Most consumers understand those concepts and fear those things. Most understand nothing about the economic impact of monopolies and anti-competitive business behavior and the harms they cause consumers in the form of higher prices, lack of innovation, reduced choice, and poorer quality products and services.
So Apple plays off those fears by using language consumers understand, making them actually want the very monopoly that is being forced on them and actually harming them while making billions for Apple.
It's unethical behavior, no more defensible than Sam Bankman-Fried's effective altruism, a.k.a. "mostly a front." This is all right out of Apple's standard playbook.
That playbook really gets around huh.
Which is ironic, considering that the App Store is likely one of the largest malware distribution vectors on the planet.
Looking at one virus alone, the App Store distributed half of a billion copies of it to iPhones and iPads[1]. Similarly, there are multimillion dollar scams on the App Store, as well[2].
[1] https://www.vice.com/en/article/n7bbmz/the-fortnite-trial-is...
[2] https://www.theverge.com/2021/2/8/22272849/apple-app-store-s...
> But now, thanks to emails published as part of Apple's trial against Epic Games, we finally know how many iPhone users were impacted: 128 million in total, of which 18 million were in the US.
> "In total, 128M customers have downloaded the 2500+ apps that were affected LTD. Those customers drove 203M downloads of the 2500+ affected apps LTD," Dale Bagwell, who was Apple's manager of iTunes customer experience at the time, wrote in one of the emails.
> Apple also disclosed the apps that included the malicious code, some incredibly popular such as WeChat and the Chinese version of Angry Birds 2.
Still a huge deal, particularly in China, but considering all the virus really did was collect some device info (less information than most ad networks) (and maybe it was able to open URLs and popups on command)[1] and it was the biggest virus on the App Store ever (that I can find), maybe not as awful as you suggest.
The scams on the App Store, yeah that's pretty bad. Though, can you point me at a marketplace as big as the App Store without loads of scams?
[1]: https://www.lookout.com/blog/xcodeghost#what-does-it-do
Nah, that would mean that what really protects iOS users from malwares is just a good sandboxing mechanism and not the "human" control of the App Store. That would also mean that bypassing the App Store shouldn’t be a real security issue.
The question is whether there’s more malware on stores like f-droid, and the answer is yes, there is of course significantly more malware.
This even pollutes the official Play Store to some extent because of course google can’t put the foot down too hard when Facebook et al can simply “start their own app stores” to bypass review if they really want to. Malware rates are much higher on android in general.
https://arstechnica.com/information-technology/2020/09/joker...
Not the person you're replying to but isn't that the point?
You are shown that this is by no means as secure as they want you to believe.
Then you argue that "of course, with a market that big!"
So basically you are proving that Apple uses the excuse of security to hold a monopoly.
Suppose there were multiple app marketplaces for iOS. Then some of them could be extremely selective by finding a niche, and thereby be more trustworthy than any unified store that has to carry a million general purpose apps with only cursory evaluation from various publishers of little or unknown reputation.
GNU/Linux repositories.
https://nitter.net/npm_malware has twenty postings in the last 19 hours, quite far from "without".
Probably OP was thinking about the deb and rpm repositories of the main distributions but yes, NPM and the likes are other examples of large repositories.
I agree there are linux-only repos that are ~1% of that size and contain little or no malware or abuse. That's true whether you measure size in updates per day or total count of packages, so 1% seems reachable without considerable malware problems.
Another plausible explanation is that pure FLOSS repos are free fron malware.
No, it's not even a Linux package repository. Think repositories for Debian, Fedora, Arch, etc.
I don't think either Debian, Fedora or Arch are anywhere close to a million packages or a thousand updates per day. Well below 10%. They're GNUish and 100% linux, but really bad on the size axis.
The app store has at least two classes of problems that those three don't have, and have to handle the problems at much higher scale. "Those guys manage to handle a simpler problem at much smaller scale, so it's possible for the app store too" is hardly an argument.
As long as a FLOSS repo is small and has few uploaders, it'll be safe. Hardly a model for a big and busy repo like the app store, of couse.
The distinguishing feature of Linux distributions is the existence of maintainers. Human beings who put in effort into maintaining the quality and integrity of the packages and keeping them up to date. We Linux users generally trust those people, and they stand between us and all the software developers out there. To get to us, you gotta go through them. And they generally aren't in the habit of allowing obvious malware into the software repositories. That's why we trust them in the first place.
Contrast that to repositories like npm, pypi, rubygems, cargo which are all designed so that any random person can make an account and push up any package they want. There's no checking. Accounts might be compromised by or outright bought by malicious actors. Just like popular browser extensions which get bought and converted into malware.
Maybe the issue is being so big then. Which is exactly why the EU did this in the first place. So Apple has yet another lever to comply: reduce their size.
Tech journalists have literally warned Android users that they need to be wary of apps from inside Google's walled garden.
> With malicious apps infiltrating Play on a regular, often weekly, basis, there’s currently little indication the malicious Android app scourge will be abated. That means it’s up to individual end users to steer clear of apps like Joker. The best advice is to be extremely conservative in the apps that get installed in the first place. A good guiding principle is to choose apps that serve a true purpose and, when possible, choose developers who are known entities. Installed apps that haven’t been used in the past month should be removed unless there’s a good reason to keep them around.
https://arstechnica.com/information-technology/2020/09/joker...
Many, many people game the system in terms of in-app payments, e.g. showing a link to subscribe on their website but hiding the link for the review.
If they can't catch that, why do you they can catch anything?
Also, most of my apps come from fdroid anyway.
Apple is well aware of this and plays into it hard.
Apple has been repeatedly requested to change the colour to a less ugly shade, or to give users the choice to disable the feature or to give Android apps an API of some sort so they can comply with whatever Apple's requirements and get the blue text boxes.
Apple hasn't taken action because they like the current state of affairs, they want the social ostracism of non-Apple users.
That's because people are idiots. There's nothing that iMessage does that whatsapp, telegram, kakao, line can't do. In fact, US/Canada are the only ones that actually use SMS or iMessage, as far as I know, and the rest of the world use other messaging apps. I have been living in Canada for 5 years already, and in no instance I had any issue whatsoever. I now use iPhone, but nobody talks to me via iMessage, it's all either Messenger or Whatsapp, or Instagram
If Apple is able to hold such a stronghold over Americans because of something so easily bypassed, then you deserve to be controlled, really.
That part of the market not being separate from the other part of the market is the issue. There could be a dozen different reasons that someone might want an iPhone over some competitor, and if they buy one for that reason, they're stuck with Apple's store even if they would have chosen something else given the option.
Not only that, the markets are tied together in both directions.
Suppose that you do want to go into competition with Apple and Google and make your own competing phone platform. The biggest problem you're going to have is that people expect you to have a lot of apps available for your phone before they'll buy one, but you have to have a lot of customers before anyone will make apps for your platform.
The traditional way to solve this is by creating a cross-platform framework and then giving developers an incentive to use it, generally by making it easy to distribute apps to existing platforms. For example, Valve wants game developers to develop for SteamOS, so they provide cross-platform frameworks and a distribution system that also works on popular incumbent platforms like Windows. Then developers make games that run on Windows and incidentally also on Linux/SteamOS, and now there are more games available for SteamOS than ever before and it's the most promising competitor to Windows for PC gaming in a long time.
Conversely, Microsoft is prevented from making an app store for iOS, so they can't do that and their ambition to create a viable competitor to Apple and Android faltered. Likewise Ubuntu Touch and Firefox OS and every other attempt to create a viable alternate phone platform. And then you say "just buy a different phone platform" -- as if that wasn't the problem.
so, is it "safer"? what's "safer" about it? or is it really just a meme apple has successfully perpetuated about it's limitations?
A year ago, I also saw a fake advertisement for a squid game. These fake advertisements have already become a meme, but they also offer to download from Google Play a slightly similar game, where after quickly clicking on the screen, the smartphone will suddenly prompt you to buy an expensive subscription and then you will not be able to cancel it, because Google does not provide for them refund. This idea comes from SMS scams since j2me platform, and judging by the comments on this game, people are still losing money, especially if they leave their phones to children.
I don't use ios and won't say whether manual moderation there helps prevent the same crap, but let's not ignore that if you're not tech-savvy, this Android security alternative is pretty easy to get around.
funnily enough, some bits of it might be worse because ios and app store are promoted as 'being secure' period, almost unequivocally - so it ends up being a thing like 'well, ios is secure and this app is on the store, so it's all good, right?", which doesn't always happen to be the case.
AFAIK, This cannot happen on Apple.
I think that this is faith, not objectivity - which is misplaced in this specific scenario.
The challenge isn’t market dynamics, but rule breaking and predation on victims.
Non tech inclined people are targets/marks for bad actors.
Malicious websites, innocuous messages, hard to avoid buttons - are all designed to circumvent good intentions.
This is resolved with rule enforcement, retributive and governance powers.
If we are adamant about competition, then apple being locked down while Android remains open is about the best you will see.
these questions are silly if you pivot them to be about other things rather than the fruit company, just like the arguments that "[company] needs to run open-infrastructure so other companies can build commercial products on [company] servers".
It's rather obvious they're being asked in bad faith with the intention of dragging down the discussion. You know perfectly well what SELinux and application sandboxing are for, and that they're net benefits.
I take care of Android devices used by elderly people, and they have just zero issues. Not anymore than they would have with iOS.
All this is nonsense talk trying to help the indefensible position of Apple. Most people also use Windows computers with no monopolistic app store and even though sometimes they are problems they almost always come from user errors. Most of the time it's poor choices, generally from greedy behavior (trying to get stuff for free without knowing much).
If a user doesn't know what it's doing, it can ask someone for help or stick with Apple's App Store if that suits him. Allowing other possibilities for more competent people doesn't change this fact one bit.
Her phones become really slow because of this.
In fact, their notification system makes it complicated to just allow specific behavior and not something else. It's not better than the notification settings in typical web apps. As a day one user of iOS, I find it funny that you complain about notification out of all things, because if there is one place where iOS is just as fucked as every other platform it's notifications...
Nowadays I have resorted to basically denying notification for everything but the few stuff where they are actually relevant...
Also, you should correctly set things up for your mother and refuse notification prompt for every website and just whitelist the few that might be usefull..
Sorry but the actual statistics from mobile security companies that track this stuff show otherwise. From Nokia's Threat Intelligence Report 2020 (https://pages.nokia.com/T005JU-Threat-Intelligence-Report-20...):
Among smartphones, Android devices are the most commonly targeted by malware. Android devices were responsible for 26.64% of all infections, Windows/PCs for 38.92%, IoT devices for 32.72% and only 1.72% for iPhones.
Android malware infections are an order of magnitude higher compared to iPhones.
(I tried to look for data from more recent years but iPhones don't show up in the reports after 2020.)
They need to “investigate”
Especially the constant mentioning of the "EU" when this applies to the EEA, leaving out two entire countries. I hope they actually realize this internally.
> If someone posts an app before you that is to similar to what you post, they will tell you no.
search "2048 game" and let me know how many similar games they said no to.
> search "2048 game" and let me know how many similar games they said no to.
I don’t know how old the rules are for this. I just know it currently exists. Also, it’s possible that a number of them were submitted at the exact same time and there was a race condition allowing the market to be flooded.
People test an app out on Android. If it works, they will make an iOS app.
That would make innovation across mobile devices, not android/apple. Wouldnt it?
For example, they force you to go find your country's D-U-N's number provider, which usually costs time and money -- unlike the US, where looking up your own number is free. Then they verify it. Apple just looks it up for you, for free.
When you register as a person, Apple just requires basic supporting documentation and doesn't require a real device. Google requires that you have a specific brand of device in-hand to sell an app, and won't let you use smaller, less known brands (at least in the US, even if the brand is popular where you live). This means you need to drop nearly $1,000 USD on a phone, just to make a free app. Apple is $99, all-in.
The play store (for me) was approx 955 + 25 + 15 to get an app listed.
So no, Apple is probably a less expensive gamble. Especially if you already have access to a mac (rented or paid).
