5 Minute Friday | A New EU Mandate Makes iOS Less Secure
6m 32s
The Digital Markets Act (DMA) introduced by the EU targets big tech companies like Apple, identifying them as gatekeepers with significant market influence. The focus on Apple and the iOS App Store raises concerns about security implications if third-party app stores are permitted on iOS devices. Side loading apps from unofficial sources can introduce security vulnerabilities, leading to risks for personal and corporate data. iOS malware threats could rise as a result, impacting affluent users and enterprise security. While Apple has promoted iOS as a secure platform, potential changes due to the DMA may compromise security levels. The evolving situation requires vigilance from security teams and users to safeguard against emerging threats in the mobile ecosystem.
Transcription
1038 Words, 6153 Characters
(upbeat music)
- Hi everyone, my name is Hank Schlesse
and welcome to Five Minute Fridays,
where we highlight one story from the cybersecurity world
that you need to know about.
This week, we're going to talk about
the Digital Markets Act or DMA
and what it means for the security of iOS devices.
So back in early March,
the EU enacted the Digital Markets Act or DMA.
This is a new rule designed to protect competition
in European digital markets.
The regulation starts off by naming 22 services
from six companies, which they term as gatekeepers.
This is defined as organizations
that basically have outsize influence
on consumer behavior in their particular market.
The six companies included in this are Apple,
Alphabet, Amazon, ByteDance,
which is the parent company of TikTok,
Meta and Microsoft.
So what's happening here is that the EU
is basically trying to level the playing field
for smaller organizations
that provide similar services to these giants.
Today, we're going to focus on Apple
and specifically the App Store for iOS.
And whether you're an iPhone user or not,
you probably know that the iOS App Store
is essentially the only way that an app developer
can get its app out to Apple device users.
Android devices, on the other hand,
have historically been much more open to apps
from other sources, as is the nature
of the Android operating system being open source.
But that's a topic for another time.
So the fact that Apple has so much control
basically means that they can make their own rules.
Specifically, in this case,
they've implemented strict guidelines
in order to be an app developer in good standing.
For any of you fans of the office out there,
it's like when Michael Scott says
that he wants people to be afraid
of how much they love him.
Developers love the App Store
because it gets millions of eyes on their app,
but they better not tick off Apple or it's game over
because they can essentially shut off your developer account
and then you have no way of making money
from your application.
Now, on top of all of that,
developers also pay Apple between 15 and 30%
of the revenue they make through the App Store.
It's been interesting to see some developers
take an alternate approach to this
where they have a free version of their application
on the App Store, but then if you want to subscribe
or get the premium version,
an example that comes to mind is Spotify,
you actually leave the App Store
and pay for your premium subscription
separately on Spotify's website.
Now, the battle between Spotify and Apple
has been pretty much the banner story
for this whole DMA conversation,
especially because Spotify and Apple compete
and they compete over Spotify versus Apple Music.
Now, there have been a few other app developers
who have either been banned from the App Store
because of their practices
or have chosen to remove themselves
and intend on making their own App Store,
such as Epic Games,
which developed the very popular App Fortnight.
All of that, again, could be a topic for another time,
but let's dive into where security ties into all of this.
Really, it's about this term
that we use in the mobile security industry
called side loading.
Historically speaking,
side loading has had a negative connotation
because it refers to the practice
of downloading an app to your device
that doesn't come from either the iOS App Store
or Google Play Store.
Keep in mind that there have always been
third-party app stores out there,
but they often lack the tight security reviews
of the two dominant app stores.
And for that reason,
they're frequently used by malicious app developers
who create alternate versions of legitimate applications,
usually with some additional capabilities,
and lace it with malware.
So it'll take time,
but with the DMA requiring Apple to open up iOS
to these third-party app stores,
we could see some of the most popular apps
moving away from Apple
and a steady rise in the popularity
of these third-party stores.
Users themselves might not understand
that as they use their personal devices for work,
side loading apps can actually put company data
and compliance standing at risk
because of these applications
having less stringent security requirements.
They may have far-reaching permissions,
or they may be sharing data with parts of the world
that maybe the usual enterprise
doesn't want their data going to.
Now, it's also important to remember
that protecting against iOS malware
is something that security teams
haven't really had to worry about too much,
especially in comparison to other mobile security risks,
like phishing, for example.
But now that they're going to have to find a way to do so,
it's gonna get a little more complicated.
And threat actors have always been targeting iOS.
It's the most used platform by affluent executives
at Fortune 500 companies who have arguably
some of the most valuable data in the world
at their fingertips
and can access it from their iOS devices.
And hacking someone's phone
is like hacking the person themselves.
It can see what they see,
it can see what they see,
it can hear what they hear,
it can see where they are.
And most importantly these days,
it can actually be a key to access most
of that individual's data,
especially data they have access to
in corporate infrastructure
through multi-factor authentication.
Now, we have to give a hat tip to Apple
because they've always done a great job marketing iOS
as the more secure mobile operating system.
But even they admit in their own communications
that this will make their devices less secure
and users should be more careful.
It'll be interesting to see really
how this unfolds over the coming months.
And as always, look out will proactively protect users
against threats on both iOS and Android.
And we'll be sure to keep a close eye
on whether there's an upward trend in iOS malware
now that the DMA is in place.
But for now, that's today's five minute Friday.
Thanks for listening and stay safe.
(upbeat music)
Podcast Summary
Key Points:
The Digital Markets Act (DMA) in the EU aims to regulate competition in digital markets.
Apple, Alphabet, Amazon, ByteDance, Meta, and Microsoft are identified as gatekeepers under the DMA.
Concerns about iOS security arise due to DMA potentially allowing third-party app stores on Apple devices.
Side loading apps outside of official app stores like the App Store or Google Play Store can pose security risks.
iOS malware threats may increase with potential changes in app distribution policies.
Summary:
The Digital Markets Act (DMA) introduced by the EU targets big tech companies like Apple, identifying them as gatekeepers with significant market influence. The focus on Apple and the iOS App Store raises concerns about security implications if third-party app stores are permitted on iOS devices. Side loading apps from unofficial sources can introduce security vulnerabilities, leading to risks for personal and corporate data.
iOS malware threats could rise as a result, impacting affluent users and enterprise security. While Apple has promoted iOS as a secure platform, potential changes due to the DMA may compromise security levels. The evolving situation requires vigilance from security teams and users to safeguard against emerging threats in the mobile ecosystem.
FAQs
The Digital Markets Act is a regulation enacted by the EU to protect competition in European digital markets.
Organizations like Apple, Alphabet, Amazon, ByteDance, Meta, and Microsoft are termed gatekeepers under the Digital Markets Act.
The DMA aims to level the playing field for smaller organizations by targeting Apple's strict guidelines and revenue sharing model for developers.
Side loading refers to downloading apps from sources other than official app stores, potentially exposing devices to malware and security risks.
Side loading apps on iOS devices can compromise company data, compliance, and security due to less stringent reviews and potential malicious activities.
The DMA requiring Apple to open up iOS to third-party app stores may impact iOS security, leading to potential rise in malware threats and security challenges.
Chat with AI
Loading...
Pro features
Go deeper with this episode
Unlock creator-grade tools that turn any transcript into show notes and subtitle files.