Mountain Lion quietly includes app blacklist and security restrictions
red-sweater.com
red-sweater.com
It's "hidden" because it's almost certainly a hacky stop-gap. As far as I can tell, it isn't live updating or checking for new signatures, so the signatures are probably updated on a release basis as issues are found.
Conspiracy theorists: for Apple, this technique dates back to at least the eighties or so. At some time, Apple introduced a system error "Application has special memory requirements" that basically meant "Sorry, we cannot run Excel 2.2" (text and version may be of). Reason was that that Excel used some bits in pointers for data storage. The new OS or hardware started using those bits itself, so that version of Excel could not run on with it. So, the Finder refused to run that program.
The term is "kludge."
Though, in this case, the stop-gap is at least indefinite from Apple's perspective, since they have no plans to restore binary compatibility for badly-written or otherwise broken drivers and applications, and it's up to the third-party vendor whether to issue a free patch.
> Wow, they really don’t want me to open this app!
I can't really imagine why one would instantly jump to the first conclusion, and then after a kernel panic still believe it to be malice on the part of the operating system developer. The instant a kernel panic is thrown into the mix, you barely need to check the crash log to realize that there's something fundamentally incompatible.
I was nearly expecting a follow-up line to say "It looks like Apple is patching the VMware modules at runtime, to cause them to crash!"
> ... it’s worth considering whether they will be tempted to use these powers for less honorable goals.
In addition to the version blacklist described here, there's the much-bandied-about "killswitch" in the iOS app store. In the years since iPhoneOS 2.0, has Apple used it for less honourable goals than platform security?
Come to think of it, has Apple used it at all?
Given that Fusion 4.1.0 is blacklisted while 4.1.3 works fine on Mountain Lion, it's not entirely unreasonable to think that Apple purposefully disabled 4.1.0 to prevent users from virtualizing Snow Leopard against their will.
Not the conclusion I would have jumped to right off the bat, but I can see the train of thought.
Criminal Hacker gets Dev ID, makes malicious app, distributes said app, runs for months, then one day whamo! it does Nasty Shit. Apple blacklists the app and the Dev ID certs. Easier worm and virus control. At least until one of these rogue devs finds a privilege escalation bug that gets it out of the sandbox and also into more privileged execution.
It's not a magic bullet, but it'll be a good thing unless they abuse it. An example of Apple's track record in this regard would be GPL apps on the App Store - they'll pull the app from the store but I have yet to hear Apple 'remote wiping' someone's previously downloaded apps.
Tangentially, I'm a little miffed at spending $100 to get certificates to do Developer ID, but in the Grand Scheme of Business, it's just not that much money.
*I have flashbacks to 'The Net' - I shudder
That doesn't mean that I like the current state of these apps any more than you.
My understanding is that Gatekeeper signing is free.
The Apple employees that I am connected to were also surprised to find out that it wasn't free outside the Mac Dev program. A former Appler helping me dig around also noted that Apple never said it'd be "free."
If you can find somewhere Apple said it would be free, I'd love to dig deeper.
Also note this in my comment above: "...in the Grand Scheme of Business, it's just not that much money."
This is simply a mechanism for Apple to stay ahead of any worm-like activity and they decided to attach a barrier to entry ($99) and recoup a pittance while they're at it.
I'd also assume that Apple blacklists any certificate if the developer used some sort of fraudulent payment. I'd hope so, in fact.
Actually they won't "pull the app" by themselves.
At least in the one example I'm aware off, a minor contributor to a project (VLC) specifically _asked_ Apple to remove the app from the iOS app store, pissing on both the users wanting it AND the developers doing the porting for free and making the source code available for everyone, because it being on the app store didn't satisfy some GPL technicality.
[1] http://www.ilounge.com/index.php/news/comments/vlc-developer... [2] http://www.linkedin.com/in/remidenis
I guess all it takes is a misguided picking of licence in the beginning and a zealot that contributed somewhat (even marginally) to ruin it for all the other contributors who could care less about 100% enforcement. Maybe that explains why BSD and MIT style licences rule the roost when it comes to new projects on GitHub...
Even if Apple sticks with blocking the application entirely (which in this particular case they're probably right to do so, as it would cause a kernel panic) it would be nice to put something actionable in the dialog.
Before I opened the phone to try to find a fix, I wanted to resolve the issue with software. That because I knew it was a software and not a hardware issue.
Googling around I've found a fix. I had to jailbreak and SSH into the phone in order to delete a launch deamon. After downloading the app for the job, to my amusement, when i executed the app nothing happened.
I quickly fired up a terminal window so I could run the app. It ran. I could jailbreak the device, remove the service, and then the issue was gone.
So Apple is really blacklisting apps in Mountain Lion, not only to protect users. But to keep us from running things they don't like.
Lucky for us that we're hackers. ;)
Really. Perhaps you could point to the app on the openly viewable blacklist?
The blacklist can't really be called "quiet": On first boot after system upgrade, a dialog box pops up that tells you that incompatible software was moved to a special folder. The affected stuff is mostly kernel extensions that become incompatible.
On one hand, I love opening up the App Store on my MacBook and flipping through all the shiny icons in one central location that is safe and easy to use. On the other hand, I worry about Apple controlling the entire distribution channel for consumer software.
[0]http://www.intego.com/mac-security-blog/dl/How-the-Anti-Malw...
Most Browsers and BitTorrent clients are set to quarantine files that they create. A lot of keys for App Store categorization etc.
I'm not sure why I had to reinstall in the first place. Specifying "Allow software from ANYWHERE to run" did the trick. This might be off-putting to some.
This part is really interesting, that Apple is externally enforcing the quarantine bit rather than relying on the apps to set it.