Number of Government Agencies Have Concerns About 'Sideloading' on iPhone, Apple Says (reuters.com) 109
A number of government agencies in the European Union and elsewhere have voiced concerns about security risks as Apple opens up its iPhones and iPads to rival app stores to comply with EU tech rules, Apple said on Friday. From a report: Under the Digital Markets Act, from March 7 Apple will be required to offer alternative app stores on iPhones and allow developers to opt out of using its in-app payment system, which charges fees of up to 30%. The U.S. tech giant, which on Jan. 24 detailed the changes to bring its App Store in line with the EU rules, said "sideloading" has sparked concerns from both EU and non-EU government agencies and users.
My BS Meter is over 9000! (Score:5, Insightful)
Re: (Score:3, Informative)
Android doesn't suffer security issues from sideloading
it quite literally does.
Re:My BS Meter is over 9000! (Score:5, Insightful)
And this is utterly irrelevant. The owner of a device should not have to fight with the manufacturer to do whatever the fuck they want to do with that device even if the decision is bad for them or their device in the long run. If a manufacturer has more control of it than the owner, then the device is pre-loaded with malware from the factory even if that malware is the legitimate software products of that manufacturer. That is a huge issue with software and devices today.... treating the owner as if they are the thing that needs to be protected against.
Re: (Score:1, Funny)
Then go buy your preferred Android device and stop forcing your preferences on me.
Re: My BS Meter is over 9000! (Score:2)
Re: My BS Meter is over 9000! (Score:5, Insightful)
Giving people control over their own devices does not break Apple devices. It only breaks their business model. It shouldn't even be a question for owners to be the sole decision maker over their devices whether it is phones, cars, tv's, media players, gaming consoles or anything. It really should be regulated by law that companies cannot over ride the owners wishes and that all devices must be shipped with a way to lock the manufacturer out entirely if the owner wishes to do so. Choice is never bad. Many people will choose to continue giving Apple or Google that control, but it should NEVER be forced on the owner of any device.
Re: (Score:1)
Re: (Score:2)
Giving people control over their own devices does not break Apple devices. It only breaks their business model.
Which we, APPLE USERS, Understand, CHOSE OF FREE WILL, and Agree-With!
Now Who is REALLY Restricting Freedoms?
Re: My BS Meter is over 9000! (Score:3)
Re: (Score:2)
But it's your own choice if you want to sideload or not, if you don't, your iPhone/iPad is just as safe as it's now, which isn't as safe as you believe it is, many enough mallware have gone through Apple's so called app-checks.
And it happens seldom-enough that it is still Front Page News on Slashdot.
If the same Coverage was given to Android Exploits, there wouldn't be room for any other Stories!
Re: (Score:2)
Then go buy your preferred Android device and stop forcing your preferences on me.
"If we allow abortion to be legal that means all women are going to be forced to get abortions."
Do you see how stupid your response is now?
Re: (Score:3)
Re: (Score:1)
Re: (Score:2)
Re: (Score:2)
By that logic Apple should declare all of their products feature complete and halt all development on them. After all, any new feature, support, or update can create a exploitable vulnerability that didn't exist before. So enjoy the last iPhone, Citizen!
Actually, Apple, and its Users, are intelligent enough to understand the distinction, and the ramifications thereof.
Re:My BS Meter is over 9000! (Score:4, Insightful)
Re: (Score:2)
Then go buy your preferred Android device and stop forcing your preferences on me.
Exactly.
Re: (Score:2)
If an owner wants to take risks with their devices, that is on them; however, for the OP to outright state that there is no risk is disingenuous to the argument. In this case, the owners which are government entities are pointing out that there are risks to sideloading. This should not be news to anyone.
Re: (Score:2)
And my point is that the government should have the ability to make that decision if they own the device. If they don't then it should not be their decision.
Re: (Score:3)
Re: (Score:2)
Isn't that just standard provisioning in the business world, like on Android?
Re: (Score:2)
Re: (Score:1)
the owners which are government entities are pointing out that there are risks to sideloading.
Fun fact: Both government entities and private corporations have numerous tools for preventing sideloading on Android. The android ecosystem managed to find a way to allow private owners of devices and corporate/government entities to prevent sideloading. Or provide insulated sandboxes that completely side-step and work around this concern. You can have your cake and eat it too. This is a false-dichotomy.
Re: (Score:2)
You can have your cake and eat it too. This is a false-dichotomy.
And how is this a false-dichotomy? There are risks to side loading. Since Apple has never allowed it on iPhones government agencies have never had to comment about it for their phones.
Re: (Score:1)
Re: (Score:2)
Because you can leave the "don't allow third-party apps" box checked?
First of all, you do know there is more to sideloading than 3rd party apps right? Sideloading means installing from other sources. Facebook is a 3rd party app that can be installed from the Google Play Store and Apple App Store. Fazebook is also a third party app from Mike's App Emporium. I'm sure that it connecting to Mike's App Emporium is perfectly safe with a government phone, right?
No one forces you to uncheck the box.
You do understand that as the owner of a device, government agencies want the ability to override what the user (their emp
Re: (Score:1)
Re: (Score:2)
Yes, and on Android you have to install the APK for "Mike's App Emporium" by unchecking the box . . .
So you saying that there are a lot more to sideloading than 3rd party apps. And you are surprised that government agencies do not want their users to be able to do that?
That's correct. You can't disable a non-existent setting using a device policy management system. This article presents as "see sideloading is iNsEcUrE!" - so you shouldn't support it, not "Hey, Apple doesn't support proper device management" - do you see the difference? One is spreading FUD to try to continue to drive profits, the other one just tries to fix a technical problem. But crucially, we don't know that Apple isn't going to give this device management capability to corporate/government customers on their as-yet-unreleased feature.
The article specifically spells out what everyone should know about side loading. Enterprises like government agencies are saying there are risks. Did you even read the article?
so you shouldn't support it, not "Hey, Apple doesn't support proper device management" - do you see the difference
Again did you even read the article? Government agencies want the ability to block side loading on government iPhones. And? What is wrong with that request?
? One is spreading FUD to try to continue to drive profits, the other one just tries to fix a technical problem..
You are
Re: (Score:1)
Did you even read the article?
Yes.
You are the one that asserted it was BYOD.
No, iOS covers private use, BYOD, Corporate owners, and government owners of devices. Private individuals, and even some corporations want the ability to side load. If Apple nukes the option to sideload, that affects BYOD users and private users. So yes, this is part of the BYOD scenario. And for that matter many governments and government departments support BYOD. You are the one that says it is BS for an enterprise to want to control what their users install on their equipment. You turn what should b
Re: (Score:2)
No, iOS covers private use, BYOD, Corporate owners, and government owners of devices. Private individuals, and even some corporations want the ability to side load. If Apple nukes the option to sideload, that affects BYOD users and private users. So yes, this is part of the BYOD scenario. And for that matter many governments and government departments support BYOD.
The ENTIRE point of the article was about government owned phones. No one was saying that consumers could not do what they wanted on their own phones. No one is talking about BYOD except you. But you immediately cried "BS" about a topic that no one was talking about. Or you didn't bother to read the article and went half-cocked into complaining about BYOD rights. Now you are desperately trying to pretend you knew the entire article was about government owned equipment.
That's actually not something I said, but you seem to think I did. Did you read what I posted?
Your entire post: "They allow "sideload
Re: (Score:2)
Private individuals, and even some corporations want the ability to side load.
Let's see some statistics on that.
Re: (Score:2)
You can do whatever you want with your apple device. Toss it in the garbage disposal if you like. No one cares. But you are asking Apple to help you, which they should be able to decline.
Re: (Score:1)
Re: (Score:2)
No, it's worse than that: Apple actively try to prevent users from "doing whatever they want" and then hide behind things like the DMCA to justify preventing users from doing whatever they want in the name of "security" while offering other products that allow just such sideloading that would "be a security risk" yet would never claim it's insecure.
It's evidence that it isn't about keeping you "secure" but instead that what they really want is to keep you inside of their walled garden because it helps their bottom line.
Then why not do it on Macs, too?
Re: (Score:2)
There were some signs that they were starting to... In OSX Lion they introduced the app store to Mac. It's not that much further to "no side loading" Fortunately, they haven't done that (which is why I still use Mac laptops) but it seemed like they were trending in that direction. Of course, it's a little harder to prevent me from rooting my mac...
They never will.
They have taken some measures to try to keep the Normies safe(r); while still allowing the use of Secret Moose Handshakes to get past the Restrictions.
Re: (Score:2)
The owner of a device should not have to fight with the manufacturer
Huh? The owner *IS* the manufacturer. They are merely letting you use it for a princely one time fee. Same with cars and many other technology devices. YOU are not the fucking owner; otherwise, they would not be allowed to design the devices the way they do.
Don't even get me started on Microsoft.
Re: My BS Meter is over 9000! (Score:3)
What it literally doesn't suffer security problems from is the very existence of sideloading, which is what apple and apple fanboys claim.
No Android user suffers reduced security because they can sideload, only if they actually do it.
Even then by default Play Protect is on and will scan devices for known malware.
Re: (Score:2)
What it literally doesn't suffer security problems from is the very existence of sideloading, which is what apple and apple fanboys claim.
No Android user suffers reduced security because they can sideload, only if they actually do it.
Even then by default Play Protect is on and will scan devices for known malware.
Bitch, Please. . .
Re: (Score:1)
Re: (Score:2)
It's not, actually. There are two "sandboxes" on Android devices. They long ago established a VM for businesses to allow you to prevent sideloading apps. For example Samsung Knox [samsungknox.com]. Microsoft InTune [microsoft.com] does something similar. And eventually, this was incorporated directly into the Android operating system and work can no longer wipe the entirety of my PERSONAL phone when I leave an employer - only the E-mail and sensitive corporate secrets that are limited to such sandboxes and workspaces.
Once upon a time, before this technique existed, I had to root my phone and install a custom E-mail client to prevent work from wiping the photos of my kids, music, and other personal data that they have no business destroying. If Apple is unwilling to do the same, it's actually LESS secure because now I have an incentive to root my device while Android was able to find a solution so that I never even need to do that.
But, even assuming that is all true, it is obviously unfair to Demand that Apple to redesign and test such a sweeping change within the ridiculous Enforcement timeframes that Governments have and will Demand.
Re: (Score:2)
Android doesn't suffer security issues from sideloading..
My BS meter is over 900000000.
Re: (Score:1)
Re: (Score:2)
I'm sure side loading is one of the possible vehicles for malware, but not allowing that option to be enabled, if and when the user specifically chooses to, is control freak behaviour.
Apple would have been much better off allowing the option before it got to the point it is forced to do it. That way they would have been able to add a serie of "Do it at your own risk" messages without those messages being considered a problem.
Now any message to make sure the user understand what they are doing will be considered an attempt to circumvent the law.
Wrong!
It will take .000005 femtoseconds for Epic, Spotify et al, to complain to $RANDOM_GOVERNMENT that "Apple is trying to Discourage Third-Party Downloading, which is "Anticompetitive Behavior".
Then, Apple will be forced to Remove the "Scary Warnings".
You know it, and I know it.
Re: (Score:1)
Re: (Score:2)
That's exactly what I'm saying. Had they allowed side loading before any of these legal battles erupted, Apple would have had a better argument to say it was important to have a warning there, now it is too late.
So, please tell me how a Government can say that Apple not having a feature (sideloading) that their Competition does, somehow gives Apple an "Anticompetitive Advantage"?
Only in Topsy-Turvy World. But that's what we apparently have, here.
Re: (Score:1)
Re: (Score:1)
Re: (Score:2)
towers = toward, sorry :)
Apple owes App Developers Diddly minus Squat.
Re: (Score:2)
It would be interesting to investigate these "government agencies", and see who received "donations" from Apple.
Re: (Score:2)
It would be interesting to investigate these "government agencies", and see who received "donations" from Apple.
Government agencies which control which websites their employees (which are government employees) visit are risk adverse to their employees installing whatever software from whatever store they want. I am not sure why you think there is a grand conspiracy here. I once contracted for a state agency and state employees could not visit the state lottery website using state computers as it was gambling.
Re: (Score:2)
They allow "sideloading" on their laptops...
What are you talking about? Many places I have worked including for government entities lock down all computers so that users cannot install whatever they want.
Android doesn't suffer security issues from sideloading.
Again, what are you talking about? Sideloading on Android is a security risk and has always been. Just this month Google has blocked sideloading from some apps. [thehackernews.com] Google gives consumers more rope to hang themselves, but they can and do hang themselves if they choose to sideload.
Apple just wants to push this narrative to line their pocketbooks. As long as they can keep you trapped in their eco system, they can keep milking you for money.
If you want sideloading, that's fine. But to state things which are not tr
Re: My BS Meter is over 9000! (Score:3)
You moved the goalposts in your first sentence and you want to cry about claims made by others?
Re: (Score:1)
You moved the goalposts in your first sentence and you want to cry about claims made by others?
His first comment is "They allow "sideloading" on their laptops!" Please read before you comment. I can assure you that in general government agencies do not allow sideloading on government owned laptops. His second comment was "Android doesn't suffer security issues from sideloading." That is factually untrue; there are security issues from sideloading. There has always been risks. If a consumer wants to sideload, it is up to them but saying there are no security issues is dishonest. That is as idiotic as
Re: My BS Meter is over 9000! (Score:2)
I read, that's how I knew it was bullshit. Apple doesn't prevent you from loading that software, meanwhile managed Android devices can be prevented from sideloading so that is meaningless.
Re: (Score:2)
I read, that's how I knew it was bullshit. Apple doesn't prevent you from loading that software, .
I see I need to explain things slowly to you. The ENTIRE article is about how government agencies want the ability to block sideloading on government owned iPhones. The OP's first sentence is that on laptops sideloading is allowed. Neither you nor he understands that is not true on government owned laptops. Government owned computers are locked down as to prevent users from installing whatever software they want. He apparently did not read the article to know the focus was about government owned equipment.
Re: (Score:2)
Oh how cute, you think you're in a position to dictate what is discussed in a Slashdot comment thread on the basis of what's in the article. Adorbs!
Re: (Score:2)
Oh how cute, you think you're in a position to dictate what is discussed in a Slashdot comment thread on the basis of what's in the article. Adorbs!
Did you read the article or not before you started complaining? Because it says clearly talks about government owned iPhones. You and the OP started bitching about things which have nothing to do with the article. Your modus operandi has always been to complain about everything Apple regardless of what the topic actually is.
Re: (Score:1)
What are you talking about? Many places I have worked including for government entities lock down all computers so that users cannot install whatever they want.
Yes, and you can do this on a Mac too. But we're talking about a BYOD piece of hardware, not something government or work issued - and Android even has very elegant options for splitting the difference.
Google gives consumers more rope to hang themselves, but they can and do hang themselves if they choose to sideload.
*if they choose to sideload* - at that point it was my option to engage in risky behavior. But what I don't need is a nanny state where a corporate overlord makes that decision for me. All anyone wants is the *option* to make that decision. I've always voted with my feet by rejecting Apple devices, but it is
Re: (Score:2)
Yes, and you can do this on a Mac too. But we're talking about a BYOD piece of hardware, not something government or work issued - and Android even has very elegant options for splitting the difference.
No we are not. The entire point of the article was about government purchased iPhones not BYOD. Did you even read the article?
It said the agencies wanted assurances that they would be able to prevent government employees from sideloading apps onto government-purchased iPhones and that several said they planned to block sideloading on every device they manage.
*if they choose to sideload* - at that point it was my option to engage in risky behavior. But what I don't need is a nanny state where a corporate overlord makes that decision for me. All anyone wants is the *option* to make that decision. I've always voted with my feet by rejecting Apple devices, but it is anti-competitive behavior at the least to not give users the choice as other companies - and even Apple themselves (with other products) demonstrate.,
Again, the article was about government agencies being able to disable sideloading for government purchased iPhones. Government agencies block users from doing all sorts of things with government equipment. I am not sure why every one is surprised that they want to block sideloading for government iPhones.
Re: My BS Meter is over 9000! (Score:2)
Re: (Score:2)
They allow "sideloading" on their laptops... Android doesn't suffer security issues from sideloading. Apple just wants to push this narrative to line their pocketbooks. As long as they can keep you trapped in their eco system, they can keep milking you for money.
Liar.
Apple has repeatedly and consistently held that:
1. macOS is indeed less secure due to allowing Downloads from anywhere.
2.iOS and macOS are different use-cases; and thus justify differing security vs. convenience Models.
Oh, and I don't know who you are trying to convince that Android doesn't suffer, Security-Wise, by allowing indiscriminate Downloads; but the proof has been in the news for years.
Quit Lying, Shill.
Owner should get to say (Score:2)
I am a huge naysayer of walled gardens and think they should never exist. I think the owner of any device should the sole God of that device and should be the only decision maker that matters. BUT that means if the owner is a business or a government entity then they should set the devices up to their chosen level of security. If a regular person is owner of the device, then they should have say over whether sideloading or rooting is OK. Personally I believe if you don't have root on your own device then it
Re: (Score:2)
Expect with an i-Device, you're not the owner, you're a renter.
Re: (Score:3)
You misunderstood my point. No matter whether the owner is a business, the government or a normal everyday user buying it with their own money. Whoever the OWNER is, is all that matters and no security decision should over ride the owner of the device even if it is a bad decision. Owners should have every right to, and the ability to lock out even the manufacturer of a device once they have purchased it. And every decision that owner makes should be law of the land for that device. If someone, even the manu
Just give the EU ... (Score:1, Flamebait)
Re: (Score:2)
How does side-loading malicious apps but continuing to be lulled into a false sense of security with blue bubbles improve it?
Yeah (Score:2)
Put a green tint over any app purchased on a non-Apple ap store.
Lock them down. (Score:2)
The government must be able to block sideloading on devices they provide for business use. So should companies. It would be just plain f-ing stupid to hold them accountable for security, and also demand they accept the wild west of "anything goes in apps". This is conceptually no different than denying people localadmin.
Is there even a debate to be had? They should stay out of the question of what individuals do with their personal devices, but this does not seem like an overreach to me.
Re: (Score:2)
The issue is BYOD. They've been saving money that way for a while. They'll have to alter their BYOD policies and tighten the screws on iPhones.
They already support Android so this is not impossible.
Re: (Score:2)
It said the agencies wanted assurances that they would be able to prevent government employees from sideloading apps onto government-purchased iPhones and that several said they planned to block sideloading on every device they manage.
Re: Lock them down. (Score:2)
It's a matter of MDMs supporting that kind of lockdown same as they do with Android.
Re: (Score:2)
Re: Lock them down. (Score:2)
Re: (Score:2)
Supervised mode, use mdm to use an allow list of apps, problem solved. They should do that any way, it's not like exploits don't get uploaded to Apple's store.
Re: (Score:2)
Supervised mode, use mdm to use an allow list of apps, problem solved. They should do that any way, it's not like exploits don't get uploaded to Apple's store.
I would guess there are more risks than whitelisting apps. Using an alternate store may present other security problems. But the underlying concern from these agencies is that there needs to be a way to block it from their standpoint. The actual implementation is not defined yet.
Re: (Score:2)
What risk could there be? The alternative app store apps are still just apps, despite that they are distributed across the web I assume supervised mode will block them if they aren't on the allow list.
I guess the attack surface is increased by a couple hundred lines of code due to new code paths for installing apps ... a couple hundred on top of millions.
Re: (Score:2)
What risk could there be? The alternative app store apps are still just apps, despite that they are distributed across the web I assume supervised mode will block them if they aren't on the allow list.
I guess the attack surface is increased by a couple hundred lines of code due to new code paths for installing apps ... a couple hundred on top of millions.
You are a Simpleton.
Re: (Score:2)
No you.
Then Apple should do the reasonable thing (Score:3)
It sounds like Apple needs a method for the OWNER of the device to decide where apps can be loaded from. If the phone is employer issued, the employer gets to decide. If it's a personal phone, the owner gets to decide.
Note, if the individual owns the phone and the employer wants them to use it for work, that's fine, but the individual will be the decider about what gets loaded from where. If the employer doesn't like that, they can cough up the money to buy an employer issued work phone.
Re: (Score:1)
Re: (Score:2)
Yes, meaning all of this is just Apple trying to stir the pot and cast the EU's pro competitive stance in a bad light so consumers will shelter under Apple's protective wing.
Re: (Score:2)
Yes, meaning all of this is just Apple trying to stir the pot and cast the EU's pro competitive stance in a bad light so consumers will shelter under Apple's protective wing.,/quote>
How is this Apple "trying to stir the pot" when it is government agencies in the EU have concerns? And their concerns are valid. They would like the ability to block sideloading on their phones that does not require 3rd party software.
Re: (Score:2)
Apple is trying to stir the pot because it's their press release and they could easily answer the concerns the same way they do for their own App store by allowing employers that issue (and so actually own the phone) to set policy on apps.
Wheras "Sideloading" Means Installing (Score:2)
Re: (Score:2)
Re: (Score:2)
There is exactly zero chance that Apple doesn't provide an MDM configuration policy to allow / disallow sideloading, which the owner of the device (the government or company) would be allowed to legally control.
They're just trying to piss and moan about it, in the long hope that it will be reversed if they can just piss and moan about it enough.
Re: (Score:2)
There is exactly zero chance that Apple doesn't provide an MDM configuration policy to allow / disallow sideloading, which the owner of the device (the government or company) would be allowed to legally control.
And has Apple done that already in an OS patch that has yet to be released? Government agencies are pointing out that they need this feature. Seriously this should not be a controversial topic but many people here failed to read the article to know the entire topic is about enterprise owned equipment. All the reactions were immediately about how Apple was evil for blocking users from sideloading without reading the actual article was enterprises want to block their users from sideloading on devices that the
Well then (Score:3)
Yes MDM is the correct answer. (Score:3)
Complaining that your mom and pop store level of security is being further weakened is frankly funny.
Re: (Score:2)
If these government agencies are relying only on the App Store for the security of their devices they are not very competent. With a Mobile Device Management platform they can bar sideloading, enforce installation policies, password policies, deploy certificates, force updates, remote scan, remote wipe, and all sort of other useful things.
As stated in the article some of the agencies are independent and small. They do not have a IT department to handle such matters.
Riiiiight (Score:3)
The fact of the matter is that companies have been providing computing devices to their employees for decades, and those devices have been capable of sideloading software unless properly configured to prevent that activity. If anything, my biggest concern as an employer would be if Apple would apply malicious compliance by "forgetting" to add enterprise controls to disallow sideloading on devices deployed by governments and corporations. And that may very well be why these companies are expressing their concerns with Apple.
Can you be any more vague? Who? And why? (Score:2)
If you're a government worrying about your employees... block it! Use a management tool that I assume Apple certifies or sells. If they don't, they will soon.
If you worry about general people installing broken stuff, welcome to results of your own actions!
Apple claims... (Score:4)
Apple claims that a customer-friendly policy that they don't like is going to be massively problematic, even though Apple allows exactly the same customer-friendly policy on other products they ship without issue, and have for decades.
SHOCKING.
Pay unlock tax to be 100% owner of device :P (Score:1)
Re: (Score:2)
Jesus H. These people are really damn stupid. They bitch and moan that Apple and Google should allow sideloading (aka alternative app stores) and then wonder why mobile devices become a fertile ground for malware.
The reason is app stores act as lightning rods for bottom feeders due to low barrier to entry and global reach.
The only reason these platforms are able to persist is entirely due to underlying security model in which applications run in their own isolated jails /w inherently limited ability to fuck with each other. Where the app is downloaded from is an irrelevant sidecar.
Re: (Score:2)
Jesus H. These people are really damn stupid. They bitch and moan that Apple and Google should allow sideloading (aka alternative app stores) and then wonder why mobile devices become a fertile ground for malware.
The reason is app stores act as lightning rods for bottom feeders due to low barrier to entry and global reach.
The only reason these platforms are able to persist is entirely due to underlying security model in which applications run in their own isolated jails /w inherently limited ability to fuck with each other. Where the app is downloaded from is an irrelevant sidecar.
Except that it isn't.
One source, the App goes through Apple's Historically-almost-perfect App Approval System.
The Other, er, Doesn't.
Simple. As. That.
Re: (Score:2)
this may come as a surprise for you, but different people from within the same private or public organization may have different concerns, priorities, goals - sometimes even at odds with one another
there is no "these people"
Re: (Score:2)
Re: (Score:2)
The utter lack of significant Malware in iOS Apps, even several years after the Opening of the Apple iOS App Store, nicely lays-bare your pathetic attempts at propaganda, subterfuge and downright lying.
Give it up.
Re: (Score:2)
Jesus H. These people are really damn stupid. They bitch and moan that Apple and Google should allow sideloading (aka alternative app stores) and then wonder why mobile devices become a fertile ground for malware.
Exactly.
That's why Parent has been shamelessly Punish-Modded.