Live data from Hacker News

Application trust is hard, but Apple does it well

security-embedded.com

51–60 of 213 posts

Re: Application trust is hard, but Apple does it well

#51
post #8

Can this site maybe consider specifying a better contrasting font colour between the text and the background? On my firefox browser both on the desktop and mobile it looks like a rather light grey on white background. That is just plain difficult to read and is just terrible UX.

Thanks to uMatrix, this site just renders as a completely blank page. Fortunately Reader Mode can pull the text out in a perfectly readable format.

Re: Application trust is hard, but Apple does it well

#53
post #11

If this unacceptable mess is "doing it well", perhaps the whole idea is doomed and should not be attempting to do it at all. > It comes down to an argument of trust - do you trust Apple is acting in your best interests No. I mean really very obviously no. Neither Microsoft. Nor Google. Why would I assume any company would act in my interests when they have clear incentives to increase their profits and control by act…

People really want to believe these corporations are charitable organizations, not inhuman slow AIs optimizing for profit. The propaganda departments of these corporations really do a number on people.

Re: Application trust is hard, but Apple does it well

#54
post #38
post #29

Earlier quoted context omitted.

>"...and it works well 99.9%..." Can I please have a reference confirming this number >"...It's not like Apple is doing this to track users." And you of course have reliable inside source who can confirm this.

And of course downvote without having shred of evidence supporting the original claims.

You're getting downvoted because your comment seems like trolling.

The reason it seems like trolling is that the information you're demanding "evidence" for is:

- the number of elapsed hours since October 7, 2019, when Catalina was released and OCSP became mandatory

- the number of hours of outage the other day

- how division works

None of these seem to be fairly in dispute.

Re: Application trust is hard, but Apple does it well

#55
post #11

If this unacceptable mess is "doing it well", perhaps the whole idea is doomed and should not be attempting to do it at all. > It comes down to an argument of trust - do you trust Apple is acting in your best interests No. I mean really very obviously no. Neither Microsoft. Nor Google. Why would I assume any company would act in my interests when they have clear incentives to increase their profits and control by act…

> Why would I assume any company would act in my interests when they have clear incentives to increase their profits and control by acting counter to them? I get what you're saying, but (as an Apple fanboy) I have to point out that Apple's incentives are to act in your, the customer's, interests since that is what they are selling now. They are differentiating themselves from the Googles by taking user privacy seriou…

It's not in my interest to have Apple censors control what web browser I run on my phone or what games I can play on my phone.

Re: Application trust is hard, but Apple does it well

#56
post #14

Earlier quoted context omitted.

So, if they started leasing their hardware to users, it would be fine? I can see the argument, but at the same time, if they really did, I’m not sure I would agree. I also am not sure that’s completely theoretical. Apple (almost?) has the money to do so (yearly revenues about $260 billion, cash reserves about $190 billion), and I think ‘the world’ is getting used to not owning stuff more and more. Many users already…

Personally I'd be very much more fine with them honestly stating: you get a compute resource, don't expect to control it, pay a monthly fee. Would I sign up for that? Certainly not. But if that sounds unattractive, then they should just accept that when you sell something and the buyer owns it, you don't control over anymore. I keep pushing this distinction in DRM contexts, too. It's kinda my personal soapbox. :)

The issue I have with this, is that anyone who is technical enough to install an operating system from source, must necessarily have an understanding what hardware they will be able to install it on. I’m curious if you have ever done this.

No such person would have any illusion about what Mac hardware they could use.

Everyone else, reasonably expects Apple to take care of the OS for them. Indeed that is arguably the selling point and key differentiator of the Mac.

Nobody is misled.

See elsewhere where I respond to the distinction you are making about ownership: https://news.ycombinator.com/item?id=25093873

Re: Application trust is hard, but Apple does it well

#57
post #8

Can this site maybe consider specifying a better contrasting font colour between the text and the background? On my firefox browser both on the desktop and mobile it looks like a rather light grey on white background. That is just plain difficult to read and is just terrible UX.

Agreed, the entire article text looks like what you’d use for a greyed out option to de-emphasize it.

Re: Application trust is hard, but Apple does it well

#58
post #2

> there are a lot of folks reasonably asking if they can trust Apple to be in the loop of deciding what apps should or should not run on their Macs. My argument is - who better than Apple? ... The user?

> ... The user?

As someone who works in IT: not for most users. Certainly not for any of my relatives, as successful/smart as they may be in other fields.

Certainly have manual overrides for Alpha Geeks (to use O'Reilly's term), but even if a person is on the right-hand side of the Bell curve generally, that doesn't necessarily mean they can make informed software decisions specifically.

I'm fine with automatic seatbelts as long as there's a Terminal.app command I can run to disable them on an as-needed basis.

Re: Application trust is hard, but Apple does it well

#59
post #7
post #5

Earlier quoted context omitted.

Anyone who has programmed or developed anything....knows that the end user can never be trusted.

I have programmed and developed things. I am also a user. I want to run the apps I want to run, thank you very much. No one else should have any say in that. It's my computer.

Likewise, I am a developer, a user, and I have fond memories of the old days of 2003 when I could download and run whatever I wanted on my Mac without any fear or security concerns.

Unfortunately, that world is no longer the one we live in.

One of the things I’ve learned about software security is the need to minimise the attack surface of your systems — don’t keep a database running on your web server unless you actually need it, don’t keep ports open unless they’re important, don’t install packages or dependencies you can do without — because everything has the potential for a zero-day exploit. Likewise for my own productive output: the only code guaranteed to be bug free is the absence of code.

For any computer not attached to the public internet, I agree that you should be free to run whatever you want. For anything networked? That’s anarchy, and although I would like the freedom of anarchy I experienced in 2003, unfortunately I don’t like the consequences of everyone else having the freedoms of anarchy in 2020.

I don’t have any fun, easy, side-effect free, solutions.

Re: Application trust is hard, but Apple does it well

#60

Earlier quoted context omitted.

> Why would I assume any company would act in my interests when they have clear incentives to increase their profits and control by acting counter to them? I get what you're saying, but (as an Apple fanboy) I have to point out that Apple's incentives are to act in your, the customer's, interests since that is what they are selling now. They are differentiating themselves from the Googles by taking user privacy seriou…

It's not in my interest to have Apple censors control what web browser I run on my phone or what games I can play on my phone.

This is irrelevant to the topic at hand.
Post reply on HN