Upwardly Mobile - API & App Security News

UK Watchdog Targets Apple and Google: Mobile Ecosystems Under Scrutiny for Stifling Innovation


Listen Later

In this episode of Upwardly Mobile, we delve into the critical issue of mobile app security and explore the argument that Apple and Google's monopolistic practices are hindering innovation and increasing long-term cyber risks for consumers1.... We examine how the dominance of these two tech giants in the mobile app ecosystem may be inadvertently creating vulnerabilities and limiting the potential for more robust security solutions. We also discuss potential alternative approaches to mobile app security.
Key Discussion Points:

Monopolistic Behavior: We discuss how Apple and Google control the mobile app ecosystem, restricting competition and innovation.... This control extends to app stores, operating systems and browsers5.

Impact on Security: The episode will explain how the lack of competition in mobile app security could lead to a monoculture that is vulnerable to attack... The podcast highlights that while Apple and Google currently provide reasonable cybersecurity, their dominance stifles innovation from third-party vendors.

The Offense-Defense Imbalance: We explore the concept that in cybersecurity, attackers have an inherent advantage over defenders2. It's much easier to attack than defend2.

Lack of Vendor Diversity: We highlight the absence of major cybersecurity vendors in the mobile app security space, unlike the cloud security sector, which has a thriving ecosystem of vendors such as Wiz and Palo Alto Networks.

Google Mobile Services (GMS): The episode examines how GMS locks down the Android mobile app environment, potentially hindering external mobile app security vendors11.... Alternatives exist, but the dominance of GMS is a barrier.

Alternative Ecosystems: We discuss non-GMS mobile phone manufacturers, primarily from China, such as Transsion, Huawei, Xiaomi, and Oppo. These manufacturers offer alternatives but raise geopolitical concerns16....

The UK's CMA Investigation: We examine the Competition and Markets Authority (CMA) investigation into Apple and Google's mobile ecosystems, which aims to determine if these companies have "strategic market status" and are stifling innovation and competition5.... The CMA is assessing the level of competition and barriers to entry within these ecosystems, and if Apple and Google are favouring their own apps and services21.... The investigation will also explore if app developers are required to sign up to unfair terms and conditions23....

Proposed Solutions: The podcast delves into recommendations such as:

Apple and Google facilitating the use of third-party mobile app security vendors.

Incentivising developers to use third-party security solutions through reduced commission rates.

Adopting open standards for mobile app security evaluations, such as those developed by the Open Web Application Security Project (OWASP).

The Bigger Picture: We discuss how greater competition and open standards can improve mobile app security and potentially enhance user trust in mobile technologies, including their use in future elections28.
Relevant Links:

Approov: https://www.approov.io/ - Sponsor of the podcast. Learn more about their mobile app security solutions.

TAG Infosphere: https://www.tag-infosphere.com/

NYU Center for Cybersecurity: https://cyber.nyu.edu/

US Department of Justice Sues Apple: https://www.theverge.com/2024/3/21/24105363/apple-doj-monopoly-lawsuit

Cyber Defense Review report on offensive/defensive balance: https://cyberdefensereview.army.mil/Portals/6/Documents/2022_summer_cdr/08_Valeriano_CDR_V7N3_Summer_2022.pdf

Wired article on Google's App Store Monopoly: https://www.wired.com/story/googles-app-store-monopoly-ruled-illegal-jury-epic/

Department of Justice report on the 1984 AT&T decree: https://www.justice.gov/archives/atr/att-divestiture-was-it-necessary-was-it-success

Apple's Platform Security Documentation: https://www.apple.com/business/docs/site/AAW_Platform_Security.pdf

Google's Cybersecurity Approach: https://safety.google/stories/micklitz-pietraszek/

NowSecure Mobile App Breach News: https://www.nowsecure.com/mobile-app-breach-news/

OWASP Foundation: https://owasp.org/www-project-mobile-top-10/

Merriam-Webster Definition of Monopoly: https://www.merriam-webster.com/dictionary/monopoly

Spotify vs Apple Commission Fees: https://forums.appleinsider.com/discussion/233654/spotify-speaks-out-against-apples-30-commission-fee-again

Epic Games vs Apple: https://appleinsider.com/articles/20/08/23/apple-versus-epic-games-fortnite-app-store-saga-the-story-so-far

HONOR Explanation of GMS: https://www.hihonor.com/sa-en/blog/what-is-gms/

GMS vs Non-GMS Android Apps: https://emteria.com/blog/gms-vs-non-gms/

Epic vs Google Trial: https://www.theverge.com/23994174/epic-google-trial-jury-verdict-monopoly-google-play




































...more
View all episodesView all episodes
Download on the App Store

Upwardly Mobile - API & App Security NewsBy Approov Limited