Apple releases dev preview of Mac OS X 10.7 Lion with AirDrop, FileVault
appleinsider.com
appleinsider.com
In other words, Apple has finally brought the key features of Lisa OS to the Mac. It took a little longer than expected.
That's pretty awesome if so. Means I'd be willing to fork over the cash for one of those Mac Minis to use for Calendar/Contact syncing instead of using MobileMe.
> Lion Server is now part of Mac OS X Lion.
At least it did up until they put out the iPhone developer program and didn't give the paid up Apple developers access without stumping up even more cash, which was the point where I rage-quit (would have been 2007 or 2008).
Also note that Lion will be sold from the App Store, so physical discs (DVDs) are probably out. (They'll likely include one of those little flash drives with the new hardware with the install disk image on it.)
Fingers crossed!
A bunch of folks on Twitter apparently discovered the same thing this week.
Sounds like full ASLR might be in the cards for Lion as well (which would be nice).
That said, some SSDs can do their own encryption in hardware, but they need OS support (via Trusted Computing Group standards) for it to be effective (storing the key within the controller would defeat the point). Hopefully this, too, will be supported under Lion. Certain versions of Windows 7 already support it.
In any case it's a very positive (if long overdue) move.
Furthermore, many chipsets (such as Nehalem and Sandy Bridge) have integrated AES acceleration that offer significant encryption/decryption performance improvements. While encrypted reads/writes will never match the performance of standard reads/writes, Nehalem and SB very much mitigate the performance hit and will still give multi-hundred MB/s throughput on fast SSDs.
If I were Apple, I'd ignore TCG Opal and focus on distributing Nehalem and Sandy Bridge throughout the product lineup. (Or, in the case of iOS devices, toss custom ASICS on the upstream IO pipeline.) Then you can offer true encrypted user segregation (or one encrypted user and an unencrypted OS volume) while still buying standard HDDs and SDDs in bulk. Win-win.
Segregated users and accelerated filesystem-level encryption is all good stuff, but even with it, you still need WDE.
Assuming a perfect implementation, whole disk encryption costs money and power. Any additional logic on the drives will raise their cost (at no benefit if there's already CPU provided acceleration for the same operations) and will raise power consumption.
The biggest benefit comes from truly segregated, properly and completely encrypted user volumes, where all user-created is always encrypted with their private key at all times. Chrome OS does exactly this, and all OSs should strive to do the same. [1]
Opal solves a single use case. Flexible per-user encryption solves all cases and offers better performance.
[1] http://www.chromium.org/chromium-os/chromiumos-design-docs/p...
What if system and program files were modified from within the system? WDE doesn't help in this case.
WDE doesn't solve integrity or availability problems. It's primary goal is confidentiality.
Whole disk encryption guarantees nothing more than your disk is encrypted. On pure single-user systems that are never accessible by other users, that might be fine. The second you allow more that one user, remote or local, to access the disk, you may as well treat the disk as unencrypted. At that point, you need to rely on per-user data encryption and OS and app signature validation to prevent malicious attacks.
WDE solves that problem. If your disk is block-level encrypted and you carry your laptop around powered off, you can make an attestation-level promise that a stolen laptop didn't compromise customer data.
Along with an audit regime that makes sure it's configured properly, WDE allows you to promise that not one block of data on a device is readable without a key.
Indeed, yes, I am. My experience in shipping systems used by tens of millions leads to that line of thinking.
> The problem is not that anyone cares about your OS binaries. The problem is that it is theoretically possible that customer data could have wound up in /sbin (maybe a script broke and did something stupid as root). Obviously customer data could routinely end up in /. Unless you can promise that there is no customer data in any unencrypted volume --- not assure that it is extremely unlikely, but promise --- then the assumption is going to be that the data was compromised, and stakeholder disclosure has to happen.
I agree 100%. No one cares about OS or app binaries, as long as those binaries can be cryptographically guaranteed to be unmodified. Given that, no one cares about them.
So, set that aside. Once that's a given, why can't you entirely isolate all user data into individual per-user containers? I can think of numerous ways that can be implemented. Chrome OS has done one such implementation themselves. Hell, union mount an encrypted per-user volume over the unencrypted OS volume. If you don't like that, find some other way. The bottom line: it's software. Implement some way to promise user data is always isolated and encrypted. It can be done and if you think it can't, you're thinking too small.
WDE guarantees one thing – whole disk encryption. That buys you nothing when one single malicious user gains access to that volume. And keep in mind: that malicious user could have been benign and even friendly to begin with.
You really do want per-user data encryption.
> You really do want per-user data encryption.
What kind of situation where users don't have physical access to the machine is user-segregated on-disk data encryption necessary?
Once you get used to working with documents scattered all over, and clicking on them to move them to the front and so forth, it becomes a more productive way of working.
I'm not sure what it was about Windows that drove everyone to the full screen way of doing things. I think possibly the thing is that all windows look so similar on Windows that there was never really any visual clue about where the window you wanted had gotten to, so it made doing that style of navigation much harder.
I don't think the scaling is particularly good in Win 7. From memory it used to be better. I recently had a crack at using it, and I played around with different resolutions. Every single resolution that I tried other than the native one was blurry. Some were only a little bit blurry, but some were very blurry. I remember it being better than that (maybe I've just gotten fussier). I ended up in the native (highest) resolution because anything else was too horrible.
For myself, it's because so many applications have massive amounts of chrome and tiny vertical scrolling content areas. Height is necessary. Add to that that you can drag things above / below the borders of your screen, and unnecessary borders on everything, and no shadows to show "height", and your desktop becomes a cluttered, disorganized mess with too much scrolling in almost no time.
7 fixes a lot of that. You can drag things to the top of the screen to maximize, and pull away to un-maximize. Height via transparency and shadows. And a regression to thicker-than-ever borders :\ I guess you can't have it all.
You can, actually - the border thickness can be adjusted in the "Window color and appearance" dialog. The setting is called "Border padding" or something like that. And before you ask - yes, it works in Aero too (dialog says otherwise).
Thanks! That's much better.
Odd that one thing calls it "Window Color and Appearance" yet the control panel calls it "Window Color and Metrics"... the latter is more accurate, but wagh inconsistency.
Didn't know that about dragging stuff to the top of the screen to maximise, that's a good tip, thanks.
How does Win 7 perform with multiple monitors? Good? Bad? No change?
Not that many applications have a rational layout if you drag them across two monitors' worth of width, or restrict them to a half-screen. Especially Microsoft applications. But omg is it nice to have full-width code from two sources side-by-side... it almost makes Visual Studio bearable (though I'd vastly prefer being able to rip windows out of VS). I still keep a decent programmer's text editor handy for quick changes and better side-by-side comparisons, but it's not too bad.
The other guys were talking about "scaling the DPI". Are they really the same thing? In which case, why on earth wouldn't they just say "make the text bigger"?
http://www.apple.com/macosx/lion/#video-gestures
at the 1'00" to 1'28" mark.
It prioritizes the platform vendor's feature desires over those of the developer or the users' direct vote, but I think it's wonderful for the industry to have at least one vendor (and one who arguably has good taste!) doing so.
Nobody wanted a mouse until they were shown what you could do with a mouse and Aldus Pagemaker. Nobody wanted "undo" consistently implemented across all applications. And absolutely nobody wanted their applications to run in fully little "windows" on the screen.
From this cherry-picked example, I conclude that a good platform does allow the vendor to push certain features forward, but it also gives developers a certain amount of leeway to innovate.
This is why I'm happy to see both models exist and thrive. Android would look like an old Blackberry if not for Apple. And likewise Apple can pick up any advantage that Android has (other than a few, such as meeting the needs of markets outside Apple's target).
Resume is more involved, however: the application is responsible for (de)serializing its state. Again, for a document-based application that doesn't stray far from the "recommended" path, it should be fairly simple to implement. It's just a matter of the document and UI being auto-saved on termination, which requires little work from the developer. One very interesting side-effect of the Resume feature is that it removes the need for applications to stay running: the system can silently terminate unused applications, and bring them back if they're needed again. What's really exciting about this, is that it's turning applications into something that is "always there".
"Mac OS X Lion introduces overlay scrollbars similar to those in iOS. These scrollbars appear as an overlay on top of the window's content while the user is scrolling and remain visible briefly to allow scrollbar dragging."
It's more likely about reducing the amount of clutter on the screen. If you don't need something, why put it on the screen? Apple's minimalist design strikes again.
Edit: Aha, they addressed this: "With the new scrollbars, if all of the user’s pointing devices support both horizontal and vertical touch scrolling, the scrollbars are hidden during normal use. They will appear as an overlay on top of the window's content while the user is scrolling, and remain visible briefly to allow scrollbar dragging."
"When you’re done with AirDrop, close *the Finder* and
your Mac is no longer visible to others."
I wonder if that's a typo and they really meant 'Finder window' instead of 'Finder'. In the current Mac OS X, you can relaunch the Finder but you can't keep it closed.If the copy on the Lion page is accurate, then Apple is moving towards operation without the Finder, replacing it with Launchpad and Mission Control. I can see how that could work for first-time Mac users, especially those who already have an iOS device.
It reminds me of At Ease [1], an environment that hid the Finder from new users, offering something similar to Lion's Launchpad.
Although, if Mail 5 is inspired by Mail on the iPad, it's probably more fair to say that Sparrow looks almost exactly like Mail on the iPad. Also, is that right that the developer preview is being distributed via the Mac App Store? How does that work?
I will say though, I'm looking forward to impressing potential clients with some fancy swiping at the coffee shop :)
I use fewer site-specific browsers than I otherwise would because of memory usage, but these days many of us have 4-8 GB RAM and running one or two SSBs doesn't break the bank, so to speak.
A. They don't automatically close. (I think you can change this for each web app individually, but I would like a browser-wise setting). This wouldn't be a big issue, if not for...
B. The close button is freaking tiny. I can dismiss Growl notifications by clicking anywhere on them, which is much nicer on a laptop than trying to move to a small button.
C. The notifcation windows resemble what Apple calls panels. [1] The problem is, "Panels float above other windows and provide tools or controls that users can work with while documents are open." [2] The user isn't meant to be closing panels often, which is why the title bar can be small. Chrome's notifications feel out of place in that regard.
1. http://maxcdn.googletutor.netdna-cdn.com/wp-content/uploads/...
2. http://developer.apple.com/library/mac/#documentation/UserEx...
That's strange. They automatically close for me and I didn't change any settings anywhere.
I would be nice if they were just Growl notifications however.
Sparrow's ui is mostly fine - but a bit frustrating at times. I find occasionally I miss new messages - something that never happened in mail.app.
But, it really does combine the best of both worlds between Gmail and a desktop app.
You get a "redeem" code from developer.apple.com that you enter into the MAS like you would an iTunes gift card, and Lion starts downloading.
File Sharing for iPad: Lion Server delivers wireless file sharing for iPad. Enabling WebDAV in Lion Server gives iPad users the ability to access, copy, and share documents on the server from applications such as Keynote, Numbers, and Pages.
This sounds like the OTA iOS file sync we've been waiting for.
I really really hope they offer a "blow it away and restart from scratch" option for apps. Having to delete and reinstall apps on the iPad that have properly crashed (as in fall over, and then when restarted just crash straight away again†) is annoying.
I actually preferred the 'inferior' way of doing things back when iPad was single tasking, because hitting the home button would undo most programmer screw-ups.
†Not sure how they manage this, probably via some settings in their core data that they read in and then get borked up again each time. My theory is that removing the app and then putting it back in works because the persistent storage for that app gets reclaimed when removed.
To force quit, you stay in the app you are quitting, hold down the power button til you get the power-off bar, then hold down Home til the app quits.
If you scroll all the way to the left, you get a bunch of music options, and the screen orientation lock, which is quite useful since they decided to remove that function from the hardware switch.
Now, while that bar is showing, you can press and hold one of those recently run apps, and it will jiggle and you can force quit it by pressing the x in the corner, very much like removing the app. As far as I know the force quit through this method is the same as the one with the power button and home key thing (maybe a bit faster).
Where your technique comes in handy is that the list of recently run apps does not include the currently frontmost or 'runningest' app or whatever it is. So you can't quit an app while you're in that app using the ribbon technique.
$ open Library
to open it in a Finder window.
# SetFile -a V ~/LibraryI'm happy about the OpenGL 3.2 support. But what about 4?
Also, what's AV Foundation? Is this what QuicktimeX was supposed to become? Will we finally get codec plugins without having to program for the crusty old Component Manager?
You'll also be able to download the latest 10.6.7 build if you'd like.
iOS GMs have always been ready to ship, minus a few 3rd-party apps and last minute exploits(JBs). If they are throwing GM designator on anything that isn't usable than I'm severely disappointed.