Hacker Timesnew | past | comments | ask | show | jobs | submitlogin

As a developer, I'd rather they build it and sign it for me. The key signing stuff always seems difficult.


As a user, I'd rather you build your code and sign it for me. Enabling a third-party to alter your programs taking away the trust I would have in you.


But you are already trusting Apple to manufacture your device and the operating system the app runs on top of.


Hypothetically, signing power could be useful if an organization wanted to attribute malicious code to somebody else.


I would hate that. How could ever be sure Apple (or anyone else) hasn’t added/modified my code without consent?

I wouldn’t ever stake my reputation on signed code which hasn’t been signed by myself!


Apple owns the hardware, OS and distribution, they can do whatever they want. Your signature is neither here nor there.

The only thing it can do do is show Apple you compiled the code.

There's no way you as the dev or the end user can verify the installed software really originated from you.


Yeah, it's not like Apple is in charge of the entire operating system running the app and verifying said signatures. Having them sign your app is definitely what gives them too much power.




Consider applying for YC's Summer 2026 batch! Applications are open till May 4

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: