9 ms·
I don't know the exact issues but might be related to the issues why I left Apple : I was developing a very successful little tool for MacOS ( https://github.c
by milgra 4y ago
I don't know the exact issues but might be related to the issues why I left Apple : I was developing a very successful little tool for MacOS ( https://github.com/milgra/macmediakeyforwarder https://github.com/milgra/macmediakeyforwarder ) which listened for keypresses. From 2016 to 2019 it became harder and harder to install it because apple added more and more restrictions to apps like this. By 2019, you had to enable the application explicitly to listen for events at least in three places deep down in the system preferences, click accept in various popups and if you stuck somewhere then nobody could tell why it wasn't working. So I had a very expensive laptop and the OS didn't let me use it freely. So I just switched to freebsd and linux. Hardware quality is far away from Apple's but it is cheap, I don't have fancy productivity apps like photoshop and final cut but with open source tools and with my own desktop applications I created the best looking/most usable desktop experience MacOS will never have. ( https://swayos.github.io/ https://swayos.github.io/ )
- dtgriscom 4y agoGiven that it should be difficult, if not impossible, for random applications to listen in on user actions, is there a better way Apple could have done this? (Disclaimer: Apple fan/user since 1985.)
- milgra 4y agoA popup on the first start with an alert and a password prompt is a good solution, but usually too many users type in their passwords blindly in case of a password prompt, so I would go with just an alert with "you need root privileges to run this app" and then they have to figure out 1. why do they need root privileges 2. how do they start an app with root privileges.
- deleted 4y ago[deleted]
- KerrAvon 4y agoThe security barriers for getting keyboard events in macOS are not as simple as “root has access to everything”, and for various reasons can’t and shouldn’t be that simple. So ignoring that part, Apple could make this into a one-click solution, but the number of legit apps that need to do this are so small that it’s very unlikely they will dedicate engineering time to it. This is obviously where open source is superior. Apple probably can’t justify cleaning this up in macOS, but you can just go in and make it easier on on Linux if you have the knowledge and time.
- tomrod 4y agoOne click is preferred. Anything that gets in between a legitimate program and the user is friction.
- kitsunesoba 4y agoI think permission systems are bound to wind up in all desktop operating systems, eventually. They’re already on Linux for those using Flatpak. Trusting random third party binaries with access to everything is increasingly too much of a gamble, even for more technical users. That said, I agree that the macOS implementation has issues. It’s tricky though, because if they make it as simple as confirm/deny dialogs, you’ve set users up to quickly succumb to “yes-click syndrome” which is likely why Apple went with the “flip a switch in a preference pane” design for some permissions instead.
- wkat4242 4y ago"Random third party binaries" are not something Linux users really use, generally. Most of it is open source and comes through the repository.
- kitsunesoba 4y agoRepos are generally safer yes, but they can still act as vectors for malware. There’s also systems like Arch’s AUR which is quite popular and more likely (if still unlikely) to carry malware, to the point that the Arch Wiki warns that use of AUR is at the user’s own risk. Plus, many people are going to need to use proprietary software, which is always an unknown and likely to act badly in any number of ways. A lot of such software is Electron-based to boot, and devs are notorious for using ancient (and vulnerable) Electron versions.
- sandworm101 4y agoExcept when it comes to hardware. Proprietary drivers are still widespread.
- stametseater 4y agoIndeed. The idea of flatpack is to change desktop linux culture by normalizing the installation of 3rd party software, particularly proprietary software that people otherwise wouldn't trust without some form of sandboxing. Who does this benefit? I can think of two groups of people. 1. Commercial software vendors who want more Linux users to install their proprietary software. 2. 'Transplants', new Linux users who are already accustomed to the Windows/MacOS style of wantonly installing proprietary third party software they downloaded off random corners of the net, and don't want or know to change their habits. The value proposition for experienced linux users who don't do that sort of thing in the first place is next to nil. The only applications that might benefit from such sandboxing are applications like browsers, which have large attack surfaces and might be compromised while browsing the net. But even this is mostly theoretical, not a realistic day-to-day concern for typical linux desktop users.
- equivocates 4y agoMaybe this is an unpopular opinion, but I prefer my OS put several hurdles in front of a key logging app.
- milgra 4y agoEven if you downloaded that app explicitly for key logging? That's crazy! :)
- tourist2d 4y ago... and the OS is supposed to determine your intent how?
- noisy_boy 4y agoBy whatever mechanism the OS has to verify that you have the privilege. E.g. sudo. Not by raising a plethora of hurdles.
- oefrha 4y agoAn admin password prompt is hardly a deterrence to people doing stupid things. A young physics PhD friend of mine fell victim to a tech support scam, happily installing whatever spyware “Apple Support” told her to install over phone. That was a few years ago. The average person is too easily social engineered into allowing anything.
- wutbrodo 4y agoSure, I don't think either this[1] commenter or Ken Thompson were trying to say that the product category shouldn't exist. A computer is vastly overpowered for what the average user is capable of or interested in doing[2], which is why toy devices like iPads are so popular. I interpreted both of their comments as claiming that the direction MacOS is taking is a poor fit for those who still get value from powerful, general-purpose computers (myself very much included! I occasionally have the misfortune of using Macs, but am much much happier on systems where I can dig as deep into its layers as I need to solve my problems or scratch my itches) [1] https://news.ycombinator.com/context?id=35219381 https://news.ycombinator.com/context?id=35219381 [2] Though I do think it's a minor tragedy that the increasing amount of guardrails has narrowed the opportunity for an inquisitive youngster to explore his computer's internals
- drivers99 4y agousing Second Reality as the music for the swayos video was a pleasant surprise
- milgra 4y agoI'm glad you liked it! I miss the golden age of tracker music/demoscene.
- Blikkentrekker 4y agoThe situation with Wayland is actually worse than this by far.
- asveikau 4y agoNot sure what you mean. But at any rate, Wayland is completely optional. You can keep running X and nobody will stop you. People will keep running X without issue for a very long time. This is very different from what the Apple world is like.
- Blikkentrekker 4y ago> Not sure what you mean. Many of the things one can at least ask permissions for as I read it on the Apple system are actually purposefully simply not available due to similar concerns. Many of the leading Wayland developers believe in this. The Enlightenment lead developer for instance does not believe a programmatic way to make screenshots or listen to keypresses should ever exist. I had some debates with him about this and he believes the risks are too high as well as revealing that he seemed to believe that streaming videogames did not work by way of a third party tool that captures the screen contents, but that each video game had this functionality built in, which is certainly not the case and that he believes this might explain his reluctance for such an a.p.i. to facilitate this. > But at any rate, Wayland is completely optional. You can keep running X and nobody will stop you. People will keep running X without issue for a very long time. This is very different from what the Apple world is like. Opinions are divided on that matter. The reality is that many of the developers of Xorg have abandoned in in lieu of Wayland and many Wayland developers, many former Xorg developers are clear in their opinion that they see it as a replacement, not an alternative and eventually expect everyone to switch. Whether that will happen is anyone's guess. They are often met with counter arguments that Xorg and the X11 protocol itself simply has features that many businesses and private individuals need for their lifelihood so there is going to be commercial incentive to pick up maintainership should they abandon it. They have also conceded heavily already on many of the features they initially said where either unneeded or a security risk when they realized the reality that many people outside of their bubble did use them. Libinput originally did not have any mouse acceleration settings on the argument that no one would want to turn it off or fine tune it to begin with, but now has it when they realized that unlike what they thought, demand for the ability to fine tune or turn off mouse acceleration is higher than they anticipated.
- kergonath 4y ago> By 2019, you had to enable the application explicitly to listen for events at least in three places deep down in the system preferences, click accept in various popups and if you stuck somewhere then nobody could tell why it wasn't working. It’s an improvement for users because it means that not all random applications and programs that run can act as keyloggers. It’s optimising for the common use case (random people running random software and being very annoyed if they get ransomed) against the rare case. It’s the same thing with debuggers and attaching to other processes. In the end it is a good thing to not be able to do that without explicit authorisation. > So I had a very expensive laptop and the OS didn't let me use it freely. It does not prevent you from doing it. It added some friction, sure, and you can find that this friction is unacceptable (and changing OS every now and then is a good idea in general anyway). But from a fundamental perspective the functionality is still there. The OS still lets you do this. > I created the best looking/most usable desktop experience MacOS will never have. It is great that you have both the ability and the time to do this. I’ll look into it for my Linux boxes. However, my experience is that it’s never actually “the most beautiful/user-friendly/consistent/polished” (things we see all the time with new DEs). They all tend to fall apart with millions of corner cases and inconsistencies every time you get off the beaten path. In any case, good luck with your project.
- elcritch 4y agoSure optimizing for security makes sense, but Apple isn't just doing that. They're also removing ways to override those restrictions. Often old methods to disable them or to whitelist an app silently stop working. Sometimes new ones don't always work, or require an absurd number of hops. It seems alongside security there appears to be a strong desire at Apple to make macos a walled garden like iOS devices. They've hamstrung mobile safari for years to ensure the app store doesn't have competition from web apps.