Live data from Hacker News

Application trust is hard, but Apple does it well

security-embedded.com

191–200 of 213 posts

Re: Application trust is hard, but Apple does it well

#191
post #125

Earlier quoted context omitted.

What has this got to do with a certificate revocation server performing poorly?

Well, nothing other than certificate revocation server performing poorly has got to do anything with certificate revocation server performing poorly per se. None of your comments or mine for that matter. What is your point? We're discussing the implications of it. You're welcome to not if you think it's irrelevant.

I’m asking you how it is relevant. You seem to be avoiding giving an explanation. Is that because there isn’t a real connection?

Re: Application trust is hard, but Apple does it well

#192
post #124

Earlier quoted context omitted.

I own my Mac. I can do anything I want with it. How is that not ‘buying’?

> I can do anything I want with it. Except run software when the server gets a little smokey.

I can’t make pizza with it either. It doesn’t mean I don’t own it.

Re: Application trust is hard, but Apple does it well

#193

Earlier quoted context omitted.

Mac market share is less than 10% in the US, even lower in other countries. I personally know at least one person who is considering not buying one next time around just because of this incident. Some people use tools that lock them onto a Mac, but most of that is just people that have to develop for Macs (and they’re stuck no matter what Apple does, because they need to test on Macs). The iOS/App Store monopoly argu…

> The iOS/App Store monopoly arguments are one thing, but 10% is a monopoly now? It goes the other direction. If you want to develop for iOS you have to get a Mac even if you don't want one. Moreover, this behavior is objectionable regardless of market share, because a platform excluding alternative stores segregates that platform into a different market. If you're a developer whose customers use a Mac, and Apple sta…

That argument applies to literally any product that another business wants to built their own product on. I don’t see how that doesn’t turn into every business being required to make the business model of every other business whose products are built on theirs work in perpetuity. If you make a commercial OS, are you arguing you can’t ever remove any feature in a future version if it would make another company’s product impossible to upgrade?

Re: Application trust is hard, but Apple does it well

#194

Earlier quoted context omitted.

Mac market share is less than 10% in the US, even lower in other countries. I personally know at least one person who is considering not buying one next time around just because of this incident. Some people use tools that lock them onto a Mac, but most of that is just people that have to develop for Macs (and they’re stuck no matter what Apple does, because they need to test on Macs). The iOS/App Store monopoly argu…

Apple isn't just Macs. iPhone has 50% or greater market share in the USA. iPad has 65% or market share as well. Apple certainly does exploit a monopoly in various different ways. One is their monopoly on browser engines in iOS that lets them dictate web standards because if they don't implement something then the 1.5 billion iSO devices don't get it period.

You can always fashion a monopoly by adding “they have a monopoly on X on their own product” for any proprietary hardware or software vendor. If you want to argue that proprietary hardware or software shouldn’t be allowed then do that, but don’t try to tie it to monopoly. It has little to do with either the legal or economic implications usually associated with that word.

Re: Application trust is hard, but Apple does it well

#195
post #155

Earlier quoted context omitted.

> If this unacceptable mess is "doing it well", perhaps the whole idea is doomed and should not be attempting to do it at all. Well, "unacceptable mess" are your words. It's totally acceptable to me that there could be issues on a feature / launch that need to be ironed out, unless we're talking about aviation software or pacemakers. If we deemed "unacceptable" any misstep or early issue, we wouldn't even have fire,…

> You should read it "do you trust Apple is acting in your best interests OVER any random app you might install or website you visit?". For much of the software I use, the answer is no. I don't trust that Apple is acting in my best interests over GNU software, for example, not by a long shot. I don't even trust that I could understand if Apple is acting in my interests, because massive corporations like Apple have un…

>For much of the software I use, the answer is no. I don't trust that Apple is acting in my best interests over GNU software, for example, not by a long shot.

Well, this is half-thought though.

First, most people don't use any GNU software or even know what GNU is. And they can and do trust all kinds of BS that they shouldn't (that's how computers get filled with malware crap).

Second, GNU in this context means nothing. GNU is an organization and an assorted set of licenses, not a program, and a program being associated with GNU says nothing about the safety of the program or not. The programs themselves could still be maliciously polluted with malware as have happened time and again, unbeknownst to the authors of the programs and those running the repositories.

>Is our best shot at trusting one another to delegate that trust to a notoriously non-transparent corporation with a laundry list of conflicts of interest, obfuscated closed-source software

Well, if you're against closed-source software you shouldn't be using macOS or Windows in the first place.

>and that's operated out of a country well-known for surveilling its citizens and citizens of other countries?

The latter is a political issue, and best solved at the political level. You don't get out of a surveillance situation just by using different programs, when the whole state apparatus, sites you visit, even ISPs, etc, is used for surveillance.

Re: Application trust is hard, but Apple does it well

#196
post #11

If this unacceptable mess is "doing it well", perhaps the whole idea is doomed and should not be attempting to do it at all. > It comes down to an argument of trust - do you trust Apple is acting in your best interests No. I mean really very obviously no. Neither Microsoft. Nor Google. Why would I assume any company would act in my interests when they have clear incentives to increase their profits and control by act…

People really want to believe these corporations are charitable organizations, not inhuman slow AIs optimizing for profit. The propaganda departments of these corporations really do a number on people.

I read the article and you seem to sidestep all the arguments and facts they present, instead just saying their a brainwashed by propaganda. Not as convincing an argument, sadly.

Re: Application trust is hard, but Apple does it well

#197
post #182

Earlier quoted context omitted.

I was really torn on whether to up or downvote here... On the one hand, no. Probably, statistically, apple will know better. On the other hand, despite the above, if you want to call apple devices "owned" (vs "leased") then yes, the user must be the ultimate decision maker. They might want to delegate these things to apple (or someone else for that matter) most of the time. But they must have the possibility to simpl…

It's not about freedom it's about the fact that those computers cost thousands of dollars and every year Apple wants more and more control after I already gave them a huge wad of money. I am not upgrading to Big Sur, I didn't upgrade to Catalina either, but not upgrading creates its own complications in the long term.

I don't think the price was anything to do with it, we would be having the same discussions if it was Microsoft instead of Apple.

Re: Application trust is hard, but Apple does it well

#198
post #104
post #103

Earlier quoted context omitted.

It was also a tongue in cheek assumption. However the question I have is given your views, why?

> However the question I have is given your views, why? I came to the Mac almost 20 years ago. It was very different back then. The first decade of Mac OS X was brilliant. I felt it was the best consumer OS ever made. It was also a fairly "open" system: Mac UI on top, UNIX underneath. The second decade of Mac OS X (now macOS), has been a disaster IMO. It just keeps getting worse and worse. All of the restrictions we…

It was only like that in the first ten years because it wasn't common enough to become a malware target.

Re: Application trust is hard, but Apple does it well

#199

The Apple defenses are all over HN today. Honestly feels like astroturfing after the OCSP fiasco. If it's not astrptufing, I don't think I can understand the mindset of a consumer who feels the need to defend the world richest corporation from criticism.

It's not surprising when those customers are repeatedly criticised and insulted for buying a product they like.

It's the same as that Clinton comment about Trump voters being deplorables.

Insulting people won't change their mind, rather it entrenches their views.

Re: Application trust is hard, but Apple does it well

#200
post #95

>I always advocate against opt-outs for security features like this [...] Because most users are not capable of evaluating the impact of opting out of a security process. I agree fully with the author's characterizations of the dangers of disabling features or ignoring warnings, but I can't possibly agree with the conclusion that users should not be given a choice. So what if the user cannot understand the technical…

One of the reasons Apple has been so successful is because they make these decisions for the users. Customers were tired of their system breaking and getting malware because of confusing options and too much flexibility.
Post reply on HN