>you’re arguing from imaginary evidence
Thanks for the laugh.
iOS apps bring in more money and that absolutely shows in the time and effort companies put into their apps. The big names (FAANG) might have equality but once you leave the top apps the quality difference can be stark.
When someone claims he's the only one who can protect the public I immediately see some question marks.
So far, it's all been speculation, even drawing parallels with Android or Windows doesn't help because it's not similar enough. I would expect a broader ecosystem or additional facets to an existing ecosystem to also cause an expansion of questionable quality and practises, but that applies to everything, not just mobile phones.
— C.S. Lewis
I would agree with you that Apple isn't the only entity that can provide that type of vetting process but it also seems clear to me that a vetting process is actually a useful and desirable service.
And now they cracked down on small developers to revert that. So it's not a totally invalid point from Apple.
What, their shitty app sandbox isn't all that good or something? Methinks the real reason is money.
But tbf, even though I can install APKs on Android I don't really do that as there's still the fear of bad actors; maybe the Android sandbox is safe & secure but I don't _know_ that, they haven't _told_ me explicitly about it. And if it's not safe for Android too, then why not?
That’s not really the point. On the Web you have a single google.com, and on the AppStore you have a single "Google" app. If you allow multiple sources for apps you break this idea of a unique registry and allow anyone to create an app named "Google" or any other well-known brand. There’s no way of ensuring the "Google" app you’re looking at is the genuine one anymore.
Unfortunately it's not really perfect solution for the web either as plenty of people still get scammed by fake urls + not bothering to check who the cert is for/from...
> What, their shitty app sandbox isn't all that good or something? Methinks the real reason is money.
Or maybe just because designing a good sandbox is really hard. Look at snap packages on linux. They're one of the most common way of sandboxing linux apps and come with significant limitations compared to unsandboxed software.
"selinux had an escape once therefore it's useless!" no, that's not how that works and you know it.
"gatekeepers should have an obligation to interoperate with third-party systems!" oh so google needs to run open SMTP relays to allow third-parties to build commercial operations on google's infrastructure and send mail to google's users? google needs to not block unwanted commercial solicitation from third-party operators because they "have to interoperate"?
etc etc
in this case - ctrl-f for "sandbox" and virtually every single one of the comments is some variant of the same obviously bait/flamewar comment.
https://news.ycombinator.com/item?id=39143802
https://news.ycombinator.com/item?id=39141456
https://news.ycombinator.com/item?id=39140427
the discourse is always really bad in these threads and frankly a ton of it is android users who can't help but roll in the shit and sling insults constantly ("apple sheeple who only care about blue bubbles", etc) and we've completely normalized them acting out (both as a society and here on HN) for some reason.
The discourse is on why we accept that browsers can sandbox websites but we can't place the same amount of trust in sandboxing of apps and historically Android has been better at that than Apple because they actually allow you to do it in the first place, the caveat being that it's not really made clear if this is "safe" or not.
Apple is one step behind Android on this but they're _both_ many steps behind making it transparent to the user that "installing any app from anywhere is as safe as visiting any random website".
It's the same sales pitch that Canonical is using to justify its centralized snap store.
Tim Cook is parroting Steve Jobs when he says that Apple deeply cares about users' privacy and security. Jobs was smart enough to realize that emphasising security and privacy protections would increase sales because Apple is a company which sells computer products instead of advertising solutions and services like Google and others(although Apple is increasingly thinking about how to monetize their Big Data).
Because when you know how things work and what they are capable of, the last thing you want to do is fight with them so that they work. At least, someone who doesn't know better cares much less because he is clueless about the existence of a better way.
Jobs was in the business of selling bicycles for the mind, not dumb consumption machines. The latter development of basic consumer focused products is just after the success of the iPhone and happened basically precisely when he left (while officially he was still managing apple, it's pretty clear that after the launch of the first iPad, jobs didn't have a lot of impact at Apple his health condition not allowing).
It also made sense because before Apple was something to exhibit to display wealth nobody that wasn't competent enough with technology would have spent so much money on it. Which is exactly why current Apple offering is absolutely terrible for its price.
