{"id":32544,"date":"2021-05-20T12:01:51","date_gmt":"2021-05-20T16:01:51","guid":{"rendered":"https:\/\/mjtsai.com\/blog\/?p=32544"},"modified":"2021-11-09T15:56:08","modified_gmt":"2021-11-09T20:56:08","slug":"epic-v-apple-day-13","status":"publish","type":"post","link":"https:\/\/mjtsai.com\/blog\/2021\/05\/20\/epic-v-apple-day-13\/","title":{"rendered":"Epic v. Apple, Day 13"},"content":{"rendered":"<p><a href=\"https:\/\/www.protocol.com\/apple-epic-trial\/apples-craig-federighi-admits-macos-malware-level-is-not-acceptable\">Nick Statt<\/a> (<a href=\"https:\/\/twitter.com\/nickstatt\/status\/1395032968830259200\">tweet<\/a>):<\/p>\n<blockquote cite=\"https:\/\/www.protocol.com\/apple-epic-trial\/apples-craig-federighi-admits-macos-malware-level-is-not-acceptable\"><p>Epic and its lawyers have throughout the trial pointed to the freedom consumers have on macOS to download applications outside the Mac App Store and to largely do what they please on the macOS operating system. Epic has held up the openness of the Mac as an example of what the iPhone, as a general computing device in Epic&rsquo;s eyes, should be transitioned into if it were to win its case.<\/p><p>But Federighi on Wednesday argued against this proposition by saying it would destroy the level of security enjoyed by iOS users, in effect tarnishing the Mac in order to save the iPhone. &ldquo;It would become commonplace for users to be directed to download misrepresented software from untrusted sources where they&rsquo;d be subject to malware,&rdquo; Federighi argued, referring to the notion of alternative app stores as a &ldquo;pretty devastating setback for iOS security.&rdquo;<\/p><\/blockquote>\n\n<p><a href=\"https:\/\/www.theverge.com\/2021\/5\/20\/22444471\/epic-apple-fortnite-antitrust-trial-craig-federighi-ios-security\">Adi Robertson<\/a> (<a href=\"https:\/\/twitter.com\/thedextriarchy\/status\/1395029579484606464\">tweet<\/a>):<\/p>\n<blockquote cite=\"https:\/\/www.theverge.com\/2021\/5\/20\/22444471\/epic-apple-fortnite-antitrust-trial-craig-federighi-ios-security\"><p>Federighi basically says iOS users need to be more protected because the Mac is a specialist tool for people who know how to navigate the complexities of a powerful system, while the iPhone and iPad are &mdash; literally &mdash; for babies.<\/p>\n<p>[&#8230;]<\/p>\n<p>Federighi took a far broader view of security than Epic&rsquo;s own expert witness James Mickens. Mickens testified earlier that iOS wasn&rsquo;t meaningfully more secure than Android, but he analyzed mostly technical threats to the platforms. Federighi focused on scams, phishing, and other apps that target human psychology instead of computer code &mdash; many of which pose serious dangers.<\/p>\n<p>Sometimes, though, the protectiveness felt patronizing. When Federighi explained Apple&rsquo;s restrictions on cloud gaming, he focused partly on tangible security issues, like how to grant device permissions for different titles on a single gaming app. But he slipped seamlessly into discussing how the concept would be simply too confusing &mdash; that iPhone and iPad owners would be befuddled by the notion of launching a separate game catalog. Apple wants iOS devices to feel trustworthy, but at times like that, it seems more like Apple just doesn&rsquo;t trust its own users.<\/p><\/blockquote>\n\n<p><a href=\"https:\/\/www.theverge.com\/2021\/5\/19\/22444353\/mac-malware-not-acceptable-craig-federighi-apple-epic\">Chris Welch<\/a> (<a href=\"https:\/\/news.ycombinator.com\/item?id=27221083\">Hacker News<\/a>):<\/p>\n<blockquote cite=\"https:\/\/www.theverge.com\/2021\/5\/19\/22444353\/mac-malware-not-acceptable-craig-federighi-apple-epic\">\n<p>Federighi&rsquo;s mission was pretty clear from the outset: to extol the security benefits that come with iOS&rsquo;s walled-off ecosystem and warn of the dangers that would come with breaking the App Store model.<\/p>\n<p>But in building that argument, Federighi also made some surprisingly blunt concessions about security on macOS.<\/p>\n<p>&ldquo;If you took Mac security techniques and applied them to the iOS ecosystem, with all those devices, all that value, it would get run over to a degree dramatically worse than is already happening on the Mac,&rdquo; Federighi said in the testimony. &ldquo;And as I say, today, we have a level of malware on the Mac that we don&rsquo;t find acceptable and is much worse than iOS.&rdquo;<\/p>\n<p>[&#8230;]<\/p>\n<p>Federighi also cast the difference between the two platforms in unusual terms, describing the desktop platform as something akin to a car. &ldquo;If operated correctly, much like that car, if you know how to operate a car and obey the rules of the road and are very cautious, yes,&rdquo; he said when asked directly whether macOS is safe. &ldquo;If not, I&rsquo;ve had a couple of family members who have gotten some malware on their Macs.&rdquo;<\/p>\n<\/blockquote>\n\n<p>What happened to iOS devices being cars and Macs being <a href=\"https:\/\/mjtsai.com\/blog\/2013\/09\/26\/post-pc-cars-trucks-and-motorcycles\/\">trucks<\/a>?<\/p>\n\n<p><a href=\"https:\/\/www.imore.com\/craig-federighi-defends-iphone-security-throwing-mac-under-bus\">Joe Wituschek<\/a>:<\/p>\n<blockquote cite=\"https:\/\/www.imore.com\/craig-federighi-defends-iphone-security-throwing-mac-under-bus\"><p>It&rsquo;s kind of insane to know that Apple&rsquo;s strategy to protect the App Store on the iPhone requires it to throw the Mac under the bus. Federighi&rsquo;s reasoning is that the iPhone, being that it contains more private information and is carried around with you, requires a higher bar of security.<\/p><\/blockquote>\n\n<p><a href=\"https:\/\/twitter.com\/keleftheriou\/status\/1395091827728871426\">Kosta Eleftheriou<\/a>:<\/p>\n<blockquote cite=\"https:\/\/twitter.com\/keleftheriou\/status\/1395091827728871426\"><p>There it is. If Apple has their way, we might even have to say goodbye to macOS &ldquo;sideloading&rdquo;.<\/p>\n<p>A true dystopian future of centralized software distribution, in which Apple only sees upside, no downside.<\/p><\/blockquote>\n\n<p><a href=\"https:\/\/twitter.com\/tolmasky\/status\/1395111223839109133\">Francisco Tolmasky<\/a>:<\/p>\n<blockquote cite=\"https:\/\/twitter.com\/tolmasky\/status\/1395111223839109133\"><p>And of course it goes without saying that they&rsquo;re playing word games here, where an app that just tricks you into paying monthly isn&rsquo;t classified as &ldquo;malware&rdquo; in the traditional sense, but I assure you, users don&rsquo;t care about technicalities when they are scammed.<\/p><\/blockquote>\n\n<p><a href=\"https:\/\/twitter.com\/logancollins\/status\/1395110456864301058\">Logan Collins<\/a>:<\/p>\n<blockquote cite=\"https:\/\/twitter.com\/logancollins\/status\/1395110456864301058\"><p>It&rsquo;s hard not to read into this as Federighi saying &ldquo;we see the Mac as a malware-ridden mess and will change that by locking out everyone who doesn&rsquo;t agree with us.&rdquo;<\/p><\/blockquote>\n\n<p><a href=\"https:\/\/twitter.com\/ihackbanme\/status\/1395137699519082505\">Zuk<\/a>:<\/p>\n<blockquote cite=\"https:\/\/twitter.com\/ihackbanme\/status\/1395137699519082505\"><p>For those that think that iOS is safe because of the &ldquo;walled garden&rdquo; take a look at the leaked Pegasus\/NSO documents here. NSO couldn&rsquo;t care less about the &ldquo;walled garden&rdquo; because they infect devices without it: silently (0-click) or click on a link (aka 1-click).<\/p><\/blockquote>\n\n<p><a href=\"https:\/\/www.theverge.com\/2021\/5\/19\/22443616\/apple-requests-court-dismiss-epic-essential-facilities-claim-fortnite-trial\">Russell Brandom and Adi Robertson<\/a> (<a href=\"https:\/\/www.macrumors.com\/2021\/05\/19\/apple-early-motion-epic-games-app-store-access\/\">MacRumors<\/a>):<\/p>\n<blockquote cite=\"https:\/\/www.theverge.com\/2021\/5\/19\/22443616\/apple-requests-court-dismiss-epic-essential-facilities-claim-fortnite-trial\">\n<p><a href=\"https:\/\/www.documentcloud.org\/documents\/20761616-apple-motion-to-dismiss-essential-facility-claim\">In a filing Tuesday night<\/a>, Apple asked the court to dismiss one of the 10 counts alleged in the initial complaint, arguing Epic had failed to establish any evidence for the charge that Apple had violated the essential facilities doctrine by failing to provide access to software distribution tools on iOS.<\/p>\n<\/blockquote>\n\n<p><a href=\"https:\/\/twitter.com\/iansherr\/status\/1395044990271692801\">Ian Sherr<\/a>:<\/p>\n<blockquote cite=\"https:\/\/twitter.com\/iansherr\/status\/1395044990271692801\"><p>Schmid said there were &ldquo;over 80 times&rdquo; Epic asked for expedited review for Fortnite, and it was reviewed over 200 times. There were times that App Review apparently pushed back on Schmid&rsquo;s team, asking if these expedited reviews were necessary<\/p><\/blockquote>\n\n<p><a href=\"https:\/\/twitter.com\/tapbot_paul\/status\/1395145580830154755\">Paul Haddad<\/a>:<\/p>\n<blockquote cite=\"https:\/\/twitter.com\/tapbot_paul\/status\/1395145580830154755\">\n<p>&ldquo;We treat all developers the same.&rdquo;<\/p>\n<p>Pretty sure I&rsquo;ve gotten told no on my second expedited request within a year.<\/p>\n<\/blockquote>\n\n<p>See also: <a href=\"https:\/\/twitter.com\/leah_nylen\/status\/1395018673073623040\">Leah Nylen<\/a>.<\/p>\n\n<p>Previously:<\/p>\n<ul>\n<li><a href=\"https:\/\/mjtsai.com\/blog\/2021\/05\/19\/epic-v-apple-day-12\/\">Epic v. Apple, Day 12<\/a><\/li>\n<li><a href=\"https:\/\/mjtsai.com\/blog\/2021\/04\/22\/the-app-store-isnt-catching-the-most-egregious-scams\/\">The App Store Isn&rsquo;t Catching the Most Egregious Scams<\/a><\/li>\n<li><a href=\"https:\/\/mjtsai.com\/blog\/2021\/04\/05\/tim-cook-on-sideloading\/\">Tim Cook on Sideloading<\/a><\/li>\n<\/ul>\n\n<p id=\"epic-v-apple-day-13-update-2021-05-24\">Update (2021-05-24): <a href=\"https:\/\/twitter.com\/lapcatsoftware\/status\/1395456484612399106\">Jeff Johnson<\/a> (see his screenshots of the Mac App Store):<\/p>\n<blockquote cite=\"https:\/\/twitter.com\/lapcatsoftware\/status\/1395456484612399106\">\n<p>I agree that the level of Mac malware is unacceptable.<\/p>\n<\/blockquote>","protected":false},"excerpt":{"rendered":"<p>Nick Statt (tweet): Epic and its lawyers have throughout the trial pointed to the freedom consumers have on macOS to download applications outside the Mac App Store and to largely do what they please on the macOS operating system. Epic has held up the openness of the Mac as an example of what the iPhone, [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"apple_news_api_created_at":"2021-05-20T16:01:56Z","apple_news_api_id":"6b0466ba-60f6-41b9-aebb-169ad75ae430","apple_news_api_modified_at":"2021-11-09T20:56:12Z","apple_news_api_revision":"AAAAAAAAAAAAAAAAAAAABA==","apple_news_api_share_url":"https:\/\/apple.news\/AawRmumD2Qbmuuxaa11rkMA","apple_news_coverimage":0,"apple_news_coverimage_caption":"","apple_news_is_hidden":false,"apple_news_is_paid":false,"apple_news_is_preview":false,"apple_news_is_sponsored":false,"apple_news_maturity_rating":"","apple_news_metadata":"\"\"","apple_news_pullquote":"","apple_news_pullquote_position":"","apple_news_slug":"","apple_news_sections":"\"\"","apple_news_suppress_video_url":false,"apple_news_use_image_component":false,"footnotes":""},"categories":[2],"tags":[2085,1846,91,2036,38,629,1969,1768,31,1837,26,41,209,30,1891,504,2132],"class_list":["post-32544","post","type-post","status-publish","format-standard","hentry","category-technology","tag-antitrust","tag-app-review","tag-appstore","tag-app-store-scams","tag-apple","tag-craig-federighi","tag-epic","tag-fortnite","tag-ios","tag-ios-14","tag-iosapp","tag-lawsuit","tag-legal","tag-mac","tag-macos-11-0","tag-malware","tag-sideloading"],"apple_news_notices":[],"_links":{"self":[{"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/posts\/32544","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/comments?post=32544"}],"version-history":[{"count":5,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/posts\/32544\/revisions"}],"predecessor-version":[{"id":32580,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/posts\/32544\/revisions\/32580"}],"wp:attachment":[{"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/media?parent=32544"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/categories?post=32544"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/tags?post=32544"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}