The Perils of M1 Ownership
eclecticlight.co
eclecticlight.co
The UI was a breath of fresh air compared to Big Sur. Despite the screen being smaller than my M1 the information density was higher and it felt more like a tool than a toy. The lack of bullshit apps such as Apple TV, News & co and useless "widgets" was also good (for all of iTunes' flaws, it's still better than its modern successors), and it somehow felt faster despite being less than half the processing power of the M1.
I now wish I could run this on my M1 but alas I can't. At least with PCs and older Macs you could always switch to Windows or Linux, but with the M1 you're currently screwed - if Apple drops the ball or decides to take their OS in a direction you don't like you currently have no alternative (and all the "security" around locking out the user from their own machine doesn't bode well for alternative OSes).
https://9to5mac.com/2021/06/28/linux-kernel-5-13-officially-...
I think the comments in 9to5mac are just as bewildered as I and many users are. By the time a guide is written, they would have moved on to getting an M1X or M2 Macbook, still waiting.
It's only got kernel support, but is actually still not 'user ready'. Could take months for that to happen.
* Not decrying Asahi, they've done a lot of work and continue to do so. But it's best not to misrepresent the project's status.
Exactly my point as I have already said. We know it is not user ready but the parent comment is making as if it is already running on M1 Macs; which is hardly true.
To debunk the M1 Linux hype squad again, it does not work to the point of it being usable and will take months to get it 'user ready'.
I'm currently working on reverse engineering the display controller and will move onto the GPU after that. Alyssa has been working on the GPU userspace stack and the GLES2 tests are 80% or so passing, running mesa on macOS (open source userspace, Apple's kernel driver).
I've spent a lot of time brainstorming the installer and researching the approach, and we already have manual install guide. I'll work on that as soon as the GPU kernel stuff is on track.
As for userspace, there's nothing to be done for basic support; you can install any distro userspace you like. The main things there are the Mesa driver and, eventually, helpers for stuff like the Touch Bar (obviously we'll get the non-TB Macs running nicely earlier, TB is an annoying complication).
Things are in various stages of development and review, and yes, only IRQ, UART and basic bring-up is upstreamed, but I think you'll find things get to end-user usability a lot faster than you might think.
And it's doubtful Microsoft would ever go through the same effort to port Windows on ARM to the M1, instead probably relying on Apple's virtualization framework to allow it to run.
One or two steps short of the hermetic lockdown of iOS devices.
But now with Macbooks reaching $2k for a decent base model on the horizon, I'm really starting to just dip further into Linux every day. At least with ext4, btrfs, or zfs I can access those files on different operating systems. APFS? Have fun with recovering those backups without having to shell out for another Mac. Not to mention the OS is free. Had I still been an avid gamer Windows would hold it's leash on me, but Windows 11 is not looking better either.
I've successfully used Paragon's APFS filesystem driver to mount an encrypted APFS drive on Linux. The price was reasonable too: https://www.paragon-software.com/home/apfs-linux/
Your point still stands, though, with those soldered in SSDs needed for the boot process...
I really wish I could get Ubuntu on a Samsung Galaxy Book Go, but it seems it isn't possible (?)
And System76 are apure-Linux operation building their own open source firmware in house to get the level of support and features they want.
I don't think x86 will die so quickly, and Linux has been getting a lot more support from OEMs recently than it has historically.
Apple is introducing more and more mechanisms in the name of security but they keep access and information very close to their heart. All us Mac admins have struggled with SecureToken in combination with AD accounts and it took two major releases for Apple to actually introduce a way for us to manage these properly through MDM. In the mean time most information had to be gathered through blogs such as this one.
Another issue is that more and more enterprise management features are becoming dependent on managed (federated) Apple IDs. But Apple requires that the email and identifying account address (UPN) are the same which will never happen in our 200k user environment. So we're stuck with more and more things to work around.
This is really something that should have been considered from the start. And this owner key thing sounds worse. Security is good but the end user or corporate admin should have the keys to every lock. Not just the vendor. Now my successor can deal with this stuff.
I used to be a big fan of macOS personally too but I moved over to FreeBSD 2 years ago and I'm glad I did. I really want an OS that answers to me.
Especially the app dev guys tend to have fairly nonstandard usecases. However most of it happens in labs firewalled off the company network.
Anyway, I'm glad I'm not the one having to figure out how to work around these things with very limited documentation from Apple, like I have before ;)
Unfortunately, vendors haven't really thought about how to explain these changes to end-users. They are trying to make them fairly transparent, which probably works at least 95% of the time, but for a small percentage of people, becomes a big PITA.
The kicker was that the Windows 11 install was borked and I had to wipe everything and reinstall. Ha.
you can install windows directly on it and tell the UEFI to boot off of it with absolutely no fuss
This is from years back, but my experience is that running Windows from an external drive isn't really easy. I hardly use the OS any longer, but I'd like to keep it around on an external drive if possible.
apparently some USB flash drives have a bit you can toggle with some vendor specific tool, but I've not tried that
for a non-removable device installing Windows is exactly the same as for a normal hard drive (no fuss with Windows To Go or other rubbish)
The real problem wasn’t the update size itself. The real problem was the updating through the Mac store, which would invariably fail to properly download the update if you were on anything outside a several hundred mbps connection, and even if you did successfully download it, would potentially fail to install and/or give really poor progress updates where it looked like it hadn’t installed.
