6 ms·
> * And now macOS is adopting the worst of iOS' draconian policies. You won't be able to run non-notarized apps on macOS on Apple Silicon based computers at all
by stassats 6y ago
> * And now macOS is adopting the worst of iOS' draconian policies. You won't be able to run non-notarized apps on macOS on Apple Silicon based computers at all.
Where did you get that information and what makes Apple Silicon different here?
- dmoy 6y agoSome sort of security hypervisor on the chip?
- stassats 6y agoI don't think you need any hardware support for that. And notarization already exists on intel macs, just that it doesn't prevent you from launching non-notarized binaries.
- Rebelgecko 6y agoIt was discussed in this article and a bit in the comments yesterday: https://news.ycombinator.com/item?id=24217116 https://news.ycombinator.com/item?id=24217116
- supermatt 6y agohttps://developer.apple.com/documentation/macos-release-notes/macos-big-sur-11-universal-apps-beta-release-notes https://developer.apple.com/documentation/macos-release-note... "any executable must be signed with a valid signature before it’s allowed to run"
- stassats 6y ago> There isn’t a specific identity requirement for this signature: a simple ad-hoc signature issued locally is sufficient, which includes signatures which are now generated automatically by the linker. This new behavior doesn’t change the long-established policy that our users and developers can run arbitrary code on their Macs Ok, not really true.
- stassats 6y agoAnd as to >and what makes Apple Silicon different here I guess this is a backwards-compatibility breaking change, but Apple Silicon is a new platform so there's nothing to break, all new binaries will have it from the start.
- supermatt 6y agoWell, now you need to ad-hoc sign the app with the codesign tool, or compile it yourself. You cant simply right-click to open as you can at present. I am not sure if you can distribute ad-hoc signed apps - I think they are only signed for local use.
- stassats 6y agoSince there's no reason to do that only on arm and not on intel macs you would still be able to launch it after jumping over some hurdles. Just that now the linker automatically signs every binary. So that something like gatekeeper could disable it based on the signature. That would be my non-"apple is draconian" interpretation, as I don't have an arm mac.
- supermatt 6y agoThe linker doesn't sign every binary - it signs every binary it links - i.e. binaries you build on the machine. That is not the same as it signing "every binary", otherwise there would be no point in signing in the first place. I'm not sure how I feel about it, personally. I think code signing is a great idea. I just don't believe this single authority approach is the way to do it. I totally understand that as you already trust apple to provide the OS, it makes sense that you can trust them to sign apps - but that shouldn't mean you cant (as a user) choose to trust other parties. Of course, they don't actually check the apps aren't malicious - they don't even check that you are a real person when you create a dev account... But they do have a signature they can revoke if your software is exposed as malware.
- stassats 6y ago