Live data from Hacker News

Can't you just right click?

lapcatsoftware.com

411–420 of 765 posts

Re: Can't you just right click?

#411
post #275

Earlier quoted context omitted.

>It is a lifestyle brand now, people money because it is Apple, not because there is real value they gain for the higher cost. Oh come now, there are millions and millions of professionals using macOS to do work every single day. This is basically a slippery slope fallacy. Today they're making it marginally hard, what might they do tomorrow?!? There are many reasons to prefer macOS to Linux or Windows. The Apple ecos…

> Oh come now, there are millions and millions of professionals using macOS to do work every single day. Right, and how many of those are using macOS because they're "forced" to, as a sibling suggests, or simply by force of habit? Moving from macOS to Linux or Windows (or from any one OS to any other, really) does require some time. It's not necessarily difficult, but it still takes time. Time that the same professio…

> Right, and how many of those are using macOS because they're "forced" to, as a sibling suggests, or simply by force of habit?

Right, because you know why each and every one of the billions of users do what they do, and of course, none of them would be doing something by choice, because how could anyone possibly like something you do not?

Re: Can't you just right click?

#412
post #44

Earlier quoted context omitted.

As someone whose elderly parents run Windows and have never run 'any executable that any website tells them to download', and I myself have not seen a website that gives me a random executable in over a decade: Out of curiosity, how often do your parents encounter the dialog in the article?

Try using safari on a MacBook. Last time I spent 10 minutes on my wife's laptop, every website was filled with garbage ads saying your Mac is infected with a virus you must download an anti virus quick (#malware). The shadier websites (streaming) sent a dmg executable as soon as they were opened. It's shocking, it's worse than Windows (sad fact: Mac has more malware/adware than Windows since the last 3 years). Of cou…

I use Safari on a Mac without an ad blocker as my main browser, and I don’t see anything like what you describe. What kind of websites are you visiting where you get that kind of result?

> Safari removed support for extensions last year, dropping all adblockers, it's wide open to targeting.

This is not true. There’s a dedicated section in the Mac App Store for Safari extensions, including ad blocking extensions:

https://apps.apple.com/gb/story/id1377753262

Re: Can't you just right click?

#413

Earlier quoted context omitted.

I think you've misunderstood the article. Ad-hoc signing is absolutely supported on Apple Silicon Macs. You don't need Apple's permission to build your own software on your machine, nor to distribute it to others.

I understood it perfectly, which is why i wrote "you cannot run unsigned software" instead of "all software must be notarized by Apple".

Disingenuous. "Signed software" is generally understood to mean signed with am Apple-issued certificate. The fact that you can ad-hoc sign with no certificate at all makes that kind of signing little more than a linker step. You might as well have said "you cannot run uncompiled software" for all the relevance it has.

Re: Can't you just right click?

#414
post #2

This makes me wonder how open source is supposed to work on macOS. People seem to become more and more aware of it and even enterprises that insisted on support contracts can see that they can't get around open source completely anymore. Meanwhile Apple is removing the ability for me to have a pet project without paying an Apple tax. If the message were completely transparent, something like "The developer didn't pay…

In my day job, I work on a relatively large open-source non-GUI application macOS is becoming an increasingly difficult platform on which to release software. We're going down the notarization rabbit hole (which is a nightmare), but given that we don't fit on the App Store, it's very obvious that Apple doesn't want us on the platform. My suspicion is that they will eventually charge $$$ for a "developer unlock" on Ap…

If developers move from Apple to Windows because of this, they haven't learned from their mistakes.

Re: Can't you just right click?

#415
post #299

Earlier quoted context omitted.

Safari's ad-blockers are not really comparable[0] to what's currently possible on Firefox, Chrome, or other Chromium-based browsers. They rely on declarative blocking and/or system-wide interception (ie, you run them as an entirely separate app outside of Safari). The majority of them are not going to be able to handle things like CNAME unmasking or page source rewrites[1]. The declarative blocking API in Safari isn'…

As I understand this is somewhat alleviated in Big Sur as Safari now has support for WebExtension.

No, that doesn’t support WebRequest.

Re: Can't you just right click?

#416

The power that tech companies accumulate with tactics like this, and the justifications for that power, are strangely reminiscent of autocratic governments: we decide which programs you can develop and run, and we can levy an arbitrary 30% income tax (on top of regular VAT). But don't worry, it's all for your safety and security! We are fast becoming corporate citizens, for better and for worse: https://www.youtube.c…

Frankly, I’m afraid your premise is a bit of a straw man argument.

I’m constantly running npm, mvn, sbt, docker and some that download hundreds of megabytes from unknown organizations, hosted on unknown servers, written by unknown developers.

Next to that, I’m running desktop applications downloaded roughly under the same circumstances, and was the update image it just installed when I opened it genuine? Transmission was 0wned, as well as Handbrake. Any other I was never aware of? Perhaps one that I’m currently using?

I have several GB of irreplaceable (to me) photos and financial documents on this laptop. When was the last time I tested my cold-storage restore procedure? (Hint: never.) What if I get hit by a ransomware? What if they grab my GAccount cookie and run away with my identity?

All this makes me fret, and aware of how much vulnerable my information persona has become.

I can run Linux, and trust Ubuntu or Debian or whatever to thoroughly audit and verify every line before PGP signing any package released for distribution (riiight, it’s already a gift out of free will, am I going to make demands now?) I could manage, begrudgingly though because I’m more interested in using the tool than to constantly grind it’s sharp edges.

But what about normal users? Not necessarily idiots. Just people that haven’t explored the dense thicket of Linux on the desktop and ACPI, and kernel driver (oh, by the way... what about those drivers?) Don’t they have the right to some trust and expectation of privacy? (that they can immediately forego and upload to Facebook)

Why must everyone constantly have to risk their own neck to defend someone else’s perception of freedom. Why should they all pay (in terms of risk and time mitigating against it) for something that someone else presumes it would benefit them?

Apple can abuse their grip on their integrated platform. Apple can turn this infrastructure into a rent-seeking scheme, into extortion.

But for the time being, they can’t deliver cryptographic app control soon enough.

Re: Can't you just right click?

#417
>although Apple has indicated that a future version of macOS may not allow unsigned code to run at all

Where is this comming from? I doubt Apple indicated such a thing.

Re: Can't you just right click?

#418
post #272
post #155

Earlier quoted context omitted.

Could that be turned into a little funding opportunity? "Here are the sources, here are the binaries, here you subscribe to get access to signed binaries that run without the scare quotes"

The developer who signs the software is thereby taking legal responsibility for the software, and taking the blame if anything is wrong with it. That's not a good risk unless you're signing for someone you trust completely.

How much does that actually change liability vs building and distributing unsigned? Signing has no legal implication other than lowering deniability. What's added is the contract with Apple. Is that such a minefield?

Re: Can't you just right click?

#420
post #152

I thought that a developer status will autosave me either from malware or from being babysitted, but then [1] happened. No matter how hard I tried to start that binary, OSX didn't allow me to do that. Damn OS which knows better, who do yo think you are? Did you see checksums, site certs, my competence, my willpower? I thought that it must be something with a build process that transmission uses, some signature didn't…

So the moral is that we should give up freedom for security? Because that's a bad moral.

So is the moral that we should give up security for freedom?
Post reply on HN