Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

>Apple's own apps are still blessed with permissions that other apps have to ask for. This needs to be addressed too.

This is a strange position imo. Why would we expect third party apps written by totally unknown people with unknown goals to have the same permissions as apps written by Apple itself?



Because not doing so hampers competition, it gives Apple’s first-party apps an unfair advantage over third-party alternatives.

Also, I don’t actually know Apple’s developers and their goals.


But you likely feel somewhat comfortable with them if you purchased an iPhone.

Purchasing an iPhone self-selects people who are comfortable with the idea of the features it is marketed as having, such as being able to take, store and manipulate photos out of the box.

This is also an issue primarily because there is no third-party photo picker extension point. A third party only gets photo picker support if they store their photos into the Photos library. If third party photo apps could have similar integration points based on them maintaining their own first-party library, they would not need to ask permission to manipulate another program's data store.


I’m not more comfortable with them as with third-party apps that I choose. Either of them are products that I sought out.

I agree that the photo picker should integrate with third-party photo apps just the same.


Requiring Apple's own apps to use the same permission prompts as 3rd party apps does something very important: it incentivises Apple to improve the permissions experience for all developers.

Currently, the permissions APIs and user experience are designed horribly, and there's a disincentive for Apple to fix it.

Random example: if you write into the photo library, you don't have permission to read back what you wrote. You can't even deep link to that media in the photos app*

*Unless you are Apple.


I thought the appstore was safe because of its vetting, at least that's what they officially say


I don't think that is contradictory either. By limiting 3rd-party permissions, Apple is able to prevent many potential issues before an application even makes it to the vetting process. The less there is to vet, the more robust the vetting process should be in theory.


Idk what their vetting includes but I doubt it's a full security audit of the codebase of each app for example and so without something like that why would you ever expect a 3p app to get the same permissions as an Apple internal one?


Personally I don't, I would just downgrade the Apple permissions to match normal apps, I'm just pointing the doublespeak


Which essentially makes the phone a brick and unusable for 99% of consumers. Average users don't care about your weird esoteric privacy and security concerns.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: