> Here in Thailand banking apps fraud is rampant
Citation needed (on the "rampant" part).
> Most of the cases are found to be on android devices
Even if it's true most of the phones in Thailand are Android.
> clicking some link that installs some app
Not possible the way you describe it. You need to go through several system screens and popups to install a third party apk file from browser.
> takes control or mobile banking and transfers money from their account
As an app developer I can say, this is probably false. There is no API to do anything like that. Unless we are talking about a 0 day exploit, like iPhone NSO exploits. In that case you need to provide a source.
Let's check your source https://www.nationthailand.com/thailand/general/40024972
They are sending detailed instructions to victims on how to install screen recording apps. Users are always warned if their screen is being recorded on both Android and iOS, sideloaded or not. It's a matter of false trust, not sideloading. It's a phishing attack, those people would fall victim in any OS.
- https://www.bangkokpost.com/business/2524469/mobile-banking-...
- https://www.nationthailand.com/thailand/general/40024972
Enjoy!
And it's not like people with iOS are resistant to being scammed - there are hundreds of ways criminals can dupe you to sending them money, the invoice scam being the simplest example and it doesn't require any special apps.
[0] https://www.nationthailand.com/thailand/general/40024972
Also your comparison of people 'working on their own cars' is a bit off here. Most people buy cars to drive, and give the car to the mechanic to 'work on'. It's much much harder to repair your own car than to click a link that can scam you.
>>You should read this article[0]. It outlines clearly that victims are downloading .apk files
I feel for the victims but I literally don't see how that's an argument against sideloading.
I do understand that sideloading is something desirable for some percentage of people.
Point is every thing has pros / cons. Sideloading is like buying a car and upgrading it with NOS. Yeah it's wonderful. Your going to have a very powerful car. But the risks also increase. Most people don't need NOS in their car.
I'm speaking for most people. In my household I recommend everyone to use Apple devices, it keeps them safe and happy.
Ultimately everyone is entitled to their own choices and have to accept the consequences. I guess we'll have to wait and see how it plays out now that it's coming to iOS 17 in the EU.
No, sideloading is freedom. Imagine that car manufacturer put a part in your car that only works if: * watch ads or pay $ every month * collects all your information * has fake freedom to install only parts from their store that follow previous two points * extorts authors of parts for 30%
all while smugly saying "take it or leave it".
Do you have some relevant sources about banking fraud? Android devices make up more than 70% of Thailand's market share [0], so it's not a surprise.
[0] https://www.statista.com/statistics/814490/market-share-mobi...
Also, the government mentions that the scams affect users of both platforms, because the scams propagate via calls, web links and emails that ask for personal information[2].
[1] https://www.bangkokpost.com/tech/2487659/phone-users-warned-...
[2] https://www.bangkokpost.com/business/2499931/online-scammers...
I'm not saying iOS is 100% bullet proof. I'm saying the problem is much more manageable without sideloading.
> Right, but for Apple to take down those apps, it's much easier than taking down some random link the fraudsters put up.
Seems like the issue here is that the government has to tell iOS users not to install specific apps because Apple hasn't taken them down. I'm sure it's easy for Apple to do what it wants on the App Store, the issue is making them care. They have a history of letting multimillion dollar scams flourish on the App Store[1].
[1] https://www.theverge.com/2021/2/8/22272849/apple-app-store-s...
The banks then reply and say “the fraud transaction originated from customer’s device”. When you look at the screenshots of victims giving example it’s all Android as far as I can see.
Generally after talking to the banks and customers discover that it was their own fault for clicking on a seemingly harmless link they shut up and go quiet.
This is a story that plays out often here.
I don’t particularly have a link because these cases get deleted from social media (by the customer themselves) after the bank has proven that it’s the customers fault.
Edit: You can try searching the internet for “mobile banking fraud Thailand” you’ll find these links, here is one example.
https://www.bangkokpost.com/business/2524469/mobile-banking-...
Edit: here is an example the article mentions downloading of .apk on android
Each year the central banks up the ante on security protocols to implement to stop the fraud. I should know I used to work for a finance app here in Thailand.
We have to go through strict security audits, and procedures that costs a lot for any financial institution to implement.
