Does this mean that anything distributed outside of the App Store will have to be approved by Apple? Will the App Store sandboxing rules apply to outside apps too?
Does this mean that anything distributed outside of the App Store will have to be approved by Apple? Will the App Store sandboxing rules apply to outside apps too?
That sentence means that in the future, the second category (applications which are not on the App Store but are cryptographically signed) will need you to generate a certificate with Apple. Nothing about the app store's sandboxing rules, and nothing about all applications -- you can run unsigned applications to your heart's content.
I feel like eventually I'll have to abandon Mac, but for what? Linux is still flaky and Windows adware unless you spring for Enterprise.
I would pay for a commercial Linux as polished as MacOS, but there may not be enough of me. (It could also have a list of officially supported hardware to at least approach the stability benefits of Apple's vertically integrated HW/SW stack.)
I would spring for Fedora or Ubuntu and deal with the lack of paid support for my own personal use but then again I've been using Linux for a while.
Both options are perfectly stable desktops, it's really the commerical software support that will get you.
Barring software bugs that allow for arbitrary code exec as the binary?
Signed package + necessary keys embedded in silicon -> processor verfies signature at memory load -> processor disallows user privilege escalation to write to arbitrary memory
You can run unsigned apps. The new policy affects the process for signing apps.
https://access.redhat.com/ecosystem/search/#/category/Laptop... https://www.suse.com/yessearch/ https://certification.ubuntu.com/desktop/
Even on windows my experience is that signed-non-windows-store apps can get flagged as malicious upon download if they're fairly niche/aren't used by many people, supposedly using an EV Cert helps with that. The user experience is actually worse from my experience (windows will show something red, then you have to click some non-obvious buttons to successfully run the app).
But I’m Windows, any approved CA can issue a certificate, not just a Microsoft.
Apple’s new regime is not only restricted to Apple being the only CA, but that Apple is the only one who can sign the apps.
That’s immensely restrictive.
Give the fucking shenanigans we've seen from the commercial CA's recently, I'm not surprised.
This exact discussion first happened when the original iPhone came out. It's been a decade+ now, and nothing has happened to your ability to run whatever you want on a Mac.
If this really happens to be some sort of frog-boiling conspiracy, it's progress must be glacial. Which doesn't square very well with the other usual criticisms, namely that Apple doesn't care about the Mac, and that they suffer from short-termism.
That’s a myth: https://en.wikipedia.org/wiki/Boiling_frog
https://www.theatlantic.com/technology/archive/2006/09/the-b...
App-signing is about protecting the user within an already booted OS, trusted or not.
These are very different concepts.
Similarly in Windows you can control which CAs (or individual cettificates) you trust.
They 100% respect the users freedom.
Very much unlike Apple does with gatekeeper.