Before app stores, installing software meant trusting a lot of strangers. After them, it means trusting one very large one.

Section 01The deal you accept at the door

For most of computing history, finding software meant navigating a chaotic sprawl — publisher websites, download portals, shareware discs — with almost nothing standing between you and whatever a developer chose to ship. App stores changed that by inserting a gatekeeper: one company that reviews submissions, sets rules and curates what reaches you. Apple's App Store, opened in 2008, established the template; Google Play followed, and both remain dominant on mobile today.

The pitch is genuine. Curation catches a real category of harm. Sandboxing — the technical cage that limits what any app can reach on your device — means a badly written game cannot silently read your contacts or log your keystrokes. On traditional desktops, an installed program can do almost anything your user account can do; on a managed mobile platform, it largely cannot. For ordinary users who never wanted to think about permissions architectures, this is a meaningful improvement.

The sandboxing model also changed what permissions on a phone actually mean in practice. A permission prompt on iOS or Android is backed by an enforced technical boundary, not merely a polite declaration. When an app asks for your location, granting or refusing that request has real effect. That is not universally true of software installed on a desktop.

15–30 percentApple's commission rate on in-app purchases
2008year Apple's App Store launched, establishing the dominant model

Section 02What the gate costs

The bargain has a second side. When a single company controls the only practical distribution channel for a platform, it controls much more than malware. It controls pricing, business models, speech and competition. Apple's 15–30 percent commission on in-app purchases has been the subject of litigation in multiple jurisdictions. Developers building tools that compete with platform-owner products have found their apps rejected, delayed or removed. The rules are set unilaterally and can change.

For users who care about free and open-source software, the constraints bite in a specific way. FOSS applications can and do appear in both major stores — many do — but the stores are not neutral ground. Distributing outside them is effectively blocked on iOS without technical workarounds. Android is more permissive: sideloading is permitted, and alternative stores like F-Droid exist specifically to distribute libre software, often with stricter no-tracker requirements than Google Play enforces. F-Droid builds apps from source itself, which is one way of addressing the question that open source raises about trust: knowing the source code is public is not the same as knowing the binary you downloaded matches it.

FOSS applications can and do appear in both major stores — many do — but the stores are not neutral ground.

The curation promise also has limits that are easy to understate. Both major stores have shipped malware — apps that passed review and later turned out to exfiltrate data or run ad fraud. Review processes catch a proportion of bad actors, not all of them. The security guarantee is probabilistic, not absolute, and the store's brand tends to absorb the credibility that should attach to individual scrutiny.

a mechanical keyboard on a wooden desk in low light
a mechanical keyboard on a wooden desk in low light — the desk, where all of this actually happens.

Key facts · the words used here

sandboxing
technical isolation that limits what an installed app can access on a device
sideloading
installing an app outside the official platform store
in-app purchase
payment made inside an already-installed app, often subject to store commission
curation
a store's process of reviewing and approving apps before distribution

Section 03The question that changed

Before app stores, the question was: can I trust this developer? After them, it became: can I trust this platform? That is not obviously a better question — it is just a different distribution of risk. You traded a thousand uncertain strangers for one powerful intermediary whose interests align with yours on malware but not necessarily on privacy, pricing or openness.

The practical upshot for anyone thinking carefully about their software: the store's presence is not a reason to skip your own assessment. An app that requests unnecessary permissions is worth questioning whether it arrived through a curated store or not. Sandboxing reduces the blast radius of a bad choice; it does not eliminate the choice. The gate handles one problem well and leaves others standing, which is roughly the honest account of every security measure that has ever existed.

  1. 2008Apple App Store opens; establishes the review-and-sandbox distribution model
  2. shortly afterGoogle Play (then Android Market) follows with a parallel model

Apple App Store

Referenced in this piece

Apple's mobile software marketplace, iOS/iPadOS exclusive distribution channel

Google Play

Referenced in this piece

Google's Android app marketplace, dominant on Android devices

F-Droid

Referenced in this piece

independent Android app repository focused on free and open-source software

Programs and organisations are named as examples, not recommendations. Where we link, we link the official project page. The desk hosts no files and ranks no vendors.