apps that have been signed by a recognized distributor may also damage your computer; the signature isn't proof against errors or intentional maliciousness. So that wording is ridiculous.
And 'It can't be trusted.' Really? That's ridiculous too. It's entirely possible it could be trusted. There's lots of software that Apple hasn't signed which is trusted and has been for decades.
This dialog just confirms suspicions. The intent is clearly and explicitly to throw FUD on, wall off and eliminate non-Apple-approved software.
> apps that have been signed by a recognized distributor may also damage your computer; the signature isn't proof against errors or intentional maliciousness. So that wording is ridiculous.
Right, that's a way better wording. "Oh, and signed apps could harm your computer too and also can't be trusted. Guess you're fucked then!"
I wonder why I leave with the impression that you are just looking for things to nitpick because you don't like Apple as opposed to offering a genuinely helpful suggestion?
> This dialog just confirms suspicions. The intent is clearly and explicitly to throw FUD on, wall off and eliminate non-Apple-approved software.
...Well, duh. Did you encounter anyone with a different impression? Also, what suspicions? Is it surprising to you that Apple is on a path to disallow unsigned code?
This is the way forward people. Assuming malware will stop being a problem or users will suddenly stop screwing things up are the complete pipe dreams here. With the addition of the signed but not reviewed category in Mountain Lion, I'm happy. It's the best of both worlds, and a much better solution than no centralized distribution at all like Windows, or a Wild West style distribution platform like the Android Market.
> The best of both worlds is having a centralized distribution of verified software but still be able to install unverified software, in my opinion.
Can an average user download a random app and be hit with malware on default settings with that model? Then it isn't the best of both worlds at all, it's the same old "blame the stupid user" broken strategy we've been using forever.
At least on my system, installing an external package does present a warning (not as alarmist as Apple's, of course) that installing from repositories doesn't.
So yes, Linux really does have the best approach here.
You can add a repo though. You add a repo you thought was trustworthy or a repo becomes compromised, the end.
> So yes, Linux really does have the best approach here.
Nope, just another "blame the idiot user" excuse. Feel free to try again though.
Get over it. You're not going to alter computing with your Hacker News comment. The only real way to stop malware is through code signing. This isn't a new concept or something that Apple came up with, it has always been the case and it's about time we stopped pussyfooting around it.
You stop supporting them. They haven't shown any indication of doing that and I'm not a paranoid conspiracy theorist like much of the HN community.
Rules like that are for the App Store to enforce, hence why they are part of the "App Store Submission Guidelines", it's not the job of code signing. They have specifically cited "malware developers" and only them when giving examples of devs that could have their certs revoked. If they stick by that, I'm happy.
I'm sorry, did you really criticize my logic on the grounds that it would not fit into a dialog box? The fact is, the dialog box is intentionally deceptive.
"This is the way forward people." Actually, the way forward is the direction we've already been going on; where there are no gatekeepers interrupting their collection of punitive tolls on software only long enough to lie about the software they don't collect their 30% from.
> I'm sorry, did you really criticize my logic on the grounds that it would not fit into a dialog box?
No, I didn't. I don't even know what you are referring to with this. I criticized it because it was a completely unhelpful response that would only serve to confuse users even more.
Are you joking? You're going to sit there with a straight face and argue that Apple should tell users that signed apps are a credible threat? Jesus.
> The fact is, the dialog box is intentionally deceptive.
No, it isn't. The app is untrustworthy because it is unsigned, and they are using a "signed = trustworthy" model. It's as clear as day and completely factual.
> Actually, the way forward is the direction we've already been going on.
No, it isn't. The way forward is simplifying interaction with computers. Arguing otherwise is completely idiotic, take any other example of technology in the world and notice that it advanced faster and more efficiently than ever before when it was simplified to the point of the masses being comfortable with it.
> where there are no gatekeepers interrupting their collection of punitive tolls on software only long enough to lie about the software they don't collect their 30% from.
They aren't lying, and they aren't imposing this on "apps they don't collect their 30% from" that is actually a flat out lie and you know it. Signed apps don't have to be distributed through the MAS. They can be distributed through the web, not result in that dialogue box, and not have to pay 30%.
And 'It can't be trusted.' Really? That's ridiculous too. It's entirely possible it could be trusted. There's lots of software that Apple hasn't signed which is trusted and has been for decades.
This dialog just confirms suspicions. The intent is clearly and explicitly to throw FUD on, wall off and eliminate non-Apple-approved software.