All of these people saying: switch to Windows, its better than mac! Have you really done that? REALLY? Because I work on Mac, Win10 and Linux every day. And Win10 doesn't even come close to the other two in terms of reliability, stability, and lack of unnecessary bullshit. I just don't understand who can make this claim that Win is better than Macos with a straight face. Maybe for gaming. Maybe. The cost/fps is clear…
Can't you just right click?
641–650 of 765 posts
Re: Can't you just right click?
#642Earlier quoted context omitted.
To the average user, yes, but Apple can see the chain of trust and can do the data science required to figure out who signed what. You better believe that in the even of a large scale malware distribution via signed binaries, they're going to be revoking those certs and tracking down the accounts responsible (like after the VLC website hack).
The data science to find out who ran md5sum on their binary?
https://developer.apple.com/documentation/xcode/notarizing_m...
Re: Can't you just right click?
#643Earlier quoted context omitted.
If the signed software is notarized, and the signature checks out, then you can be sure that Apple did some malware-scan-like process to the app on their server at some point(1) and that the app you’re seeing is the same one they saw. (1) and probably a manual review if the App under analysis was found to call into any but a whitelist of “safe” system APIs. Without the code signing, you can’t be sure that the app you…
I think we all agree on what the security benefits are, because we know what’s going on. But Apple is telling users that they can’t verify it’s free from malware, implying that all notarized code is free from malware, which is a ridiculous claim to make, and discourages people from using excellent software that Apple, for whatever arbitrary reason they like, have decided not to notarize.
How so? Even if they don’t catch malware during notarization, Apple also reacts pretty quickly to invalidate a developer’s code-signing certificate if they use it to sign apps that contain malware (as soon as Apple is made aware of that malware-app, for which they maintain relationships with both major antivirus vendors and independent security researchers.) Your computer then receives the new Apple code-signing CRL in a silent update, and won’t run the app (or any app by that developer) any more. Even if you’re offline at the moment, and so can’t contact the notarization servers to find out the app has been denotarized, as long as you’ve been online at any point since the CRL was updated, you’ll be protected. (And where does malware come from? These days, 99% of the time, the network. So if you stay offline, you’re extremely unlikely to run into novel malware anyway. And if you’re online to receive the malware, you’re almost certainly going to have received the CRL update first.)
And sure, there’s a small period of vulnerability before Apple is made aware of new malware; but most malware infections are not from zero-day malware, but rather from malware that’s been going around for a long time already. (And I believe they also push ‘disinfectant’ logic in those same silent updates that update the code-signing CRLs, same as Microsoft does with Windows Defender. So the usual “join a botnet, hijack your browser” kind of malware can simply be reverted.)
Plus, there’s the whole System Integrity Protection thing, meaning that macOS malware can’t really do anything to permanently subvert the Gatekeeper infrastructure, since it lives in the “untouchable” root partition. (It could do something clever with a system extension, but as of Catalina you have to explicitly activate those in the Security preference pane; and probably, as of Big Sur, you won’t be able to activate them at all.) So it’s only people with SIP off (i.e. system extension developers; Hackintosh owners) who would even feel any sort of “deep impact” from any of this malware. Meaning that macOS malware authors basically don’t bother to try to “deeply embed” their malware into the OS, given that the process will only actually work on a tiny fraction of systems.
Anyway, all that being said: it’s not like Apple said they can’t “guarantee” that the app is free from malware, implying that signed+notarized apps would be guaranteed free from malware. They just say they can’t “validate” that the app is free from malware, implying that the apps that don’t show this warning have been “validated” by Apple—i.e. audited, to the best of their own abilities and current knowledge. Signed off on, like a home inspector signs off on a house. And that’s exactly the case. Apple has “validated” those apps. That doesn’t translate to some technical guarantee of safety, like running the app in a VM would give. It only translates to “you can trust this app to the degree that you trust Apple’s validation process.”
