Live data from Hacker News

Application trust is hard, but Apple does it well

security-embedded.com

41–50 of 213 posts

Re: Application trust is hard, but Apple does it well

#41

Earlier quoted context omitted.

Computers haven’t worked well without external dependencies in a very long time. How long can you perform useful work without DNS?

Extraordinary amounts of work are done without DNS. And even if it weren't, this is nothing like DNS because you can choose your own DNS servers and most people have a primary and a fallback. Where can I set trustd to use a different OCSP server? What is Apple's recommended secondary OCSP server?

This is a more important point than those of us talking about working offline.

A single point of failure, whether local or remote is an unfortunate design decision.

Re: Application trust is hard, but Apple does it well

#42
post #11

If this unacceptable mess is "doing it well", perhaps the whole idea is doomed and should not be attempting to do it at all. > It comes down to an argument of trust - do you trust Apple is acting in your best interests No. I mean really very obviously no. Neither Microsoft. Nor Google. Why would I assume any company would act in my interests when they have clear incentives to increase their profits and control by act…

I’m so fucking bored of this Stallman-esque stance on technology.

Don’t like, use something else.

Re: Application trust is hard, but Apple does it well

#43
post #24

I agree that app signing is good, but I disagree that we have to give in and accept the potential risks of fully trusting Apple. I think there is a practical middle way that protects non-technical users without usurping their privacy, and also a way to give same extra control to power users. I think it's fairly straightforward: - instead of OCSP use CRLs or a better technique that allows MacOS to verify locally if a…

It all comes down to configuration/choice. Its not bad to have OSCP to improve security, but there should be a simple way to turn it off (without those /etc/hosts or similar hacks).

Re: Application trust is hard, but Apple does it well

#44
post #11

If this unacceptable mess is "doing it well", perhaps the whole idea is doomed and should not be attempting to do it at all. > It comes down to an argument of trust - do you trust Apple is acting in your best interests No. I mean really very obviously no. Neither Microsoft. Nor Google. Why would I assume any company would act in my interests when they have clear incentives to increase their profits and control by act…

Where does the author belittle those who prefer a different answer?

Further, GP is outright belittling those that disagree with them with the Stockholm syndrome comment.

Re: Application trust is hard, but Apple does it well

#45
post #43
post #24

I agree that app signing is good, but I disagree that we have to give in and accept the potential risks of fully trusting Apple. I think there is a practical middle way that protects non-technical users without usurping their privacy, and also a way to give same extra control to power users. I think it's fairly straightforward: - instead of OCSP use CRLs or a better technique that allows MacOS to verify locally if a…

It all comes down to configuration/choice. Its not bad to have OSCP to improve security, but there should be a simple way to turn it off (without those /etc/hosts or similar hacks).

But I don't want to turn it off. I want to benefit from checking the revocation list without sending my data to Apple on every app start, even if I am vulnerable for a few hours, until my computer syncs the revocation list. I want a middle way, not an ON or OFF button.

Re: Application trust is hard, but Apple does it well

#46
post #23

Earlier quoted context omitted.

The internet is a malicious place, filled with the non-technical and uninformed. I guess we’ll wait for you to design a better trust-based system that allows you to stop malicious software from executing on N different machines without needing N users to do anything.

Norton Antivirus will protect me

I trust in McAfee, the software is as stable as the founder

Re: Application trust is hard, but Apple does it well

#47

Earlier quoted context omitted.

Computers haven’t worked well without external dependencies in a very long time. How long can you perform useful work without DNS?

> How long can you perform useful work without DNS? Is this a serious question? My entire dev toolchain works without internet...

Without DNS a lot of my workflows would stop workong since they include various machines/services which all communicate though hostnames/URLs rather than IP addresses, yet almost all are local to my network. So for me this is a valid question.

Re: Application trust is hard, but Apple does it well

#48
post #17

> "there are a lot of folks reasonably asking if they can trust Apple to be in the loop of deciding what apps should or should not run on their Macs. My argument is - who better than Apple?" My argument: sod off and let me decide what I want with my own hardware. Luckily I have no business case to deal with Apple products and as a private person I do not care what they do as I am not in their "ecosystem" or whatever…

So, basically, you have nothing useful to add to this conversation. You're just here to let everyone know you don't use Apple products. Cool.

Re: Application trust is hard, but Apple does it well

#49
post #11

If this unacceptable mess is "doing it well", perhaps the whole idea is doomed and should not be attempting to do it at all. > It comes down to an argument of trust - do you trust Apple is acting in your best interests No. I mean really very obviously no. Neither Microsoft. Nor Google. Why would I assume any company would act in my interests when they have clear incentives to increase their profits and control by act…

I conclude the opposite:

Yes. I mean really very obviously yes.

And Microsoft. And Google.

I assume they're acting in my interests because they have clear incentives to increase their profits by giving me useful helpful products that I'll buy.

That's the entire premise of competition and the free market. The invisible hand gives consumers what they want. If, as a company, you don't, then you go out of business.

If this were a communist country where the Party performed validation checks? With no choice between products? Then no.

But in a competitive free market? Absolutely. In fact I'm relying on their motive to increase profits in order to trust that they'll act responsibly. What can you trust more than someone else's self-interest, at the end of the day?

Post reply on HN