Live data from Hacker News

Apple Accidentally Approved Malware to Run on macOS

wired.com

81–90 of 134 posts

Re: Apple Accidentally Approved Malware to Run on macOS

#81
post #55

Earlier quoted context omitted.

> $99/year is such a small amount relative to the costs of software development that it's hard to worry about Huh? Some Open Source/Free software have a $0 budget.

Software development typically requires at least a computer (a Mac for MacOS and iOS development), internet service, and electricity. Dwarfing those, though, is the significant time software development takes. For OSS, the time is donated, whether by individuals or by corporate sponsors who sometimes dedicate employee hours to projects of particular value to them. But in either case the donator has to be in a positio…

> But in either case the donator has to be in a position to afford it, which typically means significant income from other means.

Even if someone has the time and resources to contribute to OSS, it does not automatically follow that they should be willing to spend said time and resources on notarization (of all things).

Put another way, not every purchase is worthwhile just because you have a million dollars in the bank.

Re: Apple Accidentally Approved Malware to Run on macOS

#82

Earlier quoted context omitted.

> It's astonishing that the developer community is fine with requiring open source projects to pay $99/yr for notarization to run on macOS. There is NO "requirement" for notarization. This FUD keeps getting perpetuated, but you can publish macOS software without paying $99 year. > It should be possible to verify developers and distribute open source apps without a cost on macOS. The cost is convincing your users to t…

From what I've read, Apple will require notarization on Apple silicon. If that holds for both desktop apps and cli software, it would be neigh impossible to use a mac for development. So I imagine/hope they will have a way of handling OSS better.

That's not true. They're requiring all executables to be signed on Apple Silicon systems, but that's as an ad hoc signature added by the linker at link time. There's no additional cost or overhead on AS.

Re: Apple Accidentally Approved Malware to Run on macOS

#83
post #56
post #44

Earlier quoted context omitted.

That doesn't change the fact that developer resources cost money that has to be paid for somehow. If Apple doesn't charge developers, they could, e.g., pay for it through more margin on device sales, which means Apple customers are paying for it. That sounds nice for developers, but that's going to cause the developer resources to lose developer focus. Developer resources will be treated as marketing expenses and the…

You're taking the current Apple developer program as an eternal truth, when in fact it has changed significantly over time. Before the App Store, you could develop for the Mac completely free. There was a developer program, which was much more expensive than $99 per year, but it was mainly concerned with WWDC and pre-release builds. There was even a hardware discount for developers, which was very popular, and effect…

> You're taking the current Apple developer program as an eternal truth, when in fact it has changed significantly over time.

Well, I've been developing Mac software for 25 years, so I've seen the developer program changes. Generally, it's gotten a lot cheaper and a lot better over time. (Except there's never been anything like the old Inside Macintosh books, and I guess there never will be.) I guess that's why $99/year doesn't bother me. Historically speaking, it's a great deal.

I'm sure there are more changes to come, but none of us knows what that will be, so there's not much to discuss.

> Before the App Store, you could develop for the Mac completely free.

I haven't kept track of a timeline on this, so I'm sure you're right, but you're talking about a transient state. Before Xcode you had to pay a lot for Apple's developer tools (which I can't remember the name of), or pay a lot for the superior (or so I believed at the time) CodeWarrior. At first, Xcode itself wasn't exactly free, because it was bundled with the OS updates, which cost a decent amount back then.

I guess at various times there has been more or less you could do at the free tier, but it has seemed to me that you could only rarely do a decent job of releasing and supporting mac apps without paying for something.

Re: Apple Accidentally Approved Malware to Run on macOS

#84
post #42

Earlier quoted context omitted.

Insane is a bit of a strong word — it seems like a reasonable way to ensure that the world isn't flooded with incredibly low-effort apps. I know, I know — the world is already full of those, but I imagine it would be a lot worse if people didn't have to put down $99. Also, the $99 is the blanket cost to be an Apple Developer, including access to the App Store, technical support, etc. and it seems like a reasonable fe…

The app store is full of low effort apps, and the 99$ entry fee really doesn't matter. I think it still is a "Apple greedy". If I were to operate a personal fleet of devices, I wouldn't be able to build my own software once and run it on the fleet. I'd have to build it everywhere. If Microsoft were to do the same thing, people certainly wouldn't be trying to rationalize it as anything else but the money grab that it…

> The app store is full of low effort apps

If you notice, I actually mentioned this in my comment. I think it would be much worse. $99 isn't enough to stop everyone from making crappy apps, but it's definitely enough to stop a lot. Think of every low-effort app made by some 12 year old who discovered Xcode for the first time.

> If I were to operate a personal fleet of devices, I wouldn't be able to build my own software once and run it on the fleet. I'd have to build it everywhere.

I don't understand what this means. If I understand you correctly, then no, you can definitely deploy internal apps to Apple devices without putting it on the App Store.

Re: Apple Accidentally Approved Malware to Run on macOS

#85
post #47

Earlier quoted context omitted.

It's automated approval...

... which is neither approval nor accidental

Maybe "erroneously" is a better word than accidentally. That's the word Apple used when apologizing to Charlie Munroe for their automated systems revoking his Apple Developer ID and remotely disabling his published Mac apps:

"We determined that your app Downie 4 was erroneously identified as malicious due to invalid logic in our malware detection system. This triggered the revocation of your certificate under Section 5.4 of the Developer Program License Agreement."

https://blog.charliemonroe.net/a-day-without-business/

Re: Apple Accidentally Approved Malware to Run on macOS

#86
post #42

Earlier quoted context omitted.

The app store is full of low effort apps, and the 99$ entry fee really doesn't matter. I think it still is a "Apple greedy". If I were to operate a personal fleet of devices, I wouldn't be able to build my own software once and run it on the fleet. I'd have to build it everywhere. If Microsoft were to do the same thing, people certainly wouldn't be trying to rationalize it as anything else but the money grab that it…

> The app store is full of low effort apps If you notice, I actually mentioned this in my comment. I think it would be much worse. $99 isn't enough to stop everyone from making crappy apps, but it's definitely enough to stop a lot. Think of every low-effort app made by some 12 year old who discovered Xcode for the first time. > If I were to operate a personal fleet of devices, I wouldn't be able to build my own softw…

If I can deploy internal apps to Apple devices without getting them notarized, then open source devs can distribute their apps to their users without them being notarized too, no? What is the measurable difference here? Obviously, open source apps still work today, but they won't soon. macOS will become a lot more like iOS soon.

Re: Apple Accidentally Approved Malware to Run on macOS

#87
post #67
post #6

It's astonishing that the developer community is fine with requiring open source projects to pay $99/yr for notarization to run on macOS. Malware authors will happily pay the developer account fees, as seen here, while open source projects are seriously hindered. It should be possible to verify developers and distribute open source apps without a cost on macOS.

I think open source licenses are ripe for an update with the following clauses to deal with FAANG companies: This software shall not be used on platforms that hinder users in their free choice of software. This software shall not be used to create or in conjunction with adware, spyware, or other malicious software. (Perhaps after a lawyer has reworded it properly so people can't pretend to not understand what is mean…

“This software shall not be used on platforms that hinder users in their free choice of software”

That’s the GPL, isn’t it? Version 3 was specifically created to close loopholes w.r.t. to that (https://en.wikipedia.org/wiki/Tivoization: “Tivoization is the creation of a system that incorporates software under the terms of a copyleft software license (like the GPL), but uses hardware restrictions or digital rights management to prevent users from running modified versions of the software on that hardware“)

Re: Apple Accidentally Approved Malware to Run on macOS

#88
post #22
post #11

Earlier quoted context omitted.

What makes you thing that open source developers are fine with that? What are their other choices? Apple doesn’t care.

The choice is don't build for MacOS. In the long run Apple won't be happy with that and maybe they'll waive the fee.

I haven't been building Apps on their platform. Apple advertises to me daily.

Not sure if related.

Re: Apple Accidentally Approved Malware to Run on macOS

#89
post #65

Earlier quoted context omitted.

> So then why do I have to pay them if I'm using emacs and gcc and C++? You may still be using developer resources like documentation. But yeah, a flat fee for a wide variety of services risks edge cases where someone using only minimal resources gets a poor deal. Of course, an alternative is a nickel-and-diming pay-as-you-go micro-transaction scheme, which your main users will hate. Also, strictly speaking, you don'…

> You may still be using developer resources like documentation. That's not any different. If I write a POSIX-compliant program then it should run on macOS without having used any of Apple's documentation. And if they charged for documentation (which is dumb) it would create a market for third party macOS documentation that I could use instead. > But yeah, a flat fee for a wide variety of services risks edge cases wh…

> I don't want to use anything they make, I just want to have access to my customers who use macOS.

These are conflicting statements. You will have a very difficult time supporting your Apple-using customers without using any Apple stuff yourself.

Re: Apple Accidentally Approved Malware to Run on macOS

#90
post #61

Earlier quoted context omitted.

> In the long run Apple won't be happy with that and maybe they'll waive the fee. I think you greatly overestimate how much Apple cares about this.

I think you underestimate how many power users use macOS. Most of their privacy and security marketing isn't really targeted at normal people. The avg. person doesn't really care that much.

You are overestimating how many power users use Apple products.

If you are technology literate, you've seen the evils of Apple for decades.

A power user fixes their own problem, not waits years for Apple to fix it.

Post reply on HN