Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Again, none of that requires the walled garden.

Epic tried to stare down Google, wielding peak Fortnite as a crowbar, and Epic still came back to the Play Store with its tail between its legs.

The App and Play store still offer phenomenal discoverability (warts and all).

Sideloading wouldn’t be a default and thus something only a tiny percentage of users does, probably deterred even further by the myriad of warnings Apple will spam at you.



Sideloading comes with plenty of downsides.

It's a source of malware and viruses. It prevents the ability to unsubscribe in one place. It allows apps to use private APIs which Apple can't prevent (i.e. Obj-C dynamic dispatch) thus opening up all sorts of attack vectors e.g. "phone" apps that record conversations etc.

And I assure you that it wouldn't be a tiny percentage of users if companies like Facebook would use it to do a run-around Apple's privacy controls. Sideloading could unlock tens of billions in lost advertising revenue to many companies.


You can't have everything. I personally side with a device I can modify.

I think generally in Android there are enough warnings (those with timers and large "SECURITY RISK" warnings that are difficult to ignore) when enabling side loading, and also going out of the way to download malware apks in the first place, that the number of affected users has to be quite low. And you can have default on malware scanning too (which I believe Google Play does). Also you can malware scan before install as well. I think this is low enough risk that the benefit is greater than disabling it entirely.

Same could be said for allowing root and different OS install. I could install something very insecure or make bad choices. But then I want to have that choice, and I think it shouldn't be so easy that users would just do it by chance. We need to remember there are other social engineering attack vectors against the most secure systems (like asking for passwords, or even asking to lend the phone and so on) too. The attacks I hear on Android users recently mostly seem to be related to hijacking SMS auth and so on -- I really don't believe side loading has proven to be a large security issue at all (or other OS images for that matter).

In fact I think they should be making installing alternate OS images and alternate app store easier, if Google wants to earn my vote of confidence (at least as far as Android goes) :)


None of those are intrinsic to sideloading.

Those private APIs also mean Apple gets to play favorites with its own apps in a lot of ways, which they have.

> And I assure you that it wouldn't be a tiny percentage of users if companies like Facebook would use it to do a run-around Apple's privacy controls.

This was addressed by my Fortnite example already.

All in all, if you don’t like sideloading, you’ll never have to engage with it.

I hate this kind of attitude, and it’s the same as the office lovers trying to prevent WFH as much as possible. Stop trying to lock us both in the cage because you’re too afraid to step out of it.


I will have to engage with side-loading though.

Apps like Facebook, Instagram, Twitter etc will immediately move because they would be able to side step Apple's privacy controls. Billions are on the table here. Outlook will move because they can tie the app to Edge which will now be able to use JIT.

And a bit hypocritical to say that I should stop locking us both in a cage when it's your choice to be in there. Support companies who allow side loading. Win win for everyone.


I will refer you to my Fortnite example for a third time. Good day.


Epic and Meta are not the same size.


> Those private APIs also mean Apple gets to play favorites with its own apps in a lot of ways, which they have.

While I shouldn’t be surprised, I’m always surprised that a technical audience brings up the “private APIs” bugaboo. Once you make an API public, you have to continue to support it warts and all. Apple should dog food their own stuff before they make it public.

On the other hand, do you expect Apple to make every API available to random developers?


Should Apple be allowed to kneecap competitors products (e.g smartwatches?)? They pretty clearly keep APIs to themselves to make their own products seem better. It's one thing to keep an unpolished rapidly changing API out of view and another to prevent competitors from doing the same thing on your platform that your 8th generation product does.


Do exactly which private API is used to “kneecap” competitors?


Things like replying to messages via. the watch. On iOS the ONLY watch allowed to do this is of course the Apple Watch.


This is not true.

You can reply to messages from Slack on your watch and it use to be better when they had a Watch app 5 years ago.

https://www.techradar.com/news/slack-is-dropping-its-apple-w...


Where did I mention Slack? I say "messages" and you assume Slack? Seriously? Also WTF does that article have to do with non-Apple smartwatches being unable to reply to message notifications on iOS?

You can not reply to SMS or iMessage notifications on non-Apple smartwatches. It's not allowed.


What are you talking about then? Using a third party app that can reply to your iMessages or SMS? Why in the heck would I trust a third party for my SMS messages?

But as far as third party watches replying to SMS/iMessages, they could do it just like you respond to messages from cars before CarPlay was a thing - you support the appropriate Bluetooth profile.

Microsoft did it on computers without official Apple support

https://www.theverge.com/2023/3/24/23654672/microsoft-phone-...


