That's a pretty nasty move and I feel the mask has slipped slightly here for Apple.
That's a pretty nasty move and I feel the mask has slipped slightly here for Apple.
On a device I own, there should be no parties that are trusted more than myself. It's ridiculous I even have to write this.
TIL I learned "GNU" is somehow pronounced with one syllable ("gnew") and not two ("guh-noo"). (I know lowercase "gnu" is pronounced with one syllable.)
It starts out reasonable, but then has gems like "please buy bus tickets only with cash under a fake name", "find me a parrot", "go to the hotel and figure out if their phone jacks do dial-up because that's most likely the only thing that will work with my machine".
The latter may have adjusted with the times, since the document is old; but then again, the demands he places on streaming technology etc. are perfectly reasonable nowadays, but a massive obstacle back then.
This is because he's actively against surveillance. It's not a hard requirement, I've lent him an anonymous (i.e. pre-paid) public transport card before, and while he didn't like the requirement to both check on and check off, he did it anyway.
> find me a parrot
That's a misrepresentation. It's a "it'd be nice if" type thing. There's also the "don't buy one" comment, because you can be sure someone has done that.
> go to the hotel and figure out if their phone jacks do dial-up because that's most likely the only thing that will work with my machine
That might be really old, his machine definitely has wifi. And if the request is from the pre-wifi with free software drivers days, it's completely reasonable for someone who lives a chunk of their life on the internet to request internet access.
It's much, much more reasonable than you're making out, especially if you consider it in the context of why you're probably asking him to speak at some event.
That's exactly what protesters did in Honk Kong in 2019 to avoid retaliation from China
So he was right, again
More recently, he was pushed out of MIT and the FSF last year for questioning whether one of Jeffrey Epstein's victims was truly a victim or not.
He prefers Emacs over Vim.
There are probably other examples, but that's off the top of my head.
He's a monster.
`cat>newfile.txt` - teaches you not to make typos.
I wasn't expecting to laugh, haha. This is great, good stuff!
...But seriously why? How could such a thing be possible?! I would like to know his reasons.
I’ve never really been much of an RMS fan beyond admiration for what he has done for free software, but this is not what he said, at least according to his words as quoted in the post that initiated his cancellation[1]. I’ve pasted it from that post below [2]. The author of that post quoted this and then somehow inferred this [3]. How she (and everyone reading it thereafter) went from one line to the next from “she PRESENTED herself as willing” (not that she actually was willing), “assuming she was being COERCED by Epstein” somehow got reinterpreted as “she was entirely willing”.
Nothing RMS said stated he thought she wasn’t a victim, just that Minsky may not have known due to how Epstein coerced her to present herself.
But hey, the witch hunters got their burning.
[1] https://medium.com/@selamjie/remove-richard-stallman-fec6ec2...
[2] We can imagine many scenarios, but the most plausible scenario is that she presented herself to him as entirely willing. Assuming she was being coerced by Epstein, he would have had every reason to tell her to conceal that from most of his associates.
[3] and then he says that an enslaved child could, somehow, be “entirely willing”.
The context also make his comments strain credulity beyond the breaking point. "We can imagine many scenarios, but the most plausible scenario is that she presented herself to him as entirely willing." So this 73 year old man has a 17 year old approach him for sex on one of his patron's famous young-girl-harem flights, and I'm to understand that Minsky can't apply his AI-pioneering genius to figure out what's going on? Like, am I supposed to believe that he thought this girl young enough to be his granddaughter was just attracted to his magnetic personality? Give me a break.
> Minsky may not have known
Can you really look me in the screen and tell me you believe that? Again I say: give me a break.
I think it's better to call a spade a shovel here and concede that Minsky knew what he was doing. The fact is Stallman probably _didn't_ consider Minksy to have done anything wrong, and that's why he spoke up, and he was "cancelled" because it was pretty plain to everyone else that it _was_ wrong.
I think you’re relying heavily on hindsight here. Yes it’s obvious to us looking in from the outside, but thinking back to any large events/conferences I’ve been at, especially if alcohol was involved, if somebody pretended to be willing because they were coerced to do so, I’m not sure it would have been so obvious and it’s easy to get caught up in the moment and not realise something was off.
But, that’s not the issue here. I don’t necessarily disagree with you and if the argument had stated what you said then it would have been ok to call RMS out.
But that’s not what happened, instead people twisted his words to make him out even worse. Nobody said “how can you believe that Minsky didn’t know something was wrong?” They said “you said she was willing and not a victim! How dare you!”, when he very clearly did not say that.
So you figure 73 year old Minsky was on this plane or whatever, a highschooler offers to have sex with him and he just figured, what, she was caught up in the heat of passion? Maybe high schoolers offer to have sex with him in the normal course of his geriatric affairs?
I think you’re still not really being honest by trying to construct some scenario where Minsky could have not realized this young girl was either paid or ordered to have sex with him. Walk through it in your head and I defy you to come up with a scenario where Minsky could have not known this was a girl being either paid or ordered to have sex with him.
No, I meant he might have been caught up in the moment and ignore his better judgement. Also, I dunno about you, but I iften find it very dificult to tell the difference between a somewhat mature looking highscooler and someone who is 19 — 21 ish. Of course, I also don’t have sex with people in that age group, but my point is that its often very hard to tell if someone is late teens ir early twenties, so, again, in the heat of the moment, especially with alcohol or other substances, its not hard to think that she’s young, but not underage.
I’ve been in plenty of situations where there were “groupies” willing to sleep with much older guys because of fame or oerceuved money or power, where nothing nefarious was going on. So, no, I don’t think its a stretch at all that he could have thought this. I obviously have no idea what the reality was in thus particular situation; neither of us know what Minsky was or wasn’t thinking. I’ve also heard reports that withesses said he turned her down, but I can’t find anything to back that up now, so could be BS.
I’m not saying he’s innocent, he could have been completely willful in the situation, but I do not believe its a 100% clear that he’s definitely guilty either.
And in the context of RMS, I think what he said, in context, wasn’t particularly unreasonable. I think people should have challenged his views and had a conversation like we’re doing, instead if twisting his words to tell a false narrative because they don’t like him and wanted an excuse to attack him.
To be honest you've changed my mind a bit here & I'm a bit more on RMS's side now. Agreed that a witch-hunt was in progress, which caught some "actual witches" and lots of others along the way.
But from an optics perspective, ffs why would you defend an Epstein associate & fellow-traveller at that point in time. I mean he's dead, he's not going to be hurt by the accusations at that point. ️ oh well.
Note that this is current law in Germany.
Does he also prefer apples over oranges?
The nominee is quoted as saying that if the choice of a sexual partner were protected by the Constitution, "prostitution, adultery, necrophilia, bestiality, possession of child pornography, and even incest and pedophilia" also would be. He is probably mistaken, legally--but that is unfortunate. All of these acts should be legal as long as no one is coerced. They are illegal only because of prejudice and narrowmindedness.
[0]: https://stallman.org/archives/2003-may-aug.html
---
I don't think child pornography should be legal.
14 September 2019 (Sex between an adult and a child is wrong)
Many years ago I posted that I could not see anything wrong about sex between an adult and a child, if the child accepted it.
Through personal conversations in recent years, I've learned to understand how sex with a child can harm per psychologically. This changed my mind about the matter: I think adults should not do that. I am grateful for the conversations that enabled me to understand why.
[0] https://stallman.org/archives/2019-jul-oct.html#14_September...
---
Stallman's former view on this was always wrong. But it is good to hear he has changed his mind, and I think to be fair to him, if one brings up his former views, one should also bring up his more recent disavowal of them.
I hope that he has changed his mind, but until there's some evidence that he's changed his behavior, there's no reason to assume he was doing anything but covering his ass (possibly at the behest of someone else) and trying to save his position and status. That's what would be assumed of anyone else, that's what should be assumed of him.
I think his former views were completely wrong, but I try to understand where he was coming from: RMS comes out of a progressive 1970s cultural milieu in which a lot of people were willing to question all aspects of traditional moral values, including age of consent laws. I can think of a number of now-mainstream European politicians, who in the 1970s were willing to associate with (or at least tolerate) "pro-pedophile" advocacy groups, and that way they behaved in the 1970s has come back to bite them – Daniel Cohn-Bendit, Harriet Harman, Jack Dromey, Patricia Hewitt. Someone like Allen Ginsberg, who was an open member of NAMBLA – and, by at least some accounts, actively abused underage boys – was nonetheless an acceptable figure in polite society – something that would be quite unbelievable in the year 2020. In the 1970s, a lot of what is now the mainstream gay rights movement was willing to associate with organisations like NAMBLA; by the 1980s, the mainstream gay rights movement had fully severed those ties, which was a prerequisite for the cultural and political successes of the LGBT movement of today. In the 70s, the victims of child sexual abuse were largely invisible, they were not being heard in the conversation in the way they are now, and society (including much of the radical left) had not yet begun to take their experiences seriously.
What makes RMS a bit different, is that figures like Cohn-Bendit, Harman, Dromey and Hewitt, realised their mistake (or at least cared enough about social acceptability to move with the times.) RMS clung to this view long after it had become seriously socially unacceptable in a way it had not been in his twenties. Why?
Well, it is obvious to me that RMS has a lot of autistic traits (as do I myself). I'm not the only person to notice this – https://news.ycombinator.com/item?id=20969320 – to arrive at and defend socially unpopular positions through application of abstract reasoning, completely divorced from real world human experience, and then to cling to them pigheadedly, is something a lot of people with autistic traits end up doing at some point. So I think his autistic traits are another big part of the picture here that other people may not be seeing.
RMS' former views were always wrong: I'm the father of two young kids myself, to me their wrongness is completely obvious. But I can understand how something which is completely obvious to me, even to most people, might not have been obvious to him, and why it might have taken some real world interaction with abuse victims for him to understand it. And, to the best of my knowledge, these wrong views of his were purely theoretical, I've never heard any claims he's actually acted on them, or even had any personal interest in acting on them – unlike someone like Allen Ginsberg.
I'm not saying this because I think he should be the leader of the free software movement. I think he has done an enormous amount for that movement, but it probably now would be better served by someone younger and more attuned to contemporary culture. But he's a human being, and I feel the urge to understand him sympathetically, rather than join in a mob out to get him.
There should always be room in society for someone to see the error of their ways and amend, but it's going to take more than a tweet's worth of text to make up for decades of - and let's be honest - sometimes passionate advocacy for reprehensible behavior, and the anecdotal evidence of creepy behavior towards women IRL, and that's not unreasonable. Sympathy doesn't mean one shouldn't expect growth.
Frankly speaking, I think most of the "normal mainstream" that condemned Stallman without even bothering to check up on and verify the facts of the accusations made against him outed themselves as easily manipulated, savage, and unstable individuals with little or no consideration for the damage they heaped upon a man who was doing nothing more than trying to encourage postponing of judgement until the facts were all in. In that one, tragically twisted-by-the-media email, Stallman did exactly what any civilized person who believes in the tenets of our system of justice should have done. He called for calm, and to give his friend the benefit of a doubt until all the facts were in. The "weird creepy guy" acted more in line with the ideal of normalcy than anyone else!
I'd take 100 more people just like him with all the inherent quirks than any of the mob who rushed to condemn him without even so much as getting to know him. I mean, good God. Show me someone who hasn't had a questionable view in their life from lack of reflection, and I'll show you someone who hasn't actively tried to get to know all the many facets of their species, or consciously come to terms with their own capacity for atrocity.
Let he who is without sin cast the first stone! Til then, people need to nut up, shut up, and take a damn number. Thank who/whatever they worship they woke up this morning, and give thanks but that there for the Grace of $Subject_of_Worship go I.
Now get off my lawn, and keep your damn chickens out of my garden! They may be cute, but they're ruining my sprouts!
grumble grumble
If there were anything else, fanboys like you wouldn't hesitate to mention it every time you want to pull the "autism sympathy" card to make anyone who's been creeped out and offended by his behavior out to be " easily manipulated, savage, and unstable individuals" who can't comprehend the tragic, broken genius who's too good for this world.
The movement will be fine. The movement doesn't need him, and if it does, it's not a movement, it's a cult.
>I'd take 100 more people just like him with all the inherent quirks than any of the mob who rushed to condemn him without even so much as getting to know him.
Yes, well, you can have your hundred quirky middle aged pedophile apologists, as society seems to have enough to go around. I'll be satisfied when they're kept away from positions of authority and their behavior stops being defended by people around them. Just be sure to burn your sheets after they stay over.
Jesus Christ, get some perspective.
If the person is also resistant to discarding views merely because those views are hated, then, well, it's easy to see how their beliefs might end up where they do.
you may be surprised at some of the names here:
https://www.wikiwand.com/en/French_petition_against_age_of_c...
I'd bet you have to be really sloppy nowadays to get caught.
I don't think it is a black and white issue as much of a tool of entrapment. I am not pro possession of it, but the laws are clearly entrapping innocent people. Romeo and Juliet laws exist for underaged people, should a similar law exist if you make it yourself so you don't get labeled a sex offender for making a video of yourself?
During his time it was about not legislating everything. Dworkin who was anti pornography debated a conservative judge, who saw no difference of exploitation of children as of women. Here she debates a conservative judge on wanting to make it illegal. https://m.youtube.com/watch?v=zt8KVB8AunQ
I can find one thing I disagree with on anybody
Btw he wasn't even completely wrong on this one...
I trust Apple more than any party in the world. Even the government. Fortnight devs, Epic, whatever are not even on the same radar. They'll sell your privacy in milliseconds if they can get 2.5 cents for it.
I would never ever own an open source phone. Not because the operating system is open source (probably good that it has eyes on it) but there is no way to control third-party apps. Even the os builds can get hacked and I cannot trust it. I have so much personal stuff on my phone on it that I cannot afford to entertain Richard Stallman and his righteousness.
That opinion is likely to be a bit of an outlier, heh.
If not for IME, I could have a computer under my control, running software guaranteed to be free from the Trusting Trust attack, right now.
People like yourself can probably manage their own security, have a secure NAS, multiple firewalls, etc.
Do you see it from the perspective of average Joe (or me)?
I usually choose to trust them, because it's convenient and because they probably know better than I do. But my trust in Debian is completely voluntary, non-exclusive and revocable.
This doesn't need to be an either/or situation. You can outsource your security and privacy decisions to Apple while simultaneously allowing others to take full control of their devices.
Given the conditions of how ignorant large percentage (~ 99.999%) of the Apple customers are, I would trust Apple more than any other party to keep them and myself safe.
Can you imagine third parties siphoning off data, metrics, photos, etc. without Apple safe guarding user's interest?
I would pay a lot of premium for security if I don't have to do it myself.
I am not saying that Apple is not prone to hacks, gov influence, but based on their past record, their stance on privacy - who else could be more trust worthy?
Can you provide examples of whom you would trust more if you owned an iPhone to manage your phone?
I agree that things like openssh can be more secure because there is a huge number of individuals and corporations using it, there are a lot of eyes on it. It is open source and secure.
That's not the same as something as big as an iPhone. iPhone is an ecosystem of apps, cloud data, biometrics, hardware encryption (secure enclave), etc. and finally the physical device.
I rather use my brain cycles for something else. This is compounded for people who have no interest in tech but rather just want to use them to perform certain tasks.
Are some of practices unfair sometimes to a small subset of companies/developers. Definitely yes, But what are the other options that have this level of privacy or trust worthiness with a similar ease of use/setup. I don't know of any.
It's more or less choosing the lesser evil.
It would be interesting to see if these users views stack up in practice or these are just beliefs that are not practically demonstrable.
Dev tries to make it super flexible, tries to make it fancy, implement DRY like one's life is dependent on it ultimately resulting in a hard to read/maintain messed up spaghetti code.
Also i don't see how can a person know all of the security stuff with a beast like Android unless they spent/are willing to spend an insane amount of time on keeping up latest exploits, architecture etc.
Sometimes choices are not a good thing.
The power you're talking about (and the risk you're not talking about) are of no value to me.
Fortnite tried pushing people to side-load on Android is a perfect example.
Even though that step failed, still a lot of people did side-load without knowing what they were doing and that's a problem.
Your phone's security will not be compromised by adding an extra optional feature.
Like root certificates, you have to trust someone, at some point. I am choosing to trust Apple.
By allowing side-loading apps, that is eroded, even if the tiniest bit.
I'm not talking about the pedophilia comments, the sexual harassment of women in tech, or the toe jam. All those are well documented and don't need restating. No, if you look at the FSF's recent policies regarding software freedom, they are also bass-ackwards.
The FSF had a "respects your freedom" certification which is designed to encourage devices to be less free, thanks to a concession for blobs and proprietary firmware. Effectively, they know that it's impossible to build modern hardware without blobs, so instead what they did is require those blobs to be hidden, immutable, un-freeable, un-auditable. That way they can claim, for all the clueless free software evangelists, that the devices are 100% Free (because there are no closed blobs in /lib/firmware! They're just... elsewhere, where you can't see them, audit them, touch them, or actually replace them with a free version). I wrote up the story in this Twitter thread, it's crazy:
https://twitter.com/marcan42/status/1040626210999431168
Then there is also the AGPL, which isn't a Free Software license, but rather an end-user license agreement (EULA), because it violates Freedom Zero: the freedom to use software however you want. All free software licenses only impose restrictions on distribution, making them copyright licenses - you can use original or modified versions of e.g. GPLed software at will, with no condition, as long as you don't redistribute them to others. The AGPL requires advertising and offering source when used as a network server, which is a condition on usage, and thus incompatible with the Free Software definition. rms will never admit to this, but AGPL-licensed software is, by any reasonable reading of the Free Software definition, not Free Software, and shouldn't be included in the Debian main repository, for example. It's just that nobody seems to be able to read past the "AGPL is from the FSF so it must be free software" idea.
These are just some ways in which the FSF and rms are hurting their own cause. If you want to support an organization, I would recommend the FSFe instead of the FSF. The European branch is actually doing good work for free software advocacy, instead of all the nonsense the FSF is doing which only makes the movement look worse.
This is common in politics, so I don't blame you, but I don't think you're serving yourself or anyone else well.
Claiming that it is, though, sure sounds like a common dismissive tactic in politics, and especially when defending people who otherwise commit undesirable, even detestable public actions ("but he's a great guy, he'd never hurt anyone" etc).
If you have this opinion of the AGPL, then you should also have it about the GPL, since the only difference between the two is section 13 of both of them (seriously, just diff them) which says that conveying over a network also triggers copyleft. This is just a modernisation of plain ol' copyleft from the days when conveying was mostly done on physical media instead of over a network. If some day we discover a way to distribute software over neither a network nor physical medium (I can't imagine what that could be... quantum entanglement?), then the definition of "conveying" should be updated to reflect the new technology.
The GPL has long been considered open source by OSI and free software by the FSF. You are free to use the software however you want -- you're just not free to deny this freedom to your users or clients, with neither the GPL nor the AGPL.
You might think this is a valid clause to include, and like its effects, and that's fine (though a close reading of that AGPL clause reveals a myriad of problems; it's extremely poorly thought-out and I find it unlikely that it would survive in court if properly challenged, with many workarounds possible, or causing problems for normal usage, depending on interpretation). But it doesn't change the fact that, suddenly, it makes it into an EULA, since it imposes a condition on usage, not distribution.
The GPL and other Free Software licenses strictly give you rights. You have no right to copy software by default under copyright. Those licenses give you the right to do so, subject to certain conditions.
The AGPL removes rights. It removes the right to use (not distribute) the software as you wish if you do not follow certain conditions (that you don't modify it without making those modifications available to remote users who are otherwise not receiving a copy of the program anyway, and not invoking copyright).
Linux distributions should be including the AGPL as a click-through license when users request to install such software from the repositories. In the current status quo, users are required to abide by terms they haven't been required to read, and might accidentally violate the license by doing something that is otherwise legal, such as editing a script in /usr that is part of such an app and exposing it over the Internet.
It's not a requirement on users anymore than the GPL requiring you to distribute corresponding source on CDs was a requirement on users. Morally and legally, the distribution medium does not make a difference. When you make the software available over the network you are no longer the user -- the users of the software over the network are the users. When you convey the software over the network you are a network operator and a distributor. Being a network operator and a distributor imposes obligations upon you.
It is not a EULA. The AGPL even says, in the same section that the GPL says (to wit, section 9) that you don't need to accept it in order to be granted its rights.
If I give you a CD with nginx, I'm distributing it.
If I send you a .tar.gz with nginx, I'm distributing it.
If I bring up nginx on a server, put some HTML files in the webroot, and give you a URL to it, I am not distributing nginx. I am merely using nginx, and offering you a service using nginx. I am not offering nginx itself. I am distributing my HTML website, and I am merely using nginx for it.
Cases 1 and 2 invoke copyright. Case 3 does not. In the absence of a license, you are not allowed to do 1 nor 2, but you are allowed to do 3. I can give you software I created, say nothing whatsoever about its license (which means, implicitly, "all rights reserved"), and international copyright law says you can not do 1 nor 2, but you can do 3.
The GPL, BSD, and other free software copyright licenses say you can do 1 or 2, under certain conditions.
The AGPL, and other EULAs, says you can NOT do 3, unless you meet certain conditions (other EULAs may, for example, limit the number of users, which would be typical for typical proprietary software server EULAs; the AGPL limits how you can serve the software, in that you must provide source changes to users of the service).
Therefore, the GPL and BSD strictly grant rights (to copy). The AGPL both grants rights to copy and restricts rights to use. It is therefore not a copyright license, but a contract, an EULA, a click-through usage agreement. And anyone who treats it as a copyright license (i.e. users are not expected to care) is doing a disservice to their users, because they are, in fact, not allowed to use the software without abiding by that contract (license).
If nginx were AGPL-licensed (thankfully it isn't), and I made a change to the source for personal use, then the AGPL would require me to stick a download link to that modified source in the footer of every website served using that copy of nginx, even if I am not serving the nginx binary itself.
The GPL is already perfectly suited to cover distributing software on the internet, as tarballs or whatever. The GPLv2 had some outdated provisions referencing a "medium" and written offers (e.g. the CD story), and the GPLv3 already covered that by saying you can just send the source via the same medium as the binary, e.g. from a network server.
The AGPL is a very different beast, and it has nothing to do with updating the GPL to allow for network transmission of the source, as you seem to imply.
Have an example: I run a Nextcloud instance for personal use. It is AGPL-licensed. Thankfully I have not made any changes to the code. However, if I touch a single php file in my /var/www/nextcloud (other than config files - hopefully, the AGPL is too vague to say for sure), that means I now need to figure out how to package and distribute that change to literally every visitor to my instance, which could be anyone on the internet (even if they just hit the login page). This is NOT possible with a purely copyright license. And my distribution did not warn me about it (like they did for proprietary software EULAs, which require an explicit ack), because they erroneously believe that the AGPL is not an EULA, because the FSF wrote it.
Does this make sense now?
People add links to the source code because it's much less work than responding to emails. It's entirely voluntary. Users have a right to the source code of AGPL software you make accessible to them and you can satisfy that constraint any way you see fit.
> your modified version must prominently offer all users interacting with it remotely through a computer network [...] an opportunity to receive the Corresponding Source of your version by providing access to the Corresponding Source from a network server at no charge [...]
An email does not cut it. It has to be a direct link to the source, or some kind of equivalent mechanism to directly download it from a server. Merely providing you the opportunity to ask a human for it does not cut it (an email bot might, but that'd be dumb).
It is an copyright offence to perform any of the following acts without permission of the owner:
Copy the work.
Rent, lend or issue copies of the work to the public.
Perform, broadcast or show the work in public.
*Adapt the work.*
A person who take a copyrighted software and adapts it into a online service need to get adaptation permission from the author. If the work is given out under a AGPL license then that license is proof of permission as long as the person follow the terms, just as with any other copyright license.You do not need permissions from a copyright license unless the action a person does falls within the scope of copyright. If a person don't copy, rent, lend, issue copies, perform, broadcast, show, or adapt the work, then the AGPL conditions are irrelevant because the user do not need permission in the first place. An EULA or contract however is not limited in this way and can restrict usage of a program outside the scope of copyright.
While it is true that copyright protects the right to create derivative works, that is, in practice, usually applied to creating such derivative works and distributing them. Otherwise, scribbling with a pen on a book you bought would be a copyright violation.
Similarly, while technically running a program requires copying it into memory (and thus requires a license), no court in this day and age is likely to rule that running software which was acquired legally, but which does not come with a license to run it, is a copyright violation.
The memory issue has been well discussed and handled in the past. The law has an explicit exception made with this in mind where legal owners of the software has a right to both copy and adapt software if it is an essential step towards utilization of the program. licensees however does not have this right and are restricted to the terms under the license. Naturally this is designed more towards the world of proprietary software where such distinction is more clear.
The AGPL attempts to control any changes made to the code, not just, say, a substantial refactoring or reworking. So in principle a one-line patch is sufficient to trigger AGPL clause 13.
Does it make sense now?
In fact, courts have repeatedly ruled that the output of software (i.e. the packets nginx sends over the network, but which aren't its own code) is not covered by the software's copyright itself.
If I lend you my phone, in the absence of more restrictive EULAs, and excluding media (which is reproduced verbatim by the phone), you are free to use any software on it without being subject to the copyright of said software.
Does it make sense now?
Does it make sense now?
You're grasping at straws here. There's provisions based on copyright, and then there's everything else. Redefining users to exclude the person running the server and implying that means the person running the server loses all rights under the Free Software definition is ludicrous.
Once you serve to other users, though, they also become users of nginx. In this regard, you have an upstream/downstream relationship between you and the other users of nginx that you've made users by giving them access over the network.
You are still free to use nginx for your military website or your online shop or whatever. Your usage of nginx has not been restricted for any purpose.
By granting network accesss to our hypothetically AGPLed nginx, though, you now have an AGPL obligation to provide a link to the source code of nginx, in case you modified that source yourself. This isn't taking any rights away from you -- indeed, the AGPL is only granting you rights. You wouldn't have the right to even serve nginx to other users or to modify its source code if it weren't for the AGPL.
None of this is substantially different from the GPL except for the method of interaction with the software.
Note that a shrink-wrap end-user license agreement from Adobe also doesn't take away your rights; it only grants you rights.
At least, according to copyright rhetoric.
Merely receiving a license-free piece of software (i.e. "all rights reserved") with no strings attached gives you a certain set of default rights (i.e. anything not in violation of copyright), such as to run it for any purpose. EULAs like a shrink-wrap agreement from Adobe, or the AGPL, then attempt to remove some of those rights.
Though, sure, you can look at it from the point of view that in the absence of a license at all, nobody would've been able to distribute the software to you in the first place, and therefore you'd have had no rights as a result.
Yet, the copyright law is what the AGPL is trying to wield as its basis.
It does not seem valid. Has anyone tested it in court?
I don't think that copyright can assert use restrictions. You cannot say that someone is not authorized to have a copy of something if they do not use it in such and such a way.
It's exactly like a "license" written in the flap of a book which says that you must read only the even-numbered pages. If you read any odd-numbered page, then you are breaching the license under which you're permitted to have a copy, and must destroy the book.
I would cheerfully deploy a modified AGPL program and not reveal the code to anyone. Nothing would happen at all.
I'm surprised Google are so allergic to the AGPL. If it came down to it, they could crush this bullshit in court like swatting a mosquito.
The notion that the platform owner is somehow doing you a favor by denying you that choice is nothing but a manifestation of Stockholm Syndrome in action.
We can put all the warnings on bleach we want, someone out there is still going to drink it.
If we went with the Apple solution, this means nobody gets to use bleach.
Some mistakes are costly, but people learn from them. Such is life.
Can you get social engineered into crashing a car or stabbing yourself? The difference here is that people most likely know the consequences of their actions, unlike with phones/computers where the consequences are nebulous.
So maybe they need to be educated on that? Or just, in general, to think critically at all times?
> Can you get social engineered into crashing a car or stabbing yourself?
There were cases of people "social engineered" into wearing bomb belts and blowing themselves up. It's just that this social engineering was much more sophisticated than telling someone to send bitcoin to have it doubled.
Ah, these are pretty simple things. We don't allow to sell any drugs, or some drugs without prescription, because drugs are hard and require education. So do computers.
Imagine someone selling you a house and despite that you think you own the house the seller defines what things you can or cannot have in your own house, and even the ones he let you have, you must buy through them (so they can get a tax and force control) and if suddenly they are not ok with that anymore, it can simply vanish from your home.
"Hey look, you cant have that knife that its not from Apple Houses, it will hurt your kids.. we are always thinking on your safety"
Then you buy a car that you think its the one you like, but its not on you Apple Home store, so you are not allowed to drive that car.
But hey Apple homes have said its for your own safety, because that car was evaluated and could kill your wife.
In this case its clear "Apple Homes" succeeded in through marketing in psycological tatics to influence the house owner to do be ok with those things and still think he actually owns the house while the property is in reality leased where they define what you can access to or what can simply vanish even if you bought them.
I just cant understand how people can try to defend this sort of behaviour even when its clear it goes against their self interests and can damage them in several ways.. as the parent have said, just some sort of "stockholm syndrome" can explain this.
That's exactly like housing in developed world works, lol. When you buy a flat in Germany, you implicitly agree on a huge set of rules.
No one would allow you to buy a flat and turn it into a brothel or a disorderly house, or even run a pretty legal business in it) And many have additional rules, like not playing piano too loud.
But your analogy is wrong. Apple doesn't prohibit you to do something with your phone, they regulate the service they provide to you on a constant basis. Following your analogy if you've bought a flat, nobody is obliged to deliver food to you, especially when some food vendors do not comply with delivery's rules.
This line of thinking doesnt apply in the relationship between Apple, its developers and its consumers.
Its a direct relationship and we are trying to understand here what rights Apple have vs. the rigths their developers and consumers have.
> Following your analogy if you've bought a flat, nobody is obliged to deliver food to you, especially when some food vendors do not comply with delivery's rules.
What you are lacking here is that theres a conflict of interest going on. The better scenario would be "Apple Homes Inc" also owning a fast-food chain, having the power to define, the food delivery you have access to.
The key thing here, is that they do it before you are even aware you are lacking options. So you wont feel as freedom of choice is being taken from you, because when you look at the "food store", you have options. And having options make you feel that you have choices and freedom, while you actually dont.
Some people like you, could be fine with it. But my main point is that its breaking foundamentals laws our societies are built on. Freedom, property, etc..
There is no specific law yet, because its unregulated. But im pretty sure that once law experts decide to really tackle this issue, some of those things will get much clearer.
A company like Apple or Google have too much power with this, and you can imagine the mess if somehow the powerful of the world get their hands on this powerful pipelines that can control the lifes of so many..
Without good and effective laws to really regulate them, we can be in a mess real quick.
(And im not even debating the rights of people who create apps and are dumped with clients wanting their products but not being able to reach them, because Apple forbid them with bogus reasons)
Don't people normally get qualified to drive, controlled by the Government? Is that what you are advocating?
The problem is that most people know nothing about software distribution, signatures etc etc, and would become an easy target for fishers, as they do on Windows or Android. People oft underestimate how little avg user knows about computers and basic hygiene.
That doesn't sound like my problem, or, frankly, yours.
If you create an environment where careless people never experience the consequences of their carelessness, then rest assured, you won't get fewer careless people or less careless behavior as a result. You will get more of both.
You will have bred a culture of dependency... which is certainly financially convenient for Apple.
They are not careless, they are uneducated on topic. Are you advocating for finishing FDA and drug regulation, because if people bought wrong drugs, it's their carelessness and consequences are just?
That's nonsense. Historian should not know much about computers, just like me, a computer guy, should not know much about drugs. If there is a company allowing safe computing, which Apple is, people are better to stick with it, and you are better choosing linux or something and stop advocating for reducing people's choice.
Not when people don't thoroughly understand the possible consequences, no. Same as why drug prescriptions are not just recommended, and driving license is not optional.
It's either the enforcement of training, or the walled garden.
Making mistakes is a crucial part of learning.
https://www.npr.org/2015/03/02/390245038/ben-franklins-famou...
Because Apple has shown that they will use that mechanism to exert commercial control, not just to secure your data.
Is Chamberlain the curator of the garage door opener product, so they can determine what remotes can be used?
You may prefer a world where DRM and the DMCA can be leveraged beyond preventing copying to constrain consumer choice, but I consider that a poorer and less innovative world.
https://www.eff.org/wp/unintended-consequences-under-dmca/ar...
It's incredibly scummy and inappropriate, but I would put it more along the lines of an attack-ad than an outright ban.
Edit: Now, one thing that isn't totally clear is whether or not devs who have their own developer accounts, and use Unreal Engine to target iOS, can still make iOS builds. If not that's a much bigger deal, though the fundamental issue would still lie with iOS, not macOS.
(`spctl` does not, in fact, disable it completely.)
I don't think thats an option on newer MacBook Pros any more.
On Windows, at least, the “Run anyway” button is merely behind the “More information...” link.
A ragtag band of devs all banned-for-life from Apple’s stores could put together a new app-engine or game-engine that other devs use as the basis for their app and provided that those apps don’t break the rules about undocumented APIs or malware (and no-one in Apple’s higher-ups gets suspicious...) then those apps will appear. I don’t believe Apple has any way to automatically ban or delete all apps that use the same third-party libraries by using their macOS Notary system or iOS Certificate revocation system - they’d have to inspect every published app-package individually (granted, this would be automated, but you know what I mean).
As far as I'm concerned, Mac openness is just a cat that got out of the bag, before anyone knew they could produce a _mint_ from rent seeking walled garden platforms. I find it highly unlikely Apple is not looking to correct this mistake on Mac, even if it's done so gradually that by the time the pull the trigger, no one even bats an eye.
I would not be shocked however if at some point they switched to developers having to buy special Macs to have this capability, and normal Macs would cease to be able to turn off secure boot and SIP and would require code signing/store distribution universally.
[1]: https://developer.apple.com/programs/security-research-devic...
You right click it and select “Open”...
Almost all MacOS users even the non-technical types encounter this at some point unless they go 100% Mac App Store which almost no one does if they have a job.
I gave up on catalina when I couldn't install little snitch without a network connection.
(Apparently there's a way, but I don't know it - it wasn't csrutil)
You use a pavlovian adequation mechanism on your users for some time, labeling as "dangerous", until you completely ban the thing.
By then users wont miss.
I´ve never used anything Apple by this same reason. Apple seems to think that once you by one of their products, they own you.
Its not just inappropriate, for me its pretty scary and humiliating.
Its like that girlfriend or boyfriend who thinks it owns you, and want to say what you should dress or if you can hangout with our friends.
It dont get it how people can be ok with this kind of stuff (as this is just one example) and later just say it snarkly as if it was your kid being naughty, where actually it can have severe consequences if they can get away with it, and future generations wont even argue because its already normalized for them.
The scary warning and convoluted workaround for running un–notarized apps is ostensibly to prevent non–technical people from compromising their computers. Now Apple is abusing that security mechanism for Business Reasons that have nothing to do with protecting users.
The fact that users can technically bypass it is a weak defense; if it’s an effective way to stop malware, it’s probably an effective way to prevent people from running Unreal Engine games as well.
Probably only one or the other. If Epic produces legitimate software that users have a legitimate reason to run, some of them will become accustomed to clicking through in order to run a legitimate program. Then, they will become more likely to click through on other programs: "Oh, they're probably banned for business reasons like Epic, not for security reasons like malware".
Apple is clearly hoping that is not the outcome, and that Epic simply loses as close to 100% of their Apple-based customers as they reasonably can.
Sounds like Apple will rather teach young consumers to ignore security warnings.
The end result will be that Unreal Engine, and all applications developed with it will be dead in the water on MacOS/iOS/iPadOS.
From the the legal filing:
>... when Epic sued Apple to break its monopoly on app stores and in-app payments, Apple retaliated ferociously. It told Epic that by August 28, Apple will cut off Epic’s access to all development tools necessary to create software for Apple’s platforms—including for the Unreal Engine Epic offers to third-party developers, which Apple has never claimed violated any Apple policy. Not content simply to remove Fortnite from the App Store, Apple is attacking Epic’s entire business in unrelated areas.
and...
>Apple stated that unless Epic capitulates, Apple will also block “[e]ngineering efforts to improve hardware and software performance of Unreal Engine on Mac and iOS hardware [and] optimize Unreal Engine for the Mac for creative workflows”.
PDF link: https://cdn2.unrealengine.com/epic-v-apple-8-17-20-768927327...
And that's the issue. The overwhelming body of evidence in recent years suggests Apple does not consider the devices they make to be "yours." Rather, their attitude seems to be that those devices forever belong to Apple, and Apple simply allows you to pay for the privilege of using them.
The user is locked in to a large minimum spend; the user is responsible for EOL disposal of the device; the users perform self price discrimination, where more wealthy users replace their phone more often so effectively pay a higher monthly rate.
It is ridiculous. Nowadays, physician could do a surgery in remote. How about during operation there is an update.
Some of versions does not have ability to stop updating (maybe current version of Windows 10 Home?).
This is only true if you contain at least the minimum amount of knowledge to built said device yourself. If you cannot design the type of CPU required, you must trust the vendor. If you cannot design the RAM, you must trust the vendor. If you cannot design the motherboard, you must trust the vendor.
You must also have the ability to supervise every step of construction. If you don't have that ability, then your knowledge is worthless.
You can only be the most trusted party in your system if you can be personally 100% certain nothing was inserted into the system without your knowledge. This is not restricted to the software, which theoretically you could inspect the source code to.
Maybe there SHOULD be systems where you are the most trusted party, but realistically, there are almost none. You have to trust the engineer who designed the road, the worker who delivered the package, the maker of the chips that go on the board, the company who makes the air filter in your home HVAC, etc.
Society is built on trust.
It's as if you bought a house but couldn't repaint the walls and rearrange the furniture to your liking. You'd have to call a special person from the company that built the house.
You do indeed have to trust the designers, manufacturers and suppliers of your equipment, in the sense that they are in a position to cause you harm without a realistic way to prevent that beforehand.
However, when "trust" is used in the sense of "what is allowed", what we're actually talking about is sovereignty or authority, not "trust". I believe the word is used in this context because giving a third party authority over your device necessarily puts them in a position of trust, but it is actually the authority that is important here, and the fact that you have some measure of trust in a party does not imply that the party should also be granted authority.
If you recast the GP's comment in these terms, I believe it captures the essence without muddying the waters with "trust":
> On a device I own, there should be no parties with more authority than myself. It's ridiculous I even have to write this.
For every person who knows what they're doing and can trust themselves, there are 1000 who will install malware and other crap and end up at an Apple store getting it fixed, and they'll blame Apple instead of themselves.
If your engine fails because you drove it into a river, then the warranty don't cover it and you'll pay out of pocket for repairs.
I feel like I have to be misunderstanding you because that makes no sense.
While I may not always agree with Apple's approach I can understand their reasoning and don't believe that it simply comes down to earning a few extra bucks with the 30% cut in question and all the seemingly drastic measures that come with it.
Most users do not want this, but some do.
Some users will consider a RAT a way to fix things, while others will consider some game to be a malicious drug. Both should be allowed to make their own decisions if they really want to.
And, now that I think about it, I don't even know what the equivalent of "driving into a river" would be, and that's as a software engineer who's been working with computers for 25 years.
It is definitely clear that apple does not have the best interest of me, their customer, at heart. Epic were being very sneaky towards Apple, but not malicious towards users in any way. Apple is being malicious. If I want to run Epic’s software without disabling security features of the OS I feel I’ve definitely spent enough money on my iMac to get a say in that. This is the sort of thing 90’s microsoft would have done. “It’s just business, they knew what they were getting into.” would have been Gates’ excuse for throwing them from the windows platform.
Or Apple doesn't vet all of these apps, and refuses to notarize any app that is not associated with a valid developer account.
It's a whole other can of worms if you want to get into the merits of being able to install and run any app you find. Apple made the decision to not allow the average user to do that, and I don't see the mass exodus of people showing that the public doesn't agree with this design choice. Just like iOS and the app store, the average user seems happy with a curated and largely vetted selection of things to use that... 'just work (TM)'.
When I brought up that Notarization was going to be used to gatekeep (literally with Gatekeeper[1]) access to the macOS platform, I was assured it would only be used for security and never for evil.
Apple only made Notarization mandatory this February, too, so that didn't take long at all.
People have been claiming the iOS-style trusted/treacherous computing cancer will hit macOS “any day now” for most of a decade at this point, and it’s still not even on the horizon.
This would be horrific of course, but I could totally see them doing this.
What? It's basically all there. Apple just needs to remove the last workaround of popping up the preference pane and clicking allow for untrusted apps. I'm sure there's a flag for this somewhere.
Notarization is about protecting users who are not capable of making an informed decision about code safety from developers who refuse to comply with Apple's terms of service. Epic willfully violated their terms with Apple to make a point, and Apple is responding in the same way that they did to Facebook: taking away their access to the users, because they cannot be trusted to comply with the restrictions placed on their behavior.
Most (if not all) of the restrictions on the App Store exist to protect users from app developers who prioritize their own greed over the rights of privacy and safety that Apple promises the users of the App Store. Developers are the threat model, and there's nothing inherently wrong with Apple's response to Epic declaring themselves a rulebreaker — and, thus, a threat.
(If Epic was not trying so hard to be able to sue for damages, they might have been able to negotiate, same as Facebook did. But they wanted to be a martyr for the cause, so here we are.)
Consider this thought experiment: At your employer, an IT employee goes rogue and installs malicious code on your computer to read your email. How would you feel if IT leadership said "they promised not to do it again" and allowed them to continue unsupervised work on your computer while you're away? Most people would feel awful, because you can't trust the IT employee's word — they literally just broke their agreement not to snoop! — and because your leadership clearly doesn't care about your privacy.
Should Apple "fire" Epic, now that Epic's word can no longer be trusted? This answer should, in theory, match the answer above. I bet for most software developers, it does not. I encourage thinking through that dissonance rather than rejecting the thought experiment.
No, notarization is about preventing malware. That's all. This has been promised to us by Apple many many times. Malware prevention only. Fortnite is not malware.
Notarization is not a stick-less carrot. Anyone can sign up and agree to the rules and pay the fee begin notarizing apps. If you break the rules you agree to when you sign up, you lose access to notarization.
It seems like we disagree about this basic understanding, so I'll take a couple guesses at it.
Are you, perhaps, arguing that Apple should not be allowed to terminate developer access to notarization under any circumstance — regardless of their behavior? Or are you arguing that Epic's behavior is "acceptable" rule breaking, but other kinds of behavior are "unacceptable" rule breaking?
I'm happy to consider that I could be wrong here, but I'll need a few more sentences from you to do so.
At the very least such decisions should be subject to appeal to an independent board, and failing that the legal system.
Should they have not exercised that right, and left us all at risk — even though the daemon itself wasn't malware, nor had it been abused for such purposes by anyone?
Checks and balances are not a new concept.
If Apple wants to suspend someone's App Store developer account, fine. But you should be able to distribute outside the App Store regardless.
