That said, other commenters are pointing out a very large revenue figure relative to the popularity of these apps. That smells more like money laundering or fraud. In that scenario, Apple should have been more specific in their communications.
That said, other commenters are pointing out a very large revenue figure relative to the popularity of these apps. That smells more like money laundering or fraud. In that scenario, Apple should have been more specific in their communications.
I guess the App Store fraud prevention team hasn’t necessarily found a good solution yet.
0: https://youtu.be/tJeEuxn9mug?t=22m57s&si=CVfkqSqEULyFTx-8
The most essential device of the century is owned by two companies. The ability for them to completely control software and business activities on top of something that is almost as essential as public transportation is appalling.
The DOJ needs to remove the "app store" racket for essential computing devices. Software needs to be freely installable, sans vendor control, unfair competition, scare tactics, mandatory taxation, and adversarial ad placement by the cellphone duopoly.
Not only is cell phone compute freedom essential, but we desperately need more than just two vendors.
No stores. Web install. Web first class. No "only Safari/webkit engine" limitation.
If Apple is so genius, they can solve malware with all of those engineering minds and dollars they have. They don't need to hind behind a store to do that. The tools and techniques are readily available and accessible for a company of their size and stature.
Permission layer, app runtime heuristics, and fingerprints are a start. They can do this. They just don't want to / have to, because they're currently Gods of the Phone Universe with unfettered and completely unfair control over "their domain".
And the threat surface of the iOS sandbox is so large that it’s impossible to secure everything everywhere the first time. Every iOS jailbreak since at least iOS 10 starts with a sandbox escape exploit and executed via a sideloaded app (besides the single hardware exploit found in recent years, checkm8)
An App Store with a human review process is one tool in the toolbox.
> Permission layer, app runtime heuristics, and fingerprints are a start. They can do this.
I think this is Google’s approach. How’s that been going?
How does that work? If it's open web download and install with no notarization (because that's also gatekeeping) then we're back to the good ol' days of the 90's and early 00's. In other words, anything goes and it's up to the user to keep themselves secure, which in practice means rampant security failures and users getting scammed and hit with ransomware at every turn.
I don't like Apple having so much control over everything. I really preferred the old days of the web and the anything goes, full control over my computers I had back then. But the web is absolutely way nastier today. It's jam packed with scammers and ransomware gangs and botnets. It's really quite sad and frustrating for anyone who grew up with the full potential of computing.
A lot of the solution is just not to install random shit out of app stores, and to install software that has a good reputation (and use adblockers on search engines like google so you don't click on trojan ads).
If you scroll down to the 10th page of the listings for 2048-clone games and install something at random you're probably going to get hacked.
They installed some kind of DNS redirector, so, when he thought he was contacting Apple, he was actually talking to a scammer.
Their customer service was great, which I told him, should have been a red flag.
In any case, he was able to extricate himself from the scammers, but not before they had grabbed a bunch of PiD, so he’s still dealing with the whole identity theft issue.
Not sure how he got owned. Likely, some drive-by malware on a Web site. He basically uses Safari as his operating system.
An insurer/ health insurer, employer, government, etc will require it, and just like that the "just don't use them" crowd will hold up their hands and pretend that no one could have imagined this disaster.
If the problem is truly Apple exhibiting favouritism or limiting competition through their app approval process: then the EU should have just forced them to spin it out into an independent entity for the EU stores, or even take control of it themselves - but they didn't and 2024/25 is going to be a shitshow for it.
Legislating for side loading and multiple app stores is the least imaginative and most obviously flawed approach to the competition problem and the sole reason why Android's share of malware is staggering in comparison to iOS.
You’re making a very simple issue way more complicated than it needs to be. Having Apple spin out EU specific new corporate entities with unclear relationships to its parent company sounds extremely complex.
Requiring Apple to allow people to install apps they want on their own device is pretty simple and should be a fundamental expectation of a free society.
If normal user wants the walled garden Apple experience, that’s fine. Make it unintuitive to install third party apps. Require checking a big red disclaimer that you might brick your phone. But just have some sort of path where if party A made an app and party B wants it on the device they paid a lot of money for, they can do that without some unqualified drone in Cupertino blocking it .
