When Sequoia eliminated the ability to override Gatekeeper by control-clicking, it became clear to me that Apple is now employing a frog boiling strategy towards their ultimate goal -- more control of the software you can run on their hardware.
When Sequoia eliminated the ability to override Gatekeeper by control-clicking, it became clear to me that Apple is now employing a frog boiling strategy towards their ultimate goal -- more control of the software you can run on their hardware.
Trying to get the program to work with our Mac users has become harder and harder. These are all internal developers.
Enabling developer mode and allowing Terminal execution isn't enough. Disabling the quarantine bit works - sometimes - but now we're getting automated nastygrams from corporate IT threatening to kick the laptops off the network. I'm exhausted. The emergency workaround, which I tell nobody about, is way less secure than if they just let us run our own software on our own computer.
Developers pay exorbitant amount of money for much lesser value, and the idea of putting your teammates at risk to stick it to apple is kind of sad bordering with negligence from a business POV.
The cost is far far higher than the price.
I develop and distribute few free apps for macOS, and building / notarising is never a problem.
In most cases, just involving account management makes the corporate case 10x more of a PITA. Doing things in a corporate environment is a different game altogether.
Yes, you need to put keys on the build server for the "Developer ID Application" (which is what you need to distribute apps outside of AppStore) signature to work.
You do not need to give any special access to anything else beyond that.
Anyway, it is indeed more difficult than cross-build for Darwin from linux and call it a day.
It is ugly: https://hearsum.ca/posts/history-of-code-signing-at-mozilla/
I do this professionally, I maintain macOS CI workers for my employer. Apple doesn't make it easy.
For your personal needs, you do not need to pay anything for building and using apps locally.
It's about setting a higher floor for malicious actors than "random botnet residential IP + a captcha solving service". It's about proving some semblance of identity through a card number and a transaction that goes through without a chargeback.
As the case upthread shows, there's plenty to dislike about a system that inhibits running code built for personal use. And it's obviously neither foolproof nor without collateral damage. Reasonable people can debate if it's worth it. But it still ought be acknowledged that the motivations are closer to the reason you have to identify yourself and pay a nominal fee to drive a vehicle on public roads.
Since this isn't true, no acknowledgement required, it doesn't need to be a "major" profit center to magically become a benevolent feature
In particular, the security boundaries are nonsensical. The whole model of "notarization" is that the developer of some software has convinced Apple that the software as a whole (not a specific running instance) is worthy of doing a specific thing to the system as a whole.
But this is almost useless. Should Facebook be allowed to do various things that can violate privacy and steal data? What if the app has a valid reason to sometimes do those things?
Or, more egregiously, consider something like VSCode. I run it, and the fancy Apple sandbox helpfully asks me if I want to grant access to "Documents." The answer is really "no! -- I want to grant access to the specific folders that I want this workspace to access", but MacOS isn't even close to being able to understand that. So instead, one needs to grant permission, at which point, the user is completely pwned, as VSCode is wildly insecure.
So no, I really don't believe that MacOS's security model makes its users meaningfully more secure. At best, the code signing scheme has some value for attribution after an attack occurs, but most attacks seem to involve stolen credentials, and I bet a bunch just hijack validly-notarized-but-insecure software a la the VSCode example.
Notarization does some minimal checks, but is mostly about attaching a real identity so that maliciousness has at least some real-world consequences. The most obvious being that you lose the ability to get more apps notarized.
Last time I tried setting up an Apple developer license inside a large corporation, one that they paid for and not tied to me or my credit card, it was also a nightmare.
And yes, it's also on principle.
Permission that can be revoked for any reason, including being compelled by someone with more power than Apple.
Once signed, binary will work forever, you only need active subscription when you need to re-sign / re-notarise.
Do you have any evidence that it happened in any different circumstances at least once?
https://developer.apple.com/documentation/security/code-sign...
https://developer.apple.com/documentation/security/notarizin...
There are dedicated sections of the developer web forums:
https://developer.apple.com/forums/topics/code-signing-topic
https://developer.apple.com/forums/topics/code-signing-topic...
...and there's an apple developer support person, Quinn, who appears to be heavily if not solely dedicated to helping developers do binary signing/notarization/stapling correctly.
They have written a slew of Tech Notes about signing and notarization. Main TN is at https://developer.apple.com/documentation/technotes/tn3125-i...
Quinn also has their email address in their sig so people can just reach out via email without even needing an Apple account, or if they prefer more confidentiality.
I mean, come on.
Maybe because I'm using Electron framework which makes things more complicated, but I don't really understand why there's is a difference between different types of certificates (Developer ID, Apple distribution, macOS distribution) and I had to guess which one to use everytime I set it up.
Also why is notorization a completely different process from code signing, and requires completely different set of credentials from it. Seems odd to me.
Because they do completely different things. Signing is a proof that you were the one to write and package that software; notarisation is an online security check for malware. If I recall, you still sign but do not notarise when distributing to the Mac App Store.
Or maybe simpler, why can't Apple just do code sign and notarization with one single cli call, with one set of credentials?
Google Play does this under the hook, I don't even think about it. iOS is similar, Transponder app does everything in one go.
Edit: I haven't tested it yet, but it does seem that you can sign an executable with your own certificate (self-signed or internal CA-issued) however you can't notarize it. Right now, notarization is only required for certain kinds of Apple-issued developer certificates, but that may change in the future.
btw, for those who don’t want to search, Quinn’s signature states:
“ Quinn “The Eskimo!” @ Developer Technical Support @ Apple let myEmail = "eskimo" + "1" + "@" + "apple.com"
I once really urgently needed `nmap` to do some production debugging ASAP. Unfortunately, the security tools would flag this immediately on my machine, as I knew this from previous experiments. Solution - compile my own binary from sources, then quickly rename it. I assume that this "workaround" was totally fine for sec department. At least production got fixed and money kept flowing.
You were denied the tools to get your job done. You've put yourself at risk by applying an unapproved workaround.
Never ever do this (unless you hold substantial shares). Let the company's bottom line take the fall. If that's the only thing they care about, that's your only way to make the problem visible.
But the underlying SRE culture here is that, if you know what you are doing and have a functioning brain of a responsible person, you'd be forgiven a jump over the fence, if it means putting out a fire on the other side of it. We aren't kids.
I don’t get this at all.
I’d much prefer a team of highly empowered and highly responsible engineers than impotent engineers who need hand holding in case they make a mistake.
Engineers _should_ have leeway in how they resolve issues. As I read, though, you have a company policy which explicitly disallows the action you needed to take to fix the problem (if I misread, my apologies). Getting the stakeholders involved is the responsible thing to do when policies need to be broken.
Ideally, the way this kind of situation gets handled should be documented as part of a break-glass policy, so there’s no ambiguity. If that’s not the case, though, the business should get to decide, alongside the policy maker (e.g.: security), whether that policy should be broken as part of an emergency fix, and how to remediate the policy drift after the crisis.
If you’re all tight enough that you’re allowed to make these kinds of decisions in the heat of the moment, that’s great, but it should be agreed upon, and documented, beforehand.
By the way, I'm still burnt out. This work is stressful. Don't let it take away what's already scarce for you.
For binary patching: codesign --force --deep -s - <file> (no developer ID required, "ad-hoc signing" is just updating a few hashes here and there). Note that you should otherwise not use codesign as it is the job of the linker to do it.
Last time we did this I had to spend a week explaining to management that Macs could actually run software other than PowerPoint and it was necessary for our job.
The local workaround that we use is to just spin up a Linux VM and program devices from there. The less legal workaround is using WebUSB and I'm afraid to even tell the necessary people how I did it, because it's sitting out on a public-facing server.
Unfortunately, I still have to deal with macOS for work due to corporate policies.
I spent a day or so hacking around with kanata[0], which is a kernel level keyboard remapping tool, that lets you define keyboard mapping layers in a similar way you might with QMK firmware. When I press the 'super/win/cmd' it activates a layer which maps certain sequences to their control equivalents, so I can create tabs, close windows, copy and paste (and many more) like my macOS muscle memory wants to do. Other super key sequences (like Super-L for lock desktop or Super-Tab for window cycling) are unchanged. Furthermore, when I hit the control or meta/alt/option key, it activates a layer where Emacs editing keys are emulated using the Gnome equivalents. For example, C-a and C-e are mapped to home/end, etc.
The only problem is, this is not the behavior I want in terminals or in GNU/Emacs itself. So I installed a Gnome shell extension[1] that exports information about the active window state to a DBUS endpoint. That let me write a small python daemon (managed by a systemd user service) which wakes up whenever the active window changes. Based on this info, I send a message to the TCP server that kanata (also managed by a systemd user service) provides for remote control to switch to the appropriate layer.
After doing this, and tweaking my Gnome setup for another day or so, I am just as comfortable on my Linux machine as I was on my Mac. My main applications are Emacs, Firefox, Mattermost, Slack, ChatGPT, Discord, Kitty, and Steam. My Linux box was previously my Windows gaming box (don't get me started about frog boiling on Windows) and I'm amazed that I can play all my favorite titles (Manor Lords, Hell Let Loose, Foundation, Arma Reforager) on Linux with Proton.
I know it's mostly muscle memory, but macOS shortcuts just seem sane and consistent and that has been one of the biggest frustrations when trying to switch. I found toshy[0] which does something similar - did you try that? The goal is purely macOS key remappings in Linux, so a much smaller scope than kanata.
[0]: https://toshy.app
I have a Kinesis 360 keyboard, and my config[0] probably won't work for other keyboards, but it can give you a starting point for your own config.
[0]: https://gitlab.com/spudlyo/dotfiles/-/blob/master/kanata/.co...
But here's my (unpopular) take as a GNOME user and using Fedora immutable distros + flatpaks -- I suspect Linux is going to go in a broadly similar direction. Maybe not soon (even flatpaks aren't universally acclaimed), but sometime.
I don't even mind that they've introduced a level on the totem pole that's above root. But on my computer, -I- should be the one at that level, not Apple.
the issue seems to be that you still believe this?
However, less corporate distros that mostly just ship built upstream software as-is since they don't have to support it for long periods (think Arch, Fedora, Void, etc) don't have that problem, so I expect we'll continue seeing them use traditional packages.
Ubuntu does the exact same thing with their snap repository, the Firefox apt package from Ubuntu is fake. At least Flatpak is a community-led project unlike snap.
You can limit the file system permissions of the app, like giving only access to downloads, so that if/when there’s a sandbox leak you’re fine. You can also disable various things, like webcam or mic, this way.
In addition, you can get perpetual updates to the latest version of your browser even on old, stable distros like Debian.
Linux is pretty diverse, there are still distributions out there that haven't adopted systemd.
It’s like criticism of the quality of Google search dropping. It has absolutely tanked, but it’s not because the algorithm is worse, it’s because the internet has grown orders of magnitude and most of it uses the same hyper aggressive SEO optimisation, such that the signal to noise ratio is far worse than ever before.
"Those who refuse to give up essential Liberty to purchase temporary Safety deserve to have to deal with the GNOME desktop user experience."
I miss macOS sometimes.
Kagi lets me completely block specific domains. If Google cared about quality they’d let you do the same.
We know this because the emails came out in discovery for one of the antitrust suits.
Suddenly the users file hierarchy started wherever the Home folder was located and it became an island of user controlled environment surrounded by complexity of computer operating systems.
The result I found overall well thought out but when the desktop became just a folder I felt the Mac moved from it’s simplicity embracing the complexity that was offered by windows.
It's amazing the rose tinted glasses people have about the original Macintosh environment. It was insanely janky and (unless you were ruthlessly conservative) insanely unstable by today's standards. By version 10.5 (Leopard) the modern UNIX-based MacOS was unequivocally superior to Classic MacOS in every metric other than nostalgia.
I also believe that the simplicity could have security as performant. The real advantage of the Unix layer is compatibility that the Macintosh was missing.
Are you trying to say that it’s possible for a system to be both simple and secure? Absolutely that’s the case, but with a trade-off — either it needs to restrict the user’s freedom, or be fully disconnected from the outside world.
The threats in the world are real and the internet doesn't help. I 100% agree that a network connection needs to be kept at a distance to make things simpler.
I think the power of language used to describe a system is where simplicity begins.
What I'm working on is creating a crisp line of delineation between "local" and "public" networks.
If by default after is on the "local" network auto-discovery is secure. If things are explicitly needed a user can publish them through physical manipulation to publish to the outside world.
The outside world can now be described using classic Users and Groups which is cultural easy to understand.
I'm trying to create an environment that focuses on making those 2 things plus a third element simple to understand and physically manipulatable.
The freedom I'm looking for is available on the "local" network. The "public" network is where our data is interchanged with the outside world based on our publishing. I don't expect people to interact with this layer much. I expect people to configure it for whatever institution/organization/government.
Most of the complexity I see in computing these days is market drive demand for eyeballs/clicks/...
I can't believe I even have to say this out loud. Look up enshittification.
Actively depleting the good-will they accumulated over the years definitely makes it worse. It's that harder to give the benefit of the doubt to a company also showing the middle finger to their Devs.
Giving priority to AdSense sites, fucking around with content lengths (famously penalising short stay sites), killing advanced search options. That's just thinking about it for 10s, but to me most of it is totally of Google's making.
If Linux, you'll have to be more specific, because users don't use Linux. They use Android, Ubuntu, Gnome, pop!os, redhat etc.
sudo spctl —-master-disable
Are most people better off with Apple defaults?
And it’s not because the problem is “difficult”. It’s because for 20 years it has been claimed that this will be the “year of Linux on the Desktop” and it’s never been good enough for most people.
The second part of your post is incoherent to me, I can't tell what you're trying to say.
The problem with Linux is that, while it’s very good, it’s different.
Nobody actually cares how intuitive something is, at least not in absolute. People will still say Windows is intuitive. Pretty much nothing in Windows, from the registry to COM to IIS to setting/control panel/computer management, is intuitive. But they know how to use it and are used to that particular brand of buggy inconsistency.
Linux desktops have been high quality for a long time now. The reality is you, and others, measure quality as “how much is it like windows” or “how much of it is like macOS”. When that’s your metric, Linux will always come up short, just by definition.
Can I get a high performance Linux laptop with good battery life, fast graphics, that runs cool and silent?
What's high performance for you?
I can certainly get a Framework (Fedora and Ubuntu officially supported), throw my prefered Bluefin-Framework image in and get working
Battery life around 7 hours is the average I see reported, Fast/Silent will depend on the model, but I don't see the issue really Upgradability and easeness of battery replacement are a plus
I just picked framework because they were first to come to mind, but I think Dell has a nice Linux story, Tuxedo also comes to mind
These are the typical reviews I see around the Framework
https://community.frame.work/t/fw-16-review-the-good-the-bad...
Poor battery life, heavy, runs hot, poor build quality, bad speakers, and decent but not great graphics.
And yes, everything works. On bleeding edge 2 month old hardware.
I even use thunderbolt 4 to connect my external displays and peripherals. Not only does it work, but it’s pleasant. KDE has a settings panel for thunderbolt. I can even change my monitor brightness in KDE settings. No OSD required!
