{"id":33915,"date":"2021-10-15T15:39:50","date_gmt":"2021-10-15T19:39:50","guid":{"rendered":"https:\/\/mjtsai.com\/blog\/?p=33915"},"modified":"2021-10-15T15:39:50","modified_gmt":"2021-10-15T19:39:50","slug":"apples-threat-analysis-of-sideloading","status":"publish","type":"post","link":"https:\/\/mjtsai.com\/blog\/2021\/10\/15\/apples-threat-analysis-of-sideloading\/","title":{"rendered":"Apple&rsquo;s Threat Analysis of Sideloading"},"content":{"rendered":"<p><a href=\"https:\/\/www.apple.com\/privacy\/docs\/Building_a_Trusted_Ecosystem_for_Millions_of_Apps_A_Threat_Analysis_of_Sideloading.pdf\">Apple<\/a> (PDF, via <a href=\"https:\/\/news.ycombinator.com\/item?id=28851533\">Hacker News<\/a>, <a href=\"https:\/\/www.macrumors.com\/2021\/10\/13\/apple-says-sideloading-makes-android-less-safe\/\">MacRumors<\/a>, <a href=\"https:\/\/apple.slashdot.org\/story\/21\/10\/13\/2219203\/apple-argues-against-allowing-app-sideloading-by-pointing-out-androids-malware-figures\">Slashdot<\/a>):<\/p>\n<blockquote cite=\"https:\/\/www.apple.com\/privacy\/docs\/Building_a_Trusted_Ecosystem_for_Millions_of_Apps_A_Threat_Analysis_of_Sideloading.pdf\"><p>iPhone is a highly personal device where users store some of their most sensitive and personal information. This means that maintaining security and privacy on the iOS ecosystem is of critical importance to users. However, some are demanding that Apple support the distribution of apps outside of the App Store, through direct downloads or third-party app stores, a process also referred to as &ldquo;sideloading.&rdquo; Supporting sideloading through direct downloads and third-party app stores would cripple the privacy and security protections that have made iPhone so secure, and expose users to serious security risks.<\/p><\/blockquote>\n\n<p><a href=\"https:\/\/twitter.com\/s1guza\/status\/1448367120585269249\">Siguza<\/a>:<\/p>\n<blockquote cite=\"https:\/\/twitter.com\/s1guza\/status\/1448367120585269249\">\n<p>31 pages of fearmongering?<\/p>\n<p>Damn, Apple must <em>actually<\/em> be scared!<\/p>\n<\/blockquote>\n\n<p><a href=\"https:\/\/twitter.com\/TimSweeneyEpic\/status\/1448619938906886148\">Tim Sweeney<\/a>:<\/p>\n<blockquote cite=\"https:\/\/twitter.com\/TimSweeneyEpic\/status\/1448619938906886148\"><p>If automated software analysis or human review were essential for security, iOS could support or even require it for competing stores. Mac notarization shows it&rsquo;s feasible. Nothing about security requires an Apple monopoly on distribution.<\/p>\n<p>Furthermore, competing stores could do a much better job than Apple of ensuring quality software, going above and beyond Apple&rsquo;s modest standards for human review - typically a 6 to 12 minute process staffed by only several hundred employees worldwide, most of them not engineers.<\/p>\n<p>Look at the amazing job that Sony, Microsoft, and Nintendo do of quality assurance on console. It&rsquo;s so good that a sub-par game release is almost a once-in-a-decade news story. If Apple faced competing stores, those companies plus Valve, Epic, and others could step up.<\/p><\/blockquote>\n\n<p><a href=\"https:\/\/twitter.com\/elkmovie\/status\/1448654606628651010\">Michael Love<\/a>:<\/p>\n<blockquote cite=\"https:\/\/twitter.com\/elkmovie\/status\/1448654606628651010\">\n<p>I don&rsquo;t think alternate stores make any sense without sideloading; if it&rsquo;s important sideloaded apps by reviewed by sb you can have a bunch of 3rd party Notarization Authorities or whatever, but the binary should be coming from my server.<\/p>\n<p>Alternate app stores add competition - which is certainly good - but don&rsquo;t fundamentally change the app distribution model; direct sideloading does because it lets installation happen at the point of discovery, and discovery can happen anywhere; can install an app from a tweet.<\/p>\n<\/blockquote>\n\n<p><a href=\"https:\/\/appleinsider.com\/articles\/21\/10\/14\/thieves-abused-apples-enterprise-app-programs-to-steal-14-million-in-crypto\">Mike Wuerthele<\/a>:<\/p>\n<blockquote cite=\"https:\/\/appleinsider.com\/articles\/21\/10\/14\/thieves-abused-apples-enterprise-app-programs-to-steal-14-million-in-crypto\">\n<p>Thieves have used a combination of social media, dating apps, cryptocurrency, and abuse of Apple's Enterprise Developer program to steal at least $1.4 million from unsuspecting victims.<\/p>\n<p>[&#8230;]<\/p>\n<p>After gaining the trust of the victim through the dating apps, scammers start discussing cryptocurrency investments. They are then directed to a website that looks like the Apple App Store, and then told to download a Mobile Device Management profile, giving control of a number of features, and the ability to use signed apps made by the fraudsters.<\/p>\n<\/blockquote>\n\n<p>Previously:<\/p>\n<ul>\n<li><a href=\"https:\/\/mjtsai.com\/blog\/2021\/06\/25\/apple-attacks-sideloading\/\">Apple Attacks Sideloading<\/a><\/li>\n<li><a href=\"https:\/\/mjtsai.com\/blog\/2021\/04\/05\/tim-cook-on-sideloading\/\">Tim Cook on Sideloading<\/a><\/li>\n<\/ul>","protected":false},"excerpt":{"rendered":"<p>Apple (PDF, via Hacker News, MacRumors, Slashdot): iPhone is a highly personal device where users store some of their most sensitive and personal information. This means that maintaining security and privacy on the iOS ecosystem is of critical importance to users. However, some are demanding that Apple support the distribution of apps outside of the [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"apple_news_api_created_at":"2021-10-15T19:39:53Z","apple_news_api_id":"c44ef1b7-8783-499d-a86d-22ce9df5ccc8","apple_news_api_modified_at":"2021-10-15T19:39:53Z","apple_news_api_revision":"AAAAAAAAAAD\/\/\/\/\/\/\/\/\/\/w==","apple_news_api_share_url":"https:\/\/apple.news\/AxE7xt4eDSZ2obSLOnfXMyA","apple_news_coverimage":0,"apple_news_coverimage_caption":"","apple_news_is_hidden":false,"apple_news_is_paid":false,"apple_news_is_preview":false,"apple_news_is_sponsored":false,"apple_news_maturity_rating":"","apple_news_metadata":"\"\"","apple_news_pullquote":"","apple_news_pullquote_position":"","apple_news_slug":"","apple_news_sections":"\"\"","apple_news_suppress_video_url":false,"apple_news_use_image_component":false,"footnotes":""},"categories":[2],"tags":[91,31,2078,504,1746,355,48,2132],"class_list":["post-33915","post","type-post","status-publish","format-standard","hentry","category-technology","tag-appstore","tag-ios","tag-ios-15","tag-malware","tag-mobile-device-management-mdm","tag-privacy","tag-security","tag-sideloading"],"apple_news_notices":[],"_links":{"self":[{"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/posts\/33915","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/comments?post=33915"}],"version-history":[{"count":1,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/posts\/33915\/revisions"}],"predecessor-version":[{"id":33916,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/posts\/33915\/revisions\/33916"}],"wp:attachment":[{"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/media?parent=33915"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/categories?post=33915"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/tags?post=33915"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}