4 ms·
I dont mind Apple putting more restrictions around signing, but they make it SO onerous for Desktop users to explicitly allow unsigned apps. Tell me its unsign
by mesh 6y ago
I dont mind Apple putting more restrictions around signing, but they make it SO onerous for Desktop users to explicitly allow unsigned apps.
Tell me its unsigned and the dangers, but then give me the option to run it. Stop treating me like some dolt.
Right now, you have to really jump through hoops:
https://github.com/mikechambers/dcli/wiki/Running-dcli-tools-on-Mac-OS-X https://github.com/mikechambers/dcli/wiki/Running-dcli-tools...
(this is for a open source project I run)
- ogre_codes 6y agoI'm not sure why, but I don't see many of these prompts myself. You can disable Gatekeeper. sudo spctl --master-disable That should get rid of the prompts.
- asiando 6y agoI’d rather not. After the initial setup I don’t see that many annoying prompts either, I’d rather not disable security measures when they’re really not that painful.
- ogre_codes 6y agoI don't have it disabled myself. But if it's a burden, the option is there.
- GeekyBear 6y ago> they make it SO onerous for Desktop users to explicitly allow unsigned apps Not really onerous. However, you do have to use a terminal command to turn off Gatekeeper. https://www.imore.com/how-open-apps-anywhere-macos-catalina-and-mojave https://www.imore.com/how-open-apps-anywhere-macos-catalina-...
- webmobdev 6y agoHe means from the perspective of an app developer - it is hard to educate users when Apple's deliberate UI scares the user. Asking some some of them to disable Gatekeeper can also backfire with ignorant users, because it is a security measure against malware spread and execution (once malware is identified).
- GeekyBear 6y agoFrom the app developer's perspective, you can hardly spin a terminal command as any more onerous than a registry edit on Windows. Windows 10 SmartScreen is just as deliberate and just as scary.
- JosephRedfern 6y ago"Everyday" users shouldn't have to edit the registry in order to install an app, either. Being no worse than Windows doesn't make it good.
- deleted 6y ago[deleted]
- shawnz 6y agoYou don't need to pay anything or sign up for any app store to be approved by SmartScreen, and even if you are not approved there is a "Run anyway" button right there in the dialog.
- GeekyBear 6y agoYou absolutely have to pay for an extended validation code signing certificate for Windows 10 Smartscreen to allow your installer to run.
- shawnz 6y agoThat's not true. Binaries can acquire a positive reputation by being commonly downloaded. However paying for an EV certificate (or getting windows logo certification) is the only way to bypass the warning with no reputation.
- GeekyBear 6y agoWhat new developer already has a reputation score? You absolutely have to pay for an extended validation code signing certificate, or your installer will be blocked by default. Third parties charge more for that code signing certificate than Apple does for a developer account.
- shawnz 6y agoTurning off gatekeeper disables the protections for all apps, not a specific app of the user's choosing. That is not what the other poster was asking for
- millstone 6y agoCompletely agree, especially because a signing key is $100 a year. Feels like the church selling indulgences. That said, it's not quite as bad as your link. The secret is to right click or control click on the app, and choose Open. The warning dialog will have an Open button to bypass the Security pref pane. (Though maybe that doesn't work for you since you're making a CLI tool?)
- ziaddotcom 6y agoI disagree, I don't really want the signing key to be $0.99 and someone just making 100+ developer accounts that can't be tracked with some leaked list of SSNs or similar. That would negate the whole point of the signing key for the end user almost entirely.
- _qulr 6y agoThe $100 fee is no barrier at all to professional criminals. Whereas it's a huge barrier for open source developers.
- ziaddotcom 6y agoMaybe a fee waiver for oss with certain licenses and dev accounts for .edu addresses with a couple other ID requirements would be a good start.
- _underfl0w_ 6y agoWhat you're seeking is proper identity verification, not necessarily a tariff or upfront cost to even do business.
- ziaddotcom 6y agoIs proper identify verification something that Apple can do at a marginal cost significantly lower than $100? I agree that the $100 fee in no way guarantees proper identity verification has been done. I also see plenty of other unnecessary barriers the fee creates, I just don't know what an obvious alternative would be.
- vbezhenar 6y agoIt used to be option+click, then "Open". They removed that approach?
- JosephRedfern 6y agoSometimes, rather than giving me a "friendly" warning that the app is unsigned, I get and exception with a stack trace, with: Termination Reason: Namespace CODESIGNING, Code 0x1 I can (re)sign the application with: codesign --force --deep --sign - /path/to/The.app which often resolves the issue. but what's the difference between the error that causes the friendly warning, and the error that cases the stack trace/exception? Is this the difference between a lack of code signature and a failed check?
- sovande 6y agoIt’s a failed code sign of some sort. E.g. and typically, the developer used an installer cert for an app.
- fartcannon 6y agoThe point isn't to imply you're a dolt, but to slowly convince you to use the App store for the percentage they make.