3 ms·
> There isn’t a specific identity requirement for this signature: a simple ad-hoc signature issued locally is sufficient, which includes signatures which are no
by stassats 6y ago
> There isn’t a specific identity requirement for this signature: a simple ad-hoc signature issued locally is sufficient, which includes signatures which are now generated automatically by the linker. This new behavior doesn’t change the long-established policy that our users and developers can run arbitrary code on their Macs
Ok, not really true.
- stassats 6y agoAnd as to >and what makes Apple Silicon different here I guess this is a backwards-compatibility breaking change, but Apple Silicon is a new platform so there's nothing to break, all new binaries will have it from the start.
- supermatt 6y agoWell, now you need to ad-hoc sign the app with the codesign tool, or compile it yourself. You cant simply right-click to open as you can at present. I am not sure if you can distribute ad-hoc signed apps - I think they are only signed for local use.
- stassats 6y agoSince there's no reason to do that only on arm and not on intel macs you would still be able to launch it after jumping over some hurdles. Just that now the linker automatically signs every binary. So that something like gatekeeper could disable it based on the signature. That would be my non-"apple is draconian" interpretation, as I don't have an arm mac.
- supermatt 6y agoThe linker doesn't sign every binary - it signs every binary it links - i.e. binaries you build on the machine. That is not the same as it signing "every binary", otherwise there would be no point in signing in the first place. I'm not sure how I feel about it, personally. I think code signing is a great idea. I just don't believe this single authority approach is the way to do it. I totally understand that as you already trust apple to provide the OS, it makes sense that you can trust them to sign apps - but that shouldn't mean you cant (as a user) choose to trust other parties. Of course, they don't actually check the apps aren't malicious - they don't even check that you are a real person when you create a dev account... But they do have a signature they can revoke if your software is exposed as malware.
- stassats 6y agoI think most binaries go through the linker, and since everyone will have the same linker version from the start it shouldn't be a problem. They also say >enable the system to better detect code modifications. So that part doesn't require any central authority and can be handled locally. (But I'm guessing there are more parts)