This kind of thing reminds me of why I've always felt there shouldn't be a gatekeeper. Add your repos, install your apps. Folks should be allowed to have more than one repo to install apps from.
But if you allow users to have freedom, grandma will get hacked! We should all be told what to do and where to go and rely on gatekeepers for permission, for safety. (And no, of course there’s not any solution that would allow competent individuals to go outside the safe zone.)
There is an easy solution to this: Allow the user to decide whether they want to allow for apps from outside a particular ecosystem. Then Johnny can set up Grandma's phone and (in a deep byzantine menu where she will never accidentally stumble on it, maybe locked behind a pin), Johnny can set it so that Granny's phone can only install software from "Super premium, high class, curated, guaranteed not to hack your phone" walled garden app store. And Johnny, on his own phone, can choose what to download himself, including from the "Buyer Beware, half our shit is malware" dark web app store.
In my opinion, the Apple app store should actually be FAR more curated than it is, and far less curated options should be equally available. The Apple App store (and the Google app store for that matter), should be a relatively small list of apps that have extremely high standards and guarantees. It should essentially be impossible for spammy bullshit to get into these places. User-controlled, parental control like options should determine whether or not other app sources can be installed from (including allowing for specific other sources, so that app source control can be granular and detailed. I should be allowed to add FDroid but nothing else for example).
Done. Problem solved. Everyone is happy. Grandma is safe and Johnny has control over his phone.
But of course, that assumes that keeping Granny safe is actually the reason. Facially obviously, it is not, and is in fact entirely pretextual.
There are two big problems with this (not that Apple’s caprice is the only alternative):
1. The vast majority of people are Grandma, and they do not have a Johnny available to administer their tech. Most people are not technical.
2. The vast majority of Grandmas will follow instructions on a “how do I share cute photo” website even when that website directs them to dig deep into configuration settings and ignore six “are you sure you want to allow this app to fully remotely control your device?” warnings. Even if Grandma has a healthy suspicion of scams, when she is instead trying to accomplish a goal she will suddenly prove quite adept at giving software with questionable provenance root access to her life.
And what if my grandma is Admiral Hopper. I wonder if there's a way to argue for or against paternalistic corporate gatekeepers without invoking sexism, ageism, or both?
I think the bigger question is whether this is even worth solving. If people really want to give someone root access and do it willingly, maybe we just say this is out of our purview and allow it. And then, slowly, people will learn. They will be hard lessons but evidently baby proofing the entire world is not really working, so we might just abandon ship on that idea.
I'm not going to argue we should close all banks or whatever ridiculous argument people come up with just because someone lost money.
The only way to 100% prevent scams is to remove the potential entirely. There are scams, infinite actually, right now, on iPhones. Do you support that? Surely not, so we should lock iPhones down more no? Ideally, we ban smartphones altogether, to prevent scams. Oh you don't support that? Well come back when one of your relatives loses 1 million dollars.
Look, we can take steps to prevent scams, and we do. What we should NOT do is go so extreme that people cannot even use their devices the way they want that they paid for. This is anti-consumer. If I want to install some software, I should be able to. It is not Apple's responsibility to baby me, baby you, and baby the entire world and say "no no you can only use our approved software!"
Especially when some of that approved software is... wait for it... malware! Yes, there is quite a lot of malware on the Apple App Store and the Play Store. But I can't install open-source software I've audited myself on my iPhone? How strange.
It appears to me this has nothing to do with scams, and everything to do with control, censorship, and profiteering.
The comparison to banks is actually pretty interesting.
Unlike app developers, banks are by default directly liable for fraud that happens on their system. In many cases, even when someone gets their bank to send money to a scammer, they can still get that money back. Since the bank doesn't want to risk regulatory reprisal, they have a lower threshold for spending money to make customers whole. Exceptions and subtleties abound here, but the underlying incentive structure is very different: the broker of the sensitive resource (money, for banks) is often held responsible for mis-use of that resource. How would we do that for e.g. apps that store your password in plaintext and then get hacked?
Relatedly, banks have thus started adopting the practice of blocking and calling/talking to customers about suspicious transactions. You can still authorize it if you really push, but you have to talk to someone with expertise about fraud risk, and have to spend some time doing it (which helps a lot with the "urgency" dimension of scams). Most permission approval prompts on phones/computers have no such human intervention or time-delay option, even if you might want them to.
