6 ms·
Apple's security measures feel like they're designed to protect Apple, with users as an accidental side effect.
by Ruq 4y ago
Apple's security measures feel like they're designed to protect Apple, with users as an accidental side effect.
- lockhouse 4y agoI think Apple struck an excellent balance with Gate Keeper. Your average user can’t run random software they accidentally download from shady sources, but yet it’s easy enough for power users to get around if they’re willing to accept the risks. If Apple ever takes away the option to run software that hasn’t been notarized then I’ll feel differently.
- m463 4y agothey did it with ios. my opinion of apple would change drastically if they let me run my own software on ios. Heck, I can't even access my full filesystem on ios. (EDIT: without asking permission, let alone paying or renewing a cert)
- kitsunesoba 4y agoApple has been pretty clear in that they consider Macs to be in a wholly different category of devices than iPhones, iPads, Apple Watches, and Apple TVs. It's why they bothered to make booting arbitrary operating systems a publicly accessible feature on M-series Macs, which they absolutely didn't have to do, with the iPhone/iPad having served as the basis of M-series Macs.
- deleted 4y ago[deleted]
- smoldesu 4y ago> which they absolutely didn't have to do Strictly speaking, Apple doesn't have to do anything. They're judged against the quality of their prior products though, and prior Macs have worked well with an unlocked bootloader. If Apple threw that feature away (like the headphone jack or 32-bit software), then it would have been noteworthy, but it's not. You're ascribing goodwill to something as simple as a non-removed feature. Whatever the case is with Macs, regulators at-large don't seem to agree with Apple's product segmentation. If they want to distinguish iPhones from Macs, they'll have to find a way that doesn't undermine user authority.
- renewiltord 4y agoYou have to pay Apple for the developer program membership but after that you can write your own code and run it on the iPhone.
- lilyball 4y agoThey didn't take it away on iOS, it was never a feature of iOS to begin with.
- lapcat 4y agoThere are many known instances where malware from shady sources has been notarized. Anyone in the world with $99 can join the Apple Developer Program, and Apple's automated malware checker is not that great. Moreover, any innocent appearing app can download another app and run it without having to go through Developer ID or notarization, so the whole thing is security theater.
- oneplane 4y agoWhat it mostly provides is a revocation mechanism, which in itself is relatively powerful. On top of that, there is the notary mechanism which further strengthens the option of creating a digital immunity system. The main issue is the balance between security and usability, which is not something that is perfectly solved within a single decade.
- whartung 4y agoIt's certainly an improvement, but in the end it ends up like the "type in your password to continue installation". If an app is not notarized, you can right click and open it. Do either of these enough, and it becomes automatic. Back in the day, on Windows, pretty much everything out of the box had to be installed "as admin". Even the most mundane apps required admin. Folks just routinely simply logged in as "admin", giving every random app privilege, make the limitation effectively pointless. Many apps on the Mac require an admin to install them. It's not universal, like it seemed to be on Windows, but many apps require admin. It's not a leap to blindly right click on a new downloaded installer, and type in your password to install it. Or "<App> wants to access removable media" "OK!" We're conditioned to just click through these warnings because, honestly, we just want the software, and we just want it to work. We don't want to interview everything as a hostile party.
- nyanpasu64 4y agoJust the other day I tried installing a custom Webcord build to fix "select all" on macOS (https://github.com/SpacingBat3/WebCord/issues/319 https://github.com/SpacingBat3/WebCord/issues/319). Surprisingly this time, right-click and open didn't make the "app corrupted" message go away, and I had to disable Gatekeeper entirely to install the package.
- cobbal 4y agoI find the command `xattr -r -d com.apple.quarantine SomeApp.app` goes a long way toward fixing many gatekeeper problems. For some reason, the right click often fails for me.
- mrguyorama 4y agoSupposedly the right click method only works if you have already attempted to open the app a normal way, and gotten the "error" message. Only then can you right click to open anyway.