Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Looking at Android, where sideloading has been available forever, there doesn't seem any evidence of your worry.


Apple will make it annoying enough to sideload that no meaningful amount of users will do it, causing it to be largely irrelevant.

It’s only worth it to app makers to have side loading if they can do it for large numbers of users, bypass the app store’s rules, and bypass apple’s take. I’m expecting apple to set it up in a way they can do none of those things, by making it cumbersome to sideload, not giving entitlements to apps not published through the store, and by taking a cut for sales from sideloaded apps.


It is already annoying enough without Apple needing to do anything.


Recent example: https://www.reuters.com/technology/google-suspends-chinas-pi... Malicious app in alternative store, the one in Google Play is different.


That's exactly the point, though: side loading is not something to worry about, since normal users won't and shouldn't care about it at all. It is not a threat to the Apple App Store.

But it does allow for niche applications such as NewPipe and F-Droid, for technical users who know the risks.


Almost everyone in China uses alternative stores, like Huawei or Xiaomi; how else do you think malicious PDD app got on their phones? The same applies to other counties in South-East Asia. I have seen our app for Android repackaged with malware and uploaded to an alternative store and listed there with hundreds of thousands downloads.


> how else do you think malicious PDD app got on their phones?

The malicious PDD app is really, actually, published to the alt stores by PDD Holdings itself. It loads the exploit config and post exploitation modules from PDD's own CDN.

It's not the same repackage-with-malware shit plaguing China/SEA market since forever. It's first party.

And the Google Play version contains the same exploit delivery codes, though no real evidence that it was activated.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: