Main menu

Pages

Apple on the attack! Company cites sideloading for Android malware issues

It’s no secret that the late Steve Jobs despised Android and considered it a blatant rip-off of iOS. Jobs said he wanted to destroy Android and would do so even if it meant wiping out Apple’s cash. To the average layman, the two operating systems appear to be similar, but there are huge differences, as phone enthusiasts know.

Apple blames Android malware for platform’s ability to sideload apps

Where iOS is, to use the typical cliché, a “walled garden”, Android is open, giving users the ability to customize their devices to their liking. And while Apple has recently borrowed from Android (the use of home screen widgets, the new customizable lock screen coming in iOS 16 are two examples), an Android feature that Apple is adamant not to ever offer is the ability to download apps.

Android users have the option of installing apps from third-party app stores. It’s called sideloading and Apple has been under pressure from both domestic and foreign governments to allow it on the iPhone. Europe’s recently passed Digital Markets Act (DMA) could force Apple to allow sideloading on its devices (while providing some sort of cross-platform support for messaging and allowing third-party payment options for iOS apps).

Not that side loading is without problems. Allowing the use of third-party app stores beyond Apple’s control could lead iPhone users to accidentally install malware on their handsets. The Senate Judiciary Committee called Apple’s stance on sideloading “baseless, bad faith, and dishonest.” But Apple did a favor with a strongly written letter to the committee that was obtained by 9to5Mac.
The letter, dated March 3, was signed by Apple’s senior director of government affairs, Timothy Powderly. “Not a single one appeared to use a ‘technical exploit’ to gain access to the device or perform its attack. These apps all operated within the security boundaries of the operating system, with no exploit required.”

The letter notes that Kaspersky security researchers came to the same conclusion. Kaspersky blamed the malware found on Android phones for cybercriminals “passing off one malicious app as another popular and desirable one. All they have to do is correctly identify the app, or at least the type of apps, that are currently in demand.”

Apple asks Congress to maintain the status quo

You can read what’s going on here. In an effort to defend its no-sideloading policy, Apple blames sideloading for all of Android’s malware issues. Apple’s Powderly wrote: “On Android, apps offered outside of the official store and claiming to help protect user security are, with some frequency, found to be malware. For example, it was recently discovered that a
The Android app claiming to be a two-factor authenticator was also used to deliver malware designed to steal sensitive financial data from the user.”

In a comment to cryptographer Bruce Schneier, who told lawmakers that Apple’s sideloading concerns were “unfounded,” the letter said, “Mr. Schneier is correct that ‘sophisticated malware,’ often used by state-sponsored attackers, can bypass device security.But on iPhone, this sophisticated malware is very complex, costs millions of dollars to develop, and often has a short lifespan. strives to protect users against all threats, including this type of malware, the vast majority of users will never be the target of such attacks.”

Apple adds that “to focus the discussion on this rare threat, we miss what really harms millions of users every day on other mobile platforms: social engineering attacks, a threat ‘Apple’s App Store was incredibly good at removing’. The letter ends with a message to lawmakers: “We hope Congress preserves consumers’ ability to choose the safest option for themselves and their families.”