Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

We are here, ladies and gentlemen.

    Users have three choices which type of apps can run on Mountain Lion:

      Only those from the App Store
      Only those from the App Store or which are signed by a developer ID
      Any app, whether signed or unsigned

   The default for this setting is, I say, exactly right: the one in 
   the middle, disallowing only unsigned apps.


Interesting. Let's say I'm a developer writing a Bittorrent client. Do I leave it unsigned and get lower adoption because people are afraid of malware, or do I sign it and hope that Apple doesn't someday revoke my key?

Of course, Apple could have done this before. They could push out an OS update that wiped an app from everyone's computers. But that was a huge undertaking and now they have a process that is generally accepted from the App Store, and I wouldn't be surprised if we start to see it more regularly.

Edit: Apple wouldn't even have to be against Bittorrent clients. They could just get sued by record labels and lose, and then a judge would say "You built the capability to remotely disable apps, so use it to disable this one."


Practically speaking, I don't see this being much of a problem. If Apple does disable your app, but your app is not malicious and users actually want it, they can just return to your site and download an unsigned version. This would be a minor annoyance to your users, but if you are having the kinds of troubles that cause Apple to disable your app, you probably have much bigger things to worry about than a few thousand customers downloading your app again.


Are you making the assumption that people would be afraid of your application because it could potentially be malware, or because they don't want to switch to the third mode? If it's the latter, I hope the control is on an individual applications basis so that I am alerted about other unsigned applications even after having allowed yours.

If it's about the first, I think the users who can get a Bittorrent client up and running (and have an interest in it, in the first place) are also able to read reviews and ask friends who may have recommended them this application.


We're not quite here yet. I think a better version of Gatekeeper would offer:

      Only those from Trusted Sources
      Only those from Trusted Sources or which are signed by a developer ID
      Any app, whether signed or unsigned
Where "trusted sources" is something that future Gatekeeper would give you control over.

Enterprises spend a ridiculous amount of effort in locking down and pushing out software to workstations, so allowing them to maintain their own code-signed internal "app store" could be game changing. Apple has almost no enterprise presence, and this could be an opportunity for them to steal market share from Microsoft, who lately appears directionless and out of touch.


Apple has an enterprise version[1] of the iOS App Store available. I'd wager that an equivalent for the Mac App Store is pretty likely.

[1] https://developer.apple.com/programs/ios/enterprise/


This is a preference in system preferences that is pretty easy to change. I don't think it's entirely unreasonable to say that if you can't figure out how to change it, you probably would have trouble figuring out what's safe to install on your computer anyway. You'd also probably have trouble finding things to install on your computer that you didn't get at best buy (would be signed anyway), through the app store (would be signed anyway), or through a malicious site trying to get you to install some fake virus scan scam (wouldn't want).

But it's not going to slow down developers, or even kids who like to explore.


Edit: Actually it looks like I may be mistaken about this. There is some confusion in the press currently about whether a paid developer program will be required for obtaining signing keys. If not, this is only a minor encroachment of control.

> This is a preference in system preferences that is pretty easy to change.

That doesn't matter. It means that if I want people to use my software, I will now have no choice but to join Apple's $99/year Mac Developer program.

Time to port to Linux/Windows.


FTA: "It’s a system whereby developers can sign up for free-of-charge Apple developer IDs which they can then use to cryptographically sign their applications."


Yes, as I noted in my edit, there seems to be some confusion about this in the media. Some sources are saying that you will have to be a member of the Mac Developer Program (which costs $99/year), while others are saying the signing service is free of charge.

Here's Apple's own page on the matter: http://www.apple.com/macosx/mountain-lion/security.html

> Apple wants to help you steer clear of malware even when you download applications from places other than the Mac App Store. That’s why Apple created the Developer ID. As part of the Mac Developer Program, Apple gives developers a unique Developer ID for signing their apps.

This seems strongly to imply that a Mac Developer Program membership is required for code signing.

I very much hope that their phrasing is merely imprecise, and if not, that they will change their minds and provide free signing. I love OS X as a development program, but I will leave it behind if they start down this path.


I've never understood this for a second. Xcode only runs on the Mac OS, and the Mac OS only runs (without hassle) on exceptionally expensive computers. What is $99 more per year to get a signing enrollment? Who gives a fuck about the $100? You're building apps on a $1700 laptop while sipping a $6 coffee in your $2000/month apartment, for fuck's sake.

Why waste time being outraged about something unimportant when you could be BUILDING SHIT?


Right now, the next generation of hackers is around twelve years old and screwing around on computers they can't afford, which is only possible because their parents found having a computer around (unlike a gilt-edged DRM key) to be useful for other things. Anyone who can't start until they can afford their own is is probably going to be a dud. This is yet another reason we should be alarmed and offended over trends that make the world more hostile to tinkerers.


> Who gives a fuck about the $100?

FOSS and freeware developers, I imagine.

>You're building apps on a $1700 laptop while sipping a $6 coffee in your $2000/month apartment, for fuck's sake.

Sorry, no I'm not. I'm scraping by on a laptop that cost $1100 when I bought it six years ago. My living situation is... let's just say that you're just a tad north of reality. I was making an OK living off of some shareware I wrote until Apple pulled the rug out from under its smaller developers with last year's App Store transition. $100 is not a hardship, but it is a significant chunk of change.

Now, with that all out of the way, that's not actually the point. The point is what this does to people just starting out. Consider how much free/cheap software there is out there because somebody took their little weekend project and decided to pop it up on the web. Now consider what proportion of those people are going to take that leap if they have to pay a hundred bucks for practically anyone to be able to use it. Do you think any of them will be willing to put it out there for free under those conditions?


Everyone's focusing on this switch, but the switch isn't the real issue. As many have pointed out, there's no reason Apple wouldn't want to leave it around indefinitely.

If I were a Mac developer with a skepticism about Apple's increasingly tight grip on their platform, I'd be much more concerned about the widening circle of APIs that are unavailable to non-App Store apps.


You're right that the rise of Mac App Store-only APIs is more troubling. This is a "boil the frog slowly" trick. Today, you can run all the unapproved software you want, but, someday, if Apple makes the APIs compelling enough, you won't want to.

That being said, it isn't like the switch (and its parameters) and the development of Mac App Store-only APIs can't be trends that reinforce each other, of course.


Is this just iCloud, or something else? Needing to be in the app store (or signed) to use iCloud makes perfect sense to me. If you don't want to do that, simply use Dropbox -- which works better anyway (at the moment).


This seems to me like a good feature, one that finds an actual good use for code signing on OS X. What's the issue?


The issue is that Apple is the only certification authority.


There is no other reasonable way to implement that feature that would scale across Apple's customer base. If you don't like it, they provided the third option ("Ignore all this code signing stuff").


There is a way. Allow at least one more certification authority. Let, say, Verisign sell code signing certificates for OS X. This will ensure that Apple is not the only party in control of which software runs on Macs.

I have the third option, but I will also have to explain this option to the users of my software. Plus, the option is not granular -- it seems like you cannot disallow all unsigned software, but make exceptions.


This feature would not be better if the sewer vampires that run the SSL CAs got to control it.


What moral argument are you using where Apple comes out on top and SSL CAs don't?


Is that a serious question?

Here, let's try just one response and you just (safely) assume that it stands in for a myriad of other similarly horrible issues:

Likelihood that Apple will sell its CA root key to an unnamed Fortune 500 company under NDA to make some kind of software rollout problem simpler for them at the expense of the security of every Mac computer in the world? Zero.

Likelihood that an SSL CA will, after sucking the intestines out of a freshly killed puppy dog using its razor sharp SSL CA proboscis, sell its CA root key to an unnamed Fortune 500 company under NDA to make some kind of software rollout problem simpler for them at the expense of the security of every Mac computer in the world? Not zero. Not close to zero.


1. Will it prevent Apple from controlling which software runs on Macs? Yes.

2. Will the code signing scheme be more vulnerable to malware because of the third-party CA? _____ (fill in)


   2. ___ YES ___


I agree. But it's still better than letting Apple be the only CA. Would you like to have a single CA for TLS?


Huh? It is the opposite of better.


> Let, say, Verisign sell code signing certificates for OS X.

How many security breaches has Verisign had? Allowing 3rd party authorities to issue certificates would simply weaken the security that the feature provides. Moreover, it would mean that Apple cannot revoke the certificates, defeating the entire point of the feature.

> it seems like you cannot disallow all unsigned software, but make exceptions.

That would be a pretty broken feature. The only ways for OS X to handle that would be for it to say "screw it, I don't care what's in this specific directory, you can run it", which means that the directory becomes a vector for malware, or to disallow updating the directory once you exclude it, so that the OS can be sure that what you allowed is actually what's running. Both of these are pretty terrible options.


I'm glad that you tried to install your own and failed. I wasn't convinced by second hand knowledge of a marketing presentation.


Well, there were signals that something would change as soon as Apple launched the App Store for OS X. I think having signed developer ID's, with the option of allowing unsigned, is an OK step and might even bode for a more open iOS platform ... down the line.

All in all, of the two ways it was likely to go (allowing only App Store apps by default, or allowing only signed Apps that meeting certain criteria), I think this is the much more palatable one.


Say I use my Macbook for development, and I compile a small toy C program using gcc. Does that mean now that I cannot run the produced binary by default?

Forgive me for being naive, but what does "app" mean in this context? Is a shell script an app? What about a python script with GUI elements?


Nope, you'll be able to run it: "Finally, it’s important to note that because Gatekeeper uses the File Quarantine system, it only works the very first time you try to launch an app, and even then only when it’s been downloaded from an app on your Mac like a web browser or email program. And once an app has been launched once, it’s beyond the reach of Gatekeeper." (http://www.macworld.com/article/165408/2012/02/mountain_lion...)


No, it does not mean that.


Sources?


The actual article you just read, for one.

The way code signing is implemented today, for another.


C|Net reports you can override Gatekeeper on an app by app basis (even at the most restrictive setting), so as long as you trust yourself you're good:

"It's also been designed to let you manually override the protection measures and install something that hasn't been signed, even if your settings are turned all the way up to App Store only."


Even if this is the case I believe this would mean that the third setting will allow you to run anything just fine, but I believe this will only apply to .app folders that are the bundled applications.


Good question. I can't see this just yet, but it will happen. Probably by 10.9 which won't even have a command prompt -- or at least not one you can access easily without invalidating warranty or some such nonsense.


Why do you feel the need to be so overdramatic? You don't seriously believe that do you? Many users regularly need access to the Terminal. Developers for one user it all the time. I use it for git. Many people (including non-developers) use vi. People run scripts from it and use it for automation.


Yeah, or 10.30, which will not even have a UI, just an OS-to-Mind interface.

Can we please stop repeating BS?

People like to make it sound like some kind of slippery slope, but including Mountain Lion, NOTHING has been taken away from users re: freedom, from OS X 10.0.1 to 10.8.

In addition to running whatever from whatever, 10.7 gave you the option to use an App repository. You know, like the one, say, Debian had from decades, only not restricted to OSS.

In addition to running whatever from whatever AND from the App Store, 10.8 adds the ability to only run signed apps. You, know, like the security solution that is considered one of most effective ones by security boffins.


> NOTHING has been taken away from users re: freedom, from OS X 10.0.1 to 10.8.

Well, no, that's not quite true. See also: PTRACE_DENY_ATTACH in random binaries (e.g. iTunes) and the gimped DTrace implementation.

Are these showstoppers or the end of freedom as we know it? Not be a long, long way. Are they (fairly small) limitations on the freedom of users? Yes.


Introducing new features that aren't completely open is not the same as taking away existing freedoms.


Some inline context - this appears to be about protecting against malicious software. Was always going to catch flak :)

http://www.apple.com/macosx/mountain-lion/features.html#gate...


And we'll probably see that default move another level up the list by the time 11.0 comes round, before the other options disappear altogether on at least some devices (Macbook Air and Mac Mini perhaps).

I know a lot of people won't like it, it's the equivalent of locking up the box with proprietary screwdrivers, but these restrictions do make life a lot easier for regular users and the people who have to support them.

Also, it's nice to have a choice of operating systems. This kind of thing fits in with the siloed approach Apple takes across the board, so for dedicated Apple users it's not evil, it's just an improvement on what they're already used to.


And then Apple will be able to start charging for developer IDs. To help prevent malware authors obtaining developer IDs of course.


They're letting developers use a free Apple ID to sign apps. You only need to pay if you're distributing through the Mac App Store.


Yes, but my point was in the future, once apps must be signed, it is not unreasonable to imagine them introducing a fee, with the excuse that they need to do this to introduce more barriers for malware authors.


$99 apparently http://techcrunch.com/2012/02/16/os-x-mountain-lion/ but revenue from developers is not the business model here.


And then, Apple will come to your house, and eat your cat.


Who cares about $100? You're coding on a $1700 laptop.


I came here just to post this exact snippet. Does this seem at all ominous to anyone else? Perhaps I'm overreacting.


