If the fake reviews are indeed the reason why the apps were taken off the store, that does strike me as an inappropriate action. Take down the reviews, yes. But closing the developer account creates a big opportunity to eliminate competition by buying fake reviews for your competitors. There's also nothing developers can do to prevent this since they can't curate or reject reviews from what I know.
That said, other commenters are pointing out a very large revenue figure relative to the popularity of these apps. That smells more like money laundering or fraud. In that scenario, Apple should have been more specific in their communications.
This was talked about by Phillip Shoemaker (head of App Store Review 2009-2016) in this talk[0], where some developers figured out that if they hired marketing firms to commit review fraud on a competitor’s app, their competitor would get terminated because there’s no clear way to actually attribute the fraud to the developer.
I guess the App Store fraud prevention team hasn’t necessarily found a good solution yet.
If Apple isn't able to police this then maybe it's unhealthy for the market to be completely controlled by them. They make billions off the AppStore and their refusal to reinvest in proper moderation (especially for an app worth hundreds of thousands in revenue) is quite telling.
This isn't an Apple problem, it's a problem with every business review platform. If a shady marketing firm takes a contract to give an app fake 5 star reviews, there's no way for the review platform to know if that shady marketing firm was hired by the app's developer or their competitor. Only the marketing firm knows.
If the App Store is the only vehicle for selling mobile apps on Apple devices, then by virtue of their monopoly, they have a duty to be entirely transparent and fair. It’s entirely an Apple problem.
Plus, they point to their 30% take as helping to prevent these kind of issues. So if that 30% isn’t helping to police the Apple Store, what is it doing?
You don't seem to understand what a monopoly is. You can't arbitrarily put an app onto their hardware because they built it so you couldn't.
However, not all hardware is created by them. You're free to purchase a different phone, and you can even make the number of app stores supported a primary buying decision.
This kind of reasoning is perfect if you want to halt all future innovation.
Why would someone advance the state of the art in any device if the immediate result is attacks for the new device being a "monopoly" within the scope of the new device or improvements?
What? Aren't AMD, ARM, and Intel advancing the state of the art of CPUs because they have open platforms, and have no monopoly or gatekeeper position on what software can run on their platform?
I can't see why you would be unable to advance the state of the art if you don't block (thus allow) everyone from building on your platform.
What about fridges, toasters, smart TVs, playstations, watches, etc.
All devices made with purpose in-mind and only allow the manufacturer's firmware to be installed and are not "open platforms". In the case of smart TVs and many game consoles, you have a direct comparison to phones as they have a single app store with no competitors allowed on their platform.
Should all of these single purpose decives have to bare the burden and cost of opening up their platform for competitors too?
In one sentence you say "direct comparison," and in the next you contradict yourself by using the words "single purpose devices." A phone is a general computing device. A smart refrigerator is not. Is there even an app store on a smart fridge which contains third party apps?
Whether or not it is a monopoly is a red herring, since being a monopoly is not illegal. Abusing a dominant position in a marketplace is. Apple has dominance in the Apple app marketplace, which they could theoretically abuse by discriminating against competitors. Thus, it is in their interest to be transparent about how they're managing their app store.
They are transparent and fair. Fake reviews are not allowed. Apple has no way to know if you hired a fake review company or if some competitor did. Their moderation team can only check for fake reviews, not who paid for them. Of course, if they ask developers if they did something wrong and they did, they will get lied to.
And it shouldn't be Apple's problem. Apple is not a court of law. They have no business knowing about their developers internal affairs, imagine the conflicts of interest. This is a matter for an actual court of law, that can issue warrants and subpoenas, where perjury is a thing, where there is fair trail and where you can ask damage and the guilty party get charged for fraud. You obviously don't want to give these powers to a private company.
Apple engages in a lot of anti-competitive practices. I think in the case of App Store it's called captive supply, it is detrimental for both users and developers but good for Apple
There is a way for the platform to handle that scenario... Manual review. Apple chooses not to rely on manual review and we shouldn't discount this decision of theirs.
How would you be able to tell by manual review if a fake review from a SEO firm was paid for by that app's developer or by their competitor? There is no signal there. The ads are identical.
I'd say to "an acceptable level of moderation" - not perfect. But I agree with that statement if the company is itself profiting from the moderation. I think there's a separate example to be considered when the company is a "dumb host" - but as soon as the company starts promoting certain content with a complex algorithm (smarter than "most recent", "has most updoots", or even "has most updoots with a decay function") instead of just being a place people park their content then I think they adopt that responsibility. I feel quite similarly about things like Instagram and Facebook - I'd give a pass to Reddit because it basically does nothing outside of hosting discussions (similar to this platform).
But yea, if you're a business that makes money promoting other people's content then you're responsible for that content. Similarly, I'd argue that a skywriting company that writes libel in the sky should be held responsible as an accessory to the client if they were aware the statements were libelous.
pretty clever, it reminds me of the early days of the app store when apps would be taken down for copyright strikes but if you provided proof you'd be given "immunity" from further strikes taking down your app while Apple investigates
it became a strategy to copyright strike your own app, have proof ready so that no downtime was necessary, then you have the temporary immunity so that competitors couldn't submit a copyright strike, which costed them nothing to do and had no consequences if they were wrong about it
This is actually what I started thinking when I got to the end of the article. Maybe just immediate human snatch and grab cynicism.
That the author hired somebody to dump review, does something fishy with money like those above noted, and then sues for more money.
Levine over at Bloomberg had an interesting article where ransomware gangs are now filing SEC reports, as a way to pressure companies to pay, or minimize ROI.
It probably isn't now, but in the early days the iphone app store was a giant pinata full of money for anyone who wanted to knock up a flashlight app or whatever.
It's apparently common on Twitch for scammers to try and blackmail streamers by threatening to followbot them.
Not every streamer knows that they can forward such threats to Twitch's support staff, and if they don't, their stream is at risk from automated bot detection penalizing them.
