Earlier quoted context omitted.
More than... yourself?
Yes, when it comes to keeping things secure, I honestly trust Apple more than myself (I've forgotten to lock my car upteen number of times) and my family. I am not saying that Apple is not prone to hacks, gov influence, but based on their past record, their stance on privacy - who else could be more trust worthy? Can you provide examples of whom you would trust more if you owned an iPhone to manage your phone?
Apple to kill Epic’s accounts on Friday the 28th
471–480 of 996 posts
Re: Apple to kill Epic’s accounts on Friday the 28th
#472Earlier quoted context omitted.
And so that's why I never liked nor trusted this whole idea of code signing with non-self-signed certificates, especially on desktop OSes. This notarization mechanism introduced a single point of failure: Apple. And now there is concrete evidence of how exactly this is bad. On a device I own, there should be no parties that are trusted more than myself. It's ridiculous I even have to write this.
It's important to note that you can still run unsigned Mac apps. Apple isn't preventing users from running a tool they want to run, it's just showing them a big scary warning and making them jump through some extra hoops. It's incredibly scummy and inappropriate, but I would put it more along the lines of an attack-ad than an outright ban. Edit: Now, one thing that isn't totally clear is whether or not devs who have…
The scary warning and convoluted workaround for running un–notarized apps is ostensibly to prevent non–technical people from compromising their computers. Now Apple is abusing that security mechanism for Business Reasons that have nothing to do with protecting users.
The fact that users can technically bypass it is a weak defense; if it’s an effective way to stop malware, it’s probably an effective way to prevent people from running Unreal Engine games as well.
Re: Apple to kill Epic’s accounts on Friday the 28th
#473Earlier quoted context omitted.
That advice might be feasible for the average HN reader, but what about the average person? How resistant do you think they will be against a social engineering attack telling them to disable code signing?
So let them install that malware and have their data stolen despite all warnings because they deserve it? We can't have safety nets everywhere, and we, in fact, don't. We allow everyone to drive, use knives and handle all kinds of potentially dangerous stuff every day, but for some reason can't trust them with their own phones. Some mistakes are costly, but people learn from them. Such is life.
Don't people normally get qualified to drive, controlled by the Government? Is that what you are advocating?
Re: Apple to kill Epic’s accounts on Friday the 28th
#474Earlier quoted context omitted.
> Notarization is about protecting users who are not capable of making an informed decision about code safety from developers who refuse to comply with Apple's terms of service. No, notarization is about preventing malware. That's all. This has been promised to us by Apple many many times. Malware prevention only. Fortnite is not malware.
I'm sorry, it sounds like we're saying the same thing. Notarization is not a stick-less carrot. Anyone can sign up and agree to the rules and pay the fee begin notarizing apps. If you break the rules you agree to when you sign up, you lose access to notarization. It seems like we disagree about this basic understanding, so I'll take a couple guesses at it. Are you, perhaps, arguing that Apple should not be allowed to…
At the very least such decisions should be subject to appeal to an independent board, and failing that the legal system.
Re: Apple to kill Epic’s accounts on Friday the 28th
#475Earlier quoted context omitted.
You need to re-sign it frequently because the certificate is only short-lived, and I think there are difficulties in signing existing binaries that make it mostly only useful for things you can distribute the source for. It's not really an alternative to an app store. There are also enterprise signing certificates for distributing custom apps within large companies without these restrictions, along with cases in the…
How can they shut down distribution? If a personal team can install any sourcecode, how could apple block the distribution? Even if they scan for a binary hash, all it takes are some minor modifications to have a different program to install.
- your typical user wouldn’t know what to do with it
- every install would run only for a limited time (only apps distributed through the App Store have a certificate that doesn’t expire), so those users would have to reinstall the app every week or so.
- it would make it harder for them to make money from it (they would give away the game for free. The in-game store wouldn’t give away stuff, but the source likely would soon be changed to support alternative stores)
Re: Apple to kill Epic’s accounts on Friday the 28th
#476I don’t generally like Epic, and used to be a big Apple fanboy, but in this matter, I really hope the judge tears Apple a new one, this kind of abuse of monopoly power needs to end.
Re: Apple to kill Epic’s accounts on Friday the 28th
#477What took me aback was the withdrawing permission to notarise their apps for Mac. That was only meant to be a check for known vulnerabilities/malicious software. Apple was more within their rights to kick Fortnite until the dust has settled from the iOS store, that was the retaliation, but now a mechanism supposedly for security has been repurposed as punishment. That's a pretty nasty move and I feel the mask has sli…
Epic expressly snuck code through the door to activate a user-visible feature in direct prohibition to App Store rules. Apple could have revoked their developer certificate in response, which would have essentially killed all installations of Fortnite iOS/Mac worldwide within 24 hours. That they are merely revoking their ability to sign new code and giving them 2 weeks to perform an orderly shutdown is far less draco…
Re: Apple to kill Epic’s accounts on Friday the 28th
#478Earlier quoted context omitted.
Epic expressly snuck code through the door to activate a user-visible feature in direct prohibition to App Store rules. Apple could have revoked their developer certificate in response, which would have essentially killed all installations of Fortnite iOS/Mac worldwide within 24 hours. That they are merely revoking their ability to sign new code and giving them 2 weeks to perform an orderly shutdown is far less draco…
> Notarization is about protecting users who are not capable of making an informed decision about code safety from developers who refuse to comply with Apple's terms of service. Epic willfully violated their terms with Apple to make a point, and Apple is responding in the same way that they did to Facebook: taking away their access to the users, because they cannot be trusted to comply with the restrictions placed on…
You are arguing that Apple is incorrect to assert that rulebreakers should not have privileges to deploy code to end-user devices worldwide, when the rule is not one that protects users.
Apple's counter-argument would presumably be that this business rule exists specifically to protect users from being harmed by developers, given the prevalence of "free trial" subscription scams over the past X decades of Internet marketing (and before that, TV commercials).
So, I don't buy the argument that Epic did nothing unsafe. It takes seconds to construct multiple scenarios where users have been abused by third-party payment systems, such that Apple would consider them "malicious behaviors that impact the user".
ps. There's a technicality branch here on "malware" != "malicious behaviors", but, like, malicious payment processing is implemented using software, "malware" is "malicious software", so "malware" still applies to the scenario I constructed above — and that flexibility demonstrates why "malware" is a terrible abbreviation for whatever everyone individually thinks it means.
Re: Apple to kill Epic’s accounts on Friday the 28th
#479Note that this applies to Mac systems, not just IOS. Apple is trying to prevent Unreal Engine from working on any Apple-controlled platform. So, if you're a gamer or a game developer, do not buy a Mac . Developers now using Macs need to be planning an exit strategy.
The engine is open source isn't it? They can't stop you from downloading the source and compiling it, right?
Re: Apple to kill Epic’s accounts on Friday the 28th
#480Earlier quoted context omitted.
I honestly do. Who would you trust more?
Myself. If not for IME, I could have a computer under my control, running software guaranteed to be free from the Trusting Trust attack, right now .
People like yourself can probably manage their own security, have a secure NAS, multiple firewalls, etc.
Do you see it from the perspective of average Joe (or me)?