5 ms·
In defense of Apple, if the account someone is using is not an administrator, they probably shouldn’t be downloading things in the first place.
by docbrown 7y ago
In defense of Apple, if the account someone is using is not an administrator, they probably shouldn’t be downloading things in the first place.
- twodave 7y agoHuh?! Explain your position here, please.
- brazzledazzle 7y agoNot the OP but: Some sysadmins and devs work in institutions where this wouldn’t be allowed or be practical to support (e.g. schools, some healthcare, etc.). It’s not universally applicable to every environment but it’s easy to get in the mindset that it is after you’ve seen what a determined idiot can do.
- twodave 7y agoOh, I agree there are plenty of scenarios where you want to restrict a user's ability to do something. But to draw that line at the admin level seems a bit overkill to me (and de-values the idea of having varying levels of privilege, which is more or less exactly what's going to happen for organizational users anyway). I'm not super familiar with Apple's business features but in a Microsoft shop this would (to an extent) be managed through group policy on the domain controller anyway.
- filleduchaos 7y agoI'm curious about _your_ position, actually. If a user doesn't have admin privileges and doesn't have the credentials to gain admin privileges, that's a clear indication that they both do not own the device _and_ haven't been trusted by the owner of the device to do whatever they want with it. Why exactly should they then be able to install and run random untrusted software on it?
- twodave 7y agoMy position is nobody ought to probably be running as admin for the vast majority of tasks, and having to elevate to an admin account in order to "download anything" would be a nightmare for any substantial IT department to support. Accounts ought to be granted privileges based on the user's need to get things done. Most consumer laptops and PCs I've seen (and I've seen a lot) don't even have a non-admin user account setup.
- filleduchaos 7y agoI don't quite see how an IT nightmare follows. Where do you work that people are downloading and installing software on work computers every day? > Most consumer laptops and PCs I've seen (and I've seen a lot) don't even have a non-admin user account setup. Have you ever used macOS or are you basing this on Windows laptops?
- twodave 7y agoI work on both, have friends and family and coworkers and acquaintances who use both. If they really didn’t want grandma running as admin they would make it harder to find.
- pilif 7y ago>My position is nobody ought to probably be running as admin for the vast majority of tasks in macOS, even if you run as admin, the only thing that gives you is `sudo` access. Your "admin" user still is a normal user, but it's allowed to gain elevated privileges by supplying their password (or doing biometric auth). The only difference between running as an admin and not running as an admin is that in the former case you don't have to type in your user name. >having to elevate to an admin account in order to "download anything" would be a nightmare for any substantial IT department to support normal users can download all they want. They can't execute it though. That's absolutely what I would like my machine to be configured as.
- Someone 7y ago”My position is nobody ought to probably be running as admin for the vast majority of tasks” Who disagrees with that? For most users, by a long shot, installing software is only a tiny fraction of the tasks they perform. Anybody, including that substantial IT department has to elevate to an admin account to install software, and that is a good thing. Any halfway smart IT department won’t have to type an admin password on every machine or even visit every machine, though.
- deftnerd 7y agoThat's an odd position to take. I purposefully make my primary account a non-administrator and elevate permissions with my administrator account when I need to perform administrative tasks. This prevents scripts or programs from misusing permissions without my knowledge. It's also the default policy of my work, a university. Staff do have local administrator access to their machines, but are not supposed to use it for regular operations for safety.
- snowwrestler 7y agoMe too, and when I need to install non-Apple-approved software, I log into my admin account, do it, then log out of it again. Once the software is installed, I can use it from my regular account. > Staff do have local administrator access to their machines, but are not supposed to use it for regular operations for safety. The point of this exercise is that installing random software from the Internet shouldn't be a regular operation; users should take extra care when doing it.
- dkonofalski 7y agoJust out of curiosity, why don't you just put in your admin credentials when the prompt displays? Logging completely out of the current account and logging in to another account just to install software seems way more convoluted than necessary.
- snowwrestler 7y agoThat's what I do if it's an option, but I think I've run into some software where that didn't work and I had to actually log into my admin account to install it. (But not log out of my regular one; more than one account can be logged in at once.) I can't recall what software that was, though.
- filleduchaos 7y ago> I purposefully make my primary account a non-administrator and elevate permissions with my administrator account when I need to perform administrative tasks So...elevate permissions when you need to perform this new administrative task? I don't see how that changes the crux of the matter (you still are the de facto admin, even though you've applied artificial constraints to yourself, because you hold the admin credentials).
- heavyset_go 7y agoIn defense of users, when my parents want to use an app, I'm not going to send them documents on the Unix security model or explain how macOS security diverges from it. They should be able to download and app and use it without having to call tech support.
- jakelazaroff 7y agoAlso in defense of users, they should be able to use any app they install without worrying whether or not it's malware.
- heavyset_go 7y agoAgreed. This is why a robust sandbox/containerization system is preferred to an arbitrary approval system. Anti-user features like intrusive telemetry are standard fare in commercial software, and running those apps in a sandbox could protect the user without having to rely on Apple's approval system.
- jakelazaroff 7y agoYup, that's why Mac App Store apps are sandboxed. The Mac App Store is the experience we're describing: install an app and use it without having to call tech support or worry about malware.
- heavyset_go 7y ago> The Mac App Store is the experience we're describing It isn't if the user wants to use software that isn't available on the App Store. Arbitrary programs can be run with the macOS sandbox, there is no need for the App Store for security.
- saagarjha 7y agoVery few applications opt in to the macOS sandbox outside of the App Store.