Live data from Hacker News

macOS 11’s hidden security improvements

blog.malwarebytes.com

121–130 of 152 posts

Re: macOS 11’s hidden security improvements

#121
post #115

Earlier quoted context omitted.

> If you genueinly think running linux isn't a UIUX downgrade.... You've betrayed yourself with this statement. There isn't one Linux . I know this might just seem like more of the complexity non-Linux users want to avoid, however users are free to install whatever desktop environment or window manager they like. You could even opt for a desktop environment that resembles MacOS in most ways. I use MacOS in my profess…

But that's part of the problem. There isn't a single DE which means that any applications that aren't specific to a DE will provide a UX that is inconsistent.

Apple's own UI is far from consistent either. They're always breaking their own UI guidelines. And many apps are electron which don't integrate well visually either.

Re: macOS 11’s hidden security improvements

#122

Earlier quoted context omitted.

You get that. And about a million tradeoffs in terms of usability. No thanks. Edit: To those downvoting. If you genueinly think running linux isn't a UIUX downgrade on macOS you are totally deluded. Its more open. Cool. It's also a UX nightmare.

Recently the hard drive in my Mac became inaccessible to MacOS even after formatting and a lot of other things. Somehow it was able to install Linux though, so I did that while waiting on the new drive to arrive. I tried a number of different distributions, and I had the experience you describe. It was death by UX papercuts and I could not wait to get back to MacOS by the second day. I hadn't used Linux in a decade o…

Playing with a distribution for 10 minutes and then installing another one is not going to make you understand it. It took me a while to take to KDE too. After you start actually working on it you'll find things that annoy you, start looking and find that there's actually a wealth of configuration options (which macOS absolutely doesn't have).

If you want something more Mac-like, Gnome is a thing of course but it's too opinionated like Mac for me.

Re: macOS 11’s hidden security improvements

#123

Very hidden. The 11.5.2 patch from last week had no release notes ( https://eclecticlight.co/2021/08/15/last-week-on-my-mac-trus... ), and Apple replied to inquiries with "No further details on the Big Sur 11.5.2 update will be released" ( https://twitter.com/ClassicII_MrMac/status/14256327792624312... ).

Both Microsoft and Apple are treating users like they don't care now. And probably 99.99999% of the users don't. Today you have to run Linux to control your computer yourself.

Same as with the error messages. Almost every MS app has removed the messages that actually tell you what's going wrong and replace it with something like "Oops!! Something went wrong!" that tells you absolutely nothing. And some stupid "funny" picture.

Re: macOS 11’s hidden security improvements

#124

Earlier quoted context omitted.

Both Microsoft and Apple are treating users like they don't care now. And probably 99.99999% of the users don't. Today you have to run Linux to control your computer yourself.

What's the state of running Linux on Mac hardware these days?

On Intel: Works pretty well. No longer a need to have special ISOs like Ubuntu used to have. You do have to turn off the "secure boot" on newer systems with T2 chip (using the startup security utility in recovery mode)

On M1: Still in progress. Linux boots but the kinks have to be worked out. Not production quality yet.

Re: macOS 11’s hidden security improvements

#125
post #49

Earlier quoted context omitted.

I thought those were entirely separate things? There's now a GUI option for the unsigned kernel extension block (in the startup security utility). I don't think that's part of SIP per se. It's also the one you need to run any other OS. Whereas SIP is a thing within the OS itself as far as I know. But I have to admit this is where my knowledge gets fuzzy :) The kind of control I'd want is allowing to add a signator fo…

If you’re a corporate admin you can whitelist kernel extensions via MDM, maybe that would help? https://support.apple.com/guide/mdm/kernel-extension-policy-...

I know! And I do (it prevents popping up a user with a gazillion prompts to accept when they enrol)

But this is just kernel extension stuff. We know users use some software (not with kernel or system extensions) that's not allowed in our environment. Zoom for example (people are allowed to use it in the browser only for contact with external parties but many people install the full thing anyway). Our security department has banned the full client because of the backdoor it introduced.

Right now we mark it as malware in our antivirus, but it would be great to be able to prevent it altogether.

Re: macOS 11’s hidden security improvements

#127

Earlier quoted context omitted.

You get that. And about a million tradeoffs in terms of usability. No thanks. Edit: To those downvoting. If you genueinly think running linux isn't a UIUX downgrade on macOS you are totally deluded. Its more open. Cool. It's also a UX nightmare.

