Apple’s macOS Ventura – New Security Changes
sentinelone.com
sentinelone.com
[1] https://dortania.github.io/OpenCore-Legacy-Patcher/MODELS.ht...
[2] Except the mainboard, display and shell everything else thats modular (wifi card, ssd, battery and keyboard) was replaced/repaired at some point.
You can look on the Macrumors forum and Reddit to see if they're already getting the betas to work.
https://forums.macrumors.com/threads/macos-13-ventura-on-uns...
https://www.reddit.com/r/venturapatcher/
Edit: the OCLP team released an official statement, looks like they're having quite a few challenges. https://github.com/dortania/OpenCore-Legacy-Patcher/issues/9...
Will Safari 16 be available on older macOS? Assuming Apple doesn't break their tradition it should support two prior OS release, Monterey and Big Sur.
While I could do without an OS update on my MacBook Pro 2015. ( I cant record a single useful feature from all the previous OS update other than Universal Clipboard ) That means for MacBook Pro 2015 Model users they will only have two more Safari Update.
Short answer: you'll get all of new web platform features (Container Queries, Subgrid, etc.); you may not get certain Safari-specific features that require a feature only present in macOS Ventura.
You can get Safari Technology Preview for Monterey and Big Sur that has those new web platform features right now [1].
[1]: https://www.macrumors.com/2022/06/21/apple-releases-safari-t...
But it involved a lot more than just firmware. And there were lots of known issues with some configurations.
I'll check that software out though, perhaps I can run Mojave on my 2010 mbp, I really miss the dark mode
- userspace filesystems: the nail on the coffin for kernel extensions. Now we won't need to run in "reduced security" to use FUSE and that was the last kernel extension that remained popular. Probably kexts will be deprecated shortly - rapid security response
- it seems also to include changes in Xprotect and mrt
But userspace filesystems are already present in iOS so you can find some reverse engineered info on that (e.g. in Jonathan Levin's books)
For your own 3rd-party file systems, you'll still have to use a kernel extension for now. (or local NFS mount).
The OpenZFS implementation on macOS also requires kernel extensions, and I don't suppose it can easily be ported to FUSE or that that would have desirable performance characteristics.
Special kernel extensions are also required to get some basic functionality working on macOS these days, like disabling pointer acceleration.
Could you point me to the kext that does that? I’ve been trying to find a way to disable it for ages.
This is what everyone uses. Mouse acceleration disable is a dealbreaker for me- I won’t update unless something supports it.
The plan being, each kext has one year timeframe to migrate to the new userspace API after its introduction, and the year thereafter the kernel API gets dropped from the new OS release.
Can anyone shed light on why it took so long? I had always figured the non-existence of a login items panel was a purposeful choice.
Apple should be proactive and extract those items automatically, but in practice, they don’t.
However that feature became a bit stale since macOS started reopening all apps anyway.
Launch Daemons in particular are managed directly by launchd and can have more sophisticated triggers including periodic execution.
And in Linux? No great way of managing systemd via the GUI either afaik.
And Apple has always been one for hiding technical complexity from the user. It's only that security became prio #1 that they're doing this. 2010 Apple would not have presented the user with these popups for example.
Apple at that time really didn't care as much about security as they do now, it was before the fappening, before wannacry etc. They were more obscure as an OS so there was not as much malware. Security was not as much on the radar as it is now.
This is presented as a flaw, but I'm not sure they are thinking through the alternatives. It's hard to give too much credence to security experts who are't thinking holistically. Perhaps there is a flaw, but I'm curious to know what it is.
It's a difficult balance. Power users, engineers, developers - we can (usually) tell when warnings need to be heeded. People who use their devices to achieve a goal without really understanding or caring about what's happening usually won't.
I really don't want Apple to decide what I can have on my computer like they do with iOS. It'll be more secure but also a lot less free and functional.
And enterprises already have a way to turn this override off so I don't really understand their beef here.
So the less toys to play, the better.
Would disagree.
I think the security changes have made the OS more usable since I now get visibility into what apps are doing.
And I love the idea that security people pushing their agenda of making devices more secure and more private is painted as a bad thing.
security = 1/convenienceI loved that machine. I was able to skip the 2017 MBP and go to 2019, but honestly I miss the smaller trackpad.
Luckily, the M1/M2 is finally a worthy upgrade, after years of keyboard issues and unwanted features.
It had a good run! (My 2011 imac died last year)
It can be maddening.
Unfortunately every time I pointed this out most of HN were quick to answer this is an user issue and not a design flaw.
But butterfly keyboard had been pretty much universally decried as a terrible mistake almost everywhere, including HN.
That was certainly not the case until the reliability problem got magnified in 2018. When the problem has been there since 2016. Before that Butterfly was somehow the holy grail for touch typist.
When they skipped or doubled keypresses started it was just the cherry on top.
Even the "returned to normal" keyboard on the new mbp is not nearly as good as the 2015 was in terms of tactile feel.
So are you locked in with Apple if you use this, or can you switch all your existing passwords to another "passkey provider/service" ?
> "Wave Goodbye to CAPTCHAS"
I assume that's Safari only... so this is bad news for Firefox?
Sites will never go full Passkeys because that obviously falls over if you want to access it from any other device or computer, support request costs would go through the ceiling
[1]: https://blog.1password.com/1password-is-joining-the-fido-all...
I don't think it will be Apple only. However, I am wondering what will happen to services like bitwarden [1] if it is available on other OSes as well.
Will major players be too powerful that no competing solutions will realistically exist.
I suppose that passwords will always be a thing for the paranoids amongst us. But i don't know whether that is enough to sustain the product.
I’d rather use bitwarden than Apples wallet.
https://fidoalliance.org/apple-google-and-microsoft-commit-t...
Eventually, yes. Not now, but the goal is eventually, yes. It requires support to come to Android and at that point, they'll build the bridge to bring them together. I don't think the system currently exists for this, but they've said Passkeys will be a "multi-year industry-wide transition" so I'm inclined to believe it'll ship in the coming years.
When you sign in with a passkey, you have the option of scanning a QR code from a locally present device running any software that can speak the standard (e.g., Android). This means that you can login using any software that supports Passkeys using any devices that support Passkeys. For example, Chrome on Windows (chrome://flags, turn on passkey support) with an iPhone is a valid pair.
That it also happens to provide better security is just more cheese on the trap.
I wouldn’t touch it with a 10 yard stick unless I have full control of the private key.
And for consumers I don't think it's a good idea to remove this option altogether. The owner should have full control if they desire it.
The constant check for modifications is great though. I'm surprised that wasn't the case before.
It will be super annoying if this now starts making developer's life hell because it is nannying binaries they are building, sharing or working with as part of their development work.
$ sudo spctl --master-disable
(That said, I will also note that frustration is not inherently constant even when something is truly static: sometimes you get used to something over time and it stops bothering you, while other times it slowly drives you mad.)
I can't picture "Monterey" or "Ventura" or any other macOS names, they have no meaning to me.
I'm not sure that's the image Apple wants to give off though...
I may be dating myself somewhat here.
[1] https://en.wikipedia.org/wiki/Ventura_Boulevard#References
The OS in most cases just refers to itself by the number and is what it will show in a lot of scenarios in addition to the marketing name.
Not entirely true: two of the cats were name variations of their predecessors to express an intent of limited end-user / feature updates and a focus on refinement (even though taxonomically the cats have basically no relationships outside of being cats, mountain lions aren’t even in the same genus as lions)
It’s only in the last few releases that the dart board has come out
So will macOS 14 be further south (Carlsbad?) or back north (Eureka?) -- stay tuned...
Mac OS X 10.7 "Lion" – 2010
Mac OS X 10.8 "Mountain Lion" – 2012
Now it is only a name I guess only people in US / California will know or understand. The same joke From Apple's "crack marketing team" and played out by Craig Federighi for something like 10 years[1].
But I guess that is post Steve Jobs's Apple for you.
[1] Just guessing since I remember they started using this line after Forstall left.
Mac OS X 10.7 Lion was released in 2011.
Also, there's no "Mac" in OS X 10.8 Mountain Lion.
These places mean nothing to me.
US tech firms have a long history of using US place names as code names for operating system releases. Windows 95 was Chicago, if I recall correctly.
Weasel-word alert. I never thought I’d see the day when technologists would applaud the gradual death of general-purpose computing, but here we are. A decade from now Apple probably won’t even ship a local version of Xcode, and the transformation will be complete as all new development happens in Xcode Cloud where no line of code goes unscrutinized by the watchful eye of the mother ship. At least we’ll be Safe™.
Once the singularity is nearly complete you'll know: macOS and iOS will merge into one monolithic OS.
According to TFA this kind of verification will now occur every time an application is launched to deter post-verification “tampering” by you, the user. How big of a privacy violation would it have to become to bother you, out of curiosity? If we let this continue we will end up in a future where full “Remote Attestation” of every hardware and software component is required to participate in the Internet. This isn’t hypothetical doom-saying, either: game consoles already work like this. I remember my XBOX360 could detect modified DVD drive firmware, launches of individual pieces of software (e.g. Halo 3 Delta leak), and other types of system modifications, then it would permanently ban that machine from XBOX LIVE. And that was all 15+ years ago.
Just imagine what a gift this will be to law enforcement, for example, once they can go to Apple all like “Hey, Siri, show me all users of Tor Browser around the time of ${BITCOIN_TRANSACTION_ID}”.
The problem if someone decides that it's going to be the only option. And another problem is that they can.
So, your work is not regression, and it definitely has a positive use case. It's just that it can also make certain unethical things possible.
how exactly will it be easier than my current workflow of:
- Boot computer
- Press win-key + d
- type the letters "qtc"
- hit enter
- ctrl-alt-shift-<index the project I'm working on>
- ready to code
Having said that, I agree, the biggest problem here is that even if it doesn't seem obvious now, once the cloud offering is there the control it offers will make it very appealing for Apple to expand its use and eventually offer features there that aren't in the real XCode. It can fast be a slippery slope to the non-cloud app being deprecated.
The ability to have policies is very different from enforcing overly strong policies. Apple seems quite clear that they see iOS as being a platform with a stronger policy, and macOS as being a platform with at least the ability to run a weaker policy.
Edit: also Xcode Cloud isn't what you imply it is/could be, and Apple's moves with Swift being developed in the open suggest to me a very different direction for development. I can't see this ever being locked down, either in terms of technology or policy.
Any young folks wondering: yes, this exact same thing was being posted ten years ago, all the time.
"Apple's gonna totally lock down macOS without any way around it, they hate general purpose computing" and the related "Apple's gonna merge iOS and macOS" are the apocalypse cult of computer geek forums. They might be right eventually, but only after being wrong a hundred times. And they never get the timeline right.
Nope, I don't.
Does anyone know how to re-enable this functionality?
Meanwhile there are 10 year old ~$1000 Thinkpads running Windows 11 or Linux. If they just wanted to run Linux on it they could have saved themselves some money.
8 years of updates to current version and 10 years of security updates should be the absolute minimum for every expensive hardware.
Companies ought to love people who give them thousands for outdated hardware worth hundreds.
[1]https://dortania.github.io/OpenCore-Legacy-Patcher/MODELS.ht...
On a pettier note, can we get a better source than a website that's using JS to change its title when it doesn't have focus to try to gain attention? (It toggles about every second between "macOS Ventura | 7 New Security Changes to Be Aware Of" and "Message from SentinelOne". https://imgur.com/ynPqpvK - it's pretty awful.) I don't normally complain about scummy websites on here, but this is just annoying.
Interestingly, I went looking for alternative sources for the content, and found that identical content is on other sites [1] which are also doing the same title-flicker technique. So presumably this is part of some content network...
[1]: https://phxtechsol.com/2022/06/13/apples-macos-ventura-7-new...
Many of the things mentioned in the article aren't trivial. They may be smaller in scope, but size (large / small) are different than complexity.
You can take a look at what's new in Ventura https://www.apple.com/macos/macos-ventura-preview/features/ but that's not even getting into the under pinnings.
Similarly Microsoft made fairly significant changes to Windows between 10 and 11, and several times to 10 within its life cycle.
Unless you're talking purely visual design, in which case what kind of changes would you expect without upending people's workflow?
Examples of modest but non-trivial changes:
- eliminate the folder-file system (or at least make it completely invisible to the user)
- remove UI distinction (but not necessarily the sandbox distinction) between web apps and normal apps.
- seamless mobile-desktop integration, so the user views them as just different form factors for accessing the same resources.
(There are of course much more radical changes than these that one could imagine.)
I similarly question your definition of "modest". The first one alone is incredibly radical, and has been tried several times in the past but people keep asking for hierarchical file systems. It's far from modest.
1. How do you propose users organize things?
2. Already exists today with electron and webview. What would you propose an OS provide here? Many apps you use today on macOS are web apps within a native context.
3. This is already growing on macOS with features like continuity handofd, universal control, being able to run mobile apps on desktop, iCloud sync of projects etc.. Each year they've clearly moved towards unifying things.
If these are what you consider modest though, I fear what you consider radical without throwing out decades of learned user interaction in the process
My reading of your comment is that you aren’t actually interested in thinking about non-trivial changes here. “Didn’t you know people have tried eliminating folder systems before? It’s hard and hasn’t succeeded yet” is obvious and does not seriously engage with the possibility. (“Didn’t you know people have been attempting to make stylus input work for decades without success?”) Likewise, the fact that web apps can be disguised as native apps is not the same thing as eliminating the distinction at the user level, and I don’t think you would have conflated these if you were really interested in it.
So I don’t think it will be productive to continue this conversation.
Saying something is trivial, by definition, implies its a simple change. Nothing mentioned so far is simple. None of your suggestions were modest.
I understand you're using the word according to how you think of it, but I'm trying to point out that you're incorrect, and that many of the things you say are modest are not so.
You're actively down playing the amount of work and it either feels disingenuous to make your point, or divorced from the reality of implementation.
It was starting to become the alternative to Android for many of us.
Had they provided a proper migration path from Windows Phone 7 into 8, and then from 8.x UA model into 10 UWP, and more Win developers would have followed along, instead of hating them for all the rewrites.