Live data from Hacker News

Application trust is hard, but Apple does it well

security-embedded.com

11–20 of 213 posts

Re: Application trust is hard, but Apple does it well

#11
If this unacceptable mess is "doing it well", perhaps the whole idea is doomed and should not be attempting to do it at all.

> It comes down to an argument of trust - do you trust Apple is acting in your best interests

No. I mean really very obviously no.

Neither Microsoft. Nor Google. Why would I assume any company would act in my interests when they have clear incentives to increase their profits and control by acting counter to them?

It's great that the author loves to exist within the limits and restrictions imposed by Apple, but don't expect me to go along with your Stockholm Syndrome and belittle me for differing.

Re: Application trust is hard, but Apple does it well

#12
post #3

This is exactly my point of view on this. I've seen people complain about Apple on HN about this in all the other posts, but to be fair, this is actually a really good thing. It protects users, and it works well 99.9% of the time (actually, I am not aware of a previous outage of this system). So, why bother? It's been like this for a while, it is actually very useful to the vast majority of users, and Apple being App…

Besides the privacy implications, 99.9% means per definition that it does not work for 8.77 hours per year. This is way too much. It is my computer and it should just work how it is meant to be without any external dependencies.

Computers haven’t worked well without external dependencies in a very long time. How long can you perform useful work without DNS?

Re: Application trust is hard, but Apple does it well

#13
post #2

> there are a lot of folks reasonably asking if they can trust Apple to be in the loop of deciding what apps should or should not run on their Macs. My argument is - who better than Apple? ... The user?

Users will never have the vast operational knowledge that most organizations do, and are generally very unsophisticated.

This is why there is no 'File Access' API in the browser, because it'd be like giving guns to teenagers, even with 'safety training' it would get out of hand.

So the issue then becomes one of 'power' as much as 'knowledge' of security, and of course all the peripherial abuse surrounding the 'security rules' that have nothing to do with security.

Involving 3rd parties, giving proper security notifications but still letting users have the final say etc. etc. there are definitely middle paths and reasonable choices we coudl make.

But there's just too much money on the table for the powers that be to look the other way, they will continue to infringe until they are stopped.

Re: Application trust is hard, but Apple does it well

#14
post #2

> there are a lot of folks reasonably asking if they can trust Apple to be in the loop of deciding what apps should or should not run on their Macs. My argument is - who better than Apple? ... The user?

I was really torn on whether to up or downvote here... On the one hand, no. Probably, statistically, apple will know better. On the other hand, despite the above, if you want to call apple devices "owned" (vs "leased") then yes, the user must be the ultimate decision maker. They might want to delegate these things to apple (or someone else for that matter) most of the time. But they must have the possibility to simpl…

So, if they started leasing their hardware to users, it would be fine?

I can see the argument, but at the same time, if they really did, I’m not sure I would agree.

I also am not sure that’s completely theoretical. Apple (almost?) has the money to do so (yearly revenues about $260 billion, cash reserves about $190 billion), and I think ‘the world’ is getting used to not owning stuff more and more. Many users already pay per month for their phones, anyways.

Re: Application trust is hard, but Apple does it well

#15

Earlier quoted context omitted.

Besides the privacy implications, 99.9% means per definition that it does not work for 8.77 hours per year. This is way too much. It is my computer and it should just work how it is meant to be without any external dependencies.

Computers haven’t worked well without external dependencies in a very long time. How long can you perform useful work without DNS?

> How long can you perform useful work without DNS?

Is this a serious question? My entire dev toolchain works without internet...

Re: Application trust is hard, but Apple does it well

#16
post #11

If this unacceptable mess is "doing it well", perhaps the whole idea is doomed and should not be attempting to do it at all. > It comes down to an argument of trust - do you trust Apple is acting in your best interests No. I mean really very obviously no. Neither Microsoft. Nor Google. Why would I assume any company would act in my interests when they have clear incentives to increase their profits and control by act…

Where does the author belittle those who prefer a different answer?

Re: Application trust is hard, but Apple does it well

#17
> "there are a lot of folks reasonably asking if they can trust Apple to be in the loop of deciding what apps should or should not run on their Macs. My argument is - who better than Apple?"

My argument: sod off and let me decide what I want with my own hardware. Luckily I have no business case to deal with Apple products and as a private person I do not care what they do as I am not in their "ecosystem" or whatever they call it.

Re: Application trust is hard, but Apple does it well

#18
post #3

This is exactly my point of view on this. I've seen people complain about Apple on HN about this in all the other posts, but to be fair, this is actually a really good thing. It protects users, and it works well 99.9% of the time (actually, I am not aware of a previous outage of this system). So, why bother? It's been like this for a while, it is actually very useful to the vast majority of users, and Apple being App…

[deleted]

Re: Application trust is hard, but Apple does it well

#19

The problem with the argument given is that it basically gives up to Apple because it thinks that the situation that Apple provides is the best default experience for the majority of users. It probably is, but the problem is that 1. Apple doesn’t really explain any of this stuff anywhere so a technical user may read about it and make an informed decision nor 2. do they really provide a way to alter the process to use…

I agree with 1 and 3 completely.

I think 2 is much more complicated and the solution is not obvious, but it’s still a very valid issue, indeed I would say it is the most important issue in the industry today.

However much of what I saw in the comments was none of these.

Most of it was intended to dishonesty brand Apple a ‘spyware’ company, or to brand anyone who uses Apple hardware or software as a participant in some great evil.

Neither of these are intellectually honest paths.

Re: Application trust is hard, but Apple does it well

#20

Earlier quoted context omitted.

Besides the privacy implications, 99.9% means per definition that it does not work for 8.77 hours per year. This is way too much. It is my computer and it should just work how it is meant to be without any external dependencies.

Computers haven’t worked well without external dependencies in a very long time. How long can you perform useful work without DNS?

Extraordinary amounts of work are done without DNS. And even if it weren't, this is nothing like DNS because you can choose your own DNS servers and most people have a primary and a fallback.

Where can I set trustd to use a different OCSP server? What is Apple's recommended secondary OCSP server?

Post reply on HN