Apple's security strategy: make it invisible
macworld.com
macworld.com
Perhaps this is the reason for their supposed push to fingerprint scanners?
Incidentally, in-app purchases have practically spoiled their nascent status as the handheld gaming platform. In-app purchases make sense for certain things, but they've ruined the app store for gaming.
I totally agree with your second point, IAP has spoiled gaming on iOS and that's the fault of the game devs for taking advantage of it. However if it didn't work they wouldn't do it and obviously plenty of people spend money via IAP. It's also their only choice. People are willing to spend more small amounts of money over time than paying a fair price up front for the game.
There's nothing reckless about handing a child their favorite game to play.
Once you've been bit with a $100 charge for an in app purchase, you start to question the true utility of the password timeout. 5 minutes ago I downloaded the game on a new device for my child to play. Now they have unfettered access to my credit card account because I just downloaded the game.
Blaming the parent for being "reckless" in this scenario is little unfair. Being a parent is extremely difficult. It requires a lot of patience, thought, and understanding.
In app purchases love to trick the end user into accidental buying. What better demographic than the child who just received the car with the keys in the ignition?
As a parent who's recklessly had this happen to them, I facepalmed and sucked up the extra charges. Mea Culpa, but it does irk me that it's so damn easy to do.
"The theft of iDevices is rampant throughout the world. While we might blame Apple for producing such desirable products, the company clearly doesn’t want people to have to hide their devices in fake Blackberry cases to use them in public without fear."
Thieves aren't stealing iProducts because they are desirable, they are stealing them because they are expensive. What the hell is a fake Blackberry case and why do I need it to be able to use my iPhone safely? What's the point of insulting Blackberry in an article about security? It's hard for me take this article or author seriously.
Apple's (and Google's) limitless boundaries should be taking a majority by concern. Third party security tools are not a bad thing. Users should be interested in understanding and learning at a level that is parallel with the risks they are taking online. This is the part that is breaking down and Apple is "solving" this for those users by further locking them out-of third party software through feature bloat. I'm surprised at the complacency Rich avoids this topic, it truly feels like a paid for point of view post.
I own Apple hardware but I find myself using it less and less in my support of transparent 3rd party tools that help, not hinder, me to control my data. I'm glad the open laptop post sits above this one. To me that's an indicator the masses here are on the same page.
What iCloud keychain does bring is much better security for the other 99%, encouraging them not to re-use the same password across all their sites and to choose good passwords by default. When I see how difficult it has been to get other members of my family to adopt 3rd party password management systems I can only see that as a good thing.
I have had no problems getting family members to adopt 3rd party password tools. An hour showing them along with explaining the rationale and the light bulb switches on. A simple document showcasing how to generate new passwords and add new sites or services goes a long way for the few times they do that particular task.
The root problem is that the 99% seems to be ignorant, not because they want to be, but because someone hasn't talked them through it. I find that pointing family to pages or videos is far less effective than me, personally, explaining things. Not sure why - but it's far more effective (maybe because they know I've actually taken time to show them vs just point them).
I still view iCloud as a bad idea and wouldn't recommend it to anyone I know.
Apple is one of the companies that work directly with the NSA.
Should we accept "security solutions" from such a company?
The only thing we can do to improve our situation is to migrate towards open-source operating systems (and software and encryption solutions).
Closed-source operating systems/software solutions are dying a slow (too slow) death.
Not all type of software is amendable to consulting/trainings as means of getting money out of it.
Open-source also means: The entire planet's population is the pool (of developers). And this in turn means:
As soon as there is a real need for something, and somebody in this world is willing to work on it (for whatever motivation), this piece of software instantly becomes available to the _entire_ planet, without barrier (no price to pay, no payment method hurdles).
This is an _extremely_ powerful property which eventually will dominate the nature of solutions we use.
I do a lot of open source on my free time, but that is because I get paid by one of those commercial bad guys companies to work on closed software, which allows me to contribute back for free.
How far do you think most open source projects would be without sponsoring from commercial companies that allow some developers to work on open source projects.
This is one of the reasons why most successful open source software is developer tooling, or nowadays hidden behind SaaS walls.
It is all nice and dandy to talk about open source ideals, but when you need to earn at least 1 000€ per month, those ideals start to fade away. Speaking from experience.
If anything, the relevance of open source is dwindling by comparison.
Also keep this in mind:
Resources there is a lot of, are not expensive...
What some people fail to observe is what happens to salaries when you apply open source all the way down, in a scale similar to app store prices.
> Open-source also means: The entire planet's population is the pool (of developers).
This is currently true, even when closed source software also exists. Or at least, getting rid of closed source software won't make it significantly more true than it is now.
> As soon as there is a real need for something, and somebody in this world is willing to work on it (for whatever motivation), this piece of software instantly becomes available to the _entire_ planet, without barrier (no price to pay, no payment method hurdles).
This either is not currently true, or is not as powerful a property as you claim.
Unless a person is independently wealthy, a significant portion of ones time and energy must be devoted to efforts that will be paid.
Therefore open source is either subsidized directly by other paying ventures e.g. corporations for whom it is strategic, of it is engaged in by individuals in the time left over after their paid work.
Until the world changes so that people don't need money to live, developer hours will flow preferentially to the ecosystem according to the available monetary rewards.
The ecosystem that makes it easiest for the most developers to get paid will attract the most developers.
This could be the "open source" ecosystem at some point depending on what business models prevail, but I see no reason why it should automatically be so.
Apple and Microsoft continues to grow. Samsung too, and they have little to no interest in OSS. Let's also keep in mind that most of the world's core services above the OS (eg Google's mail, docs, search, plus) remain closed source, as is the UI layer for most mobile devices (very, very few use stock android.)
Where OSS is doing very well is in commodity infrastructure - browsers, servers, databases, middleware, etc. It hasn't killed the closed source markets there conpletely, but it has made them work a lot harder.
It does allow many eyes to inspect source code - which is certainly important in developing cryptographic software.
However it currently does nothing to ensure the timely delivery of patches to consumers. Also, usability of open source security solutions is terrible, and unless people understand cryptographic signing, and the web of trust, and build all their software themselves they have no guarantee that their software isn't compromised.
I do not have an iPhone (or even a smart phone) so I am not exactly sure how downloads work. Can you download files to an iPhone from Safari or any other browser? If you can't then that certainly helps rule out a lot of malicious software possibilities.
The reason iOS security is so strong is because (a) there is no side loading, (b) system updates are regular, simple and apply to almost every phone and (c) apps are heavily sandboxed. It's not magic. Apple simply chose security over openness and flexibility. Android vice versa.
http://reviewtimes.shinydevelopment.com/ios-annual-trend-gra...
That was kind of my point that I was trying to make though. I definitely could have said it better but what I was going for was "It is a closed system."
Android development seemed relatively sandboxed to me though from the distributed systems course I did work for in. But I can see what you mean when you say heavily as things on Safari don't open up the Wikipedia app like on Android (if you choose to have it that way.)
iPhone's are literally only iPhones too which I imagine helps. The system updates are tailored to a specific piece of hardware. Impossible to accomplish on an Android update.