Live data from Hacker News

macOS 10.15 Vista

tyler.io

151–160 of 322 posts

Re: macOS 10.15 Vista

#151
post #87

I'm astounded with some of the user security dialogs that Macs display. I got one today: "VSCode wants to make some changes. Deny or Allow." That was the exact wording. Seriously? THIS. BENEFITS. NO. ONE. The only thing I can figure is that, somehow, Mac has required applications to display something to the user to get their permission to make some substantial system-level changes. But the application is, I guess?, a…

> centralized certificate signing authority to install something, I Trust That Application

You mean like how Facebook trusted the Cambridge Analytica apps which then went on to steal huge amounts of data.

Or how about all of the legitimate apps which include metrics libraries which have then gone on to steal huge amounts of data.

You simply can't trust the original signing process these days.

Re: macOS 10.15 Vista

#152

This isn’t a “step forward in user privacy” or whatever the others here are saying. It’s a mess and very poorly executed UX. Users will tend to feel overwhelmed and just click through modals when they are presented in this way. Displaying stacks of modals is an anti-pattern. The right thing to do would have been to create a migration UX that allows quick review and audit of application permissions, presented in a tab…

These are all new permissions. So there is no database of applications that need access to read/write Documents or Pictures. So a UI like you are suggesting is not technically possible to create.

If there are all new permissions, then it should be technically possible to create a list of ALL those new permissions and present that list to the user with apps requiring those permissions. What is so "not technically possible" there ... ? Actually in iOS you have list of apps with permissions in settings. At least something like that would be better then endless popups, which should be prohibited completely in _any_ interface, if you ask me. I am making effort to avoid any jumping dialogs in my apps,but now OS itself does it for me ... sad

Re: macOS 10.15 Vista

#153
post #146
post #137

Earlier quoted context omitted.

In Microsoft's defense, at least the Windows 10 updates are now quick . Last week a minor patch for MacOS took 30 minutes on a 2019 Macbook Pro.

The four hours I spent cleaning up my dad's laptop last week beg to differ. I had enough time to make and eat dinner while it was updating, rebooting, and then cleaning up the updates. Maybe he hadn't updated in a while? I made him a small Linux partition after clearing up enough space, and now everything runs so much faster that he refuses to boot back into Windows.

Maybe he hadn't updated in a while?

That shouldn’t make much of a difference, we only accept it as an excuse because it’s been the norm for so long.

Re: macOS 10.15 Vista

#154
post #123

Maybe we should be angry? Apple has been neglecting OS X since Snow Leopard, thinking that iOS is the only thing worth investing in. Microsoft apparently agrees -- they chopped up the Windows team last year, pushing out the Windows chief and dumping the remaining re-orged husk under Azure. Just for security reasons alone, it should be terrifying that there isn't a standalone Windows group anymore. Windows hasn't been…

As of Catalina, Apple has switched the default shell to zsh and nags you when you launch bash. That said... I agree. Between this, the abysmal keyboard failure rate, and some of the user-hostile choices they've made, I've switched to a Razer laptop. Windows 10 Pro lets you avoid most of the jank, by the way. But, I'm only on it as an eventual migration path to something running XFCE (my favorite wm due to its out of…

Wait what? Why/when did they do this?

Re: macOS 10.15 Vista

#155
post #73

Earlier quoted context omitted.

But they should only read and write files that you give it permission to. E.g, Word should only be reading and writing whatever files you open to edit, it shouldn't be able to access all the files in your Applications folder. If it needs temp files it can write those to it's designated section of the file system.

It should read and write whatever files it needs to without bothering me for every little thing. For instance, supposing they want to show you a welcome screen with all of your documents from your Documents folder (or anywhere else) - I don't want some asinine popup asking me for permission. Word is a well-known application. I installed it. I trust it and the corporation that wrote it. That's enough for me. The alleg…

For instance, supposing they want to show you a welcome screen with all of your documents from your Documents folder (or anywhere else) - I don't want some asinine popup asking me for permission. Word is a well-known application. I installed it. I trust it and the corporation that wrote it. That's enough for me.

But this is not how it works. Word from the App Store is sandboxed. If you open a document in Word, this is done using the native file opening dialog. This is a separate, privileged process. The file is symlinked into Word's sandbox as a result. This means that Word has access to that file from that point onwards. So, it can show a welcome screen with documents that you have previously opened (which is what applications typically do, very few applications will show all documents).

This is how things have worked ever since Apple required sandboxing for App Store apps. The problem is non-App Store apps that are not sandboxed. They have unfettered access to every file. I guess these extra permissions are to provide a certain level of protection against such apps, which is good.

Word is a well-known application. I installed it. I trust it and the corporation that wrote it.

There are many well-known incidents of trusted applications being compromised and backdoored. E.g.:

https://blog.malwarebytes.com/threat-analysis/mac-threat-ana...

To make things worse, the hash was updated in Homebrew cask. So even if you used a package manager, you would have installed a compromised application. Trusting applications may have been ok in the age of shrink-wrapped software. But now that applications are distributed over the web, allowing unfettered access is insanity.

More people will move to Linux.

The Linux ecosystem is also moving towards immutable base systems (Fedora Silverblue, NixOS) and restricted, sandboxed applications (Flatpak). Sure, it will always be possible to install a 70ies UNIX-style distribution. But the world is moving to sandboxing and putting up more restrictions, because the computing world became more hostile.

macOS is slowly but surely being turned into iOS.

This is getting tired and old. People said the same thing ten years ago and yet here we are, macOS is still an OS for 'general purpose computing'. I think Apple is finding a nice balance between securing the average user through sandboxing and SIP, while keeping giving the knobs to disable protections to advanced users. I say this as someone who currently uses Linux 95% of the time, but I wish Linux was as far as macOS with application sandboxing and system integrity protection.

Re: macOS 10.15 Vista

#156
post #123

Maybe we should be angry? Apple has been neglecting OS X since Snow Leopard, thinking that iOS is the only thing worth investing in. Microsoft apparently agrees -- they chopped up the Windows team last year, pushing out the Windows chief and dumping the remaining re-orged husk under Azure. Just for security reasons alone, it should be terrifying that there isn't a standalone Windows group anymore. Windows hasn't been…

WiFi, battery, and sleep. Have these problems been fixed with Linux on laptops?

Depends on the hardware manufacturer.

But if you're a regular laptop user the bigger issue is trackpad feel, if you're used to Apple devices or the new Windows drivers for trackpads, it's not acceptable. You're better off switching the way you work to using a window manager and shortcuts, like most hardcore linux users do at some point.

Re: macOS 10.15 Vista

#157
post #123

Maybe we should be angry? Apple has been neglecting OS X since Snow Leopard, thinking that iOS is the only thing worth investing in. Microsoft apparently agrees -- they chopped up the Windows team last year, pushing out the Windows chief and dumping the remaining re-orged husk under Azure. Just for security reasons alone, it should be terrifying that there isn't a standalone Windows group anymore. Windows hasn't been…

> the current monstrosity literally requires you to let it reboot itself on a 9-5 schedule.

* the previous monstrosity.

Windows will now let you carry on without updating until seriously important security updates are a month old. They really do have to force the hand of ignorant users eventually, else Microsoft gets blamed for an insecure OS.

I also don't understand where you get the idea that msft doesn't care about their desktop OS. They are basically overhauling it twice a year, for free. These larger updates do take 30 minutes, but, mind you, which is it: do they care too little or too much?

Re: macOS 10.15 Vista

#158
post #123

Maybe we should be angry? Apple has been neglecting OS X since Snow Leopard, thinking that iOS is the only thing worth investing in. Microsoft apparently agrees -- they chopped up the Windows team last year, pushing out the Windows chief and dumping the remaining re-orged husk under Azure. Just for security reasons alone, it should be terrifying that there isn't a standalone Windows group anymore. Windows hasn't been…

About the bash thing: Apple isn’t allowed to ship a newer version due to licensing problems. That’s also the reason why they switched to zsh [1].

[1]: https://thenextweb.com/dd/2019/06/04/why-does-macos-catalina...

Re: macOS 10.15 Vista

#159
post #123

Maybe we should be angry? Apple has been neglecting OS X since Snow Leopard, thinking that iOS is the only thing worth investing in. Microsoft apparently agrees -- they chopped up the Windows team last year, pushing out the Windows chief and dumping the remaining re-orged husk under Azure. Just for security reasons alone, it should be terrifying that there isn't a standalone Windows group anymore. Windows hasn't been…

WiFi, battery, and sleep. Have these problems been fixed with Linux on laptops?

I didn't have any issue with Wifi and sleep on my home Dell XPS 13 9380 running Arch. As for the battery, well I followed the arch wiki recommendations (add a kernel startup parameter, and use tlp) and it is ok now but it does not just work out of the box.

It is still not on par with Windows (I kept it just in case). I get around 8-9 hours of battery life on Windows while on Linux it is more like 6-7 hours. But it is mostly due to the fact that Chrome/Chromium and Firefox don't support hardware acceleration on Linux and I watch quite a lot of youtube videos. There is a Chromium that uses the video acceleration API (VAAPI) but it comes from the user arch repository, there is now also a snap package (I haven't yet fully tried them).

Re: macOS 10.15 Vista

#160
post #106

Earlier quoted context omitted.

Maybe we have different understandings of how that UI would work, but I imagine it to be totally possible: Take all the windows/notifications from OP's screenshot, map each of them to a row in a table, group by application. Show all this info in 1 modal, call it Migration Assistant.

The notification is thrown at the point of need. Some will appear when the application is first started, but some will only appear if the app is directed to a specific state by the user.

Still you can direct user to one list of apps/permissions each time those needs to be tuned, where user can review all permissions associated with particular app and decide whether to turn them on or off. How can you do that with endless dialogs and how can you review what you've allowed later, after dialog disappeared ...
Post reply on HN