Live data from Hacker News

Application trust is hard, but Apple does it well

security-embedded.com

21–30 of 213 posts

Re: Application trust is hard, but Apple does it well

#21
post #3

This is exactly my point of view on this. I've seen people complain about Apple on HN about this in all the other posts, but to be fair, this is actually a really good thing. It protects users, and it works well 99.9% of the time (actually, I am not aware of a previous outage of this system). So, why bother? It's been like this for a while, it is actually very useful to the vast majority of users, and Apple being App…

99.9% is far too unreliable for something so fundamental as whether you can run programs on your own computer, especially when the downtime is unscheduled and occurs in the middle of the day.

It should be at least five nines, preferably six nines. Anything less than that is absolutely inexcusable.

Re: Application trust is hard, but Apple does it well

#22
post #3

This is exactly my point of view on this. I've seen people complain about Apple on HN about this in all the other posts, but to be fair, this is actually a really good thing. It protects users, and it works well 99.9% of the time (actually, I am not aware of a previous outage of this system). So, why bother? It's been like this for a while, it is actually very useful to the vast majority of users, and Apple being App…

Besides the privacy implications, 99.9% means per definition that it does not work for 8.77 hours per year. This is way too much. It is my computer and it should just work how it is meant to be without any external dependencies.

This is an extremely reasonable criticism.

Quite unlike most of the critiques we saw on the original post.

Re: Application trust is hard, but Apple does it well

#23
post #11

If this unacceptable mess is "doing it well", perhaps the whole idea is doomed and should not be attempting to do it at all. > It comes down to an argument of trust - do you trust Apple is acting in your best interests No. I mean really very obviously no. Neither Microsoft. Nor Google. Why would I assume any company would act in my interests when they have clear incentives to increase their profits and control by act…

The internet is a malicious place, filled with the non-technical and uninformed.

I guess we’ll wait for you to design a better trust-based system that allows you to stop malicious software from executing on N different machines without needing N users to do anything.

Re: Application trust is hard, but Apple does it well

#24
I agree that app signing is good, but I disagree that we have to give in and accept the potential risks of fully trusting Apple. I think there is a practical middle way that protects non-technical users without usurping their privacy, and also a way to give same extra control to power users. I think it's fairly straightforward:

- instead of OCSP use CRLs or a better technique that allows MacOS to verify locally if a certificate is valid. This would preserve user privacy and wouldn't risk slowing down the user's computer in case things go wrong. It would also introduce slightly bigger risk because of the increase in the validity window, but I think that's a price worth paying. Regarding the size of the CRL's, there should be some cryptographic techniques like accumulators, bloom filters etc. that could improve the size.

- allow power users to add separate trust anchors in cases where they deem appropriate. The same way you go to Control Center to allow an app that was downloaded from the Internet to run, you could also be allowed to add another certificate from a developer you trust.

I think these 2 improvements could go a long way in restoring goodwill for Apple.

Re: Application trust is hard, but Apple does it well

#25
post #11

If this unacceptable mess is "doing it well", perhaps the whole idea is doomed and should not be attempting to do it at all. > It comes down to an argument of trust - do you trust Apple is acting in your best interests No. I mean really very obviously no. Neither Microsoft. Nor Google. Why would I assume any company would act in my interests when they have clear incentives to increase their profits and control by act…

Your tone here does not seem proportionally appropriate to the level of discourse this article is attempting.

The fact of the matter is that computers offer myriad ways to compromise your life and behave maliciously, and avoiding that is a tall challenge for any company. Apple is trying it their way, and you can try it yours. But to call it Stockholm Syndrome is an unfortunate take on these efforts.

Re: Application trust is hard, but Apple does it well

#26
post #8

Can this site maybe consider specifying a better contrasting font colour between the text and the background? On my firefox browser both on the desktop and mobile it looks like a rather light grey on white background. That is just plain difficult to read and is just terrible UX.

yeah, it's not sufficient for accessibility, ran lighthouse and outside of the title it's not ok

Re: Application trust is hard, but Apple does it well

#27
post #23
post #11

If this unacceptable mess is "doing it well", perhaps the whole idea is doomed and should not be attempting to do it at all. > It comes down to an argument of trust - do you trust Apple is acting in your best interests No. I mean really very obviously no. Neither Microsoft. Nor Google. Why would I assume any company would act in my interests when they have clear incentives to increase their profits and control by act…

The internet is a malicious place, filled with the non-technical and uninformed. I guess we’ll wait for you to design a better trust-based system that allows you to stop malicious software from executing on N different machines without needing N users to do anything.

Norton Antivirus will protect me

Re: Application trust is hard, but Apple does it well

#28
post #2

> there are a lot of folks reasonably asking if they can trust Apple to be in the loop of deciding what apps should or should not run on their Macs. My argument is - who better than Apple? ... The user?

I was really torn on whether to up or downvote here... On the one hand, no. Probably, statistically, apple will know better. On the other hand, despite the above, if you want to call apple devices "owned" (vs "leased") then yes, the user must be the ultimate decision maker. They might want to delegate these things to apple (or someone else for that matter) most of the time. But they must have the possibility to simpl…

This owned vs leased analogy is not a valid one.

The user is the ultimate decision maker - the user gets to decide whether they want MacOS or not.

The only people talking about constraining this freedom are the ones asking for the government to regulate software distribution.

What you are asking for is for Apple to make a design change to their software to support your use case.

That is a very reasonable thing to want, and to reject Apple for not providing, but it has nothing to do with some ideology of what it means to ‘own’ something.

My car has software problems I don’t like - the digital speedometer only reads kph, whereas I live in a place where mph is standard. There is no facility for changing the software.

Obviously I still own the car.

Re: Application trust is hard, but Apple does it well

#29
post #3

This is exactly my point of view on this. I've seen people complain about Apple on HN about this in all the other posts, but to be fair, this is actually a really good thing. It protects users, and it works well 99.9% of the time (actually, I am not aware of a previous outage of this system). So, why bother? It's been like this for a while, it is actually very useful to the vast majority of users, and Apple being App…

>"...and it works well 99.9%..."

Can I please have a reference confirming this number

>"...It's not like Apple is doing this to track users."

And you of course have reliable inside source who can confirm this.

Re: Application trust is hard, but Apple does it well

#30
post #10

Earlier quoted context omitted.

I was really torn on whether to up or downvote here... On the one hand, no. Probably, statistically, apple will know better. On the other hand, despite the above, if you want to call apple devices "owned" (vs "leased") then yes, the user must be the ultimate decision maker. They might want to delegate these things to apple (or someone else for that matter) most of the time. But they must have the possibility to simpl…

You shouldn't downvote things you disagree with. This place would be a lot more interesting if less people did that.

Well I said I was torn. I opted to up+comment in the end. :)

Also, I think while we're exchanging meaningless and besides-the-point platitudes: "fewer people" ;)

Post reply on HN