Live data from Hacker News

Apple Accidentally Approved Malware to Run on macOS

wired.com

91–100 of 134 posts

Re: Apple Accidentally Approved Malware to Run on macOS

#91
post #6

It's astonishing that the developer community is fine with requiring open source projects to pay $99/yr for notarization to run on macOS. Malware authors will happily pay the developer account fees, as seen here, while open source projects are seriously hindered. It should be possible to verify developers and distribute open source apps without a cost on macOS.

[deleted]

Re: Apple Accidentally Approved Malware to Run on macOS

#92
post #65

Earlier quoted context omitted.

> So then why do I have to pay them if I'm using emacs and gcc and C++? You may still be using developer resources like documentation. But yeah, a flat fee for a wide variety of services risks edge cases where someone using only minimal resources gets a poor deal. Of course, an alternative is a nickel-and-diming pay-as-you-go micro-transaction scheme, which your main users will hate. Also, strictly speaking, you don'…

> You may still be using developer resources like documentation. That's not any different. If I write a POSIX-compliant program then it should run on macOS without having used any of Apple's documentation. And if they charged for documentation (which is dumb) it would create a market for third party macOS documentation that I could use instead. > But yeah, a flat fee for a wide variety of services risks edge cases wh…

If you write a program strictly to POSIX, your program doesn't have a GUI and is run from the terminal, which already bypasses Gatekeeper by default.

Re: Apple Accidentally Approved Malware to Run on macOS

#93
post #83
post #56

Earlier quoted context omitted.

You're taking the current Apple developer program as an eternal truth, when in fact it has changed significantly over time. Before the App Store, you could develop for the Mac completely free. There was a developer program, which was much more expensive than $99 per year, but it was mainly concerned with WWDC and pre-release builds. There was even a hardware discount for developers, which was very popular, and effect…

> You're taking the current Apple developer program as an eternal truth, when in fact it has changed significantly over time. Well, I've been developing Mac software for 25 years, so I've seen the developer program changes. Generally, it's gotten a lot cheaper and a lot better over time. (Except there's never been anything like the old Inside Macintosh books, and I guess there never will be.) I guess that's why $99/y…

> At first, Xcode itself wasn't exactly free, because it was bundled with the OS updates, which cost a decent amount back then.

Xcode and Mac OS X were included on disc with Mac hardware. This is how I became a developer.

When Mac OS X was released, that was the period when Apple truly embraced open source and Unix. Since iPhone, however, there's been a lot of backtracking in that area, which I find very unfortunate.

In general, macOS is becoming more and more like iOS. Consequently, it is becoming more hostile to openness.

Re: Apple Accidentally Approved Malware to Run on macOS

#95
post #61

Earlier quoted context omitted.

I think you underestimate how many power users use macOS. Most of their privacy and security marketing isn't really targeted at normal people. The avg. person doesn't really care that much.

It’s pretty impressive that Ubuntu and Arch (Power User-only experiences in my mind) are considered an alternative to macOS by anyone at all. It shows the Linux desktop is actually delivering something very valuable despite the numbers. Although that the numbers don’t tell the whole story isn’t really saying much. What if it turned out that ease of use and OS-wide app consistency was the easy part all along? That bui…

The thing to remember is that, under all the chrome and Apple styling, macOS is rooted in BSD. So the power users who enjoy the *nix-y bits of macOS and are looking for a replacement will look for something that gives them more of that.

Re: Apple Accidentally Approved Malware to Run on macOS

#96
post #67

Earlier quoted context omitted.

I think open source licenses are ripe for an update with the following clauses to deal with FAANG companies: This software shall not be used on platforms that hinder users in their free choice of software. This software shall not be used to create or in conjunction with adware, spyware, or other malicious software. (Perhaps after a lawyer has reworded it properly so people can't pretend to not understand what is mean…

I appreciate your eagerness and positivity but I fear it's not a solution. After all, who defines 'hinder', 'adware' or 'spyware'? (I'm reminded of the phrase "one man's terrorist is another man's freedom fighter".) Any company willing to make adware/spyware probably isn't above ignoring a plea in a license agreement. There are laws against burglary, assault, embezzlement, murder, too, and even with very harsh penalt…

> who defines 'hinder', 'adware' or 'spyware'? The new license should define this.