The whole point of distributing outside the App Store is to avoid all that nonsense with Apple's rules.
Since most people are essentially prevented from running non–notarized macOS software, Apple should treat notarization as a rubber stamp. As long as your app is not literally malware, Apple should notarize it.
Apple's use of notarization as a stick for Epic here certainly goes against if not the letter, then the spirit of their developer documentation: [1]
> Notarization gives users more confidence that the Developer ID-signed software you distribute has been checked by Apple for malicious components. Notarization is not App Review. The Apple notary service is an automated system that scans your software for malicious content, checks for code-signing issues, and returns the results to you quickly. If there are no issues, the notary service generates a ticket for you to staple to your software; the notary service also publishes that ticket online where Gatekeeper can find it.
[1] https://developer.apple.com/documentation/xcode/notarizing_m...
1. You can submit software anonymously, or with a free account, or with a paid account.
2. Apple can refuse notarization for the usual reasons they do now.
3. Apple can, in the future, revoke notarization and notify you.
3a. If you choose to submit anonymously, notification is impossible.
3b. If you choose to submit with a free developer account, they'll notify you of revocation and why.
3c. If you choose to submit with a paid developer account, they'll allow you to contest the revocation.
Well, it kinda is, isn't it?
> Programs are also considered malware if they secretly act against the interests of the computer user.
Is convincing children that they need to spend money to not be a "default" really in the interest of a computer user? Is taking advantage of gambling addictions with lootboxes really in the interest of a computer user (or society at large)?
I get what you really mean, and I'm probably stretching the definition a bit much; Yet it's worth considering if Fortnight is really a good thing in the first place.
IMO that's a fine conversation to have, but it is not Apple's place to make that decision for me.
Apple and Google are hardly faultless, but Epic is is the one who started this dick-measuring contest.
That's a fine argument to make, but it's nothing to do with what we're discussing here :)
If you wrote a blog post about how Apple and Google should ban gambling reward techniques from their app stores, I'd read it if you posted it to HN!
Well, except we're talking about how these measures are generally reserved for malware. Thence my (pseudo) logic chain.
"2.3.1 Don’t include any hidden or undocumented features in your app; your app’s functionality should be clear to end-users and App Review."
In old sci-fi books, there's a couple that describe a future where connecting an old device to the Internet without having first installed updates will result in the device being exploited and/or ruined within a few seconds.
I notice that the Xcode worm was reposted again this morning, which seems like the perfect mechanism for covertly preparing for a worldwide hack of all iOS devices through a backdoor that has been compiled into all software. (You could get a similar effect by introducing malware into CocoaPods, and with similar reach.) All of these protections Apple has with Gatekeeper and Notarization would, to many extents, protect end users against that attack.
As you said, it's definitely a broad brush. The risk is absolutely real, though I imagine we all disagree on how important it is. It's the same problem as the risk of Python/Ruby/Node dependency compromises. Any solution that would work for protecting us against an NPM compromise would also work for protecting us against a macOS software compromise. Apple's solutions have a higher total value of protection, in exchange for a higher total value of bothersome.
Is the NPM model (you can ship any code worldwide, have fun!) safe enough for non-technical users, such that Apple could just drop Gatekeeper and let us all go back to the wild west macOS days? If not, what model is acceptable, given that Apple's model isn't?
Does the sale require me to submit payment details to a not-already-trusted platform?
The change remotely triggered by Epic redirects users to a third-party (Epic) payment system, but what if it were, say, a malicious Epic insider? How much user payment info/cash could they grab before they were detected and disabled?
Apple says "you can't do this", but Epic does the thing and says "I should be allowed to do this. As you can all see, this is what happens when I try to put my foot down on it and here's this target audience of people who are benefited by the thing I'm trying to do". This works for them because they are advocating for a freedom of software choice and to rebel against the massive profit line that has made Apple the target of Spotify's legal hate as well.
The rules they broke prevent Epic from doing a thing that consumers would prefer (lower prices) and has been argued against by other parties (30% cut). It doesn't really matter that they broke the rule if the court of public and legal opinion is that the rule was not good to begin with.
Forcing me to give them to Apple is, if I prefer to give them to Epic and hide them from Apple
Guess which one is the only Apple approved option
Yeah isn't that what people see as a problem?
> Notarization is about protecting users who are not capable of making an informed decision about code safety from developers who refuse to comply with Apple's terms of service.
My family owns a Mac on which we have played Fortnite in the past. We have no desire to be "protected" from Epic Games. I thought to point of notarization was to prevent malware, not to punish companies which Apple doesn't like.
You're conflating two things here: code safety, and what Epic did. At no point did Epic do anything unsafe, nor did they put their users in any danger. They simple violated a business rule Apple enforces.
You are arguing that Apple is incorrect to assert that rulebreakers should not have privileges to deploy code to end-user devices worldwide, when the rule is not one that protects users.
Apple's counter-argument would presumably be that this business rule exists specifically to protect users from being harmed by developers, given the prevalence of "free trial" subscription scams over the past X decades of Internet marketing (and before that, TV commercials).
So, I don't buy the argument that Epic did nothing unsafe. It takes seconds to construct multiple scenarios where users have been abused by third-party payment systems, such that Apple would consider them "malicious behaviors that impact the user".
ps. There's a technicality branch here on "malware" != "malicious behaviors", but, like, malicious payment processing is implemented using software, "malware" is "malicious software", so "malware" still applies to the scenario I constructed above — and that flexibility demonstrates why "malware" is a terrible abbreviation for whatever everyone individually thinks it means.
I shudder at the thought.
I very much categorize Epic's actions in the "unsafe" basket.
This is exactly what apple tried to prevent (snd is earning a shit ton money with it): manual credit card entry because except the big ones almost no one would be safe
Imagine that
Imagine a world where people buy things on a website let's name it Amazon
Or pay for online auctions using something very sketchy, something like a PayPal
Imagine paying online for cabs, food delivery, books or to rent a movie or a BnB on the other side of the World, to buy a flight, theater, museum ticket
What a wild wild west it would be, we will be fighting each other like crazy if it wasn't for Apple that saved us all from ourselves...
I don't think "snuck" is accurate. They did intentionally do it, but it was likely pretty obvious to the app reviewer. This was necessary, because you can't sue a company because they'll harm you for something you'd like to do, but haven't done yet. You have to do the thing, get harmed, and then sue.
> Apple could have revoked their developer certificate in response, which would have essentially killed all installations of Fortnite iOS/Mac worldwide within 24 hours. That they are merely revoking their ability to sign new code and giving them 2 weeks to perform an orderly shutdown is far less draconian than they're capable of being here.
Don't pretend they're doing this to be nice to Epic; they know that if they cut off all existing Fortnite users, they'd get a huge amount of customer complaints and bad press. At least here they can appear like they're being reasonable and only hurting the company that violated their policies.
Well, presumably only in-app purchases made with apples payment system.
If Apple was about user protection then one would expect there to be a way for users to opt out of their safety sandbox if it didn't fit users needs.
Their OS and store restrictions are about monetising the ecosystem as much as anything else, calling developers who try to circumvent the apple tax greedy while pretending Apple is doing this purely for user experience is some cognitive dissonance.
It takes a real sucker to fall for the “its for your own safety” propaganda while they arbitrarily tax you 30% on the fields you tilled like some medieval feudal lord.
I used to do consulting work as part of which I submitted Mac compatibility patches into the Unreal Engine source code repository. As is, it is not clear to me if I'll be hit by the Apple ban-hammer, too, or if they will limit it to "only" the 4000+ people directly employed by Epic.
This is why I want Epic to lose.
This type of people need protection.
That's not even the case here.
Epic built an app using webviews and the web part of the view is loaded from a remote server controlled by Epic.
Which is the most common way to build multiplatform apps nowadays.
Epic simply updated the web part on the remote server.
Which also proves Apple can't even provide the basic safety they are promoting to push notarization.
Unless they ban webviews completely, we will never know how many apps are already doing it exploiting the less tech savy users, but still bringing profit to Apple.
My response was based on the OP suggesting the account closure was based purely on the App Store policy violation. I’m pretty sure it’s based on more than that, such as the fact that Epic is suing them in bad faith.
There’s probably a million app developers which have violated the policies in some manner at some point and yet very few get blacklisted by Apple.
macOS was always a general purpose computing platform, anyone could publish software for it.
iOS has not been seen as a general purpose computing platform, merely "a phone", and hence Apple's tight control has been seen as justifiable.
Apple added notarization of software to macOS last year, and in response to fears that this was another step on the path of "iOS-ification" of macOS, promised that it was not going to be used for anything but to stop bona-fide malware.
This stunt shows that that was bullshit, and the iOS-ification of macOS is complete. macOS is no longer a general purpose computing platform, it is now also a software console, with Apple as a gatekeeper.
If Apple retaliated against their publishing on iOS that would be one thing. Taking away their ability to notarize macOS software is my line in the sand.
Apple is too scary at this point for big developers like Epic who are well diversified on other platforms. Imagine the fate of small/upcoming developers who might start with Apple's products itself.
Apple needs to be really reined in either by regulation or customers, latter being way harder because it is harder to convince people of long term detrimental effects. I stopped using iPhone long time back, but now I will make a conscious effort to not even live in the MacOS ecosystem.
If they had stopped with just suspending their iOS publishing powers, it could have been understandable. Taking action on all platforms just seems like abuse, it is not like Epic was doing something like distributing malware, they broke the payment terms of iOS.
They make a majority of the money in mobile.
Apple’s poor financial state under Sculley was more because they had an objectively poor product (going by the technical merits alone), a confusing product line-up, a failure to recapture the education sector that was quickly switching to Windows due to its enterprise-friendly features like Group Policy and compatibility with Directory Services like NetWare, and because it didn’t have a plan going forward into the 21st century.
I do note that in the 1990s under Sculley they both licensed macOS to third-party hardware vendors and were fine with PowerPC being adopted by other platforms (even Microsoft, and evening when it was incompatible with Apple’s architecture) - that’s the very opposite of the vendor lock-in-in that you’re describing. It can be argued that Apple’s “nice guy” approach further contributed to their decline - it certainly didn’t help raise sales nor their share-price.
Aldo consider when Steve Jobs returned they made deals with Microsoft to ensure Office would still be available for the Mac. Apple’s stewardship of WebKit was about driving open web-standards, even though Safari is very much Apple-exclusive. Apple also made a big-deal about how the then-new Mac OS X was a POSIX-compliant BSD system.
I think you’re confusing Apple’s aggressive control of the user-experience with IBM and Oracle-style lock-in. With IBM/Oracle a company or gov dept will have sunk $lots into a system that they cannot take away to a different vendor: there is literally no alternative than to continue with whatever gargantuan system their sales reps convinced the customer to buy. This is why banks and insurance companies are still rocking IBM Z-series today after 30+ years even though a system that’s just as resilient could be built for a fraction of the price on commodity hardware (I’m not going to pretend that Linux was a viable option back then, but systems like VMS or a project requirement to use POSIX were options back then). When people say that banks/insurance companies are “conservative” when it comes to technology I think it’s better to describe them as being technically inept or even corrupt which led to them being caught in vendor lock-in which paralysed them internally: I feel the arguments that they don’t want to risk losing billions over a bad technology move are just excuses for being unable to make a technology move even if they wanted to.
I believe that Apple sees that their controlling of the user-experience of its customers creates value for the user - whereas IBM/Oracle-style lock-in rarely does. I reckon 90%+ of non-developers using Apple hardware today (iPhone, iPad, Mac, etc) could switch to Android, Surface, and Windows PC respectively without losing much in the way of capability - but they would lose a cohesive and well-thought-out user-experience, which is Apple’s moat.
Nit: Safari shipped for Windows for a few years
I mean if they really wanted to they could blacklist your CN or O value in the certificate, or add you to the windows defender/smartscreen detection list, which will effectively kill your app for a good segment of the windows userbase.
Having to pay money introduces a money-trail and a paper-trail. If a payment for a certificate is made with stolen CC details then the certificate gets revoked. This also effectively stops opportunistically-written malware taking advantage of current events (click bait email subject lines) to spread via email attachments.
The value from code-signing isn’t just the (I agree: very weak) attestation of the software’s author’s identity - but because it introduces a revocation mechanism and a reputation system - and creates barriers-to-entry that burden malware authors more than legitimate software vendors.
It’s not perfect, but don’t let perfect be the enemy of good.
Also remember that the only proven successful alternative to the current open PKI/CA system is the closed walled-garden approach favoured by Apple. I don’t think any Web-of-trust system has ever really been demonstrated as being feasible long-term without some WoT nodes evolving into pre-trusted/super-trusted nodes with the same power that CAs have today.
And at least with PKI+CAs you can add your own trusted root certificates and remove those you don’t trust.
I have code-signing certificates myself: the verification process did not fill me with confidence that the system is trustworthy - GlobalSign had me email them details of my DUNS/ UBI / business registration and a notarised copy of my driving license and checked that my name matched, and that was it. I could easily fraudulently obtain a code-signing certificate with a fake ID matching the name and state of some other vendor I just took a disliking to.
(I recognise that this system’s adding of barriers-to-entry does eliminate large numbers of opportunistic malware and provide a means to quickly disable installation and execution of revoked certificates - so I’m not calling for the system to be torn down!).
Or has that setting been removed?
Create a public key register if security +++) is that important to you and you get the same features but don't try to tell me a developer certificate from FAANG isn't for business purposes.
+++) completely neglecting the fact that malware was even introduced in signed software...
I've been warning my friends for years that giving Apple this much control was risky but without concrete examples like this those warnings were too easy to ignore.
And you thought it wouldn't be used as punishment... I wonder, why people are so naive? I'm pretty sure that any kind of software that is not deemed good for the guardian's business(i.e. Apple in this case) will be blocked/suspended. DMCA related suspensions are the first that come into my mind.
Where do you see this specifically, or are we just inferring it from that fact that Epic will lose access to the developer portal?
"Upon further review of the activity associated with your Apple Developer Program membership, we have identified several violations of the Apple Developer Program License Agreement"
So it doesn't sound like it was just for this Fortnite issue.
Question is how serious the multiple infractions are.
1) not giving Apple their 30%
2) publishing code without prior approval by Apple
You simply can't pay Apple the 30% cut nor can you publish apps without Apple approving it. So it's impossible for a company to violate either of those.
They might "creatively interpret the facts and make novel legal arguments in a way that paints their client's position in the best possible light", though.
They probably won’t lie in court or in depositions, but the same assumptions shouldn’t be made about all statements.