Safely open apps on your Mac
support.apple.com
support.apple.com
sudo spctl --master-disable
sudo defaults write /Library/Preferences/com.apple.security GKAutoRearm -bool false
This reveal add and select a third option, "any source", under "allow applications downloaded from".The setting will still occasionally reset after installing some system updates because it's 2023 and computers these days are extremely unreliable when it comes to remembering user preferences.
Broadly speaking, as a developer you should expect that none of your users will have disabled those protections and your release plan should have notarizing as a step.
Asking users to disable system protection, or at the very least fiddle with system settings is a non-starter.
https://support.google.com/chrome/thread/15235262/chrome-upd...
And Apple isn’t immune either. There was a bug in the iTunes installer where it would erase files if there was a space in the name of the hard drive.
Then some companies are just evil.
https://www.zdnet.com/article/zoom-defends-use-of-local-web-...
I don't want to spend $99/year for the rest of eternity for the privilege of having a slightly less scary warning when my users run my app for the first time. Thus, the readme for the one macOS app I made that has gained a bit of popularity instructs users to right-click, then select "open". Works reasonably well so far.
I would absolutely have embraced notarization if it was offered for free. Otherwise it feels like straight up extortion.
Which it is
At this point, I'm not sure it's worth investigating. This isn't the 90s when everyone was running application software directly on their PC; now everything is done in the cloud or through your web browser somehow. I honestly find it funny when Windows users have all kinds of agony because of that "contempt" you refer to; if they don't like it, they're free to switch to another OS. I've been watching this for over 25 years now but people just won't give up Windows, even when they only use it for web browsing, so I've lost all sympathy for them, even though the Windows user experience keeps getting worse.
windows is/was laden with malware, requiring antivirus, just full of crap for decades.
Now in the DMA/DSA times, things are different. It took them a couple of decades, but the EU is starting to take action.
In that sense yes that is understandable.
As an American developer, $99/year is something I can afford, can write off as a business expense, and hopefully make back with software proceeds.
It should be noted, keeping the bar annoying but not prohibitive with a token fee does cut down on both junk submissions and malware.
> can write off as a business expense, and hopefully make back with software proceeds.
That's if your software involves money. Mine doesn't — it's all pure altruism. I just want to put my stuff out there for other people who might want it.
That’s what you see. Users see it differently. I’m not running random exes on my computer. Even package managers are run in containers and VMs
The sudo touchid mod gets reset so often now that I've stopped bothering with it. Ok, you win apple!
Uncomment, copy it over the default file, win.
Far less hidden.
Glad I could help. It ran through my feed today by chance.
I love Touch ID in general on this Mac. This just didn’t do anything special for me, so I never really adopted it.
defaults write com.apple.security.authorization ignoreArd -bool trueI'm not sure if this is because that info is out of date, or due to some other issue specific to my work machine and what the org has installed/configured on it.
What drives me insane: the inconsistent/invisible functionality around this stuff. In Ventura, if you double-click an unsigned app, it won't run, with a big scary message that it cannot be verified.
...except if you right-click and select "open", you can now click on a button that lets you run the app anyway.
This is not remotely obvious or even indicated in any way. There's nothing that explains this to the user, nada. It just behaves differently if you select "open" instead of double-clicking.
How on earth that compliant with Apple's human interface guidelines?
Apple stopped emphasising discoverability a long time ago.
But this makes me curious! What versions of Mac OS nailed discoverability and how? I'd love to look at old videos and/or emulate hardware for them and play around.
https://i.stack.imgur.com/bdY7i.jpg
Sometime at or after OS X, the industry pivoted to surprise and delight instead, and so did Apple. (Not sure who pioneered it.)
This feeds in well with the whole "cult of apple" thing, since to use the laptop / phone, you have to get other users to show you cool non-discoverable tricks. Take this article explaining basic functionality in Finder for example:
https://www.lifewire.com/use-mac-finder-2260739
I've been using OS X for about 10 years, and didn't know half that stuff.
Instead, I know just enough Mac OS CLI to know to avoid macports and brew, and to instead use a hypervisor or ssh to a machine with a reasonable filesystem layout.
Here's an article plugging surprise and delight. I'm not a fan, so I'm not going to try to enumerate its purported advantages:
https://medium.com/@davidporretta/surprise-and-delight-in-ux...
(Begrudgingly sent from an apple device.)
In addition, over the the next year we will introduce several changes to our security checks:
• A new encrypted protocol for Developer ID certificate revocation checks
• Strong protections against server failure
• A new preference for users to opt out of these security protectionsDone.
> Strong protections against server failure
Unknown, but presumably done.
> A new preference for users to opt out of these security protections
Never done. Apple lied.
The macOS appocalypse was a really shocking moment -- it was so disappointing to learn that despite the privacy marketing shtick, macOS engineers chose to have Macs phone home sensitive data in an seemingly aggressive way, with no opt out. Now in 2023 the fact that "a preference for users to opt out of these security protections" never materialized, and the copy just disappeared from the website, is quite disappointing. Great write up here [0] - thanks @lapcat!
Anecdata: Ever since that day I've blackholed ocsp.apple.com/ocsp2.apple.com at the DNS level, and all my Mac apps have launched just fine since.
If anyone at Apple reads this, I want to be given the choice. Warn me, stuff the setting into whatever plist -- whatever, but give me the choice.
Frankly for a company with Apple's resources, it's hard to believe the OCSP test suite somehow didn't consider half-open TCP connections. If a global catastrophe like that can happen once, it can happen again - which is why, in addition to the clearly negative privacy implications, Apple should give users who care a clear opt-out.
"Safely" is strong language that implies software digitally signed by Apple does not contain malware. In my experience, their system is more a sieve than the condom it purports to be.
By that definition, as convenience goes to zero, then availability, and therefore security goes to zero too.
You get a different dialog box with an option to open the file and this saves a lot of clicking.
Wow, this is a big TIL! Until now I thought all cases of "damaged" had to do with something like bad/incomplete build or wrong architecture. Now it seems like any of them could've been attempts to deliver malware from possibly infected hosts.