Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

The huge, HUGE advantage that the App Store brings to the average consumer is a feeling of safety. An app installed from the App store:

- Can be uninstalled easily, and leave no trace behind (remember "Register cleaners"?)

- Cannot interfere with other apps

- Cannot run in the background and spy on your surfing habits

- Cannot steal your credit card information and upload it to Russian mafia servers

For a long time, the standard geek response to these problems is "that's the user's problem -- they should be more careful about what they install". The response appears to be "fuck you, I don't want to waste my time worrying about whether this purple monkey screen saver will secretly empty my retirement account."

If you can find a way to make this "free and open" system also safe, then I think you'll have a winner.



All of them are solved by sandboxing and permission mechanism.

"Fuck you, I don't want to waste my time" is actually the response developers should be giving to Apple when they are made to wait more than a month for their app to be reviewed and finally it gets rejected for a political, ideological, arbitrary, or personal (competes with an Apple service) reason.


Much as I love Android, and much as the Android team has done yeoman's work on this front...

Sadly, today, the more accurate statement is all of them are theoretically solvable by sandboxing and permissions mechanisms. Getting those sandboxes and permissions where they need to be at a technical level, explaining those permissions to users in a way they can understand and make decisions based on and making the overall framework as transparent and usable enough is very much an unsolved problem.


What I meant was, this is the correct approach. The implementation is not necessarily perfect. But in my opinion, it is much better than Apple's approach, which actually gives the world a bigger problem: A company deciding what software I can install on my device and what software I cannot.


My preference is that Apple keep doing what they're doing but also take a less aggressive approach to jail breaking phones.

As someone who gets dragged in to sorting out the IT issues of friends, family, neighbours and who knows what else, there is a lot of benefit to the Apple approach at what is for most people, little real cost.

The problem is the absoluteness of their position. I don't mind if they make people jump through hoops to jailbreak phones, I don't mind if their default support position for phones is to restore them to factory settings before they'll even look at it, but I think allowing for the possibility of jail breaking as an accepted thing would be good for both choice, and making sure Apple stay honest.


Yes, absolutely.

I just think it is important to remember where the weaknesses are and why some people are making an alternative tradeoff.


Whilst you are technically correct, I don't think this is what most people would have in mind when they are thinking of "open" systems.

Have a think about the types of application that are trotted out when people want to point out the advantages of open android :

a) new virtual keyboards - not possible with sandboxing

b) new launcher screens - not possible with sandboxing

c) access to data from other apps - not possible with sandboxing

Or rather, if you can do these things with sandboxing, then sandboxing is not providing the protection that you need. How do you guarantee that the funky new keyboard you just downloaded isn't actually a keylogger sending all of your passwords to a server somewhere for nefarious purposes. Or less nefariously, how do you know that the new keyboard hasn't forgotten to implement a special key that is necessary fo you to use application X. How do you go about backing out that installation of the keyboard, including the reinstallation of the default keyboard?

On the other hand, if you protect against these problems of security and confidence that an app won't break the system, what exactly are the advantages that such a system would have compared to a closed system such as Apple provides?


Did you ever stop to think that, despite this being a potential problem, why it has not been a problem?

Android isn't an immature product. google have activated something like 300 million devices. 300 million opportunities for your theoretical issue to manifest and yet it hasn't.


No, of course I didn't stop to think, that would just be a waste of my time - much better to just send off a response without any thought what so ever...

Of course, back in reality, I do actually know someone that installed Swype on their Android phone, didn't like it, and couldn't figure how to get back to the default keyboard, so I don't know why you think these types of problems aren't already cropping up in the Android world.


New keyboards have to be manually activated in Android, via the same mechanism that you'd use to switch to the default keyboard, so that honestly sounds like a pretty straightforward PEBKAC (heh) problem.

Turning on Swype implicitly trains you in how to turn it off.


Point 1 and 2 have nothing to do with the App Store. Android does the same.

3 & 4 are not prohibited by the App Store review process.

Of course, the iphone app can steal all kinds of information on your phone and send it to russian servers.

Do you really believe the App Store review can prevent malware?

Or are you really only talking about the _perception_ of the App Store review process?


> The response appears to be "fuck you, I don't want to waste my time worrying about whether this purple monkey screen saver will secretly empty my retirement account."

With the amount of non-techies I know with jailbroken phones with all kinds of super-tacky OS hacks installed, that is definitely not the only response.


Maybe you're forgetting the whole "why does Angry Birds need to know my phone number and have access to my contacts etc". The iPhone NEEDS a firewall so we can selectively block apps from calling home and sending usage data back every time you use them, and other data that we otherwise did NOT grant permission to do so when we installed the app.


Indeed the feeling of safety from the app store is important. However I'd rephrase your last sentence as "If you can find a way to make the "free and open" system seem safe enough that average users believe it's safe then you have a winner".




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: