Live data from Hacker News

Application trust is hard, but Apple does it well

security-embedded.com

91–100 of 213 posts

Re: Application trust is hard, but Apple does it well

#91
post #82

Earlier quoted context omitted.

> Obviously I still own the car. Do you still own the car if it'll just turn off the engines when attempt to drive into a sketchy neighbourhood? Let's assume the car manufacturer knows the city/town's crime rates well and they have your best intentions in mind. They want you to be safe. Do you still own the car?

If I bought a car knowing that is how it worked, then of course I do. Note: I agree that scenario isn’t desirable. However there is no slippery slope.

For me, the slippery slope is exactly allowing this sort of transaction to be called "buying".

And yeah, when people lost access to their zune music, or their steam stuff, they did get upset.

Mind you, I would not outlaw the transaction. But calling it a "sale" is false advertising in my book.

Re: Application trust is hard, but Apple does it well

#92
post #69
post #61

"I always advocate against opt-outs for security features like this" The author conveniently overlooks the fact that customers pay literally thousands of dollars for Apple computers. We're not talking about a free online service here. This is why "you no longer own your computer" has so much traction. Shouldn't we own the devices that we buy? The tech companies are trying to destroy the very concept of product owners…

“You no longer own your computer” has no traction outside of ideology. There are a few people who bring it up, and then use manipulative rhetoric: “Shouldn’t we own the devices we buy?” Of course, who would disagree with that! But this is manipulative because you are affirming the consequent . I.e. leading the reader into accepting the conclusion that you don’t own your computer. “The tech companies are trying to des…

> How about examining some of the technical issues instead of ideological rhetoric?

Way ahead of you: https://news.ycombinator.com/item?id=25074959 https://news.ycombinator.com/item?id=25076588

> I have to assume you neither own nor lease any Apple devices.

This was a ludicrously bad assumption.

Re: Application trust is hard, but Apple does it well

#93
post #25

Earlier quoted context omitted.

Your tone here does not seem proportionally appropriate to the level of discourse this article is attempting. The fact of the matter is that computers offer myriad ways to compromise your life and behave maliciously, and avoiding that is a tall challenge for any company. Apple is trying it their way, and you can try it yours. But to call it Stockholm Syndrome is an unfortunate take on these efforts.

Can you explain why? You've offered assertions but haven't explained why you feel that way.

I don't follow... what did you want me to explain and what assertions are you referring to. If you mean, the assertion that Apple users are suffering Stockholm Syndrome is an inappropriate discourse, I'm not sure how to better explain that.

Re: Application trust is hard, but Apple does it well

#94
post #88
post #74

Earlier quoted context omitted.

The real solution is a least privilege hardened operating system that limits the damage both in terms of malicious effects and data exfiltration/ surveillance. Exposing permissions to users is also a hard UI/UX problem. Code signing and OCSP and such are band aids to cover the fact that our OSes have deeply inadequate security models. They all date back to the days when the net was far less hostile or in some cases b…

I’d say this is only one half. Many malicious effects involve social engineering, fraud, etc, and are not about exfiltration of files.

In that case code signing can’t do much either.

Re: Application trust is hard, but Apple does it well

#95
>I always advocate against opt-outs for security features like this [...] Because most users are not capable of evaluating the impact of opting out of a security process.

I agree fully with the author's characterizations of the dangers of disabling features or ignoring warnings, but I can't possibly agree with the conclusion that users should not be given a choice. So what if the user cannot understand the technical terms of a popup warning them about malware risk? How does that justify taking away their freedom to proceed anyway and run the program? The author's attitude is patronizing (and also intellectually dishonest as explained already by another commenter [1]).

There are lots of domains in life where we're out of our depth and make decisions anyway that might be dangerous, and we don't have anyone trying to hold or hand or to stop us altogether. Imagine you get into your Apple Car and plot a course on the GPS. The computer's voice says "there is a dangerous stretch of road on the plotted itinerary; please wait for your assigned Formula 1 driver to drive you to your destination". The car refuses to move no matter what you do. Half an hour later a small guy with a thick neck shows up, enters the car (because they've got the keys apparently) unlocks it so it can finally move and explains to you "oh yeah, a car fell down a cliff on that road back in 93". You complain about them not even apologizing for the delay. "You accepted the Terms and Conditions, didn't you?"

I get that the lack of freedom to run potentially malicious programs might be a feature, not a bug of Apple's systems. But I don't see them advertising it as what it is in practice. The notion of "false advertising" is well known and understood, but what about the notion of absence of advertising for a feature that might be unwanted to the point of making at least some potential buyers balk? Is there even a name for that?

Whether before the purchase of an Apple system or later at program startup time, the user should be able to make a decision as to whether to give Apple control of their computer in the fashion we've seen. All the necessary information and data should be provided to them. Whatever choice they make should be respected and they should not be judged for it, even if they did not understand the provided information. But the decision should not be made by some security nerd on a massive ego and power trip, imparting their enlightened guidance to "the lowest common denominator".

[1] https://news.ycombinator.com/item?id=25093906

Re: Application trust is hard, but Apple does it well

#96
post #61

"I always advocate against opt-outs for security features like this" The author conveniently overlooks the fact that customers pay literally thousands of dollars for Apple computers. We're not talking about a free online service here. This is why "you no longer own your computer" has so much traction. Shouldn't we own the devices that we buy? The tech companies are trying to destroy the very concept of product owners…

I pay extra money for Apple computers is specifically due to these security controls.

I spent decades building and running my own computers and I’m not interested in doing so anymore. I own the device that I buy, I knew how to turn off these controls and didn’t bother during the outage, and I generally refuse to do so. In return, I don’t have to deal with all the weaknesses of the liberated computing approach that you frame as the only optimal outcome.

Apple’s restrictions liberate me from having to spend time on fully-liberated computing. I’m glad liberated computing exists, but the idealistic view that all computing should be that way is harmful to my life’s priorities.

Re: Application trust is hard, but Apple does it well

#98
post #61

"I always advocate against opt-outs for security features like this" The author conveniently overlooks the fact that customers pay literally thousands of dollars for Apple computers. We're not talking about a free online service here. This is why "you no longer own your computer" has so much traction. Shouldn't we own the devices that we buy? The tech companies are trying to destroy the very concept of product owners…

I pay extra money for Apple computers is specifically due to these security controls. I spent decades building and running my own computers and I’m not interested in doing so anymore. I own the device that I buy, I knew how to turn off these controls and didn’t bother during the outage, and I generally refuse to do so. In return, I don’t have to deal with all the weaknesses of the liberated computing approach that yo…

> Apple’s restrictions liberate me from having to spend time on fully-liberated computing.

This seems to conflate restrictions with defaults.

It's reasonable for Apple to configure Macs to be safe "out of the box". But it's not clear why it helps you to prevent other Mac users from changing the defaults.

Re: Application trust is hard, but Apple does it well

#99
post #98

Earlier quoted context omitted.

I pay extra money for Apple computers is specifically due to these security controls. I spent decades building and running my own computers and I’m not interested in doing so anymore. I own the device that I buy, I knew how to turn off these controls and didn’t bother during the outage, and I generally refuse to do so. In return, I don’t have to deal with all the weaknesses of the liberated computing approach that yo…

> Apple’s restrictions liberate me from having to spend time on fully-liberated computing. This seems to conflate restrictions with defaults. It's reasonable for Apple to configure Macs to be safe "out of the box". But it's not clear why it helps you to prevent other Mac users from changing the defaults.

[deleted]

Re: Application trust is hard, but Apple does it well

#100
post #93

Earlier quoted context omitted.

Can you explain why? You've offered assertions but haven't explained why you feel that way.

I don't follow... what did you want me to explain and what assertions are you referring to. If you mean, the assertion that Apple users are suffering Stockholm Syndrome is an inappropriate discourse, I'm not sure how to better explain that.

Maybe you could start by why you think it's inappropriate?
Post reply on HN