Apple Does Deep Dive Into Security Protections and Risks With Alternative App Marketplaces

Apple today published a whitepaper [PDF] detailing the privacy and security protections that it is implementing in the European Union to keep users as safe as possible while also complying with the requirements of the Digital Markets Act.

App Store vs EU Feature 2
As a recap, with the upcoming iOS 17.4 update, iPhone users in the European Union will be able to install apps through alternative app marketplaces rather than the App Store. Several companies are working on marketplaces, with Setapp and Epic Games confirming plans to offer an ‌App Store‌ alternative.

Apps installed through marketplaces are essentially "sideloaded" and are not subject to the standard ‌App Store‌ review process. In an effort to minimize the risk of malware and fraud, Apple has implemented a Notarization process that app marketplaces and the apps sold through those marketplaces must submit to.

Notarization includes both an automated scan and human review to ensure that apps do not contain malware, function as advertised, and do not engage in "egregious fraud" attempts. An app can't be installed on an ‌iPhone‌ using sideloading unless it is signed by Apple through Notarization, and Apple is requiring developers to have a Developer account and provide legitimate details like name, address, and phone number. Apps will need to explain why they need access to sensitive data like the microphone, camera, Face ID, health data, and more, and user consent will also be required for these functions to work after an app is installed.

What Notarization won't do is look at the content of apps. Apps installed through alternative marketplaces can have adult content, copyrighted content, drug-related content, and other features that would not be allowed in the ‌App Store‌. Apple will attempt to stop apps that impersonate other apps or that have undocumented features, but the company warns that sideloaded apps will not be as secure as those installed through the ‌App Store‌.

Alternative app marketplaces need to adhere to baseline criteria that requires them to commit to monitoring for and removing malicious apps and providing support to users. Refunds, for example, will need to be provided by the app marketplace because marketplaces use alternative payment methods rather than in-app purchases. Alternative payment methods are also accepted in ‌App Store‌ apps under the DMA.

European users who install an app outside of the ‌App Store‌ will be presented with an app installation sheet that provides the app name, developer name, app description, screenshots, and ratings. Sheets can be turned off for a marketplace in the Settings app, and they also disappear if a marketplace is set as the default store.

Similar disclosures are also offered up for apps that use alternative payment methods. Apple provides warnings that features like easy subscription cancelation and Ask to Buy are not available, and that there is no protection from predatory pricing.

Apple says that it has received numerous emails from European users and government agencies that are concerned with the risks of alternative app marketplaces, and Apple promises to "work tirelessly" to protect users "to the extent possible under the law." There is no way for users to opt out of the DMA changes, and Apple suggests that some people may have to use alternative apps against their will. Employers and schools may require an app that is only available through a marketplace, for example.

Much of Apple's whitepaper walks through the risks that ‌iPhone‌ users will need to contend with and the work that alternative app marketplace operators will need to do in order to keep users safe.

Notably, Apple says that the changes that it is making have been discussed with the European Commission, and there have been no concerns raised. The DMA does recognize the privacy risks associated with alternative app marketplaces, and Apple says it is aiming to do what it can to protect and educate users under the new guidelines.

‌iPhone‌ owners in the European Union who have additional concerns about alternative app marketplaces can read through Apple's full PDF to get a complete picture of the security and safety protections that Apple has put in place and the risks that still remain.

Popular Stories

New Things Your iPhone Can Do in iOS 18

20 New Things Your iPhone Can Do in iOS 18.2

Monday December 16, 2024 8:55 am PST by
Apple released iOS 18.2 in the second week of December, bringing the second round of Apple Intelligence features to iPhone 15 Pro and iPhone 16 models. This update brings several major advancements to Apple's AI integration, including completely new image generation tools and a range of Visual Intelligence-based enhancements. Apple has added a handful of new non-AI related feature controls as...
iphone 16 apple intelligence

Apple Drops Plans for iPhone Hardware Subscription Service

Wednesday December 18, 2024 11:39 am PST by
Apple is no longer planning to launch a hardware subscription service that would let customers "subscribe" to get a new iPhone each year, reports Bloomberg's Mark Gurman. Gurman first shared rumors about Apple's work on a hardware subscription service back in 2022, and at the time, he said that Apple wanted to develop a simple system that would allow customers to pay a monthly fee to gain...
iPhone 17 Pro Dual Tone Feature 1

iPhone 17 Pro Rumored to Stick With 'Triangular' Camera Design

Wednesday December 18, 2024 2:36 am PST by
Contrary to recent reports, the iPhone 17 Pro will not feature a horizontal camera layout, according to the leaker known as "Instant Digital." In a new post on Weibo, the leaker said that a source has confirmed that while the appearance of the back of the iPhone 17 Pro has indeed changed, the layout of the three cameras is "still triangular," rather than the "horizontal bar spread on the...
elevation lab airtag battery

Your AirTag's Battery Will Last for Up to 10 Years With Elevation Lab's New TimeCapsule Enclosure

Wednesday December 18, 2024 10:05 am PST by
Elevation Lab today announced the launch of TimeCapsule, an innovative and simple solution for increasing the battery life of Apple's AirTag. Priced at $20, TimeCapsule is an AirTag enclosure that houses two AA batteries that offer 14x more battery capacity than the CR2032 battery that the AirTag runs on. It works by attaching the AirTag's upper housing to the built-in custom contact in the...
apple tv 4k yellow bg feature

New Apple TV Rumored to Launch Next Year With These Features

Tuesday December 17, 2024 9:02 am PST by
The current Apple TV 4K was released more than two years ago, so the streaming device is becoming due for a hardware upgrade soon. Fortunately, it was recently rumored that a new Apple TV will launch at some point next year. Below, we recap rumors about the next-generation Apple TV. Bloomberg's Mark Gurman last week reported that Apple has been working on its own combined Wi-Fi and...
blackmagic vision pro

Blackmagic Debuts $30K 3D Camera for Capturing Video for Vision Pro

Monday December 16, 2024 4:17 pm PST by
Blackmagic today announced that its URSA Cine Immersive camera is now available for pre-order, with deliveries set to start late in the first quarter of 2025. Blackmagic says that this is the world's first commercial camera system designed to capture 3D content for the Vision Pro. The URSA Cine Immersive camera was first introduced in June, but it has not been available for purchase until...
iPhone 17 Slim Feature

'iPhone 17 Air' With 'Major' Design Changes and 19-Inch MacBook Detailed in New Report

Sunday December 15, 2024 9:47 am PST by
Apple is planning a series of "major design" and "format changes" for iPhones over the next few years, according to The Wall Street Journal's Aaron Tilley and Yang Jie. The paywalled report published today corroborated the widely-rumored "iPhone 17 Air" with an "ultrathin" design that is thinner than current iPhone models. The report did not mention a specific measurement, but previous...
mac pro creativity

Apple Launched the Controversial 'Trashcan' Mac Pro 11 Years Ago Today

Thursday December 19, 2024 7:00 pm PST by
Apple launched the controversial "trashcan" Mac Pro eleven years ago today, introducing one of its most criticized designs that persisted through a period of widespread discontentment with the Mac lineup. The redesign took the Mac Pro in an entirely new direction, spearheaded by a polished aluminum cylindrical design that became unofficially dubbed the "trashcan" in the Mac community. All of ...

Top Rated Comments

krspkbl Avatar
11 months ago
But they side-load apps on Mac.

Side-loading isn't bad. Competition (different stores) isn't bad... unless you're an AAPL shareholder, of course.

Why do we need a "whitepaper" for a basic feature that every other popular modern OS supports (excluding iPadOS lol) ?

Nice try Apple.
Score: 30 Votes (Like | Disagree)
vegetassj4 Avatar
11 months ago
Luckily, these nice people sent me an alert on how to protect myself from sideload dangers:



Attachment Image
Score: 22 Votes (Like | Disagree)
icanhazmac Avatar
11 months ago

Side-loading isn't bad. Competition (different stores) isn't bad... unless you're an AAPL shareholder, of course.
A one stop shop isn't bad either. It is a unique, and sadly, one of a kind model that may get legislated out of existence.

Yes, we all have survived with the PC/Mac app procurement model but does that mean it is the best or that other types of models shouldn't exist? Personally, I wish the walled garden extended to the Mac.
Score: 19 Votes (Like | Disagree)
krspkbl Avatar
11 months ago

You're conveniently ignoring that Apple has said many times that macOS is a less secure platform because of side loading.

You're also ignoring the fact that even Google/Android inform their users of the risks of side loading, and Google even recently issued a statement advising users to NOT side load because of risks. If I remember correctly, Google is even testing BLOCKING downloads of apps, even if you confirm on the verification that you actually want to download that side loaded app.

Apple informing the user base of the risks of side loading isn't any different than what Google does. Save your fake outrage for something where it's actually warranted.
Yet people love their Macs and Android is a huge success. There are risks and people should be warned but I'd rather have the freedom to do what I want with my devices than have someone hold my hand and tell me they know what's best for me.

Millions of businesses across the world use Windows, pretty much every server runs Linux and Android smartphones which "sideload" apps. The actual feature and functionality of it is not the problem and iOS/iPadOS should implement it worldwide.

Apple is just scared and desperately trying to not lose money.
Score: 19 Votes (Like | Disagree)
iOS Geek Avatar
11 months ago

But they side load apps on Mac.

Sideloading isn't bad. Competition (different stores) isn't bad... unless you're an AAPL shareholder, of course.

Nice try Apple.
You're conveniently ignoring that Apple has said many times that macOS is a less secure platform because of side loading. It's actually why we aren't allowed to side load ANYTHING to our Macs at work. Because someone did once and it ****** up our entire system

You're also ignoring the fact that even Google/Android inform their users of the risks of side loading, and Google even recently issued a statement advising users to NOT side load because of those risks. If I remember correctly, Google is even testing BLOCKING downloads of apps, even if you confirm on the verification that you actually want to download that side loaded app. While the EU is forcing Apple to be more open like Google, Google is trying to impose limits like Apple does. Gee, maybe the ecosystem that allows it actually thinks it's not that great of a thing! Why else would they be trying to reign it in? Multiple stories about users getting scammed spring to mind.

Apple informing the user base of the risks of side loading isn't any different than what Google does. Save your fake outrage for something where it's actually warranted.
Score: 17 Votes (Like | Disagree)
Timo_Existencia Avatar
11 months ago
I want a modern OS that is closed. I've knowingly made that choice for reasons that are important and valuable to me.

I trust business to make critical decisions on privacy and safety in tech much more than I trust Government to make those decisions; or at least I trust Apple more than I trust the EU.

I would like Apple to allow me to close off Alternate App stores on my child's devices.

I appreciate those of you who want to live in an open os ecosystem.

But why do you insist on taking my choice away? Why do you empower governments to make these choices?
Score: 17 Votes (Like | Disagree)