Live data from Hacker News

Can't you just right click?

lapcatsoftware.com

181–190 of 765 posts

Re: Can't you just right click?

#181
post #44

This feature is at about the right spot for me. It is still convenient enough for me to run software I want that isn't signed, but sufficiently obtuse that neither of my parents have figured it out. Given they are both prone to running any executable that any website tells them to download and run, this feature has probably save me several dozen hours of fixing their computers.

As someone whose elderly parents run Windows and have never run 'any executable that any website tells them to download', and I myself have not seen a website that gives me a random executable in over a decade: Out of curiosity, how often do your parents encounter the dialog in the article?

Try using safari on a MacBook. Last time I spent 10 minutes on my wife's laptop, every website was filled with garbage ads saying your Mac is infected with a virus you must download an anti virus quick (#malware). The shadier websites (streaming) sent a dmg executable as soon as they were opened.

It's shocking, it's worse than Windows (sad fact: Mac has more malware/adware than Windows since the last 3 years).

Of course you can't see that if you're not on Mac or if you have an adblocker. Ads detect the browser and specifically target Safari. Safari removed support for extensions last year, dropping all adblockers, it's wide open to targeting.

Re: Can't you just right click?

#182
post #152

I thought that a developer status will autosave me either from malware or from being babysitted, but then [1] happened. No matter how hard I tried to start that binary, OSX didn't allow me to do that. Damn OS which knows better, who do yo think you are? Did you see checksums, site certs, my competence, my willpower? I thought that it must be something with a build process that transmission uses, some signature didn't…

So the moral is that we should give up freedom for security? Because that's a bad moral.

Like anything in life there is balance, and anyone living in any sort of society today has already given up some freedom for some security.

Re: Can't you just right click?

#183
post #169

Earlier quoted context omitted.

In theory no, that's impossible. In practice, I publish checksums on my website and people trust that I am not malicious.

The thing is, your friendly scammer could also publish checksums on their website. It is clear to you that you're writing fine open source software, not malware. But how is the consumer supposed to tell? If people trust you, why bother with the checksums? (Over HTTPS, the downloaded content cannot be tampered with. If someone tampered with the content on your website, or performs a MITM, they can also replace the che…

The checksums are there if they happen to grab the binary in some way that is not "using HTTPS directly from my website" and they'd like to check. Why do the know I'm not writing malware? Trust in my software, mostly? It is unclear that notarization actually stops malware–Apple has failed to explain how it helps, but enforces it by decree.

Re: Can't you just right click?

#184
post #34

A couple other ways to deal with it (at least for some instances--not sure this applies to every kind of executable). 1.1 Hit "Cancel" in the warning dialog. 1.2 Open "System Preferences" / "Security & Privacy" and select the "General" tab. 1.3 It should have a notice about the unverified app being blocked, and offer the chance to approve it. Do so. 1.4 Try to launch the app again. You'll get the dialog again, but th…

I have to look up this fucking procedure every time I update our internal executable tools. And for whatever reason the security setting loads up some sub tab for me and I always forget you have to go back to general to find the little thing at the bottom to allow the app. This is so far beyond reasonable from a ux standpoint and they have no reason to improve because what am I going to do? Not use macos to work on i…

If you have an automated process to update internal tools, you will likely have a much better UX with updating that process to appropriately deal with quarantine.

Re: Can't you just right click?

#185

Earlier quoted context omitted.

They can do the same for the right-click technique. Omitting a setting does not change the user's understanding of the decision, it just makes this completely undiscoverable and tedious for users who know what they're doing.

A system setting risks allowing you to make more mistakes. Imagine I install some app from a trusted third party and am walked through the steps to toggle the system setting to allow installs. Then a year later when I am installing some untrustworthy tool, I am no longer warned (at least not to the same severity) that this tool is unsigned. It leaves me more likely to install that software and end up putting myself a…

But the setting doesn't have to get rid of a warning, we're discussing requiring the right-click to even show the option of running the software.

Gatekeeper right now won't even allow you to run an application unless you somehow know and remember to right-click. This is sadistic. Many well-informed users won't even know about it and even more will forget to right-click on the first try. This is far from "forcing the user to make a choice about each binary". It's clear Apple doesn't want users to even be aware that there is a choice.

Re: Can't you just right click?

#186

This behavior frustrates me, as a seasoned (=old) Mac user, but I am simultaneously quite grateful for it existing on my parents Macs. It would be nice if there was a Sys Prefs option to add a "run anyway" button to the initial prompt. It wouldn't even need to be on by default. Just give me the option.

It would be a command-line option. They used to have a system preference to disable signing, but a lot of software (including Minecraft, for a while) walked users through disabling gatekeeper security for the whole system rather than sign their individual software or try and explain right-clicking.

Re: Can't you just right click?

#187

Earlier quoted context omitted.

Question for you: what exactly does Notarization protect against? I have watched all the videos about it, I read the developer documentation, I notarize my apps because it is required by the OS…but I still have not gotten a single good explanation as to why it's useful. Apple claims that the process is extremely tolerant…so does it try to accept everything but blatant malware? Does it let malware through? What happen…

> Apple claims that the process is extremely tolerant…so does it try to accept everything but blatant malware? From what I understand, the most common use case here is to match against known malware inserted into an otherwise normal release, either from an infected dev machine or by way of an attacker coopting stolen credentials. It's not going to guard against truly novel malware for obvious reasons, but the vast ma…

But Apple can already detect that using XProtect…

Re: Can't you just right click?

#188

Earlier quoted context omitted.

The minute you admit you are in Iran, American companies aren't supposed to sell to you, generally speaking. So, yeah, that seems like a weird comment.

Which increases the point of being allowed to develop apps for a generic computing platform.

There was no intent at all to be disrespectful. The comment caught my eye in part because I have something of a personal interest in Iran.

I used to speak regularly with an Iranian who was, among other things, a software developer. My general impression is that money was not nearly as big a problem as other things, thanks to the embargo.

Your comments don't quite fit with my understanding of things, which could be just my lack of knowledge about a lot of things. If you are Iranian and, thus, your primary language is Farsi, perhaps it's due to a language barrier.

I'm trying to bow out of this discussion and already deleted one of my comments. It seems like a rather lot of negativity over a minor observation on my part. So it doesn't seem like a good place to try to start a meaty discussion of open source in Iran, or I think that would be interesting to me personally, in spite of my limited knowledge of code and so forth.

Re: Can't you just right click?

#189

Earlier quoted context omitted.

So the moral is that we should give up freedom for security? Because that's a bad moral.

Like anything in life there is balance, and anyone living in any sort of society today has already given up some freedom for some security.

They never had a choice.

There seems to be a trend in the US society today to error more on the side of safety than liberty than I've seen ever before. Particularly, this is a change in the tech community which has been a bastion in the fight for individual freedoms since I've been alive.

In the end, when you make that bargain at the levels we are making it today, the safety is only temporary but the damage to liberty is unrecoverable without starting over.

It's a bad bargain.

To be clear of straw men, I'm not saying that individuals (not groups) who have personally demonstrated bad behavior should have complete freedom to repeat such acts. This argument is, and always has been, about pre-emptive actions against the innocent in the name of safety.

Re: Can't you just right click?

#190
post #161

Earlier quoted context omitted.

Because it says the binary is damaged/malware/sketchy and that is not correct.

It doesn't say that. It says that it can't verify the developer, and can't verify that the software is free of malware. It's just some arbitrary piece of software, could be written by anyone, and/or could be software that purports to be Word or Photoshop or whatever, but has been modified. Granted, you could quibble with the details (does pointing out that you can't verify that it's free from malware imply that you c…

One of the possible warnings you can get literally has "[App name] will damage your computer. You should move it to the trash" in the dialog that shows up. There's a bunch of these, all of them pop up for various GateKeeper/Notarization shortcomings, and none of them actually seem to ever really tell you what the problem was.
Post reply on HN