Comment by zbentley
18 hours ago
The comparison to banks is actually pretty interesting.
Unlike app developers, banks are by default directly liable for fraud that happens on their system. In many cases, even when someone gets their bank to send money to a scammer, they can still get that money back. Since the bank doesn't want to risk regulatory reprisal, they have a lower threshold for spending money to make customers whole. Exceptions and subtleties abound here, but the underlying incentive structure is very different: the broker of the sensitive resource (money, for banks) is often held responsible for mis-use of that resource. How would we do that for e.g. apps that store your password in plaintext and then get hacked?
Relatedly, banks have thus started adopting the practice of blocking and calling/talking to customers about suspicious transactions. You can still authorize it if you really push, but you have to talk to someone with expertise about fraud risk, and have to spend some time doing it (which helps a lot with the "urgency" dimension of scams). Most permission approval prompts on phones/computers have no such human intervention or time-delay option, even if you might want them to.
> The only way to 100% prevent scams is to remove the potential entirely. There are scams, infinite actually, right now, on iPhones. Do you support that? Surely not, so we should lock iPhones down more no?
Nobody here has the goal of preventing 100% of scams. The ideal amount of fraud on these platforms is not zero (https://www.bitsaboutmoney.com/archive/optimal-amount-of-fra...). Rather, fraud is still extremely common and difficult to disincentivize. We want to reduce that as much as possible while not imposing overly-onerous restrictions. The discussion is about what counts as "as much as possible" or "overly-onerous", not whether we should ban phones or banks.
> I can't install open-source software I've audited myself on my iPhone
I hope you understand you're in a very tiny minority of people who can do that, using a device designed for people who cannot do that, and whose behavior if permitted to do what you're after has a proven history of causing significant damage to individuals (who lose their savings) and shared resources (sites DDoSed by end-user-device malware, hospitals that can't provide care because someone let ransomware onto a computer, and so on).
I'm not arguing we should open iPhones 100%. But the fact that ONLY apple approved software can be run is unacceptable. Alternative app stores, which Apple can approve, should exist.
We have highly secure repos on other platforms. I would argue the Debian repos are much, much more secure than the App Store. The safety and security argument against it is, simply put, wrong. It is incorrect, it should not be humored. The fact people genuinely believe only Apple can securely audit software is ridiculous, poorly thought out, and obvious corporate propaganda.
If we want iPhones to be more secure, we need to take a closer look at the permission system. What we don't need to do is let Apple continue their profiteering. And make no mistake, the singular goal of the App Store is profiteering. Security is not a goal, otherwise they would only allow open source apps that they audit. But no, they allow closed source apps which use private APIs and they do not give a fuck. And that's why there's quite a lot of malware on the App Store, and much less in the Debian repos. Despite one being run by a multi-trillion dollar corporation, and the other being run by volunteers. It's time to call spades, spades.