Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Isnt the whole point of $99 and rigorous checks, and not to mention, all the marketing and legal claims, to say that Apple's App Store review process is foolproof and necessary for their platform?

Also, so funny how 9to5mac messages this. When Apple makes a misstep, it is developers "tricking" App Store, not Apple's incompetence. Lets call it what it is, Apple's review process is mostly security theater.



But then what isn’t? You can’t check everything/everybody. Pyrotechnics are forbidden at football stadiums, there are security at the entrance but they get them inside anyway. Goods of stores with security still get stolen. Smuggling still exists.

There is no 100%


To use your analogy, the Apple stadium security will probably not let you in if you are visibly carrying pyrotechnics, but if you have a large backpack they aren't likely to look inside. In order to give the illusion that they have good security they also pick many people at random and refuse them entry and make up a reason on the spot.


That sounds all lot like pick any security/police at any event, because they don’t like your face.


Security will always start with strong software guarantees, not "guidelines" enforced arbitrarily. See the web which is doing better on this subject.


It is? The last time i checked i can easily watch a pirated movie while downloading malware on arbitrary websites…


Yeah and the top apps on the iPhone are basically half-legal casino games. At least on your example you have to search for it and disable all warnings.


Well any ad from a normal site can bring me to a shady site. The barrier to install an app is much bigger imho.


I don't think it is, nobody has any idea how many apps are really installed on their phone, not to mention the hidden built-in apps.


Most corporate security is a security theatre. I saw an InfoSec consultant on LinkedIn argue that she does not need to be technical to be a security professional. Works in banking. I wouldn't be surprised if Apple had to outsource app reviews to an offshore partner, because of the sheer number of apps submitted. Quality falls at volume.


A lot of security is human and process based. Technical is important, but the best software in the world won't survive someone being social engineered.


The best software in the world is actually explicitly designed to survive being social engineered. Launching a nuclear ICBM requires more than 4 levels of remote authorization and combined secrets from 2 trusted sources that live offsite. Being "social engineered" in a situation like this means torturing a half-dozen military personnel for confidential keys you can't even validate.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: