Apple Accidentally Approved Malware to Run on macOS
wired.com
wired.com
Otherwise Apple would have to scan every single binary submitted for notarization, which then puts a pretty large onus on them should anything slip through.
That's a big hammer because it breaks everything that was ever signed with the certificate.
1: https://developer.apple.com/documentation/xcode/notarizing_m...
It would be news if it was on the App Store, which has a review.
Apple seem to be saying that it is more than a registration process. Not passing a human review would be bigger, but it is a review of a kind.
[0] https://developer.apple.com/documentation/xcode/notarizing_m...
It's a pass of checks that might or might not find something.
It's not some official stamp of approval, except to say "those checks passed ok".
Notarisation for macOS similarly only means, “the developer presented us with their application and their certificate of authenticity and we signed it with the certificate that allows macOS to run it without complaining.”
There’s no attempt by Apple to claim that the application is safe or does what it says on the tin.
Scanning for malware is simply to avoid embarrassing situations me an author/publisher finding they’ve been compromised by some well known malware.
The outcome of notarisation is that the app has been notarised.
It’s like claiming that the outcome of toasting a sandwich is approval or rejection, no the outcome of toasting a sandwich is you have a sandwich that is toasted, aka “toasted sandwich.”
You might reject a sandwich which isn’t built properly (eg: has mismatched bread slices, is missing contents or smells of dynamite). But toasting the sandwich provided by the customer doesn’t mean you actually like it.
So that isn't part of the notarization process. It still was approved by Apple and thus was notarised.
> It’s like claiming that the outcome of toasting a sandwich is approval or rejection, no the outcome of toasting a sandwich is you have a sandwich that is toasted, aka “toasted sandwich.”
That's disingenuous. If I send a Sandwich to be toasted by Apple and get it back toasted that means the Sandwich was indeed approved by Apple since it has been toasted.
Here's a grossly simplified version of what happens with Apple's notary service:
1. Developer writes program 2. Developer signs program to provide evidence to end-user that program has not been tampered with 3. Developer submits program and signature to Apple's notarising service 4. Apple signs program and developer's signature to tell macOS that this developer signature for this program has been seen by a trusted third party (the notary, in this case Apple) — the notary signature basically states that at this date and time the developer presented Apple with the program and the developer signature and that the developer signature is the correct one for that program 5. End user downloads program which includes signature by developer and signature by Apple 6. macOS compares program signature to developer signature 7. macOS compares checks that notary signature matches the program and developer signature 8. macOS now trusts that this program is what was published by the developer, and allows it to run
At no point in this sequence has Apple provided any testimony or recommendation about this program. Notarising is only about ensuring that what you are trying to run is what the developer wrote for you.
"Approval" on the other hand implies that Apple might "disapprove" something, which is not something that happens in the notarising service. A notarising request might be rejected if the applications contains known malware (because the presence of such is an exceptional circumstance which the developer needs to take urgent action to correct, not because Apple doesn't want to sign malware). It's like a Justice of the Peace recommending that you see a doctor if you turn up to ask for a witness to your signature while bleeding profusely from your ear. The JP is not refusing to witness your signature, they are simply suggesting that you have more urgent matters to attend to right now.
Nobody should be listening to this long-winded fable spun out of yarn.
I mean, I could go through that whole thing and refute it line-by-line, but I'm just astonished that you think you get to invent all this stuff out of thin air. It's totally wrong, and you don't even have first-hand knowledge of it.
What are you talking about? That's basically the process.
>I mean, I could go through that whole thing and refute it line-by-line
But you'd only have some inconsequential pedantic details to change.
How do you know?
> But you'd only have some inconsequential pedantic details to change.
No, the writer completely misunderstands the entire purpose of the process, and consequently just makes up details about what the writer thinks ought to be happening. It sounds like more of a hypothetical than actual knowledge.
So you're admitting that you don't know what it is?
Are you or are you not a Mac developer who notarizes and distributes Mac software?
The process is described at a high level by Apple here: https://developer.apple.com/developer-id/
1. Developer signs their app
2. Developer sends signed app to Apple for Notarisation
3. Apple provides notary signature
4. Developer distributes notarised app
I've already explained how the Gatekeeper dialogs prove that your conclusion is false. Moreover, the very page you just linked shows that your claims are false. You say, "At no point in this sequence has Apple provided any testimony or recommendation about this program. Notarising is only about ensuring that what you are trying to run is what the developer wrote for you." Whereas Apple says, "Gatekeeper on macOS helps protect users from downloading and installing malicious software", "Give users even more confidence in your software by submitting it to Apple to be notarized. The service automatically scans your Developer ID-signed software and performs security checks", etc.
This story has now dropped way down in the HN rankings, and it's likely that few people are reading these comments anymore except us, so I have no desire to write a long, point-by-point treatise on how you misunderstand Developer ID and notarization.
It should be possible to verify developers and distribute open source apps without a cost on macOS.
This software shall not be used on platforms that hinder users in their free choice of software.
This software shall not be used to create or in conjunction with adware, spyware, or other malicious software.
(Perhaps after a lawyer has reworded it properly so people can't pretend to not understand what is meant here)Another one I'd like to see is:
This software is free for personal use, and for commercial use by companies with an annual revenue less than $1B.
(For commercial uses that are not covered by this license, please contact our licensing department)I've been advocating for something similar:
> This software is free for any entity that does not contain material stakeholders (bond holders, debt holders, etc) that are billionaires. A yearly licence fee of $1m waives this requirement.
Something like that. I'm sick of wealth centralization. If a startup wants to use the software, great! Once Peter Thiel invests though it's $1m a year. My core beef with billionaires is that they do not pay their fair share in taxes. The push all their money into shell companies or park it overseas and we end up with doctors that actually save peoples lives paying double or triple the tax rate that the ultra wealthy pay.
Mine is pretending they're not freeloading. A close second is the performant persecution complex. Third might be the rationalist rhetoric about slippery slopes (eg anything less than Freedom Markets™ is socialism).
That’s the GPL, isn’t it? Version 3 was specifically created to close loopholes w.r.t. to that (https://en.wikipedia.org/wiki/Tivoization: “Tivoization is the creation of a system that incorporates software under the terms of a copyleft software license (like the GPL), but uses hardware restrictions or digital rights management to prevent users from running modified versions of the software on that hardware“)
A $1B limit? no problem - "we'll just send this over to our little 500M subsidiary."
the root problem is the consumer doesn't care and there is a cultural lack of care and trust and humanity. I don't know of any solution to this but the problem runs extremely deep. In fact, there may be no cure, as these problems are noted as the cardinal sins the Christian bible documented and Dante' famously illustrated : Lust, Gluttony, Greed, Sloth, Wrath, Envy, Pride. Solve that and the rest comes easy.
> A $1B limit? no problem - "we'll just send this over to our little 500M subsidiary."
The new license can acknowledge this too
I think you greatly overestimate how much Apple cares about this.
What if it turned out that ease of use and OS-wide app consistency was the easy part all along? That building good APIs - which includes not changing them, making a good publishing experience - which includes not changing your rules every six months, and making your developers rich - which includes lowering fees - were the hard parts?
Besides the average person does care about privacy and security. Keychain is a product everyone on macOS and iOS uses. Imagine if the OS forced Private Browsing to actually work.
What demographic is this? College kids and Apple employees?
It seems like minor benefit in an otherwise atrocious platform.
What commands are you sending your macbook outside installations?
It's not like you are running a server, you still need to SSH into the server to do anything.
If you are technology literate, you've seen the evils of Apple for decades.
A power user fixes their own problem, not waits years for Apple to fix it.
I've seen them at University and some non STEM students homes.
That said, I see iPhones at work, but probably because they are not critical to doing anything other than email.
Software engineering is Engineering like sandwich Engineer is Engineering.
They should use "specialist". It's not like they are using science to prove something will work.
They have you over a barrel and they know it.
Misunderstanding sorted out, let's see. If I wanted to reach 200 customers on MacOS (real or leads) probably I can invest 0.5 USD per customer and see if I end up making some money because one of them hires me to do anything.
Not sure if related.
There is NO "requirement" for notarization. This FUD keeps getting perpetuated, but you can publish macOS software without paying $99 year.
> It should be possible to verify developers and distribute open source apps without a cost on macOS.
The cost is convincing your users to trust you and allow your unsigned app to bypass Gatekeeper.
I've seen some tools do just that, explaining that they cannot afford the notarization fee.
Can you point to straightforward apple instructions for doing so?
I publish an open source project used in classrooms, mostly used by my own students but also others. Despite strong and principled objections, which I hung on to for years, I have simply given up and now pay the fee. I'd love to not have apple be the gatekeeper. But they are. Every release, every update, every summer when I go to fix a few bugs, the restrictions get tighter and tighter, and old workarounds stop working.
