Live data from Hacker News

Apple revoked longtime Mac developer's code signing certificate with no warning

twitter.com

171–180 of 180 posts

Re: Apple revoked longtime Mac developer's code signing certificate with no warning

#171
post #3

I suspect this is why: > Ever wished you could save a video from the Internet? Search no more, Downie is what you're looking for. Easily download videos from thousands of different sites.

Is it by any chance a straight port of youtube-dl? This and

>The developer's website (software.charliemonroe.net) is blocked by my ISP (Vodafone UK)'s adult content filter. This is strange as it does not appear to contain any adult content.

would explain a lot. In order to download from a pr0n website you need to hardcode that websites domain name inside the program = pr0n filters pick it up = Apple bans it.

Re: Apple revoked longtime Mac developer's code signing certificate with no warning

#172
post #69

The developer's website (software.charliemonroe.net) is also blocked by my ISP (Vodafone UK)'s adult content filter. This is strange as it does not appear to contain any adult content. I wonder if these things are related?

It has an app for downloading videos off YouTube and other video sites. Not sure how much influence media companies have in the UK but maybe that's why? I know YouTube downloading services have struggled in the past to stay operational.

other video websites being pr0n by any chance? woul require shipping their domain names inside binary, might not make Apple all that happy

Re: Apple revoked longtime Mac developer's code signing certificate with no warning

#173
post #85

Earlier quoted context omitted.

Hi, I'm the developer. * No email in my spam box. * My contact address is still working and have received notifications about them approving my updates for the App Store yesterday (so saying that they have no way of contacting me is not true). * No known breach of account. * No accidental revocation (I was sleeping while this happened). * The certificates are revoked as you can verify via command line.

Please keep us updated with what comes of this!

See https://blog.charliemonroe.net/a-day-without-business/

Re: Apple revoked longtime Mac developer's code signing certificate with no warning

#174
post #134

Earlier quoted context omitted.

App stores leave a lot to be desired when it comes to security. In fact it can give users a false sense of security. https://www.cbc.ca/amp/1.5351280

Sure but Apple is clearly continuing to move in the direction of more security. The argument that they could be better therefore they are worth nothing, is a clear fallacy.

Then the same is true for letting people just install apps without vendor lock in.

Re: Apple revoked longtime Mac developer's code signing certificate with no warning

#175
Update from the developer: https://blog.charliemonroe.net/a-day-without-business/

"after almost 24 hours after 10PM, I got my account re-instated. Apple has called and apologized for the complications. The issue was caused by my account being erroneously flagged by automated processes as malicious and was put on hold."

Re: Apple revoked longtime Mac developer's code signing certificate with no warning

#176
post #170
post #168

Earlier quoted context omitted.

If you don’t believe that there are dangers out there for general users installing software from the internet, I don’t know what to tell you. History certainly proves otherwise, as do the number of attempts at putting malware into app stores. I’d go as far as to say that you are certainly wrong about this and you can trivially verify this by even the most cursory examination of software threat models. Author reputati…

Somehow the world outside walled gardens exists and it's not a danger-infested world. What's worse, you can't really argue for the quality controls of walled gardens such as the App Store because they are not transparent -- at most you can guess with trial and error. You haven't explained how the user has more control with walled gardens, a bold and unsupported assertion (I believe we both agree the author has less c…

Can you say where I said a walled garden was the only way to solve any of the problems?

In fact I have consistently agreed about the problems levied against the walled garden model.

I haven’t asserted that the user has more control with a walled garden, although I think they do in practice have more control with an App Store than with nothing.

I’d be curious how you came to the impression that I did - can you explain where I made that claim?

My claim is that walled gardens do introduce problems, but that they currently solve much greater problems for both users and developers than the ones they introduce.

The claim that it’s just safe for people to install software because it’s not dangerous out there is obviously false.

You can say this is just me saying ‘I’m right and you are wrong’, or you can do the most basic research on the amount of cybercrime and plain old scams and how much of it involves malware or impersonation of one kind or another.

If you think this problem doen’t exist, it would make sense that you don’t see the benefit of App stores, however to deny that it exists in this way is quite surprising, to say the very least.

The issue of reputation isn’t a matter of opinion. It’s a fact. How can I say that? All industries with a significant number of creators and a significant number of consumers have intermediaries. Only the most famous independent producers are independent.

If you can find a counterexample, I would be interested to know about it.

As for believing that the only solution to the issue of impersonation is a walled garden - I don’t know the answer to that.

Maybe some kind of distributed reputation and trust system that doesn’t involve a powerful intermediary is possible.

Perhaps some kind of blockchain or web of trust can be developed.

I’m not at all sure that this is possible - Apple’s attestation mechanism uses hardware keys to to create signatures that join a device, a particular user and an app binary.

Without the ability to link all three of these it’s hard to see how a software only solution would work.

But even if an alternative is technically possible, it quite obviously doesn’t exist today. If it did, you’d have just linked to it, and I’d have probably ordered whatever device would allow me to participate.

If you want to continue claim that App stores solve no real problems or that the problems are trivial, there are no dangers out there etc, then be my guest. I can’t change that belief in you.

If on the other hand, we have good solutions to those problems that don’t require an App Store, then I would love to know about them and if it’s true, I’ll happily concede that I’m wrong.

Re: Apple revoked longtime Mac developer's code signing certificate with no warning

#177
post #134

Earlier quoted context omitted.

Sure but Apple is clearly continuing to move in the direction of more security. The argument that they could be better therefore they are worth nothing, is a clear fallacy.

Then the same is true for letting people just install apps without vendor lock in.

No. That doesn’t follow.

I’m claiming that the App Store solution as it stands is better for most users than just freely installing apps from the web.

It’s not at all clear that the safety of just installing software without vendor lock in is getting better for most users.

In fact it seems to be getting worse.

Re: Apple revoked longtime Mac developer's code signing certificate with no warning

#178

Earlier quoted context omitted.

Yet somehow more iOS users have been hit with malware (see Xcodeghost) than Google and Amazon Android users combined, despite there being far more of the latter and despite the latter being able to install whatever they want on their devices.

I don’t see any evidence for that?

I gave it to you. Xcodeghost infected hundreds of millions of users.

Re: Apple revoked longtime Mac developer's code signing certificate with no warning

#179
post #154

Earlier quoted context omitted.

Honestly, no company should have this much control over people's businesses and livelihoods. iPhone is a generic pocket computer, and it has outgrown Apple's desire to maintain a fiefdom. Congress and the EU should force Apple to allow 3rd party marketplaces and installs. Apple is free to charge 30% for the App Store, but they can't be the only way to get code onto an iPhone. Nor should they be the only first class w…

This is actually why I completely left the Apple ecosystem. I ditched the iPhone for a LineageOS device and, since I think the Mac will eventually end up fully locked down as well, decided to get ahead of that race and migrate to Linux.

I have done the same but unfortunately bunch of my applications are not working becasue of them detecting I have modified rom! The switch is not painless.

Re: Apple revoked longtime Mac developer's code signing certificate with no warning

#180

Earlier quoted context omitted.

Honestly, no company should have this much control over people's businesses and livelihoods. iPhone is a generic pocket computer, and it has outgrown Apple's desire to maintain a fiefdom. Congress and the EU should force Apple to allow 3rd party marketplaces and installs. Apple is free to charge 30% for the App Store, but they can't be the only way to get code onto an iPhone. Nor should they be the only first class w…

I like everything going through Apple personally. In fact it's part of the reason I have an iPhone.

Thats fine. Those who want to can still go through the Apple App Store. Options should be made available for those who don't
Post reply on HN