7 ms·
It’s extremely complex. I’m not debating whether they should comply - they should. But it’s gonna cost them years of engineering effort, and maintenance far int
by interpol_p 1y ago
It’s extremely complex. I’m not debating whether they should comply - they should. But it’s gonna cost them years of engineering effort, and maintenance far into the future. See, for example, BrowserEngineKit
https://developer.apple.com/documentation/browserenginekit https://developer.apple.com/documentation/browserenginekit
They needed to engineer, maintain, document and support a whole class of APIs so that third parties can create their own competitive browser engines (that offer JIT, etc) while still maintaining iOS sandbox security. There are going to be hundreds of frameworks, thousands of APIs, that will need to come to ensure compliance with the DMA
- idle_zealot 1y agoOr, they could just let their pocket computers run the software users download and install, like every single other computer ever made and sold, rather than special-case engineer padded cells for every use-case, application class, or bit of interoperability.
- bzzzt 1y agoYou mean those users that don't even know what an application is? And you mean that software that only has the users best interests in mind and is not spying on them, trying to scam or confuse them into buying unnecessary stuff? I think Apple has done a great job of protecting non-technical people from a lot of the possible harms of malware. There's a lot of incentive for them to make sure security is handled right. I'm convinced going back to the 90s and giving every software developer full access to users phones would create a lot more problems than it would solve.
- grishka 1y agoMaybe let's not optimize everything around people being tech-illiterate? We live in a society. You are expected to have some baseline knowledge to live in one. So let's instead educate people about that stuff instead of encouraging ignorance and punishing power users.
- bzzzt 1y agoWould be nice if everything instantly became better with a bit of explanation, but I'm just a bit to cynical to trust that. Most people using tech need guard rails.
- grishka 1y agoYes, guard rails are good. I'm not denying that. They are an important part of user education. But only when they can be overridden. MacOS around 10 years ago is a good example. It came out of the box in a foolproof state — only apps from the app store or registered developers would run, and SIP is enabled. But if you know what you're doing, you could disable both those things without any loss of functionality.
- bzzzt 1y agoYou can see the problem by browsing old help forums and see how often people suggest 'disable SIP' as a solution to some problem instead of really fixing the problem. Also, the clueless user will -at best- just follow instructions and disable all kinds of security features making them more vulnerable to malware.
- grishka 1y agoIf someone is trying to help themselves by participating in forums and following instructions, that's already very much an above-average user. They'll be fine anyway. I'm talking more about the kinds of people who would download a .jpg.exe and run it. Or transfer their savings to a "safe account" because someone called them out of the blue and told them to do so. Or fall for scammy ads. You get the idea.
- bzzzt 1y agoI'm more concerned about the 'good with computers' type people helping the average users. Those are the people who use google and forums and leave other peoples phone and/or computer in a less than optimal state which makes the .jpg.exe attack more likely to succeed.
- itopaloglu83 1y agoAn iPhone isn’t a pocket computer. It needs to be really secure because someone gaining full access to it through a badly written browser would cost you your life savings if not your life for some.
- grishka 1y agoHow and why is that somehow fundamentally different from someone gaining complete access to your computer, which allows you to run anything freely? Both are your personal devices that store your sensitive personal information.
- itopaloglu83 1y agoThat’s a very good and valid question but did they sell the device with the premise that anyone can run any app they want or only the apps Apple approved can run? We believe in the same thing, our devices should be free like speech. But the whole thing turned into a show because some rich software companies don’t want to pay Apple 30% while they have no problem with other platforms like gaming consoles.
- grishka 1y agoApple does market the iPhone as a general-purpose communication and computing device. Not an appliance like a game console. Most iPhone users don't know what making an app is like, how asinine the app store review process is, and what kinds of bonkers rules developers have to follow. Apple initially did that to protect the ecosystem from malware and make sure all apps meet their quality standards. Also to make distribution easy for indie developers. All commendable goals. But as the iOS market share grew, this turned into a very convenient revenue source that they can't let go now.
- itopaloglu83 1y agoThe Original iPhone didn’t have any apps and Apple later created their own ecosystem with an end user agreement which supersedes the ads. The digital market should be regulated for sure but what’s happening is a bunch of companies who are in the digital market (and not regulated themselves) exploiting the public sentiment and the regulatory processes. Spotify and others fail to mention that they were able to access billions of Apple customers without paying a single dime to Apple initially which is unheard of in business relationships.
- interpol_p 1y agoThat is an oversimplification of what I stated. Apple has a significant engineering challenge to turn their current operating system into something that allows side-loading similar to what Google offers. It's not a matter of "commenting out an if statement" The current developer SDKs Apple offers are strongly tied to their services, which cost them money to run. So first thing is, they have to decouple that so developers can implement applications using a baseline SDK that does not use Apple services (no iCloud, no Maps, no HealthKit and so on) I think it would be great for users if they did do this. It would be akin to what Google does by shipping and updating Play Services separately from the base Android install The reason I linked BrowserEngineKit is because if you want to do this properly, you have to build something like Apple has built with that framework (which was built to comply with these policies). Take for example, implementing your own JIT: because arm64e uses pointer authentication, the system uses PACs to ensure that pointers into executable code have not been tampered with. Apple now develops and supports a whole slew of APIs like `be_memory_inline_jit_restrict_rwx_to_rw_with_witness()` in order for developers to manage this themselves. You saying "just let their pocket computers run software users download and install" is not like every single other computer ever made and sold. This is a gross oversimplification of the modern state of computing, both on mobile and on desktop. There are reasons you don't want random developers loading code into your OS kernel, and Windows and macOS both have protections for this (though the CrowdStrike crashes recently shows what happens when those protections are lax!)
- msgodel 1y agoIf Apple gave the users root and let them run arbitrary software and just didn't sign certificates for their infrastructure (for push for example) this wouldn't be a problem. Supposedly they've already even developed a VTE for iOS. All they need to do is have a toggle under settings to disable signature checking and ship the VTE so people have an escape hatch and everyone would probably calm way down.
- interpol_p 1y agoSure, I'd be into that. But that would not comply with the DMA I think? As in, Apple still has a ton of work to do, engineering wise, if they are to make their platform available to all in the way specified by the DMA For example, I don't think it would fly that they could say to the EU: users who want a third-party browser just have to enable root access and lose access to all Apple services and authentication
- EMIRELADERO 1y agoSomehow, Android manages to do it. Not only for browsers; all apps have JIT access without any entitlement/review needed. It doesn't seem like the average Android user is worse-off because of that, security-wise.
- grishka 1y agoAnd Android apps can be installed from apk files without any Google involvement whatsoever. All apks are self-signed anyway and signing identity only comes into play for updates, not initial installation. As in, when you first install an app, it doesn't matter who signed it, but installing an update over an existing app requires the new apk to be signed with the same certificate as the initial one. This is to protect the potentially sensitive data in app's private storage (under /data/data). But iOS requires that everything be signed by Apple in one form or another. Even debug builds of your own apps you run on your own device from Xcode. IMO, it is absolutely unacceptable to market your devices as general-purpose ones, make the SDK public, but still be an intermediary in app distribution for no good reason whatsoever. I'm surprised the EU is so seemingly patient with Apple's clearly contemptuous conduct.
- interpol_p 1y agoGoogle engineered and maintains the system that allows you to install APK files. This is my point. The fact that they have developed a security model around APK updates is exactly what I'm talking about. If Apple wants to offer something similar, now, they are going to have a lot of work cut out for them. You're not thinking this through, it's not a magic button Apple presses. They are going to have to develop a ton of frameworks just to get something like installable APKs. Apple allows developers to use iCloud and Maps for free. Presumably because you distribute through the App Store. So if they allow for side-loading they're going to have to lock down and split their App Store "services" into a separate framework — hey, sounds familiar? Just like Google Play services. Separating out all of Apple's authentication layers, paid and cloud services, and ensuring apps can be cleanly distributed without dependencies on those things it not a trivial engineering exercise. I'm not trying to imply that Apple should not comply with the DMA. I believe they should. I also believe that it would be a seriously complicated thing to extract their App Store services from their developer APIs in such a way that people could develop against a baseline SDK sans Apple services.