All the while eating up many gigabytes of space for I don’t know what.
Unless you're a blacksmith who makes his own drivers or a wordworker who makes her own handles, the same is true for you.
Quick and easy hack job. I'm not a machinist, mechanic, or metal working professional of any sort. But I had access to a shop at the time, so I was able to take my tools that were almost what I needed and turned them into exactly what I needed.
Literally no biggie. I feel like I'm hanging out in the kind of crowd that unironically asks "why do you change your oil yourself?"
Not "it's to be an unadventurous consumer of product".
Obviously all the marketing will focus on creative uses because it makes it a lot easier to sell to people on a 1500$ machine. The truth is 95% percent of people are using their computers as glorified web browsers and the computers are built to do that extremely well.
But aside from that, looking at the threats of ransomware attacks, they probably do need to harden them that much.
Ruining the OS install is not the objective of most ransomware because that makes it harder to show your demands and accept payment.
Anyway, I assume they do something with these unblocked phones, but maybe only androids :shrug:
When you add a Firmware Password to a Mac, you get a long recovery code as a fallback safety in case you lose/forget the password. Apple, if provided with proof of purchase for the serial number being inquired about, can create a bootable USB stick with a certificate generated using public/private key crypto for which Apple holds the private keys.
I suspect much of this newer functionality acts as a replacement for the Firmware Password, giving more options and making it a bit more well-known.
This is simply untrue. It may be hard to activate it, but it still has value for its screen, case, camera, and other parts.
https://cbslocal.com/2018/01/31/despite-anti-theft-features-...
Wasnt there a video a while back where a famous repair guy from Australia could not use the camera of another exact same iphone. The original phone was not usable but when you put the orignal camera back it starts working.
Apple might start doing that for each and every component soon in the name of safety and security.
And then you they go even further with stories like that: https://www.vice.com/en/article/yp73jw/apple-recycling-iphon...
Apple is doing such policy not for security, as they still own the master key to everything they produce (!), but for making sure people keep on buying new products and destroying the planet ever more. Screw this crap.
EDIT: If you like to think of yourself as an eco-responsible or eco-worried person, consider how "right to repair" (or "apple/samsung locks" on the other hand of the spectrum) fit into that worldview.
Why can't I, as an owner, choose to unlock the mac myself without having an external authority to "let" me?
I don't have statistics at hand, and overall the M1 is pretty new so it's not a problem for this device YET, but it's a serious problem i notice several times a year in my close circle.
Activation lock has nothing to do with the phone's pin or passphrase, by the way. It's tied to an iCloud account. In the exceedingly rare instance where someone has forgotten the pin they used to unlock a device continuously for two or three years, they can disown the device by signing into icloud.com from any web browser.
It's curious that you don't even know how the process works, which makes me begin to doubt that you've ever had to deal with it.
Not talking about Apple hardware/software specifically here, but i don't see the same here. Most computers donated to associations i'm involved with was never wiped, even when coming from corporations/institutions. Sometimes though, we do receive computers without (EDIT:) harddrive, but it's still the minority. I can count on my two hands the times someone has donated to us fresh system installs (user data wiped), in over two decades.
> they can disown the device by signing into icloud.com from any web browser
That is, assuming you know these credentials. Most people who are not entirely locked inside the Apple walled garden create an account because they're forced to but don't care/remember actual credentials, then forget it. Same goes with other kinds of credentials, not just Apple... but only forgetting Apple (and a few others, like Samsung) credentials turns hardware into useless paperweights.
Or maybe the person has diseased, or moved to a foreign country. Or maybe they've just donated the old phone in a box full of random stuff and by the time you realize the phone is locked the person has already gone and you have no way to reach them. In my personal experience, even with hardware directly donated by friends, fishing for an old passphrase more often than not raises "uuuuuuugh i gotta have this password somewhere, let me check and i'll call you back in a few days" (<-- loop here for about 3 months before you give up).
> It's curious that you don't even know how the process works
I pretty much know about it, thanks. I was suggesting precisely that iCloud lock be entirely removed, and instead a recovery mechanism would wipe the entire device as a privacy-protecting measure.
You have no idea how much of the stuff you receive is dumped on you after being stolen (or otherwise misappropriated) and judged too worthless to fence.
But we certainly know that only the tiniest fraction of devices go to recycling centres like yours, and so of course you’re going to see mostly activation locked ones which have no market value—and not the other 99.9% of devices where activation lock didn’t preclude second hand sale, trade in, or commercial refurbishing/recycling.
That's a lot of ifs to simply use a device. Most devices, including pencils, bikes and cars, do not come with such troubles. Hell, even most phones and computers do not come with that.
If you like to think of yourself as an eco-responsible or eco-worried person, consider how much conspicuous consumption occurs because stolen items tend to get replaced. Theft causes people to "...keep on buying new products and destroying the planet ever more. Screw this crap."
If you wanna go all pedant on it, let's do... Are you seriously claiming that your "right" to own a device that cannot be used by anyone else without your explicit approval even after your death outweighs my presumption of innocence?
Going around and claiming everyone who hasn't got a specific passphrase is a thief isn't helping make your case credible. You're just ridiculing yourself to people who can't afford first-hand devices.
My right to own a secure device massively outweighs any desires held by criminals, or downstream beneficiaries of criminal activity.
If i find your phone and it lets me know of a way to contact you, i'll probably return it to you whether there's an activation lock or not. It's a common courtesy that applies to wallets as well.
> My right to own a secure device massively outweighs any desires held by criminals
Your device is not in any case secure, as Apple has all the keys to break in. That's why there's an entire gray-market of icloud unlocking based on corrupting Apple workers.
Since you are so much in favor of private property, i suggest you invest in a self-destructing phone, wallet and car. If anyone who doesn't match your DNA even just touches it, they should get blown up along with the device. Because that's the only way to be sure you own stuff while making everyone else's life terrible for your little material comfort. /s
The word "get" is doing a lot of heavy lifting there. Activation lock does NOT block the second-hand trade of non-stolen devices. It blocks the illegal second-hand trade of stolen devices.
You are essentially advocating in favour of crime.
Based on your logic, you should be demanding that vehicle immobilisers and anti-theft devices are also anti-features. We wouldn't want car thieves (ahem, sorry, "second-hand owners") to be inconvenienced either. Once your car is stolen (ahem, sorry, "sold"), anything which impedes the free use by the new "owner" is ecological vandalism.
While you're at it, perhaps we should require all security safes to be openable with a paperclip, just in case you lose your keys. Otherwise people will keep buying new safes.
It also blocks the re-use of devices that were thrown away or given to a recycling center (because 95% of people who do this won't remember to turn off activation lock). I'm pretty sure that's what GP was referring to.
There are already plenty of perfectly good phones in the world; putting stolen iPhone 12 Pro devices into the second hand market lowers the value of existing devices.
Source?
> putting stolen iPhone 12 Pro devices into the second hand market lowers the value of existing devices
Funny argument. So would you be OK to remove iCloud lock from all devices except the newer line? That would be fine by my book for legit second-hand purposes. (Though i'm pretty sure Apple and its fanboys would be still pretty hostile to it)
I don’t need one, it’s entirely deductive reasoning. Do you dispute that people generally acquire a replacement phone if theirs is stolen? Do you dispute that phones have the same environmental footprint whether they’re an upgrade or a replacement for a stolen device?
As for your last paragraph, I have no idea what you’re talking about. That doesn’t sound like a response to what I said. I don’t want activation lock removed from any device.
No, i dispute that locking phones reduces theft. Because as i've explained, unlocking phones is perfectly possible and there's an entire gray-market industry dedicated to that. But yes i dispute your last statement, because it is true on an individual level but false on a collective level. If you get your phone stolen, you will buy a new one, but on a global scale, stolen goods are still circulating and therefore do not lead to increase in production of devices, and therefore has ZERO environmental impact.
> I don’t want activation lock removed from any device.
Then you truly are an enemy of the planet and the people, because you wish to keep your owner's privileges just for yourself and don't care if you have to set the entire planet on fire and ruin lives for that. I hope in a few decades, when we are struggling for basic survival (eg. finding drinkable water that has not been polluted by silicon/lithium/oil refinement), you remember that it is your choices and your acceptance of this fucked-up society that took us there.
Simply preventing passphrase recovery apart from a trusted centralized third party (Apple) is wrong on many levels: it's an ecological disaster, it's a disappointment to good-faith second-hand buyers, it's incentives for corruption within Apple and a shady iCloud unlocker business...
In essence, it's fundamentally incompatible with right to repair and fuels an Apple-insider mafia that honest people have to bribe in order to use a device. That's pretty much Apple's fault no doubt.
Which is not Apple's fault.
But they have decided to go against right to repair and against basic principles of ecology. Just as they have, in other fields, decided to go against basic principles of interoperability (Micro-USB/USB-C charger? Jack plug? Standard screws? who needs that, right?).
So yes Apple is harming users and is harming the environment. No amount of greenwashing can undo that.
The point is, this is a solved problem.
(This was five years ago, by the way.)
You have cardboard boxes for electronics devices at the entrance of every supermarket of a certain size (by law) and you simply drop it there. Although admittedly most devices thrown in there do not end up on the second hand market (though i can't say i've never helped myself from these boxes in the past :D)
But the same goes for most ressourceries and other second-hand market: some people donate cardboard boxes full of stuff anonymously, the workers triage through it, then stumble upon devices to which they don't have a passphrase... and don't have any way of contacting the original owner.
Definitely not a solved problem in 99% of the world.
This is the kind of recycling service many people use. Very common here in Australia; companies pay a non trivial price for even a five year old iPhone or iPad.
> You have cardboard boxes for electronics devices at the entrance of every supermarket of a certain size (by law) and you simply drop it there.
It baffles me that on one hand you scorn me for my supposed affluence while inferring that people in your neighbourhood supposedly just dump perfectly good iPhones into a bin without wanting any money for them. If that’s not affluence, I don’t know what is.
People talk about Apple lock-in issues in general terms. No one seem to look at from a matter of practicality. I have fixed my iPhones every time there's an issue - because I actually can. My HTC camera had the purple glare issue. HTC refused to service it unless I pay $200 + shipping back and forth and be without a phone for 3 weeks!!! Same with my LG TV or Sony laptop.
