Live data from Hacker News

Application trust is hard, but Apple does it well

security-embedded.com

141–150 of 213 posts

Re: Application trust is hard, but Apple does it well

#141
post #134
post #83

Earlier quoted context omitted.

It's not even that. This is a distraction from the real issue which is this technology exists not to improve the security posture but to enforce market control. So go back a few weeks and you buy a copy of Fortnite, Apple and Epic lock horns on a dispute and they revoke Epic's certificate. Next thing you get a shiny new M1 equipped Mac and go to install it and it's gone from the app store. Slightly deflated, you go b…

It’s about security: https://www.zdnet.com/article/apple-update-kills-off-zoom-we... As for Epic. They lied about the content of the software they uploaded to the store, and knowingly breached a contract they had signed. If that isn’t fraud, I don’t know what is. They could have sued Apple without the fraud. The certificate revocation was only about the fraudulent software update.

Yes Epic are bastards too. And Zoom. In fact these days it's wall to wall bastards.

But the end user doesn't care. They bought something and they want to keep it and use it. And that's where the buck stops.

Re: Application trust is hard, but Apple does it well

#142
post #132

Earlier quoted context omitted.

That alone isn't a justification to take away the user's rights and responsibilities. Let people make mistakes, they'll learn from it.

If they want to make painful mistakes and learn from them, they can buy a Linux box. If they don’t, they can buy a Mac. Don’t force them to choose an unsafe tool when they don’t want to.

Should we also get rid of photoshop because users could lack practice drawing and feel frustrated while trying to improve? After all they could just google a couple nice images and be done with it.

We learn from mistakes, not from success.

Re: Application trust is hard, but Apple does it well

#143
post #82

Earlier quoted context omitted.

If I bought a car knowing that is how it worked, then of course I do. Note: I agree that scenario isn’t desirable. However there is no slippery slope.

Unfortunately, there kinda is. This is what Tim Cook said about govt agencies wanting a backdoor - https://www.youtube.com/watch?v=BZmeZyDGkQ0 - right around 4:25. When I buy an Apple product, this is part of what I think Apple does to protect their customers' privacy - No matter what, not even if the govt says so. Now suddenly, we're back to talking about whether we can trust Apple after they expressly told us not t…

Don't forget that Apple is a multinational megacorp, and is user centric only when it suits them. Consider Tim Cook speaking at the conference used by the Chinese government to promote internet regulation, saying that the vision of the conference is one that Apple shares, and also the handing over of user data and encryption keys to Chinese servers (encrypted, but still out of their control).

Re: Application trust is hard, but Apple does it well

#144
post #59
post #7

Earlier quoted context omitted.

I have programmed and developed things. I am also a user. I want to run the apps I want to run, thank you very much. No one else should have any say in that. It's my computer.

Likewise, I am a developer, a user, and I have fond memories of the old days of 2003 when I could download and run whatever I wanted on my Mac without any fear or security concerns. Unfortunately, that world is no longer the one we live in. One of the things I’ve learned about software security is the need to minimise the attack surface of your systems — don’t keep a database running on your web server unless you act…

So many serious, power user-ish Mac users will just put up with SO much. That’s it.

Re: Application trust is hard, but Apple does it well

#146

Earlier quoted context omitted.

I pay extra money for Apple computers is specifically due to these security controls. I spent decades building and running my own computers and I’m not interested in doing so anymore. I own the device that I buy, I knew how to turn off these controls and didn’t bother during the outage, and I generally refuse to do so. In return, I don’t have to deal with all the weaknesses of the liberated computing approach that yo…

How would that be better than all the freedom but with good default settings? You're not forced to tinker with all controls, and if you don't agree with a default you can actually do something about it instead of saying "well, that multi-billion dollar company probably knows better what I need".

What settings are you unable to tinker with in macOS Big Sur?

Are we discussing generic theoreticals or are there actually specific settings you think you don’t have the freedom to modify?

I haven’t seen anyone say “I can’t modify this setting on Big Sur” and have that inability remain unsolved for more than an hour, yet there’s a huge ruckus about lost freedoms, so I’d love to understand where the rubber meets the road here.

Re: Application trust is hard, but Apple does it well

#147
post #132

Earlier quoted context omitted.

If they want to make painful mistakes and learn from them, they can buy a Linux box. If they don’t, they can buy a Mac. Don’t force them to choose an unsafe tool when they don’t want to.

Should we also get rid of photoshop because users could lack practice drawing and feel frustrated while trying to improve? After all they could just google a couple nice images and be done with it. We learn from mistakes, not from success.

Mistakes in the modern world can have devastating consequences. It’s not as simple as your computer freezing up and becoming part of a bot net. Your files will be stolen, your accounts hacked, you will lose money. Most users would gladly take protection from that as opposed to “learning” by making mistakes (getting infected).

Re: Application trust is hard, but Apple does it well

#148
post #11

If this unacceptable mess is "doing it well", perhaps the whole idea is doomed and should not be attempting to do it at all. > It comes down to an argument of trust - do you trust Apple is acting in your best interests No. I mean really very obviously no. Neither Microsoft. Nor Google. Why would I assume any company would act in my interests when they have clear incentives to increase their profits and control by act…

I'm entirely fine with people running "Trust" systems. But not when the platforms do it by force. If you want to pay McAfee, or some other service to force your computer to only run trusted code, then that's your choice. I might even be fine if Apple or Microsoft offered it as a service you have to pay extra for.

The problem is when one entity can lock down a platform entirely. Its a problem when its not a choice the user have. Its also a problem that even when the user wants all code to be verified, they cant choose who it gets verified by.

If yesterdays disaster had happen to a third party trust company, and not Apple, a lot of people would be looking for a new trust vendor today. Thats what should happen in a non-monopolistic market.

Re: Application trust is hard, but Apple does it well

#149
post #45

Earlier quoted context omitted.

But I don't want to turn it off. I want to benefit from checking the revocation list without sending my data to Apple on every app start, even if I am vulnerable for a few hours, until my computer syncs the revocation list. I want a middle way, not an ON or OFF button.

As this article here: https://blog.jacopo.io/en/post/apple-ocsp/ showcases, Apple doesn't send "my data" on every app start. It sends a hash of the certificate in use to Apple, which happens to be an Apple certificate that is used to sign many applications running on your system. None of your data is being sent to Apple.

Mapping developer certificates to apps is trivial. If you’re launching a Guardian Project app, for example, it’s almost certainly Tor.

Given the presence of the NSA and their ability to send NSLs or FISA warrants, this information should not be hitting the Apple network. A CRL would have been a perfectly acceptable solution.

Re: Application trust is hard, but Apple does it well

#150
post #22

Earlier quoted context omitted.

Besides the privacy implications, 99.9% means per definition that it does not work for 8.77 hours per year. This is way too much. It is my computer and it should just work how it is meant to be without any external dependencies.

This is an extremely reasonable criticism. Quite unlike most of the critiques we saw on the original post.

Wait, how is “information on which apps you are using can be determined by Apple and/or the government” not valid criticism?
Post reply on HN