> A $1B limit? no problem - "we'll just send this over to our little 500M subsidiary."

The new license can acknowledge this too

Re: Apple Accidentally Approved Malware to Run on macOS

#97

Earlier quoted context omitted.

This is simply not true. Many OS developers are working in lower income countries. Or aren't even employed yet because they are in school. Your assessment only works for working developers in high income countries. And even then requiring 99 dollars is insane.

Insane is a bit of a strong word — it seems like a reasonable way to ensure that the world isn't flooded with incredibly low-effort apps. I know, I know — the world is already full of those, but I imagine it would be a lot worse if people didn't have to put down $99. Also, the $99 is the blanket cost to be an Apple Developer, including access to the App Store, technical support, etc. and it seems like a reasonable fe…

Code signing in general is a terrible industry. Malware authors gladly pay those fees, even for EV code signing certificates, because scamming has high margins.

$99 almost seems reasonable until you consider Apple bakes in a mechanism for curation (they own the signing keys, right?).

IMHO code signing should be separate from curation systems and should focus on tying code back to a specific individual, not a company. It’s a huge pain to change your identity vs starting a new company to distribute malware.

The current systems are built to wrest control of everything. They don’t care about quality or accountability.

Re: Apple Accidentally Approved Malware to Run on macOS

#98
post #69

Earlier quoted context omitted.

> you can publish macOS software without paying $99 year. Can you point to straightforward apple instructions for doing so? I publish an open source project used in classrooms, mostly used by my own students but also others. Despite strong and principled objections, which I hung on to for years, I have simply given up and now pay the fee. I'd love to not have apple be the gatekeeper. But they are. Every release, ever…

> Can you point to straightforward apple instructions for doing so? Take a look at how other apps do it, such as: • MacDown https://macdown.uranusjr.com (also on GitHub) Download → Right/Control-click → Open → Confirm There are several such apps and open-source tools that are not notarized, some quite popular. Some of them provide those instructions next to their download links.

See the below discussion on why this is not a realistic or user-friendly option.

https://news.ycombinator.com/item?id=24217116

Re: Apple Accidentally Approved Malware to Run on macOS

#99
post #61

Earlier quoted context omitted.

I think you underestimate how many power users use macOS. Most of their privacy and security marketing isn't really targeted at normal people. The avg. person doesn't really care that much.

You are overestimating how many power users use Apple products. If you are technology literate, you've seen the evils of Apple for decades. A power user fixes their own problem, not waits years for Apple to fix it.

This is clearly anecdotal, but nearly every dev/engineer from every company I have ever worked for has had an MBP as their work laptop.

Re: Apple Accidentally Approved Malware to Run on macOS

#100
post #61

Earlier quoted context omitted.

I think you underestimate how many power users use macOS. Most of their privacy and security marketing isn't really targeted at normal people. The avg. person doesn't really care that much.

It’s pretty impressive that Ubuntu and Arch (Power User-only experiences in my mind) are considered an alternative to macOS by anyone at all. It shows the Linux desktop is actually delivering something very valuable despite the numbers. Although that the numbers don’t tell the whole story isn’t really saying much. What if it turned out that ease of use and OS-wide app consistency was the easy part all along? That bui…

For what it's worth, look-and-feel is arguably more consistent on an OSS desktop than the average commercial workstation, these days. The vast majority of free apps and DEs are built on either GTK or QT, which have a broadly similar feel and can be themed to look identical. Meanwhile, closed/commerical apps are a mess of in-house toolkits and embedded web interfaces, and Windows even has several inconsistent styles in the base install.
Post reply on HN