A friend of mine upvoted all of my StackOverflow posts daily for a period of time until it got flagged and the points were removed. He did it again later, and it got flagged again with a warning. I had to ask him to stop upvoting all my posts, because it was indistinguishable from me giving myself points via a proxy account.
> I guess the App Store fraud prevention team hasn’t necessarily found a good solution yet.
The most essential device of the century is owned by two companies. The ability for them to completely control software and business activities on top of something that is almost as essential as public transportation is appalling.
The DOJ needs to remove the "app store" racket for essential computing devices. Software needs to be freely installable, sans vendor control, unfair competition, scare tactics, mandatory taxation, and adversarial ad placement by the cellphone duopoly.
Not only is cell phone compute freedom essential, but we desperately need more than just two vendors.
Android removed the big technical measures that gave Google's Play Store a competitive advantage over alternatives, in no small part because of EU pressure. And while the Play Store is by far the biggest player in town, Amazon's Appstore, Huawei's AppGallery and F-Droid are all notable alternatives.
Meanwhile on iOS the best we seem to get is the EU Digital Markets Act setting some rules for fairness on the big marketplaces.
Google pressures device OEMS into joining the OHA, after which they can't create AOSP devices. Allegedly, Amazon is giving up on Android for their own hardware.
> Allegedly, Amazon is giving up on Android for their own hardware.
Ah, that was news to me, so Amazon Vega is predicted to be some sort of immutable OS with web apps. It seems they are thinking of starting some Chrome OS resembling thing. iOS also intended to only have Web apps and look where we are now. I don't have high hopes for OS developed for Fire devices, it will be soaked in DRM and filled with ads.
They're really not notable alternatives. I love F-Droid but its selection is very limited. Good luck finding people who use Amazon Appstore, Huawei AppGallery or any of these other stores.
Let's imagine there's a company called Ticketmuster that had a monopoly on ticket sales. If they tolerate a shitty little kiosk selling a score of tickets a day, does this mean Ticketmuster does not have a monopoly share of the market?
One of the main draws of iOS is its resistance to malware, adware, and outright scam apps. Requiring third party app stores disproportionately harms those that purchased the device specifically for these purposes (such as people at higher risks of being targeted by nation state actors). And this isn’t something that can be addressed with a new uber-secure product just for these people, because the EU will deem it a gatekeeper if enough people buy it - so I guess you have to create a hard cutoff for how many can purchase the product ever, or means test “do you actually deserve security?”.
One of the main draws of iOS is its resistance to malware, adware, and outright scam apps.
Have we visited the same appstore? Just few days ago I tried to find a puzzle game for my kid and myself to play together. A whole bunch of them, from top results, resulted in games which had shady dark UI initial screens trying to get to $14.99 or similar monthly subscriptions. Eventually I caved in to arcade sub because I couldn't trust any of the results or find a normal paid one (once). Scammy at best.
There's practically endless proof and documentation for this.
The App Store is actually a honeypot for scammers. It's a single point of failure, because once you get past app review, which is easy, you're home free, and it's also relatively easy to manipulate App Store search, App Store ratings and reviews, and App Store Search Ads.
As a non-scam App Store developer, my biggest problem is discovery, i.e., getting my app in front of the eyeballs of potential customers. It's vastly easier to do that in the App Store than it is via so-called sideloading, especially if you have no ethics. (Unfortunately, I do have ethics, which significantly limits my options for discovery.)
Your logic states that because an app can occasionally slip through the review process, that we should remove -all- protections. That isn't better, that's worse.
A scam is also a relatively low bar to set for such drastic change, since scams also frequently occur over chat apps and the kinds of access that side-loading and 3rd party stores can avail opens the door to significantly more sophisticated malware. If you truly think the situation right now is bad, just wait until there are no protections for users.
You should also recognise that there is actual data for malware on these platforms. Every year Nokia drive home the same point for why Android has such an outsized share of malware: "...most smartphone malware is distributed as trojanized applications and since Android users can load application from just about anywhere, it’s much easier to trick them into installing applications that are infected with malware."
Since all experts point to the same sources of malware - perhaps that's not the change we should be legislating. How about we do something different.
I've been using an antimalware system which has been highly successful at blocking all sorts of malware. It's where I don't run invasive closed source programs on my computers and give them access to all my shit, and I don't just give my credentials and money to anyone that asks. In other words, basic computer practices from decades ago.
I know that this system may be unattainable for some, namely children, the elderly and the intellectually disabled. But maybe we shouldn't be designing general purpose computers around the lowest common denominators of society, for the same reason you wouldn't design a car for the legally blind or a book for the illiterate.
The nature of smartphones and the internet has some pretty large consequences for the economy, politics, war, and global surveilance. I understand that some people don't know how to manage their own computer, but if you really think everyone's computers should be controlled by dictators and buerocrats maybe you should just go live in a third world country instead.
If the concept here is choice, then why not force apple to clearly advertise that side loading and 3rd party apps stores are not available. The same way that Samsung and Huawei promote theirs?
Then the consumer can make that decision for themselves.
Your position here seems to be that consumers are too dumb to make that decision, but clever enough to fend off sophisticated malware attacks. You are even so gracious to note that perhaps this might be out of reach for ordinary users (well done you! you nearly got there)
If only there was a large and popular platform of devices with side-loading and 3rd party app stores available for us to already see the consequences of what this change does to malware rates.
Let's call this hypothetical platform "Android", and then a well respected security report, say by Nokia, could include statistics about this "Android" malware.
Well, you're in luck dear friend! Actual security experts state: "most smartphone malware is distributed as trojanized applications and since Android users can load application from just about anywhere, it’s much easier to trick them into installing applications that are infected with malware". (worth stating twice because I don't think it sunk in the first time.)
So real security experts are advising the opposite approach from you, funny that.
As for a 3rd world country, maybe you should run one since you have the ego of a dictator.
Don't bother, Apple fanboys are delusional. They would willingly slave themselves for the Apple religion. And they generally are extremely dishonest, which is why they want "protection". It easy to see wrong doing everywhere when yourself are operating in a bad way most of the time.
I think somehow Apple found a way to group both limited intellects and intellectually dishonest. This way the second group can pry on the first one and they seem very happy about that.
If you were to listen to them, every windows PC is infested with malware, yet even my grandma that is over 80 years old operates a windows PC without much trouble. She doesn't install nonsense and ask competent people about stuff. Which is exactly the kind of relation Apple wants to steal. So they can charge a lot of money for it, making people dependent so they are fragile. And when they have no other choice anymore, charge as much as you can. Classic sociopath behavior...
You are the one defending the indefensible behavior of a trillion-dollar corporation but I'm the fanatic.
I don't need to strawman; you are the one misrepresenting the malware situation in Android. You are also the one misrepresenting people requesting that a corporation let them do what they wish with a device they own. If anything, you are the strawman master.
On top of the strawman nonsense, you attack me as naive. You said the previous poster he had the ego of a dictator. If there is someone who needs to rely on something else than reasonable argument (personal attacks) that's clearly you.
It's rather funny because you illustrate exactly the point I alluded to before: intellectual dishonesty.
There's a difference between spyware and a library that sends the company usage details about how you use their app. Even apps with ads are only forbidden from using bespoke APIs (other than the built-in prompt "allow <x>" to track you across other apps and websites) to track users' activity and correlate it with other sessions.
Just don't use the third party app store if you're worried about scams. Requiring that apple permit 3rd party app stores does not force users to use said 3rd part stores.
This sounds like a fair point until remembering that things like Boss-ware exist.
An insurer/ health insurer, employer, government, etc will require it, and just like that the "just don't use them" crowd will hold up their hands and pretend that no one could have imagined this disaster.
If the problem is truly Apple exhibiting favouritism or limiting competition through their app approval process: then the EU should have just forced them to spin it out into an independent entity for the EU stores, or even take control of it themselves - but they didn't and 2024/25 is going to be a shitshow for it.
Legislating for side loading and multiple app stores is the least imaginative and most obviously flawed approach to the competition problem and the sole reason why Android's share of malware is staggering in comparison to iOS.
If you’re required to install software on your phone for work then your employer should be legally required to pay for your phone. And then if you want your own phone you pay for it yourself. And if your employers IT team lets corporate devices get malware that’s on them. This is a weird edge case to get hung up on.
You’re making a very simple issue way more complicated than it needs to be. Having Apple spin out EU specific new corporate entities with unclear relationships to its parent company sounds extremely complex.
Requiring Apple to allow people to install apps they want on their own device is pretty simple and should be a fundamental expectation of a free society.
If normal user wants the walled garden Apple experience, that’s fine. Make it unintuitive to install third party apps. Require checking a big red disclaimer that you might brick your phone. But just have some sort of path where if party A made an app and party B wants it on the device they paid a lot of money for, they can do that without some unqualified drone in Cupertino blocking it .
Countless examples of the App Store review being broken , and just on principle, Apple has what’s effectively a monopoly on mobile phones in that you can’t make a mobile app and ignore iPhone and for them to unilaterally decide all software that’s allowed is way too much power.
Somehow Microsoft went to the Supreme Court for putting IE on the desktop but Apple is off the hook for a complete lockdown. At least you could download Netscape on Windows 95! What Apple is doing is like if AOL and AOL keywords became the only entry point to the web. Then you go on Hacker News and people say that’s s good thing because AOL only allows quality websites and otherwise people make malware and scam websites. It doesn’t matter, it’s too much power for one company and mobile phones are more critical to society in 2023 than the web was in the 90s. Mobile phones are not appliances.
It’s still unfathomable to me this is even a conversation on this website. Apples complete lockdown of the most important computing devices is plainly bad for consumers and society.
I'm making a pretty valid point(note Android's outsized malware share) and we'll get to see it play out next year in the EU.
It's interesting to me that your core argument is about making a choice whether or not to embrace side-loading and 3rd party app stores. However aren't users making this choice when they buy the phone to begin with. Side loading and 3rd party app stores aren't a secret, many Android manufacturers use this as a selling point and include their own stores baked-in.
I'm somehow to believe that users are simultaneously clever and dumb - and I'm not buying it.
I like how you call users dumb for choosing Apple and clever for wanting to sideload.
Or how else do you claim there is two sides here?
Pretending that Apple is protecting consumers is silly, they have repeatedly said internally the lock is for revenue alone. No claim of security protection has lasted past "wouldn't sideloaded apps be sandboxed the same as App Store apps and thus have the same security overall"? (Apple failed to counter that point)
Poking fun at the bad phrase. There was no dumb in that choice.
The reality is the author dismissed Apple supporting side loading as fundamentally impossible in a thread talking about how Apple should offer more choices.
Calling users dumb for wanting side loading on Apple is ridiculous on its face. Users didn't choose Apple to side load they might have sacrificed side loading to get Apple but calling them dumb for making a choice is ridiculous.
Apple makes $86 billion from the App Store a year. That is a quarter of their revenue from iPhone sales. No shot a 25% increase in revenue with phenomenally higher margins isn't of extreme importance to Apple.
This guy is a dangerous zealot. He attacked your "reading comprehension" because he doesn't have any real argument that is not about protecting their trillion dollars master no matter what.
It's a bit unreal seeing people like him exist everywhere.
It sounds like the poster means that people who buy one or the other are choosing between either "(nearly) absolute" security or freedom in being able to install software without the manufacturer's consent.
Certainly but there is no dumb option it is a trade off.
They got in their head that users were stupid for choosing Apple when they wanted side loading but that isn't stupid in the context of "should Apple allow sideloading".
> If you’re required to install software on your phone for work then your employer should be legally required to pay for your phone. And then if you want your own phone you pay for it yourself. And if your employers IT team lets corporate devices get malware that’s on them. This is a weird edge case to get hung up on.
I'll support any sideloading regulation that includes all of these protections. As it stands this is only a law in some countries/regions and certainly not something everyone will be protected by if they happen to be outside of EU (and maybe US) jurisdiction.
