Live data from Hacker News

Apple Accidentally Approved Malware to Run on macOS

wired.com

61–70 of 134 posts

Re: Apple Accidentally Approved Malware to Run on macOS

#61
post #22

Earlier quoted context omitted.

The choice is don't build for MacOS. In the long run Apple won't be happy with that and maybe they'll waive the fee.

> In the long run Apple won't be happy with that and maybe they'll waive the fee. I think you greatly overestimate how much Apple cares about this.

I think you underestimate how many power users use macOS. Most of their privacy and security marketing isn't really targeted at normal people. The avg. person doesn't really care that much.

Re: Apple Accidentally Approved Malware to Run on macOS

#62

Earlier quoted context omitted.

When a Justice of the Peace notarises a piece of documentation, they are not vouching for authenticity they are only voicing for certain claims made: the document was presented on a certain date, and/or that this copy is an accurate facsimile of the provided original. Notarisation for macOS similarly only means, “the developer presented us with their application and their certificate of authenticity and we signed it…

> There’s no attempt by Apple to claim that the application is safe or does what it says on the tin. So that isn't part of the notarization process. It still was approved by Apple and thus was notarised. > It’s like claiming that the outcome of toasting a sandwich is approval or rejection, no the outcome of toasting a sandwich is you have a sandwich that is toasted, aka “toasted sandwich.” That's disingenuous. If I s…

If I set up a toasting service and you sent me a ham and cheese sandwich spread with Nutella, you're going to get it back toasted. That doesn't mean that I approve of that nasty sandwich filling though.

Re: Apple Accidentally Approved Malware to Run on macOS

#63
post #56
post #44

Earlier quoted context omitted.

That doesn't change the fact that developer resources cost money that has to be paid for somehow. If Apple doesn't charge developers, they could, e.g., pay for it through more margin on device sales, which means Apple customers are paying for it. That sounds nice for developers, but that's going to cause the developer resources to lose developer focus. Developer resources will be treated as marketing expenses and the…

You're taking the current Apple developer program as an eternal truth, when in fact it has changed significantly over time. Before the App Store, you could develop for the Mac completely free. There was a developer program, which was much more expensive than $99 per year, but it was mainly concerned with WWDC and pre-release builds. There was even a hardware discount for developers, which was very popular, and effect…

It’s hilarious that according to Apple fans, Apple as a $2 tn dollar company cannot afford the program it was giving away for free as a $10bn company.

Re: Apple Accidentally Approved Malware to Run on macOS

#64
post #26

Earlier quoted context omitted.

$99/year is such a small amount relative to the costs of software development that it's hard to worry about. Meanwhile, there is good value. (The developer resources Apple provides are not free.) You can argue that Apple should provide developer resources at no cost, but that just means someone else is paying for them or you will pay them in some other way... or do without. I think at this point in the tech boom we c…

Apple are a multi-trillion dollar company, they don't need more money

Apple has more money than me, hence they should give me free iPhones and Macs.

Re: Apple Accidentally Approved Malware to Run on macOS

#65
post #43

Earlier quoted context omitted.

Apple gives away Xcode and allows people to sign apps for their own iOS devices for free (although they must resign those apps every week). This is intended to allow students and other non-professional developers to learn to code and experiment with Apple developer tools without paying any money. Of course, Apple spends huge amounts of money on developer infrastructure (Xcode, LLVM, and Swift, for example). Since eac…

> Of course, Apple spends huge amounts of money on developer infrastructure (Xcode, LLVM, and Swift, for example). So then why do I have to pay them if I'm using emacs and gcc and C++? > Just because you get a given piece of open-source software for free does not mean that its development was done by volunteers in their free time. Yet, in many cases, that's exactly what happened. And even when it isn't, if it's distr…

> So then why do I have to pay them if I'm using emacs and gcc and C++?

You may still be using developer resources like documentation. But yeah, a flat fee for a wide variety of services risks edge cases where someone using only minimal resources gets a poor deal. Of course, an alternative is a nickel-and-diming pay-as-you-go micro-transaction scheme, which your main users will hate.

Also, strictly speaking, you don't have to pay them. Vote with your dollars and platform support as a developer. If enough people do, Apple may reevaluate.

Re: Apple Accidentally Approved Malware to Run on macOS

#66
post #60

Earlier quoted context omitted.