Countless examples of the App Store review being broken , and just on principle, Apple has what’s effectively a monopoly on mobile phones in that you can’t make a mobile app and ignore iPhone and for them to unilaterally decide all software that’s allowed is way too much power.
Somehow Microsoft went to the Supreme Court for putting IE on the desktop but Apple is off the hook for a complete lockdown. At least you could download Netscape on Windows 95! What Apple is doing is like if AOL and AOL keywords became the only entry point to the web. Then you go on Hacker News and people say that’s s good thing because AOL only allows quality websites and otherwise people make malware and scam websites. It doesn’t matter, it’s too much power for one company and mobile phones are more critical to society in 2023 than the web was in the 90s. Mobile phones are not appliances.
It’s still unfathomable to me this is even a conversation on this website. Apples complete lockdown of the most important computing devices is plainly bad for consumers and society.
It's interesting to me that your core argument is about making a choice whether or not to embrace side-loading and 3rd party app stores. However aren't users making this choice when they buy the phone to begin with. Side loading and 3rd party app stores aren't a secret, many Android manufacturers use this as a selling point and include their own stores baked-in.
I'm somehow to believe that users are simultaneously clever and dumb - and I'm not buying it.
Or how else do you claim there is two sides here?
Pretending that Apple is protecting consumers is silly, they have repeatedly said internally the lock is for revenue alone. No claim of security protection has lasted past "wouldn't sideloaded apps be sandboxed the same as App Store apps and thus have the same security overall"? (Apple failed to counter that point)
That's clearly not what is written, don't invent a false narrative with your lack of comprehension skills.
Also going to need a citation for this beauty:
>"they [apple] have repeatedly said internally the lock is for revenue alone"
But judging from your reading skills earlier, I don't have confidence in it being forthcoming.
The reality is the author dismissed Apple supporting side loading as fundamentally impossible in a thread talking about how Apple should offer more choices.
Calling users dumb for wanting side loading on Apple is ridiculous on its face. Users didn't choose Apple to side load they might have sacrificed side loading to get Apple but calling them dumb for making a choice is ridiculous.
Apple makes $86 billion from the App Store a year. That is a quarter of their revenue from iPhone sales. No shot a 25% increase in revenue with phenomenally higher margins isn't of extreme importance to Apple.
They got in their head that users were stupid for choosing Apple when they wanted side loading but that isn't stupid in the context of "should Apple allow sideloading".
I'll support any sideloading regulation that includes all of these protections. As it stands this is only a law in some countries/regions and certainly not something everyone will be protected by if they happen to be outside of EU (and maybe US) jurisdiction.
If my company is mandating the installation of software on my devices, I'll request a corporate device and assume the company has root access on said device.
Employer installed apps is a use case Apple officially support.
On Android where alternate storefronts are a possibility, I have yet to be made aware of a single instance of this happening. Not even Epic in their crusade against established mobile stores made its' own platform.
1. You're not looking very hard, surveillance ware exists for employment, examinations and so on. It's not available on iOS, but is available on Android via side loading. Both Facebook and Google used iOS certificates to side load tracking apps onto iOS for regular consumers. Even rental cars brands have utilised surveillance software to track speed and apply fines. The more you dig here the more you find: it's not some outlandish concept.
2. The inability to run such types of software on iOS prevents these approaches from moving forward across the industry. Much the same way that QR codes weren't widely utilised until both Android and iOS supported it.
That's doing a lot of work. There's "... to be usable" but also "... to be automatically and unfilterably merged".
They are very different situations. What specifically are you concerned about? I'd guess that latter but you seem to be defending the former as though it is the latter.
Have we visited the same appstore? Just few days ago I tried to find a puzzle game for my kid and myself to play together. A whole bunch of them, from top results, resulted in games which had shady dark UI initial screens trying to get to $14.99 or similar monthly subscriptions. Eventually I caved in to arcade sub because I couldn't trust any of the results or find a normal paid one (once). Scammy at best.
