Live data from Hacker News

Apple’s macOS Ventura – New Security Changes

sentinelone.com

171–180 of 193 posts

Re: Apple’s macOS Ventura – New Security Changes

#171
post #17

Earlier quoted context omitted.

I can picture a big cat in my mind. That helped to peg OS X releases and enabled me to mentally distinguish and order them. I can't picture "Monterey" or "Ventura" or any other macOS names, they have no meaning to me.

Ventura has a meaning to me.... Ace Ventura, a cartoon from my childhood about a egotistical questionably competent detective. I'm not sure that's the image Apple wants to give off though...

Places in CA have a lot of references in music and movies [1]. Hollywood loves to pimp where their people are from.

[1] https://en.wikipedia.org/wiki/Ventura_Boulevard#References

Re: Apple’s macOS Ventura – New Security Changes

#172
post #2

> However, the Gatekeeper check here is overridable by users. This is presented as a flaw, but I'm not sure they are thinking through the alternatives. It's hard to give too much credence to security experts who are't thinking holistically. Perhaps there is a flaw, but I'm curious to know what it is.

Security folks tend to have a very myopic view on things. Ever wondered why your computer got less and less useable? Security people pushing their agenda.

I've always learned:

  security = 1/convenience

Re: Apple’s macOS Ventura – New Security Changes

#173
post #144

At least two other security changes: - userspace filesystems: the nail on the coffin for kernel extensions. Now we won't need to run in "reduced security" to use FUSE and that was the last kernel extension that remained popular. Probably kexts will be deprecated shortly - rapid security response - it seems also to include changes in Xprotect and mrt

> the nail on the coffin for kernel extensions The OpenZFS implementation on macOS also requires kernel extensions, and I don't suppose it can easily be ported to FUSE or that that would have desirable performance characteristics. Special kernel extensions are also required to get some basic functionality working on macOS these days, like disabling pointer acceleration.

Too bad for them, Apple has already stated multiple times that the long term roadmap is that all third party stuff will only be available as userspace drivers.

The plan being, each kext has one year timeframe to migrate to the new userspace API after its introduction, and the year thereafter the kernel API gets dropped from the new OS release.

Re: Apple’s macOS Ventura – New Security Changes

#174
post #84

> Gatekeeper’s role is to ensure that when users execute some code, that code meets the local system policy. The policy includes checks such as whether the code is validly signed and whether it has been tampered with in certain ways. Weasel-word alert. I never thought I’d see the day when technologists would applaud the gradual death of general-purpose computing, but here we are. A decade from now Apple probably won’…

I thought all UNIX heads longed for the days we used to telnet or startx into the UNIX development server, everyone had their $HOME configured with noexec, and the tooling configured by the BOFH team.

Re: Apple’s macOS Ventura – New Security Changes

#175

Earlier quoted context omitted.

Window management has continued to evolve in nontrivial ways, imo. More fundamental interactions probably won't and probably shouldn't change; those idioms are mature and deeply engrained at this point. It would alienate swathes of users to rock such an established boat.

Microsoft tried with Windows on their phones. Look where that led them.

To 10% market share in Europe right before they decided to drop it all.

It was starting to become the alternative to Android for many of us.

Had they provided a proper migration path from Windows Phone 7 into 8, and then from 8.x UA model into 10 UWP, and more Win developers would have followed along, instead of hating them for all the rewrites.

Re: Apple’s macOS Ventura – New Security Changes

#176
post #12

The login items panel is such a good change, and also like 20 years overdue.

Yes, I have been baffled that it was always so difficult for the user to manage what’s auto-launched on start-up. So many apps try to bury into start-up so they can keep collecting data and lightly spamming the user. Can anyone shed light on why it took so long? I had always figured the non-existence of a login items panel was a purposeful choice.

Maybe because it was not a common feature in the market. In Windows for example it's even more of a mess because there's a ton of places for autostarting software to run from. There this excellent tool from sysinternals called autostarts but it's not an OS feature despite sysinternals now being owned by Microsoft.

And in Linux? No great way of managing systemd via the GUI either afaik.

And Apple has always been one for hiding technical complexity from the user. It's only that security became prio #1 that they're doing this. 2010 Apple would not have presented the user with these popups for example.

Re: Apple’s macOS Ventura – New Security Changes

#177
post #38

Earlier quoted context omitted.

It's actually been there for a long time. It's a separate tab in "Users & Groups" pre-Ventura.

Apps aren’t required to use that screen though. Some of them will, but a lot of apps not in the App Store can and do register themselves with launchd on their own. Apple should be proactive and extract those items automatically, but in practice, they don’t.

Launch agents and daemons didn't even show up there. It was more for the user themselves to register programs they wanted to auto open.

However that feature became a bit stale since macOS started reopening all apps anyway.

Re: Apple’s macOS Ventura – New Security Changes

#178
post #8
post #2

> However, the Gatekeeper check here is overridable by users. This is presented as a flaw, but I'm not sure they are thinking through the alternatives. It's hard to give too much credence to security experts who are't thinking holistically. Perhaps there is a flaw, but I'm curious to know what it is.

They explain their reasoning right after that statement. Their concern is social engineering is still a way to convince people to override this.

It is but there needs to be a way for the user to keep full control of the system they own of they choose to have it.

And enterprises already have a way to turn this override off so I don't really understand their beef here.

Re: Apple’s macOS Ventura – New Security Changes

#179
post #74
post #4

Earlier quoted context omitted.

Things the user can override are things social engineers can convince users to override.

Exactly. Technical measures are important, but if someone wants to play a game or do something that's been banned on Apple's stores and finds a site that claims to have an installer (which is actually malware) with instructions to disable Gatekeeper or SIP or what not, social engineering can work. Their goal is to do the thing they wanted to do, probably not thinking of security in the meanwhile. Popup alerts are goi…

It's not a balance. There must be a way to override it.

I really don't want Apple to decide what I can have on my computer like they do with iOS. It'll be more secure but also a lot less free and functional.

Re: Apple’s macOS Ventura – New Security Changes

#180
post #83
post #53

Earlier quoted context omitted.

agreed the larger trackpad is a net minus. I get all kinds of spurious input because of it sensing my palms

Butterfly Keyboard ( And arguably the new Magic Keyboard ) with little to no Key travel distance, along with Larger Trackpad which create false positive input were two key minus design features. Unfortunately every time I pointed this out most of HN were quick to answer this is an user issue and not a design flaw.

You're not alone. I hated the butterfly keyboard, it was like tapping on stone.

Even the "returned to normal" keyboard on the new mbp is not nearly as good as the 2015 was in terms of tactile feel.

Post reply on HN