Friday was iPhone 6s day. I walked past our local Apple store around 9am on my way to get coffee and there was, predictably, a line snaking around the corner of the building. Not a huge one, this isn't a flagship store, maybe forty people deep, a mix of teenagers who'd clearly skipped first period and a few guys in suits checking their watches like the whole thing was cutting into a meeting. I did not join it. I've had a 6 since last fall and honestly, nothing about the 6s is making me regret that.
Which isn't a knock on the phone, exactly. 3D Touch sounds neat on paper, press harder on an icon and you get a little peek menu, but I tried it on a demo unit at lunch and it felt like one of those features you use twice and then forget exists, like Force Touch on the new MacBook trackpads. Live Photos is more fun, it turns your still shots into these three-second not-quite-videos, but I already know I'm going to fill up my camera roll with pointless motion clips of my coffee cup and regret it later. The Rose Gold color is the one thing that's actually driving lines, from what I can tell. Every single person I saw walk out of that store today was carrying a pink box.
Pricing-wise it's the same as last year, which I guess counts as restraint these days: $649 for the 16GB 6s, up to $849 if you want the 128GB Plus. The bump to a 12-megapixel camera and the A9 chip are real upgrades, nobody's disputing that the phone is faster. I just don't think "faster" is a good enough reason to eat a subsidized upgrade fee two years early.
The story I actually cared about this week
Buried under all the 6s coverage was something I think is a lot weirder and more worth talking about: XcodeGhost. Over the last week or so it came out that a bunch of iOS developers in China had been downloading a tampered copy of Xcode, Apple's own development tool, from mirrors that were faster than Apple's official servers (Apple's Chinese download speeds have apparently been bad enough that this was a normal workaround). That counterfeit Xcode quietly injected malicious code into any app built with it, no idea required on the developer's part.
The result was hundreds of infected apps sitting right there in the official App Store, including massively popular ones like WeChat, the messaging app practically everyone in China uses daily. Apple had to go pull them. Think about that for a second: the entire pitch of the App Store, going back to 2008, has been "we review everything, so you're safe here." And it turned out the compromise wasn't even in the apps that got reviewed, it was baked into the tool used to build them, before review ever happened. That's a much sneakier problem than a sketchy line outside a store, and a much sneakier problem than anything a fingerprint sensor or a pressure-sensitive screen is going to fix.
I don't think this is some death knell for the App Store model or anything, people are going to keep using WeChat and keep trusting the little padlock icon. But it's a good reminder that "closed and curated" isn't the same thing as "secure," it just moves where the weak point is. The weak point here was developer tooling distribution in a market where Apple's own servers were apparently too slow to bother with.
Anyway. My phone's fine. I'll probably upgrade next year when the case designs actually change and I need a new excuse to buy accessories anyway. If you were one of the forty people in that line this morning, hope the Rose Gold looks good, and hope your case order shows up before you drop it.