The crApp Store is full of scams. https://www.washingtonpost.com/technology/2021/06/06/apple-a...
https://www.wired.com/story/chatgpt-scams-apple-app-store-go...
https://arstechnica.com/information-technology/2023/02/pig-b...
https://www.forbes.com/sites/gordonkelly/2021/05/15/apple-ip...
https://9to5mac.com/2022/01/11/developer-exposes-another-mul...
There's practically endless proof and documentation for this.
The App Store is actually a honeypot for scammers. It's a single point of failure, because once you get past app review, which is easy, you're home free, and it's also relatively easy to manipulate App Store search, App Store ratings and reviews, and App Store Search Ads.
As a non-scam App Store developer, my biggest problem is discovery, i.e., getting my app in front of the eyeballs of potential customers. It's vastly easier to do that in the App Store than it is via so-called sideloading, especially if you have no ethics. (Unfortunately, I do have ethics, which significantly limits my options for discovery.)
Your logic states that because an app can occasionally slip through the review process, that we should remove -all- protections. That isn't better, that's worse.
A scam is also a relatively low bar to set for such drastic change, since scams also frequently occur over chat apps and the kinds of access that side-loading and 3rd party stores can avail opens the door to significantly more sophisticated malware. If you truly think the situation right now is bad, just wait until there are no protections for users.
You should also recognise that there is actual data for malware on these platforms. Every year Nokia drive home the same point for why Android has such an outsized share of malware: "...most smartphone malware is distributed as trojanized applications and since Android users can load application from just about anywhere, it’s much easier to trick them into installing applications that are infected with malware."
Since all experts point to the same sources of malware - perhaps that's not the change we should be legislating. How about we do something different.
I know that this system may be unattainable for some, namely children, the elderly and the intellectually disabled. But maybe we shouldn't be designing general purpose computers around the lowest common denominators of society, for the same reason you wouldn't design a car for the legally blind or a book for the illiterate.
The nature of smartphones and the internet has some pretty large consequences for the economy, politics, war, and global surveilance. I understand that some people don't know how to manage their own computer, but if you really think everyone's computers should be controlled by dictators and buerocrats maybe you should just go live in a third world country instead.
Then the consumer can make that decision for themselves.
Your position here seems to be that consumers are too dumb to make that decision, but clever enough to fend off sophisticated malware attacks. You are even so gracious to note that perhaps this might be out of reach for ordinary users (well done you! you nearly got there)
If only there was a large and popular platform of devices with side-loading and 3rd party app stores available for us to already see the consequences of what this change does to malware rates. Let's call this hypothetical platform "Android", and then a well respected security report, say by Nokia, could include statistics about this "Android" malware.
Well, you're in luck dear friend! Actual security experts state: "most smartphone malware is distributed as trojanized applications and since Android users can load application from just about anywhere, it’s much easier to trick them into installing applications that are infected with malware". (worth stating twice because I don't think it sunk in the first time.)
So real security experts are advising the opposite approach from you, funny that.
As for a 3rd world country, maybe you should run one since you have the ego of a dictator.
I think somehow Apple found a way to group both limited intellects and intellectually dishonest. This way the second group can pry on the first one and they seem very happy about that.
If you were to listen to them, every windows PC is infested with malware, yet even my grandma that is over 80 years old operates a windows PC without much trouble. She doesn't install nonsense and ask competent people about stuff. Which is exactly the kind of relation Apple wants to steal. So they can charge a lot of money for it, making people dependent so they are fragile. And when they have no other choice anymore, charge as much as you can. Classic sociopath behavior...
If you need to strawman the opposing point of discussion. Then you don't have an argument, instead you're the fanatic.
On top of the strawman nonsense, you attack me as naive. You said the previous poster he had the ego of a dictator. If there is someone who needs to rely on something else than reasonable argument (personal attacks) that's clearly you. It's rather funny because you illustrate exactly the point I alluded to before: intellectual dishonesty.
Well no, the appstore is as full of scams, malware and adware as everywhere else.
They managed somehow to convince people it's a safe space though, not sure how but I consider it a bad thing since people are more likely to trust it blindly.
> such as people at higher risks of being targeted by nation state actors
https://apps.apple.com/us/app/absher-%D8%A3%D8%A8%D8%B4%D8%B...
