Apple Users Got Owned
puri.sm
puri.sm
As I said before in a different thread: The internet is a malicious place, filled with the non-technical and uninformed. So I guess we’ll wait for you to design a better trust-based system that allows you to stop malicious software from executing on N different machines without needing N users to do anything?
I want code I run to be signed and notarized. I want malicious executables to be disabled quickly and efficiently.
You can disable the filtering bypass but then you’re in an uncomfortable position where malware that’s able to install a network filter can filter out its own revocation check requests!
Imagine if the notarization certificate for your old version of Photos is revoked (for security reasons) and now you need to update your OS to regain access to your photo collection. But sadly, upgrading requires you to purchase new hardware.
In effect, it's like a Bitcoin ransomware trojan, except that this system is operated by trustworthy good guys. Or at least you sincerely hope so.
They don't have anything new. I know it's fun to pile up on apple or any big tech company for that matter but apple users here are already aware of most shenanigans and they have already made up their mind. It's the general public that needs more of these articles with better explanations who don't know about what they are accepting.
Ffs how is this news.
Cheap hit piece from a brand that should know better.
As a professional security architect + applied cryptographer, I’m the very type of person who buys Purism type products, and this type of nonsense does nothing for their brand.
That said, Apple is clearly going out of its way to EXPLICITLY state now that they are not going to ever interfere in a Mac owner's ability to run code from outside of an Apple app store. Sounds great except that this helps them continue justifying their interference in the much more relevant iPad/iPhone platform --'just buy a Mac if you don't want us to totally control every aspect of your computing experience on your own hardware!' (IMHO, they need to be forced to license alternative app stores that any owner can opt into or outof at will and make a free version of something like Xcode run on non-Mac hardware, even if it is only for the iPadOS/iOS itself.)
Of course, Apple has in the past and can still login to any Mac connected to the Internet anytime they want and modify anything they want. They may have a good reason (such as stopping a viral agent that is damaging property or risking lives) but many don't really trust anyone at Apple or anywhere else to make calls on that level! (Just look at how crazy McAfee was.) Even if you are into the whole "blind trust" thing and appreciate the power to stomp out a computer virus network globally in minutes, who exactly is looking after these mechanisms to guard against unauthorized use (by current/former employees, contractors, hackers, etc.) --there is no transparency. Maybe they could make a Push Notification for the users that, when received, causes the machine to either power down, prompt for approval or allow them to proceed based on the user's preference expressed from time to time while logging into their Mac? No?
Yes and having that control is moot for 90% of people, especially when it's so easy to hand it off with crap like drive-by-download malware, buddy-poke type of crapware, malware and such.
Of course I'm in the 10% that takes value out of having control of their hardware, but most of people don't. Also I can run the freest of free softwares and that might be useless if I need a specific software for a specific task. Then what?