Live data from Hacker News

Application trust is hard, but Apple does it well

security-embedded.com

31–40 of 213 posts

Re: Application trust is hard, but Apple does it well

#31
I have trusted Apple with my phone for basically forever, but my work and personal computer going on the fritz made me seriously reconsider this relationship. I do not want my laptop to be like my cell phone. I frequently write crappy programs on my computer, and I've been totally fine with the earlier implementation of warnings unless you navigate to the application directory and explicitly open it and accept the warnings. As per the question, "Who better than Apple?", I wanna do bad all on my own. I do not have the technical ability to make a Linux laptop as good in terms of industrial design or hardware responsiveness (the touchpad on the laptop and the desktop version are the best user input devices ever for me), and that is what keeps me on their products. Otherwise, I'd be full time Linux again. I'm so confused as to whether or not to jump ship, and I feel like if I do I will be walking the plank

Re: Application trust is hard, but Apple does it well

#32
post #11

If this unacceptable mess is "doing it well", perhaps the whole idea is doomed and should not be attempting to do it at all. > It comes down to an argument of trust - do you trust Apple is acting in your best interests No. I mean really very obviously no. Neither Microsoft. Nor Google. Why would I assume any company would act in my interests when they have clear incentives to increase their profits and control by act…

Where does the author belittle those who prefer a different answer?

By posing false dichotomies: "do you trust Apple is acting in your best interests, or do you believe they're a malevolent entity?"

It's perfectly reasonable to believe that Apple is acting in Apple's best interest without attributing malevolence.

By downplaying rational arguments: "I think the privacy arguments are far-fetched (because others are worse)"

By using loaded terms: "Dogwhistles

The privacy squad mobilised"

Presenting strawmen: "if I have the code, build the code, nothing can hide in the code. This is a fallacy that people buy in to thanks to effective marketing "

Lying by omission: "It's not feasible for an individual to maintain the list of trustworthy or untrustworthy parties that Apple does."

It's perfectly feasible for a group of individuals. I'll take any group distro maintainers over Apple's word.

He really doesn't just sound like an Apple apologist; he is one.

Re: Application trust is hard, but Apple does it well

#33
post #14

Earlier quoted context omitted.

I was really torn on whether to up or downvote here... On the one hand, no. Probably, statistically, apple will know better. On the other hand, despite the above, if you want to call apple devices "owned" (vs "leased") then yes, the user must be the ultimate decision maker. They might want to delegate these things to apple (or someone else for that matter) most of the time. But they must have the possibility to simpl…

So, if they started leasing their hardware to users, it would be fine? I can see the argument, but at the same time, if they really did, I’m not sure I would agree. I also am not sure that’s completely theoretical. Apple (almost?) has the money to do so (yearly revenues about $260 billion, cash reserves about $190 billion), and I think ‘the world’ is getting used to not owning stuff more and more. Many users already…

Personally I'd be very much more fine with them honestly stating: you get a compute resource, don't expect to control it, pay a monthly fee.

Would I sign up for that? Certainly not. But if that sounds unattractive, then they should just accept that when you sell something and the buyer owns it, you don't control over anymore.

I keep pushing this distinction in DRM contexts, too. It's kinda my personal soapbox. :)

Re: Application trust is hard, but Apple does it well

#34

Earlier quoted context omitted.

Besides the privacy implications, 99.9% means per definition that it does not work for 8.77 hours per year. This is way too much. It is my computer and it should just work how it is meant to be without any external dependencies.

Computers haven’t worked well without external dependencies in a very long time. How long can you perform useful work without DNS?

Is this even serious question?

You really think I need DNS to edit my photos, videos, write some music, compile / build my products etc. etc ? And if needed for many things I can use my own DNS services. To post my freshly built product I do not need Apple's DNS. Can do with my own.

Re: Application trust is hard, but Apple does it well

#35
post #8

Can this site maybe consider specifying a better contrasting font colour between the text and the background? On my firefox browser both on the desktop and mobile it looks like a rather light grey on white background. That is just plain difficult to read and is just terrible UX.

Luckily it works with Firefox reader mode. I use that for nearly all sites that try and be different or have too many sidebars, etc.

Re: Application trust is hard, but Apple does it well

#36

Earlier quoted context omitted.

Besides the privacy implications, 99.9% means per definition that it does not work for 8.77 hours per year. This is way too much. It is my computer and it should just work how it is meant to be without any external dependencies.

Computers haven’t worked well without external dependencies in a very long time. How long can you perform useful work without DNS?

> How long can you perform useful work without DNS?

Month's on end. Is this a serious question?

Re: Application trust is hard, but Apple does it well

#37
post #23

Earlier quoted context omitted.

The internet is a malicious place, filled with the non-technical and uninformed. I guess we’ll wait for you to design a better trust-based system that allows you to stop malicious software from executing on N different machines without needing N users to do anything.

Norton Antivirus will protect me

Nortan Antivirus. Download now, free 6 month trial.

Re: Application trust is hard, but Apple does it well

#38
post #29
post #3

This is exactly my point of view on this. I've seen people complain about Apple on HN about this in all the other posts, but to be fair, this is actually a really good thing. It protects users, and it works well 99.9% of the time (actually, I am not aware of a previous outage of this system). So, why bother? It's been like this for a while, it is actually very useful to the vast majority of users, and Apple being App…

>"...and it works well 99.9%..." Can I please have a reference confirming this number >"...It's not like Apple is doing this to track users." And you of course have reliable inside source who can confirm this.

And of course downvote without having shred of evidence supporting the original claims.

Re: Application trust is hard, but Apple does it well

#39

Earlier quoted context omitted.

Where does the author belittle those who prefer a different answer?

By posing false dichotomies: "do you trust Apple is acting in your best interests, or do you believe they're a malevolent entity?" It's perfectly reasonable to believe that Apple is acting in Apple's best interest without attributing malevolence. By downplaying rational arguments: "I think the privacy arguments are far-fetched (because others are worse)" By using loaded terms: "Dogwhistles The privacy squad mobilised…

Fair points, I should have re-read it after seeing the GP’s comment.

Re: Application trust is hard, but Apple does it well

#40
post #11

If this unacceptable mess is "doing it well", perhaps the whole idea is doomed and should not be attempting to do it at all. > It comes down to an argument of trust - do you trust Apple is acting in your best interests No. I mean really very obviously no. Neither Microsoft. Nor Google. Why would I assume any company would act in my interests when they have clear incentives to increase their profits and control by act…

> Why would I assume any company would act in my interests when they have clear incentives to increase their profits and control by acting counter to them?

I get what you're saying, but (as an Apple fanboy) I have to point out that Apple's incentives are to act in your, the customer's, interests since that is what they are selling now. They are differentiating themselves from the Googles by taking user privacy seriously.

If they act against that they lose their key advantage.

Trust but verify perhaps?

Post reply on HN