Live data from Hacker News

Application trust is hard, but Apple does it well

security-embedded.com

101–110 of 213 posts

Re: Application trust is hard, but Apple does it well

#101
post #98

Earlier quoted context omitted.

I pay extra money for Apple computers is specifically due to these security controls. I spent decades building and running my own computers and I’m not interested in doing so anymore. I own the device that I buy, I knew how to turn off these controls and didn’t bother during the outage, and I generally refuse to do so. In return, I don’t have to deal with all the weaknesses of the liberated computing approach that yo…

> Apple’s restrictions liberate me from having to spend time on fully-liberated computing. This seems to conflate restrictions with defaults. It's reasonable for Apple to configure Macs to be safe "out of the box". But it's not clear why it helps you to prevent other Mac users from changing the defaults.

You’re right, “Apple’s out-of-the-box restrictions” is a better phrasing.

I don’t understand your final sentence about “prevent”, and it doesn’t seem to be connected to anything I said. I apologize but as a result I can’t consider or reply to it as stated.

Re: Application trust is hard, but Apple does it well

#102
post #94
post #88

Earlier quoted context omitted.

I’d say this is only one half. Many malicious effects involve social engineering, fraud, etc, and are not about exfiltration of files.

In that case code signing can’t do much either.

On the contrary code signing is the only current solution to this problem.

It allows fraudulent, malicious, or easily exploited code to be disabled.

Re: Application trust is hard, but Apple does it well

#103
post #92
post #69

Earlier quoted context omitted.

“You no longer own your computer” has no traction outside of ideology. There are a few people who bring it up, and then use manipulative rhetoric: “Shouldn’t we own the devices we buy?” Of course, who would disagree with that! But this is manipulative because you are affirming the consequent . I.e. leading the reader into accepting the conclusion that you don’t own your computer. “The tech companies are trying to des…

> How about examining some of the technical issues instead of ideological rhetoric? Way ahead of you: https://news.ycombinator.com/item?id=25074959 https://news.ycombinator.com/item?id=25076588 > I have to assume you neither own nor lease any Apple devices. This was a ludicrously bad assumption.

It was also a tongue in cheek assumption.

However the question I have is given your views, why?

Re: Application trust is hard, but Apple does it well

#104
post #103
post #92

Earlier quoted context omitted.

> How about examining some of the technical issues instead of ideological rhetoric? Way ahead of you: https://news.ycombinator.com/item?id=25074959 https://news.ycombinator.com/item?id=25076588 > I have to assume you neither own nor lease any Apple devices. This was a ludicrously bad assumption.

It was also a tongue in cheek assumption. However the question I have is given your views, why?

> However the question I have is given your views, why?

I came to the Mac almost 20 years ago. It was very different back then. The first decade of Mac OS X was brilliant. I felt it was the best consumer OS ever made. It was also a fairly "open" system: Mac UI on top, UNIX underneath.

The second decade of Mac OS X (now macOS), has been a disaster IMO. It just keeps getting worse and worse. All of the restrictions we see now were added in the past 8 years or so.

In short, I was already fully committed to the Mac before it started to get locked down, but I'm becoming increasingly uncomfortable with it as time goes on. There's not a great alternative, however.

Re: Application trust is hard, but Apple does it well

#105
post #11

If this unacceptable mess is "doing it well", perhaps the whole idea is doomed and should not be attempting to do it at all. > It comes down to an argument of trust - do you trust Apple is acting in your best interests No. I mean really very obviously no. Neither Microsoft. Nor Google. Why would I assume any company would act in my interests when they have clear incentives to increase their profits and control by act…

Perhaps we should think about this from a utilitarian perspective. There are obvious security advantages to app signing. But there are also negative implications for privacy and availability. Given tens of millions of non-technical users, is app signing likely to result in more good than bad, taking into account the fact that it can be turned off? I don’t know the answer, but I’m pretty sure those who relentlessly focus on the possible downsides don’t know either.

(Pretending to be able to see into the minds and motivations of people you don’t know is rarely helpful. You have no grounds to attribute users’ behavior and opinions to Stockholm Syndrome, and it doesn’t apply anyway: no one is held hostage or abused in this scenario)

Re: Application trust is hard, but Apple does it well

#106
post #77

Earlier quoted context omitted.

By posing false dichotomies: "do you trust Apple is acting in your best interests, or do you believe they're a malevolent entity?" It's perfectly reasonable to believe that Apple is acting in Apple's best interest without attributing malevolence. By downplaying rational arguments: "I think the privacy arguments are far-fetched (because others are worse)" By using loaded terms: "Dogwhistles The privacy squad mobilised…

You’re exaggerating, and then falling into the same traps you are accusing him of. A lot to people are claiming Apple is a malevolent entity. In context, it is reasonable for him to rebut that. I agree with you about his use of loaded terms, and the dismissiveness. The straw man you cite isn’t a straw man. It is a solid argument. https://www.bunniestudios.com/blog/?p=5706 The lie of omission you assert isn’t a lie. N…

> A lot to people are claiming Apple is a malevolent entity. In context, it is reasonable for him to rebut that.