Doing 2 FA is already a mandate for doing transactions. However 2FA in Thailand is mostly done using SMS which is still not that secure.
Forcing everyone to use a token or a 1Password app is also not viable since that’s going to shut a lot of people out of mobile banking.
It’s a complex problem, which I think Apple has already solved. Disabling sideloading reduces so much costs downstream and made things simple and secure for the lay man.
Guess what happens currently on iOS instead? Instead of installing a custom app, you are sent a link to log in to a dodgy bank page with all your details with the exact same result.
>>Disabling sideloading reduces so much costs downstream and made things simple and secure for the lay man.
I don't believe this is the case, and I really believe any arguments otherwise are made in bad faith to maintain the status quo because obviously apple could never do any wrong.
How?
Tokens embedded into your app can and will be extracted. You can make life harder for criminals by rapidly updating tokens and invalidating all but the last X updates, but I doubt your users are going to like that, and I doubt criminals will be stopped for long with the amount of money at stake.
There are ways to make it incredibly difficult for hacked apps but if the file ends up at a user's device, you lose control.
>>that'll just create a market for pre-jailbroken devices.
I don't understand - people will get pre-jailbroken devices so they can be hacked easier? The whole idea with forcing apple to allow sideloading is that you can be on the very latest, most secure iOS version and sideload apps.
Not to mention that iOS apps keep those kinds of secrets in the Secure Enclave and you can't get anything out of it unless you are the app that put the secret in there in the first place - that doesn't change whether apple allows sideloading or not. If you need a jailbreak to break that protection then this isn't something that will affect your "normal" user like many here are worried about. Normal iOS protections will be more than enough.
This is irrelevant because banks need to support people using older versions of iOS as well.
> Not to mention that iOS apps keep those kinds of secrets in the Secure Enclave
iOS doesn’t store tokens in the Secure Enclave. It can generate keys and use them to sign things, but keys and tokens are different things. The Secure Enclave isn’t a generic secret store, it has very specific, limited functionality. Are you perhaps mixing it up with the keychain?
Also, you didn’t answer the question:
> What kind of token? How does it obtain it?
It’s still unclear whether you are thinking of a static token bundled with the application or a per-user token obtained during first use. In the former case attackers can just download the IPA and extract it themselves without even thinking about attacking a user’s device. In the latter case, you need a mechanism to distribute tokens to untrusted devices, so that is the most likely entry point for an attack, not trying to obtain an existing token after the fact.
What kind of token? How does it obtain it?
Any way to circumvent this requires app isolation to be broken somehow.
Also, I wouldn’t personally describe an out-of-band token delivery / exchange mechanism like that as “actually trivial” for apps to do.
I’ve seen even the most educated tech savvy people fall for these frauds. So I would say “educating people” is insufficient.
Another problem is because the law works extremely slowly, by the time any legal action can be taken to take down the destination bank accounts the fraudsters have already gained and taken the money.
Sideloading is the thing that works because the legal infrastructure simply can’t keep up with the fraudsters.
I would be inclined to agree with you if I know that the legal system immediately stops fraudsters and returns the money to the people without damange. We’re far from that.
https://www.osha.gov/etools/machine-guarding/presses/two-han...
https://en.wikipedia.org/wiki/Lockout%E2%80%93tagout
> educate people on proper online safety measures so that they don't fall victim to fraudulent attempts.
This is so inefficient and prone to failure. You think you're an expert, but my mom is not an expert. I don't want to educate my mom, I want to just hand her something that's safe to use.
It's close to impossible, that my mum figures out how to install an untrusted apk on her Samsung s22.
I guess what I want to say is: Having good security should not prevent you from installing custom software if you want to.
The side-loading debate is an indirect reference and to talk about side loading it must first be decomposed.
Question 1 is should Apple be able to prevent an engineer from running software they want on their phone? Probably not.
Question 2 is should Apple be able to prevent a layman from running software they want on their phone with effort? Debatable.
Question 3 is should Apple be able to prevent a layman from running software they want on their phone easily? I think so.
Question 4 is should Apple be able to prevent an alternative app store? Yes. Definitely.
So should side loading be allowed depends greatly on which question a person is asking and what the "sideloading" reference is pointing to.
