Live data from Hacker News

Application trust is hard, but Apple does it well

security-embedded.com

71–80 of 213 posts

Re: Application trust is hard, but Apple does it well

#71
post #25

Earlier quoted context omitted.

Your tone here does not seem proportionally appropriate to the level of discourse this article is attempting. The fact of the matter is that computers offer myriad ways to compromise your life and behave maliciously, and avoiding that is a tall challenge for any company. Apple is trying it their way, and you can try it yours. But to call it Stockholm Syndrome is an unfortunate take on these efforts.

I see little to nothing in the way of discourse. Much like HN over the past few days, it's mostly a hand waving away of the reality that has always existed beneath the exterior. What doesn't help is that it's the nature of humans to fervently defend the ecosystem they've invested in. We at HN like to hold ourselves apart from other communities, but is merely an echo chamber for what gp refers to. Alright, let's not c…

> Alright, let's not call it Stockholm syndrome. A "collective hypocrisy" would be more appropriate.

Apple is so awesome, they have already come up with the perfect phrase you can use to describe them. It's "Reality distortion field".

Re: Application trust is hard, but Apple does it well

#72
post #23
post #11

If this unacceptable mess is "doing it well", perhaps the whole idea is doomed and should not be attempting to do it at all. > It comes down to an argument of trust - do you trust Apple is acting in your best interests No. I mean really very obviously no. Neither Microsoft. Nor Google. Why would I assume any company would act in my interests when they have clear incentives to increase their profits and control by act…

The internet is a malicious place, filled with the non-technical and uninformed. I guess we’ll wait for you to design a better trust-based system that allows you to stop malicious software from executing on N different machines without needing N users to do anything.

It’s unfortunate that this is a response to a bulveristic comment. This really is a very important problem, indeed perhaps the most important problem in computer science today.

Re: Application trust is hard, but Apple does it well

#73

Earlier quoted context omitted.

> Why would I assume any company would act in my interests when they have clear incentives to increase their profits and control by acting counter to them? I get what you're saying, but (as an Apple fanboy) I have to point out that Apple's incentives are to act in your, the customer's, interests since that is what they are selling now. They are differentiating themselves from the Googles by taking user privacy seriou…

It's not in my interest to have Apple censors control what web browser I run on my phone or what games I can play on my phone.

You aren’t their customer.

Re: Application trust is hard, but Apple does it well

#74
post #72
post #23

Earlier quoted context omitted.

The internet is a malicious place, filled with the non-technical and uninformed. I guess we’ll wait for you to design a better trust-based system that allows you to stop malicious software from executing on N different machines without needing N users to do anything.

It’s unfortunate that this is a response to a bulveristic comment. This really is a very important problem, indeed perhaps the most important problem in computer science today.

The real solution is a least privilege hardened operating system that limits the damage both in terms of malicious effects and data exfiltration/ surveillance. Exposing permissions to users is also a hard UI/UX problem.

Code signing and OCSP and such are band aids to cover the fact that our OSes have deeply inadequate security models. They all date back to the days when the net was far less hostile or in some cases before WANs were a common thing.

Web browsers run code from everywhere and do a decent but not perfect job of this. It’s possible.

Re: Application trust is hard, but Apple does it well

#75
post #19

The problem with the argument given is that it basically gives up to Apple because it thinks that the situation that Apple provides is the best default experience for the majority of users. It probably is, but the problem is that 1. Apple doesn’t really explain any of this stuff anywhere so a technical user may read about it and make an informed decision nor 2. do they really provide a way to alter the process to use…

I agree with 1 and 3 completely. I think 2 is much more complicated and the solution is not obvious, but it’s still a very valid issue, indeed I would say it is the most important issue in the industry today. However much of what I saw in the comments was none of these. Most of it was intended to dishonesty brand Apple a ‘spyware’ company, or to brand anyone who uses Apple hardware or software as a participant in som…

That may be true. But Apple themselves started us down the path of zero trust. This is what I was promised - https://www.youtube.com/watch?v=BZmeZyDGkQ0

This isn't what Apple is doing. If we're to take Apple's words that the govt agencies aren't 100% trustable just because they have a trustable setup today, why should we trust Apple just because they seem to be the good guys today?

Re: Application trust is hard, but Apple does it well

#76
post #11

If this unacceptable mess is "doing it well", perhaps the whole idea is doomed and should not be attempting to do it at all. > It comes down to an argument of trust - do you trust Apple is acting in your best interests No. I mean really very obviously no. Neither Microsoft. Nor Google. Why would I assume any company would act in my interests when they have clear incentives to increase their profits and control by act…

[deleted]

Re: Application trust is hard, but Apple does it well

#77

Earlier quoted context omitted.

Where does the author belittle those who prefer a different answer?

By posing false dichotomies: "do you trust Apple is acting in your best interests, or do you believe they're a malevolent entity?" It's perfectly reasonable to believe that Apple is acting in Apple's best interest without attributing malevolence. By downplaying rational arguments: "I think the privacy arguments are far-fetched (because others are worse)" By using loaded terms: "Dogwhistles The privacy squad mobilised…

You’re exaggerating, and then falling into the same traps you are accusing him of.

A lot to people are claiming Apple is a malevolent entity. In context, it is reasonable for him to rebut that.

I agree with you about his use of loaded terms, and the dismissiveness.

The straw man you cite isn’t a straw man. It is a solid argument. https://www.bunniestudios.com/blog/?p=5706

The lie of omission you assert isn’t a lie.

No group of distro maintainers has solved the problem Apple is solving. The author used the word ‘feasible’. This is currently true, but doesn’t need to remain so. The fact that you are technically literate enough to know about distro maintainers, and trust them does not mean it is feasible for everyone to do so.

“He really doesn’t just sound like an Apple apologist; he is one.”

If that isn’t a loaded term, I don’t know what is.

Re: Application trust is hard, but Apple does it well

#78
post #28

Earlier quoted context omitted.

I was really torn on whether to up or downvote here... On the one hand, no. Probably, statistically, apple will know better. On the other hand, despite the above, if you want to call apple devices "owned" (vs "leased") then yes, the user must be the ultimate decision maker. They might want to delegate these things to apple (or someone else for that matter) most of the time. But they must have the possibility to simpl…

This owned vs leased analogy is not a valid one. The user is the ultimate decision maker - the user gets to decide whether they want MacOS or not. The only people talking about constraining this freedom are the ones asking for the government to regulate software distribution. What you are asking for is for Apple to make a design change to their software to support your use case. That is a very reasonable thing to wan…

> Obviously I still own the car.

Do you still own the car if it'll just turn off the engines when attempt to drive into a sketchy neighbourhood?

Let's assume the car manufacturer knows the city/town's crime rates well and they have your best intentions in mind. They want you to be safe.

Do you still own the car?

Re: Application trust is hard, but Apple does it well

#79
post #19

Earlier quoted context omitted.

I agree with 1 and 3 completely. I think 2 is much more complicated and the solution is not obvious, but it’s still a very valid issue, indeed I would say it is the most important issue in the industry today. However much of what I saw in the comments was none of these. Most of it was intended to dishonesty brand Apple a ‘spyware’ company, or to brand anyone who uses Apple hardware or software as a participant in som…

That may be true. But Apple themselves started us down the path of zero trust. This is what I was promised - https://www.youtube.com/watch?v=BZmeZyDGkQ0 This isn't what Apple is doing. If we're to take Apple's words that the govt agencies aren't 100% trustable just because they have a trustable setup today, why should we trust Apple just because they seem to be the good guys today?

Whether this is what they are doing or not, is a very good argument.

For example, not end to end encrypting iCloud backups is a major problem, especially if it is at the FBI’s request.

However, this has nothing to do with the certificate server outage.

Trust is not binary, and no matter what harmful things Apple does, nothing they do justifies intellectual dishonesty and lies from their critics.

If we want to critique them, let’s critique them for the things they are actually doing, and compare them to real alternatives or technical solutions.

Re: Application trust is hard, but Apple does it well

#80

Earlier quoted context omitted.

> How long can you perform useful work without DNS? Is this a serious question? My entire dev toolchain works without internet...

Without DNS a lot of my workflows would stop workong since they include various machines/services which all communicate though hostnames/URLs rather than IP addresses, yet almost all are local to my network. So for me this is a valid question.

Could you switch DNS providers if one fails? Could you have a fallback?

What's the parallel here?

Post reply on HN