The developer's website (software.charliemonroe.net) is also blocked by my ISP (Vodafone UK)'s adult content filter. This is strange as it does not appear to contain any adult content. I wonder if these things are related?
Just wondered: If the adult content filter is ISP-level, can you deactivate it or like in this case report false positives? It sound's as orwellian as Apples certificate shenanigans.
Apple revoked longtime Mac developer's code signing certificate with no warning
131–140 of 180 posts
Re: Apple revoked longtime Mac developer's code signing certificate with no warning
#132Sadly, this is what a walled garden results in. Please don't be surprised, shocked or even remotely discontent because by signing the ToS you have waived away any and all of your rights regarding the use and publishing of software in this walled garden. The only reason an issue like this will get "fixed" is when this (post/tweet) goes viral and the PR department will work extra hard to correct this.
Don't know why you are downvoted since you are completely correct. It is unfair to the developer but we wouldn't even have this discussion if people rejected app stores. I like that more developers just reject software certification processes. There is zero benefit aside from lock in.
And of course there are benefits beyond lock-in.
Do you know about the attestation service Apple has introduced?
How would you build such a thing on your own?
Re: Apple revoked longtime Mac developer's code signing certificate with no warning
#133This seems relevant. “MPlayerX hasn’t been working for almost a year now. Also they still offer my apps on the App Store, they revoked my (direct) distribution certificate...” https://twitter.com/charliemonroe/status/1290629792430280704...
MPlayerX was caught bundling installer with malware: https://www.reddit.com/r/apple/comments/3bhvh9/psa_do_not_in... So this could be justified
Re: Apple revoked longtime Mac developer's code signing certificate with no warning
#134Earlier quoted context omitted.
Other than open season on the users with malware out the wazoo. But who cares about security. Do you buy healthcare from the back of a pickup truck?
App stores leave a lot to be desired when it comes to security. In fact it can give users a false sense of security. https://www.cbc.ca/amp/1.5351280
The argument that they could be better therefore they are worth nothing, is a clear fallacy.
Re: Apple revoked longtime Mac developer's code signing certificate with no warning
#135Earlier quoted context omitted.
Just wondered: If the adult content filter is ISP-level, can you deactivate it or like in this case report false positives? It sound's as orwellian as Apples certificate shenanigans.
You can deactivate it by verifying your age with a credit card or photo ID. Vodafone don't seem to offer a way to report false positives, but I've seen that option with other providers.
Re: Apple revoked longtime Mac developer's code signing certificate with no warning
#136Earlier quoted context omitted.
Other than open season on the users with malware out the wazoo. But who cares about security. Do you buy healthcare from the back of a pickup truck?
I don't think it follows that malware is the only possible alternative to walled gardens. You could still have trust mechanisms while downloading from sites where the author , not the walled garden, has the control.
Wouldn’t it be better to have the user have the control?
The walled garden does have problems, but I generally don’t see anyone adding any value to our understanding of how to replace it with something better.
Re: Apple revoked longtime Mac developer's code signing certificate with no warning
#137Earlier quoted context omitted.
Okay, so what are the situations where it can be false? * apple actually did communicate to them, but it was via carrier pigeon or something and it got lost * apple is under gag order * the developer is actually a long time repeat offender and is trying to evade via sockpuppet accounts None of them seem plausible to me. Also, unlike with the apple 30% refund fiasco, we know for sure this is happening, because other u…
- Developer was hacked and is unaware of it. - Developer accidentally clicked "revoke my cert" (no idea if that's a real button, but that's not the point). - A national security agency sent one of those scary letters preventing Apple from speaking but requiring the action. - Developer had a mental breakdown and has lost grip on reality. - Developer realized app was infected with malware and ... Truth is stranger than…
Re: Apple revoked longtime Mac developer's code signing certificate with no warning
#138Another possible explanation: The developer‘s certificate leaked and was really used to sign malware. Or his github repo was hacked and something evil was added to his code without him noticing. Maybe I’m just rationalizing, because if Apple is really going down the road that most commenters here suspect, then there will be no arm macbook for me unfortunately... :(
A CRL / OSCP makes sense, more or less, for websites as they can simply abandon a cert.
If the cert leaks, is the remedy really to completely blacklist the certificate? Because that means that anyone who is able to steal the cert can effectively blackmail an author.
I'd definitely want to revoke it, but if there's a set of valid releases, it seems like you'd want to do a partial revocation, e.g. "valid until YYMMDD." Or have a blacklist / whitelist and mark known good releases.
I can't imagine how they don't have a separation of concerns given that app certificates must expire.
[1]: https://developer.apple.com/support/certificates/
[2]: https://help.apple.com/developer-account/#/dev138c9fac7
[3]: https://developer.apple.com/library/archive/documentation/Se...
Re: Apple revoked longtime Mac developer's code signing certificate with no warning
#139Earlier quoted context omitted.
Because it is a lot of hand-waving bullshit. This "walled garden" talk gets tiring fast. And, uh oh, big surprise, you have to actually behave according to ToS you signed. How can it be, hmmm? Nobody forces you to sign anything. Go have your own platform and distribution chanells. Oh, you want to be where the money is? Well, than. Maaaaybe there is some correlation between being the walled garden and the place there…
That doesn't invalidate the point, it reinforces it: when you sign up for an Apple-style "walled garden" you cede all control of whether or not your app ships — and, assuming you do ship, whether or not your users can keep using your app. You being tired of it doesn't change anything. ¯\_(ツ)_/¯
As a developer I want a store where someone is investing in the safety and security of the ecosystem.
If I want Apple to be able to be able to remove malware from the store, I obviously have to accept that if I make malware, then they may remove it.
The arguments about what they are somehow holding back are completely without merit.
It’s not expensive to buy an Android phone.
Android phone allow both sideloaded apps and alternate stores.
Where are the amazing Android apps that are only possible through side-loading?
Re: Apple revoked longtime Mac developer's code signing certificate with no warning
#140Earlier quoted context omitted.
You can deactivate it by verifying your age with a credit card or photo ID. Vodafone don't seem to offer a way to report false positives, but I've seen that option with other providers.
What age do you have to verify? Don't you already have to be an adult to sign up for service?