Live data from Hacker News

Apple Accidentally Approved Malware to Run on macOS

wired.com

71–80 of 134 posts

Re: Apple Accidentally Approved Malware to Run on macOS

#71

Earlier quoted context omitted.

This is simply not true. Many OS developers are working in lower income countries. Or aren't even employed yet because they are in school. Your assessment only works for working developers in high income countries. And even then requiring 99 dollars is insane.

Insane is a bit of a strong word — it seems like a reasonable way to ensure that the world isn't flooded with incredibly low-effort apps. I know, I know — the world is already full of those, but I imagine it would be a lot worse if people didn't have to put down $99. Also, the $99 is the blanket cost to be an Apple Developer, including access to the App Store, technical support, etc. and it seems like a reasonable fe…

> [the $99 fee] seems like a reasonable way to ensure that the world isn't flooded with incredibly low-effort apps

Lol. In my experience a fee is a way to _ensure_ it is filled with incredibly low-effort apps (which tend to be the most profitable).

Re: Apple Accidentally Approved Malware to Run on macOS

#72
post #61

Earlier quoted context omitted.

I think you underestimate how many power users use macOS. Most of their privacy and security marketing isn't really targeted at normal people. The avg. person doesn't really care that much.

It’s pretty impressive that Ubuntu and Arch (Power User-only experiences in my mind) are considered an alternative to macOS by anyone at all. It shows the Linux desktop is actually delivering something very valuable despite the numbers. Although that the numbers don’t tell the whole story isn’t really saying much. What if it turned out that ease of use and OS-wide app consistency was the easy part all along? That bui…

How reliable is the security vetting in the Ubuntu store?

Re: Apple Accidentally Approved Malware to Run on macOS

#73
post #69

Earlier quoted context omitted.

> It's astonishing that the developer community is fine with requiring open source projects to pay $99/yr for notarization to run on macOS. There is NO "requirement" for notarization. This FUD keeps getting perpetuated, but you can publish macOS software without paying $99 year. > It should be possible to verify developers and distribute open source apps without a cost on macOS. The cost is convincing your users to t…

> you can publish macOS software without paying $99 year. Can you point to straightforward apple instructions for doing so? I publish an open source project used in classrooms, mostly used by my own students but also others. Despite strong and principled objections, which I hung on to for years, I have simply given up and now pay the fee. I'd love to not have apple be the gatekeeper. But they are. Every release, ever…

> Can you point to straightforward apple instructions for doing so?

Take a look at how other apps do it, such as:

• MacDown https://macdown.uranusjr.com (also on GitHub)

Download → Right/Control-click → Open → Confirm

There are several such apps and open-source tools that are not notarized, some quite popular. Some of them provide those instructions next to their download links.

Re: Apple Accidentally Approved Malware to Run on macOS

#74
post #6

It's astonishing that the developer community is fine with requiring open source projects to pay $99/yr for notarization to run on macOS. Malware authors will happily pay the developer account fees, as seen here, while open source projects are seriously hindered. It should be possible to verify developers and distribute open source apps without a cost on macOS.

> It's astonishing that the developer community is fine with requiring open source projects to pay $99/yr for notarization to run on macOS. There is NO "requirement" for notarization. This FUD keeps getting perpetuated, but you can publish macOS software without paying $99 year. > It should be possible to verify developers and distribute open source apps without a cost on macOS. The cost is convincing your users to t…

From what I've read, Apple will require notarization on Apple silicon. If that holds for both desktop apps and cli software, it would be neigh impossible to use a mac for development. So I imagine/hope they will have a way of handling OSS better.

Re: Apple Accidentally Approved Malware to Run on macOS

#75
post #67
post #6

It's astonishing that the developer community is fine with requiring open source projects to pay $99/yr for notarization to run on macOS. Malware authors will happily pay the developer account fees, as seen here, while open source projects are seriously hindered. It should be possible to verify developers and distribute open source apps without a cost on macOS.

I think open source licenses are ripe for an update with the following clauses to deal with FAANG companies: This software shall not be used on platforms that hinder users in their free choice of software. This software shall not be used to create or in conjunction with adware, spyware, or other malicious software. (Perhaps after a lawyer has reworded it properly so people can't pretend to not understand what is mean…

If malware is going to ignore a variety of other things, do you honestly think they'd abide any licensing? I doubt they really care and will happily break that agreement and they're fine doing so until someone can take them to court to stop it (who's going to pay that fee? and I doubt finding the author of such malware is going to be particularly easy, never mind their country of operation may not even make any of this straight forward at all)

Re: Apple Accidentally Approved Malware to Run on macOS

#76
post #65

Earlier quoted context omitted.

> Of course, Apple spends huge amounts of money on developer infrastructure (Xcode, LLVM, and Swift, for example). So then why do I have to pay them if I'm using emacs and gcc and C++? > Just because you get a given piece of open-source software for free does not mean that its development was done by volunteers in their free time. Yet, in many cases, that's exactly what happened. And even when it isn't, if it's distr…

> So then why do I have to pay them if I'm using emacs and gcc and C++? You may still be using developer resources like documentation. But yeah, a flat fee for a wide variety of services risks edge cases where someone using only minimal resources gets a poor deal. Of course, an alternative is a nickel-and-diming pay-as-you-go micro-transaction scheme, which your main users will hate. Also, strictly speaking, you don'…

> You may still be using developer resources like documentation.