The exclusive "or" in "do you trust Apple is acting in your best interests, or do you believe they're a malevolent entity?" still makes it a false dichotomy.

> The straw man you cite isn’t a straw man. It is a solid argument.

"if I have the code, build the code, nothing can hide in the code.":

is not something someone knowledgeable would ever claim, only that having the code and building the code will be at least as safe or safer than not having the code at all. Presenting it as "nothing can hide in the code" and then attacking that is, in my opinion, a strawman argument.

> The author used the word ‘feasible’.

And he is correct in that. No single individual can maintain the software integrity of an entire operating system, but a group of people can do so. The omission here is that that group of people need not be Apple.

The argument here is that without Apple taking control of the user's software the user would fall prey to the privacy violating practices of the likes of Google and Microsoft, which is not true. Hence the "lie by omission".

> If that isn’t a loaded term, I don’t know what is.

The term is from the article: "While I'm going to sound like an Apple apologist,"

He claims he is not X, but has given no argument why he shouldn't be considered X and has presented a lot of arguments on why he should be considered X.

He has presented no reason to assume he is not a devoted Apple user, or in his words, an "Apple apologist".

In short, I'm not sure I'm exaggerating, but that I'm willing to disagree on.

Re: Application trust is hard, but Apple does it well

#107
post #83
post #70

The article goes over the horrors of X.509, pulls the typical open source cliche that I actually don't see anybody spreading around, contrary to the article's claim, then argues that the privacy part is fine so long as there is a third-party audit. If the best thing the security community can do is install a global mass surveillance network of devices that come at every expense of users' computing freedoms, then I th…

It's not even that. This is a distraction from the real issue which is this technology exists not to improve the security posture but to enforce market control. So go back a few weeks and you buy a copy of Fortnite, Apple and Epic lock horns on a dispute and they revoke Epic's certificate. Next thing you get a shiny new M1 equipped Mac and go to install it and it's gone from the app store. Slightly deflated, you go b…

Yes, thanks for the reply. I was giving the author the benefit of the doubt, but their arguments just have no solid grounds. And like you said, this is about market control, not security, the latter just being a distraction.

Another thing in line with what you mentioned is the ability for the company to squash competition. Not only do they have the last word to veto programs from running, they also get a global view of what everyone is running that nobody else has. This kind of information has been abused by Amazon to drive out competition in favour of their own "Amazon essentials" products, for example.

Re: Application trust is hard, but Apple does it well

#108
post #11

If this unacceptable mess is "doing it well", perhaps the whole idea is doomed and should not be attempting to do it at all. > It comes down to an argument of trust - do you trust Apple is acting in your best interests No. I mean really very obviously no. Neither Microsoft. Nor Google. Why would I assume any company would act in my interests when they have clear incentives to increase their profits and control by act…

>If this unacceptable mess is "doing it well", perhaps the whole idea is doomed and should not be attempting to do it at all.

Well, "unacceptable mess" are your words. It's totally acceptable to me that there could be issues on a feature / launch that need to be ironed out, unless we're talking about aviation software or pacemakers.

If we deemed "unacceptable" any misstep or early issue, we wouldn't even have fire, a relatively tried and tested technology, that still has its issues...

>No. I mean really very obviously no.

The question is not an absolut one.

You should read it "do you trust Apple is acting in your best interests OVER any random app you might install or website you visit?".

Not to mention they don't even do the kind of tracking the original "sky is falling" post assumed they do: https://blog.jacopo.io/en/post/apple-ocsp/

As this post says, "Now that you know the actual facts, if you think your privacy is put at risk by this feature more than having potential undetected malware running on your system, go ahead [and disable the checking via /etc/hosts]".

>It's great that the author loves to exist within the limits and restrictions imposed by Apple, but don't expect me to go along with your Stockholm Syndrome and belittle me for differing.

The author is a security specialist, not some random dude. And he made his point with technical arguments, not hand waving.

Re: Application trust is hard, but Apple does it well

#109

Earlier quoted context omitted.

Without DNS a lot of my workflows would stop workong since they include various machines/services which all communicate though hostnames/URLs rather than IP addresses, yet almost all are local to my network. So for me this is a valid question.

Could you switch DNS providers if one fails? Could you have a fallback? What's the parallel here?

The original statement I was objecting to was this:

> It is my computer and it should just work how it is meant to be without any external dependencies.

DNS is an external dependency, regardless of the level of redundancy.

Re: Application trust is hard, but Apple does it well

#110
post #93

Earlier quoted context omitted.

I don't follow... what did you want me to explain and what assertions are you referring to. If you mean, the assertion that Apple users are suffering Stockholm Syndrome is an inappropriate discourse, I'm not sure how to better explain that.

Maybe you could start by why you think it's inappropriate?

Because it's a "mass psychology" BS explanation based on the premise of "others are misguided/idiots/sheep/Stockholmed and I know the truth/true freedom" - as opposed to a good faith argument, understaning that it's an ideological preference and that others (including people with 10 times the degrees, career experience, computer science knowledge of the author, can think otherwise).

If that very basic thing needs to be spelt out, I'm not sure how any discussion is possible...

Post reply on HN