The Saudi Arabian app to track what your wife is doing is still on the appstore, no need for a thirdparty store.
While I usually don't like the saudi system but this app in particular is about making it easy to manage official government paperwork online [1]. This applies for all residents (citizens or not) and people really like it. So it is not an app to track females movements. While you can disagree or agree on the male approval requirements for a female to travel (I disagree) but it is not like it tracks movements using GPS or any invasive data. It just make it easier to manage the permits and all other interactions with the government without having to drive long distances and wait in lines.
Well as a complete outsider in another country who probably never went to Saudi Arabia like yourself, I would be more careful.
I'm open to some kind of argument like "apple has no choice in such dictatorship" but this argument is contradictory with the argument that its protecting from nation states.
And since we mentioned Saudi arabia, we can also mention China where icloud is dodgy, it's not a unique case. I'm sure they are others I don't know about.
This is one service among all other government interactions services that the app provide. If the app is not here. Women still need to get male guardian approval because this is local law. You can disagree on that matter (I am not defending or debating it). I was just clarifying.
And yes, apple has to follow local laws. The app doesn't collect privacy invasive information used to track movements as your comment suggested. And it is not required to be on your phone.
Android allows third party app stores and it is not a significant cause of problems. I am sure there must be some bad app stores out there, but the well known ones like F-Droid are probably better curated than Google's own.
Linux has always allowed third party repositories. Again, rarely a source of problems - again, there must be some bad things out there but the percentage of users affected is tiny.
If you bought an iPhone because you wanted protection from the purported dangers of third-party apps, then ... just don't install any...?
These alternative app stores will be infinitely more trust worthy than apple, amazon, google etc
If there is no payment or the trial is canceled one could use the digital id.
Apple could even gather some simple statistics. Opening the app and using it for 1 minute would be a special kind of review. You wouldn't count 1 star reviews like that until manual review-review confirms the app is really that bad.
Refusing other users the freedom to run the apps they want without Apple's permission just because you might get mildly inconvenienced by it seems very immoral to me.
People could pay Apple to vette sources to indicate that software therein isn't malware even if it doesn't follow other Apple standards.
Anyone maximally concerned would just only use Apple sources. If Apple was less onerous about trying to get a cut most major software would be in the official store. Say a 5% cut.
Remember at one time the manufacturer trying to get a cut of the action on a device was rightfully absurd.
Your oven doesn't refuse to bake a pie unless Betty Crocker cut in GE nor did Magnavox require a cut from blockbuster.
Both could be implimented for your protection and both would have been protection rackets. Apple's arrangement is as well it's just that the mob actually oversees permits too and charges on the way in.
If you could trivially use only official apps and most apps would be available as such how would you be harmed?
Android phones can have alternate appstores, and yet we don't see widespread malware, fraud etc from that.
https://www.forbes.com/sites/ryanwhitwam/2018/08/25/epic-gam...
And then
https://www.komando.com/security-privacy/ratmilad-android-ma...
As long as people play along, yes it is indeed.
If more people were installing a free mobile OS, and thus take back ownership of their hardware and digital lives, the story would be much different.
It's the same story with PCs. If you actually want to control the hardware you own, install Linux. It's not as if the alternatives to corporate control didn't exist.
The fact is most of the stuff that makes phones what they are, is hidden behind closed hardware and firmware. Even Android, which as you know is Linux, has closed binary blobs in its kernel tree.
You can get away with that somewhat for devices like the SoC on the Raspberry Pi. But things get a lot more complex when half the stuff that makes your phone usable is closed hardware and firmware blobs. What you ultimately end up with is still a device you don’t fully control but with the added inconvenience of a less mature software ecosystem too.
I don’t see this problem being solved any time soon. In fact quite the opposite, I think it’s getting increasingly difficult with each passing year.
The problem with binary blobs is entirely a corporate one. And frankly I don’t blame them for wanting to keep their products closed. I makes complete sense for them to do so. Really this is no different to nvidia keeping their GPU drivers closed. Except you can still have a functional laptop without Cuda, whereas you cannot have a functional phone without the ability to connect to cell networks and make phone calls.
They exist, but break my touchpad upgrading to kernel 5.19 from 5.15. I'd rather pay for something locked down than something that breaks.
https://bugs.launchpad.net/ubuntu/+source/linux/+bug/2002356
I think people would if there were a viable free option.
Also it isn't easy to find good mid-range hardware. I bought HMD(Nokia) for years but then I spent 250 on one of their new models and the phone was absolutely unusable (laggy UI).
Having to research models and software versions of CyanogenMod every few years just wastes my time. And then run into issues.
Plus security matters to me.
Microsoft failed to enter the market with billions spent - it isn't an easy problem.
Meanwhile on iOS the best we seem to get is the EU Digital Markets Act setting some rules for fairness on the big marketplaces.
Ah, that was news to me, so Amazon Vega is predicted to be some sort of immutable OS with web apps. It seems they are thinking of starting some Chrome OS resembling thing. iOS also intended to only have Web apps and look where we are now. I don't have high hopes for OS developed for Fire devices, it will be soaked in DRM and filled with ads.
Let's imagine there's a company called Ticketmuster that had a monopoly on ticket sales. If they tolerate a shitty little kiosk selling a score of tickets a day, does this mean Ticketmuster does not have a monopoly share of the market?
I'm not sure that adding more would make all that much difference. One player would have absolute pricing power. Two keep one another at least a little in check.
That assumes no collusion, and that's not entirely true, by not completely false either. Many cases of similar behavior are just them responding to the same market in similar ways.
I think that completely free and open player you want isn't going to be much of a competitive advantage. It has a small niche but not enough to break into the insane levels of overhead in creating a complete ecosystem. Especially since most users just want the device to work with a minimum of grief. And especially since the use of public airwaves means a ton of regulation.
it became a strategy to copyright strike your own app, have proof ready so that no downtime was necessary, then you have the temporary immunity so that competitors couldn't submit a copyright strike, which costed them nothing to do and had no consequences if they were wrong about it
That the author hired somebody to dump review, does something fishy with money like those above noted, and then sues for more money.
Levine over at Bloomberg had an interesting article where ransomware gangs are now filing SEC reports, as a way to pressure companies to pay, or minimize ROI.
Not every streamer knows that they can forward such threats to Twitch's support staff, and if they don't, their stream is at risk from automated bot detection penalizing them.
And it shouldn't be Apple's problem. Apple is not a court of law. They have no business knowing about their developers internal affairs, imagine the conflicts of interest. This is a matter for an actual court of law, that can issue warrants and subpoenas, where perjury is a thing, where there is fair trail and where you can ask damage and the guilty party get charged for fraud. You obviously don't want to give these powers to a private company.
But yea, if you're a business that makes money promoting other people's content then you're responsible for that content. Similarly, I'd argue that a skywriting company that writes libel in the sky should be held responsible as an accessory to the client if they were aware the statements were libelous.
A company at Apple's level absolutely doesn't see "frozing $100K" from random devs (or the amount that would result in aggregate from all those freezings) as a profit center.
But Apple doesn't care, because it relies on shady apps for a significant part of App Store income.
So the decision is "Do we make significant money from addictive games and scams and tolerate the occasional false positive that nukes a legitimate developer? Or do we spend significant resources curating an App Store full of quality apps and no noise, with high quality support for devs with problems?"
Guess which one of those is going to bring in significantly more money.
This has been going on for a long time.
Developer good will lost? Then they can just go to the other iOS store to sell there apps, oops.
Google can’t figure out how to make money without ads, so they punish people (blocking ad blockers on chrome and not allowing access to YouTube if using an ad blocker) because of their own failure.
They can and they have. YouTube Premium exists! You can pay for it!
The two business models that are feasible for YouTube are (1) free and you have to see ads and (2) paid and you don’t have to see ads. They offer both. I don’t think it’s reasonable to expect to be allowed to pick (1) but opt out of the ad side of the bargain. Their ad-blocking shenanigans are obnoxious, but it’s disingenuous to claim that they “can’t figure out” how to monetize YouTube without ads when they actually do provide that option.
Lots of people have called me a "sucker" or worse, a Google shill, for paying money for a "free service." These same people then turned around and threw a temper tantrum when YouTube started detecting and punishing ad blockers.
