8 ms·
Then don't use this particular app? This already exists today: A lot of apps are android-only, or jailbreak-only. In the same sense, tomorrow we'll likely have
by roblabla 4y ago
Then don't use this particular app? This already exists today: A lot of apps are android-only, or jailbreak-only. In the same sense, tomorrow we'll likely have amazon-store-only apps.
In practice I doubt many apps will use a third-party appstore. Apple has a lot of leeway in how they will implement the regulation - they can make it painful enough to use a third-party store that most popular apps will want to keep using the primary app store to get maximum reach. Just like how almost every android app is on the google play store - despite sideloading being a thing since forever.
- est31 4y agoThe issue is what if you have to use a specific app to access some service or community. And then that app requesting access to your location data and your address book even though there is no point in it requesting either. Sure you can deny but if you do it, the app will refuse service. It can only be solved by the app store requiring that users denying access won't result in the app refusing to work, or only the features will refuse to work that actually need that data. "just don't install the app" won't work in many, many cases.
- MichaelCollins 4y ago> The issue is what if you have to use a specific app to access some service or community. Such compulsions are the real problem. In a free society, nobody should be compelled to have a phone at all, let alone install software on one. Government services in particular should never be gated in this way. If no compulsion exists, then there is no problem with people having the choice to use any appstore they wish. If by 'have to' you mean something along the lines of "My brother keeps badgering me to install WhatsApp" then the answer is to simply say "No." Real example. He texts me instead.
- warkdarrior 4y agoIn US I have not seen any government services that are available only via mobile devices. Most online government services are accessible via a website, and one can go to a public library to use a (non-mobile) computer there.
- est31 4y agoIt's thankfully not mandated by governments. However, often there is social pressure to obtain a given app. E.g. when a friend group is all on snapchat and they organize outings via the group chat. Do you want to be left out of that discussion and only be informed by one person from that group who forwards the decision when and where to go to you?
- hammyhavoc 4y agoSounds like you need better friends.
- laggyluke 4y agoIdeally OS should give you a way to feed such evil apps some fake / spoofed data. I believe a rooted Android used to allow something like that, not sure if that still works nowadays.
- est31 4y agoThe app might be able to detect the pattern generated by the fake data generator and refuse to work in that instance. E.g. apple's approximate location feature often puts you into the city center at a very specific location. It's trivial to detect devices that are always at that precise location and only move around in discrete steps between those points. This can lead to an arms race where the OS creates increasingly advanced/realistic fake data, and apps get increasingly sophisticated logic. So I'm not a fan of solving this the technical way. A policy is way better, but you need to be able to enforce it.
- laggyluke 4y agoWhy not both? Sure, it'll lead to arms race like you describe on one side, but let's say 99% of the apps won't even engage in that arms race if the fake data is generic enough to cause a high number of false positives (blocking someone who's not actually faking the data). Then, we can focus on the remaining 1% of worst offenders to actually enforce the policy.
- yoavm 4y agoBut this doesn't really happen on Android now. Even though I can sideload apps and use different app stores, my bank never told me to get their app from Shady Store and the public transport company didn't ask me to you F-Droid. The official app store is still _the_ place you find apps in, you're just _also_ free to wander on your on.
- est31 4y agoThe most famous example of an app choosing not to be on the play store is Fortnite. Google even had to add a feature to their play store search to show a message that Fortnite is not available, so that people don't get desperate and install one of the many scams. Fortnite did this because they didn't want to pay the Google tax, but other apps might do it because they want to spy on users more. The danger exists.
- ThatPlayer 4y agoWe can always use Apple's favorite defense on why they don't have an app store monopoly: use your browser. Facebook, Instagram, TikTok etc. all still work via the browser. I don't know a single one that doesn't (though I could be wrong)
- thefounder 4y agoAnd the browser sucks on purpose for app development/distribution.
- krzyk 4y ago> use your browser Yeah, but I can't I can use only Safari engine, and I would like to use Firefox one.
- derefr 4y agoYeah, but for the apps that are on iOS devices, Apple is effectively currently standing in the position of "the lawyer who writes a 4000 page contract to de-risk the wish they're making with the evil wish-granting genie", so that we don't have to. Apple forces apps on their store to obey certain restrictions that make life better (less tracked, especially) for consumers; and those restrictions are begrudgingly accepted by the developers, because there's no other way for the dev to access the iOS user-base. As soon as those devs can avoid Apple's restrictions and deliver their apps directly to users with the "intended" experience, they will. Personally, I like neutered-evil-genie apps, and will be sad to lose them (i.e. have them turn into unfettered-evil-genie apps, which I won't use.)
- easton 4y agoIsn't the answer for Apple to provide operating-system level restrictions to apps (regardless of source) that make it so the only way any application on the system can access the identifier is by permission from the user? I wouldn't be surprised if this is how it works right now anyway, just because an app is deployed by an enterprise developer doesn't mean it should be able to bypass the app tracking transparency prompt. Or does the EU law prevent them from having private APIs/system components period? It seems like many people are making the assumption that this means that every single sideloaded app will be able to bypass all of the privacy/security features on the device, and I don't see why that would be. My understanding is that this is for "fairness", which would mean that apps that are sideloaded would have the same level of access as those on the App Store, meaning they use the same APIs that trigger the same prompts.
- derefr 4y agoNo, because this isn't about OS-level identifiers; it's about things like e.g. applications working together to track you by passing permacookies through Shared Containers; or about apps that ask for microphone privileges then listening for ultrasound beacons in retail stores to determine their location. These are the sorts of prohibited behaviors that can be heuristically recognized by technical means (e.g. static analysis), but where any such recognition would necessarily result result in tons of false positives; and so those issues, when raised, must be passed to a team of human auditors for determination. This is, by-and-large, why App Store submissions — even for updates — still require that human-auditor step. They're always watching for those seemingly-minor "this app got sold to someone evil" updates that slip in spyware — the kind you see often with Chrome Extensions.
- elzbardico 4y agoThen YOU don't use this particular brand of smartphone?
- 2muchcoffeeman 4y agoI think they have to make side loading a painful developer only endeavor. Other wise you can end up like the streaming situation where people are just giving up with all the subscriptions and just pirating everything.
- thefounder 4y agoPirating should be a breath of fresh air on mobile. Maybe the streaming services will finally start providing more value.(i.e shared catalog)
- highwaylights 4y agoUltimately I think the only person this benefits is Tim Sweeney, as he gets the Epic store on iOS/Android/Playstation/Xbox. Realistically this just drives people into a different walled garden. One that is device-vendor agnostic, but a walled garden nonetheless - in that your purchases are tied to Epic. This law could have been so much better, but now it just trades one problem for a bunch of new ones (some even worse than what it's trying to solve). One thing that might have been nice - making allowances in the law for centralised certification authorities with fixed tariffs, so that Apple still checks the builds as it does now for the App Store, but then the builds can be released elsewhere (as the signatures will match). For this they could charge a fee, which could be capped in the law at a percentage of the sale price (and obviously much lower than 30%). This way iOS/Android could still have guaranteed protection, for which Apple/Google's costs are covered, but the user would have freedom to get their software from wherever. The problem is that hardline free software advocates would still complain about this, insisting that the certification authority be scrapped. iOS and Android are now Windows, and it's going to be a mess.
- selfhoster11 4y agoYou underestimate the blessing that is an app store that's free of bullshit policies restricting what you can and cannot publish. With F-Droid on Android, I used to have access to apps like NewPipe that Google would never even consider carrying on their app store, but - because I had a third party store, that wasn't a problem. Now that I have an iPhone, I miss NewPipe greatly. But with this law, I might be able to get something like it in a few months without jailbreaking.
- highwaylights 4y agoNot underestimating it at all, it has value. Unfortunately it undermines so much of the security model in other areas that both platforms will rapidly become malware swamps.
- alsetmusic 4y ago> Then don't use this particular app? And when your employer / school / insurance provider / other requires it, what then?
- hammyhavoc 4y agoA dedicated phone for work/school that operate BYOD schemes? VM?