Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Any user who doesn't know what Gatekeeper's purpose is (and how to disable it) probably stand to benefit from keeping it on. I imagine these people are the ones most at risk for downloading malware.

I don't necessarily disagree (I have a mom too ;)), but: (1) there are many trustable open source programs that are unsigned because their developers cannot afford or do not want to pay $99 per year for an Apple developer account; (2) OS X could display a warning that the user can override.

What happens now is that people will Google for the error to install some legitimate software, find a blog post that describes how to disable Gatekeeper, and switch of Gatekeeper permanently.



> OS X could display a warning that the user can override.

If it had an overridable dialog straight from double-click, people will just see this as an annoyance and end up clicking the "Yeah, whatever!" button without skipping a beat.

The way it is, it's actually overridable per application with "right click->open" which gives you the overridable warning you wish for, with OSX actually remembering the overriding and you can subsequently double-click on the now whitelisted app. This whitelisting apparently survives even Sparkle updating.

It appears that it's just convoluted enough for people dangerous to themselves not to shoot themselves in the foot, yet convenient enough for the informed user to act easily. And ironically the solution is actually written in the non-overridable dialog, yet the kind of people not reading dialogs is precisely the risky kind. I'd venture it's made so on purpose.


The way it is, it's actually overridable per application with "right click->open"

As I said in my original comment ;).

This whitelisting apparently survives even Sparkle updating.

Sparkle probably never sets the com.apple.quarantine attribute and if the application does not have LSFileQuarantineEnabled set in its Info.plist, its downloaded files are not put in quarantaine. Applications that do not have that extended attribute are never checked.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: