‘Sideloading is a cyber criminal’s best friend,’ according to Apple’s software chief


“Sideloading is a cyber criminal’s best friend and requiring that on iPhone would be a gold rush for the malware industry,” according to Apple senior vice president Craig Federighi, who delivered a dramatic speech at Web Summit 2021 declaiming the security risks if Apple were required to let users sideload apps.
Federighi, who oversees Apple’s iOS and macOS software divisions, was specifically protesting the European Commission’s proposed Digital Markets Act, which, if passed, would require Apple to let users install apps outside of the iOS App Store. According to Federighi, the lack of sideloading is what separates Apple’s relatively low rate of malware on iOS from the “5 million Android attacks per month,” and that if Apple were forced to let users install their own apps, “the floodgates are open for malware.”
Federighi also argues against a popular proposed solution of letting users decide for themselves whether to take the risk of sideloading apps. The problem is that “criminals are clever, and they’re really good at hiding in plain sight,” and that even informed users might get caught by misleading websites, or even get stuck with fake app stores installed on their phones.
And even if you, a tech-savvy smartphone expert, might not be fooled, Federighi plays on the heartstrings and asks the audience to think of the children or parents who might be fooled. “The fact that anyone can be harmed by malware isn’t something that we should stand for,” Federighi concludes, despite the fact that Apple still routinely deals with multimillion-dollar scams that the company only just added the ability to report in September.
Federighi’s picture of doom doesn’t just stop there, though: he also raises the concern that if Apple were to allow sideloading, “some social networking apps will probably try to avoid the pesky privacy protections of the App Store and only make their apps available via sideloading.” According to Federighi, Apple’s privacy requirements in the App Store go beyond those of the letter of the law, and social media companies looking to escape those could force customers to choose between “losing touch with your friends online, or taking on the risks of sideloading.”
“Sideloading undermines security and puts people’s data at risk,” according to Federighi, and that if customers and regulators want the option to sideload apps, the alternative of Android should be enough to meet that without requiring it for iPhones. But all the concerns on iOS are curious, given the other half of his job description: leading the macOS software team, where apps can be freely installed outside of Apple’s app store (and have been for decades) without suffering from apocalyptic malware attacks.
If Apple wanted, it could enable iOS sideloading in a similar manner and require something like the Gatekeeper system on macOS, which allows for Apple to check signed developer IDs to confirm the software is genuine. It’s an argument that Judge Yvonne Gonzalez Rogers noted as well during the Apple / Epic trial, commenting that Federighi may be “stretching the truth” on Mac malware concerns and that Apple could likely make a similar system work on iOS.
And most notably, Federighi’s speech completely ignores the fact that by requiring all apps to be installed through the App Store, it forces all app commerce to flow through the App Store, too — where Apple collects its highly contested 30 percent cut, to the tune of billions of dollars every year.
“Sideloading is a cyber criminal’s best friend and requiring that on iPhone would be a gold rush for the malware industry,” according to Apple senior vice president Craig Federighi, who delivered a dramatic speech at Web Summit 2021 declaiming the security risks if Apple were required to let users sideload…
Recent Posts
Archives
- February 2025
- January 2025
- December 2024
- November 2024
- October 2024
- September 2024
- August 2024
- July 2024
- June 2024
- May 2024
- April 2024
- March 2024
- February 2024
- January 2024
- December 2023
- November 2023
- October 2023
- September 2023
- August 2023
- July 2023
- June 2023
- May 2023
- April 2023
- March 2023
- February 2023
- January 2023
- December 2022
- November 2022
- October 2022
- September 2022
- August 2022
- July 2022
- June 2022
- May 2022
- April 2022
- March 2022
- February 2022
- January 2022
- December 2021
- November 2021
- October 2021
- September 2021
- August 2021
- July 2021
- June 2021
- May 2021
- April 2021
- March 2021
- February 2021
- January 2021
- December 2020
- November 2020
- October 2020
- September 2020
- August 2020
- July 2020
- June 2020
- May 2020
- April 2020
- March 2020
- February 2020
- January 2020
- December 2019
- November 2019
- September 2018
- October 2017
- December 2011
- August 2010