Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Notepad computers don't kill people, worst case your stuff doesn't work and they won't use it again.

This is not 'mission critical' by a long shot.

It all boils down to the safety vs freedom argument, we can be 100% safe or we can have a lot of freedom. Personally I'll take the freedom, if you want to be 100% safe but only able to run vendor approved applications then that's fine with me, but it is one step too many in the direction of 'trusted computing' for me.



No, worst case your app steals their credit card info (witness the recent Android bank phishing app) and costs them tremendous time and bother (not to say potentially money) cleaning up the mess.

In this case, at the first sign of malwareism, Apple can disable the app immediately for everyone, limiting the damage.


Phishing requires active participation by the end user, you can't protect against stupidity.

Do app store applications have the source code audited?

Will Apple take responsibility if something like that were to happen to the iphone?

Besides, I already said I'm fine with malware scans, what they could simply do is audit and release a key that approves the app.

If you install an app that was not vetted you're on your own.


> "you can't protect against stupidity."

Trusting that an app on the Android marketplace is who it says it is is not stupidity. Honestly, this sort of geek arrogance ("but surely you must've known to discombobulate the zorgotron before you bazzed the foobar!") is what turns people off to geek-friendly platforms.

> "if something like that were to happen to the iphone?"

Apple at least vets who you say you are supposed to be before publishing your app. It's questionable if they will take responsibility if something makes it through, but the idea is that they're doing due diligence up front, Android is apparently not.

> "Besides, I already said I'm fine with malware scans"

This isn't malware that a malware scan will pick up. It doesn't try to take root, it doesn't nuke your files, and in fact it doesn't do anything a banking app is not expected to do. No amount of port blocking will save you, since everything this app does (according to the OS) is fully expected.

> "If you install an app that was not vetted you're on your own."

Yet... One side vets the app for you, the other one carries itself like an authoritative safe haven, but in fact isn't. Any wonder why people flock to the iPhone App Store?


If you install an app that was not vetted you're on your own.

This is why I think Apple should sell a "Pro" version of this kit that comes with an unlocked "sandbox". I envision something that looks more like OS X, with a "iPad" app that flips you to the locked iPad OS. On the iPad side, there would be an "OS X" app that would flip you back over to the sandbox. Actually, both environments would be virtualized, so they'd be well insulated from each other.


Actual case of an approved App-store app making premium-rate phone calls without informing users: http://www.theregister.co.uk/2010/01/27/iphone_admob/


So, Apple will make sure any user accessing email from the iPhone/iPad won't go after the money he just inherited in Nigeria.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: