8 ms·
Which APIs were only available via Mac App Store that prevented distribution outside it?
by pixelcort 8y ago
Which APIs were only available via Mac App Store that prevented distribution outside it?
- IshKebab 8y agoI'm assuming they are referring to the Network Extension API. It seems the forced transition to the MacOS app store has begun. I give it 10 years before apps from outside the store cannot run at all without disabling SIP.
- Wowfunhappy 8y agoAs long as SIP can be disabled I don't mind this outcome. However, that's a very big and important condition.
- 1over137 8y agoSIP is useful though. It would be better that we could have SIP enabled and still be able to install whatever we want without going through App Store.
- Wowfunhappy 8y ago> SIP is useful though I am very skeptical on this point. macOS, like all Unix systems, already limits privileges for non-root users. What do you accomplish by placing limits on root as well? If a malicious application gets root, you are very screwed. The app can encrypt most of your hard drive, monitor most keystrokes, do nasty things with your hosts file, and steal most of your personal data. It won't be able to directly inject itself into other processes and certain critical OS files we protected, but how relevant is that? As I see it, SIP's main purpose is to (1) prevent non-technical users from (completely) hosing their systems by copying and pasting terminal commands from the internet, and (2) to protect TCC.db so that apps can't bypass Apple's privacy system. If you're able to turn off SIP, you have enough technical knowledge than #1 isn't necessary. I suppose #2 may have some limited value, but not much. If I am completely off base on this, feel free to educate me—but in my several years of research I have not come across any plausible scenarios for when SIP's protection would be helpful. ------ Edit: One other relevant note: Apple lets you selectively disable and enable parts of SIP. So you'd likely be able to turn off sideload-blocking (or whatever it is) without disabling SIP completely, if you want to for whatever reason.
- pvg 8y agoIf a malicious application gets root, you are very screwed. SIP is a piece of design intended to make you less screwed when that happens.
- Wowfunhappy 8y agoYes, but how meaningful is that? If a thief breaks into my house, I don't particularly care if he can access the drawer where I keep pencils.
- pvg 8y agoI'm not sure I understand this but if you prefer it in terms of strange analogies - you're walking past a construction site where they're building a highrise and see they're hammering a giant steel pylon into the ground. You smirk and say 'that won't keep the rain out!'.
- Wowfunhappy 8y agoMy analogy was somewhat stupid and I apologize. Stated better: it appears to me that the consequence of a malicious app getting root is already so incredibly catastrophic, that at that point it makes little difference whether or not SIP is enabled.
- pvg 8y agoRight, and I'm trying (and seemingly failing, sorry) to convince you you are looking at it backwards. SIP is not there to magically save you in a system where an all-powerful administrative account is compromised. The goal is to come up with a system that doesn't have something like an all-powerful administrative account, among other security improvements. It's only part of an effort to retrofit an existing consumer desktop OS to be more resilient to adversarial software - a long and arduous one that all makers of consumer OS'es are engaged in and have been for years.
- IshKebab 8y agoThe issue is that normal users will not (and should not) disable SIP because it is complicated and scary. Therefore it will become unviable for 99% of apps to be distributed outside the app store, so they won't. I distribute an app outside the app store. It's free and open source, but not meant to be for technical users (it's art-related). I like people being able to use it, because I am a nice guy, but I also don't want to pay Apple $100/year and go through the hassle of putting it in the app store, if that would even work. My users are not going to disable SIP so if Apple continues in this way I really will be forced to put it in the app store (or more likely, abandon OSX).
- zx2c4 8y agohttps://developer.apple.com/documentation/networkextension/nepackettunnelprovider https://developer.apple.com/documentation/networkextension/n...
- Wowfunhappy 8y agoWow. Is there any way around this for a user? What if SIP is off? If there's no workaround, that makes me quite uncomfortable.
- oneplane 8y agoThere are plenty of workarounds, but the issue is that when you want to pass quality control you have to play by they platform owner's rules. While not always nice on one hand, on the other hand this does mean that most users will be safe to install most software checked and distributed that way, without needing the intimate knowledge we have. I totally understand that if Apple builds and maintains a PKI-based security model, they are going to want to check your stuff before allowing you in. If, on the other hand, the user doesn't care, they can simply turn off the security model or adjust it.
- Wowfunhappy 8y ago> they can simply turn off the security model or adjust it. I'd very much like to know what this involves. I'll feel better knowing how it can be done. If you have a link that would be great!