5 ms·
Ah fair enough, didn't know they were so strict with software distributed outside the App Store. I say the best thing to do is distribute your software using H
by 2cb 6y ago
Ah fair enough, didn't know they were so strict with software distributed outside the App Store.
I say the best thing to do is distribute your software using Homebrew then. As well as it being super convenient since it's effectively the same as apt or any other package manager common to other Unix systems, it bypasses Gatekeeper.
Got curious how and it's amazingly simple, it literally just provides an environment variable that deletes that "quarantine" xattr metadata.[1]
Tell your users Homebrew is the supported installation method and you can skip right over Gatekeeper.
[1] https://github.com/Homebrew/homebrew-cask/issues/85164 https://github.com/Homebrew/homebrew-cask/issues/85164
- stephenr 6y agoNotarizing is not strict by any definition of the term, unless you consider "scans your software for malicious content, checks for code-signing issues" to be strict? It's an automated system. Also, if you tell me your app is only installable via Home-brew, I'm not installing it. Comparing Homebrew to Apt, is like comparing a playdough and crayon sandwich, with an actual sandwich. Sure, they both look kind of similar at a distance, and technically you can eat both of them, but one is really not well thought out, and if you say you don't like how it tastes, the child who made it will get upset with you.
- 2cb 6y agoWhat is your specific beef with Homebrew? You insult it but don't provide any reason it's so much more inferior compared to apt. There are some ways Homebrew is actually more secure than apt. For example in order to do anything with apt you must give it superuser rights. The same is not true of Homebrew, which installs binaries in userspace and explicitly tells you to never use sudo. A Homebrew installer is a simple Ruby script you can easily audit for yourself. The packages are SHA256 signed to ensure code integrity. You can point it at a specific repo you trust and tell it to get a package from there. All downloads are done through a TLS connection, which is not the case for apt. And of course the whole thing is open source. I fail to see where the hate is coming from. > Notarizing is not strict by any definition of the term, unless you consider "scans your software for malicious content, checks for code-signing issues" to be strict? I mean, having to register as a developer, get a certificate to sign your apps, and still have to send off your software to Apple each time you update it before you can distribute it on your own website is pretty "strict" compared to every other OS. It doesn't seem to do much to prevent malware in the wild either.
- yjftsjthsd-h 6y agoI don't have a stake in this fight, but some of those don't really seem like advantages over apt - > The packages are SHA256 signed to ensure code integrity. And apt uses GPG signatures. > You can point it at a specific repo you trust and tell it to get a package from there. Exactly like apt? > All downloads are done through a TLS connection, which is not the case for apt. Since apt enforces GPG signatures by default, this could be a privacy issue but shouldn't be a security issue. Unless you meant only for the sudo/non-sudo to be your point on being better than apt and the rest was just defending homebrew?
- forgotmypw17 6y agoAdding TLS into the picture introduces many extra failure modes. Examples: clock out of sync, wrong version of SSL, certificate signing problem. All of these things would cause your install to become non-upgradeable by a non-expert.
- easton 6y agoLast I checked homebrew doesn't ask for root every time because it changes the permissions on /opt/homebrew (or /usr/local/bin if you are on Intel) to allow you to install software as non-root. This is still extremely insecure, as you can now install/remove/upgrade software on the system without root's permission, which is annoying if more than one user uses the device. Not to mention other applications that you run can now also write to these directories and blow stuff up without your permission, whereas if the permissions were set as default you'd get a password prompt at least. I still use brew (because it has more apps than macports), but why in the world they made this decision rather than using, say ~/Applications (the macOS recommended practice for software that only one user needs) or ~/homebrew is beyond me (granted, apt doesn't do this either, but I'm 99% sure that you can do it with yum and it is how scoop works on windows).
- soraminazuki 6y ago> This is still extremely insecure, as you can now install/remove/upgrade software on the system without root's permission, which is annoying if more than one user uses the device. Can you name a single attack that requiring root for Homebrew can protect against? > but why in the world they made this decision rather than using, say ~/Applications (the macOS recommended practice for software that only one user needs) or ~/homebrew is beyond me Because it's not possible to distribute binary packages without using a predetermined prefix path. You can easily find devs bullied into explaining the same thing if you look into forums or issue trackers of any binary system package manager. > granted, apt doesn't do this either, but I'm 99% sure that you can do it with yum No you can't. Yum, like any other binary package manager, doesn't let users choose their own installation path. There are exceptions though, and RPM packages can be marked as relocatable by the packagers, but that's a rare case. > and it is how scoop works on windows Windows is an outlier here, because Windows programs are mostly relocatable by necessity. Scoop packages can't rely on shared paths unlike Unix packages. This is why you end up with so many copies of bash.exe on Windows.
- yjftsjthsd-h 6y ago> Notarizing is not strict by any definition of the term, unless you consider "scans your software for malicious content, checks for code-signing issues" to be strict? I'd consider "you can't ship software for people to run on their own machines without first uploading it to Apple to get their seal of approval" to be quite strict, regardless of what Apple actually does / looks at when you upload it to them. I don't care how low their bar is, I don't care that it's automated, I frankly wouldn't care if it was a complete automatic rubber-stamp with no checking at all - Apple forcing every developer to go through them is draconian.
- tokamak-teapot 6y agoIt does seems inconvenient but also intended to help keep the platform- and therefore users- secure. I’m not sure the word ‘draconian’ fits here, especially considering its original meaning and historical uses.
- forgotmypw17 6y agoIt makes the device non-serviceable without a central authority. You could not do anything with it offline. That means it is no longer a general-purpose computer, but an extension of Apple's cloud.
- tokamak-teapot 6y agoThis isn’t true. Software can be installed and used without being through this process, if the user explicitly allows it. Just as if I download some software that hasn’t come from a ‘store’ on Linux I check it out before using it and only set execute permission if I’m happy, I do the same on MacOS.
- forgotmypw17 6y agoAre you sure about that? I was under the impression that any program with a hash that had not been seen yet must be first approved remotely by a central server before it is allowed to run: https://sneak.berlin/20201112/your-computer-isnt-yours/ https://sneak.berlin/20201112/your-computer-isnt-yours/