I think after years of enjoying a free service people have become extremely entitled about it.
YouTube created this mess. Under the disguise of "free money" they attracted all kind of creators/organisation lured into a video hosting platform (something that is expensive to do at scale) under the unsustainable promise of "we host your stuff for free and you can even make money out of it". This removed most of the risk for launching video production activity but also killed diversity of potential business models and alternative sources/technical solutions. Now both parties are extremely greedy and want even more money because somehow, they think they have a captive audience. YouTube shove more ads and creators shove more sponsor bullshit. They are the ones full of shit, it's not the people requesting a fairer deal that are entitled, you have it backward. I used to watch YouTube completely with ads up until 1-2 years ago; it just became unwatchable and pretty much every "creator" has some sort of ad in the video anyway.
It's particularly disgusting because in general those are people already making 3-4 times median/average wage with complete freedom and what would be considered low output in a traditional job paying way less. Like most tech companies, YouTube enforced winner take all feudalism and single source for maximum control on the market.
If those creators had started their own website with their own hosting and figured out a way to monetize this (subscriptions, their own ads with sponsors, products, etc) and actually taken any risk to start (like pretty much every single business has to) we would not be here.
It's a situation entirely created by dishonest representation of reality and then trying to impose rules by force to extract even more money. If YouTube needs more money to run, they better ask the creators placing ads all over their content to pay for the bandwidth/views. It's completely wrong to blame AdBlock users, they alone created wrong incentives and they alone are the one responsible for all the monetization shenanigans/cheating going on...
As far as I'm concerned, I'm pretty happy they are going at war with AdBlock, because we will see what's what. It may open up opportunities somewhere else, because I don't see people paying for Premium and I don't see people sticking around with so many ads. People's attention is going to be redirected somewhere else (free or cheaper content exists, starting with the public library or TV) and we may get something better out of that.
The problems with youtube are not the victims fault. It's fucking garbage.
Honestly, Youtube is probably the service I'm most happy to pay for. Could it be run better? Probably! But it's still great.
No they haven't. YT Premium price goes up by a significant amount each year, without a corresponding increase in value. That's not a business model, it's an experiment to see what the profitability price point is.
If they knew what it was, they could go Netflix and make it paid-only. But then they'd lose out on all the sweet sweet ad revenue which apparently still doesn't cover the bills.
Since they haven't reached it, and since 95% of their audience still accesses it with ads,
It’s not a company I’d ever do business with.
All these stores are basically little monopolies with zero incentive to not suck. They also suck from a user point of view. Search is terrible, they’re full of shovelware, etc.
No experience on Steam but a few indie-game devs I know think it's OK. I've not heard them complain like App-devs on those phone-stores.
https://www.pcgamer.com/valve-takes-steps-against-steam-revi...
I don't think it's unreasonable to flag that.
IMO this is directly due to Gabe Newell's leadership. Taking an attitude of "piracy is a service problem", and proceeding to offer such a good service that it's preferable to pirating, results in a great service for everyone involved.
Whether this will outlast GabeN's tenure as CEO remains to be seen, but for now my understanding is that both users and developers are overwhelmingly happy with Steam.
My favourite way to phrase this is that "steam is the most anti-piracy store available. With piracy, you play games you didn't buy. On steam, you buy games you never play."
And Valve saw that coming some time ago, and invested in making both Steam and the games sold through it run on Linux.
Honestly, it's up to Apple to moderate the reviews and detect review farms. If posting fake reviews is all it takes to take down my competitors out of the store, it's game on.
Often AML policy prohibits this because it could be constituted as tipping off the offender.
It sucks because people who have been clearly committing fraud then plaster you with negative reviews and sob stories but casually fail to mention it was their own egregiously fraudulent activity that caused their account to be shut down.
And it also sucks because people who may not have actually done anything wrong get caught up by these controls sometimes and have effectively zero recourse.
In that scenario Apple is highly constrained in what they can say.
Does Apple get to decide this, and just keep the money, without involving any court of law? Someone mentioned anti-money laundering laws and secrecy, but can that manifest as losing your money, without trial or even being informed that you're accused of anything? That would seem to violate a few constitutional rights.