Michael Chertoff, who was the second United States Secretary of Homeland Security to serve under President George W. Bush, and the co-author of the USA PATRIOT Act, says that the U.S. government should abandon any legislation to mandate unrestricted side-loading of apps due to significant security risks.
Michael Chertoff for TechCrunch:
The Open App Markets Act, a bill that would, among many other things, require device makers to allow for the installation of unvetted applications on users’ mobile devices, won the approval of the U.S. Senate Judiciary Committee earlier this month.
This legislation [if passed and signed into law; a big “IF” – MDN Ed.] would confront the “walled garden” app distribution model, in which applications can only be installed from official app stores, that has been in place since the early days of smartphones…
This part of the proposed legislation introduces unintended, but potentially significant, device security risks by allowing app deliveries through unsupervised channels.
Poorly regulated app stores, like many found in China, are breeding grounds for compromised apps filled with malware. Inadequately regulated app stores lacking the most basic of security checks increase the risk to consumers by making it easier for users to download a compromised app that may steal their data or defraud them…
Fortunately, Congress can impose security standards on the new app stores that can help protect consumer end users.
First, they can require stores to have a base level of security review and monitoring of apps, including human review. Human review helps to ensure that the permissions used by the app reflect the app’s advertising, a step vital to preventing malicious apps from doing things they aren’t supposed to.
Second, the U.S. and other governments should abandon plans to mandate unrestricted “side-loading” — the risk to the average end user is simply too great when they can install an unknown app in a few clicks with no understanding of accompanying security risks.
MacDailyNews Take: Putting aside the richness of the co-author of the USA PATRIOT Act warning of unintended consequences, Chertoff agrees in principle with Apple CEO Tim Cook who, in June 2021, said that side-loading apps would “destroy the security” of the iPhone. If Apple had to allow side-loading, Cook explained, then features like App Store nutrition labels and App Tracking Transparency “would not exist anymore.”
I would say [side-loading] would damage both privacy and security. I mean, you look at malware as an example, and Android has 47x more malware than iOS. Why is that? It’s because we’ve designed iOS in such a way that there’s one App Store and all of the apps are reviewed prior to going on the store. That keeps a lot of this malware stuff out of our ecosystem. Customers have told us very continuously how much they value that. And so we’re going to be standing up for the user in the discussions and we’ll see where it goes. I’m optimistic, I think most people looking at security know that security is a major risk. – Apple CEO Tim Cook, June 16, 2021
Please help support MacDailyNews. Click or tap here to support our independent tech blog. Thank you!