Live data from Hacker News

Apple revoked longtime Mac developer's code signing certificate with no warning

twitter.com

161–170 of 180 posts

Re: Apple revoked longtime Mac developer's code signing certificate with no warning

#161
post #136
post #41

Earlier quoted context omitted.

I don't think it follows that malware is the only possible alternative to walled gardens. You could still have trust mechanisms while downloading from sites where the author , not the walled garden, has the control.

A lot of authors want to do things that violate the user’s trust, but are hard to detect. Wouldn’t it be better to have the user have the control? The walled garden does have problems, but I generally don’t see anyone adding any value to our understanding of how to replace it with something better.

> Wouldn’t it be better to have the user have the control?

It would, but the user has no control of the walled garden either. It's a situation where both the user and the author have little to no control, as well as poor feedback.

I'm not sure walled gardens, with their arbitrary rules, and opaque audit and review processes (which include not knowing how detailed their reviews are), are really a trusty safeguard against malicious authors. Whether you believe walled gardens protect you from malware depends on your definition of "malware".

It's not true that without the App Store there's a world of dangers out there. Author reputation goes a long way.

Re: Apple revoked longtime Mac developer's code signing certificate with no warning

#162

Earlier quoted context omitted.

most of the internet is blocked by those mobile carrier content filters

In 20ish years of using the mobile internet, going back to WAP days, I've never visited a site that was blocked by a mobile carrier content filter.

I've come across a few strange blocks. Recently when researching bread knives I found that the website of the French knife company, Opinel, is blocked by at least two UK mobile carrier's content filters. (www.opinel.com, blocked by Three and Vodafone. Not blocked by O2.)

Their US site (www.opinel-usa.com) is not blocked, however, nor are the many online retailers which sell their knives.

Re: Apple revoked longtime Mac developer's code signing certificate with no warning

#163

Earlier quoted context omitted.

Honestly, no company should have this much control over people's businesses and livelihoods. iPhone is a generic pocket computer, and it has outgrown Apple's desire to maintain a fiefdom. Congress and the EU should force Apple to allow 3rd party marketplaces and installs. Apple is free to charge 30% for the App Store, but they can't be the only way to get code onto an iPhone. Nor should they be the only first class w…

I like everything going through Apple personally. In fact it's part of the reason I have an iPhone.

It hurts all of the supply-side people that make the ecosystem healthy. It's not a sweatshop, to be sure, but it's definitely a gangster-style shakedown with the eminent feeling of having your green card revoked.

Nevermind the fact that this was the platform that pioneered race to the bottom prices with the expectation of free updates for life.

The app store is so incredibly toxic and harmful.

Re: Apple revoked longtime Mac developer's code signing certificate with no warning

#164
post #20

Apple also has the ability to remotely login to EVERYONE's Internet-connected Mac computers and monkey around (removing software etc.). Of course, they only use this when THEY feel it's really necessary. Does not matter if you subscribe to any of their paid services, does not matter if you bought a used MacMini for 50 dollars or paid 50,000 dollars for a MacPro7. Some would say "great, wish we could do it to real vir…

Pretty sure Apple doesn’t have this capability. What you’re referring too is functionality inside GateKeeper or near GateKeeper. Which is where Apple marks an application with a specific signature to be malware or dangerous and the OS automatically removes it. This is similar to an antivirus software removing it. There’s no login functionality, Apple doesn’t see your data and doesn’t do anything on your machine other…

Pretty sure you are completely wrong. It's well documented they have done it in the past and publicly made statements about it --but downvote away idiots!

Re: Apple revoked longtime Mac developer's code signing certificate with no warning

#165
post #70
post #20

Apple also has the ability to remotely login to EVERYONE's Internet-connected Mac computers and monkey around (removing software etc.). Of course, they only use this when THEY feel it's really necessary. Does not matter if you subscribe to any of their paid services, does not matter if you bought a used MacMini for 50 dollars or paid 50,000 dollars for a MacPro7. Some would say "great, wish we could do it to real vir…

You are overstating the case pretty wildly. They have the ability to cause the OS to automatically delete binaries based on checksum, not "remotely login". And every time they have used this awesome power, it has been for good and everybody here would be OK with it. They have never used this power to like fuck with some developer because he violated YouTube TOS, or used the Taiwanese flag in his app, etc. As a user,…

pull your head out and stop spouting off your (totally inaccurate) opinion as authoritative.

You do realize you used the F word, referenced the Taiwanese flag and the word "appropriately" all in the same post, right?

Re: Apple revoked longtime Mac developer's code signing certificate with no warning

#166
post #145

Earlier quoted context omitted.

> As a user, I want my OS vendor to have this power and use it appropriately. As a user I want my OS vendor to have this power with my explicit permission and use it appropriately. I also want to be able to disable this completely if I choose. There's going to come a time where Apple is going to do something shitty with this ability. Giving up the freedom to run whatever code you want on your computer is dangerous lo…

> There's going to come a time where Apple is going to do something shitty with this ability. Or even "someone who has the credentials Apple owns" does it. I presume they require more than one employee to be able to do that, but that only mitigates insider threat, it doesn't remove it. They could also potentially be fooled into doing some damage. Trust should never be evaluated on whether you think people are trustwo…

The idiot you are replying to has no clue how apps work on the Mac --remotely killing a bundle identifier is not sufficient to stop a piece of malware. to cleanup a mess, they at least have to run a script that makes all kinds of changes, including to launchd, etc. to me that is a remote login --but someone using the F word can argue semantics and get me downvoted and flagged and whatever (as if I give a damn lol --I have 40 years of experience and 30 of it is programming Macs)

Re: Apple revoked longtime Mac developer's code signing certificate with no warning

#167
post #82

Earlier quoted context omitted.

Pretty sure Apple doesn’t have this capability. What you’re referring too is functionality inside GateKeeper or near GateKeeper. Which is where Apple marks an application with a specific signature to be malware or dangerous and the OS automatically removes it. This is similar to an antivirus software removing it. There’s no login functionality, Apple doesn’t see your data and doesn’t do anything on your machine other…

Apple's first wish from the genie in a bottle was for unlimited wishes. So it doesn't really make sense to argue over whether Apple only has x-ray vision or also the ability to walk through walls yet. Gatekeeper is our benevolent dictator that consolidates power with every update because our connectedness increases the potential for widespread damage from our attackers. And I'm ok with that, but worry we'll regret th…

oh look, but one source located with 10 seconds of Googling...

https://techcrunch.com/2019/07/10/apple-silent-update-zoom-a...

Re: Apple revoked longtime Mac developer's code signing certificate with no warning

#168
post #161
post #136

Earlier quoted context omitted.

A lot of authors want to do things that violate the user’s trust, but are hard to detect. Wouldn’t it be better to have the user have the control? The walled garden does have problems, but I generally don’t see anyone adding any value to our understanding of how to replace it with something better.

> Wouldn’t it be better to have the user have the control? It would, but the user has no control of the walled garden either. It's a situation where both the user and the author have little to no control, as well as poor feedback. I'm not sure walled gardens, with their arbitrary rules, and opaque audit and review processes (which include not knowing how detailed their reviews are), are really a trusty safeguard agai…

If you don’t believe that there are dangers out there for general users installing software from the internet, I don’t know what to tell you.

History certainly proves otherwise, as do the number of attempts at putting malware into app stores.

I’d go as far as to say that you are certainly wrong about this and you can trivially verify this by even the most cursory examination of software threat models.

Author reputation goes almost nowhere these days. It’s quite obvious why. There are a huge number of authors producing software.

It’s impossible for more than a few authors to develop a reputation, and even those that do face impersonation.

As to you not being sure how much protection ‘walled gardens’ give. They aren’t perfect, but they clearly work, and you can trivially verify that.

If you think the author or the user can solve these problems without an intermediary, it bears some explanation as to how exactly this could work.

Can you explain?

Re: Apple revoked longtime Mac developer's code signing certificate with no warning

#169
post #160
post #44

Earlier quoted context omitted.

Nobody here thinks that the law is a good idea or will do anything to protect any content industries. The fact is that despite being enormously stupid, it is still the law.

Yes, I know I'm preaching the choir here. My point is that with each advance in technology, established industry "actors" panic because they foresee their business will go bankrupt. Sometimes this panic is justified, but often it's not, or it's blown out of proportion. It's not necessarily the law, either. Panicky industry heavyweights may lobby to make it a law, or try to confuse a given tech with copyright infringe…

Yep, the whole time they were focused on cassette tapes and Napster, the music industry completely missed the iPod/iTunes threat.

Re: Apple revoked longtime Mac developer's code signing certificate with no warning

#170
post #168
post #161

Earlier quoted context omitted.

> Wouldn’t it be better to have the user have the control? It would, but the user has no control of the walled garden either. It's a situation where both the user and the author have little to no control, as well as poor feedback. I'm not sure walled gardens, with their arbitrary rules, and opaque audit and review processes (which include not knowing how detailed their reviews are), are really a trusty safeguard agai…

If you don’t believe that there are dangers out there for general users installing software from the internet, I don’t know what to tell you. History certainly proves otherwise, as do the number of attempts at putting malware into app stores. I’d go as far as to say that you are certainly wrong about this and you can trivially verify this by even the most cursory examination of software threat models. Author reputati…

Somehow the world outside walled gardens exists and it's not a danger-infested world. What's worse, you can't really argue for the quality controls of walled gardens such as the App Store because they are not transparent -- at most you can guess with trial and error.

You haven't explained how the user has more control with walled gardens, a bold and unsupported assertion (I believe we both agree the author has less control with walled garden, at least).

> It’s impossible for more than a few authors to develop a reputation, and even those that do face impersonation.

The first part is a matter of opinion (and I disagree with you). As for the latter: do you really believe the only technical solution to author impersonation is a walled garden? No other form of establishing trust is possible to you? Interesting.

> I’d go as far as to say that you are certainly wrong about this and you can trivially verify this by even the most cursory examination of software threat models.

That isn't an argument. That's just you saying "I'm right and you're wrong".

Post reply on HN