(no title)
r_singh | 3 months ago
As a user I like Apple’s App Store for security personally, but I wonder how multiple app stores turn out in other regions. I see the EU already allows alternative app marketplaces — has anyone used one and can share their experience?
isodev|3 months ago
> Apple’s App Store for security
The App Store doesn’t do anything to protect you in that sense. It’s easy to circumvent and these days it’s cheaper to just buy an iOS exploit than go through the trouble of making a shady app.
fundatus|3 months ago
Even for web distribution in the EU (which they allowed some time ago) they require you to have had an Apple Developer account for at least 2 years and at least one App with more than 1m annunal downloads in the App Store.
So they're forcing you to have a very successful app in their own store before you can distribute yourself, basically making this impossible to actually use. It's such a blatant case of malicious compliance, it's insane.
r_singh|3 months ago
Interesting, their marketing has customers believe otherwise, so I wouldn't have thought that as a noob in cybersecurity.
I've submitted an app to the iOS App Store in the past, and the process is tedious and doesn't seem superficial (unlike the Play Store process, which was completely autonomous at the time), so that's another reason why I wouldn't have thought it.
alpinisme|3 months ago
But why is that easier? And is it inevitably so or a result of the fact that the boundaries of the one place to install apps from is aggressively policed?
gruez|3 months ago
Different threat models. If you're the mossad and want to go after someone in particular, yes the exploit is the way to go, but if you're running some run of the mill scam, you're certainly not going to spend 6+ figures on a ios 0day that'll get patched within days.
warkdarrior|3 months ago
"Look, you do not need a front door, and definitely not one with a lock on it. After all anybody could machine-gun you down through your windows."
spike021|3 months ago
is this any different from Macs also prompting the user when a downloaded binary is suspicious/not signed properly? or windows when installing it'd flash a screen about trusting what you're installing?
port11|3 months ago
Basically the market is still in an alpha stage. My next app will be on Alt just because I want to support the idea. Hopefully more apps gets on these stores, for now it's mostly nice to have for games, emulators, and some dev tools.
Apple didn't make it friction-free either, but it seems the issue is lack of user demand and/or lack of supply.
skinnymuch|3 months ago
I should try Alt out again with you reminding me.
extraduder_ire|3 months ago
Requires an EU apple account, a faraday bag, two esp32 boards (or other way to spoof hotspots), a VPN with an endpoint in the EU, and an iOS device with a supported OS version.
warkdarrior|3 months ago
pprg1996|3 months ago
dgjhu669|3 months ago
andoando|3 months ago
owisd|3 months ago