But wait, there’s more! I’m running 2 1440p monitors at 240hz and the system never even hiccups.
But wait, there’s more more! The battery settings are really advanced so I can change the power profile, maximum charge, everything.
The only thing I’m unsure about in your comment is “low latency audio”. It seems low latency to me, but I’m not an audio engineer.
This should not be an issue. I have hardware that varies a lot and I literally buy random wifi dongles for $1, $4, $5, Amazon, AliExpress, etc. and they have all just worked on first plugin. I can easily take my phone and tether it to my PC using USB-C and it appears in my Gnome network list and just starts using it for Internet.
> how well will it handle low latency audio
Pretty well you can use OBS to verify this. There are plenty of settings if you want to tune that.
> My graphics hardware?
Just ignore Nvidia and move on. Sure they might figure it out one day, I gave up a decade ago and I use Intel integrated or AMD dedicated for GPUs. Nvidia does "work" for most purposes but it will cause you a headache eventually and those are not worth $400 to me.
> How well will it handle power management?
I enjoy the basic controls that Gnome provides that give me a simple way to basically say "go all out" or "save some battery" etc. There are finer grain controls available and I have used commands in the past to push crappy hardware to it's limits before I chucked it (old Intel iGPUs)
> Can I get a high performance Linux laptop with good battery life, fast graphics, that runs cool and silent?
You can get ones that are specifically marketed for this purpose. Tuxedo is one that specializes in this and obviously System76 also do. These have a higher price point than a regular Dell system, which IMO is the better option in some ways. Dell sells more systems and has more users and it will "just work". They sold Linux systems for years and still do I believe.
Regarding "running silent" this is a gripe I have, not that it runs loud but some laptops have custom RGB crap and sometimes in Linux I don't have access to the extra functionality to customize my lighting or manually set my fans to ramp up etc. There are projects that aim to do this, but I have not looked into them beyond the most basic `fancontrol` built in command.
I think once you expand the scope to "most people" it might become impossible to say what the correct answer for that large of a group is. In the past their value add might have been more compelling and their feature lock not as draconian. It appears some people think that has changed over time.
Hard disagree. Audio mixing is not difficult[1]. The Linux kernel guys were right - it does not belong in the kernel. The userspace story however, has been a complete shitshow for decades. I think Pipewire mostly fixed that? Not sure, sometimes I still have to log out and back in to fix audio.
The funniest part? It's been working in the BSDs all along. I recommend reading the source of sndiod[1].
[1]: <https://cvsweb.openbsd.org/src/usr.bin/sndiod/>
What's even worse? Probably systemd. I try not to hold a strong opinion - I tolerate it, the way I tolerate traffic when taking a walk. The technical issue however is several orders of magnitude simpler - again, the BSDs come to mind, but you can also write a complete PID1 program in about 20 lines of straightforward C[2]. I don't mind the commands being unfamiliar (they're already all different in almost every OS family); it's that the entire package is dreadfully large in scope, opaque, and I find it more difficult to interact with than anything else in this landscape.
[2]: <https://ewontfix.com/14/>
However, it's worth noting that audio experts doing high grade mixing in production are using these systems quite effectively and have been for a long time. It's similar to Blender in that regard with it always having the "guts" of doing great things, but only the experts that knew the correct spells to cast were able to use it effectively before the UI/UX was improved with 2.x and later I believe.
Predefined value on current macOS's Gatekeeper is "move to Bin" instead of OK. Other option is Done - which cancels opening action. If you want to bypass that, you need to go to system settings > privacy & security and manually allow particular app there.
Who know what later updated will bring.
To run a non-motorized app requires you to open a separate app, navigate to the security section and select that you want to authorize the app to run.
Apple does not have any desire to make distribution of non-notarized binaries commercially viable.
And we've seen this change across all browsers. There no longer is a "continue" prompt for TLS issues. The result is, way fewer maintained sites go months with an expired certificate.