4 ms·
Microsoft's notorisation sounds fully automated and transparent, while Apple's is more political and hands on. Individual apps getting their notorisation slowed
by makeitdouble 11mo ago
Microsoft's notorisation sounds fully automated and transparent, while Apple's is more political and hands on. Individual apps getting their notorisation slowed down to a glacier pace because the platform owner doesn't like them doesn't seem to happen in Microsoft land.
- Earw0rm 11mo agoThe bigger difference is that Apple isn't just checking for malware, it's checking for conformance with various APIs, manifest requirements and so on. Not as strict as the iOS App Store, maybe, but it will refuse to notarize if it detects use of unsanctioned API calls. You don't even need signing for Microsoft's system to do what it does - it can operate on unsigned code, it's all hash based.
- makeitdouble 11mo ago> it will refuse to notarize if it detects use of unsanctioned API calls. Or really any reason. They're not supposed to exert editorial control but that's how it has been happening in practice.
- robenkleene 11mo ago> detects use of unsanctioned API calls Is there a concrete example of this? We know this isn't blanket policy, because of a recent story (https://news.ycombinator.com/item?id=45376977 https://news.ycombinator.com/item?id=45376977) that contradicts it. I can't find a reference to any macOS app failing notarization due to API calls.
- drysart 11mo agoNotarization doesn't blanket block all access to private APIs; but the notarization process may look for and block certain known accesses in certain cases. This is because notarization is not intended to be an Apple policy enforcement mechanism. It's intended to block malicious software. So in other words, using private APIs in and of itself isn't an issue. Neither is it an issue if your application is one that serves up adult content, or is an alternate App Store, or anything else that Apple might reject from its own App Store for policy reasons. It's basically doing what you might expect a virus scanner to do.
- robenkleene 11mo agoYeah, don't disagree with any of that, but I'm looking for explicit evidence that that is true (right now it sounds like it's just an assumption)? E.g., either examples of apps failing notarization due to API calls, or Apple explicitly saying that they analyze API calls. Without that it sounds like we're just guessing?
- Earw0rm 11mo agoI have experienced it myself but this was some years ago, may not be current. Think it was things they were trying to deprecate, which are now fully gone - was around the time they introduced Hardened Runtime, 2018-19 ish.
- hkpack 11mo agoI have the opposite experience - on macOS you can guarantee what users will see when you distribute your notarized app, while on Windows you cannot for undefined time. How often do you notarize your apps? Why does the speed matter at all? In my cases it takes 2 seconds for the notarization to complete.
- makeitdouble 11mo agoThe article is about iOS, and getting your notorization in 2 seconds or weeks is IMHO a big difference. There's obviously simple cases where the iOS notorization also flies in 2 secs, but there seems to be enough tougher cases: https://www.reddit.com/r/iOSProgramming/comments/1l9m7jd/how_do_you_deal_with_apple_notarization/ https://www.reddit.com/r/iOSProgramming/comments/1l9m7jd/how...
- robenkleene 11mo agoI went through the comment there, all of those look like the most likely explanation is just bugs in the notarization system.
- drysart 11mo agoThe length of time notarization takes depends primarily upon how large and complicated your app is, and how different is from previous versions of the same application you've previously notarized. The system seems to recognize large blocks of code that it's already analyzed and cleared and doesn't need to re-analyze. How much your binary churns between builds can greatly influence how fast your subsequent notarizations are. A brand new developer account submitting a brand new application for notarization for the first time can expect the process might take a few days; and it's widely believed that first time notarizations require human confirmation because they do definitely take longer if submitted on a weekend or on a holiday. This is true even for extremely small, trivial applications. (Though I can tell you from personal experience that whatever human confirmation they're doing isn't very deep, because I've had first time notarizations on brand new developer accounts get approved even when notarizing a broken binary that doesn't actually launch.) And of course sometimes their servers just go to shit and notarizations across the board all take significantly longer than normal, and it's not your fault at all. Apple's developer tooling support is kinda garbage.
- mort96 11mo agoWasn't there even a story some time ago about how some completely legit, legal, above-board app to virtualize old (pre OS X) versions of Mac OS got rejected by Apple's notarization process?
- makeitdouble 11mo agoYes. Probably this story ? https://9to5mac.com/2024/06/19/iphone-pc-emulator-block-illegal/ https://9to5mac.com/2024/06/19/iphone-pc-emulator-block-ille...
- raddan 11mo ago“UTM SE” is now on the App Store. Perhaps this was just a mistake? https://apps.apple.com/us/app/utm-se-retro-pc-emulator/id1564628856 https://apps.apple.com/us/app/utm-se-retro-pc-emulator/id156...
- immibis 11mo agoIt was the standard business pattern of denying your competitors everything you can, unless it causes a third-party fuss.
- mort96 11mo agoI'm honestly not even sure it's about denying competitors anything. It feels more like denying their users. Apple has a long history of intently denying users the ability to do what they want LONG before any potential App Store competitors appeared.
- robenkleene 11mo agoNote this is an iPhone app (noting because this thread seems to mainly be about macOS).
- mort96 11mo agoNotarization is the same for macOS and iOS AFAIK. Both platforms have a separate app store review process that's even more strict than the notarization process.