LibreOffice latest to fall victim to the curse of Catalina
theregister.co.uk
theregister.co.uk
Not that this is necessarily bad (although the bugs are super annoying). Vista had to happen, and I can see why many casual users in the Apple ecosystem would prefer a simple, sandbox system for their operating system. Time will tell if this is indeed a step ahead or a problem that will be made undone in the future. It just sucks that Apple customers are dealing with their own Vista now though.
Apple's permissions are smarter and the constantly asking for permission does not happen in my experience on macOS. Apparently they've integrated the open file dialog with their access control, so any such dialog will automatically permit the app to access the target file/folder. The pop-ups only appear when an app wants to access specific folders in the background. This is brilliant and would stop e.g. malware which encrypts documents or nosy apps in their tracks!
The prompts went away because the apps were fixed. Thanks to the pain Vista went through apps can run without Administrator rights and most apps were ready for Windows 7.
Now half the devs out there write config files to fucking Documents for some reason...
I don't use my Documents folder anymore because it's too hard to find actual documents among the dozens and dozens of misplaced config folders.
It should be no surprise that developers choose to dump non-documents into the user’s Documents folder.
Their attitude being the monopoly is just annoying.
For RNG/permadeath games like Don't Starve, the save file better be safe.
This pattern is called "powerbox", an idea from object capability security. I'm sure there are plenty of other usability improvements in there if you study those ideas (more so the more important security is to your application). Applying it to the web is getting easier with Mark Miller's JS standardisation work and (also his) https://agoric.com/ and https://ocapjs.org/
This isn't really about files, though. Capability UI patterns are about composing all kinds of authority in a usable way. I'm sure we'd all agree that accessing files isn't the best or ultimate description of the interesting things that people do with computers now. This is an area that's waiting to be rediscovered by the rest of the world.
I hope Apple doesn't solve the dialog problem the way Microsoft did though (by sacrificing security for usability), now we have the situation that being logged in as a local admin with UAC set to default means that any malware can gain admin privileges through UAC bypasses. You can prevent this by setting the UAC settings to max or logging in as a standard user, but then you get Vista-style annoyances again...
When the OS cant deliver you can find software that do. So why the whining about the OS security? For example the first thing I install is a proper Firewall >with advanced configuration control<.
Comodo even stopped the malicious Windows 10 update with malicious dialog design hiding how to close it and a delay timer so it can start the update without user consent. Comodo is not supposed to stop updates to but my configuration must have been why it did. And we all know that malicious updateS liked to remove personal files and software installed by the user. Im thankful for comodo. I later disabled the malicious updateS (since there were many attempts to make it run, they changed the update name several times). Nasty and malicious indeed.
And I'm not even sure UAC at max level is officially a security boundary. As for the second solution, yep, and you actually could also log in as a standard user in XP (and 2000, and NT)
Now there is a fun thing about security, is that it can be sometimes counter-intuitive. A yes-no popup on a secure desktop can be way more secure than asking for a password in some cases, because the popup screen could be spoofed, and while obtaining an admin pwd is obviously valuable, obtaining a yes-no answer from the user at the console is not... (Some mitigations exists like SAK but they are not perfect, because the users can make mistakes, especially if asked for their password all the time)
If anything UAC is a good case to show how security must come with usability, otherwise you just don't get much in the end...
The end result from a technical point of view; well obviously better than nothing, but never count on it. It is actually way more useful to avoid casual mistake than for security purposes.
On the other hand, I do like to have access to each and every file on my system if I so please and I do want to be able to use my toolset anywhere on the system. For my classes I need to run what we call "PhD-ware" every now and then (technically advanced software that is great at doing one specific job but is mostly unmaintained and requires a specific setup to work) and that's never going to be compatible with any security restriction. I want to be able to override the system when needed.
Most software I actually install through homebrew and it's nice that the software has been checked more than once by other people. To me it's the whole point of using Mac(OS), things just work (TM) and if not there's a way to make them work. One positive thing actually: I think Apple tidied up the DTrace configuration, so it's much easier to start without doing any crazy configuration stunts.
Sounds like a job for Docker, or possibly a hypervisor: Put the app in a container, put the specific files it needs to work on in the container, and the app lives entirely inside that container, whether it's a Docker image or a filesystem image with an OS or something in-between; there's no security implications because it can only touch what's already in the container with it.
As a plus, the whole system (OS, configuration, application, and all) is now reified into a single container artifact you can ship around and just run. It won't rot, or at least it'll keep a lot longer (as long as the container technology keeps).
One tool I had to use would only work on old Linux kernels, proven to be working on Ubuntu 12.04. The guest tools in the VM provided were so old that I had to set up an older version of Virtualbox in order to get the system to run, which opened a whole can of worms in itself. This was on Ubuntu at the time, so luckily that it was just a matter of installing dependencies and trying to find compatible versions that didn't clash with normal system tools. Maybe Docker is able to run VirtualBox but just thinking about glueing Docker and a hypervisor together is giving me a headache. Nested KVM works these days, but who knows how that might affect a piece of software like this.
Just for the weird legacy cruft that comes with some tools, I just want the option to mess up my system in order for something to work.
Ignoring the technical details of implementing this, you still have a semantic gap between "I don't want my document editor running wild on my files" and something you can express unambiguously. The only way anyone seems to have come up with to close that gap is Popup Whack-A-Mole, which everyone seems to agree is a massive usability failure except everyone who's reinvented it.
Permissions are probably something like"you can do what you like over HERE but can't touch anything else".
While I'd love to check all the code I've downloaded for sneaky problems, I'll agree that in this day and age that isn't entirely feasible. At some point, you have to hope your backup regimen is working.
And now macOS is adding more of the same protections...
For power users who use Tasker, Android's restrictions are a nightmare. I cannot, for example, kill an app using Tasker, and I really really need to do this. Plenty of other restrictions that made Tasker users' life difficult.
To be clear, this is on a rooted phone. Am I not allowed to algorithmically decide to kill an app on my own phone?
As an aside, I'm curious what makes killing an app so critical vs. only shutting down background processes. That seems like an edge case on an edge case?
This thread is about power users, not average users.
If I sold you a Linux PC, and gave you root access, but it was sandboxed and you couldn't kill apps from the command line, would you say the PC I gave you is fine for "power users"?
To a power user, this isn't a phone that is smart. It is a computer that is running Linux. It's totally fine to put in measures that enhance security on an unrooted phone, and it's also fine to make users go through hoops to root the phone and give them more power. But simply disallowing basic things with root privileges is hostile to power users.
Take something as trivial as backup, for example. I need a rooted app to do it (and thankfully, it works). But if you step back and realize an unrooted user cannot easily back up the contents of some of their simple apps without using a 3rd party cloud, and realizing that even that doesn't work well, then you can't reasonably view an Android device as something you truly own. I paid hundreds of dollars for a device where it's nontrivial to get access to my own data on the device.
The computer has more personal data than the phone does, often by huge margins.
And I'm pretty sure the total amount of personal information contained in the documents of people with documents vastly exceeds the total amount of personal information contained in the phones of people with phones.
Counting number of people, there probably are a lot more who use the phone as their only device, but those people aren't generating as much in the way of personal information.
Going back upthread, we have this claim:
> I honestly doubt that most people keep more personal data on computers than they do their phones.
which was in response to this claim of mine:
> The computer has more personal data than the phone does, often by huge margins.
Two different questions have been raised:
1. Are there people who have phones, but don't have computers?
2. How much personal information is on someone's computer -- assuming they have one -- compared to their phone?
#2 is the relevant question if we're talking about "something with as much personal data as a phone". The answer is "several orders of magnitude more", and that is unaffected by the existence of people who don't have a computer.
It's a solution created by power users, only usable by power users that gets in the way of power users.
With how Apple has been gradually weaning third party devs from having extensive/root access it’s nowhere near as annoying as UAC was.
Well, on a different note, even Linux desktop/workstation distributions have reached their Vista point... in the somewhat trivial sense that they now need Vista-capable hardware in order to be reasonably usable! (We do know how it happened, it's all about the usual CADT syndrome. At least they are still usable, unlike Vista or Catalina. But one can still be disappointed by such developments.)
Vista level hardware is 10-12 years old by now though. I don't think it's unreasonable to drop support for hardware over 10 years old for a fully-featured environment. People want new and shiny. Why should I want to give up on some eye candy on my five year old laptop just so that someone else's 10 year old laptop isn't missing out on anything?
Mind you, Firefox and LibreOffice are bigger slowdowns than the rest of my systems and I'm using vanilla Gnome3. The system can still boot a fully featured desktop with less than a gigabyte of RAM in use. Even Vista hardware should be able to cope with that.
When I bought my first EeePC I expected to get a reasonably recent gen hardware, just without the bling and low power. It had a brand new 10 year old Intel graphics chip inside. At least it had a decent battery life and doubled as a toaster if you opened a pdf in firefoxs javascript pdf viewer.
There's also the fact that many developers live in rich countries where good hardware is relatively cheap and easy to come by. Developing countries usually don't have access to reasonably priced hardware at all. There's billions of people whose hardware is barely capable of running a Vista equivalent. That alone should be reason to consider developing with older systems in mind.
Developing to keep an old system somewhat smooth can lead to improvements across the board. There's pros and cons to every decision and I certainly don't think every piece of software should be designed to run on a Core2Duo. In many cases some considerations for those who can't bug fancy hardware would be nice though.
This is especially true wrt. memory use, BTW. Memory bandwidth is, as a rule of thumb, the main bottleneck affecting performance in present-day systems, so most savings in RAM use yield very real increases in performance for real-world scenarios. Also, less RAM use makes it easier to run a useful number of virtual machines or containers, even on non-high class hardware.
For example, youtube doesn't play well, because the hardware is too slow to decode a full HD video stream in real time. No kidding, that's actually a big driver for people to buy newer hardware, people really care about youtube.
Another example. Loading a modern website with 10 MB of javascript bundles. It takes 5-10 seconds to process all that javascript in chrome (on developer workstations), which is slow but fine. Unfortunately that's 15-30 seconds on laptops and mobiles for end users, that is quite a lot, enough that people leave thinking the site is broken.
The problem is, running on the CPU does not make your DE faster (it's the other way around), memory that is the largest problem isn't an issue, there is some heavy disk usage on load time, but then none, and there isn't much of a CPU load. They can't run on a 2006 machine, but it does not extend into your VM.
An application that doesn't run smoothly on old hardware like that will probably not run well on current hardware either. It's twice as true if the application should be usable on modern low-end laptops, that can really have terrible hardware, worse than a desktop from back then.
Why do I need to give an app a explicit permission to access common folders in my home directory? I already gave the app permission to do that when I asked the operating system to open it. This annoys me so much! You know why? Because I have a firewall installed (LittleSnitch.app) which shows alerts a few times during the day about network connections from apps that are currently running in the system. I like these alerts, they are informative, they serve a clear purpose.
However, the alerts introduced by Apple, they are mostly useless.
Why Apple?! Why do you want to waste my time with this useless crap?!
The first time I opened Terminal.app after upgrading to macOS Catalina I got several alerts to give permission to the app to access folders that I wanted to “cd” into. The alerts would be useful if they only showed up when something is trying to access core folders, but why do I need a freaking alert when I try to execute “cd ~/Desktop/” or “cd ~/Downloads/” ??? And don’t even try to use the “find” command to search for a file in your user’s library folder, a command like this will trigger dozens of alerts: “find ~/Library/ -name "com.example.app.plist"”
These alerts trigger so often and people will start to mindlessly click “Allow”, eventually they will grant system-wide access to malware that should have been prevented by the operating system in a more graceful way. I can see many of my friends and family members who are not tech savvy ignoring these alerts and mindlessly clicking “Allow” every single time.
Because you might not be aware that the application wants to harvest all the {meta,}data in your Pictures/Documents/Downloads folders?
The era of trusting applications with wide-open privileges has long since ended.
I don’t like it either but it’s the world we've built.
A huge problem in software is that the trade off for security is almost always usability and/or convenience.
Yet, this is the default behavior for applications on all Desktop operating systems. Until now.
It'll take a while to iron out all the kinks, especially with legacy Apps, but it's the right thing to do.
This makes sense only for 3rd-party apps, but I’m talking about apps that have been notarized by Apple themselves.
Terminal.app comes pre-installed in every Apple computer, it is developed by software engineers who work for the same company that makes the entire operating system. Why do I need an alert asking for permission to execute this command: “cd ~/Downloads/” ? You could argue that you only need to allow this access once and it will carry on for future interactions, but that is not the point. The point is that Apple is focusing on increasing the security of the system the wrong way, these alerts overwhelm regular users to the point they will mindlessly click “Allow” every time an alert pops up, hackers will take advantage of this and assume users will grant system-wide access to their malicious programs.
I was happy with the previous versions of the “Security and Privacy” settings. By default, you could only open apps downloaded from the App Store. However, if you were tech savvy enough you could enable the option to allow apps from 3rd-party identified developers, and if you really wanted to take risks you could enable the option to allow apps from unidentified developers. It was your choice, and the options were “hidden” in the correct place. But today’s operating system is just overly paranoid to the point of becoming an annoyance even for security minded people like me.
The large majority of Mac owners will never intentionally use Terminal. I don't know what it's like in Catalina but I have no issue in Mojave going to Security & Privacy > Privacy and granting Terminal Full Disk Access because I'm one of the few who will be regularly using it. If Catalina is making it clear that permission needs to be granted, that's an improvement over Mojave because the first time I did something that required the Full Disk Access permission, that was not clear to me from the text shown in the shell.
Because differentiating between that command and any command that may be harmful is NP-Hard. Like I said, these kinks will have to get ironed out. Terminal is UNIX legacy and that "security" model was broken from day one. The sooner we get rid of it, the better.
