To view parent comment, click here.
To read all comments associated with this story, please click here.
It's a very poor design that will likely be exploited.
As much as geeks lament the locked down nature of the App store it does have a pristine security record.
There's more to improving the security of applications than your list shows, there is also developer verification which is part of the App store application process.
As for binary security checks they can be performed with software. Not 100% effective but when combined with developer verification you have a strong deterrent.
You can be dismissive of the app store but it has an excellent security record that cannot be denied.
What do you call developer verification exactly ? Some kind of digital signing that (is supposed to) identify the guy who submitted the app ?
Moreover, I agree that the App store has an excellent security record... But it's just like Nokia's Ovi Store, Microsoft's Marketplace, Android's Market, RIM's I-don't-remembler-how-they-called-it or even the old $5 java games download pages in that respect : there are only little to no recorded exploits in each case, so we can't make conclusions yet. It'd be like saying "Oh, dammit, those mobile OSs are so much more secure than Windows !".
To get a good picture, we should have good data in the form of hundreds of recorded exploits. Which the mobile phone repository system does not have yet, because it's just an uninteresting target at the moment. Plus, it lacks global penetration on the market : at the moment, smartphones still are mostly used by geeks and some executives who want to show how rich they are because they can...
Edited 2010-06-25 10:30 UTC
It's just a repository where package are checked before admission. Tons of these exist in the rest of the computing world. I'm not dismissive of that, as long as it's coupled with other strategies. What I don't understand is why the App Store is presented like some kind of revolutionary product.
Edited 2010-06-25 10:35 UTC





Member since:
2010-03-08
http://blogs.forbes.com/firewall/2010/06/21/researcher-builds-mock-...
Those are security defects, which indeed require patching, in the Android operating system, not in the market model. The previous posts were about the App Store model, not about iOS' specific implementation.
(I won't be advocating Android facing iOS, since in my opinion both operating systems are canned crap. In fact, I think that the whole touchscreen smartphone idea has only spawned canned crap in all of its current implementations, though Windows Phone 7 Series looks somewhat promising if they sell it on phones with a physical keyboard)
You're welcome, sir =p
Edited 2010-06-25 09:07 UTC