should send a chill down every spine. It's obviously just a monopoly. They could easily have an 'allow sideloading' option in the OS, and those that are happy with Apple's curation can leave it off, and everyone else can turn it on.
Personally, I’d like to take full control over my iphone. And create apps for myself the way I see fit. But I’m afraid that with sideloading allowed, most software vendors will go sideloading-only. That means, nobody will have any control over their app’s privilege requests, behavior and other security related things.
Basically my concern is that when I need a “ruler app”, I just install it and am sure it couldn’t even be published with sms access request. Now with wild-west sideloading this restriction is over, so everyone and their dog will nag you to allow access to AB, calls, mic, etc. All dark patterns will break loose.
There is no reason why side-loading means "not sandboxed". Apps still need to use Apple SDKs to interface with the OS, so there is still an opportunity to request permissions and for the user to deny permissions and for the OS to honor the denied permissions.
Just like it works today on macOS.
Case in point: https://f-droid.org/en/packages/org.secuso.privacyfriendlyru...
https://f-droid.org/en/packages/org.secuso.privacyfriendlyta...
Here are two simple ruler apps you can reliably use: https://search.f-droid.org/?q=Ruler&lang=en
Here are a bunch more: https://www.amazon.com/s?k=Ruler&rh=n%3A2350149011&crid=D5EU...
There are alternative app stores exactly for this reason. Nobody wants a future where you need to download random IPA files from the internet all the time, just having the ability to run F-Droid/Amazon App Store/Epic Games Mobile on your device is enough.
Honestly, I don't even get why Epic hasn't made an app store for Android yet. Mobile appsstores aren't exactly rocket science.
And the whole “free iphone” movement tries to go this route. We are basically living in a pocket between Apple pursuing their own goals (but thanks for explaining that again, someone bright here), status/rich iphone users, and app vendors who have to obey the rules. Why everyone here wants to destroy this pocket and get android-like situation on iphones when there already is an unlocked hacker-friendly f-droid or whatever is beyond me. I’m fucking sure that after Apple allows sideloading, most of these guys will say “nice, but now that it’s the same, meh” and will not buy an iphone anyway. While everyone who actually cared will suffer the consequences.
Android and iOS are not the same, and they never will be. For one thing, people bully others for having the wrong colour chat bubbles; there's a whole social problem surrounding the brand and that provides one reason why someone who wants to install an emulator doesn't buy an Android phone.
There's no reason why you can't stick with Apple's app store if others decide they don't want to. In fact, the threat of competition will only drive Apple to make their own platform better. Just look at the way Safari has been improving ever since the threat of Blink coming to iOS became a reality.
What you describe isn't an "Android-like situation". Most Android users don't even know they can install apps from the internet, just like most iOS users don't know that you can just sideload apps over the network already, albeit with some arbitrary restrictions.
If Apple gets a say in what I "sideload" (it's called installing), that's against the spirit of the law. Hopefully the EU lawmakers were competent enough to also make it against the text of the law. It would be outrageous.
I would expect it to be piloted in one region first and then phase across regions. It's not exactly something you want to YOLO and deploy to the entire world fleet all at once with customer devices and server infrastructure.
[...]gatekeepers shall:
[...](f) refrain from requiring business users or end users to subscribe to or register with any other core platform services identified pursuant to Article 3 or which meets the thresholds in Article 3(2)(b) as a condition to access, sign up or register to any of their core platform services identified pursuant to that Article
"Operating systems" is part of the "core platform services" definition. Locking the use of iOS or sideloading capabilities behind an Apple ID (another "core platform service") would be a violation of the provision.
In General the US government will have to come up with their own version of the DMA if they or their voters deem it important.
At which point they get fined billions of dollars.
The EU does not mess around.
And the more "clever" apple tries to be, the higher the fine will be.
I think a small community of interested parties will pop up, but it’s unlikely to be more than a blip compared to device sales in general.
If you want out of their platform, install Linux OS on your phone and have whatever you want there.
Wouldn't that make everybody happy - Apple, EU and customers?
Sideloading will be full of complicated very important details sucking out live from all parties involved.
I think we all agree that it should not be possible to unintentionally click or autoload link that downloads some settings app that looks like ie. iOS settings app but is developed by some shady party that has access to ie. your biometric security primitives, can look like/impersonate any built-in app/OS behavior etc.
The ability to install your own OS would be a nice end goal, but at this pace it'll take at least another 10 years of government regulation before Apple would even consider allowing that.
It would likely create second market for their devices that Apple doesn't care about (because they don't release new iOS updates for old devices), it would create incentive for vendors to support open source through legacy hardware reuse (what is your hardware legacy reuse score as opposed to destroy-recycle-as-minerals score kind of thing).
We live in times where shoes have longer life span than many billions transistor devices which is mad, non eco friendly status quo where government should be stepping in instead of some cherry picked nonsense that will take endless decades to iron out and at the end of the day will make all parties simply unhappy.
You can't meet all demands of everybody at the same time because what they think they're entitled to is mutually exclusive.
Let's not kid ourselves - Apple won't give full, unrestricted access for sideloaded code ever. It's going to run in some kind of highly isolated enclave at best, with grayed out icons, warning sign overlay, scary long list of permissions given when installing, untrusted code popups when launching, permission re-confirmations when running, without access to ie. background code execution, limited apis etc. - they must be brainstorming any loopholes left by snail speed EU bureaucracy as we speak to make it as user unfriendly and limited as possible.
All that wasted energy could be channeled into something that actually is good for people, gives them freedom while preserving Apple's deserved profit participation in the market they've created themselves out of thin air.
There are people who would like to use devices they own in alternative ways ie. to develop, experiment or simply not to throw perfectly functioning, un-updatable, just few years old hardware to the trash bin.
Apple doesn't want their platform to be polluted with privileged, unsigned code. They don't want next security breach news headline to include their name in it if it originated from code they haven't verified/signed/created - because they put a lot of effort into securing their platform and profit out of it.
Allowing running alternative OSes would make both sides happy, no?
I'm just saying that for most people it's a bad idea, especially regarding Linux. Linux's security is abysmal because the desktop security model is fundamentally flawed.
Take Flatpak for example. While it is a big step forward in terms of portability, ease of use and security, it is still allows applications to pick their permissions themselves. Even dangerous ones like X11 display server access, full file system access or camera access.
However, there already is a number of secure open source alternative mobile OSes based on Android, GrapheneOS for example.
Also, driver blobs for modems are often out-of-date and insecure. Making the phone drivers fully open source will probably not happen.
If you know what you’re doing, installing a different OS onto can be liberating and good for the environment – most of the time the hardware is perfectly fine, just the software becomes more bloated and slower as the device ages. It’s just - in my opinion - more risky.
Option 2: minimal EU-only compliance, generate A/B economic data for antitrust lawyers and regulators in other countries to compete on platform neutrality, which can be incorporated by EU in a spiral of regulatory FOMO.
Will European iPhone sales skyrocket? Will you be able to change region if you move to Europe?
So many interesting questions.
You're free to buy another product!
I know your reply was meant to be satire but I've heard that argument used legit for this case many times. I just don't know how it can be taken seriously in a duopoly like this - unless they are seriously considering GNU/Linux phones to be ready as a primary daily driver or want me to carry around a dumb phone instead?
You're free to make your own phone company! Just break the duopoly and get rich!
(american voice off)
I'm still on the lookout for an equivalent example of consumer friendly regulation that (even) americans are typically behind or at least indifferent towards.
It's likely Apple will do what Google does and instead tie their app store into various apis and services (e.g. Google Play) so that side-loaded apps have a very difficult if not impossible time integrating with the phone in a way that users expect and desire.
Seems like the EU bureaucracy goes after big entrenched US tech companies again and again, but they never really obtain any W's. They spent years fighting against Microsoft's bundling of IE and Media Player, and all that ever happened was that MS released some Euro-only version of a few Windows releases without the bundling. But both IE and Media Player were displaced within a few years anyway, regardless of any EU rules.
Likewise, all the GPDR rules seemed to have accomplished is that every site now has an annoying-as-hell "click here to accept all cookies" button that everyone has learned to just auto accept. I doubt Europeans have anymore actual privacy compared to the rest of us, especially since their own governments are far more interested in tracking their citizens online behavior with regard to tax avoidance, hate speech, etc - they absolutely require US Big Tech to keep track of all this info for them to quietly subpoena as needed.
Not saying they would, but maybe something to watch out for.
Edit: funny that people on HN, that should be smart enough to know about the World, imagine that everything that it's not from the USA must be automatically coming from Stalin.
Like no other place in the World has industries, it's either US products or the government making stuff.
If Apple stops selling devices in Europe I will celebrate, for us Europeans that's the opposite of something we are worried about.
We'll buy them from Samsung or some Chinese manufacturer, who cares.
But you know what is reality and not FUD? App Stores pushing legal apps out, at least people in EU could have an option when this will continue to happen.
The Apple cartel protection-racket framing makes only sense in a market without privacy regulations, in the EU choice and privacy aren't mutually exclusive.
What if a security incident happens just in Europe but not elsewhere?
Then it becomes instantly clear that Apple’s argument against sideloading was not a strawman.
Lets say it like that, and I know I am simplifying quite a bit:
Apple checks security at "compile time", during the App Store checks.
Android checks security only (or mostly?) during "run time".
"Compile time" can give good guarantees because the "compile time" can quite long. Then, during program execution, there need to be less run time checks (and a program can be much faster, by the way).
What do you think happens when allowing sideloading on Apple iOS devices? Suppose there are much less run time checks available because compile time checks are expected?
We've done everything in the client for privacy and reliability, but the obvious countermeasure would be to move functionality over to a backend. This would be history echoing the transition from boxed software to SaaS.
There are great pirate movie websites where you can watch all the movies at about the same user experience or even better but Netflix etc are doing just fine.
Piracy isn’t what it used to be but I do enjoy these sites.
The real problem is the subscription fatigue and fragmentation. I won’t subscribe to all the services and Even if I have a subscription it’s easier for me to find the movies in one place.
However apps are different, you are expected to open different apps for different things anyway. In apps, the danger could be something like ChatGPT becoming the main UI and doing everything the user wants from there.
That's not been my experience. Every time a crack appeared for my software sales went down. Every time I strengthened the licensing software sales went up. This is for B2B software, god knows what it is like if you sell to consumers.
In B2C, generally, convenience is the king.
So really what you're saying in this comment is that you've written your backend APIs with the assumption that the only user is a benevolent app which you wrote. If it's possible for somebody to take your app and tweak it to circumvent your subscription's restrictions, then what prevents a person from hooking up their phone to a development HTTPS proxy, intercepting the API requests, and making their own cracked client without side-loading at all?
Side-loading is NOT a problem for subscription apps done properly, and it's NOT a problem for privacy or security, so long as the side-loading implementation is done responsibly.
SSL pinning, essentially.
Totally true about Android--it's the smaller platform for us, but the fact we have not seen piracy there yet gives me hope.
To be clear I am in favor of sideloading, and we would benefit from it in several ways.
> It has to be noted that the research was carried out as part of Carnegie Mellon University’s Initiative for Digital Entertainment Analytics (IDEA), which received a generous donation from the MPAA.
https://torrentfreak.com/pirate-bay-block-doesnt-boost-sales...
If there's no legal option where your customers can pay you, that sure can lead to a revenue drop.
The music industries have been very slow to adapt to the internet and it has cost them some revenue, I'll give you that but that has nothing to do with piracy.
But you think that all stopped as soon as there was a legal option? Do you really think there are no people out there who can afford it but chose to pirate anyway?
I don't know why people find it so hard to believe other than they are trying to justify their own activity. Do you think the media industry spent all this money on anti-piracy activities just for the fun of it?
Yes it did https://www.riaa.com/u-s-sales-database/ , that's exactly what happened.
As soon as they added a way to receive money, customers paid, it's visible on the graph.
If customers can't pay you, of course you are going to lose money.
> I don't know why people find it so hard to believe other than they are trying to justify their own activity. Do you think the media industry spent all this money on anti-piracy activities just for the fun of it?
It has more to do about content control than money. Guess who benefits the most of stricter copyright rules? The RIAA, MPAA and similar organisations, it's a conflict of interest. Being harsh on piracy is easier to sell than just "give us more power because we deserve it"
Some customers paid. What I'm saying is there are a significant number who could pay but won't and the harder you make the piracy the smaller that number will be.
And music piracy isn't any harder than 10 years ago, it's using the exact same tech.
The only thing that changed is that now there's a way to pay for music legally online, which wasn't the case before.
The lesson to learn for the music industries here based on data is that customers will pay if there's realistic service they can pay for, if they don't have a way to pay for music, they won't get any money. That sounds obvious but now we have the figures associated showing that.
I personally agree with Apple’s stance. I don’t want developers of popular apps to be able to bypass Apple’s reviews and push dark patterns on users.
Before anyone talks about choice, I see this as akin to minimum wages and union memberships. There are some limitations of choices that often end up being beneficial to the average person. From the point of view of the user (if not the app developer) Apple’s walled garden provides me what I want.
If I wanted something more open, I would have gone with Android.
I am happy that Europe’s short-sightedness will not affect me.
They just have to make it hard to install apps outside the store, then apps that don't follow Apple's model won't get much of an install base and will have to comply anyway in the end.
Also, Android users seem to be discriminated in America for some reason (the green/blue bubble BS) , so the choice between Android and iOS is not as free as it seems.