Skip to content

Open App Markets Act – Does Competition Hurt Security?

June 14, 2022

Have you ever downloaded an app outside of the Apple app store? Probably not, because the current setup of app marketplaces like the Apple app store makes that very difficult. That is about to change. On Feb. 3, 2022, the Senate Judiciary Committee approved the Open App Markets Act with bipartisan support (20-2) to open up app marketplaces – creating something called “sideloading,” installing apps on devices outside of approved app stores.

The Open App Markets Act is a pro-competition law that intends to give app developers the ability to reach consumers without having to go through app stores such as the Apple app store. Currently, app developers either cannot or are disadvantaged to publish their apps unless it is on an operating system’s official app store. To Apple, the control over apps on the Apple store provides better oversight to make sure they are legitimate, secure, and not harmful to consumers.

In theory, the new law would eliminate disadvantages currently faced by developers and spur the creation of new apps. Here are some highlights from the Act to consider:

  • The Act applies to any company that owns or controls an app store that has over 50,000,000 U.S. users.
  • A covered entity cannot require developers to use an in-app payment system by the covered company as a condition of distributing an app on an app store.
  • A covered entity cannot require developers to use equal or more favorable pricing terms for distributing apps on its own app store.
  • A covered entity cannot penalize a developer for using or offering different pricing terms for using another in-app payment system or on another app store.
  • A covered company must allow and provide readily accessible means for users to choose third-party apps, install third-party apps, and hide or delete apps preinstalled by the covered company’s own app store.
  • A covered entity does not violate Section 3 for an action that is necessary to achieve user privacy, security, or digital safety.

Not surprisingly, owners of the app stores have concerns with sideloading. At the most recent IAPP Global Privacy Summit Conference, Apple CEO, Tim Cook warned that the Act would inevitably chip away at the current privacy and security protection that the Apple app store provides to its consumers. Statistics show that the Apple app store-approved and controlled apps had fewer malware infections and less infected devices than unregulated application stores. A Nokia 2020 report found that Android devices account for 26.65% of malware infections, compared to 1.72% for iPhones. Similarly, a 2021 Nokia report found that Android devices make up 50.31% of all infected devices.

Currently, Google already allows users to download apps for Android from sources other than its official Google Play. This concern is also not shared by Microsoft, which is adopting a principled approach to app store operation by announcing a new Open App Store ahead of the Act and allowing developers access to its platform as long as certain reasonable quality and safety standards are met. While the security concern over “sideloading” was shared by CISA and cybersecurity groups, it does not necessarily mean that alternate app stores cannot be safe if they are effectively moderated and users are cautious in their selection. For example, users can reduce the risk of harmful apps by limiting their download sources to official app stores, avoiding downloading from unknown sources, reading reviews, and researching developers before downloading an app.

While such changes are sure to spur development, they may bring with them concerns about app security and privacy. Will these concerns outweigh the potential for new development? Will there be additional changes to address security? Only time will tell.

Subscribe for the latest

Subscribe

Related

Event

Clark Hill's Commercial Real Estate Symposium – Dallas, Texas

Join Clark Hill’s Commercial Real Estate attorneys and industry professionals for a timely and dynamic program in Dallas, focusing on the latest challenges and top trends in the CRE industry.

Explore more
Legal Updates

What Is Likely the Weakest Provision in Your Multi-State Lease?

Using one eminent domain lease clause across states risks lost value. Learn how state laws should reflect notice and just compensation for better protection.

Explore more
Legal Updates

Critical Risk Mitigation Provisions for Design Contracts — Part 1: Waiver of Consequential Damages

An essential element of architect and engineer contracts with their clients is the treatment of risk sharing between the parties. Design professionals who are typically simply providing services for a fee, and who are not investors who will share in the profits of a successful project, can ill-afford to expose themselves to unlimited liability for negligent errors and omissions in the performance of their services. Architects and engineers would argue that it is fundamentally unfair to expose them to unlimited downside risk when they do not directly participate in the upside profit potential of the projects they design. Owners and developers would counter that this is why design professionals carry professional liability insurance. But even simple design errors can lead to liability that is many times greater than the amount of such insurance.

Explore more