{"id":34114,"date":"2021-11-09T16:55:54","date_gmt":"2021-11-09T21:55:54","guid":{"rendered":"https:\/\/mjtsai.com\/blog\/?p=34114"},"modified":"2025-10-11T12:18:22","modified_gmt":"2025-10-11T16:18:22","slug":"federighi-and-cook-on-sideloading","status":"publish","type":"post","link":"https:\/\/mjtsai.com\/blog\/2021\/11\/09\/federighi-and-cook-on-sideloading\/","title":{"rendered":"Federighi and Cook on Sideloading"},"content":{"rendered":"<p><a href=\"https:\/\/9to5mac.com\/2021\/11\/03\/craig-federighi-keynote-side-loading-speech\/\">Chance Miller<\/a> (<a href=\"https:\/\/twitter.com\/9to5mac\/status\/1455944620987359233\">tweet<\/a>, <a href=\"https:\/\/www.youtube.com\/watch?v=iwstKnhWs6k&amp;t=27119s\">video<\/a>, <a href=\"https:\/\/apple.slashdot.org\/story\/21\/11\/04\/1646256\/apple-software-exec-warns-european-app-store-regulation-would-open-pandoras-box\">Slashdot<\/a>, <a href=\"https:\/\/www.macrumors.com\/2021\/11\/03\/craig-federighi-opposes-sideloading\/\">MacRumors<\/a>):<\/p>\n<blockquote cite=\"https:\/\/9to5mac.com\/2021\/11\/03\/craig-federighi-keynote-side-loading-speech\/\"><p>Last month, it <a href=\"https:\/\/9to5mac.com\/2021\/10\/26\/craig-federighi-to-attend-web-summit-2021-in-lisbon-next-month\/\">was announced<\/a> that Apple senior vice president Craig Federighi would attend and speak at Web Summit 2021, which takes place in Lisbon, Portugal. In a keynote delivered today, Federighi vehemently spoke out against legislation that could force Apple to open the iPhone up to sideloading&#8230;<\/p><p>The Digital Markets Act legislation <a href=\"https:\/\/9to5mac.com\/2020\/12\/15\/apple-eu-legislation-app-store-changes\/\">was first unveiled<\/a> last December in the EU, and it could lead to major changes for the App Store and pre-installed first-party applications on the iPhone. The DMA in Europe would force Apple to allow sideloading on the iPhone, among other changes. <\/p><p>[&#8230;]<\/p><p>The Apple executive also warned that the legislation comes as there have &ldquo;never been more cybercriminals&rdquo; determined to access the private information on your iPhone. &ldquo;Sideloading is a cybercriminal&rsquo;s best friend,&rdquo; Federighi said. &ldquo;And requiring that on iPhone would be a gold rush for the malware industry.&rdquo;<\/p><\/blockquote>\n\n<p><a href=\"https:\/\/twitter.com\/chronic\/status\/1455989520084525057\">Will Strafach<\/a>:<\/p>\n<blockquote cite=\"https:\/\/twitter.com\/chronic\/status\/1455989520084525057\">\n<p>reminder: this is not very accurate. Apple has already solved side-loading in a reasonably smart way with their SRDs.<\/p>\n<\/blockquote>\n\n<p><a href=\"https:\/\/twitter.com\/elkmovie\/status\/1455951763371139074\">Michael Love<\/a>:<\/p>\n<blockquote cite=\"https:\/\/twitter.com\/elkmovie\/status\/1455951763371139074\"><p>If your best response to &ldquo;let people who want to take the risk sideload&rdquo; is &ldquo;people might be tricked into sideloading&rdquo; when YOU WOULD BE THE ONES DESIGNING THE SIDELOADING UI, that&rsquo;s not a very good response. (also, again, sideloaded != insecure)<\/p>\n<p>People get tricked into subscriptions all the time and yet, despite proclaiming the superiority of App Review, Apple&rsquo;s attempts to stop that are half-hearted at best. But when it&rsquo;s a form of trickery that they don&rsquo;t get a 30% cut of, somehow then it&rsquo;s an unavoidable disaster.<\/p>\n<p>Also, if you&rsquo;re really worried about the malware industry you could, y&rsquo;know, increase + actually pay out security bounties and stop antagonizing security researchers.<\/p>\n<p>[&#8230;]<\/p>\n<p>Provisioning profiles are a <em>way<\/em> bigger security hole than sideloaded apps, and yet Apple accepts that those are necessary + allows them.<\/p>\n<p>You can install a sketchy file from a third party that allows them to more-or-less take total control of your phone, but you can&rsquo;t install a fully-sandboxed third party app unless it&rsquo;s from the App Store.<\/p><\/blockquote>\n\n<p><a href=\"https:\/\/twitter.com\/reckless\/status\/1456324726008262658\">Nilay Patel<\/a>:<\/p>\n<blockquote cite=\"https:\/\/twitter.com\/reckless\/status\/1456324726008262658\"><p>This is so weird and disingenuous. Are they going to lock down the Mac next?<\/p><\/blockquote>\n\n<p><a href=\"https:\/\/www.theverge.com\/2021\/11\/3\/22761724\/apple-craig-federighi-ios-sideloading-web-summit-2021-european-commission-digital-markets-act\">Chaim Gartenberg<\/a>:<\/p>\n<blockquote cite=\"https:\/\/www.theverge.com\/2021\/11\/3\/22761724\/apple-craig-federighi-ios-sideloading-web-summit-2021-european-commission-digital-markets-act\">\n<p>If Apple wanted, it could enable iOS sideloading in a similar manner and require something like the Gatekeeper system on macOS, which allows for Apple to check signed developer IDs to confirm the software is genuine. It&rsquo;s an argument that Judge Yvonne Gonzalez Rogers <a href=\"https:\/\/www.theverge.com\/2021\/9\/10\/22667256\/apple-vs-epic-trail-judge-craig-federighi-macos-security-arguments-iphone-ios-response\">noted as well during the Apple \/ Epic trial<\/a>, commenting that Federighi may be &ldquo;stretching the truth&rdquo; on Mac malware concerns and that Apple could likely make a similar system work on iOS.<\/p>\n<\/blockquote>\n\n<p><a href=\"https:\/\/bzamayo.com\/federighi-sideloading-presentation\">Benjamin Mayo<\/a>:<\/p>\n<blockquote cite=\"https:\/\/bzamayo.com\/federighi-sideloading-presentation\"><p>Apple doesn&rsquo;t trot out Federighi to a third-party conference with a highly-produced Keynote deck for the fun of it. They are clearly concerned that European lawmakers are actually going to do something they don&rsquo;t want; that is, pass laws requiring them to offer sideloading as an option.<\/p>\n<p>[&#8230;]<\/p>\n<p>Federighi posits that a social networking app may choose to &ldquo;avoid the pesky privacy protections of the App Store&rdquo; and only make their apps available via sideloading. Apple&rsquo;s customers would then have to leave the &lsquo;safe&rsquo; Apple software ecosystem, or lose touch with their family and friends. This is sort of true. But what is omitted is that an app choosing to leave the App Store is not primarily doing so to avoid Apple&rsquo;s privacy standards, but because it would then be able to avoid Apple&rsquo;s IAP rules.<\/p>\n<p>Apple benefits financially &mdash; measured in the billions of dollars per year &mdash; by keeping the App Store as a monopoly. However much it wants to tout the user privacy and safety benefits, Apple&rsquo;s position would be far stronger if cynics weren&rsquo;t able to point to the money being accrued by the App Store gravy train.<\/p><\/blockquote>\n\n<p><a href=\"https:\/\/www.macrumors.com\/2021\/11\/09\/tim-cook-users-sideloading-use-an-android\/\">Sam Fathi<\/a>:<\/p>\n<blockquote cite=\"https:\/\/www.macrumors.com\/2021\/11\/09\/tim-cook-users-sideloading-use-an-android\/\"><p>Apple CEO Tim Cook said today that customers who wish to sideload apps should consider purchasing an Android device as the experience offered by the  iPhone maximizes their security and privacy.<\/p><p>[&#8230;]<\/p><p>Cook drew the comparison of sideloading to a carmaker selling a car without airbags or seatbelt, saying it would be &ldquo;too risky.&rdquo;<\/p><p>[&#8230;]<\/p><p>The App Store&rsquo;s in-app purchase method, which developers are required to use for digital purchases made within apps, gives Apple a 15-30% commission on all purchases made. Cook noted today that Apple has only ever lowered the commission, never increasing it.<\/p><\/blockquote>\n<p>He&rsquo;s said this multiple times, and I still find it misleading because increasing the categories of purchases subject to the commission, which Apple has done several times, is like raising it from 0% to 30%.<\/p>\n\n<p><a href=\"https:\/\/twitter.com\/elkmovie\/status\/1458119964666302468\">Michael Love<\/a>:<\/p>\n<blockquote cite=\"https:\/\/twitter.com\/elkmovie\/status\/1458119964666302468\"><p>It&rsquo;s kind of a hopeful sign that the pressure regarding sideloading has gotten serious enough that Apple feels the need to keep trotting out various executives to make this same disingenuous point.<\/p><p>Also that it&rsquo;s gotten serious enough that Tim Cook is actually telling people who want sideloading to buy an Android phone when in the past the&rsquo;ve tiptoed around even using the word &ldquo;Android&rdquo; in product keynotes.<\/p><\/blockquote>\n\n<p>Previously:<\/p>\n<ul>\n<li><a href=\"https:\/\/mjtsai.com\/blog\/2021\/10\/15\/apples-threat-analysis-of-sideloading\/\">Apple&rsquo;s Threat Analysis of Sideloading<\/a><\/li>\n<li><a href=\"https:\/\/mjtsai.com\/blog\/2021\/06\/25\/apple-attacks-sideloading\/\">Apple Attacks Sideloading<\/a><\/li>\n<li><a href=\"https:\/\/mjtsai.com\/blog\/2021\/05\/20\/epic-v-apple-day-13\/\">Epic v. Apple, Day 13<\/a><\/li>\n<li><a href=\"https:\/\/mjtsai.com\/blog\/2021\/05\/10\/epic-v-apple-day-5\/\">Epic v. Apple, Day 5<\/a><\/li>\n<li><a href=\"https:\/\/mjtsai.com\/blog\/2021\/04\/05\/tim-cook-on-sideloading\/\">Tim Cook on Sideloading<\/a><\/li>\n<li><a href=\"https:\/\/mjtsai.com\/blog\/2020\/07\/22\/apple-security-research-device-program\/\">Apple Security Research Device Program<\/a><\/li>\n<\/ul>\n\n<p id=\"federighi-and-cook-on-sideloading-update-2021-11-12\">Update (2021-11-12): <a href=\"https:\/\/pxlnv.com\/blog\/federighi-cook-sideloading\/\">Nick Heer<\/a>:<\/p>\n<blockquote cite=\"https:\/\/pxlnv.com\/blog\/federighi-cook-sideloading\/\">\n<p>But those are not the arguments these Apple executives are making. They are claiming that people actively choose the iPhone over an Android phone <em>because<\/em> it is more locked down.<\/p>\n<p>[&#8230;]<\/p>\n<p>Apparently, <a href=\"https:\/\/gs.statcounter.com\/os-market-share\/mobile\/united-states-of-america\">over 40% of Americans<\/a> want the smartphone equivalent of a car without seatbelts or airbags. This is clearly absurd, and I have to wonder if Apple&rsquo;s arguments make sense.<\/p>\n<\/blockquote>\n\n<p>I don&rsquo;t like Apple&rsquo;s analogy because there&rsquo;s little potential benefit (lower price, extra space?) to having a car without seatbelts or airbags. So, not only do car safety features likely make much more of a difference than App Store safety features, but Apple is positing giving them up for nothing in return. In the real world, some customers and developers don&rsquo;t <em>want less safety<\/em>; they want to <em>trade potentially less safety<\/em> to get more\/better apps and businesses.<\/p>\n\n<p>Update (2021-11-15): <a href=\"https:\/\/twitter.com\/reckless\/status\/1458090893324525571\">Nilay Patel<\/a>:<\/p>\n<blockquote cite=\"https:\/\/twitter.com\/reckless\/status\/1458090893324525571\"><p>Tim Cook says [allowing] sideloading is like telling a carmaker to &ldquo;not to put airbags and seatbelts in a car.&rdquo;<\/p><p>Airbags and seatbelts in cars because of regulations that carmakers lobbied against, of course.<\/p><\/blockquote>\n\n<p id=\"federighi-and-cook-on-sideloading-update-2021-11-17\">Update (2021-11-17): <a href=\"https:\/\/daringfireball.net\/2021\/11\/federighi_sideloading_keynote_at_web_summit\">John Gruber<\/a> (<a href=\"https:\/\/twitter.com\/daringfireball\/status\/1460762361652858884\">tweet<\/a>):<\/p>\n<blockquote cite=\"https:\/\/daringfireball.net\/2021\/11\/federighi_sideloading_keynote_at_web_summit\">\n<p>If Apple stopped making it look like they&rsquo;re running the App Store primarily to maximize their own revenue from it, regulators and lawmakers might stop thinking that Apple is running the App Store primarily to maximize their own revenue from it.<\/p>\n<\/blockquote>\n\n<p id=\"federighi-and-cook-on-sideloading-update-2021-12-03\">Update (2021-12-03): <a href=\"http:\/\/morrick.me\/archives\/9456\">Riccardo Mori<\/a>:<\/p>\n<blockquote cite=\"http:\/\/morrick.me\/archives\/9456\">\n<p>I grew up in an era when software was just software, and you could simply start typing a BASIC program into the computer and execute it. Generally speaking, it was an era when tinkering &mdash; both in hardware and software terms &mdash; was unhampered and even encouraged. Philosophically, I can&rsquo;t be against sideloading. I actually dislike how the term&rsquo;s connotation has been hijacked towards negativity. On the contrary, one should think of it in terms of freedom to install any compatible software available for a certain platform.<\/p>\n<p>But what about malware? Yes, in a completely open scenario, malware can indeed be a risk. But the problem, in my opinion, lies elsewhere. It lies in the tradition of treating end users like ignorant idiots instead of training them to separate the wheat from the chaff.<\/p>\n<p>[&#8230;]<\/p>\n<p>Instead of teaching users how to fish, Apple decided to position themselves as sole purveyors of the best selection of fish.<\/p>\n<p>[&#8230;]<\/p>\n<p>The problem of appointing yourself as the sole guardian and gatekeeper of the software that should or should not reach your users is that you&rsquo;re expected to be infallible, and rightly so. Especially if you are a tech giant which supposedly has enough money and resources to do such a splendid job that is virtually indistinguishable from infallibility. Instead we know well just how many untrustworthy and scammy apps have been and are plaguing the App Store, and how inconsistent and unpredictable the App Review process generally is.<\/p>\n<\/blockquote>","protected":false},"excerpt":{"rendered":"<p>Chance Miller (tweet, video, Slashdot, MacRumors): Last month, it was announced that Apple senior vice president Craig Federighi would attend and speak at Web Summit 2021, which takes place in Lisbon, Portugal. In a keynote delivered today, Federighi vehemently spoke out against legislation that could force Apple to open the iPhone up to sideloading&#8230;The Digital [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"apple_news_api_created_at":"2021-11-09T21:55:57Z","apple_news_api_id":"dd090769-d77a-45cf-b596-c779eeb66b35","apple_news_api_modified_at":"2025-10-11T16:18:24Z","apple_news_api_revision":"AAAAAAAAAAAAAAAAAAAABQ==","apple_news_api_share_url":"https:\/\/apple.news\/A3QkHadd6Rc-1lsd57rZrNQ","apple_news_coverimage":0,"apple_news_coverimage_caption":"","apple_news_is_hidden":false,"apple_news_is_paid":false,"apple_news_is_preview":false,"apple_news_is_sponsored":false,"apple_news_maturity_rating":"","apple_news_metadata":"\"\"","apple_news_pullquote":"","apple_news_pullquote_position":"","apple_news_slug":"","apple_news_sections":"\"\"","apple_news_suppress_video_url":false,"apple_news_use_image_component":false,"footnotes":""},"categories":[2],"tags":[2085,91,629,522,31,2078,2848,2132,60],"class_list":["post-34114","post","type-post","status-publish","format-standard","hentry","category-technology","tag-antitrust","tag-appstore","tag-craig-federighi","tag-inapppurchase","tag-ios","tag-ios-15","tag-provisioning-profiles","tag-sideloading","tag-timcook"],"apple_news_notices":[],"_links":{"self":[{"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/posts\/34114","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/comments?post=34114"}],"version-history":[{"count":6,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/posts\/34114\/revisions"}],"predecessor-version":[{"id":34357,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/posts\/34114\/revisions\/34357"}],"wp:attachment":[{"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/media?parent=34114"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/categories?post=34114"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/tags?post=34114"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}