Live data from Hacker News

Application trust is hard, but Apple does it well

security-embedded.com

61–70 of 213 posts

Re: Application trust is hard, but Apple does it well

#61
"I always advocate against opt-outs for security features like this"

The author conveniently overlooks the fact that customers pay literally thousands of dollars for Apple computers. We're not talking about a free online service here. This is why "you no longer own your computer" has so much traction. Shouldn't we own the devices that we buy?

The tech companies are trying to destroy the very concept of product ownership, and consumers ought to fight to the end over this. It's why "right to repair" is so important too.

Re: Application trust is hard, but Apple does it well

#62
post #25
post #11

If this unacceptable mess is "doing it well", perhaps the whole idea is doomed and should not be attempting to do it at all. > It comes down to an argument of trust - do you trust Apple is acting in your best interests No. I mean really very obviously no. Neither Microsoft. Nor Google. Why would I assume any company would act in my interests when they have clear incentives to increase their profits and control by act…

Your tone here does not seem proportionally appropriate to the level of discourse this article is attempting. The fact of the matter is that computers offer myriad ways to compromise your life and behave maliciously, and avoiding that is a tall challenge for any company. Apple is trying it their way, and you can try it yours. But to call it Stockholm Syndrome is an unfortunate take on these efforts.

Can you explain why? You've offered assertions but haven't explained why you feel that way.

Re: Application trust is hard, but Apple does it well

#63
post #2

> there are a lot of folks reasonably asking if they can trust Apple to be in the loop of deciding what apps should or should not run on their Macs. My argument is - who better than Apple? ... The user?

How many users would have the ability to do something about this: https://www.theverge.com/2019/7/10/20689644/apple-zoom-web-s...

Re: Application trust is hard, but Apple does it well

#65
post #25
post #11

If this unacceptable mess is "doing it well", perhaps the whole idea is doomed and should not be attempting to do it at all. > It comes down to an argument of trust - do you trust Apple is acting in your best interests No. I mean really very obviously no. Neither Microsoft. Nor Google. Why would I assume any company would act in my interests when they have clear incentives to increase their profits and control by act…

Your tone here does not seem proportionally appropriate to the level of discourse this article is attempting. The fact of the matter is that computers offer myriad ways to compromise your life and behave maliciously, and avoiding that is a tall challenge for any company. Apple is trying it their way, and you can try it yours. But to call it Stockholm Syndrome is an unfortunate take on these efforts.

I see little to nothing in the way of discourse. Much like HN over the past few days, it's mostly a hand waving away of the reality that has always existed beneath the exterior. What doesn't help is that it's the nature of humans to fervently defend the ecosystem they've invested in.

We at HN like to hold ourselves apart from other communities, but is merely an echo chamber for what gp refers to.

Alright, let's not call it Stockholm syndrome. A "collective hypocrisy" would be more appropriate.

Re: Application trust is hard, but Apple does it well

#66
post #11

If this unacceptable mess is "doing it well", perhaps the whole idea is doomed and should not be attempting to do it at all. > It comes down to an argument of trust - do you trust Apple is acting in your best interests No. I mean really very obviously no. Neither Microsoft. Nor Google. Why would I assume any company would act in my interests when they have clear incentives to increase their profits and control by act…

> Why would I assume any company would act in my interests when they have clear incentives to increase their profits and control by acting counter to them? I get what you're saying, but (as an Apple fanboy) I have to point out that Apple's incentives are to act in your, the customer's, interests since that is what they are selling now. They are differentiating themselves from the Googles by taking user privacy seriou…

Apple is incentivized to push you towards their services—to make installing from the App Store easier than sideloading, and to make first party services more useful than third party services. Those are not my interests.

I say this not to ascribe malicious intent—I do not think Apple implemented OCSP to push people towards the App Store. But incentives are funny things, and can cause people and organizations to rationalize all sorts of decisions, and conveniently ignore some side effects and not others.

Re: Application trust is hard, but Apple does it well

#68
Apple uses their authority to revoke certificates on macOS to further their own business interests in direct conflict with those of their users [1]. They have already demonstrated that they will abuse this trust, and use it to control what software people will use on their macs in a similar way as they do on iOS.

So no, they don't do it well.

[1] https://news.ycombinator.com/item?id=24190556

Re: Application trust is hard, but Apple does it well

#69
post #61

"I always advocate against opt-outs for security features like this" The author conveniently overlooks the fact that customers pay literally thousands of dollars for Apple computers. We're not talking about a free online service here. This is why "you no longer own your computer" has so much traction. Shouldn't we own the devices that we buy? The tech companies are trying to destroy the very concept of product owners…

“You no longer own your computer” has no traction outside of ideology.

There are a few people who bring it up, and then use manipulative rhetoric:

“Shouldn’t we own the devices we buy?”

Of course, who would disagree with that! But this is manipulative because you are affirming the consequent. I.e. leading the reader into accepting the conclusion that you don’t own your computer.

“The tech companies are trying to destroy the very concept of product ownership”

This is an ideological claim with no factual basis, there are no memos or recordings supporting that anyone is trying to do this. It’s just you claiming to know the plans of ‘the tech companies’.

It could just be that Apple is trying to stop malware. Perhaps not a secret plot! Maybe there is no conspiracy!

It’s also a laughable exaggeration, as well as black and white thinking . Do you own your house? Presumably not since there are many legal restrictions on what you can do with it. Do you own your car? Presumably not, since you can’t install your own software on its computers. Do you own your toaster oven? Presumably not since you can not reprogram the microcontrollers.

Perhaps the conspiracy is deeper than I realized!

“Consumers ought to fight to the end over this”

More manipulative language. Frame things in terms of a fight between corporations and consumers, and a ‘fight to the end’.

Are you a ‘consumer’?

But more importantly, what is ‘this’? It seems like you are asking to fight over the belief that ‘Tech companies are trying to destroy the concept of product ownership’. I.e. divide people and exhort them to fight over an ideological claim you are making about intentions that you haven’t substantiated.

How about examining some of the technical issues instead of ideological rhetoric?

Here’s one: If the security features can be disabled, how can I trust a Mac I haven’t maintained custody of the whole time?

Here’s another: If people don’t want their computer software to come from Apple, they can buy something else. What is wrong with that?

I have to assume you neither own nor lease any Apple devices. Why are you trying to control what other people do?

Re: Application trust is hard, but Apple does it well

#70
The article goes over the horrors of X.509, pulls the typical open source cliche that I actually don't see anybody spreading around, contrary to the article's claim, then argues that the privacy part is fine so long as there is a third-party audit. If the best thing the security community can do is install a global mass surveillance network of devices that come at every expense of users' computing freedoms, then I think these guys need to go back to the drawing board.
Post reply on HN