A bunch of apps will be able to bypass Microsoft's new store and use own update methods
- Reference: 1627401611
- News link: https://www.theregister.co.uk/2021/07/27/microsoft_new_store_updates/
- Source link:
When Microsoft introduced Windows 11, the company confirmed there would be a [1]new Microsoft Store , backported also to Windows 10, in which all the content is "tested for security, family safety and device compatibility."
At the time it was the support for [2]Amazon-flavoured Android applications that drew the headlines, but Microsoft also said that "starting today, Windows developers can publish any kind of app, regardless of app framework and packaging technology – such as Win32, .NET, UWP, Xamarin, React Native, Java and even Progressive Web Apps."
[3]
In a [4]related video , Microsoft principal program manager Pete Brown explained that the new store means you can "publish those traditional desktop applications using your own install packages." Brown showed how developers can submit a classic setup application in .exe or .msi format, located on the vendor's own infrastructure, but with a promise that "once submitted, the binary at the provided URL must not change." It must also be a complete installer, not a downloader for another install package. The installer also has to run in silent mode.
[5]
Submitting a Win32 package for the new Microsoft Store
The [6]detailed terms for the new store have revealed an important limitation. For those apps "packaged as a Win32 App," the terms state that "end users will not be able to receive updates from the Store. Apps can be updated directly by you via your app that is installed on a Windows Device after download from the Store."
[7]You, too, can be a Windows domain controller and do whatever you like, with this one weird WONTFIX trick
[8]Windows 11 comes bearing THAAS, Trojan Horse as a service
[9]Latest Windows 11 Preview a well-rounded update – literally
[10]Securing the cloud while Windows burns: Microsoft pops CloudKnox in trolley
There is provision for the developer to replace the installer in the Store with a newer one, but the user will not be prompted to reinstall it.
There are a couple of problems with this approach. One is that the user experience for applications that handle their own updates is variable. Some applications update frequently and have annoying pop-ups, or install background services solely for this purpose.
[11]
[12]
Another issue is that if a user installs an application from the store, which then updates itself, the updated version has in effect bypassed any checks which Microsoft made on the submission. How can the company still state that the content is "tested for security, family safety and device compatibility?" This model is unlike that of Apple's stores on Mac or iOS, or Google's Play Store, where all updates come through the Store after automated vetting for security and quality.
Microsoft developer advocate Scott Hanselman [13]said that recent publicity around this issue is "misleading… apps can use MSIX and update. It says on each app page if it updates itself or if the store does. It's pretty clear."
[14]
The word here with a special meaning is packaging. A Win32 application can be packaged as [15]MSIX , Microsoft's modern packaging format, in which case it will get auto-update. Apps packaged using the older MSI format, or a .exe installer, will not.
The issue is that users cannot be expected to understand the difference between MSI and MSIX, and may put unwarranted trust into apps downloaded from the Store by this mechanism. A Twitter user responded to Hanselman, [16]saying : "Also misleading. You're acting as if any Win32 could use MSIX while the majority does not… even your in-house VS Code still doesn't use it."
This is another example of Microsoft's weaving as it tries to satisfy the demands of security and a modern mobile-like experience – which was at its tightest in the Metro environment of Windows 8 or the locked-down Windows RT – and keeping faith with the expectation that a Windows PC will run any Windows application. ®
Get our [17]Tech Resources
[1] https://blogs.windows.com/windowsexperience/2021/06/24/building-a-new-open-microsoft-store-on-windows-11/
[2] https://www.theregister.com/2021/07/19/microsoft_windows_11_hands_on/
[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_software/applications&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YQCCFZ-g3mp08uefu7AjJAAAAIc&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[4] https://developer.microsoft.com/en-us/microsoft-store/desktop-apps/
[5] https://regmedia.co.uk/2021/07/27/package.jpg
[6] https://query.prod.cms.rt.microsoft.com/cms/api/am/binary/RE4OG2b
[7] https://www.theregister.com/2021/07/26/petitpotam_microsoft_windows/
[8] https://www.theregister.com/2021/07/26/windows_11_comes_bearing_thaas/
[9] https://www.theregister.com/2021/07/23/windows_11_preview/
[10] https://www.theregister.com/2021/07/22/microsoft_cloudknox/
[11] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_software/applications&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YQCCFZ-g3mp08uefu7AjJAAAAIc&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[12] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_software/applications&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YQCCFZ-g3mp08uefu7AjJAAAAIc&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[13] https://twitter.com/shanselman/status/1419737569747603470
[14] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_software/applications&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YQCCFZ-g3mp08uefu7AjJAAAAIc&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[15] https://docs.microsoft.com/en-us/windows/msix/overview
[16] https://twitter.com/L0nghanks/status/1419749326834835458
[17] https://whitepapers.theregister.com/
What could possibly go wrong?
Brown showed how developers can submit a classic setup application in .exe or .msi format, located on the vendor's own infrastructure, but with a promise that "once submitted, the binary at the provided URL must not change." It must also be a complete installer, not a downloader for another install package. The installer also has to run in silent mode.
And of course if the developer goes bust there's no chance of their domain getting nabbed by a ne'er-do-well.
Re: What could possibly go wrong?
I'd expect a certificate to be involved, so that won't pose a risk.
It seems to me that it would have been wiser to restrict the store to applications that can be updated through the store.
Many people these days have certain expectations of app stores. By doing what they've done, they have made the situation confusing.
It cannot surely be *that* difficult for an application vendor to repackage their application to use the new MSIX format for the store. I would imagine that it is similar to packaging for both RPM and DEB, perhaps a bit of a pain to set up, but once done, it is a mundane maintenance task.
It looks like they're trying to lower the bar again since nobody jumped it when they lowered it last time.
Does that mean I can submit e.g. a Linux installer, which will (among other things) suggest erasing a previously installed Windows system?
If not, why not? it's definitely "tested for security, family safety and device compatibility."
You could submit a WSL distro to the store, and then push an update that enhances the experience by installing it natively.
I hope someone actually does it.
App Stores
All the app store operators are scurrying for the corners like cockroaches in a brightly lit room.
They must be seeing the writing on the wall that's coming from the Epic/Apple battle of earlier this year.
Ever notice that thieves come in droves, and when they do the sheriff goes on a drinking binge.
All of the obscurity, non of the security
Worst of both worlds
Just a setup.exe on a website will do.
Actually, if Microsoft just provide me with a public www directory that I can upload exe installers, Linux deb/rpms and macOS dmgs, that would be useful. They can keep the rest of that silly store crap however.
Microsoft need to offer some reason why devs would use their store
MS: Hey, developers! Use our store! You can keep 70% of your app revenue!
DEVS: Er, can't we just put it on our website and keep 100%?
MS: And you don't have to use UWP any more! You can keep 70% of your app revenue!
DEVS: Nah, I'm good with 100%
MS: It has auto updating and you can keep 85% of your app revenue!
DEVS: 100% still better.
Microsoft & Windows
It’s like a Groundhog Day train wreck.
Why can they not get anything right?
Copy Apple for fucks sake, it won’t be invented in Redmond, but fuck it, it might actually be useful!!!!
Perfect attack vector
So let me get this straight...
"For those apps "packaged as a Win32 App," the terms state that "end users will not be able to receive updates from the Store. Apps can be updated directly by you via your app that is installed on a Windows Device after download from the Store."
So find an app used by your targets (with MS guaranteeing app security to the users for you :), identify the subset of users you want to target, compromise the app update infrastructure, roll out a silent update to the identified targets, and then clean up after yourself. REALLY? That's the latest in secure app distribution from MS?!?
Re: Perfect attack vector
Why all the hassle if you can just use print spooler?
The installer also has to run in silent mode
Oh, really? LIke a virus or something?
No freaking way! I expect at least the courtesy of a big freaking message saying 'Hey, I'm just going to install an update which will change your settings, remove useful features and activate more telemetry. But hey, rounded corners!'
Window Store
I think I used it to install some app and I to this day don't know whether it has installed or not.
Oh and to get WSL 2 working.
I am not sure what's the fuss is about. I think Microsoft should be pushed so that the Store and other junk apps can be uninstalled without "unintended" consequences.
Why bother?
I've never used the MS Store. I doubt I ever will.
More AC than Chicken shack
in which all the content is "tested for security, family safety and device compatibility."
Curious, I wonder what ‘tested’ means in this context and who pays for the testing and most importantly how do they pay for that testing. Excuse me if I’m unconvinced.