Well, it would have saved this person from being cheated of his life savings. But I suppose he could have simply chosen to just ”not install malware”.
The majority of victims were aged 30 to 49, and were most frequently targeted on Facebook and Instagram.
www.channelnewsasia.com
A lot of things tend to be package deals. There’s good in bad, and bad in good and I wish people here would acknowledge that rather than pretend that sideloading is pure upside with zero drawbacks at all.
The original attack vector they describe (click a link, download an app package) wouldn't work (or at least be shut down extremely quick) with the app notarization that Apple requires for all apps. The final versions rely heavily on social engineering and can be deployed against Apple users right now by directing them to install an app through Testflight. Third party stores don't change much.
Edit: I should comment on your last point, because it is a fair one. I will freely acknowledge downsides when they warrant a mention, but the messaging and indoctrination from Apple regarding the security benefits of a locked in store requires strong push-back. Allowing other app sources can potentially open up new attack vectors, but that risk is relatively minor and very manageable for Apple who has decades of experience in this area (and ready built tools to deal with threats).
Furthermore, if you look at Android, their biggest source of malware is in the Play Store itself. The security picture is a lot more complicated than: "it's best if one party reviews all the apps and has complete control over what gets in and what doesn't."
While you may think I'm downplaying security, I have my own wish as well: that people recognize that Apple's primary motivation is profit. Always. There's no other way to become a $3 Trillion company than to make profit central and core to everything they do. They talk about user protection and privacy because first it's profitable to them, then because it's a value that leadership holds, not the other way around. That's why google is the default search engine on iOS. If they valued security before profit, duckduckgo would be default search engine and Apple would charge nothing for it. Instead Apple charges Google $20 Billion annually to be default search and collect browsing data on all users who don't actively change it.
Any discussion about third party app stores (and security) has to start with profit motive, because that is by far Apple's greatest motivator. Open sourcing iMessage would have increased the user security on iOS (by basically doing away with SMS completely). They backed away from that plan when they realized it was more profitable to keep iMessage as iOS exclusive. They got a second chance with RCS and refused to engage with it at all, and almost killed it through non-support. Carriers never supported it because they knew Apple wouldn't add it. Google had to build their own servers to keep the idea alive. Now they are finally adding it under threat of legal action and laws written against them (lost profits), but still doing the minimum. The security angle can only be appropriately discussed after Apple's profit motive is accounted for. If people can't acknowledge this most obvious fact, I'm not going to trust their insights on security tbh.