4 ms·
Out of curiosity, what do you find annoying about it?
by nmgycombinator 1y ago
Out of curiosity, what do you find annoying about it?
- muppetman 1y agoEvery time I update an app I have to be told I downloaded it from the Internet and do I trust it. Can this app look on the local network? Constantly being nagged to the point I don't even check/care anymore. Exactly what Vista used to do.
- nmgycombinator 1y agoThe local network popup thing is too overdone in my opinion. However, I do think it is a good choice (in some respects) for Apple to have the "this is a program downloaded from the Internet", even if it can be annoying. It might also be a push to get developers to publish on the App Store (where Apple can be more sure (hopefully) that the apps are safe). It's a double-edged sword in my opinion. I think it's good that the OS is looking out for the user in a lot of cases. I also understand how it can give the users pop-up fatigue.
- bigyabai 1y ago> It might also be a push to get developers to publish on the App Store (where Apple can be more sure (hopefully) that the apps are safe). This is exploitation of developers, plain and simple. Apple should secure their runtime, not roleplay as a software rent-a-cop that manually (and fallibly) inspects submissions. The App Store is a blatant moneymaking racket, on mobile and desktop alike. "Security" is a fig leaf for the perverse incentive Apple has to corral developers under their thumb.
- nmgycombinator 1y agoHonestly, I think you have a fair point there. I personally don't believe that any system could be 100% secure. But I do think there is a point to be made on the efficacy of securing the runtime compared to individual app inspection.
- charcircuit 1y agoApple does both. They secure the runtime and review apps.
- bigyabai 1y agoAnd to NSO Group's delight, they don't review SMS messages or Safari contents either. The "curated security" shtick is a lie, it does not protect anyone and doesn't function reliably in the first place. Both targeted malware and generic scams are rampant and unrestrained on iOS. Many of them are promoted as iPhone Search Ads, or suggested Siri results. The knock-on effects it has are even worse. By relying on this game of shuffling private entitlements around, Apple has less incentive to actually review what developers are doing with them. Look at the Uber iPhone app's screenrecord permissions, or when TikTok stole iOS clipboards. Apple uses "secure" review as an excuse to not review apps or secure their runtime.
- charcircuit 1y agoBut they do secure their runtime. It's not an excuse not to.
- saagarjha 1y agoApple's review sucks but you are very confused about your "takedown" of their security practices. It's not meant to protect against everything. Even well-made security boundaries can fail against sophisticated attackers, or be too onerous against generic malware.
- p_ing 1y agoI think entitlements are the correct direction to move in. I don't like Apple's implementation. But it gives us that fine-grained control of what an app can and cannot do with things outside of the app's "bubble" (or sandbox). We need Discretionary Access Control.
- trollbridge 1y agoI simply run `xattr -d downloaded-app.dmg` on apps I download that I trust to turn off this behaviour.
- dylan604 1y agoyeah, 'cause that's so much easier than just saying yes to the prompt, or right-clicking and selecting open from the context menu
- p_ing 1y agoIn macOS 15, there is no GUI bypass. Right click -> Open no longer works. xattr is "the way". I'm sure someone has probably created an Automation or something for it.
- nmgycombinator 1y agoThere's a small section in System Settings that they don't really tell you about that pops up when the OS blocks a file from opening. You can then override the block there. Yes, it's extremely annoying.
- trollbridge 1y agoI have an alias set in my shell for `xattr -d ~/Downloads/.{dmg,zip,z}`.
- deleted 1y ago[deleted]
- ben-schaaf 1y ago> It might also be a push to get developers to publish on the App Store (where Apple can be more sure (hopefully) that the apps are safe). Apps on macOS need to be signed and notarised. Apple has the exact same capability to scan for malicious behaviour and revoke your keys regardless of how you publish. We all know the real reason they want to push apps towards the app store.
- zakki 1y agoMicrosoft was right.
- DecentShoes 1y ago*the App Store where apple can be more sure they'll get a 30% cut
- mike_hearn 1y ago"This is a program downloaded from the internet" isn't a push to the app store. It predates the Mac App Store, iirc. It's another quick security hack (as they often are in any OS). Many years ago someone noticed that apps can pick any icon they want. And, therefore, if you could convince a browser to download a file to ~/Downloads (not hard), the user might look inside and find what appears to be a harmless JPEG or Word document, double click it and are immediately pwnd because back then there was no app sandboxing of any kind, no SIP etc. macOS in that era was a conventional desktop UNIX. So the quick hack - make apps that download things mark files with extended attributes, and if the Finder sees that, it pops up the warning and then removes them. Now the user realizes (maybe) that the document-looking-thing was actually an app.
- nmgycombinator 1y agoThat's a fair point. But did Mac have the same issue as Windows where file extensions were not shown by default? That feels like it would have been the core issue.
- thewebguyd 1y agoThere is a "show all file name extensions" option in Finder, but I don't recall if it's on by default or not as I haven't had to set up a fresh macOS install in a while and I've always had it turned on. But, macOS isn't like Windows - the file extension doesn't matter. I can have a "file.txt" but it's actually a .xlsx excel workbook, and Excel will open it just fine (albeit, with a warning that the file extension doesn't match but that's dependent on the application presenting a warning). Windows actually uses the file extension to determine the type, macOS (and other *nixes) don't, they'll use some other file metadata. You can put whatever extension you want on a file, it doesn't matter except for determining what default app will attempt to open it when double clicking it in Finder.
- jeroenhd 1y ago> where Apple can be more sure (hopefully) that the apps are safe Ha, they'd love to capture the 30% Apple tax on macOS too, I'm sure. I don't think the mark-of-the-web feature is bad, but I am particularly annoyed that I have to open the system settings app to open an application. Honestly, when I first tried modern macOS, I was surprised how bad the popups and warnings were. This is exactly what Apple (rightfully) made fun of when Vista came around. I've caught myself mindlessly approving prompts because there are so many of them and most of them don't make much sense at all ("do you want to allow iTerm access to your downloads" after I've explicitly dragged the thing to the special "developer tools" setting? what the heck?).
- TylerE 1y agoThe one that I find really obnoxious is granting permission to read from a “removable” drive. Like the one my steam library lives on.
- nmgycombinator 1y agoHow often do you face that? I would think the OS would save your response in a way it could refer back to.
- TylerE 1y agoFrequently. The problem is it’s per app not per drive. I had my entire homedir on there for a while but the prompts just got to be too obnoxious.
- nmgycombinator 1y agoDamn, that sucks.
- p_ing 1y agoThis isn't what Vista "used to do". Vista had a single elevation popup dialog / shatter attack prevention screen. Any request that required elevation required this popup. macOS has not only elevation requests but entitlements. Using the local network is an entitlement. What macOS gets very wrong is any denied entitlements will re-prompt next time you perform that action with the app, which may simply be starting the app. It also does one entitlement at a time, i.e. if you have an app that requires screen sharing and camera, you'll get the first entitlement, restart app, go to do action you wanted again, second entitlement. Both OSes have MoTW, but Apple goes beyond with the notarization warning/block. macOS users are going to suffer from prompt fatigue. And the /r/macos "secure cus UNIX!" will be wrong on two points.
- nmgycombinator 1y agoQuick clarification on terminology. From a developer perspective, entitlements a static dictionary (or a collection of key-value pairs) attached to the app at code-signing time. The entitlements you mentioned don't "entitle" the app to access resources, as user consent is still required. An app with [the com.apple.security.device.usb entitlement](https://developer.apple.com/documentation/bundleresources/entitlements/com.apple.security.device.usb https://developer.apple.com/documentation/bundleresources/en...) is technically always going to have that entitlement attached to the app regardless of user consent.
- sureIy 1y agoTechnically you're right. From an end-user standpoint, it's irrelevant. Apple's mock vista ad applies just as well to Ventura: they're all annoying and a security theater if the user is just told to input admin password into any random popup. https://www.youtube.com/watch?v=VuqZ8AqmLPY https://www.youtube.com/watch?v=VuqZ8AqmLPY
- jeroenhd 1y agoFWIW, Vista's level of prompts is the only way to run UAC in any kind of secure fashion. The configuration that has been the default since Windows 7 makes it trivial for a low-privilege application to gain UAC privileges. Microsoft doesn't regard UAC as a security boundary if you're logged in as an admin (https://learn.microsoft.com/en-us/previous-versions/tn-archive/cc751383(v=technet.10)?redirectedfrom=MSDN https://learn.microsoft.com/en-us/previous-versions/tn-archi...). You can use UAC as one as part of a defence-in-depth approach by logging in as a non-administrator user (like everyone tells you to do but nobody wants to do) and entering a password for every prompt, but for that to work well you'd need to make sure to turn UAC prompts back to max (read: Vista level or worse). I don't think I'd set up a system like that without a fingerprint reader or Windows Hello facial recognition camera, because typing out the password that often is just a massive pain. Windows, as configured by default, barely runs any downloaded files. You can pay hundreds of euros for a certificate, sign your installer, and still have users get told off by SmartScreen for daring to open an executable file. I don't think Apple's notarization has done anything useful so far, but their security prompts are a lot less scary than Windows'. I think it's a matter of time before unsigned Windows executables with the MotW simply won't open by default like those on macOS.
- bigyabai 1y agoOh god, don't get me started... 1. iCloud nags never go away if you don't log into iCloud 2. Apple Music is just an advertisement by default and "conveniently" opens every sound file mimetype 3. Functionally useless subscription slopware like AppleTV+ comes installed by-default for no reason 4. Package management is a colossal clusterfuck that can't even enforce package parity across system architectures 5. Apple still doesn't trust their users enough to have modern amenities like a native Vulkan runtime or Nvidia GPU drivers Vista was terrible, but it didn't suffer from this level of identity crisis.
- nmgycombinator 1y agoI agree that it's weird that Apple TV comes pre-installed. The others I have less experience with so I can't really comment on them.
- tough 1y agoyou might like https://github.com/philocalyst/infat https://github.com/philocalyst/infat to change the mimetypes associations
- bigyabai 1y agoI might prefer respectful default apps that delight the user and don't cost anything more than what I paid for at checkout. MacOS isn't for me, I guess.
- tough 1y agoI hear you, but 10y of MacOS usage habit will make that to you, it's easier for me to work around MacOS quirks and Apple's authoritarianism than it is to try and get a Linux distro I like to work perfectly for me for more than 6 months, or worse, go back to win
- louthy 1y agoSlight tangent: Apple TV constantly has MLS (major league soccer) and Apple TV+ in the left-side pop up Home menu, taking up real-estate for something I will never access. So annoying. Why, as someone from England — with arguably the best football league in the world — would I want to watch American Soccer? I don’t even watch the English league. The menu is: ——————— * Search * Home * Apple TV+ * MLS * Store * Library ——————— Title: Channels & Apps * This is where all the channels I have actually opted for live — separate from the Apple products that I don’t want ——————— Both Apple TV+ and MLS should not be on that menu permanently. And it should be possible to turn them off.