Comment by LoganDark
5 hours ago
This is Apple we're talking about. What may be the bare minimum for you was a lot of work for them. Work they could have passed up and we would've all had to simply deal with it. They do that all the time, and there's nothing we can do about it. But here they didn't. Here they did "the bare minimum" to allow custom operating systems on their newer hardware. That should be commended. Yes, we should celebrate that hardware we purchase and own still allows us to run code we wrote. Because the alternative is that it could not. Their non-macOS devices already don't.
To be perfectly clear, Apple is like a lifeline to a lot of people. They are one of the last bastions of quality in the hardware and software world. This is why it's such a disappointment that they've been faltering lately: we had high expectations of them, which hasn't been quite so true for the rest of the industry for a while. So it is a big deal that hidden gems like this continue to crop up from them: it is a sign that some of their core values still remain. And I really hope the new CEO will bring back some of what they lost after Steve Jobs.
Being able to run “custom” code is the default state of computers, and doesn’t require additional effort on the part of the manufacturer. How do you think they got their own code on there? Apple has just not spent effort in the opposite direction to lock it down in this case. That’s not something to celebrate, we should demand it as the bare minimum, ideally via the law.
It literally takes effort to reach Apple's level of platform security while simultaneously having escape hatches designed to allow custom code without compromising the trust in the first-party code. Even simple, arbitrary decisions like having the secure boot state be per-operating-system rather than platform-wide take effort. Keep in mind Apple designed everything from the ground up including the silicon, so they did not just pull a part off the shelf that already can execute any code and then lock it down, they took their already very locked-down iPhone/iPad SoCs and specifically re-engineered the chain of trust to have these escape hatches while preserving the trust in macOS. Very careful engineering and not the "default state" of anything.
There are a lot of shortcuts they could have taken to leave us with less freedom and they did not take those shortcuts. For that, I am grateful.