{"id":23164,"date":"2023-10-19T06:30:04","date_gmt":"2023-10-19T14:30:04","guid":{"rendered":"https:\/\/www.palada.net\/index.php\/2023\/10\/19\/news-16894\/"},"modified":"2023-10-19T06:30:04","modified_gmt":"2023-10-19T14:30:04","slug":"news-16894","status":"publish","type":"post","link":"https:\/\/www.palada.net\/index.php\/2023\/10\/19\/news-16894\/","title":{"rendered":"Apple\u2019s latest China App Store problem is a warning for us all"},"content":{"rendered":"<p><img decoding=\"async\" src=\"https:\/\/images.idgesg.net\/images\/idge\/imported\/imageapi\/2022\/09\/20\/11\/iphone-app-store-red-100932515-small.jpg\"\/><\/p>\n<p>Ask anyone who knows, and they\u2019ll tell you that when it comes to security, the weakest point is always people. Yet, as pressure grows for Apple to <a href=\"https:\/\/www.computerworld.com\/article\/3708248\/are-you-looking-forward-to-the-new-age-of-mobile-app-insecurity.html\">allow app purchases from outside the App Store<\/a>, the fact the company fired App Store staff for \u201cbusiness misconduct\u201d is cause for alarm.<\/p>\n<p>As first reported by <em><a href=\"https:\/\/www.theinformation.com\/articles\/apple-fired-app-store-staff-after-finding-improper-dealings-with-game-developers\" rel=\"nofollow noopener\" target=\"_blank\">The Information<\/a><\/em>, the Apple story is pretty simple.<\/p>\n<p>As a result of those \u201cinteractions,&#8221; it sounds likely some apps were given prominence on the App Store home pages, which helped boost sales.<\/p>\n<p>The report doesn\u2019t delve deeply into what actions these employees actually did, but I don\u2019t think that matters much.<\/p>\n<p>What matters is that App Store employees were compromised to provide business benefit to certain apps.<\/p>\n<p>Now consider this. <a href=\"https:\/\/www.applemust.com\/how-apples-app-store-saved-consumers-from-2b-fraud-in-2022\/\" rel=\"nofollow noopener\" target=\"_blank\">Apple runs a well-policed App Store<\/a>. The fact these problems were identified and action taken proves this, and while we don\u2019t know how long these events were taking place, the fact that the company was able to slam the brakes on things is a good thing.<\/p>\n<p>The matter exposes one of the biggest threats to App Store security: people.<\/p>\n<p>People can be corrupted or misled, so at what point will staff within these teams become targets for criminals, hackers, or worse? After all, if you can get your app promoted at the App Store with a few meals and a little entertainment, what will it cost to bribe members of the team to get an app carrying a malware payload into the store?<\/p>\n<p>What will the affect be on those maverick nations that are effectively <a href=\"https:\/\/www.computerworld.com\/article\/3705370\/new-law-could-turn-uk-into-a-hackers-playground.html\">legislating to make digital platforms less secure<\/a>?<\/p>\n<p>Apple has lots of protections against that, of course. And as of now, I can\u2019t recall a single App Store incident of this kind. As far as I know, malicious developers haven\u2019t been able to bribe bad apps into the Apple stores. Some have managed to trick their way in, and some have managed to break into the OS via different routes.<\/p>\n<p>But&#8230;<\/p>\n<p>While Apple\u2019s protection isn\u2019t perfect, what about the other stores? We know App Stores are going to proliferate soon. The EU will <a href=\"https:\/\/www.computerworld.com\/article\/3701368\/the-eu-data-act-is-a-lot-bigger-than-icloud.html\">force Apple to support third-party stores<\/a>, and once it does, the company will be forced to do so on a global basis over time.<\/p>\n<p>But not all those competing stores will be as well resourced, managed, or policed as Apple\u2019s own digital retail outlet \u2014 and there will be a lot of them, at first. Obviously, the cost of running these stores and the challenges of attracting customers to them mean that in a relatively short time, just a handful will remain in business; the so-called benefits of \u201cfree market competition\u201d will only mean a <a href=\"https:\/\/www.applemust.com\/morgan-stanley-microsoft-may-threaten-apples-app-store\/\" rel=\"nofollow noopener\" target=\"_blank\">slightly larger number of people share the cash<\/a>.<\/p>\n<p>That\u2019s how these things work.<\/p>\n<p>Most of the time when people arguing over money talk about \u201cfreedom,\u201d the only liberty they really crave is freedom to grab as <a href=\"https:\/\/www.computerworld.com\/article\/3571426\/epic-vs-apple-is-not-about-freedom.html\">much of it as possible<\/a>. Your insecurity is far less important than their profit.<\/p>\n<p>With a lot of stores in open competition for apps and customers, money will be tight and most smaller operators won\u2019t be able to deliver the <a href=\"https:\/\/www.computerworld.com\/article\/3636244\/apple-warns-sideloading-apps-threatens-an-icrime-wave.html\">same degree of protection<\/a> larger retailers provide.<\/p>\n<p>Staff turnover will likely be frequent, salaries low, and business stakes high. This is a perfect environment in which <a href=\"https:\/\/www.computerworld.com\/article\/3694132\/security-researchers-uncover-nso-group-iphone-attacks-in-europe.html\">nation state or organized criminal gangs<\/a>\u00a0will approach staff to find out what they can get for a few meals and a little \u201centertainment.&#8221; It\u2019s really a no-brainer that at least one store will be compromised and at least one app containing malware and\/or surveillance code given a high profile on one of these independent stores.\u00a0<\/p>\n<p>While the relative reach of smaller stores may be much less than Apple\u2019s, you can bet your last dollar that the first company customers tricked into installing such malware will go to for help will be the one headquartered in Cupertino.<\/p>\n<p>It\u2019s a nightmare waiting to happen, and this latest Apple App Store story shows how likely this dark dream will be realized.<\/p>\n<p>(This already happens on some Android stores, of course).<\/p>\n<p>Given the sheer quantity of data on digital devices, and the vast difference in tech knowledge across the globe\u2019s billions of users, the impact of such theft will be a quantum scale worse than a hacked PC.<\/p>\n<p>As the App Store economy gets \u2018liberalized,&#8221; IT would do well to mandate which stores should be used by managed devices. And it seems plausible that enterprise tech will need to closely examine each store\u2019s privacy and security policy before permitting employees to get software there.<\/p>\n<p>That&#8217;s particularly true as <a href=\"https:\/\/www.computerworld.com\/article\/3705613\/three-quarters-of-large-us-firms-now-using-more-apple-devices-survey.html\">more and more Apple devices are used across the enterprise<\/a>.<\/p>\n<p><em>Please follow me on\u00a0<a href=\"https:\/\/social.vivaldi.net\/@jonnyevans\" rel=\"nofollow noopener\" target=\"_blank\">Mastodon<\/a>, or join me in the\u00a0<a href=\"https:\/\/mewe.com\/join\/appleholics_bar_and_grill\" rel=\"nofollow noopener\" target=\"_blank\">AppleHolic\u2019s bar &amp; grill<\/a>\u00a0and\u00a0<\/em><a href=\"https:\/\/mewe.com\/join\/apple_discussions\" rel=\"nofollow noopener\" target=\"_blank\"><em style=\"font-weight: inherit;\">Apple<\/em>\u00a0<em style=\"font-weight: inherit;\">Discussions<\/em><\/a><em>\u00a0groups on MeWe.<\/em><\/p>\n<p><a href=\"https:\/\/www.computerworld.com\/article\/3709090\/apples-latest-china-app-store-problem-is-a-warning-for-us-all.html#tk.rss_security\" target=\"bwo\" >http:\/\/www.computerworld.com\/category\/security\/index.rss<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p><img decoding=\"async\" src=\"https:\/\/images.idgesg.net\/images\/idge\/imported\/imageapi\/2022\/09\/20\/11\/iphone-app-store-red-100932515-small.jpg\"\/><\/p>\n<article>\n<section class=\"page\">\n<p>Ask anyone who knows, and they\u2019ll tell you that when it comes to security, the weakest point is always people. Yet, as pressure grows for Apple to <a href=\"https:\/\/www.computerworld.com\/article\/3708248\/are-you-looking-forward-to-the-new-age-of-mobile-app-insecurity.html\">allow app purchases from outside the App Store<\/a>, the fact the company fired App Store staff for \u201cbusiness misconduct\u201d is cause for alarm.<\/p>\n<p>As first reported by <em><a href=\"https:\/\/www.theinformation.com\/articles\/apple-fired-app-store-staff-after-finding-improper-dealings-with-game-developers\" rel=\"nofollow noopener\" target=\"_blank\">The Information<\/a><\/em>, the Apple story is pretty simple.<\/p>\n<p class=\"jumpTag\"><a href=\"\/article\/3709090\/apples-latest-china-app-store-problem-is-a-warning-for-us-all.html#jump\">To read this article in full, please click here<\/a><\/p>\n<\/section>\n<\/article>\n","protected":false},"author":4,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"colormag_page_container_layout":"default_layout","colormag_page_sidebar_layout":"default_layout","footnotes":""},"categories":[11062,10643],"tags":[2211,11063,10480,8826,10554,11066,714,24580],"class_list":["post-23164","post","type-post","status-publish","format-standard","hentry","category-computerworld","category-independent","tag-apple","tag-data-privacy","tag-ios","tag-iphone","tag-mobile","tag-mobile-apps","tag-security","tag-small-and-medium-business"],"_links":{"self":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/23164","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/comments?post=23164"}],"version-history":[{"count":0,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/23164\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/media?parent=23164"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/categories?post=23164"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/tags?post=23164"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}