{"id":3858,"date":"2024-06-03T16:45:11","date_gmt":"2024-06-03T21:45:11","guid":{"rendered":"https:\/\/www.darkreading.com\/mobile-security\/ways-apple-ios-sideloading-can-be-more-secure"},"modified":"2024-06-03T16:45:11","modified_gmt":"2024-06-03T21:45:11","slug":"ways-ios-sideloading-can-be-more-secure","status":"publish","type":"post","link":"https:\/\/ddi.mohflo.net\/index.php\/2024\/06\/03\/ways-ios-sideloading-can-be-more-secure\/","title":{"rendered":"Ways iOS Sideloading Can Be More Secure"},"content":{"rendered":"<div class=\"media_block\"><a href=\"https:\/\/i0.wp.com\/eu-images.contentstack.com\/v3\/assets\/blt6d90778a997de1cd\/blt4760481746fcb74f\/664fcfdedcead06c6fade457\/iphone-Tiny_Ivan-alamy.jpg?ssl=1\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/06\/ways-ios-sideloading-can-be-more-secure.jpg?w=640&#038;ssl=1\" class=\"media_thumbnail\"><\/a><\/div>\n<div><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/06\/ways-ios-sideloading-can-be-more-secure.jpg?w=640&#038;ssl=1\" class=\"ff-og-image-inserted\"><\/div>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><span class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_bold\">COMMENTARY<\/span><\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Thanks to the European Union&#8217;s Digital Markets Act, earlier this year sideloading became possible on iOS devices in Europe. In a historic shift, Apple finally unlocked the gates to its tightly controlled ecosystem, enabling users to download apps from third-party marketplaces and websites. While many have welcomed this newfound freedom, it has, somewhat unsurprisingly, sparked major security concerns.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Since the very first iteration of iOS, Apple has maintained strict oversight over its operating system, ensuring a high level of security by thoroughly vetting each app before allowing it into the App Store. This centralized control has provided a key advantage in preventing malware and unauthorized apps from infiltrating Apple devices. For years, Apple&#8217;s &#8220;walled garden&#8221; has distinguished it from its competitors \u2014 notably Android, where sideloading has long facilitated the widespread distribution of malware. Now with the &#8220;androidification&#8221; of iOS, Apple, too, must contend with these security concerns. But how will it do so?<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"The Garden Is Still Walled, the Walls Are Just Smaller\">The Garden Is Still Walled, the Walls Are Just Smaller<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The first and most obvious line of defense is Apple&#8217;s notarization process. Unlike Android, apps installed from outside of the App Store must be notarized by Apple or else iOS will not install them, ensuring that they meet certain security requirements. Any iOS developers reading this will already be thinking this sounds familiar. However, Apple&#8217;s notarization differs from the traditional App Store review process in that it does not impose content restrictions, such as on pornography and illegal substances.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">During this notarization process, Apple probes for malicious behavior by combining automated scanning and human review. The human aspect is a vital component as it detects threats that automatic tools may miss, such as social engineering attacks using fake apps. However, we should anticipate that malicious apps will still slip through the net. The fact that a <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/endpoint-security\/lastpass-warns-password-app-apple-app-store\" rel=\"noopener\">fake version of the password manager LastPass made it into the App Store<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> earlier this year shows that Apple&#8217;s notarization process won&#8217;t be bulletproof.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">That being said, Google has never exerted this level of control, instead allowing anyone to generate a certificate and sign applications. So, while Apple won&#8217;t catch every malicious app, this level of safeguarding will still play its part in preventing iOS from becoming an Android-like Wild West. This involves a process of identity verification in which all developers need to provide a legal name, phone number, and an address. Even though Apple prevented the creation of <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/cloud-security\/apple-boots-half-million-devs-official-app-store\" rel=\"noopener\">nearly 105,000 fraudulent developer accounts<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">, in 2022, it&#8217;s still widely known that there are sneaky methods to circumvent such identity verifications.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"Ensuring a Resilient Runtime Environment\">Ensuring a Resilient Runtime Environment<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">During the notarization process, Apple scans the apps that are submitted for sideloading for suspicious behavior. <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><span class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_italic\">When<\/span><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> and <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><span class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_italic\">how<\/span><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> these apps are scanned is key to reinforcing app security on iOS. To truly counteract the dangers of sideloading, iOS must bolster the real-time monitoring of its apps for vulnerabilities and threats while they&#8217;re actively running in an authentic environment. This is because more advanced and dangerous apps can determine whether they are being run during the review process (e.g., by checking the date or the location of the device) and might not exercise their potential malicious behavior \u2014 a digital poker face, if you will, before it reveals its hand.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">On Android, Google has been scanning installed applications with its Google Play Protect feature for some time. Apple could follow and expand on that example by actively observing the execution of the applications on their users&#8217; devices, a measure even Google has yet to implement. The observed behavior could then be analyzed with advanced threat detection algorithms.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Leveraging machine learning and behavioral analysis, such algorithms analyze app behavior and can proactively detect suspicious patterns. For instance, if a user sideloads an app onto their iOS device, unaware that it contains code designed to initiate unauthorized network connections, the app may exfiltrate user data to servers controlled by malicious actors. However, an advanced threat detection algorithm will detect anomalous behavior instantly, signaling it as a potential threat. The system can then initiate measures to quarantine or remove the malicious components and thus protect the user&#8217;s device from harm.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">To give Apple credit, there are some existing security features on iOS that will play a role in mitigating the dangers of sideloading. Sandboxing, for example, has long been used by Apple to contain the damage that a malicious application can cause when getting sideloaded. By walling off each app in a controlled, restricted environment (or sandbox), this method limits where certain code can be executed and, by extension, the capabilities of apps. This should prevent bad actors from accessing sensitive systems unless explicitly authorized. For instance, a user may sideload a video-editing app onto their iOS device that may, despite the app&#8217;s legitimate functionality, attempt to access the device&#8217;s microphone for undisclosed purposes. App sandboxing will detect and contain this unauthorized activity, blocking the app from accessing potentially sensitive data.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Apple&#8217;s current approach to sideloading reflects a delicate balance, aiming to provide users with flexibility while ensuring that security standards are upheld. Ultimately, there&#8217;s no way around the fact that sideloading will increase iOS&#8217;s susceptibility to malware. Only time will tell how severe this threat will be.<\/span><\/p>\n<p><a href=\"https:\/\/www.darkreading.com\/mobile-security\/ways-apple-ios-sideloading-can-be-more-secure\">Source<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>COMMENTARY Thanks to the European Union&#8217;s Digital Markets Act, earlier<\/p>\n","protected":false},"author":12,"featured_media":3859,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[1],"tags":[809],"class_list":["post-3858","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-dark-reading"],"featured_image_urls":{"full":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/06\/ways-ios-sideloading-can-be-more-secure.jpg?fit=1800%2C1013&ssl=1",1800,1013,false],"thumbnail":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/06\/ways-ios-sideloading-can-be-more-secure.jpg?resize=150%2C150&ssl=1",150,150,true],"medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/06\/ways-ios-sideloading-can-be-more-secure.jpg?fit=300%2C169&ssl=1",300,169,true],"medium_large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/06\/ways-ios-sideloading-can-be-more-secure.jpg?fit=640%2C360&ssl=1",640,360,true],"large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/06\/ways-ios-sideloading-can-be-more-secure.jpg?fit=640%2C360&ssl=1",640,360,true],"1536x1536":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/06\/ways-ios-sideloading-can-be-more-secure.jpg?fit=1536%2C864&ssl=1",1536,864,true],"2048x2048":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/06\/ways-ios-sideloading-can-be-more-secure.jpg?fit=1800%2C1013&ssl=1",1800,1013,true],"chromenews-featured":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/06\/ways-ios-sideloading-can-be-more-secure.jpg?fit=1024%2C576&ssl=1",1024,576,true],"chromenews-large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/06\/ways-ios-sideloading-can-be-more-secure.jpg?resize=825%2C575&ssl=1",825,575,true],"chromenews-medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/06\/ways-ios-sideloading-can-be-more-secure.jpg?resize=590%2C410&ssl=1",590,410,true]},"author_info":{"display_name":"Dark Reading","author_link":"https:\/\/ddi.mohflo.net\/index.php\/author\/darkreading\/"},"category_info":"<a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/uncategorized\/\" rel=\"category tag\">Uncategorized<\/a>","tag_info":"Uncategorized","comment_count":"0","jetpack_featured_media_url":"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/06\/ways-ios-sideloading-can-be-more-secure.jpg?fit=1800%2C1013&ssl=1","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/3858","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/users\/12"}],"replies":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/comments?post=3858"}],"version-history":[{"count":0,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/3858\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media\/3859"}],"wp:attachment":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media?parent=3858"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/categories?post=3858"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/tags?post=3858"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}