{"id":42573,"date":"2024-03-20T15:52:06","date_gmt":"2024-03-20T19:52:06","guid":{"rendered":"https:\/\/mjtsai.com\/blog\/?p=42573"},"modified":"2025-01-22T13:47:54","modified_gmt":"2025-01-22T18:47:54","slug":"dma-compliance-workshop-notarization-and-core-technology-fee","status":"publish","type":"post","link":"https:\/\/mjtsai.com\/blog\/2024\/03\/20\/dma-compliance-workshop-notarization-and-core-technology-fee\/","title":{"rendered":"DMA Compliance Workshop: Notarization and Core Technology Fee"},"content":{"rendered":"<p><a href=\"https:\/\/twitter.com\/KayJebelli\/status\/1769635526062043315\">Kay Jebelli<\/a>:<\/p>\n<blockquote cite=\"https:\/\/twitter.com\/KayJebelli\/status\/1769635526062043315\"><p>Big day today as the [European] Commission kicks off its second round of DMA compliance workshops, this time focused on specific gatekeepers, their compliance reports, and the feedback of third-parties.<\/p><p>[&#8230;]<\/p><p>Interesting detail: the EC told Apple that they aren&rsquo;t allowed to notarize apps to protect users. So &ldquo;government authorities are the ones that are going to have to step up to protect&rdquo; app developers and users from the risks of these 3rd-party apps.<\/p><p>[&#8230;]<\/p><p>On the difference between iPhone and Mac app distribution, Apple cites the unique differences: mobiles are always carried with us, have more sensitive data, and are a much more attractive target for harmful actors, the risk greater, as are the steps necessary to protect users.<\/p><\/blockquote>\n<p>I&rsquo;ve never really understood this argument because everything on iPhone is sandboxed, and the sensitive sources of information like the camera and GPS are protected by access prompts.<\/p>\n\n<p><a href=\"https:\/\/mastodon.social\/@stroughtonsmith\/112120521055132578\">Steve Troughton-Smith<\/a> has an auto-generated <a href=\"https:\/\/gist.github.com\/steventroughtonsmith\/d393e13a2b0a3e41e69724b328a8b04c\">transcript<\/a> of the workshop.<\/p>\n\n<p><a href=\"https:\/\/twitter.com\/rjonesy\/status\/1769915897085362522\">Ryan Jones<\/a>:<\/p>\n<blockquote cite=\"https:\/\/twitter.com\/rjonesy\/status\/1769915897085362522\"><p>- EC told Apple they can&rsquo;t notarize alt apps &#x1F92F;<br><\/br>\n- $1M and 2M alt store rules are to prevent rip-and-run scams on users &#x1F44F;<br><\/br>\n- Apple cites: distribution, discovery, promotion, and trust as reasons for their commission &#x1FAE4;<br><\/br>\n- Apple cites 3 things alt stores will lack: Report a Problem, Family Sharing, and Ask to Buy. (Surprisingly weak, and notice how it doesn&rsquo;t match the reasons for commission&#x1F92B;)<br><\/br>\n- Someone asks to force users to scroll to see all alt browser choices. &#x1F926;&#x200D;&#x2642;&#xFE0F;<br><\/br>\n- Apple is using some contract engineering resources for this &#x1F633;\n<\/p><\/blockquote>\n\n<p><a href=\"https:\/\/twitter.com\/bvirlet\/status\/1769994650834596222\">Bruno Virlet<\/a>:<\/p>\n<blockquote cite=\"https:\/\/twitter.com\/bvirlet\/status\/1769994650834596222\">\n<p>They keep repeating this and I can&rsquo;t get this argument when e.g. Facebook gets to be on the AppStore for free. Also valid for the Core Platform fee.<\/p>\n<\/blockquote>\n\n<p><a href=\"https:\/\/mastodon.social\/@elkmovie\/112118626223919207\">Michael Love<\/a>:<\/p>\n<blockquote cite=\"https:\/\/mastodon.social\/@elkmovie\/112118626223919207\"><p>The basic problem with the Core Technology Fee - aside from the fact that they shouldn&rsquo;t be charging one at all - is that downloads are a terrible proxy for revenue, both in general and across different app categories \/ business models.