> It's astonishing that the developer community is fine with requiring open source projects to pay $99/yr for notarization to run on macOS. There is NO "requirement" for notarization. This FUD keeps getting perpetuated, but you can publish macOS software without paying $99 year. > It should be possible to verify developers and distribute open source apps without a cost on macOS. The cost is convincing your users to t…

When did this change? You need to codesign/notarize your application lest users get the super scary warning that tells them to move it to trash when they try to run it. Apple literally tells your users your app is garbage unless you pay for this. Definition of a shakedown.

Perhaps the warning could be improved.

For now, a dev has to add an explanation next to the download link, and let the users decide.

Re: Apple Accidentally Approved Malware to Run on macOS

#67
post #6

It's astonishing that the developer community is fine with requiring open source projects to pay $99/yr for notarization to run on macOS. Malware authors will happily pay the developer account fees, as seen here, while open source projects are seriously hindered. It should be possible to verify developers and distribute open source apps without a cost on macOS.

I think open source licenses are ripe for an update with the following clauses to deal with FAANG companies:

    This software shall not be used on platforms that hinder users in their free choice of software.

    This software shall not be used to create or in conjunction with adware, spyware, or other malicious software.
(Perhaps after a lawyer has reworded it properly so people can't pretend to not understand what is meant here)

Another one I'd like to see is:

    This software is free for personal use, and for commercial use by companies with an annual revenue less than $1B.

    (For commercial uses that are not covered by this license, please contact our licensing department)

Re: Apple Accidentally Approved Malware to Run on macOS

#68
post #61

Earlier quoted context omitted.

> In the long run Apple won't be happy with that and maybe they'll waive the fee. I think you greatly overestimate how much Apple cares about this.

I think you underestimate how many power users use macOS. Most of their privacy and security marketing isn't really targeted at normal people. The avg. person doesn't really care that much.

It’s pretty impressive that Ubuntu and Arch (Power User-only experiences in my mind) are considered an alternative to macOS by anyone at all. It shows the Linux desktop is actually delivering something very valuable despite the numbers. Although that the numbers don’t tell the whole story isn’t really saying much.

What if it turned out that ease of use and OS-wide app consistency was the easy part all along? That building good APIs - which includes not changing them, making a good publishing experience - which includes not changing your rules every six months, and making your developers rich - which includes lowering fees - were the hard parts?

Besides the average person does care about privacy and security. Keychain is a product everyone on macOS and iOS uses. Imagine if the OS forced Private Browsing to actually work.

Re: Apple Accidentally Approved Malware to Run on macOS

#69
post #6

It's astonishing that the developer community is fine with requiring open source projects to pay $99/yr for notarization to run on macOS. Malware authors will happily pay the developer account fees, as seen here, while open source projects are seriously hindered. It should be possible to verify developers and distribute open source apps without a cost on macOS.

> It's astonishing that the developer community is fine with requiring open source projects to pay $99/yr for notarization to run on macOS. There is NO "requirement" for notarization. This FUD keeps getting perpetuated, but you can publish macOS software without paying $99 year. > It should be possible to verify developers and distribute open source apps without a cost on macOS. The cost is convincing your users to t…

> you can publish macOS software without paying $99 year.

Can you point to straightforward apple instructions for doing so?

I publish an open source project used in classrooms, mostly used by my own students but also others. Despite strong and principled objections, which I hung on to for years, I have simply given up and now pay the fee. I'd love to not have apple be the gatekeeper. But they are. Every release, every update, every summer when I go to fix a few bugs, the restrictions get tighter and tighter, and old workarounds stop working.

I work entirely on Linux and Win10, but I maintain a mac laptop and pay the $99/yr out of pocket just to keep this project alive. I've spent tens of days trying to find a way around either of these requirements, but it's just too difficult (for me, or for my students, or for others wanting to try my software).

Re: Apple Accidentally Approved Malware to Run on macOS

#70
post #18

Earlier quoted context omitted.

What else is the scanning of an uploaded executable than an (automated) review process though? The notarization process wouldn't be needed to implement a "kill-switch" for executables by revoking the certificate (code signing with an Apple certificate was required long before notarization). If anything, the notarization creates an illusion of security for the user which might be worse than an unsigned executable (bec…

> What else is the scanning of an uploaded executable than an (automated) review process though? It's a pass of checks that might or might not find something. It's not some official stamp of approval, except to say "those checks passed ok".

Notarized apps are allowed to run by macOS Gatekeeper. Non-notarized apps are rejected by macOS Gatekeeper. You can quibble about the word "approved", but notarization is very important nonetheless.
Post reply on HN