Live data from Hacker News

Apple revoked longtime Mac developer's code signing certificate with no warning

twitter.com

61–70 of 180 posts

Re: Apple revoked longtime Mac developer's code signing certificate with no warning

#61
post #45

Earlier quoted context omitted.

Don't know why you are downvoted since you are completely correct. It is unfair to the developer but we wouldn't even have this discussion if people rejected app stores. I like that more developers just reject software certification processes. There is zero benefit aside from lock in.

Someone said there are security benefits to the user. Obviously nothing is 100%, but there is a benefit. There’s also discovery benefits to both sides and trust benefits. I am find apps more easily on app stores, and am much more quick to buy an app through the store then some random website. Maybe those benefits don’t outweigh the downsides, but to say there is no user or developer benefit is objectively false in bo…

Right, there might be some superficial advantages but I would question them as well. Sure, I don't expect an Apple or Google app to act as a trojan, but I surely expect any bad behavior under the sun, especially concerning data exfiltration.

Re: Apple revoked longtime Mac developer's code signing certificate with no warning

#62

Sadly, this is what a walled garden results in. Please don't be surprised, shocked or even remotely discontent because by signing the ToS you have waived away any and all of your rights regarding the use and publishing of software in this walled garden. The only reason an issue like this will get "fixed" is when this (post/tweet) goes viral and the PR department will work extra hard to correct this.

WTF. I dare any one of you who downvoted this to explain why in public.

Re: Apple revoked longtime Mac developer's code signing certificate with no warning

#63

Earlier quoted context omitted.

As a developer it’s a pain but as a user it’s definitely useful for security purposes. It’s hardly “zero benefit”.

Advantages and disadvantages. It is a bit like a kindergarten for software. At some point you might want to break out of there. There are severe disadvantages though: https://medium.com/vchaincodenotary/developers-unite-against... Additionally, the most predatory kind of app milks your wallet and these come in signed and unsigned forms. Also, quite a few companies with long time certs have leaked them pretty quickly.…

Most apps in 2020 are malware by early-2000s standards.

Re: Apple revoked longtime Mac developer's code signing certificate with no warning

#64
post #4
post #3

I suspect this is why: > Ever wished you could save a video from the Internet? Search no more, Downie is what you're looking for. Easily download videos from thousands of different sites.

Is there something wrong with downloading videos to my computer?

It's against the YouTube terms of service. One characterization of this software is that it is designed to violate the YouTube terms of service.

"The following restrictions apply to your use of the Service. You are not allowed to:

    access, reproduce, download, distribute, transmit, broadcast, display, sell, license, alter, modify or otherwise use any part of the Service or any Content except: (a) as expressly authorized by the Service; or (b) with prior written permission from YouTube and, if applicable, the respective rights holders;"
- https://www.youtube.com/static?gl=CA&template=terms

Re: Apple revoked longtime Mac developer's code signing certificate with no warning

#65
post #53

Earlier quoted context omitted.

They pretty clearly have a monopoly on iOS app stores. Now we can skip the part where somebody says that you can't have a monopoly on your own product and then I point out that monopolies always look like that because their product is the only one in the market, and the reason that android app stores and iOS app stores are different markets is that you can't install Android apps on iOS devices or vice versa.

Surely by moving the goalposts you can make everything look like a monopoly. In the end both mobile platforms have practically the same popular apps.

> Surely by moving the goalposts you can make everything look like a monopoly.

Walmart doesn't have a monopoly on SAE 5w30 motor oil. You can't make it look like a monopoly when it isn't one, because when it isn't you can identify competitors who sell substitute products to the same customers.

> In the end both mobile platforms have practically the same popular apps.

The market they have a monopoly on is iOS app stores, not individual apps.

It's very straight forward. For Google Play to be in the same market you would have to be able to use it to install apps on your Apple iPhone. Since you can't, it isn't, and since there is only one app store that can, it's a monopoly.

Notice that it has nothing to do with the fact that Apple also makes the phones, outside of control over the phone being used to enforce the app store monopoly by locking out competitors. If Amazon for some reason had the only app store for Apple iOS devices, they would be the one with a monopoly in that market.

Re: Apple revoked longtime Mac developer's code signing certificate with no warning

#66
post #51

Earlier quoted context omitted.

Honestly it doesn’t matter at all if it actually happened, that they could is unacceptable. EDIT: To be clear, it's not the certificate revocation that's bad, it's that the certificate is required to distribute code and can only be acquired from a single organization.

I think certificate revocation of signed code is a good, useful feature and something that I want as part of my security infrastructure. I wouldn't want it any other way if I have to use non-open source code that I can't inspect. But the basis of all my core software is going to be open source.

This will lead to computing being locked down further with really questionable benefits. In fact open source software can suffer greatly because these certs make deployment cost non-zero. So someone providing binaries of such software has to pay for it to large corps like Apple and Microsoft.

Re: Apple revoked longtime Mac developer's code signing certificate with no warning

#67

Perhaps we should wait to get the whole story to discuss. Didn't we just go through this with the "Apple doesn't return 30% on refund" fiasco last week?

Except that it's been verified by many people, and you can verify on your own Mac, that the developer's certificate has indeed been revoked, and the apps don't work. That part of the story is indisputable.

Re: Apple revoked longtime Mac developer's code signing certificate with no warning

#68
post #54

Earlier quoted context omitted.

Looking at his website I don't think it is even in the store. What he names it is really none of Apple's business unless it infringed on one of their trademarks.

> What he names it is really none of Apple's business In any AppStore app, everything is literally Apple's business, considering they get a cut of any money that changes hands and can reject your app for "looking at them wrong". That's why the whole model is (rightly) controversial.

I think anything that Apple does will be controversial, as there's the anti-fans and fans that are at political war.

But the true controversy is not a curated store, the controversy is that the curated store is the only way for people to load native code onto the device without compiling it themselves on a separate laptop.

Re: Apple revoked longtime Mac developer's code signing certificate with no warning

#69

The developer's website (software.charliemonroe.net) is also blocked by my ISP (Vodafone UK)'s adult content filter. This is strange as it does not appear to contain any adult content. I wonder if these things are related?

It has an app for downloading videos off YouTube and other video sites. Not sure how much influence media companies have in the UK but maybe that's why?

I know YouTube downloading services have struggled in the past to stay operational.

Re: Apple revoked longtime Mac developer's code signing certificate with no warning

#70
post #20

Apple also has the ability to remotely login to EVERYONE's Internet-connected Mac computers and monkey around (removing software etc.). Of course, they only use this when THEY feel it's really necessary. Does not matter if you subscribe to any of their paid services, does not matter if you bought a used MacMini for 50 dollars or paid 50,000 dollars for a MacPro7. Some would say "great, wish we could do it to real vir…

You are overstating the case pretty wildly.

They have the ability to cause the OS to automatically delete binaries based on checksum, not "remotely login". And every time they have used this awesome power, it has been for good and everybody here would be OK with it.

They have never used this power to like fuck with some developer because he violated YouTube TOS, or used the Taiwanese flag in his app, etc.

As a user, I want my OS vendor to have this power and use it appropriately.

Post reply on HN