4 ms·
I think there's a couple solutions to this. First, "trust" should depend on your own evaluation of the developer, based on metrics like how long their app has e
by 43920 8y ago
I think there's a couple solutions to this. First, "trust" should depend on your own evaluation of the developer, based on metrics like how long their app has existed, customer reviews, what protections they have around handling data, etc. You have the ability to do a much better job evaluating trust than Apple or Google are likely to. But even beyond that, sandboxing needs to be made effective enough that even if you do install a malicious app, it doesn't matter. iOS actually does a really good job of this - apps are contained in their own sandbox, and have to get your permission to access any sensitive data, which you can easily choose to accept or deny. There are also limits on resources, and apps can't do much to your system unless you actively open them, which makes it really easy to escape from a bad app.
I know you mentioned disabling javascript, but browsers are also a really good example of this. Browsers run your code in a sandbox, and the rendering engine itself is sandboxed in case of bugs. As a result, you can pretty much visit any random website and know that it won't compromise your system - as far as I know, there haven't been any widespread attacks using browser vulnerabilities since sandoxing was introduced (except maybe Internet Explorer, which doesn't really count). The worst that can happen is that a browser tab starts using too many resources or doing something annoying (like autoplaying a video), and you can just close the tab and make it go away.
- sonnyblarney 8y ago""trust" should depend on your own evaluation of the developer, based on metrics like how long their app has existed, customer reviews, what protections they have around handling data, etc. You have the ability to do a much better job evaluating trust than Apple or Google are likely to." Wow - no, we do not have the ability to ascertain the overall trustworthiness of a dev, certainly not better than Google or Apple. Reviews can be faked, and 'how long their app has existed' is not a very good measure of anything. Their T&C's on 'protections' don't mean anything if they are not already trustworthy. So unfortunately, this is one of the valuable things that AppStores can provide.
- 43920 8y agoAssuming the developer has been in business for a significant amount of time, there are a lot of signals that help tell you whether an app is legit or not. As a random example, if I look for information aout Overcast (a fairly successful app from an independent developer), I get: * A bunch of reviews from users, very few of which sound fake: https://itunes.apple.com/us/app/overcast/id888422857 https://itunes.apple.com/us/app/overcast/id888422857 * Articles about the app from well-known websites: https://9to5mac.com/2018/04/29/overcast-versus-apple-podcasts-app/ https://9to5mac.com/2018/04/29/overcast-versus-apple-podcast... * A wikipedia article: https://en.wikipedia.org/wiki/Overcast_(app) https://en.wikipedia.org/wiki/Overcast_(app) * Information about the developer: https://marco.org/about https://marco.org/about You could fake all of this, but it would be really difficult and expensive, and probably wouldn't work in the long-term. It's true that for a brand-new app from an unknown developer, it's difficult to say what their intentions are, but Google and Apple don't really have any more information to go off of than you do regarding that - at best, they likely have the developer's contact information, but you can probably find that yourself as well. Additionally, the nice thing about sandboxing and permissions is that you don't really have to trust the developer in order to run an app. For example, the other day I was looking for a protractor app that would give me measurements in tenths of a degree, and I found this app [1]. Aside from a few reviews (which, as you said, could easily be fake), I know absolutely nothing about this developer - for all I know, they could be trying to steal all my data. But because iOS sandboxes everthing, they won't actually be able to access any of my data or do anything bad unless I approve it, and if I don't like the app, I can press one button and get rid of it. As a result, I can feel comfortable installing the app anyway, even if I don't trust the developer. [1] https://itunes.apple.com/us/app/angle-pro/id750327028 https://itunes.apple.com/us/app/angle-pro/id750327028
- sonnyblarney 8y ago"but Google and Apple don't really have any more information to go off of than you do regarding that " Apple requires people to provide a business number among other things, and they have substantial ability to 'dig in' to a developers background. Users have zero interest in this, and nobody has time to do some big investigation into some company for the sake of some app. The whole point of the app stores are to filter through the crap for us and give us some idea of what's good and what's not.
- yoz-y 8y agoDisregarding security, the app stores also (try) to filter out crap applications, blatant rip-offs, applications that steal your data or ruin your battery by mining bit coins. These things usually don't really need to circumvent the sandbox. One can of course argue that the stores don't really do a great job policing the right things but they are efficient to some degree (e.g.: the recent facebook spy-vpn fiasco). One other thing is that, at least in Apple app store, the review process catches use of private APIs which are in theory harmless but are not considered stable and could cause the application to crash if a minor update changes the way they work.
- 43920 8y agoIf an application is a "blatant rip-off", users are most likely going to realize it and uninstall it/stop spending money on it/dispute it with their credit card company, which should eventually stop the scammers from making money. And even before you install the app, you can still read reviews from other people to determine whether it's trustworthy. Excessive resource usage is already pretty easy to avoid - iOS will limit resource usage when an app is in the background, and show you which apps are using a lot of battery power so you can uninstall them. I would imagine Apple could expand this more by showing an unobtrustive notification somewhere with a message like "____ is reducing your battery life, would you like to stop it?" Regarding private API's, if Apple's position is that third-party apps are not allowed to use them, they should just stop exposing these APIs to other apps completely. Solving privacy issues is tricker, at least in the short term, although I think this should eventually be handled by government regulation. Assuming we can get fair and well-written regulation (which, to be fair, is a big if!), we could have clearly-documented rules that apply equally to all market participants, and aren't quite as clearly biased based on commercial incentives (although there would still be an indirect effect due to lobbying).
- Wowfunhappy 8y ago> as far as I know, there haven't been any widespread attacks using browser vulnerabilities since sandoxing was introduced (except maybe Internet Explorer, which doesn't really count). While non-malicious, jailbreakme.com seems to come back once every few years or so.
- 43920 8y agoThat's a good point, although the only recent exploit (in 2017) depended on a combination of 3 vulnerabilities that had already been fixed over a year and a half ago when the exploit was released.