Live data from Hacker News

Apple revoked longtime Mac developer's code signing certificate with no warning

twitter.com

121–130 of 180 posts

Re: Apple revoked longtime Mac developer's code signing certificate with no warning

#121
Another possible explanation: The developer‘s certificate leaked and was really used to sign malware. Or his github repo was hacked and something evil was added to his code without him noticing. Maybe I’m just rationalizing, because if Apple is really going down the road that most commenters here suspect, then there will be no arm macbook for me unfortunately... :(

Re: Apple revoked longtime Mac developer's code signing certificate with no warning

#122

Earlier quoted context omitted.

> Surely by moving the goalposts you can make everything look like a monopoly. Walmart doesn't have a monopoly on SAE 5w30 motor oil. You can't make it look like a monopoly when it isn't one, because when it isn't you can identify competitors who sell substitute products to the same customers. > In the end both mobile platforms have practically the same popular apps. The market they have a monopoly on is iOS app stor…

Walmart has a monopoly on being the only people who can sell products in a Walmart store.

This seems disingenuous. Once you buy an iPhone, you need to buy apps from Apple's store. There is no similar force restricting you to Walmart.

This would be more akin to buying a Ford and then discovering you could only buy parts, motor oil, etc. by visiting your Ford dealer.

Re: Apple revoked longtime Mac developer's code signing certificate with no warning

#123

This seems relevant. “MPlayerX hasn’t been working for almost a year now. Also they still offer my apps on the App Store, they revoked my (direct) distribution certificate...” https://twitter.com/charliemonroe/status/1290629792430280704...

MPlayerX was caught bundling installer with malware: https://www.reddit.com/r/apple/comments/3bhvh9/psa_do_not_in...

So this could be justified

Re: Apple revoked longtime Mac developer's code signing certificate with no warning

#124
post #69

Earlier quoted context omitted.

It has an app for downloading videos off YouTube and other video sites. Not sure how much influence media companies have in the UK but maybe that's why? I know YouTube downloading services have struggled in the past to stay operational.

Apple is a media company now. They aren't just distributing (like apple music) but are creating TV shows like Amazon and Netflix. See Apple TV I suspect this will bring about conflicts in the company between content creation and the hardware/software divisions.

Remember “Rip. Mix. Burn.”?

Apple thinks different now.

Re: Apple revoked longtime Mac developer's code signing certificate with no warning

#125
post #121

Another possible explanation: The developer‘s certificate leaked and was really used to sign malware. Or his github repo was hacked and something evil was added to his code without him noticing. Maybe I’m just rationalizing, because if Apple is really going down the road that most commenters here suspect, then there will be no arm macbook for me unfortunately... :(

When this actually happened in the past, Apple worked closely with the developer: https://panic.com/blog/stolen-source-code/

Re: Apple revoked longtime Mac developer's code signing certificate with no warning

#126

Earlier quoted context omitted.

Most apps in 2020 are malware by early-2000s standards.

Exactly right. Yet they are fully signed and sold in (supposedly) secure app stores. When people talk about a feature providing security, it's important to ask "security from who?"

I don’t know that I’d call the app store “secure” but it’s definitely more secure to download and run an app from the app store than to download and run an app from elsewhere on the internet. Better the (fully signed) devil you know.

Re: Apple revoked longtime Mac developer's code signing certificate with no warning

#127
post #111

Earlier quoted context omitted.

This doesn't really explain anything. Why is Apple enforcing YouTube's terms of service on a third-party application? Especially via a mechanism ostensibly designed to stop malware. Is the Transmission torrent client next because it could be used to download copyrighted content?

It's right here in the App Store guidelines: 5.2.3 Audio/Video Downloading: Apps should not facilitate illegal file sharing or include the ability to save, convert, or download media from third-party sources (e.g. Apple Music, YouTube, SoundCloud, Vimeo, etc.) without explicit authorization from those sources. Streaming of audio/video content may also violate Terms of Use, so be sure to check before your app accesses…

The app in question, Downie, isn't in the App Store. Why would it be subject to the App Store ToS?

Re: Apple revoked longtime Mac developer's code signing certificate with no warning

#128

The developer's website (software.charliemonroe.net) is also blocked by my ISP (Vodafone UK)'s adult content filter. This is strange as it does not appear to contain any adult content. I wonder if these things are related?

Just wondered: If the adult content filter is ISP-level, can you deactivate it or like in this case report false positives? It sound's as orwellian as Apples certificate shenanigans.

You can deactivate it by verifying your age with a credit card or photo ID. Vodafone don't seem to offer a way to report false positives, but I've seen that option with other providers.

Re: Apple revoked longtime Mac developer's code signing certificate with no warning

#129
post #62

Sadly, this is what a walled garden results in. Please don't be surprised, shocked or even remotely discontent because by signing the ToS you have waived away any and all of your rights regarding the use and publishing of software in this walled garden. The only reason an issue like this will get "fixed" is when this (post/tweet) goes viral and the PR department will work extra hard to correct this.

WTF. I dare any one of you who downvoted this to explain why in public.

HN is an Apple fan club.

Most people here are from Silicon Valley and Apple is the biggest employer over there.

Try to badmouth Samsung in a Korean sub and you get the same treatment.

Re: Apple revoked longtime Mac developer's code signing certificate with no warning

#130

Earlier quoted context omitted.

Broadcast and cable TV wasn't meant to be savable, and then VCRs came out and courts decided that saving (time shifting) is absolutely fine. It doesn't in and of itself facilitate sharing. If it breaks actual encryption (a la DeCSS) then yes, it oversteps. But TV content stakeholders don't have much pull with convincing VCR manufacturers/distributors to stop supplying VCRs. Apple does clearly have the ability to affe…

> If it breaks actual encryption (a la DeCSS) then yes, it oversteps. Don't some jurisdictions have provisions that allow for technical workarounds in order to make backups?

Backups of your own physical media. Downloading videos on YouTube doesn't qualify.
Post reply on HN