3 ms·
The problem is that a JIT implies that you can load arbitrary binary code into memory and execute it. This means that your app can load arbitrary updates from
by pilif 2y ago
The problem is that a JIT implies that you can load arbitrary binary code into memory and execute it.
This means that your app can load arbitrary updates from the server and execute them, for example based on some purchase not made in the AppStore.
This is all about keeping the 30% tax and only tangentially about security.
- madeofpalk 2y agoWell, it's about bypassing App Review and other static security analysis, undocumented apis, etc. I think there's a fairly strong case here that it's about more than just protecting revenue (which it is also!)
- pilif 2y agoGiven the sandboxing and the security architecture of iOS, my conjecture is that apps could be perfectly safe even in light of the use of undocumented APIs (calls to which can be and are obfuscated even in today's setup) and accidental security flaws (which can and still do exist even in today's setup).