Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Gruber was telling that the Apple ID was going to be free. It isn't. It requires a Mac Developer account as far as I could understand it.

When I was 15 I wrote a Taskbar dialer for Windows 9x and later NT (this was in the modem days. Of course I haven't updated it in ages and the only reason my old webpage is still there is because I found it by accident in an old backup, but here is a google search for it: https://www.google.com/search?ie=UTF-8&q=RasInTask).

I published that on the various download pages and it was good enough to even be featured in dead-tree publications.

Back then I had no permission to use a computer ("they make you stupid" was my parents argument) and certainly no credit card to pay anybody to do development - and even then, as a minor I would probably never have gotten that certificate.

With this rule in place I would never have been able to publish that dialer. I would never have felt how it is to make something that others can use and find useful. I would never have ended up where I am today.

Does this stop malware? Does this stop fraudulent call centers? Does this stop malicious people from telling people to turn it off and then still installing the malware? No.

Does it stop people like me from ever getting to their career of their dreams? Likely.

I might be an old fart, but this is far from acceptable.



Hold on, XCode is free (without a developer login) you could install that and write the app.

You can then publish it on websites exactly as you did and those who choose the appropriate security setting can run it. You have a smaller audience yes, but you can still do what you did.

And while this doesn't stop Malware, it does raise the bar a little higher.

Out of interest how would you feel about it if developer licenses were free for students?


>"You can then publish it on websites exactly as you did and those who choose the appropriate security setting can run it."

The need for a non-default security setting in order to run the software is a pretty big difference.

Requiring a developer license to work with the default security settings - thereby allowing Apple to unilaterally delete your application from your customer's computers without recourse - may only raise the bar a bit.

However, it is an entirely different development ecosystem from the one described. Microsoft couldn't delete your application or block customer's access to it arbitrarily back in the 90's.

If iOS is a precedent, the probability of Apple changing the terms of service in regards to their developer agreement in ways which have adverse effects on the saleability and distribution of existing applications is significant.


> Requiring a developer license to work with the default security settings

Gruber's article says signing will be free. No paid developer program membership required.


TFA says the default security setting DOES run any signed app. The two non-default settings are tighter (App Store only) and looser (any app).


Out of interest how would you feel about it if developer licenses were free for students?

I would be much happier (to the effect of actually seeing more good than bad in this restriction) if getting that ID was a matter of filling out a form an passing a turing test - so, for example, if any apple ID could be used to get a signing certificate, that would be much better.

(edit: this is not about the money. It's about they way of payment (minors don't have credit cards) and the required paperwork that, among other things, require you to be an adult)


That's interesting. My feeling is that the problem her is with the Apple Developer network rather than the functionality - I think the functionality just highlights the problem.

Personally I'd like to see the price on Developer licenses dropped and made free for full time or part time students. I think it would make commercial and PR sense for Apple too - show that they are developer friendly and make the Mac attractive as the machine of choice for the next generation of programmers (who will then also be a shoe in on coding iOS apps).


Historically, Apple has rarely provided free software, hardware or services to the education market. It appears to me that their strategy since the Apple II days has generally been to monetize the education industry to the highest level the market will allow. They may offer small student discounts off of list price on college campus bookstores, but I suspect it increases sales more than enough to raise profits.


I'm willing to bet that Apple is going to allow free certificates without having to pay a cent when Mountain Lion launches; Apple already did this for Safari Extensions, for example. (Safari Extensions must be signed, but anyone can request for a cert.)

It's also interesting that Apple is using the word "the _new_ Developer ID" in their developer site[1].

[1]: https://developer.apple.com/technologies/mountain-lion/


A license is $99. If you can afford a Mac to develop on your can certainly afford a $99 license.

They reason the have the fee is to keep out people who aren't serious about development. If they didn't have it for example the forums would be overrun with people who just signed up to get the latest OS beta complaining about bugs (this is already a problem at $99).

People can still develop and distribute apps without ever signing up with Apple. This restriction is a good protection step for users imo.


You shouldn't have to prove that you're "serious about development" by paying money to write and distribute software. How many developers started as hobbyists?

Charging $100 just to be capricious is not a good move and is certainly not a good omen for OS 10.9 "Tabby" wherein you can be almost certain they will remove the option to run unsigned software (for your own protection, of course! You don't want to pay Apple $100? What are you, poor? The computer cost $1000! $generic_strawman_argument!)


You don't need to pay ANY money to write software for the Mac. Xcode is free. You don't need to pay any money to distribute software for the Mac. Distribute it through your own website. You need to pay to sell through the Mac App Store. I also presume you need to pay if you want it signed. Well that's a privilege. It helps you prove to potential customers your app is safe. You benefit from it so you should have to pay for it.

