The iPhone has a full web browser, though, which is a much more likely point of entry for malicious code.
The iPhone has a full web browser, though, which is a much more likely point of entry for malicious code.
To your first point, though: I thought you were talking about listing arbitrary apps in the central App Store without vetting them. People trust things that, like you said, come from reputable sites. The App Store is seen in its entirety as a "reputable site," no matter which publisher actually wrote the app. I'm all for allowing you to just surf to an .ipa file and download/install it, but don't allow people to list a trojan-horse "Apple Remote" right beside the actual "Remote" without creating some form of community filtering or known-developer verification.
There used to be a site that you browse to in mobile Safari, and it would jailbreak the phone. A potential vulnerability in the app itself is probably what he meant.