August 10th, 2024

The Mac Is a Power Tool

The evolution of MacOS security features has led to stricter measures that may hinder power users, suggesting a need for balance between safety and functionality, influenced by the iPad's environment.

Read original articleLink Icon
The Mac Is a Power Tool

The article discusses the evolution of MacOS security features and their impact on power users. Historically, classic Mac OS allowed applications to run without restrictions, which, despite potential risks, did not lead to significant malware issues for users. However, the current MacOS has implemented stricter security measures, including sandboxing applications and requiring permissions for accessing sensitive data. While these protections are essential for less experienced users, they can hinder the functionality and efficiency of power users who need greater access to system resources. The author argues that there should be a balance between user safety and the ability for advanced users to utilize their systems effectively. He compares this to power tools, which can be dangerous but are necessary for skilled users. The article suggests that Apple is losing this balance, potentially due to the influence of the iPad's more restrictive environment. Ultimately, the author believes that users who require more robust anti-malware protections may be better suited to devices like the iPad rather than a Mac.

- The evolution of MacOS has led to stricter security measures that may hinder power users.

- Historically, classic Mac OS had minimal malware issues despite a lack of restrictions.

- A balance between user safety and functionality for advanced users is essential.

- The influence of the iPad's restrictive environment may be affecting MacOS security policies.

- Users needing more robust protections might be better served by iPads instead of Macs.

Link Icon 13 comments
By @sharkjacobs - 7 months
A lot of the time, when I agree with Gruber it’s grudgingly. With this it’s wholeheartedly.
By @roughly - 7 months
Early in my career I was working ops, and we got into a debate about a tool we were building - how much we should let people bypass some safeties we were putting in. A veteran colleague said "the fundamental requirements of my job are to do unsafe things," which stuck with me. For a lot of what we do, you cannot make a fully safe tool that's actually effective and usable. You need to trust your users when they tell you they know what they're doing.
By @jmclnx - 7 months
I do not know what to make of this.

> I want applications to be cryptographically signed by known developers and notarized by Apple by default

Not me, this describes a Walled Garden to a tee.

Power Tools mean flexibility, not locked down. The only real "power tools" out there are *BSD and Linux. With those systems I can do whatever I want without begging for permission from a commercial vendor or anyone else for that matter.

By @supportengineer - 7 months
There’s one power tool remaining, Linux
By @TacticalCoder - 7 months
> Such a laissez-faire approach to software privileges obviously wouldn’t fly today.

Funnily enough it kinda would work, again, today as most people now only ever need one app: a browser. I still need to install apps, but most people don't. So as far as the browser itself is the sandbox, the OS is fine: it runs nothing but the browser.

It's the reason I could switch my mother-in-law's laptop to a Chromebook: she's fine as long as she's got a browser.

By @nerdjon - 7 months
I will admit that the gatekeeper change is annoying. It’s already hidden under a menu with control click so I hope that change doesn’t hit retail.

But correct me if I am wrong, the weekly alerts is only for screen recording right? Realistically how many apps do you have with that permission? Given that it a highly sensitive permission since it can basically expose nearly anything else that isn’t in a password box… it seems fine?

Maybe make it 2 weeks or “smart” and taking into account how often the app is really using that permission.

But similar on my iPhone if I were to grant an app permission to read my contacts(I don’t, but still), I would want to know if it’s constantly doing that in the background.

Even if Mac has a notice at the top saying your screen is being monitored, I still think having this periodically confirm access again is a good thing.

As mentioned Apple does have to walk that line between power users and most users. Even as a power user why is a one week alert really going to interfere with my ability to use it as I wish?

To me the reality is there isn’t a solution here that appeases everyone. An app that wants unrestricted access will try to trick the user to follow a few steps to disable a safeguard. We see this all over iOS with so many apps trying to justify their tracking.

By @znpy - 7 months
> The Mac is a platform where you need to be able to shoot yourself in the foot.

This person yearns for Linux but hasn’t admitted such thing to themselves yet.

By @mediumsmart - 7 months
If I was a programmer or admin - GnuLinux. Just for gaming - windows. The Mac is what I call a Davinci Machine. Unrivaled.
By @ribs - 7 months
It’s a mass-market computer used by millions of people who don’t want to shoot themselves in the foot. People can be tricked into things, perhaps like turning off a “Bypass Mode”-like switch. I think this is a hard problem.
By @highwaylights - 7 months
I’ve been thinking more and more about this lately. I’m not sure I want macOS to be a power tool. I’m not sure I want Windows to be either - they have access to too much.

I want a VM for laissez-faire workspaces, and in those cases it makes sense for my workflows to use Linux (granted it might not for others).

This works out pretty well for me. I have my run-whatever-I-need environment isolated from my host, which means that environment doesn’t have access to emails and browser logins that I don’t really need on the VM.

Sure, the host should protect my data if the permissions are configured correctly etc., but I’m not about to give anything root access if I can help it there, whereas in a dedicated environment there’s less to worry about.

By @troupo - 7 months
--- start quote ---

The Mac is an expensive tool. On average, Mac costs more than iPad or iPhone. I dislike the idea that computing freedom belongs only to those who can afford it. That seems classist to me.

Gruber says, “Computers are such an essential part of the modern world — and almost everyone’s daily lives — that computers-that-work-like-computers aren’t for everyone.” I agree they’re essential, which is exactly why computers-that-work-like-computers ARE for everyone. Otherwise, it’s haves and have-nots.

--- end quote ---

https://mastodon.social/@lapcatsoftware/112939278677244969