4 ms·
Is it me or most of the features could be a simple app update?
by pt_PT_guy 5y ago
Is it me or most of the features could be a simple app update?
- paxys 5y agoMost of these apps (Facetime, iMessage, Safari, Maps, Wallet, Photos) aren't built using their public SDK but rather have deep dependencies on the OS itself.
- pt_PT_guy 5y agoHumm. gotcha. thank you
- Someone1234 5y agoWhich is why when these apps suffer a security vulnerability they've resulted in privilege escalation (inc. root) previously. I actually think it is a bad look for Apple not to dogfood their own public APIs. Microsoft used to do the same thing with Windows and Office, and it was a bad look then too. Credit to Google on this, since many of their apps are just normal apps. No special privileges or bypasses. Even their special stuff has pretty aggressive sandboxing and can be updated like a normal app via the store.
- defaultname 5y agoHow Apple distributes their core apps (Safari, Mail, etc) is orthogonal to how they are implemented, secured, ring levels, sandboxing, etc. These are separate considerations. Apple's core philosophy is that upgrading the system is the fundamental way to get new things. With iOS 15 we've seen the first real fracture in this model (where they are promoting a "stay on iOS 14 for now" option), and maybe eventually they'll separately distribute some of the tied applications. Google started Android with a very similar model to iOS but quickly recognized it was turning into a disaster given the slow uptake of new Android versions. Turning what were system level components (e.g. play services) into "apps" was a necessity.
- Jtsummers 5y ago> Google started Android with a very similar model to iOS but quickly recognized it was turning into a disaster given the slow uptake of new Android versions. Turning what were system level components (e.g. play services) into "apps" was a necessity. Apple hasn't had that same "pain" yet, iOS update rates are pretty high. If major OS update rates drop, then they'd be better motivated to cleanly separate their app updates from their OS updates. It just hasn't happened yet. https://www.macrumors.com/2021/06/04/ios-14-installation-rates-june-2021/ https://www.macrumors.com/2021/06/04/ios-14-installation-rat...
- Someone1234 5y ago> How Apple distributes their core apps (Safari, Mail, etc) is orthogonal to how they are implemented, secured, ring levels, sandboxing, etc. These are separate considerations. Strongly disagree. If Apple distributed their apps as normal apps, they'd have normal privileges and when exploits are found the scope would be limited to that app domain. Instead, what we have seen is that Apple's apps act like system services, and when escapes occur it can cause a wide-ranging impact (inc. root). iMessage just in the last two weeks had to be emergency patched (14.8) because of a root breakout used by an Israeli's company (NSO Group) surveillance software that they were selling to unsavory governments. If iMessage was a normal app distributed by the app store the scope would have been iMessage, instead of root.
- deleted 5y ago[deleted]
- defaultname 5y agoI understand that you disagree, however your disagreement seems to be based upon a pretty significant misunderstanding/lack of knowledge both about these apps and their privileges.
- Someone1234 5y ago> misunderstanding/lack of knowledge both about these apps and their privileges. Yet you've been able to present none. According to your claims the zero-click escape that caussed the critical 4.8 security update to be released in the last two weeks isn't possible, and yet it happened. So please, by all means, explain why Apple's apps should be structured like this: https://googleprojectzero.blogspot.com/2020/01/remote-iphone-exploitation-part-1.html https://googleprojectzero.blogspot.com/2020/01/remote-iphone... https://googleprojectzero.blogspot.com/2021/01/a-look-at-imessage-in-ios-14.html https://googleprojectzero.blogspot.com/2021/01/a-look-at-ime... Instead of being normal apps with self-contained app domains that would also limit any exploitation.
- vadfa 5y ago>Microsoft used to do the same thing with Windows and Office, and it was a bad look then too. And Internet Explorer, which was one of the pillars of United States v. Microsoft Corp.
- cmelbye 5y agoIt doesn't make any sense for a company to ship "dog food" publicly to developer partners. In fact, the decision to make an API public is critical to get right and should not be taken lightly. Making a mistake in private APIs creates some burden within Apple as revisions are made, but this is to be expected from pre-release software. Making a mistake in public APIs erodes the trust of partners that invested time and money in the platform, and it leads to subpar user experiences.
- slig 5y agoI wonder how Chrome, WhatsApp, Google Photos, Instagram, etc, can make their apps run anywhere using only public APIs and Apple can't.
- noahtallen 5y agoOne of the biggest ones (focus modes) might not be, as well as SharePlay (if it uses a new platform SDK). But new maps features totally could be an app update. I’m guessing apple has determined it to be more beneficial to do one big update at the same time instead of incrementally adding features to apps.
- deleted 5y ago[deleted]
- whywhywhywhy 5y agoStarting to feel that way with a lot of phone features too. Remember when they put Memoji only in the iPhone X. I know they used the IR camera for fancy expression detection but really it's debatable how far ahead it was from anything Snapchat etc were doing on all hardware.
- deleted 5y ago[deleted]