I'm talking about replying to SMS/iMessages from a non-Apple smartwatch. For example, with my Garmin watch on Android I can do things like send a canned message like "Yes" or "On my way" or whatever from the watch itself in reply to a notification. This is not possible on iOS with a non-Apple watch.

Why wouldn't you trust it? Yes, in theory a smartwatch could abuse my trust and send my friends spam or something but so could some no name Bluetooth keyboard yet I can use those just fine on iOS. Why should APPLE get to decide what devices I trust?

Microsoft did a hacky workaround with a whole host of limitations that proves my point. Apple is keeping the proper way to do it to themselves to make their products seem better.


There is a standardized Bluetooth protocol called the “Messaging Access Protocol”. Any Bluetooth device that you connect to the phone can work with that protocol and send and receive messages. It worked with my old 2011 Ford Fusion.

The iPhone has supported that for at least a decade.


Ok? Maybe it's unsuitable for a smartwatch (e.g power draw)?

This is a limitation common across non-Apple smartwatches on iOS. If it was SO simple you'd think they'd all do it and wouldn't have taken Microsoft 5+ years since the rollout of Phone Link.

I get that you love Apple but my man they are not the good guy you seem to believe. Have fun living in the reality distortion field, I hope you wake up one day.


So you went from “it doesn’t exist”, “Apple doesn’t support it”, “it’s a hack” to “maybe it’s too much of a power draw?

> Have fun living in the reality distortion field, I hope you wake up one day.

Yes a standardized Bluetooth profile that has been available on iOS devices for over a decade is “not reality”.

And now your excuse is that “maybe Bluetooth takes too much battery life”?

> This is a limitation common across non-Apple smartwatches on iOS

Have you ever thought that Android devices makers who are competing on price decide it’s not worth making the investment in supporting iOS devices since the Apple Watch is so dominant?

I told you exactly how it could be done using an existing Bluetooth standard that Apple has supported for over a decade. You’re really pulling at straws.

You could also at one point send “canned messages” from third party watches before the Apple Watch was introduced.

And here is an existence proof

https://help.fitbit.com/articles/en_US/Help_article/2344.htm....

And I’m sure that’s all crappy Android watch makers with horrible processors and battery life would have to do to convince Apple Watch owners to switch is to enable message replies.


Use quick replies to send customized responses to text messages and messages from certain apps with Fitbit Charge 3, Fitbit Charge 4, Fitbit Charge 5, Fitbit Inspire 3, Fitbit Ionic, Fitbit Luxe, Fitbit Sense series, or Fitbit Versa series. This feature is currently available on devices paired to an Android phone . Devices paired to an iPhone can respond to Fitbit app notifications, such as messages, cheers, taunts, and friend requests.


In the finest tradition of Jean-Louis Gassée:

The app store is a condom (or a covid mask). It's not all about "you"; it doesn't matter a damned sight if YOU are careful, or if YOU are responsible. Other people can make god-awful decisions that screw you over, and you have no power to stop them. Or rather: the app store IS your power to stop them.

I can't count the number of times I've seen windows users get duped by phishing that gives a bad actor root access. If that's your family member, that's YOUR problem; it doesn't matter if you were super careful — if your 18 year old son fucks up because he just didn't realize he was getting hacked, well — you're liable. That's what regulations are about; just like the FDA, just everything else.

I like having a platform where there is no fear. Same reason I like vaccines, same reason I like food safety regulations, etc. It's about network effects.

———

The worst thing about all this stuff is: when tragedies like this happened back in the day (and I remember, clearly, friends having their drives get wiped by script kiddies) — you suffer in silence. You sob and cry about whatever happened to you, and try to "raise awareness" in the open-source community about how maybe we should do something better, and nobody listens.

A lot of this stuff in the OSS community reminds me of gun nuts and school shootings; people wring their hands when a personal tragedy happens, the solution is right in front of them should they dare to actually adopt it, but they refuse to adopt it because it's ideologically untenable. So they just pretend the problem never happened until it personally hits their own family — and the worst thing is watching their friends, around them, engage in the same denial.

The two "real consequences" are losing your data (drive wipes, randomware, etc), and financial fraud (someone getting your CC number or bank access). I personally know people who've been hit by this. It's heartwrenching when it happens.

Have the political will to adopt the solution.


And Facebook used sideloading to spy on people to the point apple revoked their certificate

https://arstechnica.com/gadgets/2019/01/facebook-and-google-...

https://techcrunch.com/2019/01/29/facebook-project-atlas/

Given history, this feels pretty dismissive.


Fortnite is back off the Play Store for a while.




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: