TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

How malware gets into the App Store and why Apple can't stop that

158 pointsby sharjeelsayedover 3 years ago

8 comments

nbzsoover 3 years ago
Until we have some outrageously horrible events which will affect directly general population, all this facts will be comfortably avoided and &quot;mitigated&quot;.<p>This is systemic problem derived not only from bad management and absence of responsibility.<p>This is &quot;business as usual&quot; with any big corporation. There is no problem until perception of the problem affects sales directly.<p>And in the case with Apple, reality is professionally managed toward &quot;reality distortion field&quot; of uneducated masses who are addicted to &quot;latest tech&quot; and &quot;social validation psychology&quot;.<p>I don&#x27;t know any other corporation which can comfortably keep silence on issues like NSO&#x2F;Pegasus or just &quot;postpone&quot; intrusion on user privacy as CSAM.<p>People love their shiny toys. This is exactly the dynamic with tobacco companies in the past. People believed in one point in time that cigarettes are &quot;healthy things, recommended by physicians&quot;. <a href="https:&#x2F;&#x2F;edition.cnn.com&#x2F;2017&#x2F;05&#x2F;24&#x2F;health&#x2F;gallery&#x2F;tobacco-health-claims-history&#x2F;index.html" rel="nofollow">https:&#x2F;&#x2F;edition.cnn.com&#x2F;2017&#x2F;05&#x2F;24&#x2F;health&#x2F;gallery&#x2F;tobacco-he...</a><p>It is always psychology first, technology second. Or sales and shareholders first, services and tech appliances second.<p>You can thank &quot;geniuses&quot; like Edward Bernays and his contemporaries for this.
评论 #28681430 未加载
fortran77over 3 years ago
This was a very clear explanation of some very serious problems with Apple and the app store. Users who think Apple iOS is secure and private--as Apple keeps explicitly claiming--will be very sorry if their life or well-being depends on being able to have private data.
rickspencer3over 3 years ago
What really galls me is hoops i have to jump through and the money I have to spend to install my own apps written for my own use on an iOS device. How can that be for my own security? The ability to write a program for a computing device is such a fundamental capability, how can a device that lacks this ability even be sold?
评论 #28681856 未加载
azinman2over 3 years ago
“have you heard about any kind of security problems with Android recently? I haven&#x27;t.”<p>That’s a pretty silly thing to say [1] and a non-argument. Whether or not you’ve personally heard about security problems with android doesn’t mean they don’t exist or aren’t widely known to others.<p>[1] <a href="https:&#x2F;&#x2F;www.cvedetails.com&#x2F;vulnerability-list.php?vendor_id=1224&amp;product_id=19997&amp;version_id=0&amp;page=1&amp;hasexp=0&amp;opdos=0&amp;opec=0&amp;opov=0&amp;opcsrf=0&amp;opgpriv=0&amp;opsqli=0&amp;opxss=0&amp;opdirt=0&amp;opmemc=0&amp;ophttprs=0&amp;opbyp=0&amp;opfileinc=0&amp;opginf=0&amp;cvssscoremin=0&amp;cvssscoremax=0&amp;year=2021&amp;month=0&amp;cweid=0&amp;order=1&amp;trc=363&amp;sha=f1d918201ad0b0851a2b9b9562379023ac51bcd4" rel="nofollow">https:&#x2F;&#x2F;www.cvedetails.com&#x2F;vulnerability-list.php?vendor_id=...</a>
评论 #28678951 未加载
评论 #28678200 未加载
评论 #28678189 未加载
eceover 3 years ago
This is from the same person that reported iOS vulnerabilities recently: <a href="https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=28637276" rel="nofollow">https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=28637276</a><p>Thanks for all the work.
simion314over 3 years ago
So static analysis will not catch private API usage, so is mostly useless for protecting the users, it is interesting that such a rich company could not hire a team of competent developers to produce an actual secure way to give applications(and users) access to the private APIs.<p>Does Linux&#x2F;BSD sandboxing system offer such protection?
评论 #28700190 未加载
judge2020over 3 years ago
&gt; com.apple.developer.pushkit.unrestricted-voip<p>Do Duo, Otka, or Microsoft Authenticator have the special notification entitlement? These notifications never seem to be delayed no matter what internet climate i&#x27;m in unless i&#x27;m literally in the middle of nowhere.
egberts1over 3 years ago
I only download Apple apps that needs no additional privilege nor sends any telemetry back somewhere.<p>Did I do that one right?