The idea that Apple doesn't care about the Mac because it's trying to explicitly improve our privacy and security is … weird.
The idea that Apple doesn't care about the Mac because it's trying to explicitly improve our privacy and security is … weird.
I've seen similar things with apps that request access to Dropbox or Google Drive just not being scoped granularly enough, so they just ask for access to your entire account to control a single file or folder. Which leads to a shitty situation, either you give up functionality like being able to declaratively override settings and sync them between machines, or you compromise your security and allow access. There's no way the PM for the product actually cares about granular permission scoping, so of course nobody actually implements in a safer way where you don't have to make this choice.
I haven't looked closely at the new MacOS permissions and how granular they can be, but I'm kind of curious how this will turn out. I suspect the average person will just get used to clicking allow on everything, so developers won't actually care about only asking for what they need, and not much will actually improve about security. But I hope to be proven wrong.
You're probably right that it's not nefarious in this app's case, but rather just developer ignorance. But even so, this is the right path to nudge developers towards better security practices.
Also, the permissions are contextual. I didn't see this dialog until I launched the app. Similarly, the first time an app wants to show a notification, the system prompts you to allow / deny it. I'm sure Apple can polish this more over time. But I will take this over the "nearly full-system access by default" paradigms that dominate desktop OS's.
A nice benefit of storing them in Documents is that it syncs to icloud automatically even on the free tier, so you can share it between all your computers.
It's often not straight forward and often getting in some system settings somewhere. Android has this problem.
uhmm....
To me, it seems that if the Documents permission dialogue in fact caught the app doing anything bad, it should remove all trust for the app and the developer. It's all or nothing, really.
Nor do I entrust it with all my network traffic. As to whether it warrants completely removing the app or not, it's up to the user to decide, isn't it?
Similarly, for the apps requesting access to various things, if I were Apple, I'd wait a bit and then present the user a list with the apps requesting access, explaining why it's happening, etc.
So two simple screens with clear explanations and helpful advice, versus a million baffling popups.
If they didn't, people would complain that they had to click all these checkboxes, and then missed one.
Or the window wouldn't have room for applications to explain why they needed that access.
Or they would, and users would maybe read the first one, but skip others.
There is no "better experience" which doesn't sacrifice the point of the prompts.
All 150+ apps (I don’t know how many are installed by default, but I have 277 on my system), many of which the user won’t even know he has installed? (I just found out I have an “Adobe Air Uninstaller” and two “Abobe Air Application Uninstaller”s, something called “Computer.app”, and 11 different Java 8 updates, for example)
And no, I don’t think such a dialog would be useful because users could delete applications they “don’t use” from there. The average user simply doesn’t know which applications he doesn’t use. I certainly don’t.
I think they could do a bit better, but I don’t think this problem has an easy answer. For example, they could exclude all Apple apps from these questions, but I suspect that would (rightfully) give us “Apple gives its own applications preferential treatment” complaints.
This Mac notion of "if your software/hardware wasn't purchased this week, it's unsupported" is not a good look.
Apple has moved privacy to the forefront for a much longer time. Apple was the first to roll out end-to-end encryption of messages to hundreds of millions of people (iMessage 2011), the first to roll out end-to-end encrypted (video) calls to hundreds of millions of people (Facetime, 2010). They introduced the secure enclave, which was quickly used throughout the OS with iPhone 5s in 2013.
Whatever reasons they have (and despite their failings), they have been pushing privacy for almost 10 years now.
If you bombard users with dialogues for every little thing, all you will do is train them to habitually click yes. Now you have lowered security, because users will ignore the more serious warnings too. And you've wasted everyone's time in the process.
This was exactly why UAC dialogues were largely a failure. And to think that UAC appears only once per app...
You should only ever expect the user to have access to the desktop and, even then, the only apps that would ever prompt for access to the desktop are those that aren't updated for High Sierra and above. On the latest versions of macOS, the Desktop folder is shared by iCloud. This is definitely not an instance where security has been lowered nor is this the standard behavior of the new OS.
Yes! That's what applications do, they read and write files. Most other software is, more likely than not, either a game or a web page.
Does every app need to access my desktop specifically? No. But if we're trying to protect "normal users", I don't think most of them have the wherewithal to think through "what exact locations does and doesn't app X need to access?"
The alleged problem is not even solved by a permission dialog. I should answer OK to the fact that it needs to access all of my Documents, forever, and that's supposed to be more secure? Why not just ask me for permission to my whole drive so it can scan for documents everywhere? Apps will just start asking for more and more permissions like they do on iOS, which is annoying.
macOS is slowly but surely being turned into iOS. It's software for the lowest common denominator - the average idiot - which I'm not, at least when it comes to technology.
