Live data from Hacker News

Apple revoked longtime Mac developer's code signing certificate with no warning

twitter.com

31–40 of 180 posts

Re: Apple revoked longtime Mac developer's code signing certificate with no warning

#31
post #4

Earlier quoted context omitted.

Is there something wrong with downloading videos to my computer?

> Is there something wrong with downloading videos to my computer? Nope. Creating a tool perceived by those with enough lawyers to be a “copy protection circumvention device” however does run afoul of the DMCA.

Why does Apple care? It's none of their business.

Re: Apple revoked longtime Mac developer's code signing certificate with no warning

#32
post #20

Apple also has the ability to remotely login to EVERYONE's Internet-connected Mac computers and monkey around (removing software etc.). Of course, they only use this when THEY feel it's really necessary. Does not matter if you subscribe to any of their paid services, does not matter if you bought a used MacMini for 50 dollars or paid 50,000 dollars for a MacPro7. Some would say "great, wish we could do it to real vir…

Pretty sure Apple doesn’t have this capability. What you’re referring too is functionality inside GateKeeper or near GateKeeper.

Which is where Apple marks an application with a specific signature to be malware or dangerous and the OS automatically removes it. This is similar to an antivirus software removing it.

There’s no login functionality, Apple doesn’t see your data and doesn’t do anything on your machine other than remove the offending application. In addition, I’ve only see it used once.

Re: Apple revoked longtime Mac developer's code signing certificate with no warning

#33

Sadly, this is what a walled garden results in. Please don't be surprised, shocked or even remotely discontent because by signing the ToS you have waived away any and all of your rights regarding the use and publishing of software in this walled garden. The only reason an issue like this will get "fixed" is when this (post/tweet) goes viral and the PR department will work extra hard to correct this.

Another option would be changing the legislation. I wouldn’t hold my breath in the case of USA but rest of the world should certainly limit the monopoly of walled gardens as it limits the competition.

Apple is not a monopoly.

Additionally this is a Mac app and you can sideload apps on Macs

Re: Apple revoked longtime Mac developer's code signing certificate with no warning

#34

Earlier quoted context omitted.

Don't know why you are downvoted since you are completely correct. It is unfair to the developer but we wouldn't even have this discussion if people rejected app stores. I like that more developers just reject software certification processes. There is zero benefit aside from lock in.

Other than open season on the users with malware out the wazoo. But who cares about security. Do you buy healthcare from the back of a pickup truck?

App stores leave a lot to be desired when it comes to security. In fact it can give users a false sense of security.

https://www.cbc.ca/amp/1.5351280

Re: Apple revoked longtime Mac developer's code signing certificate with no warning

#35
post #4

Earlier quoted context omitted.

Is there something wrong with downloading videos to my computer?

> Is there something wrong with downloading videos to my computer? Nope. Creating a tool perceived by those with enough lawyers to be a “copy protection circumvention device” however does run afoul of the DMCA.

So a re-hash of the old "audio tapes will kill the music industry" or "video tapes will kill cinema"?

Re: Apple revoked longtime Mac developer's code signing certificate with no warning

#36

Earlier quoted context omitted.

Don't know why you are downvoted since you are completely correct. It is unfair to the developer but we wouldn't even have this discussion if people rejected app stores. I like that more developers just reject software certification processes. There is zero benefit aside from lock in.

Other than open season on the users with malware out the wazoo. But who cares about security. Do you buy healthcare from the back of a pickup truck?

Fdroid is hardly full of malware. There's a big range between locked down like Apple and "click here to install bonzibuddy" like Windows. It doesn't have to be black or white.

Re: Apple revoked longtime Mac developer's code signing certificate with no warning

#37
post #24

Earlier quoted context omitted.

Isn't keeping the 30% on refunded apps bad practice, regardless of the justification? Well, yes, if it's true, which it wasn't.

Okay, so what are the situations where it can be false? * apple actually did communicate to them, but it was via carrier pigeon or something and it got lost * apple is under gag order * the developer is actually a long time repeat offender and is trying to evade via sockpuppet accounts None of them seem plausible to me. Also, unlike with the apple 30% refund fiasco, we know for sure this is happening, because other u…

- Developer was hacked and is unaware of it.

- Developer accidentally clicked "revoke my cert" (no idea if that's a real button, but that's not the point).

- A national security agency sent one of those scary letters preventing Apple from speaking but requiring the action.

- Developer had a mental breakdown and has lost grip on reality.

- Developer realized app was infected with malware and ...

Truth is stranger than fiction, so it's actually really hard to think of all the possible strange explanations. Which is why it seems imminently reasonable to take a wait and see approach at least for a reasonable period of time.

Re: Apple revoked longtime Mac developer's code signing certificate with no warning

#38
From the page: https://developer.apple.com/documentation/xcode/notarizing_m...

> Notarization is not App Review. The Apple notary service is an automated system that scans your software for malicious content, checks for code-signing issues, and returns the results to you quickly. If there are no issues, the notary service generates a ticket for you to staple to your software; the notary service also publishes that ticket online where Gatekeeper can find it.

Perhaps the software connected to a website that was flagged as malicious by Apple. That’s one way I could see it getting flagged.

Re: Apple revoked longtime Mac developer's code signing certificate with no warning

#39

Earlier quoted context omitted.

Don't know why you are downvoted since you are completely correct. It is unfair to the developer but we wouldn't even have this discussion if people rejected app stores. I like that more developers just reject software certification processes. There is zero benefit aside from lock in.

Other than open season on the users with malware out the wazoo. But who cares about security. Do you buy healthcare from the back of a pickup truck?

Yet somehow more iOS users have been hit with malware (see Xcodeghost) than Google and Amazon Android users combined, despite there being far more of the latter and despite the latter being able to install whatever they want on their devices.

Re: Apple revoked longtime Mac developer's code signing certificate with no warning

#40
post #18

Earlier quoted context omitted.

Isn't silently revoking a longtime mac developer's certificate bad practice, regardless of the justification?

Isn't keeping the 30% on refunded apps bad practice, regardless of the justification? Well, yes, if it's true, which it wasn't.

Yeah I guess all the people yelling at this guy that his app doesn’t work are all just made up.
Post reply on HN