Live data from Hacker News

Application trust is hard, but Apple does it well

security-embedded.com

161–170 of 213 posts

Re: Application trust is hard, but Apple does it well

#161
post #11

If this unacceptable mess is "doing it well", perhaps the whole idea is doomed and should not be attempting to do it at all. > It comes down to an argument of trust - do you trust Apple is acting in your best interests No. I mean really very obviously no. Neither Microsoft. Nor Google. Why would I assume any company would act in my interests when they have clear incentives to increase their profits and control by act…

I'm entirely fine with people running "Trust" systems. But not when the platforms do it by force. If you want to pay McAfee, or some other service to force your computer to only run trusted code, then that's your choice. I might even be fine if Apple or Microsoft offered it as a service you have to pay extra for. The problem is when one entity can lock down a platform entirely. Its a problem when its not a choice the…

This plays into why Google is so big, doesn't it? Where by offering immensely valuable things (like trust[0], video hosting[1]) for free, people are willing to give up a host of freedoms assuming it doesn't directly impact them/the apps they use (which is most often doesn't, with the exception being Fortnite, and even then it just becomes another topic for reddit to have flame wars about).

0: https://www.marketwatch.com/press-release/global-antivirus-s...

1: https://www.theverge.com/2020/10/29/21531711/google-alphabet...

Re: Application trust is hard, but Apple does it well

#162
post #11

If this unacceptable mess is "doing it well", perhaps the whole idea is doomed and should not be attempting to do it at all. > It comes down to an argument of trust - do you trust Apple is acting in your best interests No. I mean really very obviously no. Neither Microsoft. Nor Google. Why would I assume any company would act in my interests when they have clear incentives to increase their profits and control by act…

> Why would I assume any company would act in my interests when they have clear incentives to increase their profits and control by acting counter to them?

Even without perverse incentives, why would another agent in your environment have any reason to go out of their way to have your best interest at heart?

Re: Application trust is hard, but Apple does it well

#163
post #122
post #119

Earlier quoted context omitted.

How can revoking apps stop a phishing attack?

Easy: Revoke the certificate of the app doing the phishing.

To add, this is exactly what google's safe browsing is https://safebrowsing.google.com/

Re: Application trust is hard, but Apple does it well

#164
post #11

If this unacceptable mess is "doing it well", perhaps the whole idea is doomed and should not be attempting to do it at all. > It comes down to an argument of trust - do you trust Apple is acting in your best interests No. I mean really very obviously no. Neither Microsoft. Nor Google. Why would I assume any company would act in my interests when they have clear incentives to increase their profits and control by act…

I conclude the opposite: Yes. I mean really very obviously yes. And Microsoft. And Google. I assume they're acting in my interests because they have clear incentives to increase their profits by giving me useful helpful products that I'll buy . That's the entire premise of competition and the free market. The invisible hand gives consumers what they want. If, as a company, you don't, then you go out of business. If t…

Tobacco.

Re: Application trust is hard, but Apple does it well

#165
post #124

Earlier quoted context omitted.

For me, the slippery slope is exactly allowing this sort of transaction to be called "buying". And yeah, when people lost access to their zune music, or their steam stuff, they did get upset. Mind you, I would not outlaw the transaction. But calling it a "sale" is false advertising in my book.

I own my Mac. I can do anything I want with it. How is that not ‘buying’?

> I can do anything I want with it.

Except run software when the server gets a little smokey.

Re: Application trust is hard, but Apple does it well

#166
post #159
post #139

Earlier quoted context omitted.

If you are someone who wants and understands how to use a machine with disabled security features, it obviously doesn’t help to have the defaults be unchangable. For everyone else, it is a very important safeguard against social engineering attacks.

People are social engineered over the phone all the time. Maybe they shouldn't be allowed to have phones or answer phone calls.

“Maybe they shouldn’t be allowed to have phones or answer calls”

Nobody is saying this. This is the same kind of misleading rhetoric you used earlier.

The fact that people are socially engineered over the phone just proves there is a demand for a solution.

You seem to want to deny people a solution.

