Go back

5 Minute Friday | A New EU Mandate Makes iOS Less Secure

6m 32s

5 Minute Friday | A New EU Mandate Makes iOS Less Secure

The Digital Markets Act (DMA) introduced by the EU targets big tech companies like Apple, identifying them as gatekeepers with significant market influence. The focus on Apple and the iOS App Store raises concerns about security implications if third-party app stores are permitted on iOS devices. Side loading apps from unofficial sources can introduce security vulnerabilities, leading to risks for personal and corporate data. iOS malware threats could rise as a result, impacting affluent users and enterprise security. While Apple has promoted iOS as a secure platform, potential changes due to the DMA may compromise security levels. The evolving situation requires vigilance from security teams and users to safeguard against emerging threats in the mobile ecosystem.

Transcription

1038 Words, 6153 Characters

(upbeat music) - Hi everyone, my name is Hank Schlesse and welcome to Five Minute Fridays, where we highlight one story from the cybersecurity world that you need to know about. This week, we're going to talk about the Digital Markets Act or DMA and what it means for the security of iOS devices. So back in early March, the EU enacted the Digital Markets Act or DMA. This is a new rule designed to protect competition in European digital markets. The regulation starts off by naming 22 services from six companies, which they term as gatekeepers. This is defined as organizations that basically have outsize influence on consumer behavior in their particular market. The six companies included in this are Apple, Alphabet, Amazon, ByteDance, which is the parent company of TikTok, Meta and Microsoft. So what's happening here is that the EU is basically trying to level the playing field for smaller organizations that provide similar services to these giants. Today, we're going to focus on Apple and specifically the App Store for iOS. And whether you're an iPhone user or not, you probably know that the iOS App Store is essentially the only way that an app developer can get its app out to Apple device users. Android devices, on the other hand, have historically been much more open to apps from other sources, as is the nature of the Android operating system being open source. But that's a topic for another time. So the fact that Apple has so much control basically means that they can make their own rules. Specifically, in this case, they've implemented strict guidelines in order to be an app developer in good standing. For any of you fans of the office out there, it's like when Michael Scott says that he wants people to be afraid of how much they love him. Developers love the App Store because it gets millions of eyes on their app, but they better not tick off Apple or it's game over because they can essentially shut off your developer account and then you have no way of making money from your application. Now, on top of all of that, developers also pay Apple between 15 and 30% of the revenue they make through the App Store. It's been interesting to see some developers take an alternate approach to this where they have a free version of their application on the App Store, but then if you want to subscribe or get the premium version, an example that comes to mind is Spotify, you actually leave the App Store and pay for your premium subscription separately on Spotify's website. Now, the battle between Spotify and Apple has been pretty much the banner story for this whole DMA conversation, especially because Spotify and Apple compete and they compete over Spotify versus Apple Music. Now, there have been a few other app developers who have either been banned from the App Store because of their practices or have chosen to remove themselves and intend on making their own App Store, such as Epic Games, which developed the very popular App Fortnight. All of that, again, could be a topic for another time, but let's dive into where security ties into all of this. Really, it's about this term that we use in the mobile security industry called side loading. Historically speaking, side loading has had a negative connotation because it refers to the practice of downloading an app to your device that doesn't come from either the iOS App Store or Google Play Store. Keep in mind that there have always been third-party app stores out there, but they often lack the tight security reviews of the two dominant app stores. And for that reason, they're frequently used by malicious app developers who create alternate versions of legitimate applications, usually with some additional capabilities, and lace it with malware. So it'll take time, but with the DMA requiring Apple to open up iOS to these third-party app stores, we could see some of the most popular apps moving away from Apple and a steady rise in the popularity of these third-party stores. Users themselves might not understand that as they use their personal devices for work, side loading apps can actually put company data and compliance standing at risk because of these applications having less stringent security requirements. They may have far-reaching permissions, or they may be sharing data with parts of the world that maybe the usual enterprise doesn't want their data going to. Now, it's also important to remember that protecting against iOS malware is something that security teams haven't really had to worry about too much, especially in comparison to other mobile security risks, like phishing, for example. But now that they're going to have to find a way to do so, it's gonna get a little more complicated. And threat actors have always been targeting iOS. It's the most used platform by affluent executives at Fortune 500 companies who have arguably some of the most valuable data in the world at their fingertips and can access it from their iOS devices. And hacking someone's phone is like hacking the person themselves. It can see what they see, it can see what they see, it can hear what they hear, it can see where they are. And most importantly these days, it can actually be a key to access most of that individual's data, especially data they have access to in corporate infrastructure through multi-factor authentication. Now, we have to give a hat tip to Apple because they've always done a great job marketing iOS as the more secure mobile operating system. But even they admit in their own communications that this will make their devices less secure and users should be more careful. It'll be interesting to see really how this unfolds over the coming months. And as always, look out will proactively protect users against threats on both iOS and Android. And we'll be sure to keep a close eye on whether there's an upward trend in iOS malware now that the DMA is in place. But for now, that's today's five minute Friday. Thanks for listening and stay safe. (upbeat music)

Podcast Summary

Key Points:

  1. The Digital Markets Act (DMA) in the EU aims to regulate competition in digital markets.
  2. Apple, Alphabet, Amazon, ByteDance, Meta, and Microsoft are identified as gatekeepers under the DMA.
  3. Concerns about iOS security arise due to DMA potentially allowing third-party app stores on Apple devices.
  4. Side loading apps outside of official app stores like the App Store or Google Play Store can pose security risks.
  5. iOS malware threats may increase with potential changes in app distribution policies.

Summary:

The Digital Markets Act (DMA) introduced by the EU targets big tech companies like Apple, identifying them as gatekeepers with significant market influence. The focus on Apple and the iOS App Store raises concerns about security implications if third-party app stores are permitted on iOS devices. Side loading apps from unofficial sources can introduce security vulnerabilities, leading to risks for personal and corporate data.

iOS malware threats could rise as a result, impacting affluent users and enterprise security. While Apple has promoted iOS as a secure platform, potential changes due to the DMA may compromise security levels. The evolving situation requires vigilance from security teams and users to safeguard against emerging threats in the mobile ecosystem.

FAQs

The Digital Markets Act is a regulation enacted by the EU to protect competition in European digital markets.

Organizations like Apple, Alphabet, Amazon, ByteDance, Meta, and Microsoft are termed gatekeepers under the Digital Markets Act.

The DMA aims to level the playing field for smaller organizations by targeting Apple's strict guidelines and revenue sharing model for developers.

Side loading refers to downloading apps from sources other than official app stores, potentially exposing devices to malware and security risks.

Side loading apps on iOS devices can compromise company data, compliance, and security due to less stringent reviews and potential malicious activities.

The DMA requiring Apple to open up iOS to third-party app stores may impact iOS security, leading to potential rise in malware threats and security challenges.

Chat with AI

Loading...

Pro features

Go deeper with this episode

Unlock creator-grade tools that turn any transcript into show notes and subtitle files.