Mac developers: Gatekeeper is a concern, but still gives power users control

Apple's next version of its desktop operating system, OS X Mountain Lion , promises developers access to hundreds of new APIs to enable new functionality for their apps. While developers we spoke to seem mildly excited about the new functionality, their immediate focus was on the implications of Apple's new Gatekeeper security feature.

Gatekeeper allows users to tightly  control which sources apps can be installed from . By default, Gatekeeper will allow apps from the Mac App Store to be installed, as well as other apps that have been signed using a special certificate given to registered OS X developers. Users can also opt to allow apps from any source—the current default on Lion. The latter would remain an option for "power users" who are confident in the source of their apps even if they are not signed, Apple told Ars.

But regardless of the options, Gatekeeper remains a hot topic of conversation among developers, as noted by Rogue Amoeba's Paul Kafasis. "If Apple uses a light touch, there's little downside here. As long as getting to be an 'identified developer' is not onerous for developers, Gatekeeper should provide more security for users, while not hindering developers in any noticeable way."

How it works

Currently, any developer who signs up for Apple's Mac Developer Program and pays the $99 per year fee will get a code signing certificate. All apps sold through the Mac App Store require code signing, and these apps have gone through Apple's review process. For apps sold outside the Mac App Store, code signing is purely optional, though the developers we spoke to say many have begun signing their code already, even for apps distributed independently.

(The developers at Panic have a pretty good in-depth explanation of code signing if you're interested in learning more.)

Effectively, what users are choosing from is the installation of only Mac App Store apps, all signed apps, or all apps regardless of signing. At this stage, Gatekeeper provides users with a warning when installing certain apps depending on the settings, which may give users pause before installing apps from untrusted sources. It also gives them a way to verify that apps haven't been modified between a developer releasing the code and the app getting to a user's machine.

Family Security Settings - News


Mac developers: Gatekeeper is a concern, but still gives power users control
Mac developers: Gatekeeper is a concern, but still gives power users control

"I think it is a pretty good idea to have it configurable, so that users like me can still download anything they want," security researcher Charlie Miller told Ars, "while we can lock down the computers of our family members!



Gatekeeper Slams the Door on Mac Malware Epidemics

Up-to-date Macs are reasonably secure against direct network attacks, and when vulnerabilities do crop up, a combination of anti-exploitation features makes it a lot harder for the bad guys (at least on Mac OS X 10.7 Lion). So for physical and network



'Reverse smudge engineering' foils Android unlock security

For that reason, I recommend pattern-swipers head over to Android's security settings and uncheck the default "make pattern visible" option. Bray recommends people stop swiping altogether and concludes that the numeric code option is the best for him:



DATA SECURITY: Don't blow it when you travel
DATA SECURITY: Don't blow it when you travel

It can broadcast your home address, the addresses of friends and family, and your travel history. If someone wanted to target you for a kidnapping or other nefarious act, your GPS could be his best friend. In a 2011 speech, the Global Security



Small glitch in armored vehicle doomed US agents

When Zapata needed it most, the Suburban's elaborate armoring was rendered worthless by a consumer-friendly automatic setting useful for family vacations and hurried commuters but not for US agents driving through a red zone in Mexico. The Feb.




Family Security Settings - Bookshelf

Security, a new framework for analysis

Security, a new framework for analysis

Sikkerhedsanalysen er en opfølgning af tidligere litteratur om emnet af forskerne Buzan og Ole Wæver, eks.

The family

The family

A chilling study of the 1969 Tate-Labianca murders offers a close-up profile of Charles Manson and his followers, discussing the origins and influence of Manson and his family, the crimes they committed, the mysteries that persist ...

Introduction to Security

Introduction to Security

This is Butterworth-Heinemann's best-selling security text of all time, an essential reference for all security professionals. * Significantly expanded chapters on computer issues, cargo, homeland security and terrorism * New chapter on ...

The Family

The Family

The author of The Godfather takes readers back four hundred years to a fifteenth-century Italy populated by corrupt popes and despotic families to introduce the first of the mafia families, Rodrigo Borgia, Pope Alexander VI, and his ...

Family

Family

Spanning the years just before and after the Civil War, this saga of an African-American family centers on Always, a resourceful woman born into slavery, and her mother Chlora, as they endure and prevail