5 ms·
When has Apple made that promise? Where do they make that promise? No system is perfect, and when you get the realm of people submitting privileged information
by defaultname 5y ago
When has Apple made that promise? Where do they make that promise?
No system is perfect, and when you get the realm of people submitting privileged information to third parties, all bets are always off. There is absolutely no way Apple could make guarantees about that. And they don't. Anywhere.
And no, saying that they review apps isn't a promise that it is "completely secure". That is absurd.
Trying for some security and confidence is a world removed from absolute security. The latter is effectively impossible.
This thread is farce. Anything if it gives people an opportunity to ply their rhetoric. It is a reminder that while HN has some good discussions, it has a lot of people who just want to make stupid arguments based on lies.
"But I thought you said TLS was completely secure? How could someripoffsite.com steal my cash?"
- smoldesu 5y ago> When has Apple made that promise? Where do they make that promise? From apple.com/privacy: "Every one of the more than 1.8 million apps on the App Store is required to follow strict privacy guidelines and report how it uses your data. And every app is rigorously reviewed by a team of experts at Apple."
- defaultname 5y agoWhich doesn't say or claim that it's "completely secure". The notion is preposterous if third parties are involved. Only a Sith deals in absolutes. Then again, so do people making disingenuous arguments online.
- delfinom 5y agoIdk, when I see " rigorously reviewed", I think being able to see the app is attempting to masquerade as an existing one...
- defaultname 5y agoWe are discussing the claim that Apple guarantees every app is "completely secure". Thanks for the comment though.
- smoldesu 5y agoExcuse me, they used the words "every one of" and "every app" to describe the purview of their security checks. Is that somehow not absolute enough for you?
- defaultname 5y agoTo be clear, you read "we review every app" and from that your interpretation is that every app is "completely secure". To be polite, ROFL. Either you're posing a disingenuous argument to win a pathetic internet argument (which is hilariously dumb, but here we are), or you're stupid. Which is it?
- ellenhp 5y agoIs the idea that a nontechnical person might trust Apple really that outlandish to you? Do you have, like, family members or nontechnical friends?
- DangitBobby 5y agoAny reasonable reading of this sentence, while technically it does not explicitly say that it's "completely secure", is that the review process will include security review. It's not without context that this sentence is read, and the history of software tells us what the point of such a review is for protection of the user. Being technically correct is not actually useful when deciding how reasonable people will interpret a piece of marketing material. They are using strong language to give the reader confidence that the apps are safe and they should not be afraid to use them.
- extra88 5y agoPrivacy and security are not the same thing. Also, an app can follow all the privacy and security guidelines and still use dark patterns to mislead and get something from you that you wouldn’t otherwise give up or outright defraud you. I’m sure Apple makes a good faith attempt at preventing that as well but they can’t catch everything.
- lukifer 5y agoThe words "strict" and "rigorous" do a lot of heavy lifting in setting user (and market) expectations. We programmers are pre-inclined to think in terms of Boolean logic, but the law frequently splits hairs on qualitative value judgments; there is no simple rubric for what counts as "reckless endangerment" or "gross negligence", for instance. I think it's a given that no one expects any QA or security process to perform perfectly. But there's some fuzzy line past which Apple's process fails to be "rigorous", and whatever that line is (or should be), courts will inevitably contrast the high expectations set by Apple's marketing with these real-world results when considering claims of negligence, liability, false advertising, anti-competitive behavior, etc.
- simondotau 5y agoIn my opinion, this anecdote is enough reason for Apple to reject any app that purports to be a cryptocurrency wallet or in any way be a secure mechanism for cryptocurrency. There's no practical way for Apple to prove that any app won't betray the user. Or in the alternative, Perhaps Apple should create a different tier of app review for any apps which claim to facilitate financial transactions (other than purchases, game currencies and microtransactions). This would encompass all apps for banking, investment and crypto. This tier should require a much higher verification of the developer's identity. The iOS sandbox should be further locked down to limit communication only to whitelisted IPs/domains which must all be under the control of the verified developer. And hey, you know what, let's even require the developer to submit the app in source code form.
- lukifer 5y agoI remember the early of days of Bitcoin, when Apple was rejecting wallet apps by default. I was honestly surprised that they relented: from consumer safety, to regulatory concerns, to 30% protectionism, they have every incentive (from their walled-garden/theme-park philosophy) to categorically ban on-device wallets. > There's no practical way for Apple to prove that any app won't betray the user. This is honestly a fundamental problem with both the App Review model, and the very concept of cryptocurrency (which for the record, I'm positively inclined towards, both technologically and ideologically): - The Review model because the developer doesn't actually submit code, and static analysis tools can only go so far. Even if Apple started requiring source (opening many thorny IP liability issues), no reviewer can realistically audit every line. Even then, the mere fact WebViews are trivially common means a developer (or a malicious hacker) can always swap out the web backend with phishing attacks, credit card scams, etc. - The cryptocurrency model because while it tells a story of "trustless" interaction and autonomy, in practice even the most knowledgable techies end up having to outsource trust to developers, firms, and communities. While it tends to be a safe bet to trust a highly-trafficked community GitHub over a random .ru site, (a) it still requires making a trust decision on imperfect information, and (b) non-technical users suffer an agent-principal dilemma when it comes time to make those decisions, which is a prerequisite to actually use crypto-currency. There are many, many shortcomings to the central-banking state currency model; but at least it has a pretty well-defined UX to the average "holder", and some hope of recourse in the event of a scam. FWIW, browser-based wallets (with or without client-side storage) do exist, and would probably be used more heavily on iOS if Apple were to forbid native wallets. In which case, it's possible the guy who lost his life savings would have gotten scammed by a "trusted" web app instead.
- toast0 5y agoHow we use your data: Your private key is used to sign a transaction transfering your bitcoin to our account. We do not share your private key with anyone and it does not leave your phone.