The moment any app on "f-droid for iOS" does something that Apple disapproves of, they can revoke its notarization and banish its developer from their walled garden.
And the moment that that do that, they can rack up millions or billions of dollars of fines from the EU.
If your app store distributes malware, it deserves to get banned.
[0]: https://www.macrumors.com/2022/09/26/ios-app-store-ad-fraud/
[1]: https://lifehacker.com/great-now-the-apple-app-store-has-mal...
[2]: https://www.darkreading.com/cyberattacks-data-breaches/malic...
You can't run any sort of marketplace in any sort of industry without bad actors slipping through every once and again.
I see a lot of negativity. Some of it is justified, some it's not.
I see only good things: finally after this, other countries will move ASAP to do something similar.
EU gave Apple a vague and open legislation. Apple's response was "okayish" and acceptable up to a certain point. Let's see what happens in the next 5 years.
https://www.macrumors.com/2020/08/31/apple-repeatedly-approv...
Notarization is literally to check malware and other small things.
You can probably still use private APIs and weird things that wouldn't pass the app review.
And it's notarized and can be used on other people's computers.
You can read it here[0] and for the entire content here[1] (this I didn't read yet).
Gatekeepers are allowed to exist, but they need to loosen up a bit. It's not an option that you are the only one able to distribute apps on a phone.
Right now on Mac OSX you can still install apps from outside the App Store - if the developer didn't notarise the app, your OSX will shout at you before letting you install it, but you can still do that.
On iOS you just can't (unless you root it, I think). That's where the law came in. And, arguably, I am not sure if the same can be done on Android (getting stuff from F-droid doesn't seem something that average Joe knows how to do).
On the other hand, the way I imagine Apple wants to do it:
- The user clicks on a link (from whatever App Store out there)
- Downloads the app
- Gatekeeper on iOS (behind the scenes) checks if the app was notarized
The user flow seems similar to what we currently have on OSX as well, but with a mix with Apple Store: you can only install an app if it was notarised by Apple to prevent malware and tampering. This is not an app review, so you can still have private API calls (as far as I know).
This is also why the responsibility falls on the external store: it's with the certificate from the external store that the notarisation will be done (on the app), as individual developers might not want anything to do with Apple Store at all. But someone has to - and this someone is the new marketplace.
To be honest: I am not worried at all about the notarisation, it typically takes not too long, and it's a very basic step to prevent malware - can you still do ugly things? Probably yes, but this is really to set a minimum standard of what's allowed to have on the phone. If you question this step "why shouldn't I be allowed to have anything that I want on the phone", I even agree with you, maybe EU will tell apple to disable entirely the OS gatekeeping process (?).
[0]: https://digital-markets-act.ec.europa.eu/about-dma_en [1]: https://eur-lex.europa.eu/legal-content/EN/TXT/?toc=OJ%3AL%3...
I don't think this is true, I recently tried to port one of my programs to macOS. After one of my test users downloaded the program and tried to run it, macOS claimed that the program was corrupted and that they needed to contact the developer for assistance (paraphrased). There was no way to bypass this error from the GUI.
This was odd because the program ran perfectly fine on my machine (virtualized macOS). The error went away after the test user ran some terminal commands to clear "downloaded from the internet" flags from the file.
My guess is that this is something the user has to explicitly check in the Privacy & Security "App store and identified developers" and in addition, when someone tries to execute the binary, the user has to explicitly allow (again) in the same privacy & security to execute that binary. That's how it works AFAIK.
If you distribute apps not signed/notarized, users have to explicitly allow them - there is no way that you can just double click on the "MyProgramm.app" icon and it works.
Another trick is to enter the "MyProgram.app" folder and double click the binary inside. That might work, although it's a pain for some.
> In order to establish adequate financial means to guarantee support for developers and customers, marketplace developers must provide Apple a stand-by letter of credit from an A-rated (or equivalent by S&P, Fitch, or Moody’s) financial Institution of €1,000,000 prior to receiving the entitlement. It will need to be auto-renewed on a yearly basis.
Source: https://developer.apple.com/support/alternative-app-marketpl...
It doesn't seem like the fee waiver removes this requirement.
And it seems like the cost for a standby letter of credit is roughly 1-10% of its value per year? So effectively it costs €10,000 to €100,000 per year just to have an alternate marketplace, separate from the core technology fee....
> If the Core Technology Fee does not apply to Your Applications under this Section 4.4, any Alternative App Marketplace (EU) You distribute may only distribute Applications from You or another developer registered with the Apple Developer Program and not subject to the Core Technology Fee under this Section 4.4.
So a hypothetical F-Droid for iOS would need all its apps to be from registered developers with fee waivers. (And individuals are not eligible for the waiver, so it could only contain apps from other non-profit organizations.)
This is just a farce at this point.
The centre of that Venn diagram is developers for apps on iOS's F-Droid-like, and I think that's a very small subset indeed - especially considering the paperwork required to become a non-profit.
Maybe the store itself will put in the work, but do you honestly believe every dev with an app on F-Droid will put up with the requirement to register as a non-profit?
Apple's terms seem to be carefully crafted to prevent users from creating such alternative F-Droid stores on iDevices.
What about the payment methods? Are these also exempted?