This seems unnecessarily crippling. Is this really required of desktop App Store apps?
This seems unnecessarily crippling. Is this really required of desktop App Store apps?
Source: https://www.google.com/search?q=os+x+root+exploit&gws_rd=ssl
It's in the best interest of the hacker that broke into your system that your system continues to work flawlessly for both you and the hacker. This is why Mac OS X "rootless" is just yet another obstacle for the power user, yet another obstacle when compiling and installing POSIX code from source, and yet another step closer to locking down OS X to be an appliance like iOS.
And if you really want to disable rootless anyway, you can do so. Boot into the recovery partition and there's an option there to turn off rootless.
I'm also completely baffled by the claim that, just because no security solution is 100% perfect, that we shouldn't even try. That makes no sense at all. Yes, security is hard. But protecting you from 99% of all malware, even if there's the rare case of malware that gets past you, is still extremely useful. Besides, it's awfully cynical to declare that SIP is an impossible goal before you've even looked at it.
But, you can disable SIP so not sure how much it really matters.
Good catch on finding something that breaks with SIP, but even if you philosophically disagree with the idea of rootless, you should still agree with the notion that library interposing is a serious security threat and should welcome the changes to block interposing of system processes[1].
[1] From the What's New In El Capitan docs[2], the specific aspect of SIP that applies here is "Code injection and runtime attachments to system binaries are no longer permitted".
[2] https://developer.apple.com/library/prerelease/mac/releaseno...
So no, I don't welcome "SIP". There are better ways to solve that problem.
I recommend that you tally up the revolutionary technologies produced over the last 30 years that allowed us to get to this point (including the web), and then consider how many of them could be invented on Mac OS or iOS today.
This protects against a whole host of issues. It safeguards against garden-variety incompetence[1]. It provides some defense against the large number of badly-intentioned people who can write an Objective-C app, but don't have the expertise necessary to weaponize a typical root escalation exploit. It prevents apps from accessing your contacts, reading your emails, determining your location, and accessing the webcam and mic without your knowledge, amongst other things.
Does it protect against a motivated, highly technical attacker? No, not really. But that hardly makes it useless.
[1]: http://www.macobserver.com/news/98/december/981229/bungierec...
The exploits tend to be trivial, often trivial enough to fit into a single tweet. (https://twitter.com/i0n1c/status/623727538234368000) They require no competence to use.
As for protecting against incompetence and mistakes, that is far too an extreme of a measure solely to protect against that. Some decent QA will fix that.
So what is the point, really, of sandboxing if it does not thwart highly technical attackers? It severely limits the functioning of apps, makes it far more difficult for app developers (myself included), and for what benefit that could be worth the trade off?
https://www.google.com/search?q=developers+leaving+%22mac+ap...
It thwarts the attackers who aren't highly technical, and frustrating the script kiddies could have flow on effects when beginner attackers don't get the reinforcement to motivate themselves to refine and build their skills.
Secondly, exploits can be patched over time. Ten years from now, is OS X going to be better off for having the sandbox? Do you expect a lot of trivial exploits to be discovered after another century of person-hours are invested in the sandbox?
And yet we do those things anyway. The idea is defense in depth, such that if one mechanism fails then hopefully another will mitigate the damage. Sandboxing isn't perfect, but it's another layer of security and I'd rather have it than not.
Yeah, cracking is asymmetric warfare that we have no hope of winning, I think anyone with any knowledge of computers realizes that is true. It doesn't mean we should smugly shoot down anything that makes it incrementally harder.
It is also the way to go on Android, iOS, Windows 10 onwards. And was on Symbian as well.
If an application get p0wned, it won't be able to access more than what is strictly necessary to perform its duty, instead of free reign over my $HOME.
- Giving 30% to Apple is no small thing
- You lose the ability to maintain a direct relationship with your customers, provide upgrade pricing, etc
- Any updates are gated behind a delay-and-frustration-prone release process.
- There are plenty of services that will handle billing for 5% or less, compared to Apple's 30%. However, in the post-Stripe universe, implementing a webstore yourself is actually super easy.
If not, there's your answer.
We have started to investigate other distribution channels. However, adding that option will take some work (= time).
Wow... based on the sandboxing thing I had assumed it was an iOS app for learning Haskell on your iPad or something.
I own a Mac but I didn't even know what "Mac App Store" was. Why does such a thing exist? The concept of a centralized app store for desktop apps is absurd.
First it was a setting in the preference panel, preventing you from installing non-MAS apps without disabling it.
Next it's the upcoming rootless OS X, System Integrity Protection: it's only a matter of time until the ability to install non-MAS apps is completely removed, buried, or hidden in Recovery mode (as the SIP setting is)
I suspect this will happen within the next one or two major versions of OS X.
The rest is pure speculation.
The SIP setting is most certainly "opt-out." Have you demoed El Capitan?
The Preferences -> Security -> Allow non-MAS/non-signed apps setting is most certainly "opt-out" on any machine you buy from Apple or at the store.
Prefacing something with "I suspect" generally allows one to speculate.
The trend is that you're gradually losing control of your machine.
And we have heard this for how long already? Doing so would basically be suicide for the Mac. First of all because a sizeable chunk of users are technical users. Secondly, a lot of software is not available in the Mac App store and likely will never be (I think Microsoft and Adobe would rather abandon OS X than giving 30% for each cloud subscription to Apple and being at the mercy of the MAS gatekeepers).
It's not "yet" -- it's now, with each release, and getting worse each time.
http://widgetsandshit.com/teddziuba/2010/05/the-future-of-ap...
Until then I find them to be the best laptops on the market.
Pretty sure the default is MAS + Signed Apps. This setting also doesn't actually stop you from installing a non-signed app. You just have to right click and select open to bypass the warning.
I actually keep this enabled so I know if an app isn't signed. So installing non-signed apps is a conscious decision.
I think that you also need an admin password, which can be an issue for users who don't control their machines. (My work distributes Macs with users configured to be admins, but on Windows machines only allows standard users, so I assume that it's only a matter of time until they change policies and this bites me.)
The "household-appliance" moniker is a red herring though. Just because they supply an App Store doesn't mean you have to use it, and it doesn't mean you can't do amazing things with it. Are we really comparing something that can help educate, research, run a business, entertain, etc. with a dishwasher or TV?
Do you think they don't know who their customers are?
I'd bet that fewer than 5% of any computer company's customers want a general purpose computer.