6 ms·
How malware gets into the App Store and why Apple can't stop that
- fortran77 5y agoThis was a very clear explanation of some very serious problems with Apple and the app store. Users who think Apple iOS is secure and private--as Apple keeps explicitly claiming--will be very sorry if their life or well-being depends on being able to have private data.
- azinman2 5y ago“have you heard about any kind of security problems with Android recently? I haven't.” That’s a pretty silly thing to say [1] and a non-argument. Whether or not you’ve personally heard about security problems with android doesn’t mean they don’t exist or aren’t widely known to others. [1] https://www.cvedetails.com/vulnerability-list.php?vendor_id=1224&product_id=19997&version_id=0&page=1&hasexp=0&opdos=0&opec=0&opov=0&opcsrf=0&opgpriv=0&opsqli=0&opxss=0&opdirt=0&opmemc=0&ophttprs=0&opbyp=0&opfileinc=0&opginf=0&cvssscoremin=0&cvssscoremax=0&year=2021&month=0&cweid=0&order=1&trc=363&sha=f1d918201ad0b0851a2b9b9562379023ac51bcd4 https://www.cvedetails.com/vulnerability-list.php?vendor_id=...
- tommymachine 5y agoIn fairness, it's a perfectly acceptable argument if you are an ostrich.
- 2muchcoffeeman 5y agoFlubot
- heavyset_go 5y agoAccording to Zerodium, iOS exploits are cheaper than Android exploits because iOS exploits are so plentiful[1][2] in comparison. It should also be noted that the #1 vector for malware installation on Android is the Play Store itself[3]. The issue isn't Apple or Google's mobile app distribution implementations themselves. The issue is that the app store model was only adopted because of its profitability, and security was an afterthought. Despite this, the companies' PR departments try to paint the app store model as necessary for "security" and then fall short of actually securing things because that might cost money or decrease revenue. There's no competition, so who is going to stop them or force them to improve? [1] https://www.theregister.com/2020/05/14/zerodium_ios_flaws/ https://www.theregister.com/2020/05/14/zerodium_ios_flaws/ [2] http://zerodium.com/program.html http://zerodium.com/program.html [3] https://www.zdnet.com/article/play-store-identified-as-main-distribution-vector-for-most-android-malware/ https://www.zdnet.com/article/play-store-identified-as-main-...
- easton 5y agoThey said that two OS versions ago, pre-Blast Door and the other improvements Apple made (not that those helped against Pegasus, of course). Have they started buying iOS exploits again?
- ghuin 5y ago>According to Zerodium, iOS exploits are cheaper than Android exploits because iOS exploits are so plentiful[1][2] in comparison. On the other hand if your iPhone is vulnerable it will get an update. Can you say the same thing about Android?
- aaomidi 5y agoConsidering Samsung is the majority of Android phones, yes. They keep up and sometimes apply security updates faster than Google.
- xxs 5y agodid you read the article, the author clearly states that Apple chose not to do anything for quite extended period of time.
- lelandfe 5y agoSamsung has the greatest marketshare in the the Android ecosystem[0][1] and they've pledged to provide security updates for 4 years for >130 models[2] – which is pretty good! [0] https://www.appbrain.com/stats/top-manufacturers https://www.appbrain.com/stats/top-manufacturers [1] https://www.statista.com/statistics/271496/global-market-share-held-by-smartphone-vendors-since-4th-quarter-2009/ https://www.statista.com/statistics/271496/global-market-sha... [2] https://arstechnica.com/gadgets/2021/02/samsung-now-updates-android-for-longer-than-google-does/ https://arstechnica.com/gadgets/2021/02/samsung-now-updates-...
- Retric 5y agoTheir 4 year support from phones initial release is still quite bad and the last year is apparently only quarterly not monthly updates. So buy a phone X months after release and you get 36 - X months of monthly security patches and then minimal support for 1 year. That’s a big deal because their manufacturing last years model S20 and many people are buying not realizing it’s apparently got 1.5 years of full support remaining.
