{"id":29305,"date":"2020-06-22T11:08:32","date_gmt":"2020-06-22T15:08:32","guid":{"rendered":"https:\/\/mjtsai.com\/blog\/?p=29305"},"modified":"2021-10-15T15:14:58","modified_gmt":"2021-10-15T19:14:58","slug":"the-app-store-doesnt-make-apps-safe","status":"publish","type":"post","link":"https:\/\/mjtsai.com\/blog\/2020\/06\/22\/the-app-store-doesnt-make-apps-safe\/","title":{"rendered":"The App Store Doesn&rsquo;t Make Apps Safe"},"content":{"rendered":"<p><a href=\"https:\/\/inessential.com\/2020\/06\/21\/the_app_store_doesnt_make_apps_safe\">Brent Simmons<\/a> (<a href=\"https:\/\/twitter.com\/brentsimmons\/status\/1274791423884345350\">tweet<\/a>):<\/p>\n<blockquote cite=\"https:\/\/inessential.com\/2020\/06\/21\/the_app_store_doesnt_make_apps_safe\">\n<p>Otherwise, App Store review is looking for basic functionality and making sure the app follows the guidelines [&#8230;] the guidelines are about protecting Apple&rsquo;s interests and not about consumers.<\/p>\n<p>[&#8230;]<\/p>\n<p>I&rsquo;d feel secure knowing that the apps, just by virtue of being iOS apps, are sandboxed and have to ask for permissions. (I&rsquo;m also imagining a Mac-like notarization step, for additional security. I think this is reasonable.)<\/p>\n<p>In other words: Apple has done a very good job with iOS app security and safety. The fact that we think this has something to do with the App Store is a trick, though.<\/p>\n<\/blockquote>\n\n<p>As discussed in the <a href=\"https:\/\/mjtsai.com\/blog\/2020\/06\/19\/highway-robbery\/#comment-3249694\">comments<\/a> <a href=\"https:\/\/mjtsai.com\/blog\/2020\/06\/19\/it-doesnt-work\/#comment-3249697\">here<\/a> yesterday.<\/p>\n\n<p><a href=\"https:\/\/twitter.com\/DazeEnd\/status\/1274811929354276865\">Charles Perry<\/a>:<\/p>\n<blockquote cite=\"https:\/\/twitter.com\/DazeEnd\/status\/1274811929354276865\">\n<p>@brentsimmons\n is right. Technical restrictions built into the OS (like sandboxing, asking user permission before accessing Contacts, etc.) are what makes iOS secure, not App Review.<\/p>\n<\/blockquote>\n\n<p><a href=\"https:\/\/twitter.com\/rileytestut\/status\/1274827249460473859\">Riley Testut<\/a>:<\/p>\n<blockquote cite=\"https:\/\/twitter.com\/rileytestut\/status\/1274827249460473859\">\n<p>This is important! Apps downloaded outside the iOS App Store would be <em>far<\/em> more safe than ones downloaded outside the Mac App Store. Regular iOS protections such as sandboxing apply to sideloaded apps like \n@altstoreio\n and Delta &mdash; the <em>only<\/em> difference is Apple doesn&rsquo;t like them<\/p>\n<\/blockquote>\n\n<p><a href=\"https:\/\/twitter.com\/rustyshelf\/status\/1274845347966103553\">Russell Ivanovic<\/a>:<\/p>\n<blockquote cite=\"https:\/\/twitter.com\/rustyshelf\/status\/1274845347966103553\">\n<p>This whole notion that it&rsquo;s Apple&rsquo;s App Store or user privacy hell is pure nonsense. It&rsquo;s not one or the other. In fact most apps on the current App Store suck up all the data they can already. That&rsquo;s a toolkit issue not a store issue.<\/p>\n<\/blockquote>\n\n<p><a href=\"https:\/\/twitter.com\/danheld\/status\/1274794070678794240\">Dan Held<\/a>:<\/p>\n<blockquote cite=\"https:\/\/twitter.com\/danheld\/status\/1274794070678794240\">\n<p>I built out and headed up App Store optimization for all of Uber&rsquo;s mobile products from 2016-2017.<\/p>\n<p>The &ldquo;review process&rdquo; allowed hundreds of fake Uber apps to be approved. The problem got so bad we had to use a 3rd party software to issue takedown requests in mass.<\/p>\n<p>If they can&rsquo;t screen at that surface level then I&rsquo;m not sure what they&rsquo;re doing with each indie dev.<\/p>\n<\/blockquote>\n\n<p>I don&rsquo;t think this is what people expected to happen, but, even without fakes, the App Store does sometimes make it <a href=\"https:\/\/sixcolors.com\/link\/2020\/06\/the-essential-nature-of-the-app-store\/\">harder<\/a> to find the official app. First, <a href=\"https:\/\/mjtsai.com\/blog\/2020\/06\/12\/how-to-improve-the-app-store\/\">search<\/a> <a href=\"https:\/\/mjtsai.com\/blog\/2019\/09\/05\/search-ads-for-competing-products\/\">ads<\/a> deliberately make it not the top hit. Second, the organic result for typing the exact name often isn&rsquo;t right. Outside the store, you&rsquo;re always going to get the right app if you start at uber.com. And a Google search is unlikely to give you the wrong result because the fake app won&rsquo;t out-PageRank Uber.<\/p>\n\n<p>Previously:<\/p>\n<ul>\n<li><a href=\"https:\/\/mjtsai.com\/blog\/2020\/06\/19\/it-doesnt-work\/\">It Doesn&rsquo;t Work<\/a><\/li>\n<li><a href=\"https:\/\/mjtsai.com\/blog\/2020\/06\/19\/highway-robbery\/\">Highway Robbery<\/a><\/li>\n<li><a href=\"https:\/\/mjtsai.com\/blog\/2020\/06\/16\/hey-rejected-from-the-app-store\/\">HEY Rejected From the App Store<\/a><\/li>\n<\/ul>","protected":false},"excerpt":{"rendered":"<p>Brent Simmons (tweet): Otherwise, App Store review is looking for basic functionality and making sure the app follows the guidelines [&#8230;] the guidelines are about protecting Apple&rsquo;s interests and not about consumers. [&#8230;] I&rsquo;d feel secure knowing that the apps, just by virtue of being iOS apps, are sandboxed and have to ask for permissions. [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"apple_news_api_created_at":"2020-06-22T15:08:35Z","apple_news_api_id":"2352ed20-26a9-40b9-9445-3138681f2319","apple_news_api_modified_at":"2021-10-15T19:15:01Z","apple_news_api_revision":"AAAAAAAAAAAAAAAAAAAAAQ==","apple_news_api_share_url":"https:\/\/apple.news\/AI1LtICapQLmURTE4aB8jGQ","apple_news_coverimage":0,"apple_news_coverimage_caption":"","apple_news_is_hidden":false,"apple_news_is_paid":false,"apple_news_is_preview":false,"apple_news_is_sponsored":false,"apple_news_maturity_rating":"","apple_news_metadata":"\"\"","apple_news_pullquote":"","apple_news_pullquote_position":"","apple_news_slug":"","apple_news_sections":"\"\"","apple_news_suppress_video_url":false,"apple_news_use_image_component":false,"footnotes":""},"categories":[2],"tags":[91,31,1667,355,343,48,2132,1441],"class_list":["post-29305","post","type-post","status-publish","format-standard","hentry","category-technology","tag-appstore","tag-ios","tag-ios-13","tag-privacy","tag-search","tag-security","tag-sideloading","tag-uber"],"apple_news_notices":[],"_links":{"self":[{"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/posts\/29305","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/comments?post=29305"}],"version-history":[{"count":2,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/posts\/29305\/revisions"}],"predecessor-version":[{"id":29329,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/posts\/29305\/revisions\/29329"}],"wp:attachment":[{"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/media?parent=29305"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/categories?post=29305"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/tags?post=29305"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}