Live data from Hacker News

Application trust is hard, but Apple does it well

security-embedded.com

181–190 of 213 posts

Re: Application trust is hard, but Apple does it well

#181
post #11

If this unacceptable mess is "doing it well", perhaps the whole idea is doomed and should not be attempting to do it at all. > It comes down to an argument of trust - do you trust Apple is acting in your best interests No. I mean really very obviously no. Neither Microsoft. Nor Google. Why would I assume any company would act in my interests when they have clear incentives to increase their profits and control by act…

> Neither Microsoft

I see more nuance here. I don't trust the Apple/MS licensing / code signing teams, but I do trust the MS defender team to do much better job. They're not directly connected to a source of profit.

Re: Application trust is hard, but Apple does it well

#182
post #2

> there are a lot of folks reasonably asking if they can trust Apple to be in the loop of deciding what apps should or should not run on their Macs. My argument is - who better than Apple? ... The user?

I was really torn on whether to up or downvote here... On the one hand, no. Probably, statistically, apple will know better. On the other hand, despite the above, if you want to call apple devices "owned" (vs "leased") then yes, the user must be the ultimate decision maker. They might want to delegate these things to apple (or someone else for that matter) most of the time. But they must have the possibility to simpl…

It's not about freedom it's about the fact that those computers cost thousands of dollars and every year Apple wants more and more control after I already gave them a huge wad of money. I am not upgrading to Big Sur, I didn't upgrade to Catalina either, but not upgrading creates its own complications in the long term.

Re: Application trust is hard, but Apple does it well

#183
post #160

Earlier quoted context omitted.

> If this unacceptable mess is "doing it well", perhaps the whole idea is doomed and should not be attempting to do it at all. Well, "unacceptable mess" are your words. It's totally acceptable to me that there could be issues on a feature / launch that need to be ironed out, unless we're talking about aviation software or pacemakers. If we deemed "unacceptable" any misstep or early issue, we wouldn't even have fire,…

Apple has been leaking OCSP app launch data in cleartext for two years. This isn’t a Big Sur release glitch.

And the world hasn’t ended. Stop fearmongering.

Re: Application trust is hard, but Apple does it well

#184
post #11

If this unacceptable mess is "doing it well", perhaps the whole idea is doomed and should not be attempting to do it at all. > It comes down to an argument of trust - do you trust Apple is acting in your best interests No. I mean really very obviously no. Neither Microsoft. Nor Google. Why would I assume any company would act in my interests when they have clear incentives to increase their profits and control by act…

> If this unacceptable mess is "doing it well", perhaps the whole idea is doomed and should not be attempting to do it at all. Well, "unacceptable mess" are your words. It's totally acceptable to me that there could be issues on a feature / launch that need to be ironed out, unless we're talking about aviation software or pacemakers. If we deemed "unacceptable" any misstep or early issue, we wouldn't even have fire,…

The author is a security specialist

In other words, an authoritarian corporate shill, just like the vast majority of others in the "security industry" whom I've had the displeasure of meeting.

Re: Application trust is hard, but Apple does it well

#185

Earlier quoted context omitted.

Mac market share is less than 10% in the US, even lower in other countries. I personally know at least one person who is considering not buying one next time around just because of this incident. Some people use tools that lock them onto a Mac, but most of that is just people that have to develop for Macs (and they’re stuck no matter what Apple does, because they need to test on Macs). The iOS/App Store monopoly argu…

> Mac market share is less than 10% in the US, even lower in other countries Do people on other platforms have so many security issues that Apple's measures are justified?

Windows may be better but any of us born before the 90s may still have PTSD from all the pain of troubleshooting malware infestations. 17 years ago I was the primary developer of a commercial Java web app and wanted nothing to do with support phone calls but on many I had to walk our web app users through the installation of Spybot Search & Destroy just so they could get rid of something interfering with their usage of our product!

I was traumatized a few weeks ago when my parents sent me a particularly jarring video of their Windows computer with audio playing telling them to call a number to get rid of something nefarious-sounding but quickly Googled it and realized it was a bunch of popup browser pop ups pretending to be worse than they were. I don’t run into stuff like that when using Firefox on my MacBook.

Re: Application trust is hard, but Apple does it well

#187
post #83
post #70

The article goes over the horrors of X.509, pulls the typical open source cliche that I actually don't see anybody spreading around, contrary to the article's claim, then argues that the privacy part is fine so long as there is a third-party audit. If the best thing the security community can do is install a global mass surveillance network of devices that come at every expense of users' computing freedoms, then I th…

It's not even that. This is a distraction from the real issue which is this technology exists not to improve the security posture but to enforce market control. So go back a few weeks and you buy a copy of Fortnite, Apple and Epic lock horns on a dispute and they revoke Epic's certificate. Next thing you get a shiny new M1 equipped Mac and go to install it and it's gone from the app store. Slightly deflated, you go b…

Yeah, if looked at in the larger context of them booting iOS apps from the app store that don't pay the 30% Apple tax for any in app payment - it's clear where they're going. It's just a boil the frog slowly strategy of making every major OS update more restrictive and trying to placate (with amazing hardware) those who complain.

Personally I drew the line at Catalina, and I think an order of magnitude more will draw the line at Big Sur.

Re: Application trust is hard, but Apple does it well

#188

Earlier quoted context omitted.

I do trust apple over a hundred different developers with random practices. I found out not long ago that a tool I was using had no hygiene practices at all - they grabbed random versions of things they packaged up, had no meaningful audit trail at all, no means to notify (or even awareness that this might be a consideration) essentially no meaningful code review and so on. I noted this because I was investigating a…

McDonald's food never makes me sick. One time I went to a different restaurant, and I found out that they had no hygiene practices at all. At least McDonald's is one step above mayhem, and it therefore is where I eat all my dinners.

That's the wrong analogy. The right analogy is Apple is acting as a restaurant inspector. They may miss a lot, but they accomplish _something_.

Re: Application trust is hard, but Apple does it well

#190
post #121

Earlier quoted context omitted.

Many invalid points, and straw men in your comment. Here are the more important ones: “The argument here is that without Apple taking control of the user's software the user would fall prey to the privacy violating practices of the likes of Google and Microsoft, which is not true. Hence the "lie by omission".” You say it’s ‘not true’. I think it’s quite likely to be true. But more importantly - it’s an argument. Not…

> He hasn’t presented any argument why he should be considered an apologist. He _ literally _ did, himself, in the article he wrote: "I think the privacy arguments are far-fetched" and actually acknowledging it verbatim : "While I'm going to sound like an Apple apologist," as in "people who say this are Apple apologists, but I'm only like one if I state it." > Many invalid points, and straw men in your comment. Of co…

I see you concede that there was no lie of omission.

You just disagree with him, but are engaging in ad hominem rather than engaging with his points.

Post reply on HN