Want to read Slashdot from your mobile device? Point it at m.slashdot.org and keep reading!

 



Forgot your password?
typodupeerror
×
IOS Apple

Apple Wants Users To Trust iOS, But It Doesn't Trust iOS Users (theverge.com) 105

Apple's software engineering head Craig Federighi had a tricky task in the Epic v. Apple trial: explaining why the Mac's security wasn't good enough for the iPhone. From a report: Mac computers have an official Apple App Store, but they also allow downloading software from the internet or a third-party store. Apple has never opened up iOS this way, but it's long touted the privacy and security of both platforms. Then Epic Games sued Apple to force its hand, saying that if an open model is good enough for macOS, Apple's claims about iOS ring hollow. On the stand yesterday, Federighi tried to resolve this problem by portraying iPhones and Macs as dramatically different devices -- and in the process, threw macOS under the bus.

The second difference is data sensitivity. "iPhones are very attractive targets. They are very personal devices that are with you all the time. They have some of your most personal information -- of course your contacts, your photos, but also other things," he said. Mobile devices put a camera, microphone, and GPS tracker in your pocket. "All of these things make access or control of these devices potentially incredibly valuable to an attacker." That may undersell private interactions with Macs; Epic's counsel Yonatan Even noted that many telemedicine calls and other virtual interactions happen on desktop. Still, it's fair to say phones have become many people's all-purpose digital lockboxes. The third difference is more conceptual. Federighi basically says iOS users need to be more protected because the Mac is a specialist tool for people who know how to navigate the complexities of a powerful system, while the iPhone and iPad are -- literally -- for babies.

This discussion has been archived. No new comments can be posted.

Apple Wants Users To Trust iOS, But It Doesn't Trust iOS Users

Comments Filter:
  • by anonimouser ( 7067209 ) on Friday May 21, 2021 @01:33PM (#61407748)
    Is this a technical board? Why would anybody with half a brain advise trusting users?
    • At least they are honest. I phones and Ipads are literally designed for babies. That's why I laugh at parents who are so proud of their baby being able to use one (and probably building some kind of addiction in the process)
      • Yes— designed for babies. That's why they aren't the most common tablet in professional environments, by a mile. Oh, wait, they totally are though. I spend all day long very carefully telling computers what to do while I'm at work using any number of programming languages. When I'm away, I want my phone to be a phone, text messenger, a competent camera, email client, slack client, something I can use to check the news and weather. I have no need to or interest in customizing, tweaking, or doing anyt
        • by Bodie1 ( 1347679 )

          Some people need Heavy Duty pickups (far fewer than actually have them.
          Nobody *needs* a Tesla or a Jeep, those are wants when the need is simply a mode of transportation.

          • "Nobody *needs* a Tesla or a Jeep, those are wants when the need is simply a mode of transportation." Semantics. Depends on how you define need, and your definition is completely arbitrary. Nobody needs any mode of transportation beyond walking if you define need narrowly enough. They built the infrastructure of all old cities and the pyramids without heavy-duty pickups. If you live in a place where EVs get free parking, you can get one relatively affordably, and you get good tax benefits, then you need o
        • by dgatwood ( 11270 ) on Friday May 21, 2021 @03:40PM (#61408134) Homepage Journal

          I spend all day long very carefully telling computers what to do while I'm at work using any number of programming languages. When I'm away, I want my phone to be a phone, text messenger, a competent camera, email client, slack client, something I can use to check the news and weather.

          Yup. And if you add games and entertainment to your list, that's how 99.99% of users use a phone. Apple's entire argument seems to be based around the phone having data that is way more private than what's in your computer. That couldn't be further from the truth. My computer contains everything I've ever created artistically and technically. It has access to literally everything my phone does, apart from GPS location, plus all of those things above, plus my taxes, etc.

          Yay, somebody could use a phone as a GPS tracker. That means nothing to me. If anybody wants to know where I go, it's not that hard to stick a tracker on my car. They're sure not going to trick me into installing an app on my phone. And if somebody does pull down GPS data by installing spyware on phones in bulk somehow, what are the odds of that affecting me one iota? Approximately zero unless I work for a three-letter clandestine agency or something.

          Privacy isn't about those things. Privacy is about knowing that your most important, most private data will remain so. And that data is almost certainly going to be on your computer. It might *also* be on your phone in some cases (e.g. private photos), but if it's important to me, you can bet it isn't *just* on a phone that can be easily lost or stolen.

          I have no need to or interest in customizing, tweaking, or doing anything else to my phone and I don't want to have to think about how my phone does those things. If I did, I'd get an android phone and be totally happy with it.

          That's where you lost me. Most people don't customize their phones meaningfully. The difference between having multiple app stores and one app store is whether you trust a single company to always represent your interests.

          Case in point: Parler. Apple deciding to kick them off of the iOS App Store began a wave of shutdowns by other companies that basically wiped them off the Internet. Now I'm not saying I like Parler by any means, but the decision to remove them from the iOS App Store was still a politically fueled decision by one company that severely crippled access to that service for presumably millions of people. So Apple isn't just applying security standards; it is also applying political standards.

          Also consider porn, gambling, foul language, etc., any of which can cause an app to be removed from or never allowed onto the platform. So Apple isn't just applying security standards; it is also applying moral standards.

          And of course, there's the payment system angle, which this case is all about, where Apple is effectively driving up prices for an entire category of items (in-app purchases) by preventing anyone from creating a competing in-app purchase system, and preventing any app developer from disclosing the fact that users can buy those same items directly from the software vendor's website at a lower price.

          Having the ability to download apps from competing app stores makes all of those concerns moot. Apple becomes the moral, political, security, and payment processing arbiter for their store, and other stores can set different standards. Users can choose on an app-by-app basis using whatever metrics they prefer. Developers who don't like Apple's standards can take their marbles and go to some other store. And so on.

          It's a different use case and there are different devices available for those different use cases. Why does that offend people so much? Some people need teslas, some people need jeeps, and some people need F350s. It would be just as dumb for someone driving a jeep derisively commenting about a tesla's comparative offroading capability.

          It's offensive

          • You're arguing that Apple doesn't do a bunch of things that I didn't say it did. I said I don't care that apple doesn't do those things because my use case doesn't require them. If your use case is different, there are alternatives. If someone buys a phone that doesn't fit their use case, they're an idiot. What the fuck is broken in some people's brains that makes them so angry that some people have different use cases?
            • If your use case is different, there are alternatives.

              Which brand of phone is appropriate for the use case of someone who wants to both A. communicate with another person who prefers to communicate through iMessage and B. use a web application that uses web platform APIs that Apple has not implemented in Safari for years [infrequently.org]?

              • What platform do I use if I want a posix compliant operating system and still play all of the latest games as they come out? What car platform do I choose if I want great gas mileage but need to transport 8 people at a time? Theyâ(TM)re called trade-offs. Iâ(TM)m willing to trade flexibility for stability in my phone. Some people arenâ(TM)t. Thatâ(TM)s not what you would prefer the trade offs to be to begin with. Sorry?
                • by tepples ( 727027 )

                  What platform do I use if I want a posix compliant operating system and still play all of the latest games as they come out?

                  PCs dual-boot a lot more easily than phones do.

                  What car platform do I choose if I want great gas mileage but need to transport 8 people at a time?

                  Electric trucks are on the way.

            • by dgatwood ( 11270 )

              You're arguing that Apple doesn't do a bunch of things that I didn't say it did. I said I don't care that apple doesn't do those things because my use case doesn't require them. If your use case is different, there are alternatives. If someone buys a phone that doesn't fit their use case, they're an idiot.

              The problem is that you're assuming a static set of use cases. In practice, for the vast majority of the users, their needs are not static.

              People's needs change. They get new jobs. They get new hobbies. They meet new people who use different communication mechanisms. New software comes on the market that expands what they can do with their devices, and they suddenly realize that they had unmet needs that they weren't even aware existed when they bought their phones.

              Users can't possibly begin to guess w

              • Jesus. I read your first sentence telling me what I was arguing and stopped because it was wrong. I was saying what MY use case was, and that it fit MY use case. It also fits the use case of many people, which is why is the most popular mobile platform on the planet. Since you canâ(TM)t have infinite use cases, these are where the feature sets landed. If you need summer or both, bummer. Itâ(TM)s a phone. Get a fucking grip. If you genuinely are offended by someone elseâ(TM)s smartphone platfo
                • by dgatwood ( 11270 )

                  Jesus. I read your first sentence telling me what I was arguing and stopped because it was wrong.

                  I didn't tell you what you were arguing at all. I said why your argument is completely uninteresting. Specifically, the way you use your phone is several standard deviations away from the norm. Almost all iOS users use their devices for playing games and media consumption. As someone who doesn't use the device for either of those things, your use case represents a tiny minority of users.

                  To put it in perspective, about 74% of U.S. and Canadian smartphone users play mobile games, with 62% of worldwide sma

                  • "You're reading way more into what I'm saying than I am actually saying."

                    Frankly, I'm actually hardly reading anything you're typing at all. If you type in paragraphs to answer a few sentences, the person you're trying to convince is yourself.

    • by caseih ( 160668 )

      If you're talking about a server facing the world, then yes I agree with you. Or even an OS that doesn't trust the apps (root vs normal user) is perfectly acceptable. But at some point a device I own has to do my bidding not matter what that is. If I want full root access, it must give it to me. Doesn't mean it shouldn't warn me I'm about to void my warranty, there are no user-serviceable parts inside, or remind me that the manufacturer disclaims all liability for me using it to injure myself or worse, o

      • The problem is nowadays that much software if not most of it is now subscription, in other words it is rented. Therefore in effect Apple only rents your the device.

      • Apple could alleviate this problem by allowing an iOS user to download software from an approved developer. That's what they do for the Mac.

        Since a phone usually has more personal information on it, they could warn the users that downloading from anywhere else other than the App Store avoids the warranty of their device, since there is a good possibility that malware was installed thereupon. That way if somebody wants to download directly from any software developer, they could do so, but at the risk of for

        • In the US, 15 USC 50 prohibits voiding a warranty because someone is using a compatible product with your product. If you're requiring registered developers then you're absolutely making the argument for the user that they should expect a compatible product.

          You might make clear to the user, as Google does, that software from third-party sources has not been approved and might do bad shit or whatever. It might make their device insecure. But you should still be able to restore the device to stock with little

    • by AmiMoJo ( 196126 )

      That's fine if it's your system. An iPhone doesn't belong to Apple after they have sold it.

    • by fermion ( 181285 )
      And as technical people we know some things are simply an accident of history. Security online for MS was a joke because it evolved as a desktop device and never fully adapted to an open network. Apple used a *nix base, which was network centric. No one would say Apple should revert to MS security.

      Likewise, the personal computer market devolved most responsibility to the end user. MS, as a corporate centric provider, added tools to allow central management by system administrators, but for Apple such a t

    • Agreed, the bulk of System Bloat and Memory and Storage needs, isn't as much what the program needs to do its job, but to deal with all the stupid things that people will do with the software.

      A few years ago we had an updated server with Office 95 installed on it (for compatibility reasons, with a vendor we were soon to replace). I never seen office run so fast, it even opened up just as fast as notepad does, Office 95 does nearly most of all the functionally we use today. Except for the fact it could cra

    • by MeNeXT ( 200840 )

      Trust. Who's phone is it anyway? When was it even OK to treat adults like children? If you can't trust users to use the stuff they own why would you trust them to elect the nations leaders? ...

      The questions are endless. The problem with your question is that you fail to even show that it's your choice to make.

    • Comment removed based on user account deletion
      • by bws111 ( 1216812 )

        Well that is an idoitic analogy. Change it to something that makes sense: my bank wants me to trust them to keep my money but it doesn't trust me to spend my money how I see fit. Oh, wait. That doesn't happen.

        • Actually your bank will put blocks on what you do with your money. Ever heard of this thing called a "hold"? Whereby you deposit a large sum of money and cannot access it for some not-predetermined amount of time? And then there is the run on the bank. Which makes you realize that you give the bank your money and they spend it right away. And cannot give it back.
    • Is this a technical board? Why would anybody with half a brain advise trusting users?

      Is this a technical board? Why would anybody with half a brain advise trusting corporations?

    • by Dracos ( 107777 )

      The users on mobile OSes are the apps, not people. They trust the apps, people are just data sources.

      A dairy farmer has no need to trust the cow, they just want the milk.

  • by david.emery ( 127135 ) on Friday May 21, 2021 @01:39PM (#61407770)

    What is it about Apple, that generates so many just plain wrong headlines? The idea of ANY PLATFORM should be to prevent users from being harmed by the platform itself, or by 3rd party apps (or hardware). How is that "not trusting the users?"

    Shouldn't this be cast as "We want users to trust iOS, so they don't have to worry about whether they have to independently verify each app?" Now some users want more control, and Android would work well for them. As someone who has owned a computer continuously since Oct '78, I'm just fine with Apple limiting my choices in iOS in exchange for substantially increased platform security. The occasional frustration is worth it, in my opinion/experience. I'm willing to be a bit more adventurous on my Mac. But Federeghi is right, Mac security is by no means where it should be. The goal should be "zero exploitable vulnerabilities", and just because a lot of software companies have demonstrated no ability to approach that goal, doesn't mean the goal itself isn't what we -all- should strive for.

    • by AmiMoJo ( 196126 )

      It's the parent-infant relationship. The infant trusts the patent completely, but the parent constantly monitors and protects the infant that can't be trusted to look after itself.

      Android is like an adult relationship. Caring but ultimately the choice is the user's.

      • I'll give you another analogy: Cars with seat belts.

        • by AmiMoJo ( 196126 )

          That's the adult relationship. The car might go as far as beeping at you if you don't put your seatbelt on, but it won't disable the accelerator.

          The infant gets strapped in with child proof buckles.

          • by mark-t ( 151149 )

            It won't completely disable the accellerator, but it can limit the speed.and/or gears the car can be put into when the seatbelt is not fastened. In vehicles that implement such locking, usually only reverse and first gear are accessible when the seat belt is not fastened.

            There are still mechanisms that can disable this if desired, but the hoops that must be jumped through must always be manually employed each time you want to turn the feature off when you are starting the car.

    • by Macdude ( 23507 )

      What is it about Apple, that generates so many just plain wrong headlines?

      This is an article from The Verge. You know, the publication that doesn't know the difference between zip ties and tweezers... so what do you expect?

    • What is it about Apple, that generates so many just plain wrong headlines? The idea of ANY PLATFORM should be to prevent users from being harmed by the platform itself, or by 3rd party apps (or hardware). How is that "not trusting the users?"

      Shouldn't this be cast as "We want users to trust iOS, so they don't have to worry about whether they have to independently verify each app?" Now some users want more control, and Android would work well for them. As someone who has owned a computer continuously since Oct '78, I'm just fine with Apple limiting my choices in iOS in exchange for substantially increased platform security. The occasional frustration is worth it, in my opinion/experience. I'm willing to be a bit more adventurous on my Mac. But Federeghi is right, Mac security is by no means where it should be. The goal should be "zero exploitable vulnerabilities", and just because a lot of software companies have demonstrated no ability to approach that goal, doesn't mean the goal itself isn't what we -all- should strive for.

      Shouldn't this be cast as "We want users to trust iOS, so they don't have to worry about whether they have to independently verify each app?"

      Uh, no, because most users probably wouldn't have a damn clue as to what you're talking about.

      (Common Layperson) "What do you mean 'verify' the app? It's right there, on my screen. There, I just 'verified' it. Stop laughing at me! This is like that time you tried to teach me about coherent light. I was talking to that damn flashlight for 10 minutes."

    • Shouldn't this be cast as "We want users to trust iOS, so they don't have to worry about whether they have to independently verify each app?"

      No. [theverge.com]

    • by tepples ( 727027 )

      The idea of ANY PLATFORM should be to prevent users from being harmed by the platform itself, or by 3rd party apps (or hardware).

      Then why do any platform publishers even allow third-party applications to exist in the first place? No third-party apps means no harmful third-party apps. And even if platform publishers do deign to permit third-party apps, why don't all platform publishers require each application to be published by an established corporation or LLC with an office location and three previous apps on other platforms?

  • Have you met us?

  • by thegarbz ( 1787294 ) on Friday May 21, 2021 @01:45PM (#61407782)

    For 30 years malware has run rampant in ways that could be prevented by the most basic of user activities. Applying security updates. Not blindly installing software. No logging in and running your desktop as the root user (yes, sorry neckbeards, there are dumb Unix users out there as well). Realising that "britney spears naked definitely not virus.scr.exe"* that a random person emailed you probably shouldn't be executed.

    Users will be trusted once they have shown to be trustworthy. But trust is earned and as shitty as it is for the technical elite one of the best advances to security came from mandatory security updates.

    I say shitty but then the first thing the technical elite do is try to figure out a way to block security updates showing that they themselves are unable to be trusted with their own safety, so there's that golden nugget as well.

    *Speaking of trusting users one long word doesn't look like ascii art you stupid worthless filter. I bet you Slashdot thinks German is ascii art too.

    • mandatory security updates

      That's the reason why I mostly left Windows.

      • The difference is that in 10+ years of supporting large numbers of iPad/iPhone devices, I have seen an iOS update bork something *maybe* twice. I know computer repairs shops that *stay in business* due to Windows 10 updates breaking things.
        • You are comparing apples to oranges dude. iOS/macOS only run on Apple's hardware (although Intel macOS can be ran on a Hackintosh hardware). Windows isn't tied down solely to Microsoft's hardware on the contrary. It is meant to run on a very wide range of x86 hardware made by mostly non-Microsoft manufacturers.
      • That's the reason why I mostly left Windows.

        I'm actually all in favour of providing 100% user control over windows updates under the conditions of an OS firewall blocking all non local traffic in and out to anything other than an update server if the update hasn't been applied within a specific period. Mind you I also believe anti-vaxxer's kids should be barred from attending school.

        Sasser was prolific on the internet for not only years after the virus was written, but years after the wormable exploit for it was patched and the writer was put in jail

        • Say someone wants a vaccine but can't afford the fee to administer it and happens to live in a jurisdiction that provides no public subsidy for vaccination. (Such jurisdictions include U.S. states that opted out of Obamacaid.) Would you call people in this situation "anti-vaxxers"?

          Say someone wants to install updates on a particular device, but no updates are available because the device's operating system has reached its end of support date. Would you call people in this situation "technological anti-vaxxe

  • I'm not thrilled with a number of Apple's policies with respect to the store and would like to see some of their business practices change. That said, the arguments made by Apple above sound pretty reasonable to me and the summary/headline do not accurately describe the content.

  • by gurps_npc ( 621217 ) on Friday May 21, 2021 @01:53PM (#61407802) Homepage

    Is serious question. Am totally not Russian Hacker looking for targets.
    Please give me American English list of company-s trusting us honest users?

    Need support good people-comapnaies, not steal from them. Promise.

  • by FudRucker ( 866063 ) on Friday May 21, 2021 @01:53PM (#61407806)
    on this argument, considering iOS has Apple Wallet, and other personal info, letting unknowns in your iphone is like letting strangers look in your wallet, or purse, i think Apple is right in using the higher security mode on the iphone and it should stay that way, i wonder how many people had their banking info stolen and/or identity stolen from malware in android phones or on a MS_Windows PC, i bet more than Google & Microsoft would want you to know
    • What's stored on a computer isn't that different than what's stored on a smartphone.

      I have a Mac, and my credit cards are stored there too. I can even buy from websites that have implemented Apple Pay - without involving my phone at all.

  • Apple trusts iOS users. They don't trust iOS *apps*. Huge, vast difference.

    The simple truth is you cannot have users realistically handle most security screening and maintenance for a daily computing platform. Android proves this to the nth degree, replicating all of the sins of past computing platforms for mobile and user suffering from malware as a result... We cannot as an industry keep shipping absolute crap that screws over users with poor security, which has been true of all desktop OSs forever (t

  • Movie theaters also don't want you to bring in outside food because you could get food poisoning from anything that isn't sold there.
    • by mark-t ( 151149 )

      I'm curious, where did you read that that was supposedly the reason they disallow outside food?

      A person could have a stroke or heart attack in the theater as well, but they don't generally require any sort of health screening to see a film.

      This has absolutely nothing to do with liability, I'm just curious where you heard that it supposedly did.

      • It's like an iron-clad law of comment sections that, no matter how sarcastic the comment, someone will come along and not get it.

        Unless you did, in which case - excellent deadpan.
  • You fools! dont trust the users! what are you thinking? User are dumb and will brick their own device if they could.
  • Just for the record let it be said that we have long known that the primary reason Apple Inc. locks phones and tablets to their proprietary "App store" is Profit. There are other reasons, but numbers 2 and 3 are also Profit. The only reason this model has spread to other makers and devices is because of their Envy of Apple Inc's massive profits. The primary reason we developer's put up with it is that Steve promised us profits too, with him getting a nearly 1/3 cut for the privilege.
  • TRUST BUT VERIFY! If I can verify it I cannot trust it.

Never ask two questions in a business letter. The reply will discuss the one you are least interested, and say nothing about the other.

Working...