Most of the crap told on Apple nowadays are complete memes from the second wave of Apple cultist (most of them arriving with the iPhone) that completely ignore the true history of Apple and how it got to launch such successful products.
Competent in other fields of endeavour, sure.
Jobs was in the business of selling computers that looked (and worked) good to people who would otherwise hate computers. Dealing with geeks was always (and still is) a necessary evil, so he'd have enough of an ecosystem to sell to "normies".
Jobs fundamentally hated the Macintosh and tried very hard to get away from it very early (Newton, anyone?). Once he got back on the saddle, his first Big Idea was to wrap them into colourful shells, and fuck the tech inside (jesus, was the first iMac dog-slow!). His second idea was to co-opt FOSS and Java developers, again to have enough geeks building stuff for his platform; they would be unceremoniously dropped once the iPod got traction and he could finally get to run the "better Sony" he always wanted to have.
The rest is just stories he told to power his reality-distortion field.
> Jobs fundamentally hated the Macintosh and tried very hard to get away from it very early (Newton, anyone?).
Jobs had nothing to do with the Newton, it was started about a year after he was forced out, Sculley coined the term Personal Digital Assistant, and it was one of the first things killed when Jobs got back to Apple.
NeXT contradicts that.
Though, I like how you mention he always wanted to be a "better Sony." That's definitely on point.
The original iMac hardware specs were also pretty reasonable for when it came out, no?
Apple Watch, Apple TV and HomePod would like a word.
And now you know why I call Tim Apple the iPope.
Remember all the times when a computer could be compromised via a bug in the jvm that was supposed to safely run the java applets?
Normally it would be fixed immediately on linux and windows, and take months on osx because apple had their own jvm (that had the same bugs because it was just a fork).
Because it does create security risks.
App code in 3rd party app stores is not going to be reviewed, which means anyone is free to craft a rootkit embedded in an app and release it to a 3rd party app store.
Enjoy!
I never knew that every app gets root access on iOS and that the security model hinged entirely in Apple's control of the App Store.
Oh no! You mean exactly like it has been on a mac for decades?
Just this week she had to install a work app for scheduling from Googles Store and got duped into a fake clone that installed 4 other apps with repeated pop up apps emulating a signup wizard.
Those non standard androids are far far more worrying and the Google App Store is way less locked down.
If my dad was in the EU I’d have to tell him never to install an app using anything but the Apple App Store.
In any case, the Internet does not have to pay Apple to be discoverable and accessible.
Firefox, too.
Phones are with you constantly with GPS, movement, cameras, and microphones regularly accessible by apps, sometimes persistently. It’s also a platform handling SMS and Bluetooth and other weakly secure protocols.
That doesn't mean it isn't a sandboxed compared to more traditional computing environments - it just means it's less restrictive than a browser.
Why are people so obsessed with "forcing" Apple to adopt the same approach that gave us the dumpster tire fire that is Windows?
If you don't want a device where the hardware and software were designed to work together, just buy from one of the literal thousands of other vendors who took your approach.
> The changes also include new disclosures informing EU users of the risks associated with using alternatives to the App Store’s secure payment processing.
There are 22 instances of the word "risks" on that page. Pathetic.
As it is, there is only one channel and no competition, so we don't know what the malware situation would be like in the absence of Apple's monopoly.
Same reason "McDonalds hamburgers" aren't a market. They're just a branded product within a larger "smartphones" market.
> How do you define market, then, if that's not a market?
Same way the FTC does:
> all goods or services that buyers view as close substitutes
https://www.ftc.gov/advice-guidance/competition-guidance/gui...
An Android is a close substitute for an iPhone, just like a Ford is a close substitute for a Toyota. People switch between them all the time.
Competition is not a panacea.
In this case, there is already competition between distribution channels, the issue is predators/malafide behavior who will always be able to run circles around channels.
I suspect that the cost of review is not apparent - review at scale is going to be outsourcing. Thats a whole bunch of contracting, management, and sheer work that new distribution channels will not be able to afford.
Adding competition doesnt help. At some point, it simply creates more vectors of attack.
The situation you describe is better served by a policing force, that stops bad actors.