4 ms·
Wait, am I understanding this right? Apple is doing exactly what they forbid iOS developers from doing for years? Downloading code from the internet and executi
by sbjs 8y ago
Wait, am I understanding this right? Apple is doing exactly what they forbid iOS developers from doing for years? Downloading code from the internet and executing it, in order to make runtime decisions or to allow live upgrades? That's just hypocritical BS right there. But the comment thread in the tweet is wrong about it being dangerous. Lua can be sandboxed like any decent VM in 2018. "Danger" isn't the problem.
- zepto 8y agoYou aren’t understanding it right. That isn’t forbidden.
- nodesocket 8y agoOf course, it is their platform. The reason they prevent runtime/live updates is because 3rd party developers can and will easily inject malicious code. Apples owns the entire platform, I have no problem with them having "root" privileges. Honestly I'd rather have a closed platform with strict guidelines than the wild wild west that is Android.
- Jyaif 8y agoSpoken like a true ignorant. What prevents 3rd party developers from embedding "malicious code" in the binary itself?
- xoa 8y ago>What prevents 3rd party developers from embedding "malicious code" in the binary itself? Required review by Apple? That malicious code is restricted from doing much precisely by the sorts of things OP is complaining about? The potential economic return isn't as high because Apple can forcefully clean it off? That it's harder to be anonymous when $100/year has to change hands for a cert and Apple wants to know who you are on some level so it'd be at least somewhat harder to avoid them going after you? None of these are bulletproof, even combined. But even so they're not worthless either to that goal. Are you actually asserting that the actual state of malware on iOS is identical or worse then that of Android or Windows/Mac/Linux? That's not something I've seen supported before but I'd read a good source if you've got one.
- Jyaif 8y agoIf I want to hide "malicious code" in my binary (whatever that means on iOS), there's no amount of Apple review that will be able to catch it. In fact, even their restriction on downloadable code is not enforceable. This limitation is not about improving security, it's about preventing developers from creating ecosystems inside their apps.
- saagarjha 8y agoApple will most likely catch whatever you have in mind. If not, they will certainly pull your developer agreement once they figure it out.
- jonhendry18 8y agoOnce someone figures out what you're doing Apple can flip the remote killswitch and disable your app.
- filleduchaos 8y agoGiven your previous comments, I'd be very surprised indeed if you'd ever even opened Xcode in your life (to talk of actually getting an app you built approved and listed in the App Store). But sure, you totally know how to sneak malicious code past Apple's security processes, and for some completely sensible reason you've neither used it for your own nefarious gain nor reported the exploit and claimed the fat bounty that would inevitably await you.
- modells 8y agoI wouldn’t blame capitalist conspiracy just yet what can be attributed to practical intentions for reasons: 0. Trying to prevent average developers from shooting themselves in the feet too often by having apps that depend on external servers to run, then having a big security incident and Apple being blamed for allowing insecure, third-party code to run. 1. Trying to keep tabs on devs pivoting too far without a re-review. Can’t sell a Farmville app that then becomes a bitcoin wallet which then steals said bitcoins. 2. Keep the quality of apps up by curating through review rather than allowing free, unlimited publishing of random/broken apps. It’s a small barrier to entry and proof that someone invested to make something worth publishing. 3. Malware for old/jailbroken iOS existed way back, but it’s not really a thing, anymore because 0days get mostly either reported to Apple or sold/auctioned off. https://www.theiphonewiki.com/wiki/Malware_for_iOS https://www.theiphonewiki.com/wiki/Malware_for_iOS
- sctb 8y agoCould you please stop breaking the guidelines by posting uncivilly and/or unsubstantively? We've asked already and eventually we ban accounts that won't stop. https://news.ycombinator.com/newsguidelines.html https://news.ycombinator.com/newsguidelines.html
- xoa 8y agoWhat. Apple has no issues trusting Apple 100% completely, nor do any of their users. Or more specifically, Apple itself is simply an inseparable part of the core trust foundation since they control the entire stack of hardware, firmware and software. You calling this "hypocritical BS" is just nonsense, it's like acting shocked that Apple doesn't allow any random developer to issue microcode processor updates even though Apple could. Of course Apple can, there is no equality there. Apple develops private code and dogfoods it before making it public. Any platform developer by definition has to do low level stuff as part of making higher level stuff. This is not difficult. "Hypocrisy" gets thrown around way too often on the Internet, and if you do so you are basically always wrong, either because it's not actually hypocrisy at all (the word is not a synonym for "anything I don't like") or because it's a meaningless thing to say anyway vs more substantive complaints.
- insidegui 8y agoIt's also worth noting that the bundle that includes the Lua code is signed and its signature gets verified by the OS before running.
- deleted 8y ago[deleted]
- denzil_correa 8y ago> "Hypocrisy" gets thrown around way too often on the Internet, and if you do so you are basically always wrong, either because it's not actually hypocrisy at all (the word is not a synonym for "anything I don't like") or because it's a meaningless thing to say anyway vs more substantive complaints. Another thing - hypocrisy has no bearing on the conclusion of the argument. You can be a hypocrite and be logically correct. OTOH, you can be far away from a hypocrite and be wrong.
- untog 8y agoApple owns the OS. They've used private frameworks in their apps for years too, even though third party apps aren't allowed. Because they own the platform. It's hardly surprising.
- samcat116 8y agoThere's a reason that there's App Review for 3rd party devs. Apple doesn't need app review for its own apps.
- machiavelli1024 8y agoYeah, right?! They also have this “Software Update” thing in Settings, which installs kernel updates and other stuff from the internet!
- joemi 8y agoAdding to the other replies explaining why it's not hypocritical, I have an example. Consider section 5.2.4 of Apple's App Store Review Guidelines https://developer.apple.com/app-store/review/guidelines/#intellectual-property https://developer.apple.com/app-store/review/guidelines/#int... > 5.2.4 Apple Endorsements: Don’t suggest or infer that Apple is a source or > supplier of the App, or that Apple endorses any particular representation > regarding quality or functionality. Apple definitely infers and suggests and even explicitly states that Apple is the supplier of their own apps. This clearly violates section 5.2.4. But Apple does not have to follow the rules that apply to third party developers because they're not third party developers. They're first party developers.