I work entirely on Linux and Win10, but I maintain a mac laptop and pay the $99/yr out of pocket just to keep this project alive. I've spent tens of days trying to find a way around either of these requirements, but it's just too difficult (for me, or for my students, or for others wanting to try my software).
Take a look at how other apps do it, such as:
• MacDown https://macdown.uranusjr.com (also on GitHub)
Download → Right/Control-click → Open → Confirm
There are several such apps and open-source tools that are not notarized, some quite popular. Some of them provide those instructions next to their download links.
Those steps are literally all it takes. It’s barely 40 keystrokes to list them.
As a user and the resident tech support for people young and old, I am glad that there’s such a barrier against the execution of arbitrary software and it’s easily skippable if one so explicitly chooses.
In any case, how is it any worse than the Windows nag prompts that people accepted more than a decade ago?
Perhaps you've configured your device in a way that gives you an easier execution path, or the app is employing a workaround to bypass Gatekeeper.
It seems MacDown uses such a temporary workaround to make the process less painful for macOS users: https://github.com/MacDownApp/macdown/issues/1106#issuecomme...
For now, a dev has to add an explanation next to the download link, and let the users decide.
Your assessment only works for working developers in high income countries. And even then requiring 99 dollars is insane.
Also, the $99 is the blanket cost to be an Apple Developer, including access to the App Store, technical support, etc. and it seems like a reasonable fee to ensure those resources aren't swamped.
It is a shame about people who can't afford it — I know Apple has a scholarship program for students but I'm sure it can't do it for everyone. I'm not saying I'm in favor of it. But it seems like there are some pretty clear reasons why this is the way it is beyond "Apple greedy".
If you notice, I actually mentioned this in my comment. I think it would be much worse. $99 isn't enough to stop everyone from making crappy apps, but it's definitely enough to stop a lot. Think of every low-effort app made by some 12 year old who discovered Xcode for the first time.
> If I were to operate a personal fleet of devices, I wouldn't be able to build my own software once and run it on the fleet. I'd have to build it everywhere.
I don't understand what this means. If I understand you correctly, then no, you can definitely deploy internal apps to Apple devices without putting it on the App Store.
Lol. In my experience a fee is a way to _ensure_ it is filled with incredibly low-effort apps (which tend to be the most profitable).
$99 almost seems reasonable until you consider Apple bakes in a mechanism for curation (they own the signing keys, right?).
IMHO code signing should be separate from curation systems and should focus on tying code back to a specific individual, not a company. It’s a huge pain to change your identity vs starting a new company to distribute malware.
The current systems are built to wrest control of everything. They don’t care about quality or accountability.
This is actually the problem. If an open source developer doesn't want access to the App Store, technical support, etc., they still have to pay for those things.
The baseline for a Mac or iOS OSS developer is still someone with a Mac and many hours of time to spend on non-paying work. So we're probably talking about students and the temporarily unemployed in first-world countries, not so much low-income counties.
Seems like a full developer account should be free for the asking for students, IMO.
You can argue that Apple should provide developer resources at no cost, but that just means someone else is paying for them or you will pay them in some other way... or do without.
I think at this point in the tech boom we can all understand that when a company gives you stuff of value at no cost there are significant tradeoffs and paybacks. In software development, I think you want most arrangements to be straightforward transactions. The strings attached to no-cost things tend to build up and cause problems, especially if you have success.
Edit: I struck a nerve, but I don't think this should be very controversial. I'll try to take the objections one at a time in comments.
So then why is the charge for signing and not for developer tools? That way if I wanted to I could use somebody else's tools instead of paying Apple.
> I think at this point in the tech boom we can all understand that when a company gives you stuff of value at no cost there are significant tradeoffs and paybacks.
Which is why I paid so much for my copy of gcc. Wait, hold on.
Of course, Apple spends huge amounts of money on developer infrastructure (Xcode, LLVM, and Swift, for example). Since each additional copy of a piece of software does not incur additional costs for the developer, Apple can subsidize the development of developer tools using the $99 fee taken from (generally) professional developers who wish to publish their apps on the App Store or take advantage of notarization on macOS.
Many major open-source projects are largely developed by employees of large technology companies and foundations with significant budgets. The Linux kernel's largest committers oftentimes work at companies like Red Hat and Intel. Just because you get a given piece of open-source software for free does not mean that its development was done by volunteers in their free time.
So then why do I have to pay them if I'm using emacs and gcc and C++?
> Just because you get a given piece of open-source software for free does not mean that its development was done by volunteers in their free time.
Yet, in many cases, that's exactly what happened. And even when it isn't, if it's distributed under a free software license then it keeps them from screwing you over because any adverse changes can be reverted.
You may still be using developer resources like documentation. But yeah, a flat fee for a wide variety of services risks edge cases where someone using only minimal resources gets a poor deal. Of course, an alternative is a nickel-and-diming pay-as-you-go micro-transaction scheme, which your main users will hate.
Also, strictly speaking, you don't have to pay them. Vote with your dollars and platform support as a developer. If enough people do, Apple may reevaluate.
That's not any different. If I write a POSIX-compliant program then it should run on macOS without having used any of Apple's documentation. And if they charged for documentation (which is dumb) it would create a market for third party macOS documentation that I could use instead.
> But yeah, a flat fee for a wide variety of services risks edge cases where someone using only minimal resources gets a poor deal. Of course, an alternative is a nickel-and-diming pay-as-you-go micro-transaction scheme, which your main users will hate.
Offering a flat fee for everything is not inconsistent with offering individual things a la carte. They could offer both. But the bigger point is that it should be possible to produce and distribute software without having any business relationship with Apple whatsoever. I don't want to use anything they make, I just want to have access to my customers who use macOS.
> Also, strictly speaking, you don't have to pay them. Vote with your dollars and platform support as a developer. If enough people do, Apple may reevaluate
That doesn't work at this level of power imbalance. Your software would have to be important enough to get your customers to switch to a different platform, and not have any viable competitors who remain on macOS even if it means higher profits due to the reduced competition. In other words, you would have to be a monopoly yourself in order to have any leverage.
These are conflicting statements. You will have a very difficult time supporting your Apple-using customers without using any Apple stuff yourself.
Yes they do, to entice developers to build apps for their phones which they sell for a premium. Remember Ballmer (different company, similar context) .. Developers, developers, developers...
Huh? Some Open Source/Free software have a $0 budget.
Dwarfing those, though, is the significant time software development takes. For OSS, the time is donated, whether by individuals or by corporate sponsors who sometimes dedicate employee hours to projects of particular value to them. But in either case the donator has to be in a position to afford it, which typically means significant income from other means.
Even if someone has the time and resources to contribute to OSS, it does not automatically follow that they should be willing to spend said time and resources on notarization (of all things).
Put another way, not every purchase is worthwhile just because you have a million dollars in the bank.
You may say that a FLOSS project has no bank account, but it does not have $0 budget (unless it has no value, and is produced with nothing of value, by noone whose time has value).
If Apple doesn't charge developers, they could, e.g., pay for it through more margin on device sales, which means Apple customers are paying for it. That sounds nice for developers, but that's going to cause the developer resources to lose developer focus. Developer resources will be treated as marketing expenses and the scope and character of them will reflect this.
Before the App Store, you could develop for the Mac completely free. There was a developer program, which was much more expensive than $99 per year, but it was mainly concerned with WWDC and pre-release builds. There was even a hardware discount for developers, which was very popular, and effectively made the developer program pay for itself in many cases.
Well, I've been developing Mac software for 25 years, so I've seen the developer program changes. Generally, it's gotten a lot cheaper and a lot better over time. (Except there's never been anything like the old Inside Macintosh books, and I guess there never will be.) I guess that's why $99/year doesn't bother me. Historically speaking, it's a great deal.
I'm sure there are more changes to come, but none of us knows what that will be, so there's not much to discuss.
> Before the App Store, you could develop for the Mac completely free.
I haven't kept track of a timeline on this, so I'm sure you're right, but you're talking about a transient state. Before Xcode you had to pay a lot for Apple's developer tools (which I can't remember the name of), or pay a lot for the superior (or so I believed at the time) CodeWarrior. At first, Xcode itself wasn't exactly free, because it was bundled with the OS updates, which cost a decent amount back then.
I guess at various times there has been more or less you could do at the free tier, but it has seemed to me that you could only rarely do a decent job of releasing and supporting mac apps without paying for something.
Xcode and Mac OS X were included on disc with Mac hardware. This is how I became a developer.
When Mac OS X was released, that was the period when Apple truly embraced open source and Unix. Since iPhone, however, there's been a lot of backtracking in that area, which I find very unfortunate.
In general, macOS is becoming more and more like iOS. Consequently, it is becoming more hostile to openness.
They don't spend all their money!
Yup, a bit glib but it gets to the essence...
"We determined that your app Downie 4 was erroneously identified as malicious due to invalid logic in our malware detection system. This triggered the revocation of your certificate under Section 5.4 of the Developer Program License Agreement."