Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> We will reject apps for any content or behavior that we believe is over the line. What line, you ask? Well, as a Supreme Court Justice once said, “I’ll know it when I see it”. And we think that you will also know it when you cross it.

This line makes my blood boil. Futhermore, later they define disallowed sexual content as:

> 1.1.4 Overtly sexual or pornographic material, defined by Webster’s Dictionary as "explicit descriptions or displays of sexual organs or activities intended to stimulate erotic rather than aesthetic or emotional feelings."

Do they not know from which ruling that quote comes from?



I completely agree. When rules aren't codified it invites biased interpretation of them.

However....

I've worked on an internal communications platform. For some reason people would forget that they were on a corporate site with their corporate email linked to it and spew garbage that any decent person would be embarrassed to say out loud.

So we deliberately didn't codify our rules. We chose not to because we were aware that if we did then people would deliberately cozy up as close to the line as they could, and that wasn't the kind of environment we wanted to foster.

We avoided bias by removing information about the flagger or flagee when content was flagged and judged it based on the content ourselves. After we judged we'd look up who was responsible for the content, and if we felt they were doing some penetration testing to see exactly where those lines were we would start to loop in their manager, HR, legal, and anyone else we felt should be aware. Our escalation procedure went up to banning, though nobody ever reached that point. And our content improved.

If the story ended there I would still be against not having codified rules, but begrudgingly accept that it worked in that situation.

Unfortunately the story doesn't end there. Staff was hired so that engineers wouldn't be responsible for this. The staff was less familiar with the ecosystem and they proceeded to clamp down more and more on acceptable content. They cozied up to HR and legal who were never really comfortable with the permissiveness of the platform, and received praise and additional funding to grow the team for these clampdowns.

I left the project and haven't looked back.

You're right, "I'll know it when I see it" is a garbage sentiment that at best is a cop out, but too often is used to withhold rules and keep people in the dark as a power play, or even squash dissenters with arbitrary and unbalanced application of force.


To begin with, I think they made it to accommodate Tencent, who once threatened to pull Wechat from App Store if they don't let them use their own payments.

First, they used them for transfers only, but later came games, and etc.


Because it is not about fairness or rules. It is about extracting as much values as possible from app developers.

That made sense when the Apple store was a small kind of start up enterprise. Nowadays, it should be regulated so all developers can use the platform in a level field where competition is real and it is not just a game for big corporations.


Regulating the app store isn't beneficial. They should be able to reject bad apps for being bad without having to go to court over it.

The problem is that they restrict the user from using any other app store. So then when they get it wrong there is nothing anybody can do. And then they have less incentive not to get it wrong, because it's much harder for them to lose users to a competitor, so then they prohibit things the user actually wants more often.


The reason why developers want to make apps for iOS is because there's a large market. That market exists because Apple has done a great job prioritizing the protection of their customers' privacy and payment information.

If third party App Stores are ever forced onto iOS devices, that market vanishes completely. Crashes, slowdowns, battery drain, malware, and information theft will become the norm. Go no further than your gaming PC to witness the nightmare that is multiple app stores all competing for CPU and control/surveillance of your system, all needing to bring their own flavors of information-harvesting/exposing DRM.

This new round of digital YIMBYism is profoundly anti-consumer and stands to destroy the trust that Apple has built with its customers. I sincerely hope that those of us who have trusted Apple with our data will start to speak out before Google-backed lobbyists tranform iOS into a malware-ridden hellscape.


I don't see that at all. The value Apple supposedly provides is safety. If consumers want the safety that Apple offers, they can continue to limit themselves to Apple's App Store offerings, while those who don't value safety as highly can use a different app store. Just because you value something in a certain way does not mean everyone else should be forced to adhere to those same values.


> If consumers want the safety that Apple offers, they can continue to limit themselves to Apple's App Store offerings, while those who don't value safety as highly can use a different app store.

I'm not even convinced that those who do value safety as highly wouldn't be better off with other stores. For example, Google Play has the actual Tor Browser, with all of the anti-fingerprinting work they've put into it, which isn't available on iOS because it isn't Safari. I think F-Droid does a better job of keeping out malware than Google or Apple, because by their nature they're more selective of what they put in. The platform's own store is going to be under a lot of pressure to include e.g. the Facebook app, whereas F-Droid is happy to not. And there is value in that to the user who places a high value on safety and security.


When you allow additional app stores, you encourage companies--like, say, Epic Games--to convince people who do not understand the ramifications or the threats involved with opening up past a rigorous review process to do so. And Epic isn't going to be following behind for the newly-credulous when they pick up another one and it's full of dangerous shitware.

Somebody who wants to not use the App Store can buy an Android device. It's fine. It's fine.


This is a really easy problem to solve - add a scary sign and/or void the warranty when a user decides they want to use an alternative app store. Then they at least have the option - and if they take it and suffer, they're the only one to blame. There's absolutely no collateral damage among users, and this feature would not meaningfully weaken security (if implemented properly) - "the user could do something dumb that only affects them" is not reduced security.


"This user just gave a third party their entire contact list" certainly does harm other people.

"This user just had their entire camera roll exfiltrated" certainly does harm other people.

These are social devices. Their users are, by and large, non-technical and incurious. Expecting them to not just click past the "scary sign", and so condition to do it again and again, so they can play Fortnite is a level of lack of understanding that borders on incredible.


...neither of those attacks you gave are unique to smartphones. Someone can leak personal information through any number of other channels - for instance, entering someone else's personal information into a website that send out emails for a group party invitation.

> Expecting them to not just click past the "scary sign", and so condition to do it again and again, so they can play Fortnite is a level of lack of understanding that borders on incredible.

That's not an excuse. This is bad behavior. It doesn't matter if it's common, or expected - it's wrong, and their responsibility for correcting - not Apple's, and especially not at the freedom of other users who have nothing to do with these idiots. If this behavior is normal, then we need to make it not normal, not continue to compensate for their ineptitude. Fix problems, don't avoid them.


They did fix the actual problem here: the complete intractability, to the point where your dismissal reads as at best impossible optimism, of expecting users to secure their devices when given the opportunity to get a sick screensaver or a game.

I appreciate the fix. And I don’t want to be hectored by bad actors to fuck up my phone for their profit margin.

Buy Android if you do. That “freedom” is right there for you. I used to buy Android when I thought I cared about sideloading; I don’t, so I don’t. Do likewise!


> If this behavior is normal, then we need to make it not normal, not continue to compensate for their ineptitude. Fix problems, don't avoid them.

This sounds great in theory, but two decades of history of malware on Windows have already taught us it is hopelessly impractical.


Possible credulous users cannot be the one-size-fits-all excuse for blocking the freedoms of everyone. There are many ways to mitigate any conceivable concern without abrogating the freedom of a phone owner to run the software they wish on their own device.


You have a perfectly viable platform that lets you run whatever you want on it in Android.

Go do that if you feel the need. Nobody's stopping you.


> The reason why developers want to make apps for iOS is because there's a large market. That market exists because Apple has done a great job prioritizing the protection of their customers' privacy and payment information.

You vastly overestimate the number of figs the average user gives about most of the privacy problems that HN grapples with. The average user, after all, uses Facebook. What the average user wants is for shit to just work.

The reason that iOS is a huge market has less to do with that, and more to do with all the other aspects of what makes a good phone.

You argument is also somewhat undermined by the existence of... A rather large amount of crap on the App Store. Somehow, the iPhone has managed to survive.

... Also, cutting side-deals with apps created by billion-dollar players, and telling all other app developers to pound sand (Regardless of the quality of the apps in question) is the main problem we're talking about. Whether or not Apple does this has no bearing on the current quality of the iPhone (But has a lot of bearing on their bottom line), but has a large bearing on the future quality of the iPhone (A vibrant app ecosystem is healthier then one where a few hand-picked winners are rewarded, and their competitors can never compete on an even playing field. At least, that's what advocates of open markets tell me.)


Breach a user's trust and/or misuse their data and you'll know about it pretty quickly. I'd wager that the average user cares much more about protecting, say, their browsing history, than they care about petty B2B contract drama.


> Breach a user's trust and/or misuse their data and you'll know about it pretty quickly.

> I'd wager that the average user cares much more about protecting, say, their browsing history,

No, you won't, for a lot of reasons.

1. If people gave a fig about their browsing history, they wouldn't have Facebook accounts. (Which, combined with tracking cookies, do a great job of leaking their browsing history.)

2. If people gave a fig about their browsing history, they wouldn't use browsers with omnibars.

3. Or browsers which sync their accounts across multiple computers/devices.

3. People don't even understand which part of the tech stack (The OS, the app, the browser, the website, the third-party cookies served by the website) that they use actually compromises their information.

4. Unless you're a political dissident being hunted by the CIA, the House of Saud, and the Mossad, when this information is compromised, the harm is difficult to quantify, and is never directly linked to the part of the stack that caused the compromise.

Ask five different people 'Who knows your browsing history?', and you will get five different answers, all of which will be wrong. If normal people cared about this in the particular, they'd be tech-literate about this sort of thing. They aren't. As long as some asshole is not using that compromised browsing history to harass them personally, as long as it's being used in the abstract, by some information broker to show them ads, most of them don't give a damn. I know that they don't, because they don't take any steps to secure it.

Obviously, the users don't care about the B2B spat between Apple and developers. I'm not asking them to - I'm pointing out that rigged markets rarely produce good products.


This is a good example of the contradictions in free market dogma. The reality is that the Facebook as it exists in the "rigged market" of the App Store violates users' privacy less than the "free market" versions on other platforms. Apple's restrictive policies have made them the only company to (have the power to) put checks on Facebook's information harvesting.


The issue is not that Facebook is restricted from doing some things in the App Store, that they aren't on other platforms. That's a strawman, that nobody in this thread is complaining about.

The issue is that the rules for Facebook on the App Store isn't subjected to the same rules as <Small competitor> on the App Store.


> I sincerely hope that those of us who have trusted Apple with our data will start to speak out before Google-backed lobbyists tranform iOS into a malware-ridden hellscape

Ive had iPhone for the past year, but before that I had many years of Android. I really don’t see my years on Android as hellscape. I never had any malware, I mostly used google play store but also sideloaded some “grey” software (a mobile hearthstone client before the game had a real mobile client). I think at some point I installed amazon App Store but not sure why.

I also can’t say that my recent Apple experience is smoother than my android experience. On my iPhone 11 Pro I’ve had multiple experiences where some app after a while started to crash on startup and clearing data didn’t help. They had to be explicitly removed then reinstalled. My previous phones (Samsung S8 was my last Android) didnt have this or really any issue.


> I never had any malware

I think you need to be careful about taking your experience as a sophisticated user that understands how to avoid malware and extrapolating that experience to the general population.

There's a reason fake Fortnite APK links have been plastered all over the internet and are successfully tricking less knowledgeable users into installing things they did not intend.


This argument doesn't hold water because it applies as much to the choice of phone as the choice of app store. There have been phones that come with malware preinstalled:

https://www.zdnet.com/article/more-pre-installed-malware-has...

A user who acts without knowledge or advice buys that phone and is infected. A user who acts without knowledge or advice buys an app from a store operated by the people who made that phone and is infected. It's the same scenario.

So how do you justify forcing the people who do know what they're doing to choose which app store they want to use based on which phone they want to buy, instead of allowing them to choose independently?

> There's a reason fake Fortnite APK links have been plastered all over the internet and are successfully tricking less knowledgeable users into installing things they did not intend.

There is a reason, but it's not the one you're implying.

The problem with having a single dominant app store is that it has given people no experience in how to be safe in installing apps from other sources, so then when an app they really want gets kicked out of the dominant store, they mash whatever buttons they think will get it back. Whereas if there were multiple major trustworthy stores, the users of an app whose developer is having a dispute with one the stores could safely and easily switch to another well-known store.

Meanwhile the users with iPhones can't mash buttons to get somewhere stupid, but they also can't do anything to install Fortnite on their phone right now, which is still worse for them than having it available in a trustworthy store other than Apple's -- which would keep them from getting the point of wanting to mash buttons.


> This argument doesn't hold water because it applies as much to the choice of phone as the choice of app store.

That's silly. The number of people who might buy a specific no-name budget brand of phone with this problem is much, much smaller than the number of people that search for "how to install Fortnite" on Google or Youtube and end up clicking on a fake installer instead of the real one, because they can't find Fortnite in the Play Store like they can with all their other apps.

The implication of your argument is ridiculous. Oh, you might accidentally buy a phone pre-loaded with malware, so we might as well give up and not bother taking any other steps to prevent the spread of malware on the rest of our phones?

> The problem with having a single dominant app store is that it has given people no experience in how to be safe in installing apps from other sources, so then when an app they really want gets kicked out of the dominant store, they mash whatever buttons they think will get it back.

So the fact that Windows has never had a single dominant app store means Windows users must be particularly experienced in how to be safe in installing apps from other sources? This does not match reality.


> The number of people who might buy a specific no-name budget brand of phone with this problem is much, much smaller than the number of people that search for "how to install Fortnite" on Google or Youtube and end up clicking on a fake installer instead of the real one, because they can't find Fortnite in the Play Store like they can with all their other apps.

If you search for "how to install Fortnite" then you get this:

https://www.epicgames.com/fortnite/en-US/download

Which is actually how you install Fortnite and not a fake installer.

People end up with the fake installer in the same ways they end up with the malware phone.

> Oh, you might accidentally buy a phone pre-loaded with malware, so we might as well give up and not bother taking any other steps to prevent the spread of malware on our phones?

There are a hundred ways to prevent the spread of malware without prohibiting multiple app stores. Allow third party apps but scan them for malware first. Get your apps from another app store, but that store checks it for malware. The only thing we give up on is the thing which is anti-competitive.

> So the fact that Windows has never had a single dominant app store means Windows users must be particularly experienced in how to be safe in installing apps from other sources? This does not match reality.

Have you used Windows lately? It comes with built in virus and malware detection for free and which doesn't expire. People are increasingly getting their software from stores like Steam and EGS which evict malware, which they can do even when they have competitors. Or getting it directly from well-known developers who they trust, like Mozilla or Adobe. Things that have no reason not to be web pages, are web pages. It works fine, even though you can still technically click through five warnings and run random garbage from the internet, because people have actually learned not to do that.

The people who haven't aren't the majority, they're the same people who buy the malware phone.


The problem is not everyone clicks on the right link. Non-sophisticated users looking for Fortnite don't even know what Epic is or whether or not they're the official place to get it.

https://blog.malwarebytes.com/cybercrime/2018/06/fake-fortni...

> There are a hundred ways to prevent the spread of malware without prohibiting multiple app stores. Allow third party apps but scan them for malware first. Get your apps from another app store, but that store checks it for malware.

The App Store review process checks for more than just malware. It also enforces privacy restrictions and ensures that developers aren't abusing legitimate APIs for malicious purposes. Malware scanning isn't going to prevent third-party apps from slurping all your friends phone numbers and selling that data to advertisers.

> People are increasingly getting their software from stores like Steam and EGS

Which is why we now have malware floating around masquerading as the Epic Games Store.

https://www.zdnet.com/article/new-lokibot-trojan-malware-cam...

I think you're making the same fallacy as the person I originally replied to, which is taking the experience of a highly technical user and assuming everyone else knows how to do the same things you do. I use all four platforms (iOS/Android/Mac/Windows) regularly. I've personally never had problems with viruses/malware on Windows, even back in the XP days before Windows Defender was a built-in thing. But simultaneously I don't believe my experience is typical of the majority of users on those platforms.


Maybe because Amazon App store used to cough up one paid app for free / day to get users to use their store.


If consumer trust were the foundation of Apple's growth, they wouldn't have to worry about folks defecting to another app store if it was available.

The reality is that, having created a great market, they are now extracting rents by using their ability to exclude apps to enforce things that don't benefit users but expand their margins (like forcing use of their identity and payment systems).


> If third party App Stores are ever forced onto iOS devices, that market vanishes completely. Crashes, slowdowns, battery drain, malware, and information theft will become the norm.

This is a wild projection. Having alternative app stores on iOS, especially if gated behind a hard-to-find switch with a scary warning sign, will be totally different than any PC experience, partially because iOS has a sandboxed architecture (and incredibly solid engineering in general) that is far more secure than Windows, and partially because Windows allows you to install stuff incredibly easily with no signing or app store required. It's really obvious that iOS will have a fraction of the security issues that Windows has had over its lifetime.


I mean, is it really that far out there if you look at the past two decades of history of malware on Windows and particularly Android?

Sandboxing has not prevented the proliferation of malware on Android, why would it be any different on iOS?

Sandboxing also doesn't really address the other major risk which is theft of personal information by supposedly "trustworthy" apps.


Malware is less of a problem for Android now than any point in Windows' history except for possibly the past few years, so I think that sandboxing has succeeded rather well, given that Windows has had 34 years to evolve defenses and Android has only had 11. Even early on in its life, Android was still better off than Windows at the time, and what do you know - Android has allowed sideloading and alternative app stores this entire time. That is, Android is doing now what we're discussing what Apple might do, and it's worked out pretty well for them.


That's not exactly a ringing endorsement, is it? Sure, the malware situation on Android is better than Windows. It's still far worse compared to iOS.

https://arstechnica.com/information-technology/2020/02/resea... (Note the date. This is an ongoing problem.)

https://www.theverge.com/2019/7/10/20688885/agent-smith-andr...

https://securelist.com/skygofree-following-in-the-footsteps-...

https://arstechnica.com/information-technology/2016/07/virul...

Don't you think there's a direct correlation between the ability to install APKs from random shady internet sources and the spread of malware on Android? Even macOS has a worse malware situation than iOS for the exact same reason.

If you believe this has "worked out well" for Android, you and I must have very different definitions of the phrase.

You also didn't address my other point, which is sandboxing is only meant to address operating system level security, not developer abuse of legitimate APIs.


> That's not exactly a ringing endorsement, is it? Sure, the malware situation on Android is better than Windows. It's still far worse compared to iOS.

> If you believe this has "worked out well" for Android, you and I must have very different definitions of the phrase.

Yes, it's a ringing endorsement. Android is good enough - actually, better than good enough. I've seen at least five cases of Windows malware from friends and family over the years, and zero Android cases.

As the article you listed above shows, xHelper has had 33K detected cases. That's literally two decimal orders of magnitude less than Conficker, which had over 9M cases, in 2008, when there were, if anything, fewer Windows devices than there are Android devices now.

iOS is only better than Android because it sacrifices a lot of user freedom for a little security - which is not an acceptable tradeoff. If I pay for a device, I (should) own it - not the company. If you, personally, are not going to check the box that says "let me install third-party apps" then you, personally, are at no risk of infection, and you have absolutely no right to tell me that you think that I should not have the right to check that box.

> Don't you think there's a direct correlation between the ability to install APKs from random shady internet sources and the spread of malware on Android? Even macOS has a worse malware situation than iOS for the exact same reason.

Yes, there's a direct correlation. If you give users sharp tools, the dumb ones will stab themselves. This is normal, and good. Users deserve the sharp tools. Put a sheath around them, but device makers intentionally restricting users from things that they might reasonably want to do, for the sake of their own profit, is borderline theft.

> You also didn't address my other point, which is sandboxing is only meant to address operating system level security, not developer abuse of legitimate APIs.

Yes, because developer abuse of legitimate APIs is irrelevant to what we're talking about here, which is whether or not to allow third-party app stores. Why? Because (a) both Apple and Google's app store review processes have let malware through before and (b) sandboxing, which doesn't necessarily prevent developers from abusing legitimate APIs, is necessary for it - and both iOS and Android take advantage of sandboxing to make it harder for devs to do bad things. For instance, iOS (now) gives you a notification if an application accesses the clipboard. Even better, there are modifications for Android that allow you to intercept and fake API data (so that an application doesn't refuse to work if you deny it access to an API) - which is significantly better than anything you can get on iOS.


Sorry I didn't see your reply earlier.

> As the article you listed above shows, xHelper has had 33K detected cases. That's literally two decimal orders of magnitude less than Conficker, which had over 9M cases, in 2008, when there were, if anything, fewer Windows devices than there are Android devices now.

That's some odd cherry-picking when I actually listed several different articles with much larger case counts. If it's magnitude you're looking for, HummingBad has infected 85 million Android devices, Chamois has infected 199 million, SimBad has infected 150 million. If you total up all of the Android malware attacks since the platform launched you're looking at several hundred million infections at the very least. This is not a small problem and is far from "good enough".

> Yes, because developer abuse of legitimate APIs is irrelevant to what we're talking about here, which is whether or not to allow third-party app stores. Why?

Sorry, I disagree. There are many APIs that can be used for legitimate purposes (for example loading my contacts so I can message my friend) that can be abused by developers who don't care about privacy (for example subsequently scraping my contacts and selling them to advertisers without my consent). Sandboxing or permissions or notifications don't really help address this issue, whereas at least with an app review policy you can say this behavior is unacceptable and you will be banned if you abuse it. Will the review process catch all of theses abuses? No. But it serves as a deterrent, and if you're comparing an app that is distributed via the App Store and subject to its privacy rules versus a version distributed directly via their website where they can do whatever the hell they want, I'd prefer the former any day. That's why it's relevant to the discussion of third-party app distribution.

> both Apple and Google's app store review processes have let malware through before and

No process is perfect and of course sometimes things will slip through the cracks, that doesn't mean there isn't value in the process. The statistics indicate that malware is a significantly larger problem on the Android platform compared to iOS and this is directly tied to the existence of side-loading and third-party App Stores.

1. Android is responsible for 47.15% of mobile malware infections compared to 0.85% on iOS. Windows accounts for 35.82% and IoT devices take up the remaining 16.17%. In other words, Android is now a larger malware vector than Windows itself, and your suggestion that malware is less of a problem on Android compared to Windows is statistically incorrect. (https://onestore.nokia.com/asset/205835)

2. Google's own reports show that Android devices that use side-loading have an 8x higher incidence of malware compared to devices that only use the Play Store, meaning it's specifically direct downloading and third-party stores that are the cause of the problem. (https://source.android.com/security/reports/Google_Android_S...)


> If third party App Stores are ever forced onto iOS devices, that market vanishes completely. Crashes, slowdowns, battery drain, malware, and information theft will become the norm. Go no further than your gaming PC to witness the nightmare that is multiple app stores all competing for CPU and control/surveillance of your system, all needing to bring their own flavors of information-harvesting/exposing DRM.

I am sorry but this is just FUD.

I own both a Macbook Pro and PC that I built and I have yet have these supposed "multiple app stores nightmare" that you are talking about.

Do you own a Windows machine yourself? Because the above comment doesn't seem to be done in good faith.


There is literally malware spreading by masquerading as the Epic Games Store: https://www.zdnet.com/article/new-lokibot-trojan-malware-cam...


I still fail to see how this will apply to iOS.

iOS doesn't magically lose it's sandboxing and become Windows just because 3d party stores are allowed.


Sandboxing didn't prevent fake versions of Fortnite and other serious malware from spreading on Android, nor does it generally prevent information theft and privacy violation through malicious use of legitimate APIs.


I don’t know if you have seen the trash heap of bad apps that is on the App Store. It gives the distinction impression that Apple does not reject bad apps, only apps they don’t like for arbitrary reasons.

I do agree that the best solution would be allowing third party stores.


Just because bad apps may make it onto the app store doesn’t mean Apple’s implementation is failing. Security holes are not discovered in a vacuum. It’s like playing wack a mole. For obvious points just like at how Epic got banned from the App Store. They snuck in a direct payment option and got approved for release, only later did Apple find out. It’s possible that those bad apps snuck in malicious codes and the app reviewer missed it. It happens. However without Apples review and ability to act as goal keeper there would be much more of those kind of apps,.

I’m not sure how third party stores are the best solution to this. That means users would have to trust another gate keeper for security and validation. 3rd party app stores will just increase the possible of malicious apps


Or just charge a flat review fee.


The only loophole I can see is to have web app stores because you can’t ban browsers. Web apps may improve greatly as lower level browser APIs like Houdini become available but I don’t think that will be enough. I think that html should be replaced by cross-platform native apps distributed over http.


Unfortunately, Apple controls the browser channel by mandating the use of their engine, WebKit, which is suspiciously limited on the features that make web apps close to native, Store-distributed apps.


The fact they need rules to enforce use of their inferior payment system shows how inherently anti-competitive IAP is. If it were optional and you could freely roll your own purchase mechanism, most (not all) developers would remove Apple IAP with the current 30% fees.


...and I would go from spending one or two hundred a month on IAPs, and spend zero instead. There is no way I’m giving an app my payment info.


How do you make online purchases? Do you just... not? Is the use of independent payment systems on the Web somehow different from in iOS apps?


Use an intermediary like google wallet or a one time virtual cc?


In which case OP should have no problem using the same solution for in-app purchases.


What about “roll your own” equates to google wallet? That’s very much not roll your own, and not what the grandparent was arguing.


You misunderstand. The customer can use Google Wallet if he wishes.

On the Web, payments almost always go through the credit card system, using one of many payment providers (PayPal, Stripe, etc.) set up by the seller. The customer also has the option of using a "safer" virtual credit card to avoid the possibility of credit card theft.


Yeah, the thing is to have codified questions. Seems weird but that's how the law does it. We are always asked to frame things in terms of what a reasonable person would find explicit, threatening, likely, implausible...basically, the law asks you: can you answer this question with a straight face?


I think there is a difference in kind over rules that govern paid employees, and rules that govern developers who are paying to be on the platform, and told to design and innovate, but if you step over a line we're not going to write down, we'll kick you off the platform and damage your business.


Doesn’t sound like a platform I’d want to bet my business on.


Your codified rule was “don’t habitually say stuff you don’t want to be attributed to you with your manager, HR, legal, and anyone else at work you don’t want reading it”.

Seems pretty straightforward to me.


Not sure if what you're arguing against is judgment calls, or against the fallout of that supreme court ruling, but to address the use of judgment, the nature of curation is that it's not always something that can be put in a set of explicit rules.

There's always people that walk right up to and over the line and generally push boundaries and find loopholes, no matter how well written rules are. Human judgment needs to be a part of the process if a good experience is desired.

Now it can be argued that Apple doesn't execute on this approach particularly well, but the idea that they want to be able to make some judgment calls is perfectly valid and if done right leads to the best experience.


> Human judgment needs to be a part of the process if a good experience is desired

Yeah just to second this I think that a lot of us coming from software backgrounds like to think of laws as being code, fully definable, automatable and capable of covering all edge cases. This isn’t the case. Judgement is required.

Not to ruin my own metaphor but I actually think there is a lesson about software as well. Software is not something capable of perfection. There is no perfect code, everything is a bodge, some bodges are more useful than others. You can’t cover every edge case. Software evolves and has flaws much like the product of natural evolution.


>Yeah just to second this I think that a lot of us coming from software backgrounds like to think of laws as being code, fully definable, automatable and capable of covering all edge cases. This isn’t the case. Judgement is required.

problem arises when the method for achieving Judgement isn't codified.

Meaning, while laws and punishment are open to interpretation by the judges, the system by which we appoint judges, their permissions and abilities, are strictly codified, and they must be in order to subdue and reduce corruption.

OK: Your company decides to stop producing specific codified rules -- what is in place to prevent judgement bias and fair interpretation of 'crossing the line'?

The answer, in most cases, is that there is nothing to hold the 'judges' accountable. Nothing to insure fair unbiased decisions. Nothing to insure that they can't hold the position indefinitely without malice.

In other words : The shorter your Terms of Service become, the longer the Employee Handbook must become to prevent corruption and overall unfairness.

Besides that problem, there is the problem where the acceptable behaviors on a platform may wander with society -- this leads to issues where developers may be barred from a platform for behavior which was perfectly acceptable earlier that year without any real warning.

How does one avoid breaking rules if they can't know the rules?

Well, one might say "Play nice.", but the reality is that we all interpret it differently. That's one of the many nice features that comes along with codified law.


In theory, the law should be written such that reasonable, disinterested people can reach consensus on the outcome of cases.

It can't be as unambiguous as code and usefully describe the world, but it shouldn't require judgment based on individual opinion - that's why the pornography ruling is such a dodge.

Judges should be disinterested and appealable; they are not in Apple's case.


Agree. Decision environments are high dimensional spaces that human judgment can tap into. Laws and rules are ways to compress that space, but the compression is lossy and can lead to a divergence between the letter of the rule and its intent.

And to add more complexity to the situation, laws and rules are but static snapshots within a dynamic system, and may simply drift away from intent with the progression of time and people's viewpoints. Kind of like a really old keyframe in a compressed video that starts smearing from the accumulation of too many changes.


One observation I've made about laws vs code is that the former allows for the use of some very... convenient descriptors. The best one is "reasonable". It's used all the time in legal agreements, and it's exactly the type of mushy concept you could never explain to a computer.

And I think that's healthy. Laws are written for people, not computers, and as far as I can (I'm very much not a lawyer), everyone basically agrees on what "reasonable" means. Furthermore, I'm not sure what we'd do without that word, because you can't realistically outline every possible scenario in advance.


