9 ms·
> The right-click/control-click option for easily opening unsigned apps is no longer available. Users who want to open unsigned software will now need to go the
by frankjr 2y ago
> The right-click/control-click option for easily opening unsigned apps is no longer available. Users who want to open unsigned software will now need to go the long way around to do it: first, try to launch the app and dismiss the dialog box telling you that it can't be opened. Then, open Settings, go to the Privacy & Security screen, scroll all the way to the bottom to get to the Security section, and click the Open Anyway button that appears for the last unsigned app you tried to run.
https://arstechnica.com/gadgets/2024/08/macos-15-sequoia-makes-you-jump-through-more-hoops-to-disable-gatekeeper-app-checks/ https://arstechnica.com/gadgets/2024/08/macos-15-sequoia-mak...
- weaksauce 2y agoat least it's still possible (and maybe more accessible) if not a bit more inconvenient. the ctrl-click thing was kinda a hidden feature.
- whywhywhywhy 2y agolets stop pretending this is anything other than trying to make apps that don't pay $100 a year feel scary.
- drexlspivey 2y agoDon't Windows do the same? I feel like every single program I run, signed or unsigned, a dialogue pops up where I have to give permission.
- makeitdouble 2y agoThis change is about macos removing the pop up altogether so you need to go dig into the settings to give permission.
- quesera 2y agoAre you suggesting that Apple is making it less convenient for users to run unsigned binaries, because they want to increase developer program revenue?
- rpdillon 2y agoNot developer program revenue. At every turn where they have a choice, Apple does the same thing: sell devices increasingly locked to their own ecosystem, and sell it as a feature to protect folks. This strategy works really well: they actually have folks arguing that giving all Apple users fewer choices is a feature. They have been ratcheting down on freedom in OS X (and then MacOS) since 2011 or so when I stopped using Apple for personal use. The introduction of the Mac App Store, subsequent lackluster performance, and introduction of scary warnings about running unsigned code in MacOS tell most all of the story. This latest update is just another step in that direction, making running unsigned code that much more difficult. The obvious endgame is to raise the next generation of Mac users to only use the Mac App Store for software, effectively replicating the golden goose that the iOS App Store has proven to be.
- nozzlegear 2y agoI don't think I agree with your conclusion about their endgame being a replication of the iOS App Store golden goose, but I do see how it could come about. The reason I disagree is because changes like this oft remind me of the problems Facebook used to have (still do?) with stolen tokens and cookies that would come about from people pasting JavaScript into their browser's devtools console. Some poor schmuck would find a viral comment that said something like "Mark Zuckerberg doesn't want you to know how to get Facebook Premium! Copy and paste this code into your browser, ignore Facebook's warnings, they don't want you to get it for free!" And badabing badaboom, stolen credentials get sent to some server. I don't work at Apple and can only speculate on their motive, but since I advise my family to use macOS, it's my hope that this change would prevent them from reading something like "download this scary blob and then ctrl+click on it to open it for free Photoshop! Ignore Apple's warning, Adobe has paid them because they don't want you to get it for free!" It does make it slightly more inconvenient for me, but I think chromedriver may be the only unsigned code that I run regularly.
- lokar 2y agoThey don’t care about the money
- nozzlegear 2y agoWouldn't they just make it impossible to bypass gatekeeper in that case?
- wpm 2y agoPrecisely the kind of hidden feature that makes it easy for power users to bypass the "rules" Apple imposes on the platform, while still making it highly likely every day users won't know how to bypass the rules meant to protect them. More and more, I find that these sorts of "we know best" attitudes towards security utterly distasteful and the total opposite of empowering. Infantilizing, more like.
- schrodinger 2y agoI want that for my mom on her macbook pro. had an ipad, prefers laptop form factor. What I'd like is upon setup it asks if this is a dev machine, and change the preferences.
- raxxorraxor 2y agoThese rules do not protect the normal user. At some point they fail to install something they want to have and then my phone rings because their OS is shitty.
- IshKebab 2y agoWe're getting closer to the bottom of the slope! I wonder what their next step will be. 1. Need to disable gatekeeper to run unsigned code. 2. Need an active developer account. 3. You can't run downloaded unsigned code.
- api 2y agoThat's when I think about jumping ship. If they require the App Store that's the end.
- ryandrake 2y agoIf you zoom out and look at the trajectory release after release, all of these things are obviously coming. Every release we act surprised that it's slightly more difficult to run unsigned, un-notarized, un-sanctioned code, but somehow that Voice Of The Fanboy within us has us convinced that "surely this last change is where Apple will draw the line and stop!"
- schrodinger 2y agodev machines are their bread and butter though! if they were going to have done this and merge iOS and macOS, I think they'd (stupidly) have done so.
- Pesthuf 2y agoOne huge step closer to iOS. Damn it. I actually liked macOS but these changes are terrible for everyone but the most basic users.
- simonask 2y agoReally? This is _huge_ to you? How many unsigned apps are you downloading and running? This is one of those features where the benefits seem to very obviously outweigh the drawbacks. 99.9% of users just aren't running unsigned software, so the moment that happens, it is most certainly malware. If you're developing software yourself, this isn't an issue either, since all the relevant toolchains, debuggers, etc., work just fine under this model. That's a supported workflow. The only thing that isn't supported is downloading some random unverified app bundle from who knows where and treating it as if you could trust it. You 100% can't. And yes, I also believe that if an OSS project considers "muggles" their target audience, they should prioritize setting up code-signing. Consider it a service to their users. If the fee is a problem, it's important enough to spend the effort to find a way to finance it. If you can't find someone who is willing to put their name on it, you shouldn't ask people to run your software on their machines in the first place.
- mort96 2y ago> How many unsigned apps are you downloading and running? For me, quite a few? Internal tools at work, open source projects which publish builds on their github, that sort of stuff. (And no, paying Apple a yearly subscription for the privilege of letting users run an app is not a reasonable expectation of small open source projects)
- throwme_123 2y agoJust tell these advanced users to compile it themselves. Problem solved.
- tengbretson 2y agoThe users are too busy buying their mom iphones.
- nailer 2y agoSame nightmarish UI path as installing an app store on an iPhone.
- __jonas 2y agoMy god, I had no idea there was a shorter way than that, can't believe I'm finding this out just as they remove it, so annoying!
- mmmlinux 2y agoYeah same. Ive been doing it the long way for years apparently.
- veeti 2y agoOh, but I was assured by Cupertino sycophants that you "just" need to CTRL-click open an unnotarized app and there is no protection racket for distributing apps, no big deal. The frog continues boiling.
- deafpolygon 2y agoWeird, that's been how I was doing it ~4 years ago before I switched to Windows for a while.
- smsm42 2y agoWow, this is really hostile design. They obviously know they can't ban third-party software on macos like they did on iphone, but they surely intend to come as close to it as possible, and make it as inconvenient as possible to install any.