Live data from Hacker News

Apple Accidentally Approved Malware to Run on macOS

wired.com

131–134 of 134 posts

Re: Apple Accidentally Approved Malware to Run on macOS

#131
post #115

Earlier quoted context omitted.

I worked at SAP for seven years in their cloud business and about half the engineering staff had MBP laptops. Some engineering teams used only Macs. Operations was the same way. Engineering computer usage in India was mostly Windows, China was ~50% Macs, US/Canada was ~80% Macs, and Europe was ~50% Macs.

Software is not Engineering. You guys call your developers Engineers?

.... https://en.wikipedia.org/wiki/Software_engineering

Re: Apple Accidentally Approved Malware to Run on macOS

#132
post #131

Earlier quoted context omitted.

Software is not Engineering. You guys call your developers Engineers?

.... https://en.wikipedia.org/wiki/Software_engineering

"One of the core issues in software engineering is that its approaches are not empirical enough because a real-world validation of approaches is usually absent, or very limited and hence software engineering is often misinterpreted as feasible only in a "theoretical environment.""

Software engineering is Engineering like sandwich Engineer is Engineering.

They should use "specialist". It's not like they are using science to prove something will work.

Re: Apple Accidentally Approved Malware to Run on macOS

#133
post #126

Earlier quoted context omitted.

You don't need to refute anything if you can describe the process yourself.

> You don't need to refute anything if you can describe the process yourself. So you're admitting that you don't know what it is? Are you or are you not a Mac developer who notarizes and distributes Mac software?

Do you even know what you're talking about?

The process is described at a high level by Apple here: https://developer.apple.com/developer-id/

1. Developer signs their app

2. Developer sends signed app to Apple for Notarisation

3. Apple provides notary signature

4. Developer distributes notarised app

Re: Apple Accidentally Approved Malware to Run on macOS

#134
post #126

Earlier quoted context omitted.

> You don't need to refute anything if you can describe the process yourself. So you're admitting that you don't know what it is? Are you or are you not a Mac developer who notarizes and distributes Mac software?

Do you even know what you're talking about? The process is described at a high level by Apple here: https://developer.apple.com/developer-id/ 1. Developer signs their app 2. Developer sends signed app to Apple for Notarisation 3. Apple provides notary signature 4. Developer distributes notarised app

Yes, those are the basic steps. The fundamental problem was with your technical understanding and interpretation of each of the steps. Also, you didn't answer my question as to whether you're a Mac developer.

I've already explained how the Gatekeeper dialogs prove that your conclusion is false. Moreover, the very page you just linked shows that your claims are false. You say, "At no point in this sequence has Apple provided any testimony or recommendation about this program. Notarising is only about ensuring that what you are trying to run is what the developer wrote for you." Whereas Apple says, "Gatekeeper on macOS helps protect users from downloading and installing malicious software", "Give users even more confidence in your software by submitting it to Apple to be notarized. The service automatically scans your Developer ID-signed software and performs security checks", etc.

This story has now dropped way down in the HN rankings, and it's likely that few people are reading these comments anymore except us, so I have no desire to write a long, point-by-point treatise on how you misunderstand Developer ID and notarization.

Post reply on HN