Should I be able to choose what medicines I want to take without a pharmacist/MD? I have a hard time with this because I think I should be able to ingest whatever I want and I think I am more intelligent than the average person, on the flip side, I think if I were a pharmacist, I would say absolutely not. If you asked me if anyone should be able to take any medication they want without blessing, I look at the ivermectin debacle and realize "probably not."
> https://en.wikipedia.org/wiki/Lockout%E2%80%93tagout
Not sure what those links are supposed to show, but having safeguards and completely disallowing something is a different matter.
If all, you're just proving parent's point.
Lockout/tagout is a technical prevention which restricts other people from messing with a system that could endanger you. Education was not enough.
A monopoly app store is a technical prevention that restricts someone from running un-vetted software that could potentially steal your life savings or compromise your entire digital life. Do you think education is enough?
I am not saying that that is true or correct, but I do think that's an argument that someone who disagrees would have to take in good faith and respond to satisfactorily.
That's what "Are you sure you want to enable sideloading?" toggle is.
> Lockout/tagout is a technical prevention which restricts other people from messing with a system that could endanger you. Education was not enough.
That's what OS is.
> A monopoly app store is a technical prevention that restricts someone from running un-vetted software that could potentially steal your life savings or compromise your entire digital life. Do you think education is enough?
A monopoly app store is a technical prevention that restricts someone from running un-vetted software that could potentially prevent monopoly app store revenue or god-forbid bypass DRM. So what?
And App Store absolutely does have malware https://lifehacker.com/great-now-the-apple-app-store-has-mal.... If it's not even 100% secure then it's not worth sacrificing my freedom to choose.
If you want to achieve something that you think sideloading is the only answer for then maybe try and find another solution? Btw. I’m not arguing we shouldn’t educate people about the dangers of phishing etc etc. just that engineers should find better solutions than shortcuts.
Some people will never understand the need to be vigilant. And even vigilant people have momentary lapses of vigilance.
[edit] i think we’re talking about deliberate sideloading but also accidental sideloading in the same breath here. One enables the other? Accidental sideloading is very much undesirable.
Right, which is why operating systems ship with security and sandboxing features. Security does not require an App Store.
With these kinds of security problems you need to decide where the restrictiveness is best for society and I would very much argue that in the case of phone security it's on the side of sideloading.
> safety interlocks
That's what sideloading switch is.
but on the other hand I already saw people trying Linux and being surprised that after multiple confirmations "this is probably a terrible idea, are you sure" it broke their systems
... and people just click though it without reading, because it's UX 101 -- nobody reads your texts, manuals and things while in the flow.
Sometimes it's a good idea to don't let people do something for their own good.
Never? So, no laws against speeding, no restrictions of the use of DDT, etc?
I think that, to make electronic devices usable for all, we have to restrict what they can do.
> Instead, we should strive to educate people on proper online safety measures
I would say “in addition”, not “instead”. I think it’s a pipe dream we can educate the majority of the population and keep them educated in these things.
Even if we restrict that to the tech savvy, they too grow old, can have periods in their live where they’re so stressed that it limits their thinking, can get mild dementia, etc.
> I suspect that the EU will regret forcing Apple to enabling sideloading when the number of fraud cases go up.
Maybe some degree of that is worth it? The functioning of digital markets and preventing platform monopolies seems very intrinsically valuable for both ethical and economical reasons. Moreover, it's highly unlikely this will be in some cartoon situation with some massive explosion of fraud.
What if this is just a small price worth paying? Something we need to accept in our lives and help further focus education efforts? That seems like a more valuable discussion than most of the discussion going on in this thread.
clicking a dodgy link can download an android installer file (.apk), but installing .apks from unknown sources has to be explicitly enabled in android security settings (twice in latest versions) following warnings about trusting the link source and possible damage
it's not as simple as downloading a dodgy .exe in Windows and clicking 'yes' on the UAC prompt
whereas sideloading is intended for developers when testing and debugging apps. this involves enabling Developer Mode in android security settings, connecting to your phone via USB, and issuing sideload commands from a console
Meanwhile, Apple is likely still going to require sideloading to have a valid Notary certificate, which is bound to a root CA, meaning that Apple can handle some amount of validation of certificates and revocations.