I can't believe they were dumb enough to put that SCOTUS line in this.

It just plays into their current "meh, here's some rules but we'll do whatever we want anyway" image.


If I remember correctly, the SCOTUS reference dates back to when Steve Jobs was CEO. I am, um, not at all surprised he put that in the guidelines.

The guidelines also used to say:

> If your App looks like it was cobbled together in a few days, or you're trying to get your first practice App into the store to impress your friends, please brace yourself for rejection. We have lots of serious developers who don't want their quality Apps to be surrounded by amateur hour.

You can tell this was personally written by Steve.

---

Taken from https://web.archive.org/web/20140903022336/https://developer.... This is the earliest available in the Internet Archive as far as I can tell; circa-2012 they were kept behind an account login.


I've heard anecdotally that Steve Jobs helped write those guidelines, and the "amateur hour" line in particular sure sounds like him. I don't mean that in a disparaging way; Jobs could certainly be a jerk, but there are times I wish more CEOs were willing to be that blunt in official communication.


And to be honest it make sense in the early days. Jobs wanted the absolute best Apps in the Apps Store.

Situation now is different though. Jobs would likely have some human touch in the current situation. Where as Tim Cook feels less so.


Given how much amateur hour there is on the app store, I think they might as well remove that rule...


That sounds like a good guideline to be honest. Perhaps not the best-worded one, but gets the point across and avoids becoming another Google Play Store.


I think it would be in excellent guideline if iOS allowed side-loading (without ridiculous restrictions). But it doesn't.

Everyone was an amateur once. How should they distribute their apps?


I do not want these apps and average Joe doesn't want them either.

Why is it so difficult for people to imagine how insanely powerful and datapacked your phone is?

Allowing sideloading to average people means they will get hacked and ransomwared left and right. Your entire life is on the iPhone.

While I agree with you about sideloading apps for enthusiasts and hackers, but the world is far different than you and me. I really don't understand why these arguments are presented on HN time and again. Jailbreaking your iPhone is a terrible idea. Horrifying even.

I am glad Apple is gate keeping. Privacy > Hackability. You can't have both. The world is full of vultures that will shred your privacy in no time. Just look at what the ad-tech is doing within these sandboxes (browsers). Microsoft got into ad-tech game because they realized "Holyshit, we are actually in a unique position...develop operating system and sell data for millions of users?".

Apple is probably the only company looking after users and yet we've got completely deluded developers on HN complaining about sideloading apps. Sigh.

For amateurs, let them develop stuff on browsers. I don't want these amateurs widely distributing apps to billions of users with system level access with a quick approval popups for billions of idiots that don't care about their privacy and would give access to anything that asks for it.


> Jailbreaking your iPhone is a terrible idea. Horrifying even.

And the fact that I can Jailbreak my phone has not caused your iPhone to to become safer or less private. All I want is for Apple to offer an escape hatch, completely optional. It would not affect your experience in the slightest.


I agree with you if that escape hatch requires explicit permission, warnings and a bunch of precautions.

Hot links, such as reddit.com launching App Store to download their app should not be allowed because some uninformed user might just download bogus apps from 3rd party stores.

Again, I support the idea of an escape hatch, but I feel like that applies to an imposssibly small slice of the total iPhone userbase. People like you and me. I feel like I should write it out: 0.00000001% people.

Do you think executives at Apple look at this feature request and spin the entire ship around so that you and I can hack a phone?


Sorry if this is nitpicky, but since you made a point of saying you were going to write it out..

The world population is ~7.8 billion. 0.00000001% of that is 0.78. If you drop the percentage, it's still only 78 people. And that's assuming every person in the world is an iPhone user.

I think the slice is obviously bigger than that.


> Do you think executives at Apple look at this feature request and spin the entire ship around so that you and I can hack a phone?

Yes, because of what happened with HKMap.live. This is incredibly important for free expression.

It’s only used by a tiny number of people until one day when it suddenly becomes essential.


Sure it would. Some major developer only offers their app as a side load and suddenly your Aunt Edna is giving system level permissions to some developer without any realization that they just gave away keys to their house.

Perhaps Apple could sell a developer edition of the phone that allows side loading.. come to think of it, they do. If you are an Apple developer you can side load apps. Any developer that wants to can post their code on github and let other developers install it on their phone.

Really, if you don’t like the rules, you have an alternative.


Android allows sideloading and I’ve literally never heard of anyone even doing that, much less getting hacked by it.

I think you massively overestimate how many people would use that functionality.


I think you massively underestimate the number of people that will click yes to install random packages on their own phones in order get access to free games or porn or whatever.

https://research.checkpoint.com/2019/agent-smith-a-new-speci...

https://blog.malwarebytes.com/android/2019/08/mobile-menace-...

https://arstechnica.com/information-technology/2016/07/virul...


Even without sideloading, the Google Play Store is so full of trash apps that request dubious permissions and are littered with dark patterns. Not that it doesn't happen on the App Store, but it's significantly worse on Android. I saw the state of my little brother's phone (tween) and it was quite shocking.


> Android allows sideloading and I’ve literally never heard of anyone even doing that, much less getting hacked by it.

I have.

https://www.forbes.com/sites/thomasbrewster/2019/07/24/warni...


> I think you massively overestimate how many people would use that functionality.

I admit that I know very little about Fortnite and am not a regular Android user, but my understanding is that, right now, anyone who wants to play Fortnite on Android is sideloading it. That's a lot of people who are opening up a pretty brutal attack vector to be able to play a game that got kicked out of the official Play Store.

https://www.theverge.com/2020/8/13/21368079/fortnite-epic-an...


It didn't get kicked out of the store for violating people's privacy or some such, it got kicked out because they didn't want to pay Google money in exchange for absolutely nothing.

Sideloading Fortnite is not opening up an attack vector unless Fortnite itself is malicious, which it's not, because it's a huge game from a huge company. As long as the official download source is known to everybody, I think it's fine.

I know there are fake (malicious) copies of Fortnite out there, but those promise free V-Bucks or some such. You could just as easily run that scam without sideloading and target the user's credit card number of similar.


I think you're understimating the level of risk associated with people attempting to sideload Fortnite. People aren't necessarily intentionally seeking shady versions (but even if they were, I find this kind of victim-blaming counterproductive). They were doing things like searching "how to install Fortnite" on Google or Youtube and getting sent links to fake versions with malware loaded. [1]

How were non-sophisticated users supposed to figure out that the Epic link was the correct link to click among the thousands of search results? How many of the people wanting to play Fortnite for the first time even knew what Epic was?

> As long as the official download source is known to everybody

It's not, and that's the problem.

[1] https://blog.malwarebytes.com/cybercrime/2018/06/fake-fortni...


I guess my question is, is this problem really unique to sideloading, and if not, can it be addressed in the same ways we address other problems?

For example, does everyone know the official source of Facebook? If so, why, and if not, why is there not an epidemic of fake Facebook scams that steal login credentials? I know there are targeted phishing attacks, which is a separate issue, but I haven't heard of significant attacks from people who just didn't know the correct login page.

One way we do deal with this is with targeted blacklists of known-bad sites, particularly Google Safe-browsing. That's certainly a mechanism that could be employed for Android Malware—and I think it already is, actually.

Problems do happen—but I don't see anyone calling on Google to restrict Chrome to a whitelisted set of approved URLs. And I'd posit that gaining access to someone's Facebook account is no less invasive than gaining access to their phone.


Don't the overwhelming majority of people access Facebook via the app these days? So the official source of Facebook for those people is... the App Store or the Google Play Store.

> And I'd posit that gaining access to someone's Facebook account is no less invasive than gaining access to their phone.

I don't think so. Accessing someone's Facebook messages and photos is one thing, gaining access to their phone means gaining access to their email which means potential access to any account linked to that email. Given how many people use mobile banking these days, I'd say there's a lot more potential for damage if your phone is compromised.


Possibly ability of sideload makes Play Store not to restrict apps hardly like AppStore.


If you're an amateur, you have to put in extra time to get your app into shape.


I'm really surprised. Did Apple shake up their PR or legal flacks? The language they've used recently (I'm thinking of the Epic stuff, too) feels different than their famously cool, considered tone; looser, more assertive, and much easier to argue with.


I disagree. They have always been this arrogant. You are just noticing it right now. Do you remember when they essentially said don't run to the press if we don't allow your app, it won't help you, which I personally interpreted as or else? Or how almost every time someone criticizes Apple they sandwich a one-sentence criticism between 50 sentences of praise because they know the cost of not doing that could be their entire business? Since the launch of iPhone, Apple has been the 800lb gorilla in the room and has acted like it.

EDIT: From App Store Review Guidelines on September 2014:

> "If your App is rejected, we have a Review Board that you can appeal to. If you run to the press and trash us, it never helps."

https://web.archive.org/web/20140903022336/https://developer...


Which is such a lie, because going to the press is exactly what gets a lot of apps re-evaluated and accepted.


Eh, it _can_ be a lie. This is some form of the quandary “if you owe the bank a million dollars, you’re in trouble; if you owe the bank a billion dollars, the bank is in trouble.”

99% of app devs will not benefit from “running to the press.” Those that will will know it for certain.


I've seen apps get their decisions reversed simply due to a post becoming popular on HN or Reddit. You don't have to be a major player for public shaming to work against apple.


I agree. Sentences like "we think that you will also know it when you cross it" are extremely arrogant.


It's always been written in an oddly informal way. When I first read it, I did a double take and had to check if I was on the right domain, because I didn't expect it from Apple, of all companies. Over the years, it has been tightened a bit (the famous "If you run to the press and trash us, it never helps" line is gone), but it's still quite relaxed and personal, which is a tone that is somewhat at odds with the strictness of the rules.


I think it's the power dynamic. The marketing material doesn't need to be as good because they're (culturally) in charge now at the company.

It used to be that engineering/design led the company. Now it's marketing and legal.


> It used to be that engineering/design led the company. Now it's marketing and legal.

Isn't that what people make fun or Oracle for?


Oracle: Sales and legal.


I think that bit has been in there for years.

edit: Here it is, from 2016, probably goes back a lot longer than that

https://web.archive.org/web/20160706210122/https://developer...


For what it's worth, I'm pretty sure that line's been in there since the review guidelines were public, years ago.


I found an article from 6 years ago that quotes that line, so at least since then: https://www.theregister.com/Print/2014/09/04/apple_new_app_s...



Everything is a judgment call. You can no more spell out everything that is considered explicit than your HR department can spell out everything that might constitute harassment.


It's their treehouse; they can do what they want. None of these platforms are your friend. Half the Apple devs I know have some kind of stockholm syndrome, though.


Apple owns the platform. I'm still going to try and change how they do business because that would be better for me. Everyone is allowed to do that and there's nothing wrong with it. If you want to give up your power as a person to try to affect change, that's cool but I'm not giving up any non-immoral tool I have.


Or just maybe they like making money on the mobile platform where people will actually spend money?


The crazy part is the people who fly into fits of rage when you suggest Apple could do something differently. Changing the web browser on iOS was one that would get tons of hate and responses like “you don’t need that! it would confuse people!”

Then Apple lets people do it and now they’re okay with it


You still can't change the browser on iOS. All the other "browsers" are heavily restricted skins over a webview, not a proper other browser.


And that's OK; if it wasn't for Apple then Google would essentially own the current and future direction of the web by now


Competition should not be created by limiting the market on one specific platform.


with their sandbagged browser that they only bother to update once a year? Firefox is the competition for Chrome, Safari is just a sandbag to hold open the gap between web apps and native apps.


Apple updates the browser between major OS updates.