Thankfully, my workstations are all Linux but I still have to deal with both macOS and Windows on a daily basis. But at least on Windows, the permissions annoyances can be avoided by simply not using UWP apps from their app store. I hope there's a way to turn this off on macOS but knowing Apple I doubt there will be because clearly they're on a mission to wipe macOS off the table. Perhaps that would be a good thing though. More people will move to Linux.
But this is not how it works. Word from the App Store is sandboxed. If you open a document in Word, this is done using the native file opening dialog. This is a separate, privileged process. The file is symlinked into Word's sandbox as a result. This means that Word has access to that file from that point onwards. So, it can show a welcome screen with documents that you have previously opened (which is what applications typically do, very few applications will show all documents).
This is how things have worked ever since Apple required sandboxing for App Store apps. The problem is non-App Store apps that are not sandboxed. They have unfettered access to every file. I guess these extra permissions are to provide a certain level of protection against such apps, which is good.
Word is a well-known application. I installed it. I trust it and the corporation that wrote it.
There are many well-known incidents of trusted applications being compromised and backdoored. E.g.:
https://blog.malwarebytes.com/threat-analysis/mac-threat-ana...
To make things worse, the hash was updated in Homebrew cask. So even if you used a package manager, you would have installed a compromised application. Trusting applications may have been ok in the age of shrink-wrapped software. But now that applications are distributed over the web, allowing unfettered access is insanity.
More people will move to Linux.
The Linux ecosystem is also moving towards immutable base systems (Fedora Silverblue, NixOS) and restricted, sandboxed applications (Flatpak). Sure, it will always be possible to install a 70ies UNIX-style distribution. But the world is moving to sandboxing and putting up more restrictions, because the computing world became more hostile.
macOS is slowly but surely being turned into iOS.
This is getting tired and old. People said the same thing ten years ago and yet here we are, macOS is still an OS for 'general purpose computing'. I think Apple is finding a nice balance between securing the average user through sandboxing and SIP, while keeping giving the knobs to disable protections to advanced users. I say this as someone who currently uses Linux 95% of the time, but I wish Linux was as far as macOS with application sandboxing and system integrity protection.
Well, the "slow" part can be slower than ten years. It might just still not be there, but compared to how macOS was 10 years ago, it does have more iOS-like restrictions nowadays even if it isn't full-on iOS.
Yes, that is how it works. Sandboxed apps can absolutely request access to an entire folder. See here:
https://developer.apple.com/library/archive/documentation/Se...
> An app-scoped bookmark provides your sandboxed app with persistent access to a user-specified file or folder.
But all of that isn't really relevant to what I was saying. You're bringing up technical details about how sandboxed apps work. I'm saying that sandboxes suck and I don't want them, particularly from Apple who will just use security as an excuse to take away more of my freedoms.
> I guess these extra permissions are to provide a certain level of protection against such apps, which is good.
I would rather not trade my freedom and liberty for even more annoying and absolutely useless security measures. You see the top comment on this thread now right? It's about how useless these dialogs are and how Apple has actually argued against them in the past.
> There are many well-known incidents of trusted applications being compromised and backdoored.
So? Don't update right away if your OS manufacturer can't be bothered to run a properly curated package management system that vets packages before anyone installs them.
> But now that applications are distributed over the web, allowing unfettered access is insanity.
I've been using desktop software for 30 years and for 25 of them, I've been downloading it from the Internet. My simple security measure are to verify sources, turn off automatic updates, don't update right away and read the news. Haven't had a problem yet.
> The Linux ecosystem is also moving towards immutable base systems (Fedora Silverblue, NixOS) and restricted, sandboxed applications (Flatpak).
Some Linux distributions are moving towards that. Anyway, I'm fine with immutable base systems. I'm even fine with sandboxed apps, as long as the permissions request infrastructure isn't annoying as it is in iOS and now macOS. And, as long as I can still install non-sandboxed apps without any further useless annoyance.
> This is getting tired and old.
No it's not. It's getting one tick closer with every release and if you want, we can certainly detail each time that macOS has changed to become more like an iPhone. Some part of you must realize that this is exactly what Apple would love to do as quickly as possible but they won't risk alienating users just yet. Do you really not see how Apple has been moving towards a less general purpose computer?
I mean, I wouldn't even call macOS "general purpose" to begin with because you can only really install it on Apple hardware. Right from the very start with Apple, their OS has always been more like "Apple purpose" - software that you can only use for Apples purposes.
> macOS is still an OS for 'general purpose computing'.
Yes, for now. Just a little bit less with each release.
> I wish Linux was as far as macOS with application sandboxing and system integrity protection.
No thanks. The world needs less security theater, more actual security and more freedom to use our own bodies and properties as we wish.
I'm by no means against Sandboxing, by the way. I think it's great that if you want to buy and use sandboxed apps—and are willing to accept more limited functionality as an occasional consequence—the Mac App Store provides that option for you. However, there needs to also be an alternate path, by which I can say "this is an application I trust, please let it do its job."
There should, of course, be several different permission levels—Parallels needs its own kernel extension, most applications don't. Permission prompts are an important part of enforcing that. And that's precisely why prompts need to be use sparingly—if you bombard the user with too many of messages, they'll ignore all of them.
The biggest protection here is that the folder is shared via iCloud in most instances. Asking for explicit permission is really the only way to do that safely.
Do you really think any application on your computer should be allowed to read and write them because "that's what applications do"? 90% of the 'applications' on my computer I didn't even install myself, like uninstallers, updaters, helper applications, background services, whatever. These have no business looking at files in my Desktop folder. And particularly not if its on iCloud and shared with other devices like my phone.
The permission is needed only when the application wants to go around the normal way of opening files.
I would like to know if an application:
- Is scanning the contents of my documents or desktop outside of files I specifically selected or it previously created
- Is monitoring data going on the clipboard
- Wants permission to make alert sounds or play other audio even if my sound is silenced/muted
- Wants to listen to my microphone
- Wants to monitor sound being output by other applications, such as VOIP
- Is monitoring for keystrokes even when it is not in the foreground.
> If you bombard users with dialogues for every little thing, all you will do is train them to habitually click yes. Now you have lowered security, because users will ignore the more serious warnings too. And you've wasted everyone's time in the process.
If the new permissions were about security, they would all be denied and applications would have to figure out how to cope. They are about user privacy.
As I see it, those are the same things within this context. The effect is the same. Users are just going to click yes. They aren't going to think through "what other files are on my desktop right now?"
You mean the place where your mom stores her confidential banking statements ?
> It would be like asking permission to access my clipboard,
You mean the place where you often copy paste passwords ?
> or read my keyboard.
You mean the place where you type your sensitive infos ?
At some point, the only way to be truly secure is to switch off the computer—that's why voting should be done on paper ballots! Once a computer is switched on and connected, everything is a tradeoff between usability and security. Personally, I have work to get done.
At what point is Apple the only one able to make useful software? And by the way, while Apple is pretty good at user privacy, they are by no means at the top of my list, particularly after the whole Siri debacle.
If the application asks for permission to access my contacts only after I select an option to share information with others, for instance, I can feel more confident about granting that permission.
Asking for all permissions up front is the permissions model that Google just abandoned.
The point was to make you aware of what permissions the applications you use require access to.
And to get explicit permission from the user.
Individual popups don't completely solve this, but it makes more obvious that a specific application is requesting a large amount of permissions. They're a bit more digestible to the crowd that won't bother to read an alert longer than one line.
It shows it at the point of access request. If 2 programs request access 5 minutes apart, how would you show that in a single window?
Do you suspend the first program and wait until another application makes an access request? What happens if another doesn't make a request in a given time period? Will the user wonder why the first application has stopped doing anything useful for 5 minutes?
Honestly, how would you show this in a single window?
Hardly. Apple could have used the OSX installer to scan two or three common locations for applications and do a bit of static analysis. Apple could have put the permissions notifications in the notification center with an annoying nag screen every hour or two for the first ~30 days turning into an immediate prompt after that (or after all detected programs have been processed).
Indeed, almost as bad as popping up countless dialogs per application.
So what's the point then? To inflict more pain?
It will just know that the program will open a file of some kind, not the location of said file.
I doubt any regular user is going to see anywhere near this amount of warnings.
As for the general quality of Catalina, there seems to be a deluge of amateur-hour flaws that affect real workflows for real users.
This looks like a pretty good alternative:
https://www.andrew.cmu.edu/user/bparno/papers/user-driven.pd...
Instead of the OS displaying an annoying prompt when the application tries to use a privilege, the application embeds an OS-drawn access control gadget inside its UI, such that the user interacting with the UI grants the privilege.
https://developer.apple.com/library/archive/documentation/Se... (search for "Powerbox")
Why not make the user know what applications do: which files, ports, devices it has to access, and what data it emits, to begin with?
You could say this is fine but it does demonstrate that something bad probably happened because we’re they presented the immediate option for existing apps they would have made a different choice.
Right now I have iOS 13 and it’s been great to see how many apps want but 1000% have no need for Bluetooth access — it’s nice to not have to comb through settings and revoke them manually.
If you click deny, BEHOLD, the application is denied that permission.
Users were already "owned" before Catalina, so waiting 5 minutes to avoid spamming 100 popups isn't a major risk.