Apple to EU, Drop Dead
spyglass.org
spyglass.org
I am a big Apple user, in many senses really a fan. But these scare tactics are just off. First of all, the safety promises of the Apple store are way worse than Apple makes them. There is tons of dubious apps around which rob users quickly, just barely within the guide lines. Often enough, bad apps slip through the nets. On the other side, many absolutely legit apps get blocked due to bad review or overzealous restrictions.
Would it be a bad idea to install apps randomly from everywhere? Sure! Would it be a security risk to install well known open source software from a reputably curated alternate store? Most likely not! Also, the system should have more robust implementation which would prevent malicious apps of doing damage until the user explicitly grants entitlements.
And I would be much less interested in installing apps from different sources, if the content of the app store were just guided by safety concerns. But a ton of stuff is blocked just becaue Apple wants to block it. That is, where the demand for alternatives comes in. And lets not even talk about adult content. It would be great for the safety of the users, if Apple would allow such content within the protections of the App Store. But no, even though you have solid age information about your users, it is banned and people are driven to sources outside of the App Store safety and outside of secure payments.
I am avoiding to release anything on iOS (even that my customers would love it) because Apple can shut me down anytime they feel like. Can I sideload like on MacOS or Android? Nope. Can I recompile my app into PWA with decent WebBLE support? Nope, because every browser is reskinned Safari with a poor PWA support. So the moment when they decide to shut me down, all the effort to create iOS application will be thrown out of the window.
While the overall ration might not be terribly high, one can read again and again about cases where Apple did reject apps or app updates out of the blue. Some got resolved later on, others not. A common theme is, that you don't really have a direct point of contact, you can only send appeals to Apple. And when they decide to block you, you are done. There is no alternative. I wonder why lawmakers have not dealt with this topic yet, but alternative app stores would go quite a way of reducing the problem.
- do not use the Mac App Store for anything other than first-party apps like keynote, et al
- Use chrome or firefox as their default web browser
- download and install software from trusted 3rd-party marketplace apps like Steam all the time
And it's not the end of the world.
Notice how they’re telling how terrible everthing will become now on iOS in EU. Yet, the next macOS will be "the safest yet”. This is also why they don’t even acknowledge Mac’s existence in these posts.
Why aren't we screaming about how unfair that is?
There are numerous games stores that game developers can use to sell their game through.
Steam do not have a monopoly on the devices it runs on.
Apple do.
Or does it mean 30% is about right for the value?
A publisher can ignore all game stores on windows or macos and still sell their game directly to user if they wanted to but they cannot do that on ios.
I'm not going to pretend EU law is a flawless godsend but I also can't say that I feel bad for Apple here.
we'll be ok, just let us use our computers
The best example is that you cannot install Chrome through the app store on MacOS. In its place? A bunch of garbage apps that people install thinking they're Chrome. So much for quality control.
Millions of users have braved the risky, buggy and deadly internet to install Chrome as a result of this. Nobody cares.
Tell me, if millions of Mac users can download apps successfully, with little malware, why is it the phones need all the protection?
We all know the real answer involves 27-30%.
"Based on these Google representations, throughout the Class Period, Plaintiffs and Class members reasonably expected that Google would not collect their data while in Incognito mode. They reasonably understood 'You've gone incognito' and ‘Now you can browse privately’ to mean they could browse privately, without Google's continued tracking and data collection.
Google could have disclosed on this Incognito Screen that Google would track users and collect their data while they were browsing privately, but Google did not do that. Instead, Google included representations meant to assure users that they had ‘gone incognito’ and could ‘browse privately’ with only limited exceptions, none of which disclosed Google's own tracking and data collection practices while users were in a private browsing mode."
https://www.wired.com/story/chrome-incognito-mode-privacy-wa...
There are some severe shortcomings of the App Store at the moment. First of all, it isn't as secure as they make it. There are enough bad apps which are not detected in time and there are many apps which are on the store which basically scam the user. But Apple is happy to take 30% of the scammed money. And the elephant in the room is the fact, that the App Store routinely rejects apps, that are absolutely no risk to the user, but rejected for non-security related reasons. Or just because of sloppy review. Just google for some random rejections. That all those internet giants try to handle customer contact in a non-personal way where your means of appeal are low or non-existing, makes the situation worse.
World: We're having a global party!
China: We'll bring the hardware!
U.S.: We'll bring the software!
EU: We'll bring the lawyers!
Instead of the political decision of a bunch of unelected Brussels would-be "elites" which would never pass a general referendum. If they ever had such things, which they generally don't.
Would we call a rule that "phones must have a USB-C connector" The Law? No, it's just lawyers with too much time on their hands.
The EU is composed of multiple bodies, one of which is unelected people, one of which is people chosen by someone who is elected (roughly) and one of which is people directly elected by EU citizens.
This last body is a Parliament, and is where laws happen.
Once laws are voted, each individual country has a delay to transform it into a local law.
So, yes, the fact that phones must have a usb-c connector is, in fact, the law. The text is here: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32...
Admittedly, it's a bit more complicated than that between who has to say OK and whatnot because, you know, that is how The Law works.
This article doesn't actually make an argument about this. Is there a good analysis of why their proposed changes won't be compliant?
The double standard is clear: you can run whatever you want on a "computer", but not your "phone" even though phones have far better permissions and protection systems.
We can solve this today if the big players will join in - neutral party code signing. Anyone can provide identity to get a dev key, they get to sign their software. If their software is malicious there's all kinds of evidence of who they are and various agencies very interested in it.
If you insist on using AI-generated images, then at least do us the courtesy of spinning the image-generating bingo cage until you get lucky and it spits out something that isn't so patently gross.
PS we have some more rules in the pipeline for you - you gonna luv them.
From Brussels with love, EU Privacy "Tzar"
Apple wants zero liability from the upcoming changes to the Product Liability Directive and the introduction of the EU Cyber Resilience Act. They want to say "the system was more secure, but the EU made us do this so go pound sand".
> Inevitably, the new options for developers’ EU apps create new risks to Apple users and their devices. Apple can’t eliminate those risks, but within the DMA’s constraints, the company will take steps to reduce them.
That's exactly what this means. Nobody will be able to argue that Apple could have done more. It will be "Apple was doing more, but the EU made them do less".
The EU isn't making it less secure, because WebKit isn't the only secure rendering engine in the world, far from it.
Be shocked and angry when Google makes a bunch of Android changes that YOU WILL NOT LIKE next year.
Apple seems to have determined it's better to fight against the intended nature of the legislation. Likely they can eek a few more months or years until the hammer comes down. As planned, I'm sure.
1) a large sovereign entity (or a collection thereof, as the case may be),
2) which, incidentally, also happens to be one of the largest economies in the world,
3) with legislative and executive power over actors wishing to make money within its jurisdiction,
4) drafts legislation intended to control said actors and
5) announces it is going to exercise aforementioned executive power,
6) to use the legislation for its intended purpose against a non-complying actor,
that entity is bluffing?
(Apple already folded, by the way. They're simply sore losers.)
https://www.apple.com/privacy/docs/Building_a_Trusted_Ecosys...
Most importantly, the idea that the App Store in its current form is exempt of malware and the best possible security is completely ludicrous.
Of course the document never mentioned that iOS has a bunch of malware on its own and the appstore doesn't seem to help any of that.
You could add [citations needed] to pretty much every paragraph.
It is obvious how sideloading could directly lead to an increase in malware.
It is obvious that the iOS/Android appstores help keep down malware.
I am sure there are arguments that can be made to support your view. But these are not those.
Hiding malware from an appstore reviewer is trivial if you really want to.
So besides writing a snarky disdainful press release they made sure no one significant ever will use the scheme required by the EU because you'd need to pay through the nose for it.
After the USB C debacle, the EU has learned to include such a clause pretty well, I guess.