Apple added YubiKey support (https://nakedsecurity.sophos.com/2019/12/12/apple-ios-13-3-i...) for 2FA in Safari in 13.3 and they added better mouse support to Safari as well as other built in apps between major releases.

Firefox is losing market share and almost completely dependent on Google for its survival. If Firefox tries not to support something that the rest of the industry is supporting (like the web based DRM) the rest of the industry just yawns.


Then stop whining about Apple's stupid rules. Apple also likes making money on their platform, and they're much better at it than you are.


> a Supreme Court Justice once said, “I’ll know it when I see it”. And we think that you will also know it when you cross it.

I personally think this is the worst line that ever came out of a Supreme Court decision because of how simple it is. It is such a blatant low effort cop out that legitimizes arbitrary rulings. At least usually they obfuscate it with legal jargon and historical rulings.


The quote is infamous for being a terribly useless statement. Not sure why they would want to use something like that to defend themselves


I think of it as the legal version of the observation from psychology that some tasks (e.g. recognition of images) are performed by the brain without conscious understanding of the process.


> In 1981 Justice Stewart commented about his second thoughts about coining the phrase. "In a way I regret having said what I said about obscenity—that's going to be on my tombstone. When I remember all of the other solid words I've written," he said, "I regret a little bit that if I'll be remembered at all I'll be remembered for that particular phrase."


Good. Considering how much damage he did to the right to free speech (and less importantly the legitimacy of the supreme court), he deserves to not be remembered for anything else.


Interesting that the film at issue in the Supreme Court case, in which 6/9 justices disagreed about the reasons why it should or shouldn't be censored, is today available on iTunes: https://itunes.apple.com/fr/movie/les-amants/id1112874509?l=...


Why would court opinions matter here? Seriously, private stores have always had the choice of what products they sell, the alternative is being able to force people to sell your product against their will.

No, anything here has to be purely a question of whether Apple or Google are acting unfairly, and everything I’ve seen says that the commissions involved match other hardware manufacturers.


That quote even has its own wiki page:

https://en.m.wikipedia.org/wiki/I_know_it_when_I_see_it


For more context, it ruled out a false positive and pushed the boundary further, not vice versa:

I shall not today attempt further to define the kinds of material I understand to be embraced within that shorthand description ["hard-core pornography"], and perhaps I could never succeed in intelligibly doing so. But I know it when I see it, and the motion picture involved in this case is not that.

The Supreme Court of the United States reversed the conviction by ruling that the film was not obscene and so was constitutionally protected.

Absurdly, apple opponents itt use its completely opposite meaning in their arguments.


I think it’s okay for Apple to remain vague here. The internet can be a weird and terrible place. By phrasing it like this, Apple can prevent all kinds of creative forms of harassment and discrimination. Instead of allowing bad actors to try to play the game of finding terrible loopholes to jump through.


> “I’ll know it when I see it”. And we think that you will also know it when you cross it.

Which means different app reviewers will have different interpretations of it. A problem that exists now.


They know this and they don't care. It's not like Apple users can just go "well screw this" and download apps from a different source easily. They'd have to switch to Android to do it or have to be technologically inclined.


And that's fine - Apple users knew that was the deal when they decided to get an iPhone over Android (for many that was why they made that decision)


I see this a lot, but do they really? I'm sure the technical Apple users knew what they were getting themselves into but most average Joe users I've run into that have iPhones for other reasons like: needing iMessage to talk with family, liking the UI, wanting to sync with their Mac, etc.

None of which require Apple to have a monopoly on app distribution.

Saying Apple users knew what they were getting into is kinda like saying Apple users agreed to the ToS, so they shouldn't complain.


You don't expect from average Joe to formulate the exact value of their phone on demand. There may be much more behind these phrases, but they are simply not used to articulating the full difference, cause they do not discuss it often, and they have less vocabulary for that kind of thing.

What we should not do, is treating average Joes as idiots with no knowledge. They are non-tech, but not clueless. If you ask one of them about installing apps from the internet, they will likely remember that guy who told them it may be unsafe and it's better to stick with official store. PC users will definitely know about viruses and other "in the wild" hazards. Even my life-long non-tech grandma asked me about dangers and banking app practices when I brought her a tablet.

Personally I even bet that many of android users want/pretend apple safety or think that these two platforms are probably as safe as apple. They do not know what they are getting info, they assume that, because why wouldn't you.


A page out of the constitution - "high crimes and misdemeanors" - deliberately overtly vague.


> inaccurate or misleading quotations of religious texts

I find it fascinating that they included ^this^ one.


So they block Safari right, because I can definitely see sexual content in Safari.


The exception for web browsers also extends to Firefox, Chrome, etc on the App Store so that exception is applied consistently.


“Yes the web is the bad place, with porn and such: you should use apps instead”. After all, in the apps “look better”.


Why? Because they didn’t tell you the “algorithm”?


> defined ... as “explicit descriptions or displays of sexual organs or activities intended to ...

wait, is this going to be a basis for pixelated/black bar’d porn on App Store


well at least he upheld the First Amendment when uttering that statement but the rest of his text basically shows he knew that First Amendment rights were more important than his moral code and asked if he could define what would cross the line he could not do so satisfactory.

Now as to Apple, I don't have to buy their products and if I do I know what to expect. If it really mattered or should I say bothered me enough I certainly would buy a different product.

Right now my Apple purchases are on hold for their virtue signaling and effective turning their backs on abuses in China and Hong Kong.

Apple Human Rights Warranty, Void where prohibited by law.


Abuses in China? So what are you planning to purchase instead? Because Apple is doing better with worker rights in China than any competitor is.


> So what are you planning to purchase instead?

E.g.: https://puri.sm/products/librem-5-usa/

But the issue wasn't about manufacturing to begin with. The trouble is that Apple have significant operations in China, which makes them subject to influence by China, while at the same time maintaining control over what their users see and what they see about their users.

A less vertically integrated company wouldn't have that problem.


As an Apple user I'd like to believe this but it would be good to get some citation on that.


So are you not going to buy any electronic items?




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: