Hacker News new | ask | show | jobs
by egocentric 1887 days ago
“Sideloading Apps Would ‘Break’ the Security and Privacy of iPhone”, said Tim Cook.

But instead of gaslighting us, Apple could let us sideload notarized apps. This means:

- Automated scan for malware

- Remote kill switch, just in case

They already do this for macOS [1]:

> “Notarization is not App Review. The Apple notary service is an automated system that scans your software for malicious content, checks for code-signing issues, and returns the results to you quickly.”

They could give users a choice, much like they're doing with the new App Tracking Transparency prompt. But when pressed on why Apple should have control, Cook said "Somebody has to."

That's… not a very convincing argument.

[1]: https://developer.apple.com/documentation/xcode/notarizing_m...

1 comments

Yeah, the whole "there is no alternative to the App Store" argument completely falls apart in the face of the existence of the Mac, and how the Mac isn't constrained by the Mac App Store.
Obviously not, because the Mac has only ever had minor sales relative to the PC even, and minuscule compared to iOS.

It’s never been a serious target.

Your Apple bashing is really quite tiresome. Macs are serious machines and have grown in leaps and bounds over the past two decades. Are you seriously saying the de facto development platform for Silicon Valley startups, as well as the home for Apple Silicon, is no longer a “serious target”? No need to shill for Windows here.
It’s not a serious target for App Store scams, or scam software in general, because the user base is tiny compared to iOS.

I think you know this.

And ransomware and botnets too: https://www.avg.com/en/signal/mac-ransomware-remove-protect

Fortunately iOS users don’t have those problems because of the security model that you are so quick to dismiss.

> because the user base is tiny compared to iOS.

One Tenth. Or 100M+ User with lots of room to grow.

I wouldn't use tiny to describe it, even in comparative sense.

Especially considering the value of the userbase and the fact theres millions of PC's propping up 'marketshare' that aren't even being used as personal computing devices (retail displays/signage, corporate/government pc's)
If you are executing a scam why on earth would you pick the market that is one tenth the size?