Earlier quoted context omitted.
See the below discussion on why this is not a realistic or user-friendly option. https://news.ycombinator.com/item?id=24217116
Exactly which part of “Download → Right-click → Open → Confirm” is user-unfriendly? Those steps are literally all it takes. It’s barely 40 keystrokes to list them. As a user and the resident tech support for people young and old, I am glad that there’s such a barrier against the execution of arbitrary software and it’s easily skippable if one so explicitly chooses. In any case, how is it any worse than the Windows na…
Apple Accidentally Approved Malware to Run on macOS
121–130 of 134 posts
Re: Apple Accidentally Approved Malware to Run on macOS
#122Earlier quoted context omitted.
When a Justice of the Peace notarises a piece of documentation, they are not vouching for authenticity they are only voicing for certain claims made: the document was presented on a certain date, and/or that this copy is an accurate facsimile of the provided original. Notarisation for macOS similarly only means, “the developer presented us with their application and their certificate of authenticity and we signed it…
> There’s no attempt by Apple to claim that the application is safe or does what it says on the tin. So that isn't part of the notarization process. It still was approved by Apple and thus was notarised. > It’s like claiming that the outcome of toasting a sandwich is approval or rejection, no the outcome of toasting a sandwich is you have a sandwich that is toasted, aka “toasted sandwich.” That's disingenuous. If I s…
Here's a grossly simplified version of what happens with Apple's notary service:
1. Developer writes program 2. Developer signs program to provide evidence to end-user that program has not been tampered with 3. Developer submits program and signature to Apple's notarising service 4. Apple signs program and developer's signature to tell macOS that this developer signature for this program has been seen by a trusted third party (the notary, in this case Apple) — the notary signature basically states that at this date and time the developer presented Apple with the program and the developer signature and that the developer signature is the correct one for that program 5. End user downloads program which includes signature by developer and signature by Apple 6. macOS compares program signature to developer signature 7. macOS compares checks that notary signature matches the program and developer signature 8. macOS now trusts that this program is what was published by the developer, and allows it to run
At no point in this sequence has Apple provided any testimony or recommendation about this program. Notarising is only about ensuring that what you are trying to run is what the developer wrote for you.
"Approval" on the other hand implies that Apple might "disapprove" something, which is not something that happens in the notarising service. A notarising request might be rejected if the applications contains known malware (because the presence of such is an exceptional circumstance which the developer needs to take urgent action to correct, not because Apple doesn't want to sign malware). It's like a Justice of the Peace recommending that you see a doctor if you turn up to ask for a witness to your signature while bleeding profusely from your ear. The JP is not refusing to witness your signature, they are simply suggesting that you have more urgent matters to attend to right now.
Re: Apple Accidentally Approved Malware to Run on macOS
#123Earlier quoted context omitted.
> There’s no attempt by Apple to claim that the application is safe or does what it says on the tin. So that isn't part of the notarization process. It still was approved by Apple and thus was notarised. > It’s like claiming that the outcome of toasting a sandwich is approval or rejection, no the outcome of toasting a sandwich is you have a sandwich that is toasted, aka “toasted sandwich.” That's disingenuous. If I s…
Notarising is only the act of a trusted third party verifying that the signature on a document is valid. Here's a grossly simplified version of what happens with Apple's notary service: 1. Developer writes program 2. Developer signs program to provide evidence to end-user that program has not been tampered with 3. Developer submits program and signature to Apple's notarising service 4. Apple signs program and develop…
Nobody should be listening to this long-winded fable spun out of yarn.
I mean, I could go through that whole thing and refute it line-by-line, but I'm just astonished that you think you get to invent all this stuff out of thin air. It's totally wrong, and you don't even have first-hand knowledge of it.
Re: Apple Accidentally Approved Malware to Run on macOS
#124Earlier quoted context omitted.
Notarising is only the act of a trusted third party verifying that the signature on a document is valid. Here's a grossly simplified version of what happens with Apple's notary service: 1. Developer writes program 2. Developer signs program to provide evidence to end-user that program has not been tampered with 3. Developer submits program and signature to Apple's notarising service 4. Apple signs program and develop…
You're just making up stuff. You have no idea what you're talking about. You're clearly not a Mac developer. Nobody should be listening to this long-winded fable spun out of yarn. I mean, I could go through that whole thing and refute it line-by-line, but I'm just astonished that you think you get to invent all this stuff out of thin air. It's totally wrong, and you don't even have first-hand knowledge of it.
Re: Apple Accidentally Approved Malware to Run on macOS
#125Earlier quoted context omitted.
Notarising is only the act of a trusted third party verifying that the signature on a document is valid. Here's a grossly simplified version of what happens with Apple's notary service: 1. Developer writes program 2. Developer signs program to provide evidence to end-user that program has not been tampered with 3. Developer submits program and signature to Apple's notarising service 4. Apple signs program and develop…
You're just making up stuff. You have no idea what you're talking about. You're clearly not a Mac developer. Nobody should be listening to this long-winded fable spun out of yarn. I mean, I could go through that whole thing and refute it line-by-line, but I'm just astonished that you think you get to invent all this stuff out of thin air. It's totally wrong, and you don't even have first-hand knowledge of it.
What are you talking about? That's basically the process.
>I mean, I could go through that whole thing and refute it line-by-line
But you'd only have some inconsequential pedantic details to change.
Re: Apple Accidentally Approved Malware to Run on macOS
#126Earlier quoted context omitted.
You're just making up stuff. You have no idea what you're talking about. You're clearly not a Mac developer. Nobody should be listening to this long-winded fable spun out of yarn. I mean, I could go through that whole thing and refute it line-by-line, but I'm just astonished that you think you get to invent all this stuff out of thin air. It's totally wrong, and you don't even have first-hand knowledge of it.
You don't need to refute anything if you can describe the process yourself.
So you're admitting that you don't know what it is?
Are you or are you not a Mac developer who notarizes and distributes Mac software?
Re: Apple Accidentally Approved Malware to Run on macOS
#127Earlier quoted context omitted.
You're just making up stuff. You have no idea what you're talking about. You're clearly not a Mac developer. Nobody should be listening to this long-winded fable spun out of yarn. I mean, I could go through that whole thing and refute it line-by-line, but I'm just astonished that you think you get to invent all this stuff out of thin air. It's totally wrong, and you don't even have first-hand knowledge of it.
> You're just making up stuff. You have no idea what you're talking about. You're clearly not a Mac developer. What are you talking about? That's basically the process. > I mean, I could go through that whole thing and refute it line-by-line But you'd only have some inconsequential pedantic details to change.
How do you know?
> But you'd only have some inconsequential pedantic details to change.
No, the writer completely misunderstands the entire purpose of the process, and consequently just makes up details about what the writer thinks ought to be happening. It sounds like more of a hypothetical than actual knowledge.
Re: Apple Accidentally Approved Malware to Run on macOS
#128Earlier quoted context omitted.
You don't need to refute anything if you can describe the process yourself.
> You don't need to refute anything if you can describe the process yourself. So you're admitting that you don't know what it is? Are you or are you not a Mac developer who notarizes and distributes Mac software?
Re: Apple Accidentally Approved Malware to Run on macOS
#129Earlier quoted context omitted.
I'm the other way, I've never seen a Macbook in an (Engineering) office setting, four fortune 500, two small businesses. I've seen them at University and some non STEM students homes. That said, I see iPhones at work, but probably because they are not critical to doing anything other than email.
I worked at SAP for seven years in their cloud business and about half the engineering staff had MBP laptops. Some engineering teams used only Macs. Operations was the same way. Engineering computer usage in India was mostly Windows, China was ~50% Macs, US/Canada was ~80% Macs, and Europe was ~50% Macs.
Re: Apple Accidentally Approved Malware to Run on macOS
#130Earlier quoted context omitted.
Is this a real thing? Like there are people that don't VM/SSH into Linux but use shell? What demographic is this? College kids and Apple employees? It seems like minor benefit in an otherwise atrocious platform.
Over the years I haven't found very many unix tools I couldn't install with homebrew. I'm also a big fan of the move from Bash to ZSH. Why start up a VM or SSH into another machine if I can just use Terminal or Iterm.
What commands are you sending your macbook outside installations?
It's not like you are running a server, you still need to SSH into the server to do anything.