Live data from Hacker News

Can't you just right click?

lapcatsoftware.com

71–80 of 765 posts

Re: Can't you just right click?

#71
post #39

Earlier quoted context omitted.

> Do you know how much $100 is in Iran? It doesn't really matter, because for developers in Iran, the question becomes do you know how hard it is to pay US companies from Iran?

The minute you admit you are in Iran, American companies aren't supposed to sell to you, generally speaking. So, yeah, that seems like a weird comment.

Fine, do you know how much $100 is in Serbia?

Re: Can't you just right click?

#72
post #27

I dont see any problem with this. If you don't feel comfortable doing this then you definitely shouldn't be running random code from the internet. I would take it a step further and force it to be run from the command line. Also, what kind of "viable software business" has trouble paying $100 a year?

Any open source developer? Do you know how much $100 is in Iran?

You need $100 fundraised across the entire userbase.

If this is a problem, projects can join together into one large app.

Re: Can't you just right click?

#73
post #44

This feature is at about the right spot for me. It is still convenient enough for me to run software I want that isn't signed, but sufficiently obtuse that neither of my parents have figured it out. Given they are both prone to running any executable that any website tells them to download and run, this feature has probably save me several dozen hours of fixing their computers.

As someone whose elderly parents run Windows and have never run 'any executable that any website tells them to download', and I myself have not seen a website that gives me a random executable in over a decade: Out of curiosity, how often do your parents encounter the dialog in the article?

I don't know how often they see it.

But in the Windows days every time I'd visit, they'd say there computer was "fucked" and had been put away until I could look at it.

Re: Can't you just right click?

#74
post #7

I still believe that Gatekeeper is a blatant cash grab and not a legitimate security feature. $100/year to avoid a scary warning about how your app is definitely a virus? It's like a protection racket.

It might be different if it went to a charity of your choice. I've been to conferences where the entrance fee was just a token amount to make sure you didn't register, reserve a spot, and didn't show. Or first-class train tickets: you don't pay for more expensive seats, you pay for it being expensive and keeping other people away.

People from rich countries that have the spare time and skills to write reasonably decent software are likely to have $100 of disposable money per year and would probably be donating anyway, so a donation might be reasonable, and I'd understand if Apple takes a few dollars to do but it really won't cost a full $100 per developer per year. For that money they can fly in from the nearest English-speaking country to verify my scowl.

Re: Can't you just right click?

#75
post #27

Earlier quoted context omitted.

Any open source developer? Do you know how much $100 is in Iran?

I just looked it up, and it seems like $100 is worth less than half a week of an average developers salary in Iran.

$100 can be an hour of a developer's salary here, or even less. The relative cost is quite large. (Oh, and guess who isn't making a developer's salary in Iran? Someone who is just starting out, or an open source developer, or someone who is currently unemployed…)

Re: Can't you just right click?

#76
post #2

This makes me wonder how open source is supposed to work on macOS. People seem to become more and more aware of it and even enterprises that insisted on support contracts can see that they can't get around open source completely anymore. Meanwhile Apple is removing the ability for me to have a pet project without paying an Apple tax. If the message were completely transparent, something like "The developer didn't pay…

Open source projects sign their Apps like anyone else. Works fine. They do the same on Windows of course and on Linux package managers.

Is there any Linux distribution charging an yearly fee for package signing?

Re: Can't you just right click?

#77

Earlier quoted context omitted.

Question for you: what exactly does Notarization protect against? I have watched all the videos about it, I read the developer documentation, I notarize my apps because it is required by the OS…but I still have not gotten a single good explanation as to why it's useful. Apple claims that the process is extremely tolerant…so does it try to accept everything but blatant malware? Does it let malware through? What happen…

As far as I know it is intended to prevent identity abuse in both the IRL sense as cryptographic sense. It means that it is harder for an attacker to abuse your systems or key material to sign something in your name. Perhaps the best analogy I can come up with is the dns-01 verification with ACME and a lower TTL. You need to compromise more pieces of the puzzle on a shorter timeline to attack that specific part of th…

Code signing was always a thing, and you can sign your code without notarizing it. And in fact notarization doesn't really seem to have much to do with the person who wrote the thing you are notarizing–you can notarize other people's software!

Re: Can't you just right click?

#78
post #8

Earlier quoted context omitted.

But then you’ll have websites that walk you through changing the setting. At least this way you have to make a decision every time, even if it costs you a few clicks each time you do it.

They can do the same for the right-click technique. Omitting a setting does not change the user's understanding of the decision, it just makes this completely undiscoverable and tedious for users who know what they're doing.

A system setting risks allowing you to make more mistakes.

Imagine I install some app from a trusted third party and am walked through the steps to toggle the system setting to allow installs. Then a year later when I am installing some untrustworthy tool, I am no longer warned (at least not to the same severity) that this tool is unsigned. It leaves me more likely to install that software and end up putting myself at risk in the future.

Take for example the Android settings for installing third party apps. I can enable it on a per-app basis, but that permission persists for the lifetime of my device. If I allow Chrome to install apps for me, that enables apps from ANY site from now until the EOL of my device, to more easily make their way onto my phone.

If I am asked every time (or even periodically) I am given a moment to consider if I know what I am doing.

Re: Can't you just right click?

#79

Earlier quoted context omitted.

The minute you admit you are in Iran, American companies aren't supposed to sell to you, generally speaking. So, yeah, that seems like a weird comment.

Fine, do you know how much $100 is in Serbia?

I spent years homeless. There are sometimes homeless developers in the US. You don't have to actually go asking snarky questions about wage rates in other countries to make the point that, for some people, that's a meaningful barrier, even for the software industry.

If that's the point you want to make, there are much better ways to make it.

Re: Can't you just right click?

#80

This feature is at about the right spot for me. It is still convenient enough for me to run software I want that isn't signed, but sufficiently obtuse that neither of my parents have figured it out. Given they are both prone to running any executable that any website tells them to download and run, this feature has probably save me several dozen hours of fixing their computers.

Apple has been making things more and more restrictive over a decade now.

New versions of mac os introducing new restrictions.

Doesn't take a genius to see that their end goal is to make mac os as restrictive as ios.

When that happens, will it still be the right spot for you?

Post reply on HN