If your company mandates installation of malware, then that's not something an app store can fix. If your company mandates the installation of malware and it's not available on the Apple AppStore, do you think they'd just say, "well okie dokie I guess the policy doesn't apply to you"? No, they'd require you carry a compliant device.
If my company is mandating the installation of software on my devices, I'll request a corporate device and assume the company has root access on said device.
I'm not sure how this is relevant to my point: "sorry your app isn't on the Apple app store" probably isn't enough to stop an oppressive employer from forcing employees to install spyware.
> An insurer/ health insurer, employer, government, etc will require it, and just like that the "just don't use them" crowd will hold up their hands and pretend that no one could have imagined this disaster.
On Android where alternate storefronts are a possibility, I have yet to be made aware of a single instance of this happening.
Not even Epic in their crusade against established mobile stores made its' own platform.
1. You're not looking very hard, surveillance ware exists for employment, examinations and so on. It's not available on iOS, but is available on Android via side loading. Both Facebook and Google used iOS certificates to side load tracking apps onto iOS for regular consumers. Even rental cars brands have utilised surveillance software to track speed and apply fines. The more you dig here the more you find: it's not some outlandish concept.
2. The inability to run such types of software on iOS prevents these approaches from moving forward across the industry. Much the same way that QR codes weren't widely utilised until both Android and iOS supported it.
> One of the main draws of iOS is its resistance to malware, adware, and outright scam apps.
Well no, the appstore is as full of scams, malware and adware as everywhere else.
They managed somehow to convince people it's a safe space though, not sure how but I consider it a bad thing since people are more likely to trust it blindly.
> such as people at higher risks of being targeted by nation state actors
> The Saudi Arabian app to track what your wife is doing is still on the appstore, no need for a thirdparty store.
While I usually don't like the saudi system but this app in particular is about making it easy to manage official government paperwork online [1]. This applies for all residents (citizens or not) and people really like it. So it is not an app to track females movements. While you can disagree or agree on the male approval requirements for a female to travel (I disagree) but it is not like it tracks movements using GPS or any invasive data. It just make it easier to manage the permits and all other interactions with the government without having to drive long distances and wait in lines.
Well as a complete outsider in another country who probably never went to Saudi Arabia like yourself, I would be more careful.
The app is doing both purpose since they follow their local laws, you can also read the wikipedia entry on the impact on women.
I'm open to some kind of argument like "apple has no choice in such dictatorship" but this argument is contradictory with the argument that its protecting from nation states.
And since we mentioned Saudi arabia, we can also mention China where icloud is dodgy, it's not a unique case. I'm sure they are others I don't know about.
Well, I was just responding to your particular claim that this app is tracking "what your wife is doing". But unless the wife is exclusively moving by airplanes (so that the app will notify male guardian she entered airport) that's is not tracking what wife is doing. It doesn't give information about activities or locations like saying many other apps.
This is one service among all other government interactions services that the app provide. If the app is not here. Women still need to get male guardian approval because this is local law. You can disagree on that matter (I am not defending or debating it).
I was just clarifying.
And yes, apple has to follow local laws. The app doesn't collect privacy invasive information used to track movements as your comment suggested. And it is not required to be on your phone.
That's doing a lot of work. There's "... to be usable" but also "... to be automatically and unfilterably merged".
They are very different situations. What specifically are you concerned about? I'd guess that latter but you seem to be defending the former as though it is the latter.
Apple doesn't want third-party stores because it would cut into their profits. That they were able to convince the public that it is about personal privacy is just great marketing on their part.
If you bought an iPhone because you wanted protection from the purported dangers of third-party apps, then ... just don't install any...?
Third party app stores don’t play into the legal liability of developing for iOS without a license. Chances are Apple still has every right to charge a percentage of revenue as the licensing fee for usage of iOS APIs.
Any regulation that requires allowing third-party stores, would be an anti-monopolistic move. So it would almost certainly include a requirement that those third-party stores be allowed to process payments themselves without paying royalties.
Copyright and patents aren't some kind of deep magic that binds the whole Earth. They're just laws. Legislators are free to change how those laws work...
Android allows third party app stores and it is not a significant cause of problems. I am sure there must be some bad app stores out there, but the well known ones like F-Droid are probably better curated than Google's own.
Linux has always allowed third party repositories. Again, rarely a source of problems - again, there must be some bad things out there but the percentage of users affected is tiny.
Exactly. Apple refuses to allow third party appstores like F-Droid because they know appstores like F-Droid would make Apple look bad and thus break the mental conditioning Apple has on their customers. Apple's appstores is filled with ripoffs and scams; F-Droid isn't.
Couldn't the app store support a singular store interface that draws from a singular default source and user added sources?
People could pay Apple to vette sources to indicate that software therein isn't malware even if it doesn't follow other Apple standards.
Anyone maximally concerned would just only use Apple sources. If Apple was less onerous about trying to get a cut most major software would be in the official store. Say a 5% cut.
Remember at one time the manufacturer trying to get a cut of the action on a device was rightfully absurd.
Your oven doesn't refuse to bake a pie unless Betty Crocker cut in GE nor did Magnavox require a cut from blockbuster.
Both could be implimented for your protection and both would have been protection rackets. Apple's arrangement is as well it's just that the mob actually oversees permits too and charges on the way in.
If you could trivially use only official apps and most apps would be available as such how would you be harmed?
If you want to resist malware, Just don't sideload apps and don't install apps from third party app stores.
Refusing other users the freedom to run the apps they want without Apple's permission just because you might get mildly inconvenienced by it seems very immoral to me.
No stores. Web install. Web first class. No "only Safari/webkit engine" limitation.
If Apple is so genius, they can solve malware with all of those engineering minds and dollars they have. They don't need to hind behind a store to do that. The tools and techniques are readily available and accessible for a company of their size and stature.
Permission layer, app runtime heuristics, and fingerprints are a start. They can do this. They just don't want to / have to, because they're currently Gods of the Phone Universe with unfettered and completely unfair control over "their domain".
No stores. Web install. Web first class... Permission layer, app runtime heuristics, and fingerprints are a start.
How does that work? If it's open web download and install with no notarization (because that's also gatekeeping) then we're back to the good ol' days of the 90's and early 00's. In other words, anything goes and it's up to the user to keep themselves secure, which in practice means rampant security failures and users getting scammed and hit with ransomware at every turn.
I don't like Apple having so much control over everything. I really preferred the old days of the web and the anything goes, full control over my computers I had back then. But the web is absolutely way nastier today. It's jam packed with scammers and ransomware gangs and botnets. It's really quite sad and frustrating for anyone who grew up with the full potential of computing.
I still use MacOS and Linux, which is still the "old days" and its been 20+ years since the last time I had issues with getting hacked.
A lot of the solution is just not to install random shit out of app stores, and to install software that has a good reputation (and use adblockers on search engines like google so you don't click on trojan ads).
If you scroll down to the 10th page of the listings for 2048-clone games and install something at random you're probably going to get hacked.
I had a friend that just got pretty severely pwned on his Mac.
They installed some kind of DNS redirector, so, when he thought he was contacting Apple, he was actually talking to a scammer.
Their customer service was great, which I told him, should have been a red flag.
In any case, he was able to extricate himself from the scammers, but not before they had grabbed a bunch of PiD, so he’s still dealing with the whole identity theft issue.
Not sure how he got owned. Likely, some drive-by malware on a Web site. He basically uses Safari as his operating system.
Stores is synonymous with side loading. Pedantically your website could be considered a “store” for the single app you distribute for it.
And the threat surface of the iOS sandbox is so large that it’s impossible to secure everything everywhere the first time. Every iOS jailbreak since at least iOS 10 starts with a sandbox escape exploit and executed via a sideloaded app (besides the single hardware exploit found in recent years, checkm8)
Apple has in fact already solved these problems satisfactorily, on a platform called macOS. That’s what a smart company does when it knows it can’t put the third-party apps back in the box, and still feels motivated to uphold its reputation for security. iOS is the aberration.
> If Apple is so genius, they can solve malware with all of those engineering minds and dollars they have. They don't need to hind behind a store to do that. The tools and techniques are readily available and accessible for a company of their size and stature.
An App Store with a human review process is one tool in the toolbox.
> Permission layer, app runtime heuristics, and fingerprints are a start. They can do this.
I think this is Google’s approach. How’s that been going?
The EU requires reviews from real customers and you have to describe how you are accomplishing this.
These alternative app stores will be infinitely more trust worthy than apple, amazon, google etc
If there is no payment or the trial is canceled one could use the digital id.
Apple could even gather some simple statistics. Opening the app and using it for 1 minute would be a special kind of review. You wouldn't count 1 star reviews like that until manual review-review confirms the app is really that bad.
As you mention two companies I can only assume the other is Google and android. Which I find odd as I have multiple other appstores and repositories on my phone and every other android device I have owned. My phones and tablets usually come with not just the Google Play Store, but also the manufacturers app store, and I install fdroid on all my android devices, and have in the past installed the Amazon app store on my phones back when Amazon and Google were having a spat over audible book sales and you breifly couldn't buy books on the Google hosted version of audible. So I don't see the problem. There are many third party app stores on the android half of the marker if you as a developer dont like the terms for using Google Play, then list you app on another storefront with more agreeable terms or your own webpage.
It would be more competitive if it worked like software sources under Linux whereby you can use a singular interface to manage software from different sources.
It's not in the interest of the DOJ to do so - 95% of people are technologically completely inept and it would expose them to fraud, malware and such at unprecedented scale
Technically illiterate people don't use open OS's so there's no reason for attackers to target those platforms. Also, the number of users is so small that it's not worth an attacker's time.
> The most essential device of the century is owned by two companies.
As long as people play along, yes it is indeed.
If more people were installing a free mobile OS, and thus take back ownership of their hardware and digital lives, the story would be much different.
It's the same story with PCs. If you actually want to control the hardware you own, install Linux. It's not as if the alternatives to corporate control didn't exist.
As someone who’s wanted to run their own mobile OS, I can tell you that doing so it a hell of a lot more challenging than installing Linux in a laptop.
The fact is most of the stuff that makes phones what they are, is hidden behind closed hardware and firmware. Even Android, which as you know is Linux, has closed binary blobs in its kernel tree.
You can get away with that somewhat for devices like the SoC on the Raspberry Pi. But things get a lot more complex when half the stuff that makes your phone usable is closed hardware and firmware blobs. What you ultimately end up with is still a device you don’t fully control but with the added inconvenience of a less mature software ecosystem too.
I don’t see this problem being solved any time soon. In fact quite the opposite, I think it’s getting increasingly difficult with each passing year.
The regulatory requirements around communications equipment (especially cellular modems) pretty much requires closed binary blobs. Eventually folks are able to reverse it, but not in a timely fashion.
I don’t think regulation is the problem (though I wouldn’t be at all surprised if some many used that as an excuse). For example the EU makes it mandatory that patents on standards are licensable to other parties. Granted that’s not exactly the same thing but it does illustrate how governments want competition. Or at least in the EU they do.
The problem with binary blobs is entirely a corporate one. And frankly I don’t blame them for wanting to keep their products closed. I makes complete sense for them to do so. Really this is no different to nvidia keeping their GPU drivers closed. Except you can still have a functional laptop without Cuda, whereas you cannot have a functional phone without the ability to connect to cell networks and make phone calls.
I don't think it's a fair comparison because in the PC market the bootloaders are (usually) unlocked and the firmware (usually) operates via an open standard like UEFI or BIOS... whereas in the smartphone market open bootloaders and firmware are the exception.
I think people would if there were a viable free option.
Also it isn't easy to find good mid-range hardware. I bought HMD(Nokia) for years but then I spent 250 on one of their new models and the phone was absolutely unusable (laggy UI).
Having to research models and software versions of CyanogenMod every few years just wastes my time. And then run into issues.