There are many differences between Linux in general and macOS, but I wouldn't name UX as the first advantage of the latter. One of the first things I do on a fresh macOS device is to install Rectangle (previously Spectacle). I have many gripes with Linux, but not about UX. I use preemptive kernels on the desktop for example, because the vanilla kernel is geared towards more general usage, which practically speaking m…

Rectangle is pretty great, thanks for that pointer. I've been trying all kinds of tiling wms on MacOS, but they just don't quite work in this world -- since they're unable to do everything that's needed. But Rectangle allows me to make the decisions, which works a bit better here.

What's still missing with this setup is a shortcut for easily moving a window to another desktop. Any clues how to achieve that?

And finally there's the irritating MacOS UX "feature", that selecting an application with cmd-tab doesn't switch to the desktop where it is, or doesn't unminimize it if it's minimized.

Re: macOS 11’s hidden security improvements

#128
post #118

Earlier quoted context omitted.

Both Microsoft and Apple are treating users like they don't care now. And probably 99.99999% of the users don't. Today you have to run Linux to control your computer yourself.

No way. Ask HN "new generation" to tell you, Apple and Microsoft are taking care of you to feel safe and protecting the children at the same time. Linux desktop sucks. It is broken. I found out that this "brokenness" is what I expect to have. To modify and optimize my UX.

I’ll bite. I’m not necessarily the new generation, but I understand the viewpoint you’re arguing against.

I am the on the more technical side, making me the help desk for friends and family. For the vast majority of people, the safest and easiest thing to hand them is a chromebook. If they want more capability or better hardware, then they will step up into OS X or windows.

They don’t care about the UX until they have to care about the UX because it’s not working the way it was intended. Then they want to fix it back to the way it was (unhide icons or the task bar). They don’t grasp how computers should work, and while I’ve tried explaining, it just doesn’t take. So they remember how to get to email by clicking icons.

99% of people for casual use would just be confused if you dropped them into a command line. There’s a reason things weren’t as popular before we made advances like we have today.

So - for the vast majority of users - an upgrade is an annoyance and downtime that is there during the 10-30 minutes a day they may need the machine (not the 10-30 minutes they are taking a break from the machine). They don’t understand, and don’t care about, the security updates.

Apple and Microsoft and Samsung and Google have no obligation to you, an edge customer, to create a lot more opportunities to screw things up for the vast majority of users who would just get confused. They have no obligation to enable users to perform illegal activity on their hardware. And they can put whatever they want to in the user agreement for their hardware and software. Your option as a consumer is to not buy it. You can complain about it, but that ship has sailed, as the vast majority of users don’t even understand the complaint and the potential implication.

But no. If you want a UX that’s fully configurable and secure and has privacy protections in place and places emphasis on security over convenience, a private, cloud focused, company like Google or Microsoft or Apple is not the right tree to be barking up.

Re: macOS 11’s hidden security improvements

#129

Earlier quoted context omitted.

Recently the hard drive in my Mac became inaccessible to MacOS even after formatting and a lot of other things. Somehow it was able to install Linux though, so I did that while waiting on the new drive to arrive. I tried a number of different distributions, and I had the experience you describe. It was death by UX papercuts and I could not wait to get back to MacOS by the second day. I hadn't used Linux in a decade o…

Playing with a distribution for 10 minutes and then installing another one is not going to make you understand it. It took me a while to take to KDE too. After you start actually working on it you'll find things that annoy you, start looking and find that there's actually a wealth of configuration options (which macOS absolutely doesn't have). If you want something more Mac-like, Gnome is a thing of course but it's t…

Being dismissive of the UX of Linux isn't going to improve the market share of Linux for ex Apple people. I wish Linux was more on par because I don't like where Apple is taking MacOS.

It wasn't ten minutes, and there were way too many configuration options that I couldn't fix (like the terrible trackpad scrolling) despite best efforts that it wasn't worth it, and too many that I didn't want to bother. The point is that out of the box, the UX of the Linux UIs has historically and still does suck compared to tools that have a UX focus, and that's a deal breaker for a lot of people that I know.

Re: macOS 11’s hidden security improvements

#130
post #118

Earlier quoted context omitted.

Both Microsoft and Apple are treating users like they don't care now. And probably 99.99999% of the users don't. Today you have to run Linux to control your computer yourself.

No way. Ask HN "new generation" to tell you, Apple and Microsoft are taking care of you to feel safe and protecting the children at the same time. Linux desktop sucks. It is broken. I found out that this "brokenness" is what I expect to have. To modify and optimize my UX.

It's not broken at all... At least not for me, being a user for several decades now. I use it at work while billing quite a lot of money so if it was breaking, I would have a massive problem. :)

I would say this though - the machine you run it on matters. The hardware matters. Some hardware runs great, other hardware will give you problems. This is due to driver support either being good or bad, not Linux itself, but the distinction is meaningless for the user.

Use a thinkpad, with Pop OS, to get you started. It will just work.

Post reply on HN