> The only way to 100% prevent scams is to remove the potential entirely. There are scams, infinite actually, right now, on iPhones. Do you support that? Surely not, so we should lock iPhones down more no?
Nobody here has the goal of preventing 100% of scams. The ideal amount of fraud on these platforms is not zero (https://www.bitsaboutmoney.com/archive/optimal-amount-of-fra...). Rather, fraud is still extremely common and difficult to disincentivize. We want to reduce that as much as possible while not imposing overly-onerous restrictions. The discussion is about what counts as "as much as possible" or "overly-onerous", not whether we should ban phones or banks.
> I can't install open-source software I've audited myself on my iPhone
I hope you understand you're in a very tiny minority of people who can do that, using a device designed for people who cannot do that, and whose behavior if permitted to do what you're after has a proven history of causing significant damage to individuals (who lose their savings) and shared resources (sites DDoSed by end-user-device malware, hospitals that can't provide care because someone let ransomware onto a computer, and so on).
I'm not arguing we should open iPhones 100%. But the fact that ONLY apple approved software can be run is unacceptable. Alternative app stores, which Apple can approve, should exist.
We have highly secure repos on other platforms. I would argue the Debian repos are much, much more secure than the App Store. The safety and security argument against it is, simply put, wrong. It is incorrect, it should not be humored. The fact people genuinely believe only Apple can securely audit software is ridiculous, poorly thought out, and obvious corporate propaganda.
If we want iPhones to be more secure, we need to take a closer look at the permission system. What we don't need to do is let Apple continue their profiteering. And make no mistake, the singular goal of the App Store is profiteering. Security is not a goal, otherwise they would only allow open source apps that they audit. But no, they allow closed source apps which use private APIs and they do not give a fuck. And that's why there's quite a lot of malware on the App Store, and much less in the Debian repos. Despite one being run by a multi-trillion dollar corporation, and the other being run by volunteers. It's time to call spades, spades.
I hope you're right, but I'm not sure they will. The less locked-down WinXP and early Android era was ... really really bad in terms of nontechnical people getting hacked/scammed. And bad actors are also innovating, so the target of what people have to learn is moving: now we have synthetic AI voice scams, easy-to-create full clones of popular websites that harvest credentials, an explosion of 0days that let people run RATs that hassle elders for their MFA codes, and so on.
Like, I'm 100% with you that baby-proofing the world is an unattainable, patronizing, and negative-externality-laden goal. We shouldn't do that. But we shouldn't go full libertarian "you're on your own; toughen up" either; I think we have a lot of data that indicates that the harms of that approach are both high-magnitude and high-volume.
On the sliding scale here where the left is "full anarchy" and the right is "goo goo ga ga baby proof the world", Apple is about 95% to the left. Here's how that looks:
Anarchy |--------O-| Goo Goo Ga Ga
And people are arguing we should be moving further right. It's ridiculous, we all need to be candid and recognize this will not work
Fortunately, it's not a linear scale. All sorts of technical and political options exist which don't fall cleanly into the anarchy or baby-proofing spectrum. Random incomplete examples, in no particular order and off the top of my head:
GGP's idea of making it more commonplace to have a "Johnny" helping people with their tech needs to prevent accidents could work socially, if there are ways for communities to create more people willing to do that.
Worldwide legal penalties for spamming/scamming could grow more teeth, increasing the likelihood of bad outcomes for people that make malware or questionable apps.
Software distribution systems could standardize on better systems of provenance and ownership handoff to further technically harden against "good extension sold out to an evil maintainer" or "github credential leak let a bad guy publish an artifact"-type attacks.
Cooldown periods for users trying to grant questionable access patterns could be imposed, though that might feel too baby-proof for some.
On-device permission boundaries could be modeled in an "XOR" way: apps distributed from Apple's walled garden could be disallowed from approving data sharing with apps users install from other repositories. That's Apple's prerogative (they own the distribution and vouch for at least some of the quality of the app store apps), but doesn't prevent users from installing parallel ecosystems if they want.
