←back to thread

380 points rezonant | 2 comments | | HN request time: 0s | source
Show context
lynx23[dead post] ◴[] No.40207781[source]
[flagged]
callalex ◴[] No.40207786[source]
Can you explain how your risk profile will change if you don’t use the feature?
replies(4): >>40207807 #>>40207818 #>>40207839 #>>40208050 #
neverokay ◴[] No.40207807[source]
It’s bad news for regular folks who will be clicking those install links with no protection from the App Store. The majority of people have been kept safe up until now.
replies(2): >>40207833 #>>40207892 #
realusername ◴[] No.40207892[source]
Why people are acting like the appstore is somehow safe? The top apps are casino-like games which aren't that far off malware. Not something I would like my family to use in any case.
replies(1): >>40208062 #
tgv ◴[] No.40208062[source]
So adding more of those is the answer?
replies(1): >>40208089 #
realusername ◴[] No.40208089[source]
Why would there be more outside the appstore since the appstore is fine with them?

I expect apps predominantly rejected from the appstore to try to go outside it and those casino-like scams are accepted on the appstore.

replies(1): >>40209260 #
tgv ◴[] No.40209260[source]
Of course there will be more backdoored, hacked spyware outside the appstore, because there's no oversight for side-loading. And if some game dev says "hey, you can get rid of the ads by side loading" then quite a lot of people are going to do that. They don't understand security.
replies(1): >>40209970 #
realusername ◴[] No.40209970[source]
I don't see how appstore reviews (because that's the only thing that changes compared to an install from a website) can prevent much spyware to happen. Only the most obvious stuff could possibly get caught in these processes.

Having passed the appstore review myself, they are nothing but very shallow (except for anything touching their revenue streams of course)

Saying that the phone will be full of malware with a normal install is just saying with other words that the iPhone sandboxing is trash, which it really isn't, it's well made.

replies(1): >>40210787 #
neverokay ◴[] No.40210787{3}[source]
You may be not be aware of or simply have forgotten ever visiting a friend or family’s computer where all kinds of AskJeeeves toolbars are installed from god knows where. Many people I know managed to have entire pop ups installed soon as they start their computer.

I’m not worried about you or me. The EU is just wrong on this one. They are making the worst assumption about the average user, and that’s that they are tech savvy.

replies(1): >>40210857 #
realusername ◴[] No.40210857{4}[source]
> You may be not be aware of or simply have forgotten ever visiting a friend or family’s computer where all kinds of AskJeeeves toolbars are installed from god knows where.

And how are you going to make those OS-wide popups with the iOS sandbox exactly?

Be sure that if apps could make it, they already would, appstore reviews or not.

There's some very strange communication on Apple side saying simultaneously that their phone is the most secure thing in the world on their website and pretending to the EU that it's Swiss cheese and that manual reviews kind of save the day instead. They have to pick one.

> I’m not worried about you or me. The EU is just wrong on this one.

No, I believe the EU is right here but very late to the party and not even pushing far enough if I'm being honest. There's some talks need to allow OS reinstalls and I don't see any yet.

replies(1): >>40212956 #
1. neverokay ◴[] No.40212956{5}[source]
I’ve seen tracking apps that prompt the user to enable a vpn on iOS so all their traffic is routed through them (this was not a vpn app, this was a user tracking app - not malicious. Now imagine a malicious one that doesn’t go through App Store review). The vpn thing on iOS is concerning. The user may not even know or remember they allowed it and it could just be sitting on their phone indefinitely.

I’d like it if Apple restricted VPN access for only App Store approved apps.

Again, it’s not you who I’m concerned about. It’s everyone else. It’s not hard, watch:

here you go dumb teenager, download this crypto app and hit accept on everything and get mining this new alt coin

Boom, vpn enabled and traffic intercepted.

replies(1): >>40213385 #
2. realusername ◴[] No.40213385[source]
Even on the web, those are blocked with a malware list, I'm not sure that's the best argument for the appstore.

The contribution of the review here (which this kind of malware would easily pass with a server side trigger anyways) doesn't seem that important.

I don't think Apple should restrict which VPN can go though anyways just because of the privacy issues in a lot of dictatorships, they're aren't the best party to do that and are subject to dubious requests, as seen as in China or Russia.