Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

You seem to be engaging in some revisionist history of Gatekeeper. The original concern was that it would be turned to MAS apps only by default, which it wasn't (and still isn't in Mavericks). By default the only thing you need is a free developer certificate to distribute apps outside the MAS (or to tell your users to right click to open, which bypasses the restriction).

Whether or not Apple does something in the future is a separate question, but accusing them of something they haven't done (despite several opportunities) appears more than a little biased.

Update: I am 100% incorrect about the developer certificate being free. You must be a member of the $99/yr Mac dev program to get one. So score one for "raising the walled garden" and I will gladly eat this humble pie.



It’s not free actually, you have to sign up to the Mac Developer Program which costs $99 / year. I think it used to be free in the past (the certificate, not the membership) but now it isn’t.


I didn't believe you so I just checked and now it's time to eat crow! You are absolutely right. I will update the original to note that my statement is completely wrong.


Correct, IIRC in the keynote they said it would be free but that turned out to, ahem, not be the case.


And beyond the fee; I would love Gatekeeper if I could manage the certificates myself! I don't want the choice to be "Apple's feudal system" or "wild fucking west" exclusively.

IMO they are being complete shitbirds about app signing and I am actually surprised to hear Mavericks is not more restrictive. I fully expect them to lock it down at some point. (I've resolved to use only FOSS in the future and not buy Apple.)

Also I want really fine-grained permissions that I can disable to make system calls return fake information a la Cyanogen Mod.


You can manage the certs yourself. Absolutely nothing to prevent adding your own cert to keychain and signing an app with it.


seriously?

then does that mean all the CA's in my system keychain can sign apps and have them run without the "risky click" dialog?


Nope, CA needs to be explicitly added to gatekeeper. http://strangetheorists.tumblr.com/post/30515713765/using-ow...


This is great! Thanks ptomato




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: