Live data from Hacker News

Apple revoked longtime Mac developer's code signing certificate with no warning

twitter.com

101–110 of 180 posts

Re: Apple revoked longtime Mac developer's code signing certificate with no warning

#101
post #54

Earlier quoted context omitted.

Looking at his website I don't think it is even in the store. What he names it is really none of Apple's business unless it infringed on one of their trademarks.

> What he names it is really none of Apple's business In any AppStore app, everything is literally Apple's business, considering they get a cut of any money that changes hands and can reject your app for "looking at them wrong". That's why the whole model is (rightly) controversial.

As I said it isn't in the app store.

Re: Apple revoked longtime Mac developer's code signing certificate with no warning

#102

Earlier quoted context omitted.

> Is there something wrong with downloading videos to my computer? Nope. Creating a tool perceived by those with enough lawyers to be a “copy protection circumvention device” however does run afoul of the DMCA.

And platforms doing standing back flips to appease stupid legislation. Reminds me of YouTube blocking Blender videos... had other reasons though, don't remember exactly, but it had to do with them not monetizing their videos and really, really bad support.

If you think the legislation is stupid, blame the legislators. Companies have to abide by laws, even stupid ones.

Re: Apple revoked longtime Mac developer's code signing certificate with no warning

#103
post #83
post #67

Earlier quoted context omitted.

Except that it's been verified by many people, and you can verify on your own Mac, that the developer's certificate has indeed been revoked, and the apps don't work. That part of the story is indisputable.

Sure but the important part of the tweet is “with no warning”. That’s why it is being posted here.

[deleted]

Re: Apple revoked longtime Mac developer's code signing certificate with no warning

#104

Earlier quoted context omitted.

Advantages and disadvantages. It is a bit like a kindergarten for software. At some point you might want to break out of there. There are severe disadvantages though: https://medium.com/vchaincodenotary/developers-unite-against... Additionally, the most predatory kind of app milks your wallet and these come in signed and unsigned forms. Also, quite a few companies with long time certs have leaked them pretty quickly.…

Most apps in 2020 are malware by early-2000s standards.

Exactly right. Yet they are fully signed and sold in (supposedly) secure app stores. When people talk about a feature providing security, it's important to ask "security from who?"

Re: Apple revoked longtime Mac developer's code signing certificate with no warning

#105
post #4

Earlier quoted context omitted.

Is there something wrong with downloading videos to my computer?

Apple might think so! I had a popular YouTube downloader app for Mac OS and I spent a lot of time on a port for iOS, but it was rejected from the app store back in 2010. The app reviewer did call me on the phone to tell me -- in fact, she called twice, once to tell me that my app was going into an extended review, and then a few weeks later she called to tell me that my app had been rejected. When I asked what the re…

Well if they called in 2010 they lost definitely can't do it now with the volume of apps.

Re: Apple revoked longtime Mac developer's code signing certificate with no warning

#106
post #51

Perhaps we should wait to get the whole story to discuss. Didn't we just go through this with the "Apple doesn't return 30% on refund" fiasco last week?

Honestly it doesn’t matter at all if it actually happened, that they could is unacceptable. EDIT: To be clear, it's not the certificate revocation that's bad, it's that the certificate is required to distribute code and can only be acquired from a single organization.

I actually like code signing. I can still run unsigned code by flipping the right setting, but I don’t have to worry about non-developer family members running something bad.

Re: Apple revoked longtime Mac developer's code signing certificate with no warning

#107

The developer's website (software.charliemonroe.net) is also blocked by my ISP (Vodafone UK)'s adult content filter. This is strange as it does not appear to contain any adult content. I wonder if these things are related?

Just wondered: If the adult content filter is ISP-level, can you deactivate it or like in this case report false positives?

It sound's as orwellian as Apples certificate shenanigans.

Re: Apple revoked longtime Mac developer's code signing certificate with no warning

#108

Earlier quoted context omitted.

We've been in this situation for 10 years now. Has the slippery slope caused any sliding yet? The cost issue is separate from the revocation issue, and my point was about certain revocation--it's an absolutely great feature for any code signing situation where you are trusting others to compile code for you and others can't confirm that a certain set of binaries came from a certain set of source files. (Reproducible…

Eh, yes, we have much more locked down systems with reduced capabilities. Consoles used it maybe for years and they are notorious for being useless for any third party content. You cannot simply write your own drivers for several devices anymore, so you basically booted a lot of engineers. It infected whole industries. We have locked down agricultural devices where users pay for expensive hacks. It is a complete nigh…

Consoles haven’t been open for 30 years, but I can still run unsigned code on my Mac. They’re not a good argument for us actually sliding down a slippery slope.

And writing drivers for hardware has often been impossible or effectively so due to poor documentation and/or signing. Do you not remember the era when most WiFi cards didn’t work with Linux, or when graphics cards required closed source binary blobs to even work?

I get you don’t like it on principle, so maybe you shouldn’t buy a Mac, but the idea that we’re going down a slippery slope is very much [citation needed]

Re: Apple revoked longtime Mac developer's code signing certificate with no warning

#109
This seems relevant.

“MPlayerX hasn’t been working for almost a year now. Also they still offer my apps on the App Store, they revoked my (direct) distribution certificate...”

https://twitter.com/charliemonroe/status/1290629792430280704...

Re: Apple revoked longtime Mac developer's code signing certificate with no warning

#110

Earlier quoted context omitted.

Other than open season on the users with malware out the wazoo. But who cares about security. Do you buy healthcare from the back of a pickup truck?

Yet somehow more iOS users have been hit with malware (see Xcodeghost) than Google and Amazon Android users combined, despite there being far more of the latter and despite the latter being able to install whatever they want on their devices.

I don’t see any evidence for that?
Post reply on HN