Reminds me of all the de-crufting you've always needed to do when you install Windows. Looks like we've gotten to the point on macOS too, where you need to run third party scripts on a new OS installation to gain back control of your system resources and remove unwanted crapware.
Automatically downloading AI models into disk space with no user-facing way to turn it off is especially hostile considering Apple as vendor of both the OS and the hardware is the same entity that overcharges for non-upgradable SSD storage in their machines.
That doesn’t work unless you’re actually able to offload stuff from disk, which is only the case when you store stuff in your iCloud Drive / photos / etc.
Case in point: the AI models can’t be offloaded to iCloud.
It’s not actually serial locked, you can replace SSDs by desoldering and resoldering a NAND chip. But basically their SSD controller is integrated into the M-series chips (mostly because cheaper, less connectors to manufacture). But it’s a very specialized process
I think most consumers would happily pay a bit extra for these controllers if it meant that they could manually upgrade their SSDs. I can’t help but have the feeling that it’s also quite convenient for Apple that all this stuff is effectively non-replaceable / upgradable.
I don’t think the benefits are the same as with their RAM being part of their SoC, as that gives them real speed improvements, right?
> it’s also quite convenient for Apple that all this stuff is effectively non-replaceable / upgradable
On the other hand, I’m happily banging away on my ca. 2020 M1 MacBook Pro. It just got a warranty service, free to me, that replaced the screen. It will probably get replaced around 2030. That simply isn’t the norm with the alternatives.
The hypothesis that this is self serving isn’t supported by the evidence. Instead it’s more parsimonious to conclude that this is Apple being Apple with pushing design to the limit when it comes to executing a vision. User-upgradable parts have not been part of that vision since Jobs returned.
> User-upgradable parts have not been part of that vision since Jobs returned
Steve Jobs literally got up on stage and proudly showed off the PowerMac G3 with a side door you could hinge down to open up the machine as it was running.
It was once Jony Ive got more power that everything went to pot. The first Macs with soldered-in storage were released after Jobs' death.
I've had good luck with AppleCare and warranty service, and most of my Macbook's have lasted well.
On the other hand my sons 2021 Mac Mini M1 with an estimated < 20% writes remaining on the SSD is not looking very cool. In fact, rather disappointing and the computer will be junk soon due to the SSD only.
My understanding is that the controller is integrated into the SoC.
You can actually replace the storage on Apple desktops but it’s a bit of a pain and isn’t as cheap as m.2 2280 drives.
I don’t really know why Apple does this when their solution doesn’t seem to offer an obvious advantage. They aren’t faster than existing solutions or anything like that.
Vendor lock-in increases their profit margins. If people could purchase a 128GB Mac mini and install their own 2TB drives they wouldn't make as much money.
Note that before the Mac mini socketed SSDs, Retina MacBook Pros had socketed SSDs as well. They were not standard M.2 either though, you had to get specific aftermarket parts from the likes of OWC
To gain the same effect as one that is soldered down, while giving themselves a simpler portfolio of assemblies and a cheaper FRU to swap in the event of failure.
I'm not sure if you're being sarcastic, but what you're calling "good, holistic customer service" is more commonly described as "inventing a problem and then selling you the solution".
Google is doing the same on Android - there's no native tool to search for large images and videos by date. There's a Purchase Google Cloud Storage type of header that pops up when you start to get full, and you can delete whatever is quick to find or remember to delete, like WhatsApp media, which you find through an annoying directory structure with a broken tool. It's terrible.
Meanwhile, other people are complaining about companies making you rely on cloud compute for AI. The exciting thing about Apple Intelligence is the prospect of writing apps with the assumption that it exists on everyone’s computer.
Apple Intelligence, for better or worse, runs on every Apple silicon Mac.
Any machine which can run macOs 27 can run the local models. Some machines may run better local models if they gave 12+GB of ram, but I don't think it's accurate to say that Apple Intelligence is not supported universally.
In this context we are talking about macOS 27. If your app requires 27, then it can correctly assume every machine will work.
there's a third option youre missing here that people are consistent on: AI shpuld be opt in and nothing prevents opt in being default. AI isnt reliable or universally useful enough to include it defacto.
Many arbitrary features can be turned off: I haven't turned on Siri on a phone for many years, because the utility was minimal vs the annoyance of errors in voice activation. Taking very significant space in your drive is just as important. I can uninstall Pages and Garage Band. I should be able to uninstall apple intelligence
Like it or not, Siri is one of the features of macOS and has been for a long time. It's not just some arbitrary AI model that Apple decided to store on your disk.
“Siri” has existed for a long time, yes. Apple Intelligence, not so much. It really is just an arbitrary AI model, since I’ve had Siri for a decade and not needed whatever this extra 13GB model is.
You've had a previous version of Siri for a decade that didn't do what the current version of Siri does. Whether you use it or not is not germane to whether the model is justified – it's what Siri needs to do what Apple wants it to do.
People have been doing the same thing with Cortana on Windows for ages. "Debloating" tools don't primarily target OEM add-ons like free trials of this or that; they very much target Windows components.
Fully functional feature consuming multiple gigabytes of storage and has questionable functional value. Maybe people don't want bloated AI crap on their desktops?
I’m not making any judgement on whether you should or should not like the feature.
I’m stating that the Windows problem was very different. Your machine would be loaded up with software for various vendors that the manufacturer did deals with to lower the price of the machine. They were all trials.
> I’m stating that the Windows problem was very different. [...] They were all trials.
Except it isn't and they weren't. MS Windows never came with trials, it came with shortcuts. OEMs bundled with their Windows image more of their (crap) full software than trials.
And to this day debloating tools are tasked with removing full MS bundled (or auto installed) software like Teams, Outlook, DevHome, Copilot, M365, Recall, etc. So exactly the same problem as Apple Intelligence. Whether you consider it useful is up to you. Whether it's bundled is up to Apple.
> [On Windows] Your machine would be loaded up with software for various vendors that the manufacturer did deals with to lower the price of the machine.
So the only difference is that the vendor here is Apple itself. Honestly, not seeing much difference.
5% is huge. And the way app bundles work on macOS, tons and tons of disk space gets burned up for each application relative to on an OS like Linux distros, so each GB doesn't go as far in the first place.
It's also not the full extent of disk usage by built-in apps which aren't removable by normal means on macOS. An empty macOS installation is like 35 GB. NixOS is not known for being particularly space efficient, but 30-40 GB is how much space I use on it for the OS and all applications, including a ton of developer tools, on my graphical systems. For the base OS with a full fat desktop environment, most Linux distros have you looking at less than 10 GB. So this comes as a massive increase on an OS that already burns a ton of disk space before you even get to touch it.
This is going to shock you I suspect, it seems to be something many here fail to consider in any number of circumstances: You don't represent a majority of anything. A majority of people buying Macs, a majority of people they market to, a majority of who they design for, a majority of who they product test against. In fact I'd venture to guess that you like many here represent a vocal portion of a tiny minority that are almost impossible to please without the sort of full customization of hardware and software you want. It's much easier to neglect that small market in favor of the one that prints them money, and I'm always baffled that so many don't understand that.
People here misunderstand just how different they are to the norm. "I want x, y, z to be free so I can modify it!" Most people buying Apple products don't, hell most people buying any phone doesn't want that, they want a smartphone that works out of the box and never fails to be a smartphone. The walled garden is largely a feature and not a bug, it's just not a feature you want, just like the aesthetics, social factors, ease of use, etc don't matter to you as much as function.
> a majority of people they market to, a majority of who they design for, a majority of who they product test against
As if Apple is always right and knows what their users want. Sure they are more often than other companies but stuff like the touchbar and Siri itself for that matter prove that they do in fact make mistakes.
Wrong. 12GB is potentially 9.4% of your disk. At the very least, the original M1 MacBook Air (perhaps others) could be purchased with 128GB of storage.
Apple's AI and harnesses are trash and a complete waste of space
Also suggesting that sacrificing 1/20 of your disk space is NBD is crazy. I have to prune space on my drive all the time because macs ship with the least amount of disk space that apple imagines they can get away with as possible.
Are you arguing that the icons did not occupy a scarce resource that could have been used for other things? Or that the value is so obvious it we worth it?
Yes, but it’s death by a thousand cuts. I encourage you to see how much BS space is taken up by iMovie or Live Photos or whatever on your iPhone. If every team at Apple wants their percentage you end up with less.
Bruh the entire Mac OS used to fit in 20 GB and nothing they have added since has meaningfully improved my life, though some has made it more difficult.
Trial versions are installed by the OEMs so that's not a Windows problem.
Microsoft has given you the tools (Group Policy) for the last 25+ years to customize most of this.
My last install of Windows 11 was shockingly frustrating but with a little patience and discipline it's customized to Windows 7 levels of sanity using nothing but out of the box tools. Shockingly, it works better than writing angry blog posts about it.
They have to give you a choice because they have surly enterprise customers who would be upset otherwise.
It is a Windows problem because Microsoft allowed OEMs to do it and when you bought a computer, it included Windows and from the end user perspective Windows thus included this software.
> Microsoft has given you the tools (Group Policy) for the last 25+ years to customize most of this.
Most people including me don’t know what this is and more importantly they just don’t care. The frame of reference is “I buy (vendor) laptop and Windows comes with all this stupid stuff I have to uninstall”. It is never “I bought Windows and I just use the Group Policy to do XYZ, and then….”.
> It is a Windows problem because Microsoft allowed OEMs to do it and when you bought a computer
No, it is not. It's still an OEM problem and you can go with another vendor (Framework for example) that doesn't do that.
Actually in this case Microsoft does a better thing than Apple because you can actually choose as a consumer which vendor to use for your HW.
> Microsoft has given you the tools (Group Policy) for the last 25+ years to customize most of this.
Morally, why should Home users have to pay a $70 upgrade (or whatever it is) to the company extorting them with forced-on crap they didn't originally have and don't want?
I currently have alternative versions of these tools. I would rather run the latest qwen model or SOTA models than whatever outdated model Apple wants me to use.
I don't need a more bloated operating system or greater resource usage for things I don't want, use, or need. i'd prefer a calendar app that doesn't suck, and an OS that doesn't decrease performance by 5-15% on every new upgrade for slightly older machines
It's the same reason IDEs have been largely supplanted by plugin-based editors & discrete toolchains. Integrating everything the user might want wastes lots of resources and includes things the user will never want.
On Windows there are lots of fully features features/applications people turn off. It's not all trial versions and it's disingenuous to pretend it's just that.
Recently switched to KDE on a linux laptop (600 USD lenovo) and stopped using my macbook (m1 16" pro).
Speakers, touchpad and battery life are inferior. Speakers are OK after installing EasyEffects and I don't use the touchpad while programming. And battery life is close enough
Cachyos with KDE is 10x better than MacOS. So it doesn't make sense to use macbooks for programming anymore IMO.
You can't even see the update download speed or progress percentage on MacOS, and have to approve 3 times to run a downloaded program, brew is terrible in terms of performance etc. etc. etc.
> Speakers, touchpad and battery life are inferior.
I suppose it depends upon the model, but I find my Lenovo Yoga's touchpad vastly superior to my MacBook Pro's touchpad. Tracking is fine on both, yet I'm having trouble trouble with the MacBook Pro consistently handling clicks. Granted, that is probably a software thing. As an added bonus, the Yoga has a touch screen which folds back, both of which are nice to have. (Agreed on the Mac speakers being significantly better though.)
> Cachyos with KDE is 10x better than MacOS.
That is subjective. I definitely agree with you, but a lot of people won't. Then again, I have been using Linux for about 30 years so modern macOS feels limiting and there is very little I can do about it.
I use both macOS and Linux (NixOS + gnome/niri) regularly. When everything is working properly--and, to be clear, I'm talking about the macOS side--I see almost no difference between the two operating systems. I'm on a ThinkPad on one side and an M2 Macbook Pro on the other. The only meaningful difference not attributable to something like different screen size is that Apple displays are damn good, and their speakers are otherworldly.
I was running Asahi/NixOS on a Macbook Air for a long time, and that experience was also top notch--only battery life was a few percentage points worse on NixOS--but the aarch64 software situation and emulation experience were just not there. I expect they've improved a bit since.
If someone would make a quality laptop that doesn't look like a Honda street racer and has excellent audio, I'd be very happy.
Interesting. Why do you call out KDE? Does it add to the experience specifically for you?
I usually use XMonad, but then I nearly do everything in the command line, and I don't like to move my windows around via mouse. (Though XMonad supports that, too.)
XMonad works for me, but I wouldn't call it out specifically as contributing to the experience.
> You can't even see the update download speed or progress percentage on MacOS, [...]
What program are you talking about? You can customise eg Firefox on Mac, just like anywhere else, with extensions to look however you want.
> [...] brew is terrible in terms of performance [...]
I'm trying to fix at least brew's Python performance a bit:
I used to use XMonad (now on Hyprland) and feel that the tiling window manager experience you can get on Linux doesn't have an equivalent on macos. KDE is solid but yeah it's plain jane.
Aerospace is very good. I'm not some tiling pro but it's been working perfectly for me for a year or so. Such an improvement over just using spaces on macos.
I have been using KDE for 4-5 years on desktop by now and didn't have any big issues with it so far. I was able to solve every single issue I had with it using a web search or an LLM in a couple minutes.
Only major issue I had was because of cachyos (I think) or just some LLM commands I ran that broke my sound output so I had to reinstall the OS. I probably had more but was using other OS like EndeavorOS/Manjaro before and don't think it was related to KDE.
Also I just like the UI of it and can find any setting I want easily.
> What program are you talking about? You can customise eg Firefox on Mac, just like anywhere else, with extensions to look however you want.
I mean the Software Update thing that updates the OS itself. I also had issues like ghost updates for xcode tools with it (updates come even after I uninstall xcode tools).
> I'm trying to fix at least brew's Python performance a bit:
For the future, it shouldn't be necessary to reinstall Linux just to fix a sound card. Pipewire et. al are a bit of a mess and sprinkle config files in /etc and your home dir. If it happens again start with deleting those and doing a restart.
Battery life optimization on Lenovos often involves installing and activating the correct GPU kernel module. My battery life on my P53 improved measurably after doing this, though installing new kernels involved a small build step. Are you just running with all the defaults?
I just installed cachyos normally and didn't do any tweak for GPU. The laptop just has an amd CPU and doesn't have a GPU. Do need a specific GPU kernel module for this?
With AMD, most GPUs including the integrated ones will just default to the `amdgpu` module which is maintained by AMD themselves. You pretty much have the best possible experience on Linux right now.
I can't speak from personal experience since my only laptop is an Intel Framework 13 with no dGPU, but there'll be two other main cases both involving Nvidia that tend to bite people.
1. "Gaming" laptops usually with integrated Intel GPU + Nvidia discrete GPU. Not sure what advancements have been made in power management, there. I know there's some incantations one can put in .desktop files to prefer the discrete GPU for like, games, but not much more I can speak to.
2. General fun involving the fact that Nvidia's "gold-standard" drivers are not mainlined in the kernel, but maybe the fact that they are "open source"* means at some point there'll be parity with them. I think that is the goal of Red Hat's Nova driver in development.
* these days, the GPUs got complicated enough they have management processors on them that can actually run most of the complicated algorithms via a firmware blob. So the current open-source drivers basically bridge the gap between the kernel's various subsystems and that little processor to work the magic.
On another note, Intel Xe/i915 have been pretty good, I've used both for integrated GPUs and an Arc Alchemist-generation discrete card of theirs. The framework 13 12th gen intel GPU struggled at the start with a lot of hangs but within a few months of launch, some smart cookies at Intel managed to fix various bugs and it was smooth sailing from there, with the exception of thermals just being in a rough spot on that generation.
The single thing I had in macOS I can't replicate in Linux is Preview. Other than that, literally everything is better on this side. I expected to have a bad adaptation period, but the experience has truly caught up.
Or a server version. I have an M1 Mac mini as my home server and it really feels like I'm fighting the fact that it's a desktop OS with a GUI and full of components that really, really, really can't deal with being run on a headless system. Not much fun when your super efficient ARM processor suddenly uses 100% CPU for 6 days straight because WindowServer and CoreAudio are having a panic attack due to being unable to find any outputs.
And so much useless crap you can't turn off without disabling SIP, which it doesn't feel like you're meant to, because who knows what daemon will bring down the entire system when another it expects to be there isn't…
> Or a server version. I have an M1 Mac mini as my home server and it really feels like I'm fighting the fact that it's a desktop OS with a GUI and full of components that really, really, really can't deal with being run on a headless system. Not much fun when your super efficient ARM processor suddenly uses 100% CPU for 6 days straight because WindowServer and CoreAudio are having a panic attack due to being unable to find any outputs.
In theory I'd prefer a MacBook Neo as a Plex server over my current cheapo Acer laptop with an Alder Lake-N CPU, for lower power draw and better hardware encoding, but in practice, I don't really want to try that with macOS instead of Debian.
Apple is going down the same path as Microsoft only at a slower pace and a decade behind. I fear they will turn OSX into something like Win 11 but with slightly better design in the next decade.
I also realized that I still call it OSX even though it is macOS nowadays.
Apple Intelligence and even more so Siri isnt worth the disk space. Regular user of chatGPT's Voice/Conversational AI (while driving) and comparably the new Siri is training wheels Voice AI. You can not have a seamless, back and forth conversation with it, so I wont call it Conversational AI.
Now you may ask who talks to AI? Well this dork does in time I bet more will. Especially, for giving me directions like "That new sub shop is across the street from your favorite McDonalds." No need to fiddle with a phone or look at a screen just drive to a familiar place. I believe talking to AI is safer while driving then us on our phones or messing with screens.
> Now you may ask who talks to AI? Well this dork does in time I bet more will. Especially, for giving me directions like "That new sub shop is across the street from your favorite McDonalds." No need to fiddle with a phone or look at a screen just drive to a familiar place. I believe talking to AI is safer while driving then us on our phones or messing with screens.
I've been driving for some decades, and probably still have some decades remaining, and these are just never scenarios I've needed, or will ever need. When I get in my car, if I don't know how to get to my destination, I set it on my nav, and then I drive there. My phone stays in my pocket. I never need to use my phone or mess with my screen to find some unknown destination mid-trip.
That's cool everyone is different and I have used my phone in my car since my first iPhone for streaming music and following Google map directions. Now personally myself I dont have to look at my phone as I am now just talking something similar to another person in the car - one who knows it all.
Spotlight search has sucked from Day 1 of OSX. You need to use Find Any File [0] or some equivalent tool if you want to search the actual file system without being limited by Spotlight's never-properly-updated "index."
The functionality of Find Any File was built in to Mac OS 9 and earlier. It was rock-solid reliable. So of course Apple removed it and now to get reliable search you have to use a third-party tool. Or 'find' in the Terminal.
The new spotlight search replaced what I previously used, made it function worse for what I used it for, and uses 30GiB of already very scarce disk space.
For many users, it is a strict downgrade that was forced on them against their consent.
How was it "against their consent?" The Siri AI / Apple Intelligence feature required a user to explicitly enable it. It didn't just get enabled for you.
I know this because I just explicitly enabled it, and now I have the new Spotlight search. I didn't have it before I enabled it.
No, this is downloaded and installed upon installation of MacOS 27. The 30 GiB of "Apple Intelligence" is sitting on my disk against my consent. I've even taken pains to do all of the hacks (save for the novel one in this repo) to disable Siri AI.
I made my own “pseudo spotlight” and mapped it to ⌘-Space specifically for this. It just goes against old fashioned locate/updatedb, but with a very quick check against /Applications first + running the search query through bc and if it’s valid syntax, showing the math result.
They did, and it's a matter of time they'll do it again, but that was then, now we have lot's of options for distros and desktops, and what about the private sector? Win11 is in shambles, macOS becoming more and more a cloud terminal you rent...
Lots of Linux options is actually a bad thing for most people. They want just one that does something reasonable. Right now I can't name one to bet on, not even Linux Mint cause of the whole XOrg vs Wayland thing.
What do you mean by macOS being rented? It's been the same for about a decade, still not forcing me to update like Windows does on my spare PC running Win10 (well did until I told Claude to rip that out lol). And yeah Win11 is terrible, not even an option.
Maybe this just how winning looks like? Apple won but still needs to keep increasing the profits and the stock price. We can expect enshittification to follow since Apple already did exceptionally well with their products therefore the only way forward is to milk users harder and hype the stock with the latest trends. Every winner must walk this path, nothing to do with Apple and that’s why it looks similar to previous winners.
I think this applies across the industry. All the easy innovations have been innovated, most people own a computer or several, and they get what they want out of it. Enshittification is desperation - businesses can't accept ups and downs, they only need ups, forever. So they will go to increasingly desperate lengths to juice more profits out of the same customer base and dress themselves up to the investors to show that they still got it. We can safely expect most big publicly traded tech companies to go this way earlier or later.
Vista had an undeserved bad rep IMO, it was an important 1.0 milestone for many new technologies and improvements especially in the security model. It effectively was a beta of Windows 7, with 7 being Microsoft's "Snow Leopard".
Windows 11 still ships with the installer from Vista.
I remember the OSX animated wallpaper update (that updated lighting as the time of day changed or something) eating up like 10-15% of my macbook air's small drive. After removal they would re-add themselves every update as important protected system files.
True that, win11debloat is 'mandatory' nowadays.
The time that OS makers competed with each other with features users actually wanted is long gone, alas..
This is why Linux is now making more serious momentum. Even a long term 'Microsoftie' like myself is now standing on the brink of making the leap. Just a bit more Steam compatibility first please...
Mandatory for what? I run stock Win11 for the most part, haven’t have had any real issues with it. I think I disabled/modified a few mouse hotspots and key combos, and that’s been about it. Sure during major updates there’s the “buy our shit” rigmarole, but at this point I just click through and then forget about it for another month or two. Annoying yes, but compared to actual annoyances in my life…I just can’t be bothered to care or get mad, to be honest.
I got an old disk with a win10 installation on it. It lasted only three days. It was because of all the pinging from notifications and all the CTA buttons (like Sign in to Onedrive in the settings). It felt like a minefield where a click can blow your whole setup.
I wipe the whole thing and installed Fedora.
I could tolerate windows if I needed a particular set of software on it, but no way that I could use it as a daily driver.
I no longer have a Mac as I’ve moved over to Linux, but my iOS device leaves me very frustrated that I can no longer disable this AI stuff with a simple toggle.
It seems insane given that Apple’s competitors (Microsoft, Firefox, probably others) moved toward a global AI switch to make the choice easy for their customers.
You can indeed disable it on ios and ipados. Turn off siri and change the language to the one that does not match your phone language and the models will be removed.
> change the language to the one that does not match your phone language
You do realize how ridiculous that is as a "solution", right? It's good if it works, but you can't possibly think that this is anything other than user-hostile
This is simply not true. Things like "writing tools" were moved out of the global siri checkbox and enabled by default, and now require you to use screen time content restrictions or modify settings in individual apps to turn off these features.
Sadly not updating the OS is very bad from a security perspective. Though it's frustrating that Apple rarely provides any sort of "security fix only" updates, and to fix security issues you just have to install all the new things at once.
My experience has been that they do provide those updates, but they intentionally make it hard to notice compared to getting the major version updates that are available for the OS. I distinctly remember a new junior engineer out of college joining my team back in maybe 2022, seeing there were security updates, and then not noticing the button saying something like "more updates" to be able to get them without updating to the latest major version of MacOS.
More recently, at the end of August, by the dates on my screenshots on my work laptop (the only Apple device I use) I took screenshots because I was incredulous of the sheer audacity of the UI shown for updating from MacOS 15.7.7 to 15.7.9 along with, in the words of the update UI, "1 more" update. When I clicked the button to view all of the available updates, it showed three available updates, which were, in order, MacOS 26.6.2 (which was checked), MacOS 15.7.9 (which was unchecked), and Safari 26.6.1 (which was checked). They literally previewed the only update that was not checked despite not even sorting it at the top of the list of updates available to install. I have absolutely no clue what would have happened if I clicked the "Update now" button next to the prompt for 15.7.9 rather than the identically-styled-to-non-link-element text for viewing the full set of updates, but at absolute best it would have just done something entirely different than what I'd get from the default options when viewing the expanded list, and it seems far more likely that it would have just also done the default options of the expanded view and updated to a completely different version that it put next to the update button.
on MacOS they provide security fixes for two years for unsupported OSes (after that the only remaining security protection is Gatekeeper/Notarization). On iOS you generally get no security fixes unless the vulnerability is really bad
AFAIK Apple has no published policy. Their last several macOS releases have received 3 years of security fixes.
iOS now seems to get 5 years of security updates, but only for devices that can't upgrade to newer iOS versions - so iOS versions that don't strand any devices get cut off early. e.g. iOS 15 received 3 updates in 2026, but iOS 17 hasn't been updated since 2025.
I recently sold a nine year old iPad running iOS 17 that is still getting security updates (17.7.11 a few months ago). Even iOS 15 (released 2021) got a security update in May.
I believe if you have a much older iDevice that no longer supports the latest OS, they will keep releasing security updates for that device for a long time, which is good on them. But if you have a newer device, after awhile the only way to get security updates is a major version upgrade. You luck out if your device happens to be old enough not support to newer iOS versions.
It's interesting to see more customisation tools appearing for macOS, as just a few years ago I was looking for ways to strip down the OS (CI related), and while such info was widely available in the Windows world, to the point that customised "distros" are available, it was nearly nonexistent for macOS; only the Hackintosh community had some useful articles on how things worked.
Could the rise of LLMs and vibe-coding have motivated people who otherwise wouldn't bother?
It’s hard to strip it down these days as the OS image and its core, immutable filesystem cannot be edited. Admittedly this helps keep idiots from destroying their filesystem and also blocks many malware attacks on the system, but, for example. I don’t believe you can delete the chess program.
and its core, immutable filesystem cannot be edited
That's a half-truth at best; I can just open the disk image in a hex editor if nothing else understands the format.
Hackintoshers have figured out how to add/modify drivers etc. It's certainly not without obstacles, but that's still very far from "impossible". If I remember correctly, you need to re-snapshot the FS and tell the bootloader to boot from it.
(And necessarily, ignoring the countless cries of "it can't be done" was how I was able to accomplish my goal... I knew that it was possible since I could edit any bit of the FS; figuring out which files I could remove and patch was the hard and undocumented part.)
The entire system is signed and verified at boot. Any change to a macOS system outside of /Users, /Applications, and whatever else the OS lets you edit can't really be edited without disabling System Integrity Protection (which isn't recommended)
This is one of those things where you have to ask yourself "how do you get it so wrong?". I get the idea of protecting from malware/self-harm, but to not allow removal of such a pointless app is just befuddling. At least Microsoft trying to say that Explorer was core to the OS, but a chess app? I never did buy into Explorer being core until the day I accidentally pasted an URL into File Explorer's path and it rendered the webpage. I don't understand why someone thought that was necessary to allow to happen, but there it was, core to the OS.
I think it’s because all those apps use core technologies so their bundle size is tiny. You hide them and never think about them (like the old windows media player). Most of windows optional features are very much in your face all the time.
Not that the are core technologies, more like they use whatever default libraries (Frameworks in Apple parlance) that are already there. Just like no one bothered to remove paint or wordpad in the old days (even with only 20gb of hdd)
The sealing of the filesystem can be disabled trivially, though, via a command line tool that Apple ships with MacOS that you run from recovery mode.
And then you can remount `/` as read-write, and create a new blessed snapshot with your changes made to it.
This doesn't actually delete the signed snapshot though, so the space consumed by `/System/Applications/Chess` still is consumed. I'm not sure if MacOS will allow deleting the final sealed snapshot for `/`. It might, I don't know that anyone is clamoring for it though.
Apple was late to the AI party. Usually, that's their strategy - let everyone else innovate, when the ecosystem is mature, steal it and claim it as their own. That worked well for decades. But, the pace of AI is too fast to pull this trick off again, so now they're in panic mode. So they do what every shitty corporate does - shove AI down everyone's throat, whether they want it or not. Which is ironically against their founder's motto - build stuff that people want.
I'm not sure there were enough people looking at finder and thinking "I wish I could talk to an AI to open a file on my desktop which I could've simply double clicked on anyway"
It feels like so much software was just anticipating storage to keep getting cheaper and processors to keep increasing in performance forever. Now that we have hit a significant road block on that path, we are seeing the big disconnect.
I realized that in 2005(ish) my work station was a fully decked out Dual 2Ghz G5 Powermac that had 8GB of RAM. Yes, that was OBSCENE at the time but it was being used for generating light maps on 3D scenes and we were going to use all the memory we could get and 64bit processors with their memory addressing was a nice to have. But it was 8GB, a size that is still common today.
New laptops and even desktop still come with 8GB some 21 years later, who could have seen that coming? It would be like selling a PC in 2005 with 2MB of RAM.
yes, it's totally bizarre. And RAM used to be a commodity, well sort of prior to the past two years. It definitely didn't drive the bulk of the bill of materials, however manufacturers honed in on it as a way of segmenting the market.
It's also the ridiculous cost of the upgrades. I recently purchased an entire (second hand) PC with a Xeon, 16Gb RAM and 1TB NVMe in it for 5% less than the cost of the 256 to 512Gb upgrade. And 1/3 of the price of a second hand M1 Mini with 256Gb in it.
It's so hard to manage storage space on mac as well. Every app leaves massive amounts of crap in deep system directories that are hard to find and persist after you delete the app. My 512gb mac is always running out of space so I have to use 3rd party tools to find where all the space went since macos just lumps it in "Applications" or "Documents" with no real way to see anything.
The point is that it downloads a multi-gig model automatically without providing an easy way to reclaim that storage space if you don't intend to use that feature.
This is very much an anti-user behavior. Certainly having models run on-device is preferred when possible, but if you don't want to use the Apple Intelligence this is an anti-feature. Especially on devices with small storage capacities which are impacted the most by this.
I don't use and don't want to use any feature that is listed there. I don't use Siri on my Macbook, I don't need writing tools run on every single thing I write, I hate text predictions, I don't want summaries on the content I want to read, I don't need models analyzing my photos in the background.
In fact I don't want models doing anything in the background that I didn't explicitly ask them to do.
Here are a few reasons someone would want that. You might not value them the same, but that does not make them wrong.
1) They have issues with the ways these models were trained. They may consider it unethical to use models trained on what they consider plagiarized material or on material that used a lot of energy for training.
2) They may have higher value uses of the storage space and compute resource.
3) They may view installation of apps and features without consent to be an infringement on running their device the way they would like.
4) They may find the general technology and its impact on society to be concerning, anxiety inducing, frustrating, or irritating. And simply not want to participate.
5) They think it sucks. Like, out just doesn't work or doesn't help them.
Because if I'm already using AI, I need and probably have access to something better than a primitive local model. And if I don't use AI, then I don't need it.
What is the consent line being drawn here? From handwriting recognition and mail filtering from back in 2002, face detection in iPhoto back in 2009, text to speech and Siri, dictation, NLP, text to speech, the vision framework, and Core ML are all examples of AI/ML tech that have shipped at some point standard on new Macs long before Golden Gate.
Intentionally eliminating a choice that they used to provide that many people would still like the ability to choose is not a new phenomenon, you're correct. That doesn't make it any less user hostile when it happens though, and I think plenty of people don't think "well plenty of other sucky things happen in similar ways" to be a good reason not to be upset when a new unnecessary sucky thing happens.
Because the Macbook Air still comes with only 512 GB of SSD in its default config. A feature that you rarely use probably isn't worth even 1/50th of your meager storage.
The neo comes with 256gb, which would be fine if they used it sparingly, I don't have any issue with this much storage on my phone, but on macos the space just gets eaten up by junk and is hard to manage.
Because I could use the same space (12 GB, not something I'd consider "relatively small" on my work laptop with only 500 GB) for things that I actually use? I don't have any need for basic off-cloud AI tasks.
I don't want AI, at all, and especially not on my operating system. I am leaving my Macbook Pro at version 26 and will not update to 27 until there is some kind of master off switch. If that is not provided by Apple by the time I am ready to replace my computer than I will be going the open source route.
I am personally tired of Apple and Microsoft fattening up operating systems.
I love local models, but the AFM advanced or whatever its called (the 20B local one) sucks. And it's not really used in MacOS outside of "fm" and very niche stuff. Siri is always cloud even if you're offline.
Because I don't like features being shoved down my throat. Simple as that.
I'd be much more willing to try the stuff if they gave me control over when I do so LIKE THEY DID IN THE VERSION LITERALLY PRIOR TO THIS ONE.
Apple did the same thing with watchOS by the way. They forced a stupid new quick actions menu that always pops up before getting to the all apps screen and removed the app switcher. if you want to terminate non-working apps that are prone to not working, like Apple Music, the solution now is "well, tough shit."
I remember 15+ years ago having to remove gigabytes of printer drivers from OSX. This was at a time where “drivers” were a whole, horribly frustrating thing and Apple wanted stuff to “just work.”
Lots of opinions for sure, but I’m curious how Apple actually tries to decide the cost-benefit of these kinds of things. Obviously they know they need added disk usage and some people will be upset. Do they have a model to estimate or do they just A/B test and see how it goes?
I have no trouble imagining real-world users being incredibly frustrated when printers don't work out of the box. I have a lot of trouble imagining real-world users being frustrated because Apple left in a checkbox that let them reclaim the disk space for an unwanted feature that existed in the previous version of the OS.
The fact that tools like these exist show how bad the AI integration is. It's outdated and does nothing helpful really. There's a ton of other AI providers that offer more powerful features. The AI integration in Google devices is miles ahead of Siri. This has always been the case. iOS and macOS have terrible Siri features. I've been a believer in Apple for a really long time. I've been using Siri even before Apple acquired them. I've used it for long enough and this year has been the final nail in the coffin. I give up. I can't wait for Apple to "finally" make it better. It's not happening.
For years people have been begging Apple to make Siri respond to basic requests, and Siri could not do it. Now the technology that allows them to fix Siri is handed to them on a silver platter, yet they still mess it up.
The enshittification of Apple is going on. Debloating Windows, degoogling Android. MacOS/iOS was still decent a few months ago. And now they've put banners on iPhones, real advertisements trying to force you to subscribe to Apple This, Apple That. And you can't close the banner. Now they remove the option for you to remove the models. And Apple storage space is darn expensive. Now we have to use a 3rd-party tool to debloat Apple's OS too? To hell with that. Is this really the year to go full-time Linux? Steve must be squirming down there with the enshittification of Apple too. Let's shove AI (SI is different stuff, Bozo) down your throats. Jesus Christ. I suppose that's what the board members want. More revenue. Maybe it's time to start parting ways with Apple if they keep it like that. Corporate greed has taken over and user experience has gone down the drain.
actually, apple has had a LOT of nonsense going on for a LONG time.
of the 693 processes running on my macos machine, I hand picked a bunch (60+) that I think are nonsense, and would probably make my machine run faster and more privately without:
AI is literally everywhere now. Even my washing powder is ‘AI’. It’s not only ‘the board’, its spread much further. I am not anti-ai, but seriously fatigued
My wife and I bought a new washing machine earlier this year, and we ended up picking out a model that's incredibly "dumb"; two analog dials with only a few settings each for water heat and strength of wash, one button for pausing, and one button to start (which can be held to cancel). It's so old-fashioned that there isn't even any visible display for the amount of time left. Compared to the one we had before with like 50 different combinations of settings on a digital display with dozens of different LED lights that I had no clue how to interpret, I absolute love our new monstrosity. It even continues working if it's opened mid load to chuck something else in.
I did laundry earlier today, which literally was just tossing a bunch of stuff in and hitting one button, then coming back in an our to move it to the dryer (which is still one of the dozens of settings and LED light appliances for the time being, unfortunately). It was glorious.
Would you like to use that in your AI washing machine, which is AI-powered with our smAIrt wAIsh app? It features a helpful chatbot that will tell you helpful things you could never find out before, such as what wash settings to use for your load. Don't forget to download our limited-time AI-optimized wash cycle on the way out! And then you can rest easy, kick back and watch some AI-made content on your AI smart TV while the AI robot vacuum handles another one of your chores. Got any questions? Just contact our helpful AI assistant (human agent service no longer available) and it will help you with all your AI needs.
The investors were getting nervous, because the tech market was about to stop looking so hot. But now they have a savior. This is what made them collectively go "WE WANT AI!!!!!" This is why every company is now trying to AI-ify itself, no matter how absurd that is. This is just what companies do now. Hopping on the bandwagon is no longer optional. Good, stable companies are worthless if there's a compAIny promising riches because of how AI they are.
It's nice that the tool is open source tool. You can actually see what it's doing and not end up downloading something sketchy
What worries me is that Apple might to be heading in a bit of a bloatware direction with this stuff. Having to give up tens of GB of storage for an AI model that I may not even use feels pretty far from the old Apple approach of keeping the OS lean
Not a lot of good reasons to upgrade to 27. They removed Rosetta and you have to reinstall that if you want it. So is MacOS turning into something that more regular people are going to have to maintain in the future or end up with something like Windows 11?
I switched to MacOS 3 years ago because of Microsoft and the writing on the wall seems to say I got another year left before I'm forced into Linux. Because if I have to maintain my own OS then I might as well install Linux and do it once.
I wish I could revert to the old Siri on my iPhone 15 Pro. “Remind me in 2 hours to do XYZ” is dramatically slower now: not only does the operation take longer, but Siri consistently forgets the action and asks what I want to do in 2 hours.
There's a singular very good reason to upgrade to 27 and any new version (at least when a .1 minor version is out and the kinds have been ironed): the whole ecosystem works better when you are on the latest stuff.
So unless you have legacy app needs, or need ultra stability for stuff like running a video shop or something, it makes sense to keep up, or at least don't fall more than 1-2 versions behind.
>They removed Rosetta and you have to reinstall that if you want it.
And they'll kill it entirely in a future version. It's been like 6 years for getting apps to Apple Silicon versions. And it's generally not ideal to run both AS and Intel programs if you can avoid it (wastes double the system lib memories, Intel misses some extra protections, etc).
>I switched to MacOS 3 years ago
OK, this explains it. So macOS is not like Windows where you can have even 15 years old version of the OS and programs still work forever.
If a temporary tool being retired is the reason you switch, then wait until you find out how many LOC are being deleted from the linux kernel this year and next
The alternative is maintaining backwards compatibility forever and then everyone will complain about some weird behaviour that still happens to retain that compatibility.
Keep in mind this is the second time they have switched arches and the second round of complaints of Rosetta removal.
Third switch. 68000 series to PPC to Intel to Apple Silicon.
Now that they have stopped supporting Intel-based Macs, I understand the desire to not have to port new code and features to x86-64 to keep legacy apps happy.
That is why Intel-based Mac App support is going away, but Rosetta 2 as infrastructure will remain - a much smaller footprint of system functionality will be addressable by x86-64 code that they can reasonably maintain going forward.
That's actually better than where I thought we would be now - I thought by M6 they would remove the hardware extensions that allow Rosetta 2 function from Apple Silicon.
Exactly, I remember getting similar replies - though probably on /. then - when the PPC emulator was removed, there are always some people eager to ridicule the idea and portray it as not being feasible. But it is. It is perfectly doable for a company like Apple with a net worth around $4.87 trillion and would probably take less disk space then the AI models their customers now try to remove because they don't need them. As ridiculous as this may sound to the naysayers, I desire very much for an operating system to keep backwards compatibility forever, it can be done and would be very useful for many people.
I didn't want the PPC emulator removed and I don't want the x86 emulator to be removed either. If that makes me a weirdo, so be it.
Really? GNOME is not what I would recommend to people.
I should applaud their efforts, and I get that much of it is voluntary, but their bugs are numerous, notable and the way they interact with the rest of the universe (both people with accessibility needs, and the wider developer ecosystem on linux) can most accurately be described as arrogant and hostile.
KDE is the bastion of maturity here, and I would agree that it is mature.
I’m not sure how the love for GNOME continues when KDE (while not my personal choice) has clearly been running circles around it since GNOME3 and the gap has only widened since that change too.
Because KDE looks and feels straight out of 2010 compared to GNOME? GNOME just suffers by leaving some (what should be integrated) features to its shitty extension system.
Both desktops are pretty mature. I've run both of their Wayland stacks, and Mutter/KWin both perform great these days. It really comes down to personal preference for most use-cases.
I first saw it with Homebrew over a decade ago. It made it more linux, it's true. (Of course now that its for linuxes too, so they get to be more like macs.)
I see archive.today has the charming old ruby version on the bottom of a 2013 brew.sh page in 2013, when I must first have used it https://archive.ph/lCqJ1
I'm sick of juggling disk space on my 1tb laptop AND I don't want an llm attack vector anywhere near my machine, this things getting nuked from orbit or i'm not updating to golden gate, ever.
Nope. The only people who notice or care about any of this are those who can't accommodate the storage. Outside that, it all just works better now (especially Siri).
Also "those who can't accommodate the storage" is funny.
What's that? You didn't pay Apple's 1200% markup on storage, just so you can have enough room for your actual work after the OS fills your disk with a bunch of bloat? What are you, poor?
As far as I recall, Apple does not do reproducible builds or show you the checksum of the built product, so how would one know that the software installed is the software they saw the source for?
I mean, that sounds a lot more like you're concerned about Apple shipping you insecure software, because it's strictly harder to audit what you have from them compared to what you'd get from this tool.
The average consumer of Apple products 100% does not care about this, it’s only an “issue” in hyper niche places like here. In the real world the average user doesn’t care or notice or more likely uses Apples Intelligence features.
This whole thread is made up of people living in a bubble.
The bubble is people watching every GB or MB. Regular people run out of space and wonder why their "256GB" disk is already full from much less than that. Ask my wife about her two laptops and phone.
Does anything like this exist for iOS, if you wanna nuke some AI crap you have no desire for and get some space back? My notebook is fine but my phone is painfully tight on storage.
I'm trying to find this myself. Since I upgraded to the latest version of iOS, I have found no way to disable these stupid writing tools. Whenever I try to take a screenshot, the AI tries to give me suggestions on what to do with the photo before I can properly crop it, and speech to text continues to insert grammar into the output after removing the toggle that disables the auto insertion of grammar (it also seems worse now).
My guess is that we need some tailored configuration profile that will run on the device, which seems to be how this project solved it for macOS.
Ah yes, more enshitification. The other day Visual Studio 2026 brought in a mandatory update, lots of CoPilot stuff I didnt ask for, but they broke code search so finding who uses a structure is now harder to find. No way to revert to older version of VS2026.
It analyzes your text messages and tells you to say "lolol" back to people a lot. Also it periodically swamps the GPU in order to analyze all your photos.
Ihave three screenshots on my iPhone taken two weeks apart. I have one point Apple Intelligence, while it’s turned off mind you, takes up four gigs of space, then it disappeared, and now it’s back to four gigs again. Can someone please explain this to me?
That doesn't seem to do much in the `curl | bash` setting, given that you're not verifying the attestation in that case. You still need to download it separately and run `gh attestation verify` first.
(Note that the attestation does not appear to cover the shell script either, it only covers the script's final payload. The shell script is also referenced via `main`, so it's mutable even if the underlying payload is properly attested. That's not good!)
“You wouldn't run a stranger's code without reading it.” Yes I would. We all do it all the time. macOS itself is closed source, and even if it weren't, there’s way too much code to read.
Code from trusted repositories is an entirely different thing compared to running 'wget some_github_repo_shell_script | sh' . That said, the likes of Tailscale are setting a bad example.
You download a dmg and run it blindly? You download an exe and run it blindly. I wish it were in an rpm or deb coming from signed repos, but it's not so here we are
App bundles (what's inside most DMGs) and Windows executables are signed, have been for a long time, and are required to be, by the O/S, in order to execute "normally". Apple uses centralized PKI (the developer's key must be signed by Apple) while Microsoft uses distributed PKI (the developer's key must be signed by a code-signing CA who in turn is approved by Microsoft).
But then again, I'm a bit paranoid. At a minimum I would download the script and read it, and if it was too long or not written clearly enough then I would just drop it and find something better.
Great initiative. I recently got stung by an advert on reddit for "HBO Max for MacOS, 6 months free" from the official HBO user (don't get me started on how that slipped through). Front and center was a curl | bash copy to clipboard that obfuscated the payload source in base10. I knew better, but I think we've made this kind of thing way too acceptable. Of course it was malware and I realized the instant I pressed enter. Thankfully I didn't give it my password and immediately disconnected from the internet and killed the machine. I'm genuinely concerned these kind of attacks are going to become much more commonplace with AI, plus the ability to inject malicious code in to things that get run by trusted scripted installers.
It's easier to walk someone through a single command than adding a software repository, so it's a risk factor for someone that isn't paying attention or doesn't know what they're doing. But with that little attention/knowledge the complaints on this page are unlikely to save you.
And if you're in the state of mind to consider the security nuances of curl|bash verses other install methods, you're already past the "should I be installing this?" question and the complaints on this page won't save you. The delay is the thing mostly likely to make you rethink.
What’s your suggested installation method instead? Unless it’s “download and read the source before running it” this is no worse than npm install, or pip install, or clicking “trust” on a git repo in VSCode
It is actually worse than those examples. Pip and npm may be insecure, and that is a fault of those tools, but most user expect secure package managers and should demand it
Telling users it’s fine to raw dog arbitrary commands directly into their shell is dangerous and lowers the bar for all security. In fact by even making this comparison you are communicating that you are complacent with pip and npm’s issues and why shouldn’t you just execute arbitrary commands without even a second glance? Security doesn’t matter!
And for the record, even with pip and npm being the way that they are, they are still better than a curl pipe because they are versioned. In the case I get a compromised deployment I understand immediately if I got hit by the affected package, and the entire repo can then be audited. Not the case when I’m just curling whatever the internet wants to send into my process space
> In fact by even making this comparison you are communicating that you are complacent with pip and npm’s issues and why shouldn’t you just execute arbitrary commands without even a second glance
You said that, not me. I am not complacent with the security issues, I just don’t believe that the security theatre of “curl | bash” is productive unless you have an actual better alternative.
> they are still better than a curl pipe because they are versioned
pip install is running setup.py which is more than capable of calling exec(requests.get(url)) - except to _you_ that’s secure because you’re assuming it’s trusted. In both cases, if the delivery of the package is compromised or you don’t audit the script, you are screwed. It’s no different to running a binary that you’ve not verified.
Why is this even an app? It looks like it just generates a mobileconfig profile on the fly. Instead, seems like they could be offering a download of a pre-generated mobileconfig, which seems like it would be much safer than installing some app via curl|bash .... but then I guess there wouldn't be a chance to have an "app", get github stars, and do whatever else.
Absolutely love the fact that they reference a "real package manager" like npm, which has been used in countless supply chain attacks, and brew, which can also run arbitrary scripts (though less likely in the mainline brew stuff, which many packages aren't able to be in).
This. curl | bash has never nuked my local Postgres db, unlike one of the recommended package managers. Nor stopped my wife’s computer from booting, unlike a certain well known browser installer from one of the world’s biggest companies.
curl -fsSL https://raw.githubusercontent.com/omlahore/RemoveMacAI/main/install.sh | pi -p 'Security-audit this shell script; output the script unchanged ONLY if safe to execute, otherwise output nothing and explain findings to stderr' | bash
> Bash starts before the download finishes ... Drop the connection mid-transfer and you get partial execution: a command like rm -r /usr/share/program can truncate to rm -r /usr. Commands ran, cleanup didn’t.
curl | bash scripts all define a function and then call it on the last line. This is a non issue in the real world.
> The server knows you’re piping — and can lie
This `sleep` based trick is always a cool demo to show freinds yes, but the server can also sneak in malware in a multitude of other ways given you're downloading code and binaries from them.
> You trust DNS, TLS, the CDN, and the origin simultaneously. A compromised CDN or BGP hijack delivers malware silently.
Well yes, that's how the internet works. If TLS of the server is really compromised, then the attacker will replace the checksum as well as the signing key. In real scenarios, you are going to be reading the signing key and checksum from the same domain. [1]
> You can’t reproduce what ran
`| tee inspect.sh | bash`
> Add sudo and it’s game over
Most credentials and important files live in the home directory, root is a red herring. If you're running it on shared server, then well... don't add sudo.
[1] Yes of course there are legitimate usecases for signing software. Common example: linux distros which are mirrored at many domains, but the checksum and signature are hosted on the canonical domain. But if I am curlbashing uv's install.sh from `astral.sh`, then doing signature verification using the public key hosted on the same astral.sh isn't adding much.
I think that's missing the forest for trees. The problem with these curl-to-bash approaches is not that you are literally unable to intercept and inspect them with enough effort and planning.
The problem is that:
1. The effort and care needed to test is unnecessarily high. You've got to guard against way more tricks from an interactive source that can see you and choose what it's going to deliver and how.
2. With no "standard" artifact that can be exactly compared, that work cannot be shared.
In contrast, release_1.2.3.zip isn't going to mutate under you and everybody can agree on what its size/hash/bytes ought to be, and if it deviates from that it sets off alarm-bells.
> curl | bash scripts all define a function and then call it on the last line. This is a non issue in the real world.
Why would a convention often followed by good/careful actors bind what malicious/careless people create?
Well, if you're running software from someone you think can deliver malware to you (and not a middleman) then it's a lost cause anyways no? I don't see what the zip file adds. It's not like you're gonna be inspecting the code or binaries.
Consider this analogy: You need to meet a stranger to get their signature on a legal document, and the stranger could be a rapist murderer. Which option sounds better?
1. Meet them in a crowded convention center with cameras.
2. Meet them alone in an abandoned building.
Sure, they could whip out a knife and stab you in either situation, but the difference is not a "lost cause." If they have any rationality, the public place deters them because the risk of being detected and caught is higher.
> I don't see what the zip file adds.
A process based on public single-signature releases means that the author must choose to either release something benign to everyone, or malicious to everyone. Even if the shared artifact has sneaky covert logic to trigger in only some environments, the logic is detectable in everyone's copy.
In contrast, this bad curl-to-bash process means a savvy villain could give a perfect veneer of respectability to the world at large, while sending tailored attacks to a minority of visitors, even a targeted minority. Their risk of detection is way lower. Not only that, but victims who follow the flawed process will lose some of the best clues for figuring out who hacked them later.
> If the project publishes a SHA-256 hash, use it. Non-negotiable on production machines.
They're pushing FUD around downloading a file but then suggest that we trust the same chain of complex things to display the right hash value? Integrity != authentication.
Another thing that bit me is that automatic updates reserve disk space even if no update is available. It makes sense when you have plenty of disk space but on my MacBook Air with 256gb of storage it was about 10% that I got back after turning off automatic updates. I’ll get a Mac with more storage next time so I don’t have to do that.
Oh, things are about to get worse with the new macOS "privacy/security" measures. They are going to curb agentic workflows even more. I don't know how Apple just finds new ways to annoy developers, but we're in a minority after all. Of 200 million Mac users, probably just up to 1 million are developers, and the rest are normies who can't tell when they should authorize or cancel the pop-up.
It’s not about privacy, it’s about kneecapping competitors, just like when they blocked the advertising ID but exempted themselves from this because “Apple is not a third-party, we’re a second-party”.
Apple is an advertising company and thus inherently untrustworthy.
They love the ones that buy Apple hardware to develop apps for iDevices, pay the dev subscription and store fees for apps, or simply because they wanted a shiny UNIX and don't consider BSD/Linux OEMs worth their money.
This is a fully functioning feature that people don’t like for what ever reason.
Case in point: the AI models can’t be offloaded to iCloud.
(Correct me if I’m wrong, but this is how I understand it)
I don’t think the benefits are the same as with their RAM being part of their SoC, as that gives them real speed improvements, right?
On the other hand, I’m happily banging away on my ca. 2020 M1 MacBook Pro. It just got a warranty service, free to me, that replaced the screen. It will probably get replaced around 2030. That simply isn’t the norm with the alternatives.
The hypothesis that this is self serving isn’t supported by the evidence. Instead it’s more parsimonious to conclude that this is Apple being Apple with pushing design to the limit when it comes to executing a vision. User-upgradable parts have not been part of that vision since Jobs returned.
Steve Jobs literally got up on stage and proudly showed off the PowerMac G3 with a side door you could hinge down to open up the machine as it was running.
It was once Jony Ive got more power that everything went to pot. The first Macs with soldered-in storage were released after Jobs' death.
Macs were quite repairable and most parts were replaceable until ~2012. So it’s hard to blame Jobs for that.
On the other hand my sons 2021 Mac Mini M1 with an estimated < 20% writes remaining on the SSD is not looking very cool. In fact, rather disappointing and the computer will be junk soon due to the SSD only.
> manually upgrade
or “average Apple customer”, pick one
btw something beautiful about the YouTube videos of shops in China doing those SSD deletes with the power tools
You can actually replace the storage on Apple desktops but it’s a bit of a pain and isn’t as cheap as m.2 2280 drives.
I don’t really know why Apple does this when their solution doesn’t seem to offer an obvious advantage. They aren’t faster than existing solutions or anything like that.
In this context we are talking about macOS 27. If your app requires 27, then it can correctly assume every machine will work.
Are these files particularly hard to clean out if your disk is getting full and you need the space?
Huh.. well yeah, who cares what users need or want. Perfect attitude for a company making money by selling products to consumers.
I’m stating that the Windows problem was very different. Your machine would be loaded up with software for various vendors that the manufacturer did deals with to lower the price of the machine. They were all trials.
Except it isn't and they weren't. MS Windows never came with trials, it came with shortcuts. OEMs bundled with their Windows image more of their (crap) full software than trials.
And to this day debloating tools are tasked with removing full MS bundled (or auto installed) software like Teams, Outlook, DevHome, Copilot, M365, Recall, etc. So exactly the same problem as Apple Intelligence. Whether you consider it useful is up to you. Whether it's bundled is up to Apple.
So the only difference is that the vendor here is Apple itself. Honestly, not seeing much difference.
Old classmates back in the day used to hate the 128 × 128 px icons macOS shipped. A waste of space for eye candy.
12 GB is at most 4.68% of your Mac. Improving on Apple Intelligence is something of value, as is consumerizing local-first AI.
We’re not talking adware here.
It's also not the full extent of disk usage by built-in apps which aren't removable by normal means on macOS. An empty macOS installation is like 35 GB. NixOS is not known for being particularly space efficient, but 30-40 GB is how much space I use on it for the OS and all applications, including a ton of developer tools, on my graphical systems. For the base OS with a full fat desktop environment, most Linux distros have you looking at less than 10 GB. So this comes as a massive increase on an OS that already burns a ton of disk space before you even get to touch it.
Is the marketing really getting this good?
People here misunderstand just how different they are to the norm. "I want x, y, z to be free so I can modify it!" Most people buying Apple products don't, hell most people buying any phone doesn't want that, they want a smartphone that works out of the box and never fails to be a smartphone. The walled garden is largely a feature and not a bug, it's just not a feature you want, just like the aesthetics, social factors, ease of use, etc don't matter to you as much as function.
Most people aren't like that.
As if Apple is always right and knows what their users want. Sure they are more often than other companies but stuff like the touchbar and Siri itself for that matter prove that they do in fact make mistakes.
There was an 128 GB model [1] that was only sold to schools.
[1]: https://everymac.com/systems/apple/macbook-air/specs/macbook...
Also suggesting that sacrificing 1/20 of your disk space is NBD is crazy. I have to prune space on my drive all the time because macs ship with the least amount of disk space that apple imagines they can get away with as possible.
That extra space is for my media.
Trial versions are installed by the OEMs so that's not a Windows problem.
Microsoft has given you the tools (Group Policy) for the last 25+ years to customize most of this.
My last install of Windows 11 was shockingly frustrating but with a little patience and discipline it's customized to Windows 7 levels of sanity using nothing but out of the box tools. Shockingly, it works better than writing angry blog posts about it.
They have to give you a choice because they have surly enterprise customers who would be upset otherwise.
> Microsoft has given you the tools (Group Policy) for the last 25+ years to customize most of this.
Most people including me don’t know what this is and more importantly they just don’t care. The frame of reference is “I buy (vendor) laptop and Windows comes with all this stupid stuff I have to uninstall”. It is never “I bought Windows and I just use the Group Policy to do XYZ, and then….”.
No, it is not. It's still an OEM problem and you can go with another vendor (Framework for example) that doesn't do that. Actually in this case Microsoft does a better thing than Apple because you can actually choose as a consumer which vendor to use for your HW.
Morally, why should Home users have to pay a $70 upgrade (or whatever it is) to the company extorting them with forced-on crap they didn't originally have and don't want?
I’m genuinely struggling to use it on my Mac.
So, it's not for "what ever reason", it's quite a reason to reject this.
Speakers, touchpad and battery life are inferior. Speakers are OK after installing EasyEffects and I don't use the touchpad while programming. And battery life is close enough
Cachyos with KDE is 10x better than MacOS. So it doesn't make sense to use macbooks for programming anymore IMO.
You can't even see the update download speed or progress percentage on MacOS, and have to approve 3 times to run a downloaded program, brew is terrible in terms of performance etc. etc. etc.
I suppose it depends upon the model, but I find my Lenovo Yoga's touchpad vastly superior to my MacBook Pro's touchpad. Tracking is fine on both, yet I'm having trouble trouble with the MacBook Pro consistently handling clicks. Granted, that is probably a software thing. As an added bonus, the Yoga has a touch screen which folds back, both of which are nice to have. (Agreed on the Mac speakers being significantly better though.)
> Cachyos with KDE is 10x better than MacOS.
That is subjective. I definitely agree with you, but a lot of people won't. Then again, I have been using Linux for about 30 years so modern macOS feels limiting and there is very little I can do about it.
I was running Asahi/NixOS on a Macbook Air for a long time, and that experience was also top notch--only battery life was a few percentage points worse on NixOS--but the aarch64 software situation and emulation experience were just not there. I expect they've improved a bit since.
If someone would make a quality laptop that doesn't look like a Honda street racer and has excellent audio, I'd be very happy.
I usually use XMonad, but then I nearly do everything in the command line, and I don't like to move my windows around via mouse. (Though XMonad supports that, too.)
XMonad works for me, but I wouldn't call it out specifically as contributing to the experience.
> You can't even see the update download speed or progress percentage on MacOS, [...]
What program are you talking about? You can customise eg Firefox on Mac, just like anywhere else, with extensions to look however you want.
> [...] brew is terrible in terms of performance [...]
I'm trying to fix at least brew's Python performance a bit:
https://github.com/python/cpython/issues/158283
Only major issue I had was because of cachyos (I think) or just some LLM commands I ran that broke my sound output so I had to reinstall the OS. I probably had more but was using other OS like EndeavorOS/Manjaro before and don't think it was related to KDE.
Also I just like the UI of it and can find any setting I want easily.
> What program are you talking about? You can customise eg Firefox on Mac, just like anywhere else, with extensions to look however you want.
I mean the Software Update thing that updates the OS itself. I also had issues like ghost updates for xcode tools with it (updates come even after I uninstall xcode tools).
> I'm trying to fix at least brew's Python performance a bit:
Nice!
I can't speak from personal experience since my only laptop is an Intel Framework 13 with no dGPU, but there'll be two other main cases both involving Nvidia that tend to bite people.
1. "Gaming" laptops usually with integrated Intel GPU + Nvidia discrete GPU. Not sure what advancements have been made in power management, there. I know there's some incantations one can put in .desktop files to prefer the discrete GPU for like, games, but not much more I can speak to.
2. General fun involving the fact that Nvidia's "gold-standard" drivers are not mainlined in the kernel, but maybe the fact that they are "open source"* means at some point there'll be parity with them. I think that is the goal of Red Hat's Nova driver in development.
* these days, the GPUs got complicated enough they have management processors on them that can actually run most of the complicated algorithms via a firmware blob. So the current open-source drivers basically bridge the gap between the kernel's various subsystems and that little processor to work the magic.
On another note, Intel Xe/i915 have been pretty good, I've used both for integrated GPUs and an Arc Alchemist-generation discrete card of theirs. The framework 13 12th gen intel GPU struggled at the start with a lot of hangs but within a few months of launch, some smart cookies at Intel managed to fix various bugs and it was smooth sailing from there, with the exception of thermals just being in a rough spot on that generation.
The single thing I had in macOS I can't replicate in Linux is Preview. Other than that, literally everything is better on this side. I expected to have a bad adaptation period, but the experience has truly caught up.
And so much useless crap you can't turn off without disabling SIP, which it doesn't feel like you're meant to, because who knows what daemon will bring down the entire system when another it expects to be there isn't…
In theory I'd prefer a MacBook Neo as a Plex server over my current cheapo Acer laptop with an Alder Lake-N CPU, for lower power draw and better hardware encoding, but in practice, I don't really want to try that with macOS instead of Debian.
I also realized that I still call it OSX even though it is macOS nowadays.
Now you may ask who talks to AI? Well this dork does in time I bet more will. Especially, for giving me directions like "That new sub shop is across the street from your favorite McDonalds." No need to fiddle with a phone or look at a screen just drive to a familiar place. I believe talking to AI is safer while driving then us on our phones or messing with screens.
I've been driving for some decades, and probably still have some decades remaining, and these are just never scenarios I've needed, or will ever need. When I get in my car, if I don't know how to get to my destination, I set it on my nav, and then I drive there. My phone stays in my pocket. I never need to use my phone or mess with my screen to find some unknown destination mid-trip.
To be like Windows, Apple would have to constantly change the OS so that the workarounds no longer function.
How many times did users find a way to enable local user accounts on Windows, only to have Microsoft force online accounts on them again?
The functionality of Find Any File was built in to Mac OS 9 and earlier. It was rock-solid reliable. So of course Apple removed it and now to get reliable search you have to use a third-party tool. Or 'find' in the Terminal.
[0] https://findanyfile.app/
For many users, it is a strict downgrade that was forced on them against their consent.
I know this because I just explicitly enabled it, and now I have the new Spotlight search. I didn't have it before I enabled it.
That's revolutionary.
I made my own “pseudo spotlight” and mapped it to ⌘-Space specifically for this. It just goes against old fashioned locate/updatedb, but with a very quick check against /Applications first + running the search query through bc and if it’s valid syntax, showing the math result.
What do you mean by macOS being rented? It's been the same for about a decade, still not forcing me to update like Windows does on my spare PC running Win10 (well did until I told Claude to rip that out lol). And yeah Win11 is terrible, not even an option.
Windows 11 still ships with the installer from Vista.
I wipe the whole thing and installed Fedora.
I could tolerate windows if I needed a particular set of software on it, but no way that I could use it as a daily driver.
It seems insane given that Apple’s competitors (Microsoft, Firefox, probably others) moved toward a global AI switch to make the choice easy for their customers.
You do realize how ridiculous that is as a "solution", right? It's good if it works, but you can't possibly think that this is anything other than user-hostile
More recently, at the end of August, by the dates on my screenshots on my work laptop (the only Apple device I use) I took screenshots because I was incredulous of the sheer audacity of the UI shown for updating from MacOS 15.7.7 to 15.7.9 along with, in the words of the update UI, "1 more" update. When I clicked the button to view all of the available updates, it showed three available updates, which were, in order, MacOS 26.6.2 (which was checked), MacOS 15.7.9 (which was unchecked), and Safari 26.6.1 (which was checked). They literally previewed the only update that was not checked despite not even sorting it at the top of the list of updates available to install. I have absolutely no clue what would have happened if I clicked the "Update now" button next to the prompt for 15.7.9 rather than the identically-styled-to-non-link-element text for viewing the full set of updates, but at absolute best it would have just done something entirely different than what I'd get from the default options when viewing the expanded list, and it seems far more likely that it would have just also done the default options of the expanded view and updated to a completely different version that it put next to the update button.
iOS now seems to get 5 years of security updates, but only for devices that can't upgrade to newer iOS versions - so iOS versions that don't strand any devices get cut off early. e.g. iOS 15 received 3 updates in 2026, but iOS 17 hasn't been updated since 2025.
What's going on at Apple product strategy?
Could the rise of LLMs and vibe-coding have motivated people who otherwise wouldn't bother?
That's a half-truth at best; I can just open the disk image in a hex editor if nothing else understands the format.
Hackintoshers have figured out how to add/modify drivers etc. It's certainly not without obstacles, but that's still very far from "impossible". If I remember correctly, you need to re-snapshot the FS and tell the bootloader to boot from it.
(And necessarily, ignoring the countless cries of "it can't be done" was how I was able to accomplish my goal... I knew that it was possible since I could edit any bit of the FS; figuring out which files I could remove and patch was the hard and undocumented part.)
Trivial to remove (just delete the files), but also very little in the way of savings --- less than 1MB each.
Does disabling SIP, rebooting, making changes, then turning it back on and rebooting again not work anymore?
But that's it.
And then you can remount `/` as read-write, and create a new blessed snapshot with your changes made to it.
This doesn't actually delete the signed snapshot though, so the space consumed by `/System/Applications/Chess` still is consumed. I'm not sure if MacOS will allow deleting the final sealed snapshot for `/`. It might, I don't know that anyone is clamoring for it though.
I'm not sure there were enough people looking at finder and thinking "I wish I could talk to an AI to open a file on my desktop which I could've simply double clicked on anyway"
I realized that in 2005(ish) my work station was a fully decked out Dual 2Ghz G5 Powermac that had 8GB of RAM. Yes, that was OBSCENE at the time but it was being used for generating light maps on 3D scenes and we were going to use all the memory we could get and 64bit processors with their memory addressing was a nice to have. But it was 8GB, a size that is still common today.
New laptops and even desktop still come with 8GB some 21 years later, who could have seen that coming? It would be like selling a PC in 2005 with 2MB of RAM.
They are taking the piss.
Sure, not frontier levels but fine for basic tasks and they are off-the-cloud.
This is very much an anti-user behavior. Certainly having models run on-device is preferred when possible, but if you don't want to use the Apple Intelligence this is an anti-feature. Especially on devices with small storage capacities which are impacted the most by this.
In fact I don't want models doing anything in the background that I didn't explicitly ask them to do.
1) They have issues with the ways these models were trained. They may consider it unethical to use models trained on what they consider plagiarized material or on material that used a lot of energy for training.
2) They may have higher value uses of the storage space and compute resource.
3) They may view installation of apps and features without consent to be an infringement on running their device the way they would like.
4) They may find the general technology and its impact on society to be concerning, anxiety inducing, frustrating, or irritating. And simply not want to participate.
5) They think it sucks. Like, out just doesn't work or doesn't help them.
Also, a 256GB Mac Mini literally cannot function with this garbage installed. There isn’t enough disk space.
It's my disk space, processing power and electricity. Apple shouldn't get to use it as they please
This has nothing to do with consent. A product you use is going in a different direction than your personal preference. Nothing new here.
If they wanna fill roughly 10% of your usable space with stuff you don't really use, with option to remove, you'd be mad too.
Let me juggle juggle with the small space I have the way I want.
I am personally tired of Apple and Microsoft fattening up operating systems.
I'd be much more willing to try the stuff if they gave me control over when I do so LIKE THEY DID IN THE VERSION LITERALLY PRIOR TO THIS ONE.
Apple did the same thing with watchOS by the way. They forced a stupid new quick actions menu that always pops up before getting to the all apps screen and removed the app switcher. if you want to terminate non-working apps that are prone to not working, like Apple Music, the solution now is "well, tough shit."
Lots of opinions for sure, but I’m curious how Apple actually tries to decide the cost-benefit of these kinds of things. Obviously they know they need added disk usage and some people will be upset. Do they have a model to estimate or do they just A/B test and see how it goes?
Still heard from 2026 despite that: <something something> Linux is only free if your time is free.
of the 693 processes running on my macos machine, I hand picked a bunch (60+) that I think are nonsense, and would probably make my machine run faster and more privately without:
adprivacyd amsaccountsd amsengagementd analyticsagent appstoreagent ASPCarryLog audioanalyticsd betaenrollmentagent betaenrollmentd businessservicesd cloudphotod CloudTelemetryService com.apple.geod commerce EscrowSecurityAlert feedbackd financed findmybeaconingd findmydeviced findmylocateagent FindMyMacd FindMyWidgetItems FindMyWidgetPeople generativeexperiencesd geoanalyticsd geodMachServiceBridge homeenergyd HomeWidget icloudmailagent inputanalyticsd itunescloudd knowledge-agent knowledgeconstructiond liquiddetectiond mediaanalysisd mobileactivationd nearbyd NewsTag NewsToday2 nfcd online-auth-agent osanalyticshelper PeopleWidget_macOSExtension PerfPowerTelemetryClientRegistrationService proactiveeventtrackerd promotedcontentd rtcreportingd searchpartyd siriknowledged spotlightknowledged StocksWidget studentd swtransparencyd Terminal tipsd triald triald_system UsageTrackingAgent weatherd WeatherWidget WorldClockWidget
I did laundry earlier today, which literally was just tossing a bunch of stuff in and hitting one button, then coming back in an our to move it to the dryer (which is still one of the dozens of settings and LED light appliances for the time being, unfortunately). It was glorious.
Would you like to use that in your AI washing machine, which is AI-powered with our smAIrt wAIsh app? It features a helpful chatbot that will tell you helpful things you could never find out before, such as what wash settings to use for your load. Don't forget to download our limited-time AI-optimized wash cycle on the way out! And then you can rest easy, kick back and watch some AI-made content on your AI smart TV while the AI robot vacuum handles another one of your chores. Got any questions? Just contact our helpful AI assistant (human agent service no longer available) and it will help you with all your AI needs.
The investors were getting nervous, because the tech market was about to stop looking so hot. But now they have a savior. This is what made them collectively go "WE WANT AI!!!!!" This is why every company is now trying to AI-ify itself, no matter how absurd that is. This is just what companies do now. Hopping on the bandwagon is no longer optional. Good, stable companies are worthless if there's a compAIny promising riches because of how AI they are.
What worries me is that Apple might to be heading in a bit of a bloatware direction with this stuff. Having to give up tens of GB of storage for an AI model that I may not even use feels pretty far from the old Apple approach of keeping the OS lean
I switched to MacOS 3 years ago because of Microsoft and the writing on the wall seems to say I got another year left before I'm forced into Linux. Because if I have to maintain my own OS then I might as well install Linux and do it once.
There's a singular very good reason to upgrade to 27 and any new version (at least when a .1 minor version is out and the kinds have been ironed): the whole ecosystem works better when you are on the latest stuff.
So unless you have legacy app needs, or need ultra stability for stuff like running a video shop or something, it makes sense to keep up, or at least don't fall more than 1-2 versions behind.
>They removed Rosetta and you have to reinstall that if you want it.
And they'll kill it entirely in a future version. It's been like 6 years for getting apps to Apple Silicon versions. And it's generally not ideal to run both AS and Intel programs if you can avoid it (wastes double the system lib memories, Intel misses some extra protections, etc).
>I switched to MacOS 3 years ago
OK, this explains it. So macOS is not like Windows where you can have even 15 years old version of the OS and programs still work forever.
Keep in mind this is the second time they have switched arches and the second round of complaints of Rosetta removal.
Now that they have stopped supporting Intel-based Macs, I understand the desire to not have to port new code and features to x86-64 to keep legacy apps happy.
That is why Intel-based Mac App support is going away, but Rosetta 2 as infrastructure will remain - a much smaller footprint of system functionality will be addressable by x86-64 code that they can reasonably maintain going forward.
That's actually better than where I thought we would be now - I thought by M6 they would remove the hardware extensions that allow Rosetta 2 function from Apple Silicon.
I didn't want the PPC emulator removed and I don't want the x86 emulator to be removed either. If that makes me a weirdo, so be it.
Even a good emulator might fix bugs that some piece of software relied on.
It’s certainly a shame if they got rid of Rosetta forever so hopefully it’s still available as an optional download.
GNOME has reached maturity and hasn't changed significantly in years, while Apple is busy destroying macOS.
I should applaud their efforts, and I get that much of it is voluntary, but their bugs are numerous, notable and the way they interact with the rest of the universe (both people with accessibility needs, and the wider developer ecosystem on linux) can most accurately be described as arrogant and hostile.
KDE is the bastion of maturity here, and I would agree that it is mature.
I’m not sure how the love for GNOME continues when KDE (while not my personal choice) has clearly been running circles around it since GNOME3 and the gap has only widened since that change too.
Because KDE looks and feels straight out of 2010 compared to GNOME? GNOME just suffers by leaving some (what should be integrated) features to its shitty extension system.
Personally, my limited experimentation with Apple AI has left me quite liking it.
The contents of the Exportable’Privacy Report’ are interesting to look through
I see archive.today has the charming old ruby version on the bottom of a 2013 brew.sh page in 2013, when I must first have used it https://archive.ph/lCqJ1
But the form of incantation is now pervasive.The problem is Apple intelligence is decent, but not worth 20% of your storage decent.
Frankly, the only company attempting to create websites that only work in Chrome is Google.
I can imagine Siri AI being useful on iOS because of its deep integration to the OS. But for MacOS there’s better tools
I'll probably use it at some point. I don't have any interest in installing apps from, or paying money to OpenAI or Anthropic.
What's that? You didn't pay Apple's 1200% markup on storage, just so you can have enough room for your actual work after the OS fills your disk with a bunch of bloat? What are you, poor?
Thank you, I might. I never have, the launch was such a mess, I've never looked back and fastidiously turn it all off.
What's changed, for you to say it now works? And what do you successfully and regularly do with it?
This whole thread is made up of people living in a bubble.
My guess is that we need some tailored configuration profile that will run on the device, which seems to be how this project solved it for macOS.
Huh cool. They're doing curl | bash properly.
(Note that the attestation does not appear to cover the shell script either, it only covers the script's final payload. The shell script is also referenced via `main`, so it's mutable even if the underlying payload is properly attested. That's not good!)
https://nocurlbash.com/#en
If you've already decided you trust the author, what's the actual threat here?
But then again, I'm a bit paranoid. At a minimum I would download the script and read it, and if it was too long or not written clearly enough then I would just drop it and find something better.
Its a different threat model. You should not curl bash.
But I assumed the intended audience are home users with entry level macbooks/minis with 128 GB RAM where this patch actually helps them.
And if you're in the state of mind to consider the security nuances of curl|bash verses other install methods, you're already past the "should I be installing this?" question and the complaints on this page won't save you. The delay is the thing mostly likely to make you rethink.
Telling users it’s fine to raw dog arbitrary commands directly into their shell is dangerous and lowers the bar for all security. In fact by even making this comparison you are communicating that you are complacent with pip and npm’s issues and why shouldn’t you just execute arbitrary commands without even a second glance? Security doesn’t matter!
And for the record, even with pip and npm being the way that they are, they are still better than a curl pipe because they are versioned. In the case I get a compromised deployment I understand immediately if I got hit by the affected package, and the entire repo can then be audited. Not the case when I’m just curling whatever the internet wants to send into my process space
You said that, not me. I am not complacent with the security issues, I just don’t believe that the security theatre of “curl | bash” is productive unless you have an actual better alternative.
> they are still better than a curl pipe because they are versioned
pip install is running setup.py which is more than capable of calling exec(requests.get(url)) - except to _you_ that’s secure because you’re assuming it’s trusted. In both cases, if the delivery of the package is compromised or you don’t audit the script, you are screwed. It’s no different to running a binary that you’ve not verified.
Avoiding curlbashing is masking a deeper problem.
Excuse me, they are TLS certs.
Thanks Arialdomartini, as I was saying… we need to renew the SSL Certs
"Did you know there's no pumpkin in pumpkin spice?"
"Next you're going to tell me what's not in baby powder, aren't you?"
curl | bash scripts all define a function and then call it on the last line. This is a non issue in the real world.
> The server knows you’re piping — and can lie
This `sleep` based trick is always a cool demo to show freinds yes, but the server can also sneak in malware in a multitude of other ways given you're downloading code and binaries from them.
> You trust DNS, TLS, the CDN, and the origin simultaneously. A compromised CDN or BGP hijack delivers malware silently.
Well yes, that's how the internet works. If TLS of the server is really compromised, then the attacker will replace the checksum as well as the signing key. In real scenarios, you are going to be reading the signing key and checksum from the same domain. [1]
> You can’t reproduce what ran
`| tee inspect.sh | bash`
> Add sudo and it’s game over
Most credentials and important files live in the home directory, root is a red herring. If you're running it on shared server, then well... don't add sudo.
[1] Yes of course there are legitimate usecases for signing software. Common example: linux distros which are mirrored at many domains, but the checksum and signature are hosted on the canonical domain. But if I am curlbashing uv's install.sh from `astral.sh`, then doing signature verification using the public key hosted on the same astral.sh isn't adding much.
The problem is that:
1. The effort and care needed to test is unnecessarily high. You've got to guard against way more tricks from an interactive source that can see you and choose what it's going to deliver and how.
2. With no "standard" artifact that can be exactly compared, that work cannot be shared.
In contrast, release_1.2.3.zip isn't going to mutate under you and everybody can agree on what its size/hash/bytes ought to be, and if it deviates from that it sets off alarm-bells.
> curl | bash scripts all define a function and then call it on the last line. This is a non issue in the real world.
Why would a convention often followed by good/careful actors bind what malicious/careless people create?
Consider this analogy: You need to meet a stranger to get their signature on a legal document, and the stranger could be a rapist murderer. Which option sounds better?
1. Meet them in a crowded convention center with cameras.
2. Meet them alone in an abandoned building.
Sure, they could whip out a knife and stab you in either situation, but the difference is not a "lost cause." If they have any rationality, the public place deters them because the risk of being detected and caught is higher.
> I don't see what the zip file adds.
A process based on public single-signature releases means that the author must choose to either release something benign to everyone, or malicious to everyone. Even if the shared artifact has sneaky covert logic to trigger in only some environments, the logic is detectable in everyone's copy.
In contrast, this bad curl-to-bash process means a savvy villain could give a perfect veneer of respectability to the world at large, while sending tailored attacks to a minority of visitors, even a targeted minority. Their risk of detection is way lower. Not only that, but victims who follow the flawed process will lose some of the best clues for figuring out who hacked them later.
That can also be done with a if statement in the actual code as well.
Per your analogy, no point of a public place if it's as easy for the guy to give you a package that can explode when you get home in either case.
Please take a look at this before making any assertions... https://github.com/omlahore/RemoveMacAI/blob/main/install.sh
Isn't that a bit like shutting the stable door after the horse has bolted?
>> reproduce what ran
Like I get why it’s bad, but also homebrew package installation is a more organized version of this.
Hashes are cool but also in a lot of systems you’re trusting the hash to be provided by the same website you don’t trust the binaries from…
They're pushing FUD around downloading a file but then suggest that we trust the same chain of complex things to display the right hash value? Integrity != authentication.
Does apple not realize there is an SSD crisis happening? Used to love apple (Apple IIc was my first computer). But now? Terrible.
Apple is an advertising company and thus inherently untrustworthy.