{"id":35548,"date":"2022-04-12T16:08:43","date_gmt":"2022-04-12T20:08:43","guid":{"rendered":"https:\/\/mjtsai.com\/blog\/?p=35548"},"modified":"2022-04-13T19:43:47","modified_gmt":"2022-04-13T23:43:47","slug":"tim-cook-attacks-sideloading-in-privacy-keynote","status":"publish","type":"post","link":"https:\/\/mjtsai.com\/blog\/2022\/04\/12\/tim-cook-attacks-sideloading-in-privacy-keynote\/","title":{"rendered":"Tim Cook Attacks Sideloading in Privacy Keynote"},"content":{"rendered":"<p><a href=\"https:\/\/www.macrumors.com\/2022\/04\/12\/tim-cook-global-privacy-summit\/\">Joe Rossignol<\/a>:<\/p>\n<blockquote cite=\"https:\/\/www.macrumors.com\/2022\/04\/12\/tim-cook-global-privacy-summit\/\"><p>Apple CEO Tim Cook today delivered the keynote speech at the Global Privacy Summit in Washington D.C. The conference, hosted by the International Association of Privacy Professionals, is focused on international privacy and data protection.<\/p><p>[&#8230;]<\/p><p>&ldquo;Here in Washington and elsewhere, policymakers are taking steps in the name of competition that would force Apple to let apps onto iPhone that circumvent the App Store through a process called sideloading,&rdquo; said Cook. &ldquo;That means data-hungry companies would be able to avoid our privacy rules and once again track our users against their will. It would also potentially give bad actors a way around the comprehensive security protections we have put in place, putting them in direct contact with our users.&rdquo;<\/p><p>[&#8230;]<\/p><p>&ldquo;If we are forced to let unvetted apps onto iPhone, the unintended consequences will be profound,&rdquo; warned Cook. &ldquo;And when we see that, we feel an obligation to speak up and to ask policymakers to work with us to advance goals that I truly believe we share, without undermining privacy in the process.&rdquo;<\/p><\/blockquote>\n\n<p><a href=\"https:\/\/tidbits.com\/2022\/04\/08\/apples-app-store-stubbornness-may-be-ioss-greatest-security-vulnerability\/\">Rich Mogull<\/a>:<\/p>\n<blockquote cite=\"https:\/\/tidbits.com\/2022\/04\/08\/apples-app-store-stubbornness-may-be-ioss-greatest-security-vulnerability\/\"><p>Apple largely has itself to blame. Apple didn&rsquo;t create a walled garden marketplace merely to ensure consumer safety; it also did so to own the billing model and financial transactions, and thus the customer relationship. Until a week ago, a developer wasn&rsquo;t even allowed to link to or mention their website for prospects to sign up for subscriptions. For over 13 years, Apple refused to budge to pressure from developers, forcing them to turn to the courts and legislatures.<\/p>\n<p>Let&rsquo;s distill this down to understand why the App Store is so important for security, how opening iOS up to alternative app stores or sideloading will reduce our safety, and why this now seems inevitable.<\/p><\/blockquote>\n\n<p><a href=\"https:\/\/talk.tidbits.com\/t\/apple-s-app-store-stubbornness-may-be-ios-s-greatest-security-vulnerability\/18693\/7\">Peter N. Lewis<\/a>:<\/p>\n<blockquote cite=\"https:\/\/talk.tidbits.com\/t\/apple-s-app-store-stubbornness-may-be-ios-s-greatest-security-vulnerability\/18693\/7\">\n<p>Of the entire chain of security listed in the article, the only one that is omitted in sideloading is the app store review.<\/p>\n<p>Everything automatic in the App Store review can be done before notarising the app as well.<\/p>\n<p>So the only thing extra is some Apple Employee launching your app and verifying that for the first few minutes that the application vaguely does what it says it does. But nothing stops the application from waiting until next month (or any other signal) and changing its behaviour entirely. So the app review [serves] no security purpose - its purpose is purely to disallow honest developers from breaking Apple&rsquo;s (often unwritten) rules in how they behave. App Review is entirely to control applications for Apple&rsquo;s benefit.<\/p>\n<p>There is no additional security in App Review, and therefore no loss of security in sideloading.<\/p>\n<p>Meanwhile there are whole categories of applications that will never be written while Apple has absolute control over what applications can be distributed. This is a huge, unknown, loss to all iPhones users, one that is impossible to quantify.<\/p>\n<\/blockquote>\n\n<p><a href=\"https:\/\/twitter.com\/KenHatesSoftwar\/status\/1508974164312420359\">Ken Harris<\/a>:<\/p>\n<blockquote cite=\"https:\/\/twitter.com\/KenHatesSoftwar\/status\/1508974164312420359\"><p>What it&rsquo;s called now &#x2192; What we called it for the 50 years before that:<\/p><ul><li>&ldquo;side-loading&rdquo; &#x2192; loading<\/li><li>&ldquo;third-party software&rdquo; &#x2192; software<\/li><li>&ldquo;app store&rdquo; &#x2192; store<\/li><\/ul><\/blockquote>\n\n<p><a href=\"https:\/\/twitter.com\/matthewstoller\/status\/1513941334666665986\">Matt Stoller<\/a>:<\/p>\n<blockquote cite=\"https:\/\/twitter.com\/matthewstoller\/status\/1513941334666665986\">\n<p>Apple&rsquo;s app store is so full of scams and garbage, and the firm is so inattentive, that one dude on Twitter - \n@keleftheriou\n - is constantly embarrassing Apple by showing their claims of protecting users are essentially fraudulent.<\/p>\n<\/blockquote>\n\n<p><a href=\"https:\/\/twitter.com\/stroughtonsmith\/status\/1513968024021352457\">Steve Troughton-Smith<\/a>:<\/p>\n<blockquote cite=\"https:\/\/twitter.com\/stroughtonsmith\/status\/1513968024021352457\">\n<p>It is incredibly frustrating that Apple has made sideloading a zero sum issue, because they&rsquo;re pushing regulators to legislate harder than was <em>ever<\/em> necessary by telling them it&rsquo;s the only option to curb Apple&rsquo;s behavior<\/p>\n<\/blockquote>\n\n<p><a href=\"https:\/\/twitter.com\/elkmovie\/status\/1513973755135016969\">Michael Love<\/a>:<\/p>\n<blockquote cite=\"https:\/\/twitter.com\/elkmovie\/status\/1513973755135016969\">\n<p>25 years ago, Microsoft violated all sorts of laws and lost a decade of innovation in a desperate attempt to stop people from writing apps for Netscape instead of Win32.<\/p>\n<p>Apple is about to let that happen to iOS because they insisted on getting a 30% cut of everyone&rsquo;s Bag O Gems.<\/p>\n<\/blockquote>\n\n<p>Previously:<\/p>\n<ul>\n<li><a href=\"https:\/\/mjtsai.com\/blog\/2022\/04\/01\/external-link-for-reader-apps\/\">External Link for Reader Apps<\/a><\/li>\n<li><a href=\"https:\/\/mjtsai.com\/blog\/2022\/03\/28\/proposed-digital-markets-act-to-require-sideloading\/\">Proposed Digital Markets Act to Require Sideloading<\/a><\/li>\n<li><a href=\"https:\/\/mjtsai.com\/blog\/2022\/02\/02\/schneier-on-sideloading\/\">Schneier on Sideloading<\/a><\/li>\n<li><a href=\"https:\/\/mjtsai.com\/blog\/2021\/11\/09\/federighi-and-cook-on-sideloading\/\">Federighi and Cook on Sideloading<\/a><\/li>\n<li><a href=\"https:\/\/mjtsai.com\/blog\/2021\/09\/13\/why-apple-should-compromise-with-antitrust-regulators\/\">Why Apple Should Compromise With Antitrust Regulators<\/a><\/li>\n<li><a href=\"https:\/\/mjtsai.com\/blog\/2021\/06\/25\/apple-attacks-sideloading\/\">Apple Attacks Sideloading<\/a><\/li>\n<li><a href=\"https:\/\/mjtsai.com\/blog\/2021\/05\/10\/inside-app-review\/\">Inside App Review<\/a><\/li>\n<\/ul>\n\n<p id=\"tim-cook-attacks-sideloading-in-privacy-keynote-update-2022-04-13\">Update (2022-04-13): <a href=\"https:\/\/twitter.com\/mdrockwell\/status\/1514330888384962565\">Mike Rockwell<\/a>:<\/p>\n<blockquote cite=\"https:\/\/twitter.com\/mdrockwell\/status\/1514330888384962565\">\n<p>Would allowing users to install apps from outside the App Store really hurt user privacy? Because right now, Apple knows every single app I have ever installed on every iOS device I&rsquo;ve ever owned. It would be cool if I could keep that private.<\/p>\n<\/blockquote>\n\n<p>Previously:<\/p>\n<ul>\n<li><a href=\"https:\/\/mjtsai.com\/blog\/2022\/03\/14\/still-no-preference-to-opt-out-of-ocsp\/\">Still No Preference to Opt Out of OCSP<\/a><\/li>\n<\/ul>\n\n<p><a href=\"https:\/\/twitter.com\/mdrockwell\/status\/1514370895124566022\">Mike Rockwell<\/a>:<\/p>\n<blockquote cite=\"https:\/\/twitter.com\/mdrockwell\/status\/1514370895124566022\">\n<p>If Apple cares so much about privacy, why can&rsquo;t I backup my iPhone to a Time Machine share on my network?<\/p>\n<\/blockquote>","protected":false},"excerpt":{"rendered":"<p>Joe Rossignol: Apple CEO Tim Cook today delivered the keynote speech at the Global Privacy Summit in Washington D.C. The conference, hosted by the International Association of Privacy Professionals, is focused on international privacy and data protection.[&#8230;]&ldquo;Here in Washington and elsewhere, policymakers are taking steps in the name of competition that would force Apple to [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"apple_news_api_created_at":"2022-04-12T20:08:46Z","apple_news_api_id":"b25f258c-356c-437e-8c4d-ee1f9e004b2b","apple_news_api_modified_at":"2022-04-13T23:43:50Z","apple_news_api_revision":"AAAAAAAAAAAAAAAAAAAABA==","apple_news_api_share_url":"https:\/\/apple.news\/Asl8ljDVsQ36MTe4fngBLKw","apple_news_coverimage":0,"apple_news_coverimage_caption":"","apple_news_is_hidden":false,"apple_news_is_paid":false,"apple_news_is_preview":false,"apple_news_is_sponsored":false,"apple_news_maturity_rating":"","apple_news_metadata":"\"\"","apple_news_pullquote":"","apple_news_pullquote_position":"","apple_news_slug":"","apple_news_sections":"\"\"","apple_news_suppress_video_url":false,"apple_news_use_image_component":false,"footnotes":""},"categories":[2],"tags":[2085,1846,91,38,31,2078,355,48,2132,60],"class_list":["post-35548","post","type-post","status-publish","format-standard","hentry","category-technology","tag-antitrust","tag-app-review","tag-appstore","tag-apple","tag-ios","tag-ios-15","tag-privacy","tag-security","tag-sideloading","tag-timcook"],"apple_news_notices":[],"_links":{"self":[{"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/posts\/35548","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/comments?post=35548"}],"version-history":[{"count":5,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/posts\/35548\/revisions"}],"predecessor-version":[{"id":35569,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/posts\/35548\/revisions\/35569"}],"wp:attachment":[{"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/media?parent=35548"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/categories?post=35548"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/tags?post=35548"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}