It’s exactly the same claim that Chrome and Edge are implicitly making when you download software through them on Windows: the software gets “validated” by Google/Microsoft as not containing malware to the best of their knowledge. It’s an antivirus signature scan, combined with a trustworthiness heuristic based on whether the developer was willing to sign their software. The only difference is that, in Apple’s case, the “antivirus scan” part happens on a server somewhere, asynchronously, rather than on the client. But it’s the same level of effective security.
Re: Can't you just right click?
#644Earlier quoted context omitted.
To the average user, yes, but Apple can see the chain of trust and can do the data science required to figure out who signed what. You better believe that in the even of a large scale malware distribution via signed binaries, they're going to be revoking those certs and tracking down the accounts responsible (like after the VLC website hack).
There is no certificate involved in ad-hoc code signing. It's just a hash with no identity or chain of trust involved.
> You can only notarize apps that you sign with a Developer ID certificate. If you use any other certificate — like a Mac App Distribution certificate, or a self-signed certificate — notarization fails with the following message: "The binary is not signed with a valid Developer ID certificate."
https://developer.apple.com/documentation/xcode/notarizing_m...
https://developer.apple.com/library/archive/technotes/tn2206...
Re: Can't you just right click?
#645Disabling Gatekeeper From the Apple menu, open the "System Preferences" application. Click on Security & Privacy > General tab. If the lock in the left-hand corner is locked, click on it, then enter your Mac's username and password. This may not be required. Click "Anywhere" under "Allow applications downloaded from:". If you followed Step 3, please click the lock in the left-hand corner to return it to its locked st…
Sounds like a security disaster for non-technical users. It is much better to trust a specific app from now on than to trust the entire internet from now on.
Not for nothing, Gatekeeper once did not exist. Myriads of Mac OS X users were not p0wned. But your point is not lost on me.
Re: Can't you just right click?
#646Earlier quoted context omitted.
The developer who signs the software is thereby taking legal responsibility for the software, and taking the blame if anything is wrong with it. That's not a good risk unless you're signing for someone you trust completely.
It also might be tough to run as a business because it's quite possible the first time you sign someone else's malware, Apple's going to revoke the notarization of all the apps you've signed (which would be for other paying customers). Not to mention it undermines the purpose of notarization, so if it became popular enough they'd probably just squash it.
There'd even be a conceivable but unlikely scenario where some automated scan deep inside the Apple publishing pipeline would detect an otherwise undetected malware intrusion in some upstream dependency or badly vetted commit and thereby indirectly protecting the users of the unsigned copy, by acting as a canary.
Re: Can't you just right click?
#647Earlier quoted context omitted.
If only we had an operating system that we could install on our computers freely, right? It is a shame that people are forced to buy a computer and not reformat the disk to install their OS of choice. It is a shame that we can not take the money that we could be saving and investing in open alternatives...
Yes, and I've used that other OS a lot as well But it is not a panacea and it is not for everybody. And it has two main issues: - developers don't care about stability and/or polish (just see the discussions on the trackpad ITT) "Oh but if you change library X to Y and reroute libinput and etc it might maybe work and maybe it will not break anything else" - because of the former reason, not all (important) applicatio…
I use Linux Mint and love it.
MS Teams, Skype and a surprisingly good list of software runs on it natively.
A Hackintosh inside VirtualBox IS a pain to setup, but pretty cool when it works. Windoz inside VirtualBox works better than ever, thanks to MS new attitude on embracing Linux.. which is still hard to wrap my head around.
Re: Can't you just right click?
#648Earlier quoted context omitted.
> At least with Linux once I configure it right it works without issue and does everything I want. Until an update breaks it because some asshole decided to break an ABI, or swap out a fundamental system component with a different one, etc. So I guess what you're saying is true so long as you never update anything.
Do you have concrete experience for that? I have only 3 things I hit: - NVIDIA driver updates (or kernel updates while using nvidia) - caused black screen... I dumped nvidia... these are due to crappy nvidia. - Ubuntu deciding to remove old libraries/apps that are not maintained. That's fixed via docker or just keeping an old version. - Major version upgrades (ubuntu 18 to 20) - here I just re-install and it's expect…
Yes.
> NVIDIA driver updates (or kernel updates while using nvidia) - caused black screen... I dumped nvidia... these are due to crappy nvidia.
This is a legitimate dispute and I'm not really counting it because as much as I think Linux should have a stable driver ABI, NVidia are being needlessly obtuse.
> Ubuntu deciding to remove old libraries/apps that are not maintained. That's fixed via docker or just keeping an old version.
Which is not a simple task. Why can't keeping old software be simple? It is in sane operating systems. Hell, even Linux can do it right, as AppImage proves, but the Linux Desktop community is so hell bent on making everything as complicated as possible that they pretty much ignore AppImage.
> Major version upgrades (ubuntu 18 to 20) - here I just re-install and it's expected, I wouldn't upgrade windows 7 to 10 either...
Ubuntu LTS receives 5 years of support, but most new software will not be backported to the repository for anywhere close to that long in my experience and instead you're getting about 2 years. Windows 7 was supported for nearly 11 years and it was rare new software didn't support it for that entire time.
> you only get annoyed by those if you are a power user anyway
Precisely. Linux Desktop people seem to think that targeting people who only need a web kiosk is somehow going to make them popular, but if people who actually know about and need the features of an actual desktop computer don't like it why would they ever recommend it to anyone?
Re: Can't you just right click?
#649Earlier quoted context omitted.
Do you have concrete experience for that? I have only 3 things I hit: - NVIDIA driver updates (or kernel updates while using nvidia) - caused black screen... I dumped nvidia... these are due to crappy nvidia. - Ubuntu deciding to remove old libraries/apps that are not maintained. That's fixed via docker or just keeping an old version. - Major version upgrades (ubuntu 18 to 20) - here I just re-install and it's expect…
> Do you have concrete experience for that? Yes. > NVIDIA driver updates (or kernel updates while using nvidia) - caused black screen... I dumped nvidia... these are due to crappy nvidia. This is a legitimate dispute and I'm not really counting it because as much as I think Linux should have a stable driver ABI, NVidia are being needlessly obtuse. > Ubuntu deciding to remove old libraries/apps that are not maintained…
Care to share?, I'm curious :)
> Which is not a simple task. Why can't keeping old software be simple? It is in sane operating systems. Hell, even Linux can do it right, as AppImage proves, but the Linux Desktop community is so hell bent on making everything as complicated as possible that they pretty much ignore AppImage.
Resources make it complicated (time/money/...). I wouldn't maintain another person's library that he doesn't bother with.
> Windows 7 was supported for nearly 11 years and it was rare new software didn't support it for that entire time.
You are comparing a paid product with something free. For better or worse new software works on ubuntu older versions as well, but you need to compile it or work to get it there. Or just upgrade.
I assume you can also switch to Red Hat which have paid support.
> Precisely. Linux Desktop people seem to think that targeting people who only need a web kiosk is somehow going to make them popular, but if people who actually know about and need the features of an actual desktop computer don't like it why would they ever recommend it to anyone?
My point there was if you are a power user you should be able to get it working, it's a skill that's very good to have. Other less skilled people don't hit it by virtue of not playing around.
The 'Linux Desktop' people that you say are targeting things for better or worse put in time to build free products, if you don't like some switch to others or contribute.
Re: Can't you just right click?
#650Earlier quoted context omitted.
This is a nice example of what a logician calls a false cause: your conclusion (definition of outrageous) isn't supported by your premise (how much you used to pay for kit). It's also a straw man, since I was talking about an OS developer wanting to publish their software, and you're attempting to sink it by portraying it as referring to a consumer wanting free stuff. The subject of your conclusion, 'current generati…
Like 1000 euros per year for a MSDN Professional license, or the required certification from several vendors that have to be renewed every couple years.
What you're referring to is the top-tier MSDN subscription, which is something that very few organizations will require.