Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

This is a scary preview of Apple's vision of desktop computing (which we all anticipated with the App Store being brought over from the iPhone world to the desktop):

The safest place to find apps for your Mac is the Mac App Store. That’s because the developers who create them are known to Apple, and the apps are carefully reviewed before they’re accepted in the store.

As I've had no reason to upgrade my home PC from 10.6 to 10.7, EOL for 10.6 will probably be when I ditch the Mac and just dual-boot Linux and Windows. It's really amazing how much Apple has changed since the pre-OSX days.



I hope you realize that Debian and Ubuntu and most of the large distros already have this: Known, vetted packages, signed and trusted, distributed through a central database. Frankly, I think it's a great idea. People in general shouldn't be downloading and executing random binaries on their machines. I think it would be great if the major distros also refused to install unsigned binaries without explicitly being told to allow it.


With Debian and Ubuntu, there is no difficulty installing arbitrary unsigned packages, putting your own binaries on and running them, etc. There is a source that the community recommends, but that's all it is -- a recommendation.

That's not the case with OSX, as far as I can tell.


> With Debian and Ubuntu, there is no difficulty installing arbitrary unsigned packages, putting your own binaries on and running them, etc.

Changing a single setting in the Preferences app (once!) is "difficult" now?


Yes.

Defaults matter. Non-technical users don't know about this computer magic.


Defaults do indeed matter. I'd say the default they've picked is the right one for anyone who thinks computers are magic.


I actually think that the distros should be more aggressive about this, and do what OSX seems to be doing: Don't allow unsigned packages to be installed without a flipped switch. Why? Because anyone who can't figure out how to flip that switch shouldn't be installing unsigned binaries, in my opinion.

In regards to OSX, the argument seems to be that this is a step towards not even having the switch there, and yes, they may be headed that way which is unfortunate. I think that's a mistake that would end up biting them if they tried it, but maybe I'm naive. I still think being more aggressive in only allowing signed binaries by default is a good approach, even for open source systems.


I don't think that's a very good comparison. A project in the Mac world begins and ends its life as a .app. This effort by Apple means that the vast majority of users will only see "approved" software. In the Linux world, most software begins as a .tgz, and earns packagers as it becomes more popular.

There are only a few things really keeping a package out of the main Debain repositories: Being "non-free" (which takes it out of "main"), being clearly malicious, and not attracting enough interest to have a maintainer/packager.

I think we've seen with the iPhone that Apple has very, very different criteria. Further, Debian hosts something in the ballpark of 20,000 packages: I seriously doubt we'll ever see such diversity for the Mac, especially with their developer fees.

The other force driving me away is their refusal to accept GPL3 software. I don't like having to build things myself that every Linux distribution provides so easily.


Well, it's down to who decides that an app is trustworthy. In the open source world, this is done through vetting by the community, whereas in Apple's case they can afford to hire people to do it. I agree that the community approach is likely to be better, but I don't think the Apple approach is inherently evil, just inefficient.

The stated goals of Apple for gatekeeping apps are practically the same as signing packages in the distros: To protect unwary users from installing malicious or broken applications. I think that's a worthy goal.


> In the Linux world, most software begins as a .tgz, and earns packagers as it becomes more popular.

But _normal_ users, that is not-very-technical people using Linux as a desktop, _never_ see that tgz. They wouldn't even know how to install it.


In Debian and Ubuntu, i can easily add new signing keys for individual people. This way I can ensure all software distributed by ubuntu and from $PERSON is accepted. Can you do likewise with new OSX?


the apps are carefully reviewed

Carefully reviewed to ensure they don't upload your whole address book.


Don't get why parent was down-voted? Seems like legitimate criticism to me: How can they claim the software is "carefully reviewed" to "protect the user" but still allow seemingly dangerous app?


Tis a marketing approach to allow them more control.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: