Live data from Hacker News

Apple Accidentally Approved Malware to Run on macOS

wired.com

31–40 of 134 posts

Re: Apple Accidentally Approved Malware to Run on macOS

#31
post #18

Earlier quoted context omitted.

> What else is the scanning of an uploaded executable than an (automated) review process though? It's a pass of checks that might or might not find something. It's not some official stamp of approval, except to say "those checks passed ok".

"Those checks passed ok" is an approval in itself. The notarization process has the outcome of either being approved or being denied. Approved means "officially agreed or accepted as satisfactory.".

When a Justice of the Peace notarises a piece of documentation, they are not vouching for authenticity they are only voicing for certain claims made: the document was presented on a certain date, and/or that this copy is an accurate facsimile of the provided original.

Notarisation for macOS similarly only means, “the developer presented us with their application and their certificate of authenticity and we signed it with the certificate that allows macOS to run it without complaining.”

There’s no attempt by Apple to claim that the application is safe or does what it says on the tin.

Scanning for malware is simply to avoid embarrassing situations me an author/publisher finding they’ve been compromised by some well known malware.

The outcome of notarisation is that the app has been notarised.

It’s like claiming that the outcome of toasting a sandwich is approval or rejection, no the outcome of toasting a sandwich is you have a sandwich that is toasted, aka “toasted sandwich.”

You might reject a sandwich which isn’t built properly (eg: has mismatched bread slices, is missing contents or smells of dynamite). But toasting the sandwich provided by the customer doesn’t mean you actually like it.

Re: Apple Accidentally Approved Malware to Run on macOS

#32
post #26
post #6

It's astonishing that the developer community is fine with requiring open source projects to pay $99/yr for notarization to run on macOS. Malware authors will happily pay the developer account fees, as seen here, while open source projects are seriously hindered. It should be possible to verify developers and distribute open source apps without a cost on macOS.

$99/year is such a small amount relative to the costs of software development that it's hard to worry about. Meanwhile, there is good value. (The developer resources Apple provides are not free.) You can argue that Apple should provide developer resources at no cost, but that just means someone else is paying for them or you will pay them in some other way... or do without. I think at this point in the tech boom we c…

> The developer resources Apple provides are not free.

So then why is the charge for signing and not for developer tools? That way if I wanted to I could use somebody else's tools instead of paying Apple.

> I think at this point in the tech boom we can all understand that when a company gives you stuff of value at no cost there are significant tradeoffs and paybacks.

Which is why I paid so much for my copy of gcc. Wait, hold on.

Re: Apple Accidentally Approved Malware to Run on macOS

#33

The title is not justified. Nowhere in the text is it proven that it was approved by accident. It might have been an employee acting with malice aforethought

Did you read the article? It's an automated process. Unless you're referring to our robot overlords there was no malicious employee involved.

Re: Apple Accidentally Approved Malware to Run on macOS

#34

Earlier quoted context omitted.

"Those checks passed ok" is an approval in itself. The notarization process has the outcome of either being approved or being denied. Approved means "officially agreed or accepted as satisfactory.".

When a Justice of the Peace notarises a piece of documentation, they are not vouching for authenticity they are only voicing for certain claims made: the document was presented on a certain date, and/or that this copy is an accurate facsimile of the provided original. Notarisation for macOS similarly only means, “the developer presented us with their application and their certificate of authenticity and we signed it…

> There’s no attempt by Apple to claim that the application is safe or does what it says on the tin.

So that isn't part of the notarization process. It still was approved by Apple and thus was notarised.

> It’s like claiming that the outcome of toasting a sandwich is approval or rejection, no the outcome of toasting a sandwich is you have a sandwich that is toasted, aka “toasted sandwich.”

That's disingenuous. If I send a Sandwich to be toasted by Apple and get it back toasted that means the Sandwich was indeed approved by Apple since it has been toasted.

Re: Apple Accidentally Approved Malware to Run on macOS

#35
post #26
post #6

It's astonishing that the developer community is fine with requiring open source projects to pay $99/yr for notarization to run on macOS. Malware authors will happily pay the developer account fees, as seen here, while open source projects are seriously hindered. It should be possible to verify developers and distribute open source apps without a cost on macOS.

$99/year is such a small amount relative to the costs of software development that it's hard to worry about. Meanwhile, there is good value. (The developer resources Apple provides are not free.) You can argue that Apple should provide developer resources at no cost, but that just means someone else is paying for them or you will pay them in some other way... or do without. I think at this point in the tech boom we c…

Apple gets its money back on the hardware alone.

Re: Apple Accidentally Approved Malware to Run on macOS

#36
post #22

Earlier quoted context omitted.

The choice is don't build for MacOS. In the long run Apple won't be happy with that and maybe they'll waive the fee.

How would that get them to waive the fee? If your app is open source and they wanted it that bad they could just build it themselves, or develop their own replacement for it, and anybody else can pound sand. They have you over a barrel and they know it.

So let's Apple port, build and distribute open source for MacOS. I have no problem with that. Yet I bet it would cost Apple more than the money they do from the license they sell to OS developers.

Re: Apple Accidentally Approved Malware to Run on macOS

#37
post #26
post #6

It's astonishing that the developer community is fine with requiring open source projects to pay $99/yr for notarization to run on macOS. Malware authors will happily pay the developer account fees, as seen here, while open source projects are seriously hindered. It should be possible to verify developers and distribute open source apps without a cost on macOS.

$99/year is such a small amount relative to the costs of software development that it's hard to worry about. Meanwhile, there is good value. (The developer resources Apple provides are not free.) You can argue that Apple should provide developer resources at no cost, but that just means someone else is paying for them or you will pay them in some other way... or do without. I think at this point in the tech boom we c…

Apple are a multi-trillion dollar company, they don't need more money

Re: Apple Accidentally Approved Malware to Run on macOS

#38
post #17

Earlier quoted context omitted.

I see your point and principle , but the salary-opportunity-cost on the number of hours that the average piece of OSS takes to develop would surely dwarf 99 dollars, making that fee maybe 1% of the total effective cost.

This is simply not true. Many OS developers are working in lower income countries. Or aren't even employed yet because they are in school. Your assessment only works for working developers in high income countries. And even then requiring 99 dollars is insane.

I agree Apple should make the developer fee a nominal amount for all kinds of developers.

The baseline for a Mac or iOS OSS developer is still someone with a Mac and many hours of time to spend on non-paying work. So we're probably talking about students and the temporarily unemployed in first-world countries, not so much low-income counties.

Seems like a full developer account should be free for the asking for students, IMO.

Re: Apple Accidentally Approved Malware to Run on macOS

#39
post #26
post #6

It's astonishing that the developer community is fine with requiring open source projects to pay $99/yr for notarization to run on macOS. Malware authors will happily pay the developer account fees, as seen here, while open source projects are seriously hindered. It should be possible to verify developers and distribute open source apps without a cost on macOS.

$99/year is such a small amount relative to the costs of software development that it's hard to worry about. Meanwhile, there is good value. (The developer resources Apple provides are not free.) You can argue that Apple should provide developer resources at no cost, but that just means someone else is paying for them or you will pay them in some other way... or do without. I think at this point in the tech boom we c…

[deleted]

Re: Apple Accidentally Approved Malware to Run on macOS

#40
post #26
post #6

It's astonishing that the developer community is fine with requiring open source projects to pay $99/yr for notarization to run on macOS. Malware authors will happily pay the developer account fees, as seen here, while open source projects are seriously hindered. It should be possible to verify developers and distribute open source apps without a cost on macOS.

$99/year is such a small amount relative to the costs of software development that it's hard to worry about. Meanwhile, there is good value. (The developer resources Apple provides are not free.) You can argue that Apple should provide developer resources at no cost, but that just means someone else is paying for them or you will pay them in some other way... or do without. I think at this point in the tech boom we c…

The world is bigger than the US, Im from a fairly wealthy part of the world on average - - eastern Europe but I can't afford it or buy their products just so I can use their tooling. Probably people living in poorer parts of the world are laughing even harder.
Post reply on HN