Live data from Hacker News

Catalina is checking notarization of unsigned executables

lapcatsoftware.com

111–120 of 182 posts

Re: Catalina is checking notarization of unsigned executables

#111

Earlier quoted context omitted.

Vagrant. https://www.vagrantup.com/downloads.html Spin up a Linux box in macOS and ssh into it directly. It is a true joy if you are comfortable working with text files (programming, admin, focused writing, etc.) It will default to using VirtualBox as the underlying virtualization. That works a treat and hides all the GUI madness of VirtualBox. However, if you open up VirtualBox then you can interact with the host yo…

I've never used that before, but it sounds a bit like Docker? As in, it's got a VM in the background and I can interact with it?

Technology aside, I would describe as being a bit more like an AWS instance, except it is running on your local machine.

Re: Catalina is checking notarization of unsigned executables

#112
post #87

Earlier quoted context omitted.

A few ideas: 1. confirm the checks are enabled: spctl --status 2. Make sure your terminal/shell/etc aren't already exempted System Preferences > Security & Privacy > Developer Tools. 3. If you already ran something that could generate a check in the last minute, the connection is still open. Most of the overhead people are recording is negotiation/handshake. If you're fairly close to the server, it seems plausible yo…

I don't have a system to check this on, but Apple seriously named an option "asses"?

Ha, no. I'm the ass, here. Fixed :)

Re: Catalina is checking notarization of unsigned executables

#113
post #79

Earlier quoted context omitted.

It seems pretty unique to Apple in my experience. I have an ancient Android tablet. I don't even know how old the OS is on it. It never nags me to upgrade. My Linux boxes never nag me to upgrade. When I do upgrade, things mostly keep working, and if they don't it's pretty easy to roll things back.

Android never getting updates is not a feature!

I much prefer no updates over broken updates, especially when they are forced on me. Stable bugs are better than a never ending stream of new ones.

Re: Catalina is checking notarization of unsigned executables

#114

Why don't companies come out and tell people what they're doing these days? Telemetry is getting to the point where people such as doctors and lawyers might be violating the law by using a modern computer. And people in the defense industry? Doesn't Apple employ thousands of forns? Who's audited their datasystems and ensured that this stuff stays private? Much easier and better to just stop using it all and move to a…

Sorry, what's a forn?

The acronym used on files is often NOFORN == no foreign nationals.

Re: Catalina is checking notarization of unsigned executables

#115

Why don't companies come out and tell people what they're doing these days? Telemetry is getting to the point where people such as doctors and lawyers might be violating the law by using a modern computer. And people in the defense industry? Doesn't Apple employ thousands of forns? Who's audited their datasystems and ensured that this stuff stays private? Much easier and better to just stop using it all and move to a…

I don't know about BSD, but even "mainstream" Linux (i.e. Ubuntu and the like) has telemetry now. This sort of spyware is everywhere. I think Windows 10 was the first to really normalise such behaviour on the desktop, and all the others just followed along.

where people such as doctors and lawyers might be violating the law by using a modern computer

That reminds me of a story I heard not long ago --- a company wanted to have more defense against malware, so signed up for a "security solution" from one of the big vendors and got it installed on all the company's machines. After a developer who was doing network tracing discovered that it was phoning home on every executable being run, and further digging discovered that it was periodically uploading file hashes and sometimes actual files --- not just the executables being run but other random files --- to the security vendor's servers, the reaction was "oh hell no!" and they immediately terminated the service and removed the product from all their machines.

Re: Catalina is checking notarization of unsigned executables

#116
I'm still trying to understand what the problem here is.

Nobody seems to have an issue with checking this for apps -- it's a good security feature to protect from malware, right? And which everyone knows about? And it only happens the first time you run something, so it's not a performance issue in everday usage.

And the article even states that there seems to be a valid reason for checking shell scripts, because they can be used to compile malware.

The original complaint was about slowness, but how often do you run something for the first time? The only scenario in which I can imagine this would become a practical peformance problem is if, somehow, you have an app that spawns new shell scripts all day long to execute, every few seconds, and a really flaky internet connection. Or new shell scripts hundreds of times a second, even with a good internet connection.

Is that something anyone ever needs to do? Programs can run shell commands directly, without a file, so it seems unlikely. Also, another comment here suggests that even if a shell script is modified, it isn't re-verified, so there would seem to be a trivial workaround anyways.

Or is the issue just that this is undocumented behavior? Or what am I missing here?

Re: Catalina is checking notarization of unsigned executables

#117
post #24

I guess the list of things keeping me off catalina (and, by extension, new Mac hardware) just got one item longer. I recently bought a new System76 laptop as a stopgap, but it might end up becoming permanent. Kind of a sad end for 25+ years of Mac use.

How does the keyboard and trackpad for that System76 laptop feel? I've been looking at those quite a bit and am seriously considering one to replace my 2014 MacBook Air.

Re: Catalina is checking notarization of unsigned executables

#118

Why don't companies come out and tell people what they're doing these days? Telemetry is getting to the point where people such as doctors and lawyers might be violating the law by using a modern computer. And people in the defense industry? Doesn't Apple employ thousands of forns? Who's audited their datasystems and ensured that this stuff stays private? Much easier and better to just stop using it all and move to a…

If only moving to Linux were an option for everyone. The other day I tried for the 100th time to move to Linux. I installed a recent build of a maintained, popular distribution (no it doesn't matter which one - I have tried them all), on hardware that is famous for it's Linux support. Everything worked for a day and a half, then the sound just fucking died. No input or output. I get millions of people use Linux daily…

Yeah I have a reload_alsa.sh script which reboots my audio. Basically the only problem I have. It's a shame, I know, but I still love my linux box.

Re: Catalina is checking notarization of unsigned executables

#119
post #41
post #24

I guess the list of things keeping me off catalina (and, by extension, new Mac hardware) just got one item longer. I recently bought a new System76 laptop as a stopgap, but it might end up becoming permanent. Kind of a sad end for 25+ years of Mac use.

My 16” is a huge disappointment. After swearing off Intel PCs after a disaster ours X1 Carbon, I switched back to a 2013 15” until this month. Figured after six months bugs would be ironed out. Wrong. I’m seeing two major glitches that have macrumors threads dozens of pages long: 1) with an external display connected, dGPU utilization shoots up to 20W at idle. (The rest of machine draws well under 10W at idle.) That…

My partner is a graphic designer who loathed her 13" macbook that her work got her. She finally got an upgrade to a 16", i9, 64 gigs of ram.

It runs adobe software like total shit.

I think it's something to do with Catalina + accessing files in Google Drive File Stream + Adobe.

It runs illustrator horribly.

It's basically the saddest thing I've ever seen.

I think I'll get her a 17" XPS for christmas this year.

Re: Catalina is checking notarization of unsigned executables

#120

Earlier quoted context omitted.

With issues like this and the 4000 series Ryzen mobile processors, top specced MacBook Pros are very noticably slower than $1k alternatives.

I see the above comment heavily downvoted but I'm specifically looking at 4000 series Ryzen laptops as my 1st move away from MacBook Pros. Such incredible CPUs really make the decision a bit more acceptable. The laptop I'm eyeing is near $1000.

Out of curiosity - what are you looking at? I'm also starting to think about replacing my 2016 MBP and quite honestly, the current MacBook Air/MacBook Pro line doesn't really appeal to me.

Lenovo has a couple of AMD-based ThinkPads that are looking pretty appealing, although they come in around $1500 with the configuration I'd want.

Post reply on HN