If you develop an app with the purpose of selling it on the Mac App Store for profit $100 should not be a problem for you.

If you want to distribute it yourself, go ahead. Apple is not charging you.


Well you can solve that by charging for access to the beta program surely?


Yes, but Apple doesn't want to allow people to pay to get into a Beta. They want only devs taking part. A fee to enter the dev program seems like the best solution to me. Honestly they should increase it to $199 to help weed out the app spammers.


There's enough money in app spamming that it would have to be a lot higher than that to put them off.

As a rule the people who act like arseholes have at least as much money as those who don't, I don't think it's going to put them off.

I agree a nominal fee is reasonable as it puts another barrier in their way (you can check for duplicate memberships off the same card for instance so they have to get multiple cards) but the actual financial amount isn't a major barrier I don't think.


That's a good point. It would help get the beta testers out of the forums though :) Every time a new iOS version starts testing the forums are overrun with people who have x bug and don't understand what beta means. I wish there was a way for Apple to prevent a lot of the App Store spam. I wouldn't be against them becoming more curated (i.e. only apps they deem useful and quality get it). Or have a special section in the store labeled 'crap'.


I'm not sure that charging more is the solution, there's no shortage of people with more money than sense!

I don't see why Apple don't invite the developers of high-ranking iOS apps to an early-access program in order to keep their best apps up to date, and not invite anybody else to the beta.


I don't see why Apple don't invite the developers of high-ranking iOS apps to an early-access program in order to keep their best apps up to date, and not invite anybody else to the beta.

Because every publisher, not just the "blessed" ones, has software in the store that could be negatively impacted by a new iOS release's changed APIs. And every publisher has potential use cases for new features Apple adds in a new iOS revision.

Apple ships major iOS releases at the same time as shipping the newest iOS device. They want a customer to unwrap their new device and have free roam of the store to download/buy as much as they can. They want the software to use the new features in iOS and they don't want their customers downloading crap that is broken.

And as a developer who isn't even close to "high-ranking" (My one paid iOS app maybe pulls in $50 on a good month) it's still not fair to me for someone to one-star my app and say "doesn't work on iOS 6" even when I've had no chance to test it before general release.


An Apple ID is indeed free. I've had an Apple ID for downloading Xcode for years now. At the moment the only way to get an app signing key is by purchasing a $99 license (which also gets you publishing privileges in the App Store) but it is extremely likely that in the future getting a signing key will be completely free and will not require a $99 license fee. It won't get you App Store submittal and won't get you publishing on the App Store, but I think that is fair.


Back then I had no permission to use a computer ("they make you stupid" was my parents argument) and certainly no credit card to pay anybody to do development - and even then, as a minor I would probably never have gotten that certificate.

The computer isn't free either. And you can always build and distribute without the ID or the certificate. This is just for distribution through the App Store or to users that have it set to only allow signed apps.

Does this stop malware? Does this stop fraudulent call centers? Does this stop malicious people from telling people to turn it off and then still installing the malware? No.

"No" to the last question, maybe. On the other hand, it stops tons of malware. Signed binaries is considered one of the most successful anti-malware strategies by security experts. Are you saying otherwise?

Does it stop people like me from ever getting to their career of their dreams? Likely.

Well, if you are that easily discouraged, then maybe that career wasn't really for you, anyway.

You present an edge case ("I need to build and distribute my software to OS X users AND I want those users to not only allow signed apps BECAUSE I can't fork $100 dollars for a developer certificate").

If that kind of thing discourages you from "getting to the career of your dreams" what to say about the hundreds of thousands of dollars and years of toil needed to become a doctor, a lawyer, not to mention the hard learning needed to become a professional programmer.


> On the other hand, it stops tons of malware. Signed binaries is considered one of the most successful anti-malware strategies by security experts. Are you saying otherwise?

As you've decided to pick anonymous security experts, I thought I'd chip in. I don't know if I'd call myself an expert but I've over a decade in industry breaking systems, fixing software and booting out bad guys, I'm speaking at BlackHat EU next month and I co-founded a security conference so I guess that means I'm not a complete security chump. I can categorically tell you that signed binaries are only part of a strategy, and not necessarily the best one at that. If your goal is to increase the cost of exploitation then signing can help, but so can a decent access control model (into which signing becomes a part thereof).

To put it another way, it's possible to defeat applocker (windows binary signing), iOS code signing on iOS 5.0.1, the XBox and Xbox 360's code signing restrictions, the PS3's code signing restrictions, and more recently, an analysis of RSA keys showed that between 2 and 4 out of every thousand keys are insecure due to weak randomness[1].