I used to complain about the same things people in this thread too - about how draconian Apple is. Until I actually started using their products and realized they both last long and are repairable. The only downside is the cost - even that is not expensive in the long run (my Pro is now 7 years old and runs like a champ with just a battery replacement).
I can assure you noone uses that in France. When people want money from second-hand devices, they either go to Cash Converters (a chain of local stores) or sell them directly on LeBonCoin.fr (our craigslist equivalent). I don't know a single person who has ever sold a device apart from those avenues.
> It baffles me that on one hand you scorn me for my supposed affluence while inferring that people in your neighbourhood supposedly just dump perfectly good iPhones into a bin without wanting any money for them.
I don't intend to scorn anyone by pointing out material privileges. Owning a brand new iPhone is upper-class privilege, as it's over 1000$ which is about twice social support (RSA) in France (~500€/month) and is the same order of magnitude as french minimum wage for full-time (35h/week) work (~1100€ after taxes). In some corners of France, you can buy a house (though not the best/biggest one) with that kind of money. In Paris, you can rent a two-bedrooms apartment with that kind of money. Wherever you live in France, you can eat for more than a year (as a single person) with that kind of money. So yes it's a privilege to afford that kind of amount.
EDIT: Just to give you perspective, of all my relatives/acquaintances, the typical phone budget is between 50€ and 200€, which gets you a brand new super-crappy Samsung/Huawei phone (super crappy software wise because you're locked with the manufacturer's Android, hardware is a charm), or a decent second-hand Apple/Samsung phone. I know one or two geeks who put more because they want to acquire a FairPhone or a Librem, but they are the exception, not the norm. And to give more perspective, i live in one of the top10 richest countries on Earth, just imagine how the phone economy works in India or South Africa.
Now i'm not exactly saying most people in popular districts throw away their functioning phones in such bins. I'm saying if they're getting rid of anything electronics for recycling that's where they put it. More specifically, and in this order, folks would typically: donate it to a relative/acquaintance, sell it second hands via CashConverters/LeBonCoin or donate it to a local ressourcerie (donation-based second-hand hardware store), sell it for a few bucks on a flea market to a phone dealer, or as last resort throw it away with the old lightbulbs in supermarket "recycling" bins.
No, it just makes it harder and feeds a gray market of phone unlocking. You appear to be a person who mostly deals with first-hand hardware in a rich western country, where there are Apple stores nearby.
Most people who sell or give away their devices DO NOT change/reset passphrases. This is true for all devices, and i've often had to recontact sellers in order to obtain such credentials. Sometimes, such communication is impossible, or the owner has forgotten the passphrase after leaving the device for years in a cupboard.
With usual computers, i can usually do without even the BIOS password and just boot on USB to setup a new system. Or at least i can take the hard drive into another computer, set it up and move it back in order to boot. With Apple/Samsung devices i end up piling them in my own cupboard and/or throwing them away, which is OK because i didn't pay for them.
It's infuriating when friends/neighbors came to me with devices they acquired in good faith for a reasonable price (<= 100€ for second-hand phone), and can't get it to boot. They then have to go to a phone store and pay 30-50€ more to get the phone (whether Apple or Samsung) unlocked, through a shady mafia (there's articles online about that). All this because of these evil companies.
> We wouldn't want car thieves (ahem, sorry, "second-hand owners") to be inconvenienced either. (...) While you're at it, perhaps we should require all security safes to be openable with a paperclip
You're making a bad faith argument here. Inconvenience is not the problem. Having to follow procedures to reset a device, changing a car security system because you were sold the car without the keys, or changing a safe lock are all possible though inconvenient. Apple/Samsung make it deliberately IMPOSSIBLE to reuse their device without going through shady third parties.
> You are essentially advocating in favour of crime.
In some circumstances, yes. I'm generally advocating in favor of burning down these Silicon Valley companies destroying our lives and our planet and making billions of the backs of workers. However, in this case i'm merely advocating for the right to repair and the second-hand market, both of which are perfectly legal occupations, at least in my country of residence (France).
I'd like to emphasize that through locking devices to a single "owner", you are essentially advocating in favor of crime, by creating incentives for corruption within iCloud services, while at the same time placing the burden of POTENTIAL theft (which i suspect is just a tiny portion of second-hand devices, though making statistics would be complex as we're talking illegal stuff here) on the good-faith customer who bought the phone on craigslist (or local equivalent) or a second-hand market without knowing it was locked. Yes, most people are that gullible. I don't think placing the cost of unlocking on second-hand owners is fair in any way, or creating any kind of sane incentives on a global scale.
And yes, it's a complete ecological disaster: ask me, i have a drawer full of apple devices (donated to me over the years) to which i don't have passwords. They are essentially highly-polluting paperweights, though i keep hoping they can at least come in handy one day when someone needs a spare part. Speaking of which, locking devices does not prevent scavenging for parts and therefore does not disable theft incentives, contrary to your argument.
> It's infuriating when friends/neighbors came to me with devices they acquired in good faith
If you don’t have the activation lock removed, you’re not the second-hand owner, you’re more than likely in possession of stolen property which has been dumped in your hands.
A stolen device doesn’t become ethically cleansed because someone bought it off the criminal “in good faith.” It’s still stolen goods.
All serious recycling services pay money for phones. Every single one I know of pays almost nothing if the device is activation locked, so it’s in the interest of the seller to deactivate it.
But I doubt that I could have gotten a firmware password for most of them. They would just have been thrown in the garbage.
I also got a couple of phones that could be used for testing web-apps. The last one was locked, and it would be pointless to try to get it unlocked.
Maybe the BIOS should give you full ownership if it can check that the device is not reported missing after one week. But I guess that would give robbers a motive to kill the owners.
Maybe devices should just unlock when they 5 years old.
Exactly! Thanks for confirming my personal experiences. I almost thought i was going crazy with all those Silicon Valley fanboys telling me my personal experience does not exist in the real world :)
> Maybe the BIOS should give you full ownership if it can check that the device is not reported missing after one week. But I guess that would give robbers a motive to kill the owners.
I don't think most people (even most thieves) would kill for a few hundred euros. But hey it's just my personal bet i don't have actual statistics :)
> Maybe devices should just unlock when they 5 years old.
Yeah maybe auto-timeout of BIOS lock could be nice to enforce for reusability of hardware. Something like you have to re-enable BIOS hardware (such as iCloud lock) every year or let it will auto-expire. This way the Apple cult can be happy with their brand new iCloud-locked iPhone which costs more than a second-hand car, while older devices could be reused instead of being thrown away or piled in a drawer.
Apple recommends against this, of course, but it's your computer, so you can make your own choices!
For example, in Myanmar[2]:
> Most recently, there was a dispute with ProtonVPN (the company that also makes ProtonMail) over an update for its app in the App Store. Proton Technologies claimed that Apple was intentionally blocking the update amid the ongoing crackdown in Myanmar.
And in China[2]:
> "China appears to have received help on Saturday from an unlikely source in its fight against tools that help users evade its Great Firewall of internet censorship: Apple."
> "The Republic of China flag emoji has disappeared from Apple iPhone’s keyboard for Hong Kong and Macau users. The change happened for users who updated their phones to the latest operating system."
> September 2019 — Apple adopts a “SIM canary”. If you insert a Chinese carrier SIM, apps like TikTok & Apple News no longer function.
> May 2021 — Censorship, Surveillance and Profits: A Hard Bargain for Apple in China
And in Russia[2]:
> October 2020 — Apple forced Telegram to close channels run by Belarus protestors
And in Pakistan[2]:
> February 2021 — Apple Removes Apps for Pakistani Government
There are about a dozen more examples than those in this article here[2]. Here's its conclusion:
> So what does any of this have to do with app developers? Why should we care? When it comes to the iOS App Store, Apple controls where we are allowed to distribute our apps. More importantly, Apple has the unilateral power remove our apps from any App Store region at any time to nurture its relationship with whatever unsavory government it is interested in pleasing in order to pursue its political motives or financial objectives.
> Apple’s centralized power over app distribution combined with its willingness to surrender to political pressures is incredibly concerning as ostensibly “democratic” governments across the globe (including the United Sates!) increasingly exhibit far-right, fascist behavior and implement fascist policies. What will happen when you need to build your own HKmap.live?
[1] https://news.ycombinator.com/item?id=26644216
[2] https://www.jessesquires.com/blog/2021/03/30/apple-cooperati...
The argument is whether you think their people should be able to use iPhones or not. If so, the rules are the rules. And the argument is that it would be better they had iPhones than domestic phones more likely to be compromised.
[1] https://en.wikipedia.org/wiki/Myanmar#2020_elections_and_202...
[2] https://www.npr.org/2021/02/11/966923582/what-myanmars-coup-...
[3] https://www.mei.edu/publications/myanmar-february-coup-and-r...
1. Within minutes, every iPhone is disabled from accessing the state owned cellular systems.
2. Any employees or executives in Myanmar risk arrest and, possibly, torture or death for allowing free speech and disobeying the government.
3. The average Myanmar citizen gets free speech for an hour or so, then gets informed they must buy a new phone, possibly made by a state owned enterprise, that is much more invasive to their privacy.
So what, exactly, did making a stand accomplish? Absolutely nothing, and everyone is worse off.
> Within minutes, every iPhone is disabled from accessing the state owned cellular systems.
Ludicrous. Myanmar has multiple private telcos. During the coup the military controlled internet access by the highly sophisticated means of cutting wires in data centers. It would take them days or weeks to individually block iPhones.
> Any employees or executives in Myanmar risk arrest and, possibly, torture or death
Some of those employees are US citizens. They all represent America's premier megacorporation. Killing them would not be a good move, especially as the US military finishes opening a spot on its "developing countries to demolish" list.
> they must buy a new phone, possibly made by a state owned enterprise, that is much more invasive to their privacy.
The junta can't make phones.
Apple has no power in China but China and Myanmar are very, very different places. If they wanted to, they could exercise significant influence.
In nations considered authoritarian, “private” should be taken with a grain of salt. In China, all businesses with over 50 employees must have a dedicated CCP representative.
Finally, it doesn’t matter if they can’t make phones. They’ll call a Chinese company in Shenzhen and they’ll rush in a pile of branded phones in weeks.
If you don't like the laws of other countries, you should be angry with the Government which enacted them—not its citizens or corporate residents for complying with them.
This claim feels a little weak when there are two other posts currently on the front page discussing a zero-click iMessage exploit in iOS 14.6, which has been abused by nation-states to spy on journalists and opposition leaders.
If this is truly their aim, then they are likely a long way from having adequate software security.
Aside from that, with all these security features I'd be quite content if there was a way to setup an endpoint at *.myco.com instead of *.apple.com for the 'calling home'.
I just don't want my hardware being so tied to the network services of one vendor. Is it too much to ask?
>According to the small print in Apple’s Platform Security Guide, when you set up a new M1 Mac, or set one up after restoring it in DFU mode, the primary admin account created is special: it’s the Owner account of that Mac. During that inital setup, the Mac sends a request to Apple for that Mac’s signed Owner Identity Certificate (OIC). This is based on a private key generated in the Secure Enclave known as the Owner Identity Key (OIK).
I'm not trying to imply that you're wrong at all, but I'm curious how the Mac goes about obtaining the OIC without a network connection.
This mainly would come into play, as the article says, if you install another operating system. By default, the OS is in Full Security mode, so it would contact Apple when installing the other OS and the OIC may come into play.
But if you aren’t installing another OS, or you set your Mac to permissive security which needs no internet, perhaps the OIC is not required because you’ve downgraded the security?
Im just speculating.
Still, somehow, the fact remains you can fully set up an M1 Mac without internet. The technicals of how it does this while reconciling that with the security guide is unknown.
> When macOS is first installed in the factory, or when a tethered erase-install is performed
So when you're setting up for the first time after the factory install, it already has the OIC. I think.
[1] https://support.apple.com/guide/security/localpolicy-signing...
apple doesn't even have a comparable os to be compared to home, as it's a market they don't even target or develop for.
Yet it will be sold on laptops to anyone that buys them, even if the customer is a 'pro'. It's their prerogative, but I would rather see 'Want to set up with an offline account? Upgrade to pro now for $80'.
Microsoft puts garbage into Pro/Enterprise too, surely you know.
Then I tried 'ATTO disk benchmark'. This tool tries a variety of read and write I/O size ranges. The results I got here were strange. As expected as the I/O size range grows, the read bytes/s increase. Then it hits 1MB I/O size and the throughput drops to almost 0. Write was consistent across the range, perhaps since it simply hits a buffer on the SSD to be processed later.
With dd I achieved good performance transferring a 5GB file, after a reboot to ensure the file cache was definitely flushed.
Perhaps it was an issue with the firmware version for the Orico or the SSD itself. Unfortunately I was unable to update the latter since the 'Samsung Magician' software is windows only. On my windows devices I have no thunderbolt ports.
I don't like that you apparently can no longer boot into the setup tools and reset a Mac to factory new condition. I had wanted to do this when I could not get LispWorks running with the newest beta macOS - I ended up just deciding to use SBCL until this gets sorted out.
I recently did this on an M1 Mac mini (wiped boot drive + did a clean install of macOS via the internet), so unless I'm misunderstanding what you mean this is definitely possible.
How much longer? Will Windows 11 finally choke off the supply of perfectly good, cheap, secondhand Linux capable hardware (by no longer requiring an unlockable bootloader)?
This quote: "I’ve been unable to find any information provided by Apple (or anyone else) which explains what’s going on, what the errors mean, or how to address them."
That's my experience constantly.
My development build had weird behavior when I explicitly launch it? Oops, Apple launched a cached version of the app inside a private temp directory (thanks Gatekeeper!) associated with the protocol handler.
But no way to tell until I casually check the process working directory. No documentation indicating how to troubleshoot this.
Countless issues like this.
Whenever I develop for JavaScript, if I find a module that just has weird undefined and undocumented behavior, I get rid of it no matter how powerful. I wish I could do that with the Mac developer ecosystem. It's closed and Apple will say that gives them a premier experience but it's the little snags that cost me 90% of my time and are impossible to troubleshoot other than grunting through it.
Have been a developer for windows applications for 20 and some years. Software I build back then still runs fine.
Have been a developer for macOS since 2013, since around 2019 I need to bring out patches for changes in the core OS multiple times per year. macOS is not a pleasant OS for a developer. Documentation is pretty shitty and the rugs that get pulled from under you all the time are frustrating.
For Windows you nowadays need EV code sign certificates in order to be able to distribute without any troubles and -while you don't pay that directly to Microsoft- these certs are significantly more expensive than the "macOS developer tax".
Yes, you can also distribute to the Windows App store, which is cheaper (a one time tax). But I'm not really a fan of "App Store's" be it from Apple/Google or Microsoft.
Windows has its quirks and bad decisions they made over the years but the developer experience is consistent, even when bad.
Apple's experience is like being in an Arabian desert: sometimes you see a mysterious oasis that wasn't there before, but mostly it is shifting dunes that cost days or months.
This works a lot better when the set of "things that cause problems" stays relatively constant.
Third party developers are an example of "out of sight, out of mind." It's easy to forget how a feature impacts them. And it's easy to say "We still have apps coming into the platform."
But what you don't see is the frustration, resentment, or apps that were never written because developers found something better to do with their time.
Mac and iOS development isn't there yet, but it sure feels like they aren't trying very hard to steer the ship in any other direction.
So the kids are now using Brave.
Used to be the case for Windows as well with Internet Explorer.
They even support this for WebView2, the embedded version of MS Edge that you can use in your applications. [2]
Both of those operating systems have been retired for a while.
Microsoft has its flaws as well, but at least in this part they are doing quite well.
I just happen to be working on a WebView2 ActiveX control and this is one of those areas that really did surprise me.
[1] https://docs.microsoft.com/en-us/deployedge/microsoft-edge-s...
[2] https://docs.microsoft.com/en-us/microsoft-edge/webview2/#su...
Personal experience with trying to switch to Mac has been...well, both expensive and unpleasant. Single data point, but new hardware that fails every 4 minutes after power on and the fix being an upsell has really put me off.
Aka "never trust Microsoft's pronouncements and stick with legacy frameworks forever, because it's the least risky option."
Linux? Sometimes. Trying to run DXX-Rebirth in a modern Linux is an exercise in frustration.
The Windows version still runs flawlessly in Windows 10.
Personally a few years ago i tried some older game demos from early 2000s from publishers like LinuxGamePublishing and TuxGames and they pretty much all worked fine after some tinkering (usually removing bundled libraries like SDL so that the binary will use the system provided libs that are more up to date and/or installing OSS support for audio). A few required some missing libraries but those were available either on the repository (Debian) or from older distros (i grabbed some RPMs and extracted the .so files manually). Two games i couldn't get run because they relied on Gtk1 though - it shouldn't be impossible to run, but lost interest (Slackware contains Gtk1 so i could have copied it from there).
`rm -rf Chrome.app`
The equivalent between native development and web is not the quirks of a library, it's the quirks of browsers. That's the metal you're running on.
Might be worth reading the entire post and commenting on it in its entirety, not cherry picking.
The bulk of my experience has been with native development, so I find these struggles familiar and un-threatening. However, when I do browser-based development and I'm faced with one of those massive "Browser compatibility" tables on Mozilla.org explaining how this "standard" is implemented in wildly different ways across the major browsers, and then the reality turns out to be different from what the table suggested, I get as frustrated as `xrd` is.
Unfortunately, the one browser causing the most miserability for web developers these days is Safari itself, not Chrome as you implied. It is the only web browser engine that's allowed to be used on iOS devices, and many people use it on Macs since it is able to use all the undocumented quirks and nooks in OS X to smash Chrome/FF in battery usage.
The problem is that it has so much stuff that's outright broken (IndexedDB), is outdated (its developer tools) or just plain sucks (it won't play <video> elements if the server doesn't serve Range HTTP headers, for example - painful if you're streaming from inside a CMS). And that's been the case for years.
Safari is the new IE. Apple should be forced, just like Microsoft, to de-bundle it from the OS and open up and document their private APIs to allow Chrome and Firefox to be competitive!
And Firefox, remember, laid off most of the engineering team. The only real people benefiting would be Chrome based browsers, with their ability to spread Chrome to even more places.
I think it's a bit of a straw man to say that the only reason web development is hard is safari. Browser support is irreducibly difficult as long as we live in a world with more than one browser. Safari may stand out as the odd duck, but I for one don't want to stream video on my 3gb a month data connection if it has to load the full content in order to jump ahead 2min.
My software has a feature where you can package certain files into a basic no-frills installer. This is a minor feature that pre-dates notarization in a much bigger suite of tools and it causes a lot of issues because users contact tech support every time Apple’s notarization service goes down (which is often). At this point I’m considering just removing the whole feature from the suite.
Isn't notarization stapling supposed to prevent this? Or does it do a OSCP/"is this signature still good" check on every launch?
This is the real problem.
You can concoct whatever inscrutable secure boot + firmware attestation scheme you want, but if you refuse to provide technical documentation for how it works, then this outcome is guaranteed. It doesn't have to be beautiful long-form prose, just a block diagram and a README level description of how it's supposed to work. Apple is really bad at this.
You might be tempted to argue that Apple doesn't care about alternative operating systems and shouldn't waste resources documenting this, but this argument is flawed. As the author states, Apple's M architecture will end up in their high end systems, and those users are going to have crazier setups than a typical consumer laptop.
It costs Apple next to nothing to let the Linux nerds figure this stuff out now and find bugs faster than Apple can, but the result for Apple is that the products they release next year and the year after will be more reliable. Basically for free. Shouldn't they want that?
Most of the reactions here are overblown to a worrying degree. Surely an average HN consumer should have more common sense than that.
Even with "secure boot" and "UEFI", I have no trouble installing other OSs on the latest Intel hardware from Microsoft, Supermicro, or Dell.
Installing betas tends to come with caveats...
What happens in the case of offline setup?
At the bottom of the article he seems to address this sentiment.
I'm still using Catalina, because Big Sur broke Display Stream Compression completely, and it's still not fixed in any of those releases, let alone Monterey.
So until Apple pays attention to the hundreds or thousands of bug reports on a completely working piece of functionality they broke (although I'm sure they'd rather we all just bought Pro Display XDR monitors), I'll dutifully stick with Catalina and cross my fingers and test each new release from an SSD, so my 27" 4K HDR 144 Hz monitors aren't completely crippled.
Not things I own. There are other places that manufacture electronics than China. And "everyone does it" does not a justification for being complicit in genocide.
Here are good places to start looking:
- https://notmadeinchina.directory/
- https://bestfreereviews.com/best-laptops-not-made-in-china/
- https://www.republicworld.com/technology-news/gadgets/non-ch...
Maybe if Europe stopped colluding and glad handing with Tyrannical governments like China and Russia they too could offer up some alternatives. Doubtful though, Germany is all about double speak, saying that they are against genocide while doing everything in their power to prop up genocidal regimes to maintain their regional hegemony.
For example, best laptops not made In China showed a Surface Pro 7. Which is Made in China.
What do you mean? Using an external webcam while connected to an external monitor works fine.
(Source: I have been using such a setup in a course for the last few weeks.)
I like the idea that should anyone be foolish enough to steal my MacBook, not only will they not be able to get my data, they won’t even be able to get much useful value out of the purloined goods.
Uhh, got a citation on that?
There’s more to be found on this new-fangled internet search engine called Google. You should try it: https://www.google.com/
I've had this happen to three people I know. Works like this: they contact you via your contacts, pretending to be apple care specialists, ship a link, then social engineer you into entering credentials, then they disappear.
(I don't really know how they get to contacts, but this was the case in all three instances)
Story was, this girl from Italy bought my phone on ebay but then saw my message and then took it to the Apple store. Someone from the apple store would contact me to arrange recovery of my stolen phone.
Couple hours later I got a message from another number asking for me to log in to my iCloud account and arrange an appointment using this link. Opened the link and about to type my details in then I saw the domain wasn't quite right. Looked into it, realised it was a phishing attempted and bailed on that.
I know they can't access the phone whilst it's still on my iCloud account so it will remain there, in lost mode, until the heat death of the universe.
Rarely are anti-features sold to unsuspecting users without having some positives to explain their existence.
That there tells me it was not production ready for M1 Macs at the time, which isn't good.
At what time?
So your point was to complain about how Docker took a long time to update their code. I guess that’s not good.
Not exactly. The software was not stable for general use for M1 users at the time of its launch in November 2020. That is the point.
I don't know anyone who thinks or recommends using unstable preview tools for production use is a good idea or even waiting for the software to stabilise for months on a newly unsupported machine. Means you can't use it properly for months.
Might as well use an already existing computer that works well.
That seems like a basic fact that nobody is contesting.
> I don't know anyone who thinks or recommends using unstable preview tools for production use is a good idea
Who is recommending that?
> Might as well use an already existing computer that works well.
It seems bizzare to suggest that the computer doesn’t work well when it obviously does.
I agree it’s better to use a computer on which the software you want to use is supported. I personally ruled out buying am M1 Mac until after Docker was supported.
Is that the point you are trying to make?
Unfortunately, most of the frustrations were from users who went 'all in' since November 2020 and realised that the device did not work well for them.
Not only basic updates didn't work, recovery mode also failed to work. Then Apple prevented the majority of popular iOS apps from running on the M1. Making it only up to the developer.
> I personally ruled out buying am M1 Mac until after Docker was supported. Is that the point you are trying to make?
yes.
It's better to wait until the software you need is available, officially supported and stable; and then switch rather than buying it and going all in and realising that the software you need doesn't work well and gets in the way.Implying that the device is at fault is dishonest.
For you to say 'All reports' is straight up dishonest, when people have reported SSD wearing issues, update and recovery issues and that WAS broken on M1 Macs on launch. You have to use/buy another Mac to recover it or go to the Apple Store since November 2020 on launch day.
Maybe if it was 'working extremely well' you wouldn't need to go there and those reporting dead M1 Macs as a result of this, well lost their data and have to buy another one.
System software also counts, and particularly for M1 Macs, it did 'not work extremely well' as soon as it released in November 2020.
Even the author of this article who also uses an M1 Mac since launch day does not hide or pretend about this.
No. We’re taking about how the computer works. Not the occasional faulty unit.
> when people have reported SSD wearing issues, update and recovery issues …
Consumer products are sometimes faulty. If you ship them in volume, some consumers will receive faulty units.
If you had evidence that M1 Macs have a greater failure rate than their competitors, you would have presented it.
And the computer needs system software to run properly to be usable, otherwise it is useless on its own and cannot boot anyway.
If the system software is causing issues, you update it. On launch day, that was broken and so was recovery when they launched.
> If you had evidence that M1 Macs have a greater failure rate than their competitors, you would have presented it.
So in November 2020, 'All reports are that the M1 Macs work extremely well?' Typically, that includes the default install of the system software upon purchase that can only be macOS for M1 Macs and for it to be "usable" it 'must be switched on' and the only way to control and update the hardware is via system software on the machine. Otherwise it is useless.
If 'All' reports were that M1 Macs worked extremely well, I would not be seeing such frequent issues or reports mentioned anywhere on launch day or a month after. That was not the case.
The author of this post has the evidence themselves and does not hide the issues that happened on launch day and for several months on end.
It worked pretty well.. sometimes you had to use the x86 container instead of the arm version. And I had one container that hadnt been updated by the maintainer in a few years, so I had to update it myself so it would work. And sometimes qemu would crash... but those cases were all exceptions, and it generally worked well.
At the time since November 2020:
> 'Docker Desktop on Apple M1 chip is still under development. We recommend that you do not use tech preview builds in production environments.'
My intention is not to 'test' this software, I am simply using it for general use and I do not suggest using beta or preview software to anyone if it is known to be that unstable. As soon as it was marked officially as a 'stable' release, then I would use it.
Those who bought the M1 would have waited 6 months for it to be stable.