> The point is that Apple is focusing on increasing the security of the system the wrong way, these alerts overwhelm regular users to the point they will mindlessly click “Allow” every time an alert pops up, hackers will take advantage of this and assume users will grant system-wide access to their malicious programs.
You don't get system-wide access, that's the point of asking you for every folder. Let me ask you, what's the alternative to asking for permission? If I accidentally give a malicious program permission to do something, how is that worse than just giving it that permission without being asked?
Turing complete.
I'm not sure if NP-Hard is the right classification for the more restricted case though.
That's what this type of thing is devolving to. It's going to get to the point that most users are simply going to click through without thinking, and those that do pay attention are going to suffer continually.
To be quite honest, I'd pass. It'd just be easier not to keep my life on the bloody computer readily accessible all the time.
Most users already know this behavior from their phones, they aren't all so dumb and reckless. They reject permissions all the time, which we know from statistics. They don't just mindlessly say "YES" to everything, but even if they did, why put everyone at risk, just because most people aren't diligent?
What statistics?
Catalina apps should be notarized, which LibreOffice is committed to doing. The Register hopes for more controversy.
Apps should be signed. App notarization should never be a requirement.
For instance, I only have one Mac; once I tell my OS to “allow” my app to do X and Y and Z, how can I change my mind and “disallow” arbitrary things when testing multiple features that all have to work under the same constraints? Ideally, Apple should have a couple of simple switches like “simulate app launch in fresh-install scenario” so that I can pretend my app doesn’t have access anymore and see what happens. Similarly, I should be able to pretend apps aren’t notarized, pretend apps have been disallowed by the user, etc. all without fiddling with different commands and settings or screwing up other permissions I already have set on my machine.
System Preferences, Security & Privacy -> Privacy.
This is, of course, not true. Password managers are both convenient and improve security. U2F beats virtually every other second factor and YubiKeys are also more convenient than copying codes from texts.
If you're changing the workflow anyway, make it both more secure, and more convenient. Sure, it's not always possible. But it very often is.
Does this no longer work on Catalina?
https://blog.documentfoundation.org/blog/2019/10/22/libreoff...
That said, FOSS or not, this is the stuff that should be tested before shipping. It's disconcerting that apparently no one on the LO team has bothered to test an install build on the latest version of macOS (and if you buy a laptop or desktop from Apple today, it likely has Catalina installed).
There's a page for that: https://developer.apple.com/documentation/xcode/notarizing_y...
Build quality hasn't been fantastic to be honest - I had to return the first one because of a faulty monitor connection (but to be fair I had exactly the same problem with my 2015 MacBook too), and the replacement has a problem with its space bar. But the great thing is that I can unscrew the back with a normal screwdriver and have full access to the internals so if I get really bothered by it I can replace/upgrade/fix any of it. Purism support was great, and they encouraged me to take the back off and see if I could spot the problems, which really blew my mind after Apple support.
I've been using it for most of a year (writing this on it) and it's been a great experience. The article's view that "I'm no longer reliant on hardware" is true, though I haven't (yet) gone the next step of picking a different window manager and storing the setup for it in a git repo. It's on my to-do list though ;)
I know a LOT of people who will only use Mac laptops and a ton more graphic and web designers who use Macs religiously. I have yet to find someone who uses any Mac products that run Gimp so I find this to be an interesting point.
I like the os and so on, yet I try to keep my workflow as FOSS as possible.
I invest a lot of time in learning and mastering my tools so I believe that using preferably multiplatform and Free software will let me keep my skills and hours I put into learning stuff under my, not some vendor’s control (e.g. if apple keeps going the direction it is going at the moment).
This is why I use emacs, inkscape, gdb, gcc etc. on Mac OS
I use a Mac and run GIMP. I even bought a recommended app (I think it was Pixelmator?) a few years ago and tried switching to it, but I liked GIMP better so that's what I stuck with.
Granted it isn't a full-fledged replacement for Photoshop, and I do have an Adobe CC subscription, but some things are simply faster and easier (for me) with GIMP.
Headline is FUD.
I like this book title already
Catalina removes iTunes and 32-bit programs.
You can run the latest (or any recent) version of iTunes on Catalina and use it to manage your iThings and content. There’s a forum post on Macrumors with a nifty AppleScript that will install an older version of iTunes (that you’ve separately downloaded) and make it available for you. It does require disabling SIP temporarily. It doesn’t seem like the determined user is forced to abandon iTunes, as of now.
If you'd please review https://news.ycombinator.com/newsguidelines.html and follow those rules when posting here, we'd be grateful.
You might also find these links helpful for getting the spirit of this site:
https://news.ycombinator.com/newswelcome.html
https://news.ycombinator.com/hackernews.html
You absolutely can. Where did you get that?