- judge2020 5y ago> com.apple.developer.pushkit.unrestricted-voip Do Duo, Otka, or Microsoft Authenticator have the special notification entitlement? These notifications never seem to be delayed no matter what internet climate i'm in unless i'm literally in the middle of nowhere.
- ece 5y agoThis is from the same person that reported iOS vulnerabilities recently: https://news.ycombinator.com/item?id=28637276 https://news.ycombinator.com/item?id=28637276 Thanks for all the work.
- simion314 5y agoSo static analysis will not catch private API usage, so is mostly useless for protecting the users, it is interesting that such a rich company could not hire a team of competent developers to produce an actual secure way to give applications(and users) access to the private APIs. Does Linux/BSD sandboxing system offer such protection?
- ece 5y agoAndroid uses SELinux by default to sandbox apps since v5[1], Linux/BSD have several forms of sandboxing[2], and the most common is probably AppArmor offered by Ubuntu and other distros. A few support SELinux as well. [1] https://source.android.com/security/selinux https://source.android.com/security/selinux [2] https://en.wikipedia.org/wiki/Linux_Security_Modules https://en.wikipedia.org/wiki/Linux_Security_Modules
- nbzso 5y agoUntil we have some outrageously horrible events which will affect directly general population, all this facts will be comfortably avoided and "mitigated". This is systemic problem derived not only from bad management and absence of responsibility. This is "business as usual" with any big corporation. There is no problem until perception of the problem affects sales directly. And in the case with Apple, reality is professionally managed toward "reality distortion field" of uneducated masses who are addicted to "latest tech" and "social validation psychology". I don't know any other corporation which can comfortably keep silence on issues like NSO/Pegasus or just "postpone" intrusion on user privacy as CSAM. People love their shiny toys. This is exactly the dynamic with tobacco companies in the past. People believed in one point in time that cigarettes are "healthy things, recommended by physicians". https://edition.cnn.com/2017/05/24/health/gallery/tobacco-health-claims-history/index.html https://edition.cnn.com/2017/05/24/health/gallery/tobacco-he... It is always psychology first, technology second. Or sales and shareholders first, services and tech appliances second. You can thank "geniuses" like Edward Bernays and his contemporaries for this.
- amelius 5y agoIf Apple wants to insist that they need to have a fully integrated and exclusive AppStore because of "security", then they should be held accountable for security issues. E.g. money-back guarantee at a minimum, and preferably compensation for lost data etc.
- ben_w 5y agoWhile I think Apple can do better, that argument about the App Store doesn’t follow. By analogy: insisting that property follows fire safety regulations doesn’t make governments responsible for arsonists.
- ClumsyPilot 5y ago"By analogy: insisting that property follows fire safety" Terrible analogy, are you really company operating in 'free market' setting T&C to a sovereign nation passing laws?
- rickspencer3 5y agoWhat really galls me is hoops i have to jump through and the money I have to spend to install my own apps written for my own use on an iOS device. How can that be for my own security? The ability to write a program for a computing device is such a fundamental capability, how can a device that lacks this ability even be sold?
- danpalmer 5y agoIt is free to run your own apps on your own device and has been for many years now.
- rickspencer3 5y agoOh? I though I had to buy a $99 developer account,and connect the device with my account to be able to build it and install it. I guess I missed something important in the docs.
- danpalmer 5y agoAnything that requires access to Apple's service – TestFlight, push notifications, Game Center, etc will require payment. If all you want is to stick an app on your phone that's free (as of ~5-6 years ago?). There are limitations. The signature on the binary is only valid for 7 days I believe, so naively you'd have to rebuild/reload every week, however there are certainly automations that do this for third party apps with a little daemon running on your Mac in the background, and I suspect there are equivalent automations for your own apps/open source codebases to reduce the hassle.
- rickspencer3 5y agoSo "free" but still a lot of hoops to jump through. For android I just plop down an apk (like a normal OS).
- nebukadnet 5y agoI worked on my first app for a year before getting a developer license and uploading it to the app store. I had no trouble installing it on my device. You missed something.
- egberts1 5y agoI only download Apple apps that needs no additional privilege nor sends any telemetry back somewhere. Did I do that one right?