<\/p><\/blockquote>\n\n<p><a href=\"https:\/\/daringfireball.net\/linked\/2024\/03\/18\/apple-dma-compliance-workshop\">John Gruber<\/a> (<a href=\"https:\/\/mastodon.social\/@daringfireball\/112120367801389775\">Mastodon<\/a>):<\/p>\n<blockquote cite=\"https:\/\/daringfireball.net\/linked\/2024\/03\/18\/apple-dma-compliance-workshop\">\n<p>We know from today&rsquo;s workshop that (a) Apple has already gotten specific pushback from the EC on aspects of its DMA compliance plan; and (b) Apple continues to think the CTF is perfectly cromulent under the terms of the DMA. That to me says the CTF is going to fly.<\/p>\n<\/blockquote>\n\n<p><a href=\"https:\/\/daringfireball.net\/linked\/2024\/03\/18\/viral-hit-ctf-problem\">John Gruber<\/a> (<a href=\"https:\/\/mastodon.social\/@daringfireball\/112120497611721840\">Mastodon<\/a>, <a href=\"https:\/\/www.macrumors.com\/2024\/03\/18\/apple-eu-core-technology-fee-viral-solution\/\">MacRumors<\/a>, <a href=\"https:\/\/9to5mac.com\/2024\/03\/18\/app-store-core-technology-fee-dma-europe\/\">9To5Mac<\/a>):<\/p>\n<blockquote cite=\"https:\/\/daringfireball.net\/linked\/2024\/03\/18\/viral-hit-ctf-problem\">\n<p><a href=\"https:\/\/altstore.io\/\">AltStore<\/a> founder <a href=\"https:\/\/mastodon.social\/@rileytestut\">Riley Testut<\/a>&#x2009;&mdash;&#x2009;who is apparently ready to go with a launch of the AltStore as an app marketplace in the EU&#x2009;&mdash;&#x2009;asked about the &ldquo;viral hit&rdquo; problem with the Core Technology Fee. E.g. what happens if a small developer&#x2009;&mdash;&#x2009;or even a kid in the proverbial garage&#x2009;&mdash;&#x2009;gets a 10-million-download hit and suddenly owes Apple 4.5 million euros?<\/p>\n<\/blockquote>\n\n<p>I was disappointed in the answer, which is that Apple doesn&rsquo;t know and that the European Commission <a href=\"https:\/\/social.vivaldi.net\/@brucelawson\/112116324070220937\">forces them<\/a> to charge free apps the CTF, which I don&rsquo;t think is the case.<\/p>\n\n<p><a href=\"https:\/\/mastodon.social\/@mike@libertynode.net\/112118793557145241\">Mike Rockwell<\/a>:<\/p>\n<blockquote cite=\"https:\/\/mastodon.social\/@mike@libertynode.net\/112118793557145241\">\n<p>Excellent question, for sure.<\/p>\n<p>It&rsquo;s worth noting, though, even if Apple waived the fee in all instances like this, the existence of the fee is likely to dissuade people from ever building the app in the first place.<\/p>\n<\/blockquote>\n\n<p><a href=\"https:\/\/mastodon.social\/@shanecelis@mastodon.gamedev.place\/112120756238106139\">Shane Celis<\/a>:<\/p>\n<blockquote cite=\"https:\/\/mastodon.social\/@shanecelis@mastodon.gamedev.place\/112120756238106139\">\n<p>How a ruling against Apple was turned into you pay Apple to NOT distribute your app, I do not know.<\/p>\n<\/blockquote>\n\n<p><a href=\"https:\/\/sixcolors.com\/post\/2024\/03\/apples-still-thinking-about-the-core-technology-fee-in-europe\/\">Dan Moren<\/a>:<\/p>\n<blockquote cite=\"https:\/\/sixcolors.com\/post\/2024\/03\/apples-still-thinking-about-the-core-technology-fee-in-europe\/\">\n<p>Still, apps that are completely free&mdash;including open-source apps&mdash;certainly don&rsquo;t seem like they should be subject to the Core Technology Fee. The question, from Apple&rsquo;s perspective, is how to police that? What about, say, an app that&rsquo;s distributed for free outside the App Store but has a big Patreon community that brings in a lot of money?<\/p>\n<\/blockquote>\n\n<p><a href=\"https:\/\/mastodon.social\/@colincornaby\/112118818539578029\">Colin Cornaby<\/a>:<\/p>\n<blockquote cite=\"https:\/\/mastodon.social\/@colincornaby\/112118818539578029\">\n<p>I feel like this whole CTF conversation will lead to a &ldquo;Pro&rdquo; version of Xcode with a subscription fee that higher end features will be gated behind. Not the worst outcome - and would cover technology usage.<\/p>\n<\/blockquote>\n\n<p><a href=\"https:\/\/social.vivaldi.net\/@brucelawson\/112115624691714315\">Bruce Lawson<\/a>:<\/p>\n<blockquote cite=\"https:\/\/social.vivaldi.net\/@brucelawson\/112115624691714315\"><p>Apple: &ldquo;for a long time, Apple has made it easy to choose a default browser other than Safari&rdquo;. No mention of alternative browser <em>engines<\/em>, even though this is explicitly mentioned in the text of the DMA.<\/p><\/blockquote>\n<p>Only <a href=\"https:\/\/mjtsai.com\/blog\/2020\/08\/05\/making-an-ios-default-browser-or-e-mail-client\/\">since iOS 14<\/a>, and only apps approved for a special entitlement.<\/p>\n\n<blockquote cite=\"https:\/\/social.vivaldi.net\/@brucelawson\/112115624691714315\"><p>There was a brief nod to humility at the start of this first Apple session (thanking the EU etc), but Apple are now trash-talking competitors, saying that they&rsquo;ve had to work really really hard for the last 18 months to meet the DMA, and avoiding\/ evading John Ozbey&rsquo;s direct question about Apple still self-preferencing.<\/p><p>[&#8230;]<\/p><p>Now, some tiresome FUD about how the sky will fall in if apps can be distributed without Apple checking them first. After all, there are literally zero dodgy apps such as <a href=\"https:\/\/appleinsider.com\/articles\/24\/02\/12\/how-russian-banks-use-trojan-horse-apps-to-stay-in-apples-app-store\">sanctioned Russian banks using trojan horse apps<\/a> at the moment now, are there?<\/p><p>[&#8230;]<\/p><p>This new Apple love for web apps is somewhat surprising so soon after some naughty boys from, er,  Apple tried to sneak out and drown Home Screen Apps in a bucket without telling anyone, then bawled &ldquo;The EU made me do it!&rdquo; when they were caught.<\/p><\/blockquote>\n\n<p><a href=\"https:\/\/isfeeling.social\/@matt\/112101869885692903\">Matt Birchler<\/a>:<\/p>\n<blockquote cite=\"https:\/\/isfeeling.social\/@matt\/112101869885692903\"><p>Sanity checking myself: does anyone else feel like the (US) punditry anger directed at the EU for forcing Apple to let devs sell things easily from a website and to ask users what default browser they want to use, is way more intense than any of the concessions (app censorship, &#x1F1F9;&#x1F1FC; flag vanishing, iCloud data moved to state-controlled data centers, etc.) they&rsquo;ve made for China over the years?<\/p><p>My memory is the vibe for China stuff is always, &ldquo;it&rsquo;s not good, but what can you do, it&rsquo;s the law &#x1F937;&#x200D;&#x2642;&#xFE0F;&rdquo;<\/p><\/blockquote>\n\n<p><a href=\"https:\/\/pxlnv.com\/linklog\/dma-compliance-workshop-apple\/\">Nick Heer<\/a>:<\/p>\n<blockquote cite=\"https:\/\/pxlnv.com\/linklog\/dma-compliance-workshop-apple\/\">\n<p>Other, similar compliance workshops are <a href=\"https:\/\/digital-markets-act.ec.europa.eu\/events_en\">coming up all week long<\/a>. Meta&rsquo;s begins just a few hours from the time I am writing this.<\/p>\n<\/blockquote>\n\n<p>Previously:<\/p>\n<ul>\n<li><a href=\"https:\/\/mjtsai.com\/blog\/2024\/03\/17\/ios-notarizations-human-review\/\">iOS Notarization&rsquo;s Human Review<\/a><\/li>\n<li><a href=\"https:\/\/mjtsai.com\/blog\/2024\/03\/13\/web-distribution-of-ios-apps-in-eu\/\">DMA Compliance: Web Distribution of iOS Apps in EU<\/a><\/li>\n<li><a href=\"https:\/\/mjtsai.com\/blog\/2024\/02\/09\/ios-17-4-changes-pwas-to-shortcuts-in-eu\/\">iOS 17.4 Changes PWAs to Shortcuts in EU<\/a><\/li>\n<li><a href=\"https:\/\/mjtsai.com\/blog\/2024\/01\/29\/app-marketplaces-altstore-and-epic-games-store\/\">App Marketplaces: AltStore and Epic Games Store<\/a><\/li>\n<li><a href=\"https:\/\/mjtsai.com\/blog\/2024\/01\/26\/dma-compliance-default-app-controls\/\">DMA Compliance: Default App Controls and NFC<\/a><\/li>\n<li><a href=\"https:\/\/mjtsai.com\/blog\/2024\/01\/25\/dma-compliance-alternative-app-stores-but-no-sideloading\/\">DMA Compliance: Alternative App Stores But No Sideloading<\/a><\/li>\n<\/ul>\n\n<p id=\"dma-compliance-workshop-notarization-and-core-technology-fee-update-2024-03-21\">Update (2024-03-21): <a href=\"https:\/\/mastodon.social\/@callionica\/112130066683872919\">Callionica<\/a> wonders whether Jebelli and others are mistaken about the EC not allowing notarization, since that doesn&rsquo;t seem to be mentioned in the transcript.<\/p>\n\n<p><a href=\"https:\/\/www.reuters.com\/technology\/eus-vestager-warns-about-apple-meta-fees-disparaging-rival-products-2024-03-19\/\">Foo Yun Chee<\/a>:<\/p>\n<blockquote cite=\"https:\/\/www.reuters.com\/technology\/eus-vestager-warns-about-apple-meta-fees-disparaging-rival-products-2024-03-19\/\"><p>Vestager said the new fees have attracted her attention.<\/p><p>&ldquo;There are things that we take a keen interest in, for instance, if the new Apple fee structure will de facto not make it in any way attractive to use the benefits of the DMA. That kind of thing is what we will be investigating,&rdquo; she told Reuters in an interview.<\/p><\/blockquote>\n\n<p id=\"dma-compliance-workshop-notarization-and-core-technology-fee-update-2025-01-22\">Update (2025-01-22): <a href=\"https:\/\/mastodon.social\/@rileytestut\/113873218521429677\">Riley Testut<\/a>:<\/p>\n<blockquote cite=\"https:\/\/mastodon.social\/@rileytestut\/113873218521429677\">\n<p>A minor annoyance with iOS notarization is that each notarized build requires a new marketing version (unlike macOS). It&rsquo;s not the worst, but it&rsquo;s especially annoying when notarizing multiple builds in a row for testing<\/p>\n<p>Thankfully I&rsquo;ve finally come up with the Perfect Versioning Scheme&trade; to make this a non-issue &#x1F60C;<\/p>\n<\/blockquote>","protected":false},"excerpt":{"rendered":"<p>Kay Jebelli: Big day today as the [European] Commission kicks off its second round of DMA compliance workshops, this time focused on specific gatekeepers, their compliance reports, and the feedback of third-parties.[&#8230;]Interesting detail: the EC told Apple that they aren&rsquo;t allowed to notarize apps to protect users. So &ldquo;government authorities are the ones that are [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"apple_news_api_created_at":"2024-03-20T19:52:09Z","apple_news_api_id":"c9b8269a-e939-48a0-9dfd-10894625121f","apple_news_api_modified_at":"2025-01-22T18:47:57Z","apple_news_api_revision":"AAAAAAAAAAAAAAAAAAAAAQ==","apple_news_api_share_url":"https:\/\/apple.news\/Aybgmmuk5SKCd_RCJRiUSHw","apple_news_coverimage":0,"apple_news_coverimage_caption":"","apple_news_is_hidden":false,"apple_news_is_paid":false,"apple_news_is_preview":false,"apple_news_is_sponsored":false,"apple_news_maturity_rating":"","apple_news_metadata":"\"\"","apple_news_pullquote":"","apple_news_pullquote_position":"","apple_news_slug":"","apple_news_sections":"\"\"","apple_news_suppress_video_url":false,"apple_news_use_image_component":false,"footnotes":""},"categories":[2],"tags":[2542,101,2571,2570,1927,31,2321,209,1842,991,1227,2569],"class_list":["post-42573","post","type-post","status-publish","format-standard","hentry","category-technology","tag-app-marketplaces","tag-business","tag-delta-emulator","tag-digital-markets-act-dma","tag-european-union","tag-ios","tag-ios-17","tag-legal","tag-notarization","tag-open-source-software","tag-top-posts","tag-web-distribution-of-ios-apps"],"apple_news_notices":[],"_links":{"self":[{"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/posts\/42573","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/comments?post=42573"}],"version-history":[{"count":3,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/posts\/42573\/revisions"}],"predecessor-version":[{"id":46494,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/posts\/42573\/revisions\/46494"}],"wp:attachment":[{"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/media?parent=42573"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/categories?post=42573"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/tags?post=42573"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}