Live data from Hacker News

Apple announces Mac OS X 10.8 Mountain Lion

apple.com

41–50 of 373 posts

Re: Apple announces Mac OS X 10.8 Mountain Lion

#41
post #30
post #13

It seems like the OS is either defaulting to allowing only only App Store applications or at least only (Apple-)signed applications: http://www.apple.com/macosx/mountain-lion/security.html It's still possible to turn this off, but I have a feeling that we should enjoy our freedom to run GNU grep instead of BSD grep for as long as it lasts.

Read what Gruber writes about that Gatekeep feature: My favorite Mountain Lion feature, though, is one that hardly even has a visible interface. Apple is calling it “Gatekeeper”. It’s a system whereby developers can sign up for free-of-charge Apple developer IDs which they can then use to cryptographically sign their applications. If an app is found to be malware, Apple can revoke that developer’s certificate, render…

Gruber was telling that the Apple ID was going to be free. It isn't. It requires a Mac Developer account as far as I could understand it.

When I was 15 I wrote a Taskbar dialer for Windows 9x and later NT (this was in the modem days. Of course I haven't updated it in ages and the only reason my old webpage is still there is because I found it by accident in an old backup, but here is a google search for it: https://www.google.com/search?ie=UTF-8&q=RasInTask).

I published that on the various download pages and it was good enough to even be featured in dead-tree publications.

Back then I had no permission to use a computer ("they make you stupid" was my parents argument) and certainly no credit card to pay anybody to do development - and even then, as a minor I would probably never have gotten that certificate.

With this rule in place I would never have been able to publish that dialer. I would never have felt how it is to make something that others can use and find useful. I would never have ended up where I am today.

Does this stop malware? Does this stop fraudulent call centers? Does this stop malicious people from telling people to turn it off and then still installing the malware? No.

Does it stop people like me from ever getting to their career of their dreams? Likely.

I might be an old fart, but this is far from acceptable.

Re: Apple announces Mac OS X 10.8 Mountain Lion

#42
post #38
post #13

It seems like the OS is either defaulting to allowing only only App Store applications or at least only (Apple-)signed applications: http://www.apple.com/macosx/mountain-lion/security.html It's still possible to turn this off, but I have a feeling that we should enjoy our freedom to run GNU grep instead of BSD grep for as long as it lasts.

That middle option, the default, is Developer Signed applications. Apple keeps the keyring and can torch the developer's key if they go rogue, but the developer does the signing. The model essentially matches Debian package distribution. (And as mentioned by oomkiller, this won't go down to unix, it is just the "application" launching.) Edit: pilaf's reply got down voted into oblivion. What he suggests is flawed beca…

So I call my malware 'ls', set it to suid root and have my victims double click that? Fine. Thanks.

Re: Apple announces Mac OS X 10.8 Mountain Lion

#46

-I'd probably pay $30 for the Airplay feature alone. -I don't know how Apple thinks they can push these web-enabled apps that only work on their platforms. A chat app that basically only lets you interact with Apple customers is kind of comical. -Gatekeeper won't win over any Apple critics, but it's actually more flexible/open than what a lot of people feared was coming (ie "App Store apps only"). -Notifications and…

A chat app that basically only lets you interact with Apple customers is kind of comical. – would be. Thankfully you probably know people with AIM, XMPP, or SMS chat identities. And iChat works with those too.

From the official Apple pages: Messages supports iMessage and instant messaging services such as AIM, Jabber, Google Talk, and Yahoo! Messenger.

Re: Apple announces Mac OS X 10.8 Mountain Lion

#48
post #13

It seems like the OS is either defaulting to allowing only only App Store applications or at least only (Apple-)signed applications: http://www.apple.com/macosx/mountain-lion/security.html It's still possible to turn this off, but I have a feeling that we should enjoy our freedom to run GNU grep instead of BSD grep for as long as it lasts.

This is a scary preview of Apple's vision of desktop computing (which we all anticipated with the App Store being brought over from the iPhone world to the desktop): The safest place to find apps for your Mac is the Mac App Store. That’s because the developers who create them are known to Apple, and the apps are carefully reviewed before they’re accepted in the store. As I've had no reason to upgrade my home PC from…

I hope you realize that Debian and Ubuntu and most of the large distros already have this: Known, vetted packages, signed and trusted, distributed through a central database. Frankly, I think it's a great idea. People in general shouldn't be downloading and executing random binaries on their machines. I think it would be great if the major distros also refused to install unsigned binaries without explicitly being told to allow it.

Re: Apple announces Mac OS X 10.8 Mountain Lion

#49
post #30
post #13

It seems like the OS is either defaulting to allowing only only App Store applications or at least only (Apple-)signed applications: http://www.apple.com/macosx/mountain-lion/security.html It's still possible to turn this off, but I have a feeling that we should enjoy our freedom to run GNU grep instead of BSD grep for as long as it lasts.

Read what Gruber writes about that Gatekeep feature: My favorite Mountain Lion feature, though, is one that hardly even has a visible interface. Apple is calling it “Gatekeeper”. It’s a system whereby developers can sign up for free-of-charge Apple developer IDs which they can then use to cryptographically sign their applications. If an app is found to be malware, Apple can revoke that developer’s certificate, render…

Malware writers will just get free ids and sign their malware.

Will all of these OSX devices be regularly polling Apple to get a list of revoked certs?

I guess this would be useful to prevent malware being installed, but it's not going to be massively useful to remove already installed malware. Especially if that malware can interrupt the polling.

I wonder how difficult it will be to get developer IDs. Might be a market for them.

Will be fun to uninstall a developers software from every machine by stealing his cert, releasing some malware signed with it, and then waiting for Apple to push out a revocation cert.

Post reply on HN