The bottom line is that code signing, like placebos only work if you believe them to unless they're backed up by something more solid to augment them and they form a stronger coherent strategy.

At this stage all code signing settings will do is encourage developers to get Apple IDs and for customers to use the App store as they know "it's safe". Even though we know it doesn't mean anything[2] to the end user in reality. The real thing that Apple will do is further on the line when they decide to make it so that you can only run signed apps (and this is at least the direction apple are taking) through their app store.

Your edge case point applies to countless open source developers, including those that worked on the original FreeBSD code that went into Darwin. Apple are of course, under the licences they've inheritied allowed to implement code signing, but please don't think this is an anti-malware measure, it isn't. It's about control of distribution. Anyone that wants to bypass code signing on an Apple product will find a way to do it.

[1] - http://www.theregister.co.uk/2012/02/16/crypto_security/ [2] - http://thenextweb.com/insider/2012/02/15/what-ios-apps-are-g...


"code signing […] only work if […] they're backed up by something more solid to augment them and they form a stronger coherent strategy."

You mean things like sandboxing and blacklisting? Or do you think this is not (an attempt at) a coherent strategy?

"At this stage all code signing settings will do is encourage developers to get Apple IDs and for customers to use the App store"

It also (even if ever so slightly) decreases the attack surface. It is harder to infect executables if the OS checks the hash of the code every time it is run. Finally, it gives Apple a handle for disabling malware, once it has detected it. That will not prevent malware from infecting systems, but it can make it less likely that machines will keep getting infected for years after the time.


The computer isn't free either. And you can always build and distribute without the ID or the certificate. This is just for distribution through the App Store or to users that have it set to only allow signed apps.

The latter is the default. So for other people to use this application I wrote as a minor, my users would have to change the setting.

Well, if you are that easily discouraged, then maybe that career wasn't really for you, anyway.

This would not have stopped me, but imagine what kind of an ego-boost it is for a 15 years old sufferer of heavy bullying due to overall geekyness to see his home-grown application not just be used by other people but actually getting mentioned in paper publications.

Nowadays I couldn't even get /permission/ to try because these various developer programs require you to be an adult due to various organizational issues.

Honestly, without that ego boost when it happened, I don't know where I would stand today, if at all.

But this is my story. I have a feeling that I'm losing objectivity here due to heavy emotional involvement. I'll be quiet in this topic from now on and just turn that switch off for myself, hoping that there will be a switch to turn off in the future.


Users don't even have to change a setting. They Ctrl-click, and select "Open". One time. On the first launch of the unsigned app. And it's done.


The latter is the default. So for other people to use this application I wrote as a minor, my users would have to change the setting.

Yeah, but should users configure their systems to the distribution convenience of some developers?

Or should Apple keep signed apps forever away from OS X for the same reason?

Or should they introduce them, but make unsafe apps the default, and thus render them useless for non security minded people?

All of those options seem a little strange to me.

Nowadays I couldn't even get /permission/ to try because these various developer programs require you to be an adult due to various organizational issues.

Yes, but consider some other things:

a) nowadays computers are a dime a dozen and more kids have access to them than ever.

b) nowadays there are tons of compilers, programming environments, most of them given away for free and/or open sourced.

c) nowadays a kid can make a web app and reach millions of people worldwide. There are tons of ways to put it up even for free.

d) nowadays there are even kids making iPhone/iPad/Android apps, and some have reached hundreds of thousands of users.

e) the sound/graphics/processing capabilities of modern machines were unheard of in those times.

f) High Level languages like Python/Ruby/Javascript trump anything available at the old times for kids (mostly stuff like Basic, Logo, etc). Especially in the libraries department.


>Back then I had no permission to use a computer ("they make you stupid" was my parents argument) and certainly no credit card to pay anybody to do development - and even then, as a minor I would probably never have gotten that certificate.

Yes but things change. Old fart or not, you're into technology, we all have to realize things change!


And he's saying that this change is for the worse. He has made substantive arguments, and you have responded with a useless platitude.


$100 does not stop anyone from realizing their dreams. Teenagers know how to make extra cash. $100 is less than 2 days work at a minimum wage job.

I would much rather have teenagers work to be able to pay $100 to distribute signed applications than make it free for anyone (malware makers) to distribute signed apps.

The trade off isn't even close here. It's free to develop the app, and even distribute it outside of the app store. If you want to go into the app store, you'll need $100, which helps keep software more secure for millions of people.


Some teenagers cannot legally work.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: