5 ms·
Good. The other day the App Store was down and I couldn't use half of my downloaded apps because they failed "verification". I'll be happy as a clam to see more
by nicksergeant 11y ago
Good. The other day the App Store was down and I couldn't use half of my downloaded apps because they failed "verification". I'll be happy as a clam to see more developers move their apps off of the App Store.
- deleted 11y ago[deleted]
- Already__Taken 11y agoSteam does this to me as well sometimes. Why can't these stores use some kind of encryption that can just validate "Yes at some point in the past this has been purchased on this computer" and leave it at that. Always online frankly seems excessive.
- roosterjm2k2 11y agoSteam seems to remember for a while... i've played Euro Truck Sim while traveling with no internet...
- WorldMaker 11y agoIt varies with different games on Steam. Steam doesn't require its DRM, so some games have no DRM, even when installed by Steam, which is great. More critically, though, Steam also doesn't require its DRM be exclusive so some games are protected both by Steam's DRM and something else, where that something else may have its own weird requirements before launching a game.
- facetube 11y agoCan confirm. I bought Goat Simulator from Steam about a year ago, have uninstalled Steam, and even moved the application between OSs and devices without any issue.
- forgotmypassw 11y agoThat's why we should promote DRM-free software distributions - like GOG.
- X-Istence 11y agoThat's exactly what Apple's scheme does, except that Apple's root certificate expired... There is no communication between you and Apple when you launch applications.
- dkonofalski 11y agoThat's not true. Apple issued a new root certificate using the latest OpenSSL standard. The apps that "expired" were using an out-of-date version. They technically shouldn't have worked in the first place, but Apple kept renewing the old SHA-1 certificate alongside the current one which allowed these apps to validate, despite using a cert that was obsolete since 2005.
- mingus68040 11y ago>Apple issued a new root certificate using the latest OpenSSL standard. The apps that "expired" were using an out-of-date version And they were simply following Apple's recommendation to statically link OpenSSL. An app which hasn't been updated in a year or two could easily fall into this trap.
- mikeash 11y agoWhich is to say, that's exactly what Apple's scheme does, except in one crucial point where it does not, which malfunctioned and caused a bunch of havoc. Why does a purchase receipt need to have an expiration date at all? It's stupid. This stuff should be once-and-done.
- baldfat 11y agoThere is an Offline mode in Steam
- walterbell 11y agoDo apps really contact the App Store to approve each launch? That would be a lot of tracking data that could be collected. How could it work if the endpoint is not connected to a network?
- nicksergeant 11y agoSomething like that. It's ridiculous. I could not use 1Password until the App Store came back up, which was pretty inconvenient. Tweetbot also had the same problem and the developer tweeted about the situation: https://twitter.com/tapbot_paul/status/664668084146339840 https://twitter.com/tapbot_paul/status/664668084146339840 (and more tweets around that timeframe).
- SyneRyder 11y agoI found this tweet from the Tweetbot developers even more significant, there was no way they could upload a patched old version to the Mac App Store to fix it: https://twitter.com/tapbot_paul/status/664822849534754816 https://twitter.com/tapbot_paul/status/664822849534754816
- deleted 11y ago[deleted]
- X-Istence 11y agoNo, they don't contact the app store to approve each launch. Apple has a root CA that expired, during this "event" apps wouldn't launch because they couldn't verify the code signing certificate. Apple updated their certificate, and all apps started working again. See: https://news.ycombinator.com/item?id=10560634 https://news.ycombinator.com/item?id=10560634
- dkonofalski 11y agoI already responded to you in another thread here, but this isn't true. The apps wouldn't launch because they were using an old, outdated version of OpenSSL that's been updated since 2005. They were referencing an old, out of date root certificate, not the current one.