Something that's very paternalistic, but doesn't involve baby-proofing what's possible, is the idea of credentialing users. You need a driver's license to operate a car. In the US, you need a (much easier to get) food handling license to commercially process food. The latter's a short briefing and test of comparable effort to those mandatory corporate anti-phishing trainings that already-technical people hate. Perhaps some users could benefit from that as a prerequisite to installing non-trusted software.
For vetted walled gardens like the App Store, further improving the granularity of and required justifications for permission requests as providers have been doing might help. "This poker app wants to access all of your saved contacts and photos" becomes "this poker app wants you to select a single profile photo and up to 5 contacts a day to add as opponents, after which access is revoked" or whatnot. This only works if App Store reviewers get serious about rejecting apps for overbroad permissions requests and explain their rationale to app developers, which would require Apple and friends to spend a lot of money to enable. Fortunately, they have insane margins. Less fortunately, their shareholders wouldn't go for this unless forced by regulation or similar.
Anything that helps with threat attribution. If Grandma can install an app from a random URL, and then gets hacked 6 months later, it'd be great if something got in her face that loudly indicated that the decision to install the untrusted app was the root cause of her compromise and some "do you want to disable the ability to do this in the future/require a phonecall to $provider to turn it back on?"-type hint.
For apps that spend money, further integrating pattern-aware anti-fraud and spend caps with payment APIs so that e.g. a microtransaction app that got hacked can't suddenly spend $100 where the user typically spent $5/month. Banks are already starting to get proactive/argumentative about unexpected transaction patterns a la "sir, are you sure you want to send $5000 in your first overseas money wire? Can you tell us more about that transaction? Are you aware of this common fraud?"
I agree with all of this, and these are very good suggestions. I think, if Apple tightens the permission system, then alternative app stores would be a good idea. I also think probably downloading stuff from Safari should not be allowed. But alternative repositories definitely should.
There's a saying about how hard it can be to design bear-resistant containers:
> There is considerable overlap between the intelligence of the smartest bears and the dumbest tourists.
The same is true for computers. Solutions that "allow competent individuals" to do something are also typically solutions scammers can convince Grandma to perform without understanding what they do.
Scammers will manage to manipulate people into giving away all of their savings just fine no matter what restrictions are put in place. The excuse is just another "think of the children" to maintain control and profit.
So your solution is to ban the sale of any kind of knife. Sucks that people can't really cook at home anymore, but do we have to make it trivially easy for murderers?
Those are very different scenarios because your "protection" is the threat of consequences. You can freely buy and use knives, you can drive your own car, but you can only use your phone to do what Apple approves of? Sure, banning knives, replacing cars with public transport, and locking down all computers should be safer in theory... but murderers will still murder and scammers will still scam.
Social engineering is the weakest link even if your grandma is doing all her banking on Windows XP.
> Hell, you'll get in trouble if your gasoline is the wrong color.
You've missed my point even though it's right in front of you. You won't get in trouble for using your Apple device in non-approved ways because it doesn't let you. Would you ban cars for everyone because it's not safe for grandma to drive anymore? Probably not - so why lock down devices for everyone?
> Do we not take steps to try and reduce murder?
Not directly? Gun/knife control probably helps but people willing to risk the consequences of murder are not going to care about breaking more laws to get illegal weapons. Or just use a weapon that's easy to get.
> You won't get in trouble for using your Apple device in non-approved ways because it doesn't let you.
The government won't let me use my car in non-approved ways. They will, in fact, stop me with guns at times.
I'm not even allowed to purchase some items, let alone use as I please. I'm allowed to buy (or sell) a https://www.fairphone.com/ style device! But no one really wants them.
Not relevant. Most people don't choose their phone/platform based on how much freedom it gives you. An iPhone is a very good phone overall but the restrictions are unfortunately bundled in.
You're obviously fine with it but it is only going to get worse in the future. The whole Android developer verification thing is a step in the same direction from Google's side. Eventually macOS will be locked down or even phased out - most young people just do everything on their phone now so why not? I don't want to accept that future so I'm not supporting platforms that restrict it.
They didn't, and I don't have one, but it's looking like Android phones are going to be locked down in the future too. Everything else will slowly lose compatibility with the apps you need.
> If you give a toddler a butcher's knife to play with and they get hurt, you'll likely get in trouble for child endangerment.
Right but granny is not a child, she is kind of the opposite of a child.
You're essentially saying we should child proof the entire world, right. Appeal to the lowest common denominator and DO NOT offer back doors. But that's a plainly ridiculous notion and everyone knows it. This argument only works on smartphones right now because it's the status-quo. As soon as you extend it to literally any other domain, it immediately crumbles and falls between your fingers.
Yes, there IS a certain level of protection that is acceptable at all times. But that level is absolutely not "maximum protection, no other options sorry". Which is what Apple is trying to do. This really is "no sale of knives" type stuff. That sounds ridiculous, right? Because it is, and we let Apple get away with murder.
> The failure modes are often quite similar - cognitive/motor issues and lack of experience with the tools offered.
Okay but again we cannot form all technology to only work for people with cognitive issues and nobody else. Again, this is ridiculous, there's no other way to describe it. It's just not a reasonable viewpoint and I feel it's a bit insane I even have to argue against it.
Look, it's great if we have the option to lock these phones down for more vulnerable people. What we CANNOT do is make the entire world locked down. It's not reasonable.
> Back doors accessible by scammers are bad for the same reasons back doors accessible by governments are.
My mistake, these are front doors. Not back doors.
> Apple's more like a shop that declines to sell knives. There are other shops that will sell you one.
NO, there are not, because Apple chooses to only allow their app store. The market we are talking about here is not "all smartphones". It's "the market of software available for iPhones", in which they hold 100% control over. This should be legislated against.
> Okay but again we cannot form all technology to only work for people with cognitive issues and nobody else.
We can take their needs into consideration, just as we legally require businesses to put wheelchair ramps in.
> NO, there are not, because Apple chooses to only allow their app store. The market we are talking about here is not "all smartphones". It's "the market of software available for iPhones", in which they hold 100% control over. This should be legislated against.
Should Gucci have to sell Coach handbags? Should Ford have to sell Toyotas?
> Should Gucci have to sell Coach handbags? Should Ford have to sell Toyotas?
If Gucci was a Walmart, then yes. If Walmart claimed to be a grocery store, and exclusively served only Walmart goods, that's a problem.
There's a difference between a brand and a marketplace. Apple is a brand. The App Store is a marketplace. The marketplace should be relatively free, in the market sense.
In addition, these are general computation devices. Some people disagree, I don't care, they're obviously wrong. It's not like a washing machine. These are supposed to be for general software and computing purposes, much like your PC. But they aren't, because unlike your PC, they are nonfree.
The bigger thing that I'm kind of hinting at is: we are not trapped into some make believe structure we have to live by. You think Apple shouldn't open their app store. That's just a belief, and one I reject. We can, and should, force their hand. We do it ALLLL the time with corporations, it's very common.
Just because things have worked one way, doesn't mean they should continue to work that way. We can change things at any time, if it is for the better. If we decided we should pass legislation to force Guccie to also sell Prada, then sure. I say why the fuck not? If that's what consumers want, then we should do it. The consumer is king. I give less than zero fucks what Apple wants. If it hurts Apple's bottom line, I still don't care. In fact, I'd argue that if we're hurting Apple's bottom line then we're probably doing something right. I will always side with the consumer 100% of the time.
> The failure modes are often quite similar - cognitive/motor issues and lack of experience with the tools offered.
Children are either not allowed to have devices, or they have them but locked down with parental controls (hopefully).
Apple could easily have a separate mode for this. Maybe there's some overlap with lockdown mode where it can be bundled together. There is no reason to force it on everyone except to benefit Apple.
Society as a whole, to some extent, and the various industries involved.
Why should children be punished with a lifetime of shitty ingrained behaviors just because they were born to shitty parents who wouldn't do the right thing? I'd rather not create the Eloi and Morlocks from HG Wells.
Exactly, computers should only be allowed to do what expert gatekeepers deem safe. There is no possible way to allow competent users to bypass this. Even if they had to go submit a blood sample and sign a document in front of a judge, grandma would just do it anyway! Lock it all down and make sure that compilers require a government license.
Correct. As a side benefit we can restrict users from installing applications that go against other societal interests, like apps that allow unrestricted communications. The framework is complete for mobile devices, we just need to tackle PCs now.
Loudly dismissing genuine and legitimate concerns may feel good, but it’s not likely to get you what you want, especially at a societal level.
I agree with you on the risks of this sort of protection! But I understand what it’s like for non-technical folks in a technical society. Their needs do matter.
You’re precisely right, and of course there’s no possible way on Earth that we could create a safe way to allow users to install apps outside of the blessed path. No matter how many steps people have to go through, even if they have to pass a special exam to prove their competence, even if they have to sign something that says they could lose their life savings and submit it to a court to document this fact. There’s just not a single possible way to protect people to an adequate degree.
That the gatekeeper and government benefit from this arrangement is just a happy accident.
Glad you agree that it’s simply impossible to protect most people and have freedom. Hopefully we can extend this approach to other areas of life soon. “Freedom” is overrated anyways!
The society should change such that grandmas could decide for themselves whether they want tech or not, and still have a comfortable life if they choose to not use it. In our current society, smartphones and the internet are forced on everyone. It's not really a choice any more. Which is quite sad.
My grandma does want tech because she loves sharing pictures with her grandchildren throughout the day. That doesn’t mean she wants to send money to Nigeria through a fake banking app?
Then maybe everyone needs to be educated to never ever trust incoming calls from unknown numbers? Or maybe these need to be blocked at the carriers? We have all this AI crap now but for some reason we can't deploy it to detect scam calls. We instead use it to automate the work that doesn't need automation, like software engineering or copywriting or art.
The average layperson doesn't even know caller ID can be trivially spoofed.
Or they accept the push notification dialog on some random site and start getting "COMPUTER HACKED, CALL MICROSOFT AT FAKE NUMBER" notifications that look like they come from the OS.
My concern has been that companies with a huge install base (hi, Meta) would take advantage of this: "in order to provide you with the best experience, you have to turn off the restricted flag to install the next release of our app".
And then, billions of users cry out in pain as their private data is hoovered into the panopticon in the cloud.
> And then, billions of users cry out in pain as their private data is hoovered into the panopticon in the cloud.
That's not how data collection works? It's Apple's responsibility to prevent their application runtime from exposing private data or unnecessary entitlements. Enabling sideloading does not prevent Apple from protecting user data any more than the App Store does.
One thing we could do is abolish the "anti-circumvention" laws, where the government goes after you with criminal penalties for "contempt of business-model" for interfering with how a company wishes it's code would run on your computer.
Then it would be legal for someone to develop and give-away a patch for the Meta app...
Exactly, and it’s impossible to regulate those business practices! Don’t even try! Better to limit what people can do on their own computing devices, or better yet remove that ownership entirely.
That's great until your device is weaponised against others (see: open HTTP proxies, open DNS resolvers, open SMTP servers, several billion IoT devices, and countless other examples)
> shut down people's connections until they removed their malware.
Yes, in an ideal world, that might work but most people don't actually know they have malware. That's the point of the malware! And it's not like you can say "no internet for you until you replace your TV[0]" because that's an extremely quick way to the courts and a customer reputation below the toilet.
(Ignoring the "who pays for that?" question because that is a whole 'nother can of worms.)
Exactly, which is why we shouldn’t be allowing user “software installs” on any device, not just phones. The world would be a lot better if all tech were fully locked down, “freedom” be damned.
While we're at it, let's also mandate the destruction of every general-purpose computing device incapable of secure boot or allowing it to be deactivated. And if someone dares to build a homebrew CPU out of relays, transistors, or logic ICs, they should expect the FBI to break down their door.
Tell them she doesn't own any devices that could connect to the internet. I'm sure they'll figure something out. They have to have procedures for this sort of thing.
Exactly. Rather than passing laws to require a non-digital option for these things, we should make sure that devices are locked down and controlled against users (aka hapless idiots).
Seems like you’re pushing for control over user tech here over any sort of other regulation. Other regulation which would be much simpler to coordinate and which wouldn’t infringe on end user freedoms!
Removing end user control, repairability, and hackability/repurposing (all related) should be the very last resort, not the first!
While we’re at it, let’s stop crime by adding more officers, reforming the bail system, oh and also installing cameras in everyone’s bedroom.
Last resorts are last resorts because they infringe on core freedoms. And your “controls” are equivalent to removing individual ownership of devices. This is a step too far towards a post-ownership society and joint corporate-state control of the individual’s means of communication and participation in society.