That's not any different. If I write a POSIX-compliant program then it should run on macOS without having used any of Apple's documentation. And if they charged for documentation (which is dumb) it would create a market for third party macOS documentation that I could use instead.

> But yeah, a flat fee for a wide variety of services risks edge cases where someone using only minimal resources gets a poor deal. Of course, an alternative is a nickel-and-diming pay-as-you-go micro-transaction scheme, which your main users will hate.

Offering a flat fee for everything is not inconsistent with offering individual things a la carte. They could offer both. But the bigger point is that it should be possible to produce and distribute software without having any business relationship with Apple whatsoever. I don't want to use anything they make, I just want to have access to my customers who use macOS.

> Also, strictly speaking, you don't have to pay them. Vote with your dollars and platform support as a developer. If enough people do, Apple may reevaluate

That doesn't work at this level of power imbalance. Your software would have to be important enough to get your customers to switch to a different platform, and not have any viable competitors who remain on macOS even if it means higher profits due to the reduced competition. In other words, you would have to be a monopoly yourself in order to have any leverage.

Re: Apple Accidentally Approved Malware to Run on macOS

#77
post #67
post #6

It's astonishing that the developer community is fine with requiring open source projects to pay $99/yr for notarization to run on macOS. Malware authors will happily pay the developer account fees, as seen here, while open source projects are seriously hindered. It should be possible to verify developers and distribute open source apps without a cost on macOS.

I think open source licenses are ripe for an update with the following clauses to deal with FAANG companies: This software shall not be used on platforms that hinder users in their free choice of software. This software shall not be used to create or in conjunction with adware, spyware, or other malicious software. (Perhaps after a lawyer has reworded it properly so people can't pretend to not understand what is mean…

> This software is free for personal use, and for commercial use by companies with an annual revenue less than $1B.

I've been advocating for something similar:

> This software is free for any entity that does not contain material stakeholders (bond holders, debt holders, etc) that are billionaires. A yearly licence fee of $1m waives this requirement.

Something like that. I'm sick of wealth centralization. If a startup wants to use the software, great! Once Peter Thiel invests though it's $1m a year. My core beef with billionaires is that they do not pay their fair share in taxes. The push all their money into shell companies or park it overseas and we end up with doctors that actually save peoples lives paying double or triple the tax rate that the ultra wealthy pay.

Re: Apple Accidentally Approved Malware to Run on macOS

#78
post #67
post #6

It's astonishing that the developer community is fine with requiring open source projects to pay $99/yr for notarization to run on macOS. Malware authors will happily pay the developer account fees, as seen here, while open source projects are seriously hindered. It should be possible to verify developers and distribute open source apps without a cost on macOS.

I think open source licenses are ripe for an update with the following clauses to deal with FAANG companies: This software shall not be used on platforms that hinder users in their free choice of software. This software shall not be used to create or in conjunction with adware, spyware, or other malicious software. (Perhaps after a lawyer has reworded it properly so people can't pretend to not understand what is mean…

These would be "field of use" restrictions. Licenses with these kinds of restrictions are normally not considered open source (see items 5 and 6 of both the DFSG and the OSD).

Re: Apple Accidentally Approved Malware to Run on macOS

#79
post #75
post #67

Earlier quoted context omitted.

I think open source licenses are ripe for an update with the following clauses to deal with FAANG companies: This software shall not be used on platforms that hinder users in their free choice of software. This software shall not be used to create or in conjunction with adware, spyware, or other malicious software. (Perhaps after a lawyer has reworded it properly so people can't pretend to not understand what is mean…

If malware is going to ignore a variety of other things, do you honestly think they'd abide any licensing? I doubt they really care and will happily break that agreement and they're fine doing so until someone can take them to court to stop it (who's going to pay that fee? and I doubt finding the author of such malware is going to be particularly easy, never mind their country of operation may not even make any of th…

Companies do care, see the JSLint case:

https://news.ycombinator.com/item?id=5138866

Re: Apple Accidentally Approved Malware to Run on macOS

#80
post #67
post #6

It's astonishing that the developer community is fine with requiring open source projects to pay $99/yr for notarization to run on macOS. Malware authors will happily pay the developer account fees, as seen here, while open source projects are seriously hindered. It should be possible to verify developers and distribute open source apps without a cost on macOS.

I think open source licenses are ripe for an update with the following clauses to deal with FAANG companies: This software shall not be used on platforms that hinder users in their free choice of software. This software shall not be used to create or in conjunction with adware, spyware, or other malicious software. (Perhaps after a lawyer has reworded it properly so people can't pretend to not understand what is mean…

I appreciate your eagerness and positivity but I fear it's not a solution. After all, who defines 'hinder', 'adware' or 'spyware'? (I'm reminded of the phrase "one man's terrorist is another man's freedom fighter".) Any company willing to make adware/spyware probably isn't above ignoring a plea in a license agreement. There are laws against burglary, assault, embezzlement, murder, too, and even with very harsh penalties (e.g. death penalty) they are not always sufficient to deter all criminal behavior.

A $1B limit? no problem - "we'll just send this over to our little 500M subsidiary."

the root problem is the consumer doesn't care and there is a cultural lack of care and trust and humanity. I don't know of any solution to this but the problem runs extremely deep. In fact, there may be no cure, as these problems are noted as the cardinal sins the Christian bible documented and Dante' famously illustrated : Lust, Gluttony, Greed, Sloth, Wrath, Envy, Pride. Solve that and the rest comes easy.

Post reply on HN