4 ms·
Because they have thousands of employees who have the time to look at the source code and determine whether it is malicious. Nobody else would bother. That’s w
by MagicMoonlight 11mo ago
Because they have thousands of employees who have the time to look at the source code and determine whether it is malicious.
Nobody else would bother. That’s why meme language repositories continuously lead to hacks and vulnerabilities.
- rkomorn 11mo agoApple employees have access to the source code of apps on the App Store?
- deleted 11mo ago[deleted]
- BoredPositron 11mo agoTechnically yes, if they want it you have to give it to them. The dev agreement and TOS is pretty broad.
- rkomorn 11mo agoIs that (Apple asking for source) a frequent thing?
- BoredPositron 11mo agoWe don't know.
- aeonfox 11mo agoApp developers do know. I can't say that I've ever worked on an app where this request has been made. Neither the App Store Connect Agreement[0] nor the Apple Developer Agreement[1] stipulates that the developer can be compelled to surrender their source code. [0] https://appstoreconnect.apple.com/WebObjects/iTunesConnect.woa/wa/termsOfService/ https://appstoreconnect.apple.com/WebObjects/iTunesConnect.w... [1] https://developer.apple.com/support/downloads/terms/apple-developer-agreement/Apple-Developer-Agreement-20250318-English.pdf https://developer.apple.com/support/downloads/terms/apple-de... All the relevant agreements can be found here, so if there's something that specifies this kind of overreach, I'd both be very surprised and interested. https://developer.apple.com/support/terms/ https://developer.apple.com/support/terms/
- BoredPositron 11mo ago“If you are required by law, regulation, or court order to disclose any Apple Confidential Information (which can include requests related to legal investigations or audits), you agree to give Apple prompt notice and to cooperate in seeking a protective order or confidential treatment of such information”
- rkomorn 11mo agoWhat part of this says Apple can compel developers to share their apps' source with Apple? Edit: oh, are you saying that such requests would be "Apple confidential information" so nobody would say if it happened?
- aeonfox 11mo agoThey haven't read the document properly. Here's the definition: > any information disclosed by Apple to you in connection with Apple Events will be considered and referred to as “Apple Confidential Information” and are subject to the confidentiality obligations of this Agreement The definition of Apple Events: > As an Apple Developer, you may have the opportunity to attend certain Apple developer conferences, technical talks, and other events (including online or electronic broadcasts of such events) (“Apple Events”).
- deleted 11mo ago[deleted]
- lapcat 11mo agoWe do know. It has never happened.
- lapcat 11mo agoThis has literally never happened.
- lapcat 11mo agoNo.
- robertclaus 11mo agoApple absolutely does not manually read all the source code they notarized.
- lapcat 11mo agoThey don't notarize source code at all. They notarize compiled app binaries. Many or even most App Store apps are closed source.
- realusername 11mo agoYou are mixing up with Fdroid, Apple doesn't do any source code reading and the tests they do are very basic. Right now you have a lot of piracy apps which are disguised as a "note taking app" and they passed the appstore review without any issues.
- heinternets 11mo agoDo you have any examples? Asking for a friend.