Live data from Hacker News

Apple revoked longtime Mac developer's code signing certificate with no warning

twitter.com

51–60 of 180 posts

Re: Apple revoked longtime Mac developer's code signing certificate with no warning

#51

Perhaps we should wait to get the whole story to discuss. Didn't we just go through this with the "Apple doesn't return 30% on refund" fiasco last week?

Honestly it doesn’t matter at all if it actually happened, that they could is unacceptable.

EDIT: To be clear, it's not the certificate revocation that's bad, it's that the certificate is required to distribute code and can only be acquired from a single organization.

Re: Apple revoked longtime Mac developer's code signing certificate with no warning

#52
I feel bad for the developer. But every time I see stories like this, I also feel a little jolt of validation regarding my choice as a developer to leave the Apple ecosystem in 2008.

At the time, the App Store (iOS) was new, and I was working on porting our SSH-based encrypted remote access tool[1] from Mac to iPhone. I had been doing mainly Mac OS X development for almost 10 years.

I had the proof-of-concept port from Mac to iOS working, but the amount of insane hoops I had to jump through (because it used "strong encryption" (we forked PuTTY SSH)) seemed, initially, like a trip the DMV. It gradually started feeling more like the movie Brazil.

I remember going directly from WWDC to the local office of (searches old files) the "Bureau of Industry and Security" (wat) and talking to some guy who had NO idea what I was talking about when I told him my company was trying to make an iPhone app that used encryption and that Apple had told me I needed to get his agency's approval. (Nice guy, though.)

Ultimately, working through the Apple documentation, I learned I had to do a bunch of weird stuff, like sign up for antique government systems that only worked on Windows XP, and provide personal info, and make a PIN, and submit an application to SNAP-R, and submit a "BIS-748P supporting document: how the Product meets the criteria of the Cryptography Note as mass market encryption software" along with a "BIS-748P supporting document: additional information to supplement our application for review and commodity classification request, in accordance with Supplement No. 6 to Part 742 of the EAR" along with "BIS-748P supporting document: sample marketing copy and brochure text" and a "BIS-748P supporting document: illustrations depicting the software in operation" and then finally a "BIS-748P supporting document: source code listings for all encryption-related source code used in the product"... that last was a ridiculous 500-page or so hard copy printout of the source code to PuTTY with the few dozen places we'd changed it (to make it multithreaded to fit better with our app architecture, haha, because I was young and dumb then).

And, while I forget a lot of the details (I've just copy-pasted those now, after finding the relevant old files), I remember vividly the moment, sitting there in a Tokyo hotel business center assembling this heavy paper package to FedEx to BIS and just suddenly thinking... wait though — maybe this isn't a game I want to play. We didn't have to do any of this to ship a Mac app — any risk of legal noncompliance was ours, of course, but in reality there was no actual risk. This was all for Apple to cover their ass.

If some government bureaucrat didn't like my application, my app wouldn't ship and the past year of work would be for nothing. And somehow that made me acutely aware that the same thing would be true if Apple for some reason didn't like my app. Like... what if they were planning to roll out similar rich, Mac-centric remote access features in the next OS update. Or, even if they approved it, but later just didn't want to deal some issue that arose around it — they could just revoke my app any time they pleased.

(As seems to be the case with the app in this thread.)

I thought about this for a couple more weeks, and then I took a corporate job doing internal systems development. The app was never finished.

The lack of my app obviously didn't hurt Apple. But looking back, I do feel like the lack of having to deal Apple — and that whole weird power imbalance, of being a peasant plowing fields owned by Apple, hoping to receive some part of the fruits of my labor — probably helped me live a more serene, untroubled life.

[1]: iGet Touch (phone apps were still called "blah blah Touch" then, just like many Mac apps from the early 2000s were idiotically prefixed with "i" (^_^); back then) was never finished — but it was basically a native iOS version of the Mac version, long dead but still archived here: http://nakahara-informatics.com/iget

Re: Apple revoked longtime Mac developer's code signing certificate with no warning

#53
post #33

Earlier quoted context omitted.

Apple is not a monopoly. Additionally this is a Mac app and you can sideload apps on Macs

They pretty clearly have a monopoly on iOS app stores. Now we can skip the part where somebody says that you can't have a monopoly on your own product and then I point out that monopolies always look like that because their product is the only one in the market, and the reason that android app stores and iOS app stores are different markets is that you can't install Android apps on iOS devices or vice versa.

Surely by moving the goalposts you can make everything look like a monopoly. In the end both mobile platforms have practically the same popular apps.

Re: Apple revoked longtime Mac developer's code signing certificate with no warning

#54

Earlier quoted context omitted.

"downie"? could it just be the name? https://www.urbandictionary.com/define.php?term=Downie though if it was that you'd think they would just pull the app and ask him to rename it...

Looking at his website I don't think it is even in the store. What he names it is really none of Apple's business unless it infringed on one of their trademarks.

> What he names it is really none of Apple's business

In any AppStore app, everything is literally Apple's business, considering they get a cut of any money that changes hands and can reject your app for "looking at them wrong".

That's why the whole model is (rightly) controversial.

Re: Apple revoked longtime Mac developer's code signing certificate with no warning

#55
post #30
post #24

Earlier quoted context omitted.

Okay, so what are the situations where it can be false? * apple actually did communicate to them, but it was via carrier pigeon or something and it got lost * apple is under gag order * the developer is actually a long time repeat offender and is trying to evade via sockpuppet accounts None of them seem plausible to me. Also, unlike with the apple 30% refund fiasco, we know for sure this is happening, because other u…

It doesn't take much imagination to come up with other scenarios. No idea if any of these are true. * apple actually did communicate to them, but it went to the developer's spam box. * apple actually did communicate to them, but sent it to an old email address that the developer never updated. * apple actually did communicate to them, but it was via a developer dashboard that the developer rarely checks. * apple didn…

>* apple actually did communicate to them, but it went to the developer's spam box.

Isn't "check your spam box" the same thing you're going to do if you're looking for an email that you're expecting?

>* apple actually did communicate to them, but sent it to an old email address that the developer never updated.

plausible, but seems unlikely that'd be the case, considering that this is a semi-important account that you won't use a throwaway account for. Also, isn't your itunes connect (app store) login based on your apple id, which is based on your email?

>* apple actually did communicate to them, but it was via a developer dashboard that the developer rarely checks.

His tweet said that his account was suspended, so he probably found that out while trying to log in, or got an email.

Re: Apple revoked longtime Mac developer's code signing certificate with no warning

#56
In other words: you can’t depend on signed mac apps for anything important as a user even if they keep everything local to your computer. The developer could do something completely unrelated and your app will suddenly stop working with no warning.

Re: Apple revoked longtime Mac developer's code signing certificate with no warning

#57

Earlier quoted context omitted.

Don't know why you are downvoted since you are completely correct. It is unfair to the developer but we wouldn't even have this discussion if people rejected app stores. I like that more developers just reject software certification processes. There is zero benefit aside from lock in.

As a developer it’s a pain but as a user it’s definitely useful for security purposes. It’s hardly “zero benefit”.

Advantages and disadvantages. It is a bit like a kindergarten for software. At some point you might want to break out of there.

There are severe disadvantages though:

https://medium.com/vchaincodenotary/developers-unite-against...

Additionally, the most predatory kind of app milks your wallet and these come in signed and unsigned forms.

Also, quite a few companies with long time certs have leaked them pretty quickly. Primarily, it is a lock in mechanism with questionable security benefits. Predatory apps can be signed which would have been classified as malware 15 years ago.

Re: Apple revoked longtime Mac developer's code signing certificate with no warning

#58
post #37
post #24

Earlier quoted context omitted.

Okay, so what are the situations where it can be false? * apple actually did communicate to them, but it was via carrier pigeon or something and it got lost * apple is under gag order * the developer is actually a long time repeat offender and is trying to evade via sockpuppet accounts None of them seem plausible to me. Also, unlike with the apple 30% refund fiasco, we know for sure this is happening, because other u…

- Developer was hacked and is unaware of it. - Developer accidentally clicked "revoke my cert" (no idea if that's a real button, but that's not the point). - A national security agency sent one of those scary letters preventing Apple from speaking but requiring the action. - Developer had a mental breakdown and has lost grip on reality. - Developer realized app was infected with malware and ... Truth is stranger than…

> - Developer was hacked and is unaware of it.

If that's the case why wasn't that communicated to him?

>- Developer accidentally clicked "revoke my cert" (no idea if that's a real button, but that's not the point).

>- Developer had a mental breakdown and has lost grip on reality.

While these are possible, they seem very unlikely. Compare the numerous cases of Big Tech silently revoking people's account with no notice or appeal, to the number of times that someone made a public announcement, and then went "nvm it was me lol".

Re: Apple revoked longtime Mac developer's code signing certificate with no warning

#60
post #51

Perhaps we should wait to get the whole story to discuss. Didn't we just go through this with the "Apple doesn't return 30% on refund" fiasco last week?

Honestly it doesn’t matter at all if it actually happened, that they could is unacceptable. EDIT: To be clear, it's not the certificate revocation that's bad, it's that the certificate is required to distribute code and can only be acquired from a single organization.

I think certificate revocation of signed code is a good, useful feature and something that I want as part of my security infrastructure.

I wouldn't want it any other way if I have to use non-open source code that I can't inspect. But the basis of all my core software is going to be open source.

Post reply on HN