Plus security matters to me.
Microsoft failed to enter the market with billions spent - it isn't an easy problem.
But there are two, which is very different from one.
I'm not sure that adding more would make all that much difference. One player would have absolute pricing power. Two keep one another at least a little in check.
That assumes no collusion, and that's not entirely true, by not completely false either. Many cases of similar behavior are just them responding to the same market in similar ways.
I think that completely free and open player you want isn't going to be much of a competitive advantage. It has a small niche but not enough to break into the insane levels of overhead in creating a complete ecosystem. Especially since most users just want the device to work with a minimum of grief. And especially since the use of public airwaves means a ton of regulation.
I don't disagree with the problem and lack of options. But forcing a company to add features feels like overstepping. I'm not sure how that can be legal or even be with the spirit of the law.
Is it even fair to call it “doing business with a company” when you’re basically just probing an opaque automated system? Sure, if you’re a supplier or say large advertiser, perhaps you are “doing business” but this sounds more like fighting for scraps together with a mix of honest and dishonest players hoping that the anti-fraud gods show you mercy and bless you with rev-share.
All these stores are basically little monopolies with zero incentive to not suck. They also suck from a user point of view. Search is terrible, they’re full of shovelware, etc.
Steam has been, and for now continues to be, much better.
IMO this is directly due to Gabe Newell's leadership. Taking an attitude of "piracy is a service problem", and proceeding to offer such a good service that it's preferable to pirating, results in a great service for everyone involved.
Whether this will outlast GabeN's tenure as CEO remains to be seen, but for now my understanding is that both users and developers are overwhelmingly happy with Steam.
> Taking an attitude of "piracy is a service problem", and proceeding to offer such a good service that it's preferable to pirating
My favourite way to phrase this is that "steam is the most anti-piracy store available. With piracy, you play games you didn't buy. On steam, you buy games you never play."
Steam will moderate or at least put a notice when a game is being review bombed for things unrelated to the game itself, such as a controversy with the developer.
Sometimes the reviews are about the game, but they're being left because that's the thing to do according to the internet that day. So a legitimate grievance but blown of proportion due to factors outside the game.
Steam isn't a monopoly, it provides ease of catalog and access. smaller companies can still sell on their own website or any other number of storefronts. The gatekeeper here now is generating MS signed apps.
That's not how money or business works. Opportunity costs means that many "amounts of money" can be meaningless to the business depending on the activity to get to them, the negatives (from processing hasles like lawsuits to PR and brand image), their overall strategy and focus, and other such concerns.
A company at Apple's level absolutely doesn't see "frozing $100K" from random devs (or the amount that would result in aggregate from all those freezings) as a profit center.
The irrationality is the problem. $100k is nothing. The loss of developer good will is worth far more than that.
But Apple doesn't care, because it relies on shady apps for a significant part of App Store income.
So the decision is "Do we make significant money from addictive games and scams and tolerate the occasional false positive that nukes a legitimate developer? Or do we spend significant resources curating an App Store full of quality apps and no noise, with high quality support for devs with problems?"
Guess which one of those is going to bring in significantly more money.
From the large corps I've worked with - those that made $B in revenue - they do everything to reach rev goals they told investors they would reach, every $100k counts. If you think a large corp is throwing away money, think twice.
In the time it took you to compose this reply, Apple made more money (in profit, not revenue) than the amount in TFA. Your cynicism borders on conspiracy theory!
They have cryptographic proof of what types of devices you’re on. There’s a lot of metadata that they have access to because of their closed ecosystem.
That sounds like the modus operandi of so many companies.
Google can’t figure out how to make money without ads, so they punish people (blocking ad blockers on chrome and not allowing access to YouTube if using an ad blocker) because of their own failure.
> Google can’t figure out how to make money without ads
They can and they have. YouTube Premium exists! You can pay for it!
The two business models that are feasible for YouTube are (1) free and you have to see ads and (2) paid and you don’t have to see ads. They offer both. I don’t think it’s reasonable to expect to be allowed to pick (1) but opt out of the ad side of the bargain. Their ad-blocking shenanigans are obnoxious, but it’s disingenuous to claim that they “can’t figure out” how to monetize YouTube without ads when they actually do provide that option.
I subscribe to YouTube premium because I think it's worth it.
Lots of people have called me a "sucker" or worse, a Google shill, for paying money for a "free service." These same people then turned around and threw a temper tantrum when YouTube started detecting and punishing ad blockers.
I think after years of enjoying a free service people have become extremely entitled about it.
Some content on YouTube is worth it but I would say most of it actually isn't. The rules have been gamified for max monetization. So now something that shouldn't take 10 min to say is full of fillers and bullshit.
Most "pro" content creators are also double-dipping with sponsors ads inside the video. I think it's disrespectful and it should be an either/or situation.
If YouTube displays ads, then they have to be reasonable and the videos themselves shouldn't have any ads. If creators want to display ads, then they should pay YouTube for the video hosting and bandwidth.
YouTube created this mess. Under the disguise of "free money" they attracted all kind of creators/organisation lured into a video hosting platform (something that is expensive to do at scale) under the unsustainable promise of "we host your stuff for free and you can even make money out of it". This removed most of the risk for launching video production activity but also killed diversity of potential business models and alternative sources/technical solutions.
Now both parties are extremely greedy and want even more money because somehow, they think they have a captive audience. YouTube shove more ads and creators shove more sponsor bullshit. They are the ones full of shit, it's not the people requesting a fairer deal that are entitled, you have it backward.
I used to watch YouTube completely with ads up until 1-2 years ago; it just became unwatchable and pretty much every "creator" has some sort of ad in the video anyway.
It's particularly disgusting because in general those are people already making 3-4 times median/average wage with complete freedom and what would be considered low output in a traditional job paying way less. Like most tech companies, YouTube enforced winner take all feudalism and single source for maximum control on the market.
If those creators had started their own website with their own hosting and figured out a way to monetize this (subscriptions, their own ads with sponsors, products, etc) and actually taken any risk to start (like pretty much every single business has to) we would not be here.
It's a situation entirely created by dishonest representation of reality and then trying to impose rules by force to extract even more money. If YouTube needs more money to run, they better ask the creators placing ads all over their content to pay for the bandwidth/views.
It's completely wrong to blame AdBlock users, they alone created wrong incentives and they alone are the one responsible for all the monetization shenanigans/cheating going on...
As far as I'm concerned, I'm pretty happy they are going at war with AdBlock, because we will see what's what. It may open up opportunities somewhere else, because I don't see people paying for Premium and I don't see people sticking around with so many ads. People's attention is going to be redirected somewhere else (free or cheaper content exists, starting with the public library or TV) and we may get something better out of that.
I pay for pemium and youtube still sucks. I still see ads in the form of embedded and in the form of other shit on the page, and now my home screen is blank, and I only get to use my account about 1/2 the time anyway because in the real world I'm often watching on someone else's device, and I have no option to disable shorts, and I'm subject to their capricious copyright and censoring bs which both directly removes content and indirectly cows all the creators into self censoring.
The problems with youtube are not the victims fault. It's fucking garbage.
Your experience is very different from mine! I pay for YT, and I really love it. So does my family. The sponsored messages are annoying... but the creators choose that. The good news is that I can fast forward? I'm free to unsubscribe from creators where annoying > value.
Honestly, Youtube is probably the service I'm most happy to pay for. Could it be run better? Probably! But it's still great.
> They can and they have. YouTube Premium exists! You can pay for it!
No they haven't. YT Premium price goes up by a significant amount each year, without a corresponding increase in value. That's not a business model, it's an experiment to see what the profitability price point is.
If they knew what it was, they could go Netflix and make it paid-only. But then they'd lose out on all the sweet sweet ad revenue which apparently still doesn't cover the bills.
Since they haven't reached it, and since 95% of their audience still accesses it with ads,
You can consider, virtually, all reviews fake in any mobile store.
Sometimes I read the reviews and wonder: Who on earth wrote this?
Honestly, it's up to Apple to moderate the reviews and detect review farms.
If posting fake reviews is all it takes to take down my competitors out of the store, it's game on.
I believe you need to own the app to review it, so there is a cost to consider. Maybe it’s freemium or just a dollar but regardless you need to create an account, buy it, review it,…
Barely any apps get you to pay upfront any more, in my experience most are free to download and it's either a trial, or so ad-ridden that it's unusable without an in-app purchase. Either way, any account could leave a review without paying.
As someone with a long time in fintech, if your account is closed without explanation and nobody will talk to you, this is with almost 100% certainty the answer.
It sucks because people who have been clearly committing fraud then plaster you with negative reviews and sob stories but casually fail to mention it was their own egregiously fraudulent activity that caused their account to be shut down.
And it also sucks because people who may not have actually done anything wrong get caught up by these controls sometimes and have effectively zero recourse.
This is garbage. Imagine if other law worked this way. "We're going to arrest you and put you in jail, but we won't tell you what you're accused of, nor give you a proper appeal." During an investigation, I get it. After charges have been leveled? Most certainly not.
Charges haven't been leveled yet. In theory, if Apple suspects money laundering they should both freeze the account and tell the authorities. The authorities want time to piece together their case before the money launderers disappear, so they ask for Apple to keep quiet until they have a chance to review everything.
In addition to what the sibling comment said, the developer does in fact have a recourse to the legal system, which they wrote that they are preparing to make use of. Attempts to analogize the TOS dispute mechanisms of companies to the legal system frequently fail to note that, at least where money is involved, they exist within the legal system, not in a bubble.
Then just let the account run? Anyone actually using their account for criminal purposes is not going to be surprised their account is blocked, and will have a very good idea of why it happened.
If you suspect criminal operation you have to shut it down. What you tell the customer is up to you, but if you're right and you tipped them off then you could get prosecuted as well.
> That smells more like money laundering or fraud.
Does Apple get to decide this, and just keep the money, without involving any court of law? Someone mentioned anti-money laundering laws and secrecy, but can that manifest as losing your money, without trial or even being informed that you're accused of anything? That would seem to violate a few constitutional rights.
I've been told this is OK because there is plenty of real competition in this space so developers can vote with their feet and develop on other platforms.
Most likely it is the reason. There were cases of accounts shutdown due to the developers writing reviews from other accounts for their apps on App Store.
I'm not GP, but your condescending attitude is not only rude but wrong.
Money laundering through things like app sales is a classic technique. It's the modern version of buying "art" that isn't valuable at insane prices. Laundering through an app store incurs a 30% haircut, but the funds are very clean afterward and every money laundering technique is going to cost that much or more. It is not unusual for the laundered funds to be 40% of what they started with.
Pointing out that money laundering is a possibility is fair. I very much dislike Apple, but if it is a potential money laundering situation then their hands have been tied by the US government.
>It's the modern version of buying "art" that isn't valuable at insane prices.
That was possible because the art world (at some point in time) enabled this. Apple and its App Store actively prevent this from happening, it's the complete opposite.
If you keep this up, we're going to have to ban you. We've already had to warn you about this more than once in the past.
If you'd please review https://news.ycombinator.com/newsguidelines.html and stick to the rules when posting here, we'd appreciate it. That means no more swipes or name-calling, and definitely no more personal attacks.
In the art world there is (or at least, was) some level of secrecy in the transactions and parties involved.
Apple would give up all information it has about you to law enforcement at the slightest suspicion of some shenanigans happening. They also comply with all KYC requirements from the law. That's how (among other things) they "actively prevent" people using their platform for criminal activities. Heck, at their scale, they must have an entire team devoted to doing just that.
> Could you enlighten us? How does one launder money through some iOS apps?
You use stolen credit cards to purchase the app. It's a very common method of fraud and does not require a criminal mastermind or a group of people to perform.
I have no opinion on what happened in this particular case, but it's crazy to imply that nobody is doing this stuff.
How would you get the money you possess and want to launder on the stolen credit card? That more sounds like a method to extract money from stolen credit cards, but not a valid way to launder money.
It sounds like you have no idea what money laundering actually is, to be honest. Money laundering is concealing the source of illegally obtained money.
You use stolen credit cards to buy gift cards (or just defraud people to obtain gift cards). This is dirty money.
You pay it to yourself on the App Store by getting an app listed and buying it. Apple then deposits money (minus their 30% cut) in your bank account, which is clean money.
The stolen CCs are not part of the laundering (that's just fraud/theft). I think it's easier to talk about laundering cash from drug sales. You buy an Apple Gift card with the cash. Use the gift card to buy jewels in an app you control, and now you have cleaned your drug money.
The challenge with doing this at scale on the App Store is the account requirement. Apple also likely has controls on how many gift cards you can redeem over a period of time. You also need an app that looks plausibly functional. The amount of money people supposedly spend on gems or whatever will help though.
"this suspension by Apple couldn't be due to Apple catching them laundering money"
because
"this isn't money laundering"
because
"if someone laundered money this way, they would get caught"?
Do you not understand that you just destroyed your own argument?
And I have inside knowledge that you're wrong at least much of the time. This particular case, I have no idea, but extremely competent teams inside FAANG believe that there are many billions of dollars of attempted money laundering of this form, that they catch and stop.
Money laundering is not "making money through illicit means" as many people confuse it with. Money laundering is the act of concealing that money, so that it becomes clean money in the face of any curious observer. They often go hand in hand but they are different things.
An example, you have 1M cash but you need it in your bank account, because you want to buy a house or a car or groceries. If you just go to your bank with 1M in a briefcase a lot of people are going to ask you "where did that money came from?". But if you do ???? and you have a legit (or legit enough) excuse for that, you may get away with it and now you can use your money and people think you're a mastermind entrepreneur or something.
There's a reason why the first money launderers were laundromats and similar businesses, anything with plausible cash flow, because then you can go to the bank and tell them "I just run a very successful laundry business, and that's why I have a big bunch of $10 and $20 bills, some of them may have a bit of blood in them, though". Much more complex ways exist but the gist of it is this.
If you take legit money from someone's bank account, move it through Apple, then send it to Chile(?), then take it out(?) that's literally the opposite of what you'd like to achieve, hence why this argument is so absurd.
> Money laundering is not "making money through illicit means"
This is correct.
> Money laundering is the act of concealing that money, so that it becomes clean money in the face of any curious observer
This is the middle step, layering. Before that is placement, introducing the funds into the financial system; after, integration, withdrawing clean money.
Here, stealing the credit cards is the original crime. That per se is not money laundering. Running them is analogous to placement. Mixing those stolen numbers with people who legitimately forgot to cancel their subscriptions is layering. Getting a bank deposit from Apple: integration. (Banks won't question deposits from Apple.) That process, altogether, is absolutely money laundering.
The stolen credit cards are actually irrelevant. If the developer's dirty sources need to layer their funds, they can subscribe to the app and have it laundered for a meagre 30% haircut. Do that across a number of assumed identities and it's a decent cottage money-laundering operation.
> it almost always involves putting cash into a bank account
It very rarely does anymore. Certainly not at scale.
>it almost always involves putting cash into a bank account
Yeah, I edited my comment shortly after but you were already writing this probably.
Only an observation, it almost always starts as money flowing into a bank account, though.
>If the developer's dirty sources need to layer their funds, they can subscribe to the app and have it laundered for a meagre 30% haircut.
No, because you cannot pay for apps with cash. If you already have cash into a bank account somewhere in the world then ... you most likely don't have the need to conceal it anymore. Buy shitcoin, send it to a tax haven, whatever, why would you make it dirty again by sending it to (of all damn options) Apple. Lol.
> If you already have cash into a bank account somewhere in the world then ... you most likely don't have the need to conceal it anymore
This is where you’re going repeatedly wrong. Most money laundering doesn’t involve cash.
If you embezzle funds, or defraud an investor, you wind up with dirty money in a bank account. While it’s there, it’s hot. You could do the crypto trade, but you’d still be in a position of holding cash (even in a tax haven, depositing loads of cash is expensive) and/or having a tainted account.
Running it through Apple yields a bank account tied to a developer entity that receives deposits from Apple. You can leave your money in that account without too many worries for extended periods of time, and produce KYC receipts to wary counterparties when asked to. That’s valuable.
A (stolen) credit card isn't cash. The whole operation here is to turn someone else's credit line into usable funds.
But also, why would sending funds to Apple make them dirty? That doesn't make sense—as GP pointed out, sending funds to Apple so that Apple sends those funds back to you is what makes the money clean. It's the difference between depositing $50k in your bank account from a drug deal and getting a $50k direct deposit from Apple's developer program. The latter won't raise a single eyebrow.
>sending funds to Apple so that Apple sends those funds back to you is what makes the money clean
No, because it is extremely easy for anyone to see that these funds came from an illegal activity, Apple would just say "these were stolen credit cards" within hours of it happening. That's the literal opposite of concealing the origin of money.
There are "companies" in developing countries that you can send money to who, if you send a large enough amount, will create and publish an app on the app store in your name and use a portion of the funds you give them to purchase stolen credit cards and/or apple store gift cards (usually obtained by some form of credit card fraud), and make purchases of that app, thus washing your original dirty funds.
This is money laundering.
You can also just buy mass amounts of stolen credit cards that have some moderate odds of successfully accepting some number of small ~$100 charges, so you can just do all this yourself. And folks do.
If you obtain funds illicitly and transmit them round-trip through a 3rd party, lossily, such that the 3rd party and any outside observer such as the government are unaware that you are both sides, you are laundering money.
But please tell me what money laundering is and is not. It's not like I have a close to a decade of real world experience in an industry whose primary goals include combating it and working with relevant authorities.
That said, other commenters are pointing out a very large revenue figure relative to the popularity of these apps. That smells more like money laundering or fraud. In that scenario, Apple should have been more specific in their communications.