4 ms·
On the one hand, of all the big companies, Apple seems closest to “getting it” with respect to security. On the other hand, NO entity is inherently trustworthy
by makecheck 8y ago
On the one hand, of all the big companies, Apple seems closest to “getting it” with respect to security.
On the other hand, NO entity is inherently trustworthy “forever”, nor should any entity have the power to be a unilateral Decider even on its own platform. Just like when a good restaurant may some day become bad under new management, we are just one “new management” away from Apple becoming something that maybe we don’t trust so much. This system is being set up to give “Apple” tremendous power for “all future definitions of Apple”, which is ridiculous. That wouldn’t make sense even if Apple were a perfect saint today, invulnerable to buggy software and disgruntled employees and other potential weaknesses.
We need a system whereby users decide which SET of entities they trust, one of which may include Apple, and which may even exclude Apple if the user so chooses. The complex mechanism for signing and verifying things should be open-source so it can be understood and validated and reproduced cross-platform. Then you decide who you trust, period. You can rely on others to help you determine what is trustworthy. Given this type of system, I would be fine with macOS saying “select at least one trusted source to enable software installations”, knowing that I ultimately decide what those authorities will be. I am not fine with their seeming “father knows best” approach.
- Arqu 8y agoThat works for "us" HN geeks. The consumer market is all about convenience, and the monent the custoners have to go through some hoops a new company will pop up that will do it as a service which they then trust for doing it properly. And while I'm all for decentralizing power, I'd rather have 1 accountable company or a couple of them handle this compared to a bunch of small independent ones consodering they are less auditable and more open to skewing the system. Maybe something like the W3 consortium but we know how that turned out...
- darawk 8y agoTrue, but there need not be a convenience tradeoff. Make Apple the default signing authority, but make it configurable by the user. Normal users need not ever see it, but they retain an opt out if it ever becomes necessary.
- tobias3 8y agoMicrosoft does this with drivers since Windows 10 (attestation singing). I think this is okay, since users hold Microsoft responsible if the kernel crashes and this at least gives them the possibility to investigate. Signing apps with normal (EV) code signing certificates is the best we have for other apps, I think. If you detect malware signed by a a certificate you blacklist that one and foward information to the relevant criminal authorities. If they don't investigate you blacklist the whole country. That last step is probably the most controversial one, but otherwise you still have a malware problem.
- Tsubasachan 8y agoSure but you CAN install unsigned drivers if you want. Windows is pretty open about this, Apple is a walled garden. Safe but boring.
- ChrisSD 8y agoTo paraphrase an infamous quote: Apple have root. What good is any signing if you can't trust the OS? There are a myriad of ways they could undermine the verification.
- SXX 8y agoI'm not Apple fanboy in any way, but how exactly trusting Apple to hold root access to your system is any worse than trusting to baseband in any other smartphone? It's just whole chain of trust so fundamentally broken so there no way you can trust to any device and Apple at least not any worse here. In literally every phone baseband is not isolated, run it's own OS and can do anything to OS even if you have root. On top of that every ARM SOC have TrustZone that supposedly might also run any code and you have zero control over it.
- ChrisSD 8y agoI think you misunderstand me. If "new management" were to take over Apple and you no longer trusted them, why would you continue to trust their OS? In that scenario code signing is irrelevant because an untrusted OS can undermine it.
- JohnStrangeII 8y agoYour position is based on an (implicit) false dilemma. It's perfectly possible to "trust" Apple in the sense that you use their operating system and hardware after you've bought it. This kind of "trust" is similar to "agreeing with an EULA or TOS". There is not much of an alternative to it. This does not imply that you therefore must also trust Apple as the one and only broker and manager of certificates for software running on your machine. You could, for example, suspect that Apple might revoke a certificate for some developer that creates a controversial product (e.g. a p2p client) or some product that competes with Apple products or some future plans of features. For example, Apple has in the past essentially copied innovative apps and revoked licences for the app store of the original developers. In theory, Apple could just erase such applications, since they "have root". In practice, they wouldn't do so. But they would and will revoke certificates and app store licences. The new rules also make alternative app stores impossible, of course, although I'm not sure they were possible before. In a nutshell, trust != trust. You can trust a hardware or software maker in some respects but not in others. The primary goal of Gatekeeper is monopolization of secure access, not security.
- specialist 8y agoAgree. I humbly suggest that you add "revokable trust" to your "opt-in trust" thesis.