Skip to main content

‘Sideloading is a cyber criminal’s best friend,’ according to Apple’s software chief

‘Sideloading is a cyber criminal’s best friend,’ according to Apple’s software chief

/

Craig Federighi says that “the floodgates are open for malware” if Apple allows sideloading on iOS

Share this story

“Sideloading is a cyber criminal’s best friend and requiring that on iPhone would be a gold rush for the malware industry,” according to Apple senior vice president Craig Federighi, who delivered a dramatic speech at Web Summit 2021 declaiming the security risks if Apple were required to let users sideload apps.

Federighi, who oversees Apple’s iOS and macOS software divisions, was specifically protesting the European Commission’s proposed Digital Markets Act, which, if passed, would require Apple to let users install apps outside of the iOS App Store. According to Federighi, the lack of sideloading is what separates Apple’s relatively low rate of malware on iOS from the “5 million Android attacks per month,” and that if Apple were forced to let users install their own apps, “the floodgates are open for malware.”

Federighi also argues against a popular proposed solution of letting users decide for themselves whether to take the risk of sideloading apps. The problem is that “criminals are clever, and they’re really good at hiding in plain sight,” and that even informed users might get caught by misleading websites, or even get stuck with fake app stores installed on their phones.

Apple is still very much against sideloading

And even if you, a tech-savvy smartphone expert, might not be fooled, Federighi plays on the heartstrings and asks the audience to think of the children or parents who might be fooled. “The fact that anyone can be harmed by malware isn’t something that we should stand for,” Federighi concludes, despite the fact that Apple still routinely deals with multimillion-dollar scams that the company only just added the ability to report in September.

Federighi’s picture of doom doesn’t just stop there, though: he also raises the concern that if Apple were to allow sideloading, “some social networking apps will probably try to avoid the pesky privacy protections of the App Store and only make their apps available via sideloading.” According to Federighi, Apple’s privacy requirements in the App Store go beyond those of the letter of the law, and social media companies looking to escape those could force customers to choose between “losing touch with your friends online, or taking on the risks of sideloading.”

“Sideloading undermines security and puts people’s data at risk,” according to Federighi, and that if customers and regulators want the option to sideload apps, the alternative of Android should be enough to meet that without requiring it for iPhones. But all the concerns on iOS are curious, given the other half of his job description: leading the macOS software team, where apps can be freely installed outside of Apple’s app store (and have been for decades) without suffering from apocalyptic malware attacks.

If Apple wanted, it could enable iOS sideloading in a similar manner and require something like the Gatekeeper system on macOS, which allows for Apple to check signed developer IDs to confirm the software is genuine. It’s an argument that Judge Yvonne Gonzalez Rogers noted as well during the Apple / Epic trial, commenting that Federighi may be “stretching the truth” on Mac malware concerns and that Apple could likely make a similar system work on iOS.

And most notably, Federighi’s speech completely ignores the fact that by requiring all apps to be installed through the App Store, it forces all app commerce to flow through the App Store, too — where Apple collects its highly contested 30 percent cut, to the tune of billions of dollars every year.

Today’s Storystream

Feed refreshed 18 minutes ago Yes, it happened again.

T
External Link
T.C. Sottek18 minutes ago
My Twitch streamer of the week is Reapz.

Hello, night Verge. The admins are asleep, so I’m going to post one of my favorite streams.

I spend a lot of time watching Twitch, and I’m constantly amazed by the creativity of variety streamers. Today I’m calling attention to Reapz: an Aussie who has one of the most creative technical setups I’ve seen. With a virtual soundstage and desk, he’s created the closest thing I’ve seen to a late night host on Twitch.


N
Youtube
Nilay Patel12:43 AM UTC
I want to interview the Sony party speaker team so badly.

This is like the fifth or sixth generation of these things. What are their meetings like? Do they go to frat parties to get feature ideas? Why did they go from “Mega Bass” to “Extra Bass” for the past few years back to “Mega Bass” for this one? Is this one team’s passion project or do they hire mercenary party speaker engineers? Please, someone contact me.


M
Youtube
Mitchell Clark12:18 AM UTC
“You think Big Brother is watching you on the subways? You’re absolutely right.”

New York City is planning on adding two surveillance cameras to its subway cars, around 13,000 in total. The Gothamist pointed out governor Kathy Hochul’s (frankly incredible) remarks about the move.

She said the similarity to 1984’s Big Brother is intentional. “If you’re concerned about this, best answer is don’t commit any crimes on the subways.”


J
Twitter
Jay PetersSep 20
Control’s lead designer shared video of an early build of the game with in-development graphics.

Some have criticized GTA VI’s graphics seen in the videos that leaked this weekend. But this early footage of Control shows how even some of the best-looking games use placeholder assets during development that are improved upon for a game’s final release. I’m a big fan of the boxes with “THROW ME” printed on the sides.


M
External Link
Mitchell ClarkSep 20
Satellite-to-phone service is getting closer.

The FCC has given Lynk, one of the companies competing with SpaceX, T-Mobile, and Apple, a license to operate a commercial satellite-to-mobile communication service (though currently it’s only for coverage outside the US).

Lynk will still have to find a mobile carrier to work with and get FCC approval for that specific service, but it’s now cleared an important hurdle — plus, the company’s CEO told Fierce Wireless that it’s currently “working with testing” for two US carriers.


E
External Link
Emma RothSep 20
Crunchyroll looks ready to dump anime voice actors who push for union deals.

Kyle McCarley, the American voice of Shigeo “Mob” Kageyama in Mob Psycho 100, posted a video to YouTube, claiming Crunchyroll refused to even discuss a Netflix-like union contract ahead of S3.

According to Kotaku, the Sony-owned service confirmed it will “recast some roles.” McCarley’s voice fits the role of Mob so well it will be missed, but the consolidation of anime streaming rights leaves fewer companies to negotiate with — or watch.


Welcome to the new Verge

Revolutionizing the media with blog posts

Nilay PatelSep 13
J
The Verge
YouTube’s biggest defense against TikTok: money.

The company is going to start giving creators a share of ad revenue when commercials play between YouTube Shorts. The platform’s relatively generous payments are a large part of its rich creator culture, and now we’ll find out if they’re enough to lure short-form creators away from TikTok.


E
Twitter
Signal, the encrypted messaging app, gets free promotion from Twitter’s lawyers.

Last year, Elon Musk tweeted “Use Signal,” leading to a spike in new users. Twitter’s lawyers said in a footnote in a previous filing that Musk had been messaging with investor Marc Andreessen of a16z on Signal about a Twitter investment. The problem for Twitter’s discovery process is that Signal messages can be set to auto-delete; Musk’s lawyers maintain he doesn’t ordinarily use Signal for business. Now, there’s a sealed motion that.... contains Musk’s Signal tweet. 👀


A
Alex CranzSep 20
If you’re into the minimalist PC build then Nvidia’s latest GPUs might present a problem.

Nvidia finally announced the 40-series—specifically the more expensive and more powerful 4090 and 4080. But big power means these are some big cards and that could be a problem for PC builders who prefer smaller, minimalist looks for their PCs. Builders at the /sffpc subreddit, that focuses on small form factor pc builds, are already worried.


B
The Verge
A lot of people seem to agree that lock screen widgets are one of the best new features of iOS 16.

So we put together a how-to on customizing your iPhone’s lock screen and wallpaper with widgets and design options, and even linking them to Focus modes. It’s easier than you’d think.


M
Youtube
Mitchell ClarkSep 20
Apple replaced the iPhone 14 Pro’s SIM slot with a block of plastic.

iFixit’s teardown of the iPhone 14 Pro gives us a look at what’s behind the Dynamic Island, and does a good job of demonstrating why the regular iPhone 14’s removable back glass is so nice.

We also get to see what’s taken the place of the SIM slot: a bare PCB, and a plastic spacer. So useful!


A
The Verge
Andrew WebsterSep 20
Deathloop is out on Xbox Game Pass today.

If you subscribe to Xbox’s Game Pass service, you should definitely check out Arkane’s Deathloop, which is out now. It was one of my favorite games of last year when it debuted on the PS5 and PC, mixing extremely satisfying action with an intricate story about time loops. Here’s the full list of the latest Game Pass releases.


E
External Link
The SPAC-lash is here.

So remember the craze for SPACs, an alternative way to take a company public? The times, they have a-changed: the SPAC King of Silicon Valley, Chamath Palihapitiya, couldn’t find acquisition targets for two of his piles of cash. One of them, Social Capital Hedosophia VI, is the largest-ever SPAC.


R
Twitter
Richard LawlerSep 20
Use every (mega) pixel.

Halide is touted as one of the best photography apps on the iPhone, and as usual, it has a new update out to help you get the most out of the best camera available on the platform — that 48-megapixel sensor on the iPhone 14 Pro.

Version 2.9.0 of Halide is live in the App Store, with quick 48MP shooting directly to HEIC or JPG and many other new features.


N
Quote
Nilay PatelSep 20
Speaking of CarPlay.

Dan posted about CarPlay earlier and it reminded me that wireless CarPlay has actually set Apple back in its quest to somehow take over the car market — problems with it disconnecting are the number one complaint from new car owners, according to JD Power. Something to think about as Apple continues its relentless quest to remove all the ports from our phones.

The most frequent problem reported across the industry regardless of powertrain type or brand cachet related to smartphone connectivity. Dropped connections with Apple CarPlay was the number one problem, as Android Auto complaints leveled off from last year. Further, the number of reported problems with wireless Apple CarPlay increased as well, due to the feature being offered in more cars.