App store to be 'split in two' ahead of EU iPhone sideloading deadline: report
macrumors.com
macrumors.com
"This app came from a third party, it can download all your private information and has not been reviewed by Apple".
Pop a warning every single time it accesses contacts or location, don't allow third party apps outside the App Store to be granted ongoing permissions to anything, etc.
They can still do a lot to make the third party App Store experience much less appealing to developers than the App Store path and still be within the letter of the law. And I'm sure they will.
(amusing side note, every time I write App Store autocorrect keeps capitalizing it for me)
But then why wouldn't EU later consider those high-friction "warnings" and security firewalls to be anti-competitive because it doesn't let 3rd-party apps be on equal footing as Apple's Official App Store?
Is there precedence from previous rulings analogous to this Apple situation to predict what EU would pursue depending on how Apple follows the "letter of the law" instead of the "spirit of the law"?
Why would you consider it "anticompetitive"? I think Apple has a good claim that this is a factual statement that is used as a security warning as a core OS feature.
Google have something like this when you sideload (or allow sideloading option, don't remember exactly when you get these warnings) and EU did not consider it "anti-competitive" (at least yet).
I would hope that the technical protections protecting user data apply to all apps and not just apps that come from Apple's store. If an app from the store wants to access your contacts or your location, the user has to approve it. Should be exactly the same with side loaded apps.
Vender lock in such as a core operating system feature that can only be accessed with Apple approved apps would be blatant anti-competitive behaviour.
> Google have something like this when you sideload (or allow sideloading option, don't remember exactly when you get these warnings) and EU did not consider it "anti-competitive" (at least yet).
The EU and the USA have both found those warnings to be anti-competitive. In the EU's case, they have the same deadline as Apple to fix it. In the USA, Google was recently fined several hundred million dollars (and will also be required to change the alerts).
I'm sure there will be some warnings, but it they will have to be reasonable - such as "[Name] is an app you downloaded from the internet. Are you sure you want to open it? Safari downloaded this app today from [Website URL]" - that's the message you get right now side-loading an app on a Mac, I think it would be hard for Apple to justify anything more "scary" than that.
What I'm saying is that it already happens for apps from the App Store, where it asks you to allow access to contacts for example. But one of your choices is "always allow". I'm saying for third party store apps, they remove the "always allow" option. Make you approve it every time, to remind you that it's happening.
I do not know EU's Digital Markets Act Laws in detail but I can't imagine that such discrimination would not be in breach of them. I would frankly see that as an unacceptable and unfair measure. I want to use my iPhone like my Mac without artificial annoyances.
> this app came from a first party, it can download all your private information and has not been reviewed by a third party
I have never seen such a warning. Even if it exists it must be very non-intrusive, otherwise I would remember it.
Now it's related to a permission per app, you need to give permission for each app to install others. Eg the browser with which you downloaded an APK. Or the files app you used to open it. Or F-Droid's store app. The lecture is gone through. But you still have to grant it explicitly.
Users very quickly learn to ignore warning popups. It's why you end up with flashlight apps that can access your contacts with millions of downloads. This "fix" almost never works in practice. It didn't work in 2006 when Microsoft introduced it in Vista w/ UAC, and it's not going to work 18 years later where users are even less technical.
Such things were present in Windows since Windows 95. I had some friends who only pressed cancel, without reading, which led to funny things.
> Pop a warning every single time it accesses contacts or location, don't allow third party apps outside the App Store to be granted ongoing permissions to anything, etc.
You bring up an excellent point, but that's a technological issue that should be solved with technological barriers.
An app shouldn't be able to download any private data without explicit user permission, but these restrictions should apply to every app, regardless of where it comes from. To be more specific, users should have complete control over every permission and have an easy way to audit their usage.
Sane security models don't rely on some app reviewer magically catching malicious behavior in an opaque review process where they don't even have access to the source code, much less the ability to review it in detail.
What I'm saying is that it already happens for apps from the App Store, where it asks you to allow access to contacts for example. But one of your choices is "always allow". I'm saying for third party store apps, they remove the "always allow" option. Make you approve it every time, to remind you that it's happening.
Sideloading should be an officially supported mechanism and safely allow any app to operate within the confines of the existing sandbox. Jailbreaking is more like taking a sledge hammer to the sandbox and other technological barriers, once you break them down, privacy and security can't be guaranteed anymore. It's why I stopped rooting my personal Android devices.
Digital Markets Act, Article 13. Anti-circumvention
"The gatekeeper shall not degrade the conditions or quality of any of the core platform services provided to business users or end users who avail themselves of the rights or choices laid down in Articles 5, 6 and 7, or make the exercise of those rights or choices unduly difficult, including by offering choices to the end-user in a non-neutral manner, or by subverting end users’ or business users' autonomy, decision-making, or free choice via the structure, design, function or manner of operation of a user interface or a part thereof."
https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32...
Also, those issues never came to pass on Android which has this feature since the beginning.
In fact I would trust apps from F-Droid a whole lot more than those "reviewed" by Google on the play store.
I mean, some of the beauty of another app store is that apps don't have to obey apple.
Or... they could popup warnings for apple telemetry, or disobey apple APIs, or "fix" the dark patterns apple has introduced.
Apple phones home all. the. time. They think "anonymized telemetry" is ok. Apple lets apps have unfettered internet access. Remember how the control panel buttons for wifi/bluetooth just disable them temporarily? etc.
I'm not sure that's going to fly. My understanding is that the DMA, like the DMCA, applies to EU citizens wherever they happen to be.
Surely in reality that will mean if your account/device is set to the European region.
DMCA is a US law also, GDPR, working time directive, or something would have probably been a better example to go with.
a) Will Apple not allow apps on the official App Store if they appear on third party ones.
b) How will Apple collect their commission. There is nothing in the regulation that says that they can't continue to do this.
b) Apple is free to act as payment provider, but can't force businesses to use it.
If they decide to do it anyway:
In case a gatekeeper does not comply with the obligations laid out in the DMA, the Commission can impose fines up to 10% of the company's total worldwide turnover, which can go up to 20% in case of repeated infringement. In case of systematic infringements, the Commission is also empowered to adopt additional remedies such as obliging a gatekeeper to sell a business or parts of it, or banning the gatekeeper from acquiring additional services related to the systemic non-compliance.
https://ec.europa.eu/commission/presscorner/detail/en/QANDA_...Apples iMessage is also currently evaluated. In a total coincidence Apple also announced recently that RCS support is coming.
So Google can't just make an EU subsidiary that never makes a profit and thus the fines don't have teeth.
It's the global turnover of Alphabet Corporation.
Not that it'd work, but might be amusing.
That would look very much like an anti-competitive move to the same EU regulators who are forcing Apple to open the store for competition reasons.
Apple can continue to enforce their own rules on their own store, but demanding exclusivity probably isn't an option for them.
You are using their developer tools and SDKs and like other tooling e.g. game engines they can recoup this cost through a per-sale model.
They tried similar minded tactics already with the Dutch complaints already and they weren't blindly accepted.
And there is nothing anti-competitive about Apple charging for their developer kit.
$99/year for the development kit will probably be seen as reasonable enough for it to be allowed, though they may have to accept allowing 3rd party alternative solutions to publish things to these other app stores or similar. The fixed price of the development kit isn't really the point when talking about the 30% commission though. That's about revenue from consumer purchases and trying to evade that via moving the pricing to the dev kit wholly then requiring the dev kit will not fly just because the DMA doesn't explicitly reference doing that being an example of a bad gatekeeping action.
Is charging a royalty for using the iOS SDK "gatekeeping"? I don't see why that's the case. Is Epic Games "gatekeeping" Unreal Engine by demanding 5% royalty to use their engine? Why should it be any different for Apple to demand royalty for using their SDK?
Even if EU magically made a law that explicitly banned royalties for operating system SDKs, that won't be the end of the story. Such measures could be construed as anti-free trade (given how it disproportionately affects US companies compared to EU companies), and will probably lead to a trade war and/or WTO arbitration between the EU and the US.
Where they'd get into trouble is by trying to turn these things into ways to move the 30% revenue cut. Just moving the 30% revenue from "rights to be on the one and only store" to "rights to write apps against the device with the one and only SDK" is quite clearly a different motive and forced cost model than having a 5% SDK fee where the developer is free to choose a different SDK.
I.e. "but others charge for an SDK" doesn't allow you to then change your SDK cost model to exactly match what was deemed illegally anticompetitive forced market pricing. It just allows you to charge for your SDK in a competitive way, nothing more.
"See this one neat legal flaw that EU regulators hate!" isn't an approach a US$350B-revenue-company wants to take, with a regulator who's already signalled their intent.
Not only that but a bunch of iOS apis incur services costs on Apple's side. Certainly seems valid that they should be able to charge to provide push notifications, iCloud storage, etc. There is a wide industry of businesses monetizing development kit usage and/or enterprise services. Nothing in the EU's regulations should preclude Apple from monetizing their investment into the iOS development platform.
Are you a lawyer specialising in the topic?
Do you actually know anything about this or is this just your opinion presented as fact?
It's not an outrageous conclusion that the law bans blatantly unfair practices, when that's what it sets out to do.
I don't think Apple can have a requirement to use their proprietary tools. That would be anti-competitive. If they want to make money off the tools... they should just charge a fee to buy the tools.
Yesn’t; I don’t think the regulators would look kindly upon Apple restricting third-party JITs, since it’d give Safari/WebKit an unfair competitive advantage over other browser engines on iOS (something I believe the DMA is also meant to open up.)
It would be interesting to see if people can replace parts of ios (sort of like grapheneos cuts out google)
The EU almost certainly wouldn't allow it.
> b) How will Apple collect their commission. There is nothing in the regulation that says that they can't continue to do this.
See Denmark which has an App Store carveout for in-app purchases within dating apps. Basically, Apple wants records and reserves the right to audit.
Considering this is more than in-app purchases, I would expect a requirement for an Apple Developer account and a legal agreement to get a process similar to notarization on macOS.
Either way third party app stores should end up being noticeably more expensive than using the official. Especially once they start having to deal with fraud, chargebacks etc.
Luckily it can still be avoided by turning off gatekeeper.
Will developers have to submit to the Apple Worldwide AppStore that excludes EU countries? Then submit a separate build to the Apple EU AppStore?
Their strategy is to reduce the economies of scale that you can achieve, and thus make them less attractive since as a developer you could not sell as much on those app stores.
Is that true? I thought it is one app store, they just filter the content according to your region, language, etc. After all I don't have to install another app store app (unlike Amazon shopping which has different apps for different regions) when I go to another country.
This is kind of subjective isn't it then? I can argue that any app that shows different content to different users is actually a separate app for each user, since all the data is "segregated in the backend". IMO the proper measure of this has to be the user-facing actual app. Not some abstract concept of an app in the backend.
I have five accounts in five different countries, from a time in my life when I moved around more. Two of those accounts are in countries within the EU, but they're not "EU App Store," they're specific to the nation in which they were opened.
Maybe the two EU accounts will be merged into a new EU Store. Or maybe that's a bad idea since history has shown that nations and join and leave the EU a lot more often than anyone anticipated.
Much like how Spotify has been painful to use the past 10 years, compared to Apple Music, for example. AirPlay did work in Spotify, but not natively on the HomePod like Apple Music, etc.
I can kind of understand why they have "given up" though, after all of Apple's anti-competitive behavior. This won't change, so It's just not worth the effort.
You can't expect Apple to integrate every music service on the HomePod and I don't see how that's related with the App Store. If you want Spotify there are lots of other speakers with Spotify connect and no Apple Music - should they be regulated too or is it just about punishing Apple?
Technically, they can provide a standard interface and registration for music apps to comply with.
Legally, if EU believes iPhone via Airplay is being used by Apple to give Music unfair advantage over competition, they can require this or ask Music to be split in a different company.
Why not?
It’s already possible to do this _now_, the limitation was just another example of Apple crippling competitors… (Spotify has not implemented it in their app yet, but other music apps have.)
You can also now set the default Music app HomePod/Siri will use.
Luckily EU regulators and others are stepping in to stop Apple in this anti-competitive behavior.
The link to the "Power On" newsletter shows me a half-loaded page that talks about the Apple Vision Pro, there is no mention of the App Store. Quality journalism.
A phone is like a PC just that its locked boot loader, locked operating system.
Someone has enough knowledge of human brain to explain this form of life way of thinking?
The generation of my parents (60s+) is generally not hugely tech savvy. They remember the days of windows XP well - endless viruses, trojans and expensive security software. One of the reasons iPhones are so popular with this group is they let them use the web without fear of dealing with that again.
This is a strange argument, given that Windows XP is more than 20 years old, and the problem already went mostly away 20 years ago, when Service Pack 2 came out.
In any case, the problem has long been a thing from the past. Moreover, I don't see anyone complaining about modern Windows or MacOS computers which aren't locked to an app store. So your explanation doesn't make sense.
I think the correct explanation is much simpler: These people are Apple fans, and fans will, occasionally, be irrationally loyal. Like PlayStation or Nintendo fans.
It did not happen on Android.
>They will be effectively forced to download apps like WhatsApp and Instagram from wherever Meta puts them
So, what's the connect? You've started with big scary viruses and ended up with WhatsApp?
For them it is a major feature of the iPhone that you can download any app with complete impunity. No need for $150/year antivirus (for those big scary viruses windows used to get absolutely riddled with). No need to worry it's going to change your default search engine or start mining bitcoin. You know when you download something from the App Store it has been through some level of vetting. I'm not sure why so many people here are wilfully blind to this use case.
Also, the reason I specifically bring up WhatsApp is that we know Facebook will take ridiculous liberties given the chance - remember Onavo?
So you think to improve the security is to make the problem even worse by having more installable unchecked ransomware on the iPhone.
Really can’t wait for the flood of sideloaded malware and ransomware that made Android phones the insecure toxic hellstew that it still is today; on the iPhone. /s
You're not describing an honest "use case", so there is nothing to be willfully blind about
Your average person does not have “computers” as a hobby.
In the same vein, I’m not going to give you shit that you don’t know how to change your spark plugs off your head even though it’s so basic.
When I helped him out, he had 3 different SMS apps installed.
You are essentially assuming everyone has the same level of survival skills to survive the technological wilderness as yourself.
Most of humanity would just end up as prey.
The walled garden keeps predatory behavior out.
and there's where the wheels fell off the bus with your argument. so many non-adults are using devices and downloading content. if their friends are using a non-Apple store and all using an app from there, they will follow. we'll see what kind of parental controls any 3rd party app store provide. teens will absolutely look for ways to skirt anything their parents are using to limit them. it's just part of being a teen.
"Others apps will stay outside to avoid Apple review process. Bugs and deliberate surveillance will run rampant. "
Yup, exactly, but...only to people that choose to actively use these other app stores. If these secondary app stores do not attempt to verify and defend against malicious apps, then they will hopefully be branded as such. For those that choose to continue using them, I have a very tiny violin here ready to play a song of sympathy.
On the other hand, if consumers want Apple involved, they wouldn't leave the app store, they wouldn't download the app, and the app will fail when there's no users.
Why do you think you will be unable to download FB, IG & WA from the App Store?
Now imagine those companies paying a percentage off the top for app store in-app purchases when there is an alternative that doesn’t involve that percentage.
Facebook and Amazon have both tried (and failed) to make their own phones. That’s how much they want to control the entire UX. Of course they would funnel people to their own app stores.
Hell, app stores themselves are places to sell ads and other apps, Apple has proven that.
So why wouldn’t a company with the developer resources and monetization potential of Meta or Amazon create their own app store?
Sure, Meta could demand that people install their super-extra-spyware version of Instagram from the META STORE instead of Google Play. But, what they'd likely find out is the same thing Epic found out when it tried to found its own store: most users just don't care enough to install stuff from third-party stores, and generally won't bother.
Maybe, maybe not. Android didn't attempt to destroy their business though, whereas Apple did (and then turned around and introduced their own, non ATT compliant ad system).
(Actually, they're one of the few people that could make a store like that work, dunno if they'd want the distraction but it might be worthwhile for the ads business).
Because that is an incredibly excessive alternative. Instead of just duplicating their app to a third-party app store run by someone else, you're assuming that Meta will go to the effort to create an entire ecosystem that they then have to manage. They would have to ensure that each app on the store is on the up-and-up and hire an immense amount of staffing for that sort of thing - moderation, development, backend support, customer support, yadda yadda. Not only do they already struggle to control the narrative around content moderation on their platforms, but now they've gotta work on preventing malware from being installed on folks phones, too?
It's way too extra, when the much more affordable option is to drop a Meta-preferred alternative onto a third-party app store that already exists. Yet they haven't even bothered doing that with something like f-droid, so I'm expected to believe that they're just going to jump to the more cumbersome option of opening their own store? When the average end user will just use the default store that comes installed on their phone?
I don't buy it. And I say this as someone who is very much in the "Fuck Zuck"/"Meta is trash" camp.
> The threat to competition that is claimed to be posed by AT&T in this industry is that, through the use of cross-subsidization and customer discrimination, it will use its power in the interexchange market to disadvantage competing electronic publishers. While the possibility of cross-subsidization is as remote here as it is with respect to other subjects considered herein, there is a real danger that AT&T will use its control of the interexchange network to undermine competing publishing ventures.
Sounds familiar, I wonder how things ended for Ma Bell?
For a while, they were broken up into the baby bells. Then, one baby bell started buying up all of the other baby bells and renamed itself ATT. Clearly, that's a totally different company than AT&T. So, ultimately, nothing.
The new comglomerate of "baby bells" isn't even the biggest Telco provider in the USA, let alone the biggest company in the USA... let alone the biggest in the world.
So don't. It's your choice. The benefit is that those who don't mind, will also be able to exercise their choice.
Someone who loves Zuck products and finds them indispensable, but still underhanded and despicable in terms of user abuse (surveillance, manipulative feeds, no socially healthy ad-free no-tracking neutral-feed for-pay option …), has reason to dislike Mr. Meta.
Unfortunately, reality is rarely as a la carte as we all might wish.
They still do since, you know, they make the OS on which those apps would run.
#9
I love a government telling me what I can and cannot buy.I bought an iPhone, in large part, for the security and convenience of all apps coming from a single verifying source.
Now it’s going to become the same Balkanized nonsense that Android is.
Thanks, Europe.
like this person feels like they are being force fed this thing?
Do you honestly believe they wouldn't? If so, I have a bridge for sale
I seriously doubt that the EU would allow such behavior.
Before US took a stance on App Store, they also wanted Apple to lobby the US Goverment to sanction any country that threatens Apple. Including pulling out of NATO.
A lot of these only died down ( a bit ) once the US Government took an official stance against App Store monopoly.
What does this "stance" amount to, given that the App Store monopoly continues to be perfectly legal in the US?
The same mindset that appreciates the "simplicity" of removing all the connection ports from a device.
I hope this solves it.
They are planning their market expansion into delivering their ransomware onto iOS. It is a sad day for security but what a wonderful opportunity for ransomware authors.
[1] https://old.reddit.com/r/apple/comments/11tw577/how_come_app...
[2] https://mashable.com/article/apple-mac-app-store-scam-forces...
Yes, Apple takes 30% for "protection."
The fact that the closest comparison people have to the App Store racket is a sovereign government (the most powerful entities on Earth) is a pretty bad sign from an antitrust perspective.
For corporate managed devices, sure. But for personal devices?
If you're happy with the defaults... don't ever change the defaults!
But someone else being able to make a different choice doesn't decrease your happiness.
The next generation of runtimes (wasm for example) have this built in out of the box.
All the innovation is happening outside it.
On desktop, I have a keyboard, a big screen, and more time. I'm sitting down to work on the computer, so having to pay more attention to it is completely fine (for nerds like me). So the walled garden approach feels more restrictive than empowering in this context, at least for me.
But you don't have to wait, right??
A year from the release of this capability, EU users will have 20 additional app stores on their phone. Each will be sending notifications, coordinating "enhanced user tracking" between their apps and partner apps, advertising additional 1st- and 3rd-party products, performing background tasks like polling for updates, etc.
Paradise!
It's no different than "I want a folding screen iPhone" or "I want an iPhone with a bigger battery/screen/camera/whatever". A year ago I'd say USB-C iPhone. "Just get an Android" or more generally "why don't you leave" is a fallacy that doesn't actually address any criticisms: https://en.wikipedia.org/wiki/Ergo_decedo
Every year, the EU’s economic importance declines, partly due to stunts like this one.
So at some point (far in the future unfortunately), their diktats will simply be ignored.