Only if one accepts the slippery slope fallacy that they'll eventually remove the "No unsigned code" option. The odds of this happening are, in my estimation, extremely low - it would make Mac software development basically impossible, and the use of Mac in educational establishments (with a lot of custom software) very hard. Heck, Apple are still sponsoring the OpenJDK port for OS X, which I doubt they'd be doing if they planned to entirely eliminate unsigned code from the platform.

The "No unsigned code default" has been coming for a while in mainstream computing, thanks to most users ability to blindly click anything attached to a random e-mail or downloaded from their favourite wallpaper site. Out of the options ("App Store Only" or some other signature system), I think they chose the right one. As long as the opt out is there, not only do I not have a problem with this, I'd suggest it's a positive step forward. The only change I'd want is to remove or massively reduce the cost of getting a developer certificate.


> Only if one accepts the slippery slope fallacy that they'll eventually remove the "No unsigned code" option.

Not at all, for several reasons. First, defaults are powerful things. The vast majority of users never change them, or even become aware that they can be changed. This remains true even if you throw an unskippable dialog box right up in their face -- lots of people will just blindly click "OK" to accept whatever the default in the dialog box is, without stopping to consider the alternatives. The result is that default settings tend to become "the new normal," even when they're sub-optimal.

(Example: why did IE6 rule the Web for a decade, despite being demonstrably inferior to the alternatives for most of that time? Because for nearly all users, it was the default.)

This seems especially true in the case of this particular preference, for two reasons. First, it's a technical question ("what's 'unsigned code?'"), which means many users will avoid changing it for fear that they don't fully understand the consequences of doing so. Second, it involves security, and users have been trained that in questions of security departing from "standard operating procedure" puts them at risk, so others will avoid changing it for fear that doing so will expose them to new vulnerabilities.

In other words, it's not unreasonable to expect that offering unsigned code will quickly become an infeasible strategy for OS X developers, even if users still have the option to accept such code. The option may be there, but those developers will find themselves marginalized simply for being something other than the default.


Apple doesn't need to remove the "No unsigned code" option, they just need to scare users into being too afraid to use apps that aren't signed. And then your unsigned app, should you choose to try and distribute it, is in the same category as MacDefender and YourComputerIsInfected.

Apple is probably making the right decision for its users, but I still feel there is something we're losing here.


Removing the "No unsigned code" option is not possible today, I agree. But one day in the future when 99% of apps are signed, because it's free right, so who wouldn't? We find ourselves in a completely different scenario... Is the freedom of that 1% of apps more important than protecting users?


It's not possible ever, as long as Apple is shipping computers outside of their buildings. People are still jailbreaking iPhones, what, six years in?

Calm down.


Well, like the article says, signing-only developer certificates are free now. You only need to pay for it if you are planning to distribute through App store.


Oh no, not ominous at all ... look for this list of three choices being reduced to the first two. Coming soon.


If Apple did that they'd kill the devotion from the development community. They may end up making App Store only the default option, but I have trouble seeing a day where you can only install Apple certified software on your Mac.

Overnight they'd lose many thousands evangelists and unpaid tech support staff (ever help a family member with their Mac?).


If Apple did that they'd kill the devotion from the development community.

Like with iOS? Hackers will be annoyed, but Apple doesn't care about them when there are more than enough developers who are either in it for the money or who agree with Apple's position.


iOS started off as a closed environment unsuitable for development. As a web developer on the Mac I'm constantly using cross-platform command line programs, system utilities, and other development tools that would never make it through an Apple vetting process. If Apple killed the ability to install those programs in an update, I would absolutely have to abandon the Mac, and I'm sure I wouldn't be alone.


I'm sure you wouldn't be alone.

However, from Apple's perspective, if there are "enough" developers who can't or won't leave (because they develop Mac software or iOS software or both), Apple might not care if you do.


They might make it harder to select the third option, but they won't ever remove it -- they're not suicidal.

And it's not like the signing process is particularly onerous -- it won't represent even the slightest barrier or inconvenience to shareware, freeware or open source app distribution.


Yeah, well, until that happens, this is great and I'm all for it. What a simple way to improve dealing with the open attack vector that is "the user being able to install their own software". I wish they had this flexibility on iOS.


Look for new scripts for Apple support:

Sir, please click on About this Mac: if there is an icon of a signed page, we are good, but if it has a circle-and-slash around it, well, your Mac is running some unsigned software. Your warranty is void. Please go to the application list in Finder to see which apps you must uninstall...




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: