I’ve given strong thought to switching away from macOS. I too have been a Max user all my life, a Macintosh Plus being the first computer in our house. I would get fed up at Apple’s hardware choices or its limitations on users. I have had a dozen Linux computers with various systems on them. I don’t know if it’s because they were Dell machines, or if it’s an Ubuntu thing, but I have had almost every single one turn i…
Ken Thompson's 75 year project: A century of popular music in a jukebox [video]
411–420 of 434 posts
Re: Ken Thompson's 75 year project: A century of popular music in a jukebox [video]
#412Earlier quoted context omitted.
Lazy in this context doesn't mean “lacks work ethic”. You might be unfamiliar with the Gates quote. Point is devs often whine when they have to take the scenic route even if it’s safer for the user. Anyway, I’m not saying they’re at odds and you can only pick one. So we seem to agree. I’m saying devs should be applauding better security and not whining about the transition away from user-domain security which is kind…
> I’m saying devs should be applauding better security and not whining about the transition away from user-domain security which is kinda what is implied in the OP. It's not better security, it's security theater. Security researchers roll out of bed in the morning and find bypasses to macOS TCC (Transparency, Consent, and Control). I've done it myself, and I'm not a professional security researcher. The so-called "s…
A fundamental design flaw in the security model or system which renders it irrelevant, on the other hand, is a problem. Are you saying there’s a fundamental flaw in Apple’s implementation of secure boot, code signatures, and sandboxing that makes it irrelevant?
Re: Ken Thompson's 75 year project: A century of popular music in a jukebox [video]
#413Earlier quoted context omitted.
> I’m saying devs should be applauding better security and not whining about the transition away from user-domain security which is kinda what is implied in the OP. It's not better security, it's security theater. Security researchers roll out of bed in the morning and find bypasses to macOS TCC (Transparency, Consent, and Control). I've done it myself, and I'm not a professional security researcher. The so-called "s…
People discover vulns all the time. A vuln is not theatre. You patch the vuln and you are secure. A vlun does not security theatre make. A fundamental design flaw in the security model or system which renders it irrelevant, on the other hand, is a problem. Are you saying there’s a fundamental flaw in Apple’s implementation of secure boot, code signatures, and sandboxing that makes it irrelevant?
Except you aren't, because there's an endless series of them.
> Are you saying there’s a fundamental flaw in Apple’s implementation of secure boot, code signatures, and sandboxing that makes it irrelevant?
I said TCC, and you said everything except TCC. (Although sandboxing is pretty insecure on the Mac too.) The fundamental design flaw is that Mac OS X started as an open system, and Apple tried to tack all of these security features on afterward, without otherwise redesigning the operating system. There are two many legacy features, including "must not break" features, too many openings, too much interoperation, too much complexity. Moreover, it often seems to me that Apple security engineers are not particularly experienced with Mac OS X, which is why an old hack like me can relatively easily find things that they've overlooked.
Re: Ken Thompson's 75 year project: A century of popular music in a jukebox [video]
#414Earlier quoted context omitted.
I think apple is degrading general purpose computing. It seems like you have to buy software to do anything on macos more conveniently. Why can't I write a script in python? or a gui script in python? it's the top language. You can use say swift, but even with "oh we opened it up", it's really an apple-specific language, and it's compiled. Yes you can get brew going, but that's not apple. and ios - what a travesty. Y…
> It seems like you have to buy software to do anything on macos more conveniently. > Why can't I write a script in python? or a gui script in python? it's the top language. You definitely don’t need to buy Python, it’s F/OSS and one command away.
Re: Ken Thompson's 75 year project: A century of popular music in a jukebox [video]
#415I was using a combination of windows/linux for a while until my archlinux laptop shit the bed after an update and I decided to say, fuck it, I'm finally buying a macbook because at least then I can still do unix shit without having to worry about everything working the next day. I'm not happy about "Apple Silicon", it does feel restrictive and often times the only way to get around it is to use licensed VMs, which fe…
Re: Ken Thompson's 75 year project: A century of popular music in a jukebox [video]
#416Earlier quoted context omitted.
People discover vulns all the time. A vuln is not theatre. You patch the vuln and you are secure. A vlun does not security theatre make. A fundamental design flaw in the security model or system which renders it irrelevant, on the other hand, is a problem. Are you saying there’s a fundamental flaw in Apple’s implementation of secure boot, code signatures, and sandboxing that makes it irrelevant?
> You patch the vuln and you are secure. Except you aren't, because there's an endless series of them. > Are you saying there’s a fundamental flaw in Apple’s implementation of secure boot, code signatures, and sandboxing that makes it irrelevant? I said TCC, and you said everything except TCC. (Although sandboxing is pretty insecure on the Mac too.) The fundamental design flaw is that Mac OS X started as an open syst…
Re: Ken Thompson's 75 year project: A century of popular music in a jukebox [video]
#417Earlier quoted context omitted.
> You patch the vuln and you are secure. Except you aren't, because there's an endless series of them. > Are you saying there’s a fundamental flaw in Apple’s implementation of secure boot, code signatures, and sandboxing that makes it irrelevant? I said TCC, and you said everything except TCC. (Although sandboxing is pretty insecure on the Mac too.) The fundamental design flaw is that Mac OS X started as an open syst…
All I'm sayings is it's kinda weird to respond to people who are trying to make a system more secure by saying "well it will never be perfect so fuck it it's just theater". I mean really? I think we agree on everything else.
This is a straw man.
Re: Ken Thompson's 75 year project: A century of popular music in a jukebox [video]
#418Earlier quoted context omitted.
The situation with Wayland is actually worse than this by far.
Not sure what you mean. But at any rate, Wayland is completely optional. You can keep running X and nobody will stop you. People will keep running X without issue for a very long time. This is very different from what the Apple world is like.
Many of the things one can at least ask permissions for as I read it on the Apple system are actually purposefully simply not available due to similar concerns.
Many of the leading Wayland developers believe in this. The Enlightenment lead developer for instance does not believe a programmatic way to make screenshots or listen to keypresses should ever exist. I had some debates with him about this and he believes the risks are too high as well as revealing that he seemed to believe that streaming videogames did not work by way of a third party tool that captures the screen contents, but that each video game had this functionality built in, which is certainly not the case and that he believes this might explain his reluctance for such an a.p.i. to facilitate this.
> But at any rate, Wayland is completely optional. You can keep running X and nobody will stop you. People will keep running X without issue for a very long time. This is very different from what the Apple world is like.
Opinions are divided on that matter. The reality is that many of the developers of Xorg have abandoned in in lieu of Wayland and many Wayland developers, many former Xorg developers are clear in their opinion that they see it as a replacement, not an alternative and eventually expect everyone to switch.
Whether that will happen is anyone's guess. They are often met with counter arguments that Xorg and the X11 protocol itself simply has features that many businesses and private individuals need for their lifelihood so there is going to be commercial incentive to pick up maintainership should they abandon it. They have also conceded heavily already on many of the features they initially said where either unneeded or a security risk when they realized the reality that many people outside of their bubble did use them. Libinput originally did not have any mouse acceleration settings on the argument that no one would want to turn it off or fine tune it to begin with, but now has it when they realized that unlike what they thought, demand for the ability to fine tune or turn off mouse acceleration is higher than they anticipated.
Re: Ken Thompson's 75 year project: A century of popular music in a jukebox [video]
#419Earlier quoted context omitted.
“keylogging” is such a moral panic. If applications can edit arbitrary files on the system it's already game over. I have no idea why people focus so much on “keylogging” as the supposed super important and dangerous thing. If one run any malware with the full file edit permissions of one's user account at that point in theory the only solution is erase not only the hard drive, but also every other drive on any other…
Oh I dunno, maybe because there's so few third party needs to log keystrokes from the user. When that need arises then you have to ask why...
The supposed threads of malicious applications keylogging and stealing your website passwords to worry about is rather strange when such an application can edit the files on your system such that you're starting a modified version of a web browser they injected with whatever code they want to do the same. In fact, this is probably easier to do than try to write some kind of a.i. that filters what it thinks are “password keypresses” opposed to altering the code of the web browser such that it simply sends whatever is being put into a field marked as “password” on a website.
It's a moral panic boogeyman that has no actual implications for actual real life security. Like quite a bit of “security” talk these days. Much of it comes down to the “door in your room” analogy where “security experts” talk about putting a big door in the middle of one's living room with an impenetrable lock on the idea of kindly asking criminals to only go through that door to steal things. In reality they'll just walk around it, and now one has an inconvenient door in the middle of one's living room.
Re: Ken Thompson's 75 year project: A century of popular music in a jukebox [video]
#420I was using a combination of windows/linux for a while until my archlinux laptop shit the bed after an update and I decided to say, fuck it, I'm finally buying a macbook because at least then I can still do unix shit without having to worry about everything working the next day. I'm not happy about "Apple Silicon", it does feel restrictive and often times the only way to get around it is to use licensed VMs, which fe…