Hacker News new | ask | show | jobs
by uxp100 2883 days ago
It's kinda a chain of trust. One of the value of the Play Store is that you trust it not to include malware (if you do). If they allowed other app stores to be installed through it, google can't be confident in saying if you use our store, you won't get malware.
1 comments

You trust the Google Play Store not to have malware?
It's certainly far more trustworthy than the iOS app store and Chinese app stores, all by a wide margin.
Based on what metric? Google doesn’t even pretend to review apps and the Google app permissions framework is laughable.
Based on total malware installs, where Apple has everybody beat by even just Xcodeghost alone.

Google doesn't pretend that manually reviewing apps prevents malware because it obviously (to any software engineer) doesn't. It does, however do both static and dynamic analysis of the apps in its store, unlike Apple and the Chinese app stores.

And that really hasn’t help. Xcodeghost basically affected the Chinese App Store where app authors downloaded a non Apple hosted version of Xcode.

https://us.norton.com/internetsecurity-mobile-android-vs-ios...

https://www.sophos.com/en-us/security-news-trends/security-t...

That doesn’t even consider all of the unpatched Android security holes.

https://www.esecurityplanet.com/mobile-security/how-secure-i...

Or the fact that most Android phones are running older versions that will never get patched.

https://developer.android.com/about/dashboards/

Compared to iPhones running the latest versions....

https://www.digitaltrends.com/mobile/ios-distribution-news/

There is no "Chinese app store" for iDevices. Anybody who downloaded WeChat anywhere in the world was affected.

Trying to bring uo unpatched devices is changing the subject (security-conscious people use Android devices that get regular security updates) — we were talking about app stores. It remains a fact that far more people have been infected with malware from the Apple App Store than from all other app stores combined.