Live data from Hacker News

Apple Accidentally Approved Malware to Run on macOS

wired.com

21–30 of 134 posts

Re: Apple Accidentally Approved Malware to Run on macOS

#22
post #11
post #6

It's astonishing that the developer community is fine with requiring open source projects to pay $99/yr for notarization to run on macOS. Malware authors will happily pay the developer account fees, as seen here, while open source projects are seriously hindered. It should be possible to verify developers and distribute open source apps without a cost on macOS.

What makes you thing that open source developers are fine with that? What are their other choices? Apple doesn’t care.

The choice is don't build for MacOS. In the long run Apple won't be happy with that and maybe they'll waive the fee.

Re: Apple Accidentally Approved Malware to Run on macOS

#24
post #8

Earlier quoted context omitted.

Wouldn’t you also want the ability to revoke just certain binaries? Let’s say a large company like Microsoft accidentally somehow got malware on their Excel app, you wouldn’t want to terminate the dev cert because that would also cancel Outlook, Word, PowerPoint, etc

If I'm not mistaken you can create as many code signing certificates as you want, so it makes sense to sign each application with its own certificate. Of course this wouldn't help when Apple "kills" the entire developer account I guess.

Nope, you can only generate 5 Developer ID Application certificates for the lifetime of your Developer account. It's a real pain to get another one, I had lost all of mine (didn't have a real Mac, so was using various temporary Hackintosh and KVM installs) and it took 2 months of emails to both Developer support and the Security team to get another one issued [and backed up].

Re: Apple Accidentally Approved Malware to Run on macOS

#25
post #17

Earlier quoted context omitted.

I see your point and principle , but the salary-opportunity-cost on the number of hours that the average piece of OSS takes to develop would surely dwarf 99 dollars, making that fee maybe 1% of the total effective cost.

This is simply not true. Many OS developers are working in lower income countries. Or aren't even employed yet because they are in school. Your assessment only works for working developers in high income countries. And even then requiring 99 dollars is insane.

Insane is a bit of a strong word — it seems like a reasonable way to ensure that the world isn't flooded with incredibly low-effort apps. I know, I know — the world is already full of those, but I imagine it would be a lot worse if people didn't have to put down $99.

Also, the $99 is the blanket cost to be an Apple Developer, including access to the App Store, technical support, etc. and it seems like a reasonable fee to ensure those resources aren't swamped.

It is a shame about people who can't afford it — I know Apple has a scholarship program for students but I'm sure it can't do it for everyone. I'm not saying I'm in favor of it. But it seems like there are some pretty clear reasons why this is the way it is beyond "Apple greedy".

Re: Apple Accidentally Approved Malware to Run on macOS

#26
post #6

It's astonishing that the developer community is fine with requiring open source projects to pay $99/yr for notarization to run on macOS. Malware authors will happily pay the developer account fees, as seen here, while open source projects are seriously hindered. It should be possible to verify developers and distribute open source apps without a cost on macOS.

$99/year is such a small amount relative to the costs of software development that it's hard to worry about. Meanwhile, there is good value. (The developer resources Apple provides are not free.)

You can argue that Apple should provide developer resources at no cost, but that just means someone else is paying for them or you will pay them in some other way... or do without.

I think at this point in the tech boom we can all understand that when a company gives you stuff of value at no cost there are significant tradeoffs and paybacks. In software development, I think you want most arrangements to be straightforward transactions. The strings attached to no-cost things tend to build up and cause problems, especially if you have success.

Edit: I struck a nerve, but I don't think this should be very controversial. I'll try to take the objections one at a time in comments.

Re: Apple Accidentally Approved Malware to Run on macOS

#27
post #23

The title is not justified. Nowhere in the text is it proven that it was approved by accident. It might have been an employee acting with malice aforethought

Notarization is an automated process. There's no human involved.

ah then the title is completely false

Re: Apple Accidentally Approved Malware to Run on macOS

#28
post #22
post #11

Earlier quoted context omitted.

What makes you thing that open source developers are fine with that? What are their other choices? Apple doesn’t care.

The choice is don't build for MacOS. In the long run Apple won't be happy with that and maybe they'll waive the fee.

How would that get them to waive the fee? If your app is open source and they wanted it that bad they could just build it themselves, or develop their own replacement for it, and anybody else can pound sand.

They have you over a barrel and they know it.

Re: Apple Accidentally Approved Malware to Run on macOS

#29
post #26
post #6

It's astonishing that the developer community is fine with requiring open source projects to pay $99/yr for notarization to run on macOS. Malware authors will happily pay the developer account fees, as seen here, while open source projects are seriously hindered. It should be possible to verify developers and distribute open source apps without a cost on macOS.

$99/year is such a small amount relative to the costs of software development that it's hard to worry about. Meanwhile, there is good value. (The developer resources Apple provides are not free.) You can argue that Apple should provide developer resources at no cost, but that just means someone else is paying for them or you will pay them in some other way... or do without. I think at this point in the tech boom we c…

> $99/year is such a small amount relative to the costs of software development that it's hard to worry about

Huh? Some Open Source/Free software have a $0 budget.

Re: Apple Accidentally Approved Malware to Run on macOS

#30
Apple created a process whereby applications are run through automated checks for malware in order to be approved for installation on MacOS by the public. The title is accurate. The process isn’t perfect, but human review isn’t perfect either. One issue this brings up is the false sense of security that review and approval processes such as this create among users.
Post reply on HN