> there are a lot of folks reasonably asking if they can trust Apple to be in the loop of deciding what apps should or should not run on their Macs. My argument is - who better than Apple? ... The user?
Anyone who has programmed or developed anything....knows that the end user can never be trusted.
Application trust is hard, but Apple does it well
131–140 of 213 posts
Re: Application trust is hard, but Apple does it well
#132Earlier quoted context omitted.
Anyone who has programmed or developed anything....knows that the end user can never be trusted.
That alone isn't a justification to take away the user's rights and responsibilities. Let people make mistakes, they'll learn from it.
If they don’t, they can buy a Mac.
Don’t force them to choose an unsafe tool when they don’t want to.
Re: Application trust is hard, but Apple does it well
#133Earlier quoted context omitted.
Anyone who has programmed or developed anything....knows that the end user can never be trusted.
I have programmed and developed things. I am also a user. I want to run the apps I want to run, thank you very much. No one else should have any say in that. It's my computer.
Re: Application trust is hard, but Apple does it well
#134The article goes over the horrors of X.509, pulls the typical open source cliche that I actually don't see anybody spreading around, contrary to the article's claim, then argues that the privacy part is fine so long as there is a third-party audit. If the best thing the security community can do is install a global mass surveillance network of devices that come at every expense of users' computing freedoms, then I th…
It's not even that. This is a distraction from the real issue which is this technology exists not to improve the security posture but to enforce market control. So go back a few weeks and you buy a copy of Fortnite, Apple and Epic lock horns on a dispute and they revoke Epic's certificate. Next thing you get a shiny new M1 equipped Mac and go to install it and it's gone from the app store. Slightly deflated, you go b…
https://www.zdnet.com/article/apple-update-kills-off-zoom-we...
As for Epic. They lied about the content of the software they uploaded to the store, and knowingly breached a contract they had signed. If that isn’t fraud, I don’t know what is.
They could have sued Apple without the fraud. The certificate revocation was only about the fraudulent software update.
Re: Application trust is hard, but Apple does it well
#135This is exactly my point of view on this. I've seen people complain about Apple on HN about this in all the other posts, but to be fair, this is actually a really good thing. It protects users, and it works well 99.9% of the time (actually, I am not aware of a previous outage of this system). So, why bother? It's been like this for a while, it is actually very useful to the vast majority of users, and Apple being App…
99.9% is far too unreliable for something so fundamental as whether you can run programs on your own computer, especially when the downtime is unscheduled and occurs in the middle of the day. It should be at least five nines, preferably six nines. Anything less than that is absolutely inexcusable.
Re: Application trust is hard, but Apple does it well
#136If this unacceptable mess is "doing it well", perhaps the whole idea is doomed and should not be attempting to do it at all. > It comes down to an argument of trust - do you trust Apple is acting in your best interests No. I mean really very obviously no. Neither Microsoft. Nor Google. Why would I assume any company would act in my interests when they have clear incentives to increase their profits and control by act…
Guns can be well engineered, but that does in no way answer whether it is or isn't acceptable to own one.
Re: Application trust is hard, but Apple does it well
#137Earlier quoted context omitted.
It was also a tongue in cheek assumption. However the question I have is given your views, why?
> However the question I have is given your views, why? I came to the Mac almost 20 years ago. It was very different back then. The first decade of Mac OS X was brilliant. I felt it was the best consumer OS ever made. It was also a fairly "open" system: Mac UI on top, UNIX underneath. The second decade of Mac OS X (now macOS), has been a disaster IMO. It just keeps getting worse and worse. All of the restrictions we…
I don’t think waging ideological war on Apple is doing anything to help us get one, especially not if you dismiss the real security benefits of their approach as part of some conspiracy to undermine the concept of ownership.
What would help is some analysis of how technically to achieve both security and openness. Nobody has achieved this yet.
Apple’s security strategy does place them as a trusted party in the system. I don’t see them changing this any time soon, since it’s an unsolved research problem, and they need to keep shipping.
I am curious what a system with no centrally trusted authority would actually look like.
Re: Application trust is hard, but Apple does it well
#138Re: Application trust is hard, but Apple does it well
#139Earlier quoted context omitted.
I pay extra money for Apple computers is specifically due to these security controls. I spent decades building and running my own computers and I’m not interested in doing so anymore. I own the device that I buy, I knew how to turn off these controls and didn’t bother during the outage, and I generally refuse to do so. In return, I don’t have to deal with all the weaknesses of the liberated computing approach that yo…
> Apple’s restrictions liberate me from having to spend time on fully-liberated computing. This seems to conflate restrictions with defaults. It's reasonable for Apple to configure Macs to be safe "out of the box". But it's not clear why it helps you to prevent other Mac users from changing the defaults.
For everyone else, it is a very important safeguard against social engineering attacks.
Re: Application trust is hard, but Apple does it well
#140"I always advocate against opt-outs for security features like this" The author conveniently overlooks the fact that customers pay literally thousands of dollars for Apple computers. We're not talking about a free online service here. This is why "you no longer own your computer" has so much traction. Shouldn't we own the devices that we buy? The tech companies are trying to destroy the very concept of product owners…
I pay extra money for Apple computers is specifically due to these security controls. I spent decades building and running my own computers and I’m not interested in doing so anymore. I own the device that I buy, I knew how to turn off these controls and didn’t bother during the outage, and I generally refuse to do so. In return, I don’t have to deal with all the weaknesses of the liberated computing approach that yo…