There is definitely a demand for a phone service that filters out scam calls, or for service providers to do something to prevent them.

Re: Application trust is hard, but Apple does it well

#167
post #2

> there are a lot of folks reasonably asking if they can trust Apple to be in the loop of deciding what apps should or should not run on their Macs. My argument is - who better than Apple? ... The user?

> ... The user? As someone who works in IT: not for most users. Certainly not for any of my relatives, as successful/smart as they may be in other fields. Certainly have manual overrides for Alpha Geeks (to use O'Reilly's term), but even if a person is on the right-hand side of the Bell curve generally, that doesn't necessarily mean they can make informed software decisions specifically. I'm fine with automatic seatb…

Then the fake tech support call center scammers just add having the user enter that command to their script. This is why 1TR became a thing, I imagine.

Re: Application trust is hard, but Apple does it well

#168

Earlier quoted context omitted.

I'm entirely fine with people running "Trust" systems. But not when the platforms do it by force. If you want to pay McAfee, or some other service to force your computer to only run trusted code, then that's your choice. I might even be fine if Apple or Microsoft offered it as a service you have to pay extra for. The problem is when one entity can lock down a platform entirely. Its a problem when its not a choice the…

Mac market share is less than 10% in the US, even lower in other countries. I personally know at least one person who is considering not buying one next time around just because of this incident. Some people use tools that lock them onto a Mac, but most of that is just people that have to develop for Macs (and they’re stuck no matter what Apple does, because they need to test on Macs). The iOS/App Store monopoly argu…

> The iOS/App Store monopoly arguments are one thing, but 10% is a monopoly now?

It goes the other direction. If you want to develop for iOS you have to get a Mac even if you don't want one.

Moreover, this behavior is objectionable regardless of market share, because a platform excluding alternative stores segregates that platform into a different market. If you're a developer whose customers use a Mac, and Apple starts operating the Mac App Store the same as the iOS one, it doesn't matter that they have 10% market share because that 10% of the PC market is 100% of your app customers and the relevant market isn't PCs, it's app distribution to a given customer base.

Re: Application trust is hard, but Apple does it well

#169
post #11

If this unacceptable mess is "doing it well", perhaps the whole idea is doomed and should not be attempting to do it at all. > It comes down to an argument of trust - do you trust Apple is acting in your best interests No. I mean really very obviously no. Neither Microsoft. Nor Google. Why would I assume any company would act in my interests when they have clear incentives to increase their profits and control by act…

> If this unacceptable mess is "doing it well", perhaps the whole idea is doomed and should not be attempting to do it at all. Well, "unacceptable mess" are your words. It's totally acceptable to me that there could be issues on a feature / launch that need to be ironed out, unless we're talking about aviation software or pacemakers. If we deemed "unacceptable" any misstep or early issue, we wouldn't even have fire,…

> You should read it "do you trust Apple is acting in your best interests OVER any random app you might install or website you visit?".

But it isn't that. That would be the argument for choosing to install apps through Apple's store, not for Apple preventing you from choosing to install apps through a competing store.

Because then it's not Apple vs. literally every random shady garbage app, it's Apple vs. some specific alternative store that you might very well trust more than Apple to be acting in your interest, e.g. F-Droid.

Re: Application trust is hard, but Apple does it well

#170

Earlier quoted context omitted.

I'm entirely fine with people running "Trust" systems. But not when the platforms do it by force. If you want to pay McAfee, or some other service to force your computer to only run trusted code, then that's your choice. I might even be fine if Apple or Microsoft offered it as a service you have to pay extra for. The problem is when one entity can lock down a platform entirely. Its a problem when its not a choice the…

Mac market share is less than 10% in the US, even lower in other countries. I personally know at least one person who is considering not buying one next time around just because of this incident. Some people use tools that lock them onto a Mac, but most of that is just people that have to develop for Macs (and they’re stuck no matter what Apple does, because they need to test on Macs). The iOS/App Store monopoly argu…

> Mac market share is less than 10% in the US, even lower in other countries

Do people on other platforms have so many security issues that Apple's measures are justified?

Post reply on HN