3 ms·
Right, third party app stores are not officially supported and for good reason. I am not sure what the alternative is, create a unmoderated free for all app sto
by cmcd 7y ago
Right, third party app stores are not officially supported and for good reason. I am not sure what the alternative is, create a unmoderated free for all app store? That goes pretty heavily against the Apple ecosystem's philosophy and would make it easy for people to download damaging apps which Apple would then get blamed for because they added an official channel for installing them.
- vageli 7y ago> and would make it easy for people to download damaging apps which Apple would then get blamed for because they added an official channel for installing them. Do Android users blame Google or the phone manufacturer when they download a damaging app?
- cmcd 7y agoYes they do, the most recent example is apps using a vulnerability to steal images. Many people are blaming Google and Samsung for not addressing this problem sooner and of course having a faulty permissions system that allowed this in the first place. Samsung is frequently attacked for security issues since they take so long to push out updates. Apple avoids these problems entirely by sandboxing apps and thoroughly reviewing functionality before accepting. It is very rare to hear about security issues for iOS yet we hear about a new one for Android monthly. https://www.forbes.com/sites/daveywinder/2019/11/19/google-confirms-android-camera-security-threat-hundreds-of-millions-of-users-affected/ https://www.forbes.com/sites/daveywinder/2019/11/19/google-c...
- heavyset_go 7y ago> It is very rare to hear about security issues for iOS yet we hear about a new one for Android monthly. This exploit existed in the wild for iOS for years[1], and all a user had to do is visit a website for their device to be exploited. There are plenty of other recent exploits found in the wild for iOS[2][3]. This implant is undetectable and uploaded iOS users' photos and location data to the attackers[4]. All four of these iOS exploits were found in the same month. [1] https://googleprojectzero.blogspot.com/2019/08/jsc-exploits.html https://googleprojectzero.blogspot.com/2019/08/jsc-exploits.... [2] https://googleprojectzero.blogspot.com/2019/08/in-wild-ios-exploit-chain-1.html https://googleprojectzero.blogspot.com/2019/08/in-wild-ios-e... [3] https://googleprojectzero.blogspot.com/2019/08/in-wild-ios-exploit-chain-3.html https://googleprojectzero.blogspot.com/2019/08/in-wild-ios-e... [4] https://googleprojectzero.blogspot.com/2019/08/implant-teardown.html https://googleprojectzero.blogspot.com/2019/08/implant-teard...
- michaelmrose 7y agoNot having adequate permissions or timely updates isn't the same as being mad at Google because they manually enabled a malicious app.
- johndubchak 7y ago> Unmoderated free for all app store I think we should call it Android. Given that, and a lack of a closed ecosystem, is why Android is hacked as much as it is, which is why I would never get rid of my iPhone in favor of an Android device - well, that and the lesser quality hardware, of course. But I think you see my point.
- PhasmaFelis 7y ago> well, that and the lesser quality hardware, of course. As an Apple user, I don't say this very often, but you're seriously drinking the Kool-Aid here. Neither mobile OS has a significant advantage in hardware quality at the high end.
- cmcd 7y agoYeah, this might have been true several years ago but these days you can get Androids with the same specs as iPhones at half the price.
- michaelmrose 7y agoThe alternative has been functional for decades. You have a single "store" interface with user configurable channels which users can add at their own risk. If you don't make it trivial for an attacker to induce a user to configure such a channel you avoid most bad outcomes for stupid people. For example you shouldn't be able to click a link and prompt the user as such prompts do not work. Personally I would expect - A setting in configuration menus to enable 3rd party channels - explicitly entering the channel data - a white list of known safe channels run by good actors even if not reviewed - a black list of known bad channels that can't be enabled
- zepto 7y agoIt’s always trivial for an ‘attacker’ to induce a user to configure a bad channel. Those ‘attackers’ will be the same media outlets who encouraged people to Jailbreak in the early days, or Google and Facebook using their respective monopolies to blanket advertise.