6 ms·
Well that was the original android phone idea. Get a hackable open device that you can write apps for your self. Even attach third party hardware to it for extr
by vincnetas 2mo ago
Well that was the original android phone idea. Get a hackable open device that you can write apps for your self. Even attach third party hardware to it for extra functionality with lots of customisation. But this idea has mutated quite a bit.
- mosura 2mo agoEven by 2015 the noise in Google was “the Chrome OS model is better” with reference to them centrally controlling everything. Andy Rubin was no saint, on so many levels, but when he was removed from Android leadership and the Chrome culture effectively took over this was always how it was going to go.
- dainiusse 2mo agoI fully agree with it. But I think Google also understands that the platform is unatractive for businesses. In my case I just don't do Android app because I know it is easy to just take and hack. It is not the case on iPhone. And my app is one time payment so the ability to just copy out the APK leaves me not doing an app at all...
- _imnothere 2mo ago> I know it is easy to just take and hack No you don't, otherwise we wouldn't have banking apps on it.
- graceful6800 2mo agoHave you tried extracting, decompiling, and modifying someone else's app? It wasn't hard before LLMs and it's nearly trivial now.
- hparadiz 2mo agoThe crypographic flow that allows payments to work is straight up pub/priv key encryption with one time use tokens. It's not something you can hack. As soon you see the token it's already been used and thrown away. So whatever nonsense about decompiling literally doesn't matter.
- skinfaxi 2mo agoYou can patch out the payment checks if you can decompile it
- hparadiz 2mo agoThe payment doesn't happen on the device. It happens at the VISA/Mastercard/AMEX level. So "the app" should be doing the validation upstream on the server side and simply reporting yes/no to the app. If you hack the yes/no okay but most payments are for physical things IRL so the payment gateway that is not on your phone is gonna be like ??? - in other words it's on the app not to trust a raw true/false signal and instead rely on server side checks. This is all irrelevant. I make regular massive purchases on my linux box where I can read the memory. It doesn't change anything.
- skinfaxi 2mo agoAh I see you are focusing on apps that have some web component that would enable ongoing authorization. I was thinking about apps that offer a trial but you can upgrade with an in-app purchase and there is no ongoing service component.
- jfyi 2mo agoSo your professional opinion is that the attack surface of mobile banking apps is limited to tokenized payments? Honestly, I'd be appalled if tokens were routed through my banking app. There is no reason the local client needs that data.
- hparadiz 2mo agoMy professional opinion is that APKs can be de-compiled regardless and that has nothing to do with tokenized payments themselves which are like you said handled through server-server communications at the payment processor level. Your phone simply sends a one time use token to authorize the transaction.
- 2mo ago
- skinfaxi 2mo agoIs that not possible with ios applications?
- Xirdus 2mo agoYou can't sideload iOS applications. Meaning there's no point to doing any of the listed things.
- drdexebtjl 2mo agoOf course you can. How do you think developers test their apps?
- actionfromafar 2mo agoNormal people can't. I'd bet more people run jailbroken than bothering with developer-mode sideload.
- Xirdus 2mo agoNever did iOS development. I always assumed it requires active USB connection with a dev machine or an emulator.
- stevefan1999 2mo agoYou technically can sideload. For 7 days or on TestFlight
- fsflover 2mo agoThis is not a practical way for installing apps though.
- dainiusse 2mo agoIt is a bit different. My app doesn't rely on 3rd party services at all. It just provides functionality. It is not about breaking into someones account. I just know that the app can just be cracked - there are plenty of sites that do that for android. Because you can't just load your app on iOS - this is just not possible (well perhaps there are a few percent of some jailbroken iPhones, but that is neglibile). On Android though, you can soon see such app stolen and on some of the apk warez sites. It just breaks the model.
- stevefan1999 2mo ago> On Android though, you can soon see such app stolen and on some of the apk warez sites. It just breaks the model. Think about Windows and software privacy
- kotaKat 2mo ago> Because you can't just load your app on iOS - this is just not possible (well perhaps there are a few percent of some jailbroken iPhones, but that is neglibile). No, smart normies are sideloading with the 7-day limit and leveraging automation to have their pirated apps automatically re-sign and re-push. If you pay the $99 to Apple for a dev cert (or like $10 to a service that'll sell you a cert off someone's account), it'll even just sign out for the year for you. No screwing with Xcode or anything, just drag-drop-sign. Even gives you the options to patch the app out at resigning so you can do hacks and mods like the good old jailbreak days. https://sideloadly.io/ https://sideloadly.io/
- kmeisthax 2mo agoThe only difference between iOS and Android when it comes to loading code onto your device is that, on iOS: - You have to setup a developer account with Apple first, and dev-signed apps can only be installed onto specific provisioned devices only[0] - The free tier of that developer account is inconvenient for actually using dev-signed apps as a daily-driver, and won't let you use certain entitlements - Apple's dev tooling is designed to make it feel like you can only sign code you're compiling yourself On the surface level, this might seem like a big difference, because Android has a command that lets you load arbitrary APKs with no particular fanfare or ceremony, while Apple's dev signer is buried inside of a compiler/IDE suite. But people have built tools to make it easy to take an arbitrary .ipa, sign it using your dev account, and resign it once the free tier's 7 day limit expires. Of course, this still requires you actually go and obtain an .ipa of the app you want to use, and Apple distributes App Store[1] app binaries[2] encrypted. That part requires actually having a jailbroken device to dump the app binary with. But once the app is cracked anyone can install it. If you want an actual "uncrackable" app you need to put a critical part of your app's workflow onto a server, and then have your app send an iOS DeviceCheck or Google Play Integrity attestation that the phone is running the actual App Store/Google Play version of your app. But that's also incredibly draconian behavior towards your customers as it basically forces your app to be always-online... which is why a disturbingly high number of games do this. [0] Yes, I know about Enterprise signing, but Apple specifically forbids distributing Enterprise-signed apps outside of your organization and those apps get revoked all the time. Signing with your own dev account is way more robust and that's what most iOS power users actually use. [1] I have no clue if FairPlay encryption applies to EU-DMA-compliance signed apps. [2] ONLY binaries - all your resources are unencrypted and can be downloaded off the App Store CDN and inspected by anyone. Code signing signatures do apply to resources, AFAIK
- Jean-Papoulos 2mo agoThe people that go through the trouble of installing apks from random websites to not pay $1 are in the minority. What's more, most of them wouldn't pay that dollar if they couldn't find the cracked apk. So the only thing you're realistically doing is cutting yourself off of a huge market. Convenience sells, the Play Store does that
- dainiusse 2mo ago$1 - most probably. What about $20?
- Eueudhsbsj32 2mo agoUnless your target market is a small niche of hackers, then yeah the vast majority would pay $20. Just look at how many pay for music and video streaming services, when it's trivial to download anything for free from illicit sources.
- drdexebtjl 2mo agoThe fact that app piracy is more prevalent on Android has nothing to do with technical differences between iOS and Android side loading, and everything to do with the markets in which iPhones and Android phones are popular.
- curt15 2mo agoDo you target macos or windows, which have always given users full control of software management?