4 ms·
> This technical failing probably, partially, explains why they are so against allowing sideloading. This occurred to me the other day. I've always laughed at
by NotPractical 2y ago
> This technical failing probably, partially, explains why they are so against allowing sideloading.
This occurred to me the other day. I've always laughed at the idea that Apple blocks sideloading for security purposes, but if the first line of defense is and always has been security through obscurity + manual App Store review (>= 2.0) on iOS, it's very possible that sideloading could cause problems. iOS didn't even have an App Store in release 1.0, meanwhile the Android security model has taken into account sideloaded apps since the very beginning [1]:
> Android is designed to be open. [...] Securing an open platform requires a strong security architecture and rigorous security programs. Android was designed with multilayered security that's flexible enough to support an open platform while still protecting all users of the platform.
[1] https://source.android.com/docs/security/overview https://source.android.com/docs/security/overview
Edit: Language revised to clarify that I'm poking fun of the idea and not the one who believes it.
- threatofrain 2y agoIs there a reputation of a security difference between Android and iOS? And in what direction does the badness lean?
- beeboobaa3 2y agoThere is a reputation of Apple being more secure, but it's largely unfounded. It just looks that way because the ecosystem is completely locked down and software isn't allowed to exist without apple's stamp of approval.
- kbolino 2y agoApple drove genuine security improvements in mobile hardware well before Android, including dedicated security chips and encrypted storage. The gap has been closed for a few years now, though, so the reputation is not so much "unfounded" as "out of date".
- beeboobaa3 2y agoYou're not talking about security that protects end users against malware. You're talking about "security" that protects the device against "tampering", i.e. the owner using it in a way apple does not approve of. Apple's "security improvements" have always been about protecting their walled garden first and foremost.
- fingerlocks 2y agoThis just isn’t true. We have multiple bricked android devices from bootloader infected malware downloaded directly from the Play store. Nothing like that has ever happened on iOS.
- beeboobaa3 2y agoThe only thing this may prove is that Apple's app store review is more strict.
- fingerlocks 2y agoYeah, along with the API entitlements. That’s how sandbox security works.
- kbolino 2y agoA mobile device, in most users' hands: - Stores their security credentials for critical sites (banks, HR/payroll, stores, govt services, etc.) - Even if not, has unfettered access to their primary email account, which means it can autonomously initiate a password reset for nearly any site - Is their primary 2FA mechanism, which means it can autonomously confirm a password reset for nearly any site That's an immense amount of risk, both from apps running on the device, and from the device getting stolen. Both of the measures I mentioned are directly relevant to these kinds of threats. And, as I already said, Android has adopted these same security measures as well.
- beeboobaa3 2y ago
- spacedcowboy 2y agoI'm not claiming that Apple is perfect, but I think comparing to Android, in terms of malware, security updates, and privacy, it comes out looking pretty good.
- beeboobaa3 2y agoGot some sources to cite, or is this the typical apple fanboyism of "android bad"? I've used android for years, never ran into any malware. I've also developed for android and ios. Writing malware is largely impossible due to the functional permission system, at least it's much, much harder than the other operating systems. Apple just pretends it's immune to malware because of the manual reviews and static analysis performed by the store. It's also why they're terrified of letting people ship their own interpreters like javascript engines.
- Aloisius 2y agoA bit old but, https://www.pandasecurity.com/en/mediacenter/android-more-infected-than-ios/ https://www.pandasecurity.com/en/mediacenter/android-more-in... One might argue that Android is targeted more than iPhone because of its larger userbase which certainly may contribute to it, but then MacOS which has a fraction of the userbase is more targeted than iOS - that makes the case that sideloading or lax app store reviews really are at least partly to blame. Given much of the malware seems to be apps that trick users into granting permissions by masquerading as a legitimate app or pirated software, it's not really too hard to believe that Apple's app store with their draconian review process and no sideloading might be a more difficult target.
- beeboobaa3 2y agoObviously a strict walled garden keeps out bad actors. The question is: Is it worth it? I say no. People deserve to be trusted with the responsibility of making a choice. We are allowing everyone to buy power tools that can cause severe injuries when mishandled. No one blinks an eye. Just like we allow that to happen, we should allow people to use their devices in the way that they desire. If this means some malware can exist then I consider this to be acceptable. In the meantime system security can always be improved still.
- GeekyBear 2y ago> the Android security model has taken into account sideloaded apps since the very beginning Counterpoint: tech websites have literally warned users that they need to be wary of installing apps from inside Google's walled garden. > With malicious apps infiltrating Play on a regular, often weekly, basis, there’s currently little indication the malicious Android app scourge will be abated. That means it’s up to individual end users to steer clear of apps like Joker. The best advice is to be extremely conservative in the apps that get installed in the first place. A good guiding principle is to choose apps that serve a true purpose and, when possible, choose developers who are known entities. Installed apps that haven’t been used in the past month should be removed unless there’s a good reason to keep them around https://arstechnica.com/information-technology/2020/09/joker-the-malware-that-signs-you-up-for-pricey-services-floods-android-markets/ https://arstechnica.com/information-technology/2020/09/joker... "You should not trust apps from inside the walled garden" is not a sign of a superior security model.
- NotPractical 2y ago> Counterpoint: tech websites have literally warned users that they need to be wary of installing apps from inside Google's walled garden. This is not a counterpoint to what I was saying. I'm talking about sideloaded apps, not apps from Google Play. I agree that Google should work to improve their app vetting process, but that's a separate issue entirely, and one I'm not personally interested in.
- GeekyBear 2y agoIf your security model is so weak that you can't keep malware out of the inside of your walled garden, the situation certainly isn't going to improve after you remove the Play store's app vetting process as a factor.
- NotPractical 2y agoI avoided making a claim regarding the relative "security level" of Android vs. iOS because it's not easy to precisely define what that means. All I was saying was that Android's security model explicitly accommodates openness. If your standard for a "strong" security model excludes openness entirely, that's fair I suppose, but I personally find it unacceptable. Supposing we keep openness as a factor for its own sake, I'm not sure how you can improve much on Android's model. This discussion seems to be headed in an ideological direction rather than a technical one, and I'm not very interested in that.
- saagarjha 2y agoAndroid and iOS have largely the same threat model with it comes to platform security. That is, app review mostly does not exist and the OS itself must protect the user.