Federico Viticci, writing for MacStories.net:
The f.lux team has built an iOS version of the app – unfortunately, they can’t release it publicly due to App Store restrictions. So, they’ve come up with a beta version that anyone can install with a free developer account and Xcode on the Mac.
This is interesting, but obviously presents certain dangers, since you’ll be running code that has not been vetted by Apple.
Imagine if, like on the Mac, Apple provided a framework to distribute and install iOS apps outside of the App Store with some security in place and a UI to manage sideloaded apps. Until a couple of years ago, it seemed obvious that it would eventually happen on iOS too.
Here, Federico is referring to Gatekeeper. From Apple’s official Gatekeeper page:
For apps that are downloaded from places other than the Mac App Store, developers can get a unique Developer ID from Apple and use it to digitally sign their apps. The Developer ID allows Gatekeeper to block apps created by malware developers and verify that apps haven’t been tampered with since they were signed. If an app was developed by an unknown developer—one with no Developer ID—or tampered with, Gatekeeper can block the app from being installed.
Not sure why this approach couldn’t work on iOS. Perhaps it’s a level of control that Apple is unwilling to relinquish.
I’m not at all sure why we need this. Android has had sideloading from the beginning and I’d wager it’s done nothing for the platform and likely has hurt it by being a security disaster. We can say “Apple, come up with a magical way we can sideload apps that is secure” but I’d much rather Apple be focused on engineering that actually benefits users and the platform than something that targets at a niche. This is something that needs a policy solution not a engineering solution that just adds more complexity to the system.
Once upon a time, the reason for the scrutiny (beyond generic ‘security’) was because of the carriers. I don’t know if it still is…
“…since you’ll be running code that has not been vetted by Apple.”
Based on recent headlines, being “vetted by Apple” doesn’t mean that much.
I think we are missing the obvious answer to this. Allowing side loading of apps will cut Apple out of the revenue stream. Developers will be able to sell directly to the customers and completely circumvent the App Store. Though this would be a nice feature for customers (and slightly risky), it would be a horrible business decision on Apple’s part.
@Brandon – You are missing the mark by a long shot. The average user – AKA 99%+ of the population that own iOS devices will not side load apps due to how complicated it is. They aren’t going to download Xcode, create a dev account, create a profile, learn how to code sign, compile, etc. These are words and concepts that 99%+ of the population does not understand and never will. Apple did this to make dev easier on iOS FOR devs. Sure there is a benefit to techies that like to experiment and also a downside for security to that less than 1% that will side load. That doesn’t hurt Apple’s lucrative revenue stream at all. Apple wouldn’t have approved the apps that are being side loaded due to restrictions in App Store policy.
Yep. That’s one of only two reasons I can fathom, the other being the need to keep content providers happy to maintain their iTunes Store deals. It would also present a possibility of app piracy as is prevalent on Android, leading to developer discontent.
Danger Will Robinson. Side loading is never a good idea.