By John Gruber
WorkOS, the modern identity platform for B2B SaaS — free up to 1 million MAUs.
My thanks to WorkOS for sponsoring last week at Daring Fireball. WorkOS is a modern identity platform for B2B SaaS. Start selling to enterprise customers with just a few lines of code. Ship complex features like SSO and SCIM (pronounced skim) provisioning in minutes instead of months.
Today, some of the fastest growing startups are already powered by WorkOS, including Perplexity, Vercel, and Webflow.
For SaaS apps that care deeply about design and user experience, WorkOS is the perfect fit. From high-quality documentation to self-serve onboarding for your customers, it removes all the unnecessary complexity for your engineering team.
Back in the day, on classic Mac OS, there were no “privileges” for software. If you launched an app, or installed a system extension, that software just did what it wanted. Something as (seemingly) innocuous as a game or as necessarily powerful as a disk formatting utility just ... ran. If that disk utility had a bug that overwrote every byte of your startup disk with zeroes, well, tough luck. If you were unfortunate enough to install malicious software that spread like a virus, well, even tougher luck. That sounds awful, but in practice, it was fine. I’ve been using a Mac since 1991 and I don’t recall ever once — not once — having a problem with malware or scamware.1
That was a long time ago.
Such a laissez-faire approach to software privileges obviously wouldn’t fly today. I want most applications on my Mac to run within a sandbox. I want applications to require explicit permission to access the camera and microphone, or to capture the content of my display. I want applications to be cryptographically signed by known developers and notarized by Apple by default. But I also want to be able to grant trusted applications non-sandboxed access to my entire file system, access to cameras and microphones, and the ability to capture my screen.
I posted a spate of links this week about how the anti-malware/anti-scamware protections in MacOS are increasingly crossing the line from “this is a reasonable balance” to “this is infuriating”. It really is turning into exactly what Apple once mocked.
The Mac is a platform where you need to be able to shoot yourself in the foot. Increased protections that make it less likely that you’ll shoot yourself in the foot are, obviously, a good idea. Many of them are downright necessary. But such protections are only undeniably good ideas when they don’t get in the way of sophisticated users using software that requires a high level of system privileges. Then they become a trade-off. There are some power users who’ve been annoyed every step of the way as Apple has increased such protections in MacOS, but I think, until recently, Apple has managed this balance well. MacOS, on the whole, has been welcoming and safe for unsophisticated users while remaining powerful and efficient for experts. But in recent years MacOS has clearly started slipping down the slippery slope of being too protective.
It’s good to be reminded of the software you have installed that requests, or outright requires, access to private data and sensitive hardware APIs. It’s very good to be alerted to any software you might have installed that has acquired such permissions without your knowledge or recollection. (Like, say, if an abusive partner has installed some sort of monitoring software unbeknownst to you.) But it’s infuriating to play whack-a-mole to dismiss a barrage of permission prompts to confirm the same permissions you’ve previously granted to the same software, and it’s even worse when you need to dig three or four levels deep into System Settings to do it.
Consider real-world power tools. No one wants to get hurt. For sure, no one wants to lose a finger. But serious tool users still have holes to drill, wood to cut, and nails to hammer. There’s a fascinating saga around the company SawStop, which invented a technology for table saws that uses capacitive sensors to prevent saws from slicing through fingers (or, say, for demo purposes, hot dogs). As of a decade ago, in the U.S. alone, over 4,000 fingers were sliced off in table saw accidents annually. That’s a lot of fingers. SawStop’s technology prevents almost all such accidents. But also: it doesn’t make table saws worse for cutting wood. The company has a FAQ about cutting wet or “green” wood:
SawStop saws cut most wet wood without a problem. However, if the wood is very green or wet (for example, wet enough to spray a mist when cutting), or if the wood is both wet and pressure treated, then the wood may be sufficiently conductive to activate the brake. If you are unsure whether the material you need to cut is conductive, you can make test cuts using Bypass Mode to determine if it will activate the safety system’s brake. The red light on the control box will flash to indicate conductivity. If the material is conductive, you can choose to operate the saw in Bypass Mode which will disengage the saw’s safety system’s brake feature and allow you to continue cutting the material.
This sounds like exactly the right balance for MacOS — a balance MacOS until recently had achieved. Safety by default, but don’t get in the way of power users doing their jobs. And when the user needs an override for the safety features, there is an override, and the situation will make clear to the user that needing to use the override is justified by the safety concerns. MacOS is veering into the territory of power users needing to flip override switches all the time.
At the two extremes of the Mac’s user base are gullible technically unsophisticated naifs, and skeptical expert power users. It’s fair for Apple to present some protections that aren’t necessary for expert power users, in the name of bolstering the guardrails for the technically unsophisticated. But at a certain point, a hammer needs to hammer whatever it strikes, and sometimes, alas, that’s the user’s thumb. That’s the Mac. It’s a Unix workstation that’s friendly enough to be used by the mass market. It is not an appliance intended to prevent any possible malware or scamware from running.
Apple makes such appliances. They run iOS. I’d go so far as to say that one problem facing the Mac has nothing to do with the Mac itself but instead is a downstream effect of the iPad’s weaknesses. I believe in the 1984 slogan that the Mac is “the computer for the rest of us”, where “the rest of us” is very much inclusive of non-expert users. But there’s a certain point of unsophistication and okey-doke gullibility where the Mac becomes an inappropriate platform for some users. There are many construction-professional power tools that shouldn’t be used by non-expert users, too.
Computers are such an essential part of the modern world — and almost everyone’s daily lives — that computers-that-work-like-computers aren’t for everyone. The world needs locked-down can’t-cut-your-fingers-off-no-matter-what-you-do platforms like the iPad. And Apple sells significantly more iPad units than Macs. But any Mac user who isn’t sufficiently served by the anti-malware/scamware protections already in MacOS shouldn’t be using a Mac at all. They should be using iPads, or something else similarly locked-down, instead. Some of these users are using Macs instead of iPads out of ignorance. Their technical needs could be met by an iPad but they don’t know it. (They are, by definition, technically unsophisticated.) But surely some of them know they’d prefer to be using an iPad instead of a Mac but can’t, because an iPad can’t do one or more things they need to do, or run software they need to run.
Power tools and user-safety features aren’t mutually exclusive. But they need to be in balance. Apple is clearly losing that balance with MacOS, and I think a big part of that is the iPad’s weaknesses tipping the scale. ★
That viruses, malware, and scamware weren’t significant problems for classic Mac OS users doesn’t mean such things didn’t exist. There was, in fact, a spate of viruses in the late 1980s and early 1990s, which were splendidly addressed by a freeware anti-virus system extension called Disinfectant, by John Norstad. But on the whole, the entire two-decade era of classic Mac OS passed without much malware. Part of that was by design, part by security-through-relative-obscurity, and part, perhaps, by good luck. ↩︎
Sundar Pichai, on X:
Unbelievably saddened by the loss of my dear friend Susan Wojcicki after two years of living with cancer. She is as core to the history of Google as anyone, and it’s hard to imagine the world without her. She was an incredible person, leader and friend who had a tremendous impact on the world and I’m one of countless Googlers who is better for knowing her. We will miss her dearly. Our thoughts with her family. RIP Susan.
Academic paper from over 100 researchers at Apple:
We present foundation language models developed to power Apple Intelligence features, including a ~3 billion parameter model designed to run efficiently on devices and a large server-based language model designed for Private Cloud Compute. These models are designed to perform a wide range of tasks efficiently, accurately, and responsibly. This report describes the model architecture, the data used to train the model, the training process, how the models are optimized for inference, and the evaluation results. We highlight our focus on Responsible AI and how the principles are applied throughout the model development.
Benjamin Mayo, writing at 9to5Mac:
Following the EU ruling in June that said Apple’s App Store anti-steering policies are officially in breach of the Digital Markets Act, Apple is announcing changes. Specifically, these changes address the rules around app developers linking out to the web to inform users about alternative payment methods. [...]
If you are operating under the EU alternative business terms, the Core Technology Fee still applies on installs. Additionally, the fees are charged as follows:
- Initial Acquisition Fee: 5%
- Store Services Fee: 10% (reduced to 5% for members of the App Store Small Business Program, or a qualifying renewal of a subscription after one year)
If you are continuing to offer your app inside the App Store under the standard business terms, the Core Technology Fee does not apply (as it never did). But the associated link out commission fee rates are increased:
- Initial Acquisition Fee: 5%
- Store Services Fee: 20% (reduced to 7% for members of the App Store Small Business Program, or a qualifying renewal of a subscription after one year)
This results in a complicated matrix of eligibility and fee costs, that developers will need to carefully evaluate. The new terms are available now to review on Apple’s developer website, including an updated fee calculator.
“Complicated matrix of eligibility and fee costs” is an understatement. Understanding all of this seems like it requires a CPA. I’ve looked across social media and read a slew of posts about this news, and I haven’t found a single person saying anything other than this is a convoluted mess. I think that’s as much on the DMA as it is on Apple: a convoluted mess of a compliance plan for a convoluted mess of a law.
What many people want is for Apple to just give in, concede, and allow iOS apps in the EU to just collect payments however they want, in-app or through links to the web, freely. Where by freely I mean free-of-charge freely. No CTF for downloads, no tracking of purchases made after users tap a link in the app to the web. What Apple wants is to continue making bank from every purchase on digital goods from an iOS app. We’re left with a mess where no one is happy with the result.
See also:
Jason Snell, “Apple’s Permissions Features Are Out of Balance”:
Some users will make bad decisions. That’s just reality. The wrong reaction is to take the decision out of every user’s hands to protect the ones who might do something stupid. Apple needs to find that balance, that protects people but gives users freedom to do what they want, however dangerous it might be.
Apple’s recent feature changes suggest a value system that’s wildly out of balance, preferring to warn (and control) users no matter how damaging it is to the overall user experience. Maybe the people in charge should be forced to sit down and watch that Apple ad that mocks Windows Vista. Vista’s security prompts existed for good reasons — but they were a user disaster. The Apple of that era knew it. I’d guess a lot of people inside today’s Apple know it, too — but they clearly are unable to win the arguments when it matters.
Never would have guessed I’d still find use for the “Windows Vista” tag in my CMS in 2024, but here we are.
Developer Thomas Tempelmann just released version 2.5 of Find Any File, his file search utility for the Mac. Find Any File (FAF) has long been my go-to tool for file search. Why use FAF instead of Spotlight? Some feature highlights:
- FAF can find files that Spotlight doesn’t, e.g. on network (NAS) and other external volumes, hidden ones inside bundles and packages, and those in folders that are usually excluded from Spotlight search, such as the System and Library folders. It can even search in other user’s folders if you use FAF’s unique root search mode.
- FAF lets you search precisely for many file properties such as name, extension, date range, size, kind etc. [...]
- FAF can also find textual content in plain text, in zip (including Word and Excel files) and even in most binary files. And with the option to include Spotlight results, it can also find text in PDF documents as long as they were indexed by Spotlight.
Amongst other features, FAF supports regular expressions, and you can save frequently-used searches to easily re-run them. There are several other good file search utilities for MacOS — and Tempelmann himself kindly offers a list of them — but FAF is my favorite. Free to download and try, and $6 shareware if you keep it. (Or buy it for $8 from the Mac App Store.)
Here’s a developer note from Apple confirming another change in MacOS 15 that many of us were hoping was a bug or glitch in the developer betas:
In macOS Sequoia, users will no longer be able to Control-click to override Gatekeeper when opening software that isn’t signed correctly or notarized. They’ll need to visit System Settings > Privacy & Security to review security information for software before allowing it to run.
Why? Is there any evidence that the Control-clicking shortcut was insufficient? If so, what is that evidence? It seems to me that the sort of technically unsophisticated non-expert users whom these features are meant to protect are the same users who have no idea the Control-click shortcut to launch non-notarized apps even exists.
I mean, if there are exploits running wild because unsophisticated Mac users are Control-clicking malware apps they’ve somehow downloaded, where are they? I can only see two possible explanations for these changes: (a) these decisions that are making MacOS increasingly annoying for expert and power users are being made by cover-your-ass bureaucrats for no good reason, and no one who knows better is shooting them down within Apple; or (b) there’s a serious rash of unreported abuse of these features and Apple is too timid to publicize them to justify the increased frequency and arduousness of these permission nags, lest they admit the Mac has any problems at all.
Neither is a good look.
Chance Miller, writing for 9to5Mac:
With macOS Sequoia this fall, using apps that need access to screen recording permissions will become a little bit more tedious. Apple is rolling out a change that will require you to give explicit permission on a weekly basis to these types of apps, and every time you reboot your Mac. [...] In the current macOS Sequoia beta, this prompt says:
“[App name] can access this computer’s screen and audio. Do you want to continue to allow access? This application may be able to collect information from any open applications on your desktop while the app is running.”
Users can then choose to “Continue To Allow” that app to have screen recording access, or they can click “Open System Settings” and immediately be taken to the preferences pane for screen recording permissions.
This prompt is designed to appear on a weekly basis. The first time you attempt to use the app each week, you’ll see this prompt and have to decide whether to “Continue To Allow” or change the permission settings. The prompt will also appear each time (for each app) when you use that app for the first time after rebooting your Mac.
I think it shows just how much care and thoughtfulness went into turning up the dial on these nags that the button label incorrectly capitalizes the “to” in “Continue To Allow”. You can say, well, that’s a little thing. But that’s exactly the sort of little thing that almost never shipped from Apple, even in beta, until the last few years.
Having to click through these confirmation nags every week, for every such utility you use, is not a little thing at all. It’s the sort of thing companies do when decisions like this are made by people looking to cover their asses, not make insanely great products.
Kylie Robison, reporting for The Verge:
Between May and August, more AI Pins were returned than purchased, according to internal sales data obtained by The Verge. By June, only around 8,000 units hadn’t been returned, a source with direct knowledge of sales and return data told me. As of today, the number of units still in customer hands had fallen closer to 7,000, a source with direct knowledge said. [...]
Once a Humane Pin is returned, the company has no way to refurbish it, sources with knowledge of the return process confirmed. The Pin becomes e-waste, and Humane doesn’t have the opportunity to reclaim the revenue by selling it again. The core issue is that there is a T-Mobile limitation that makes it impossible (for now) for Humane to reassign a Pin to a new user once it’s been assigned to someone. One source said they don’t believe Humane has disposed of the old Pins because “they’re still hopeful they can solve this problem eventually.”
Starting to think maybe Humane is in trouble.
Big new update to the amazing flight-tracking app, with a particular focus on flight delays — both predicting them, and explaining them. I was using Flighty 4 in beta over the weekend, when my wife and I were in Montreal for a wedding. Our flight home Sunday was delayed by thunderstorms — both in Montreal and Philadelphia — and the information from American Airlines at the airport was all over the place. The information from Flighty was consistent, and spot-on. Wound up being about a 40-minute delay, no big deal — exactly as Flighty presented.
Flighty costs $48/year for an annual subscription, but has a super clever $4/week option for infrequent travellers. And if you don’t like subscriptions, Flighty offers fairly-priced lifetime purchases.
On the whole I continue to think it’s a tremendous advantage for Kamala Harris to drop into the race as a fresh candidate just three months ahead of the election, but I think this branding effort is one area that shows signs of being rushed. It’s not horrible but it’s not good. It’s just meh, and in no way memorable or distinctive. I don’t see how the two typefaces pair together at all. It’s has nothing like the cohesiveness of the Biden-Harris brand from 2020 (and the first half of 2024).
Also, I think the gist of this Fast Company story, suggesting the logo is a nod to the branding from Shirley Chisholm’s groundbreaking 1972 campaign for the Democratic nomination, is nonsense. “Harris” is presented in all-caps in a compressed sans serif typeface, yes, but it’s not even vaguely the same typeface. If anything, Chisholm’s branding was better, stronger, and more timeless — I wish the Harris branding was more like Chisholm’s. And it’s not like anyone in today’s US electorate actually remembers what Shirley Chisholm’s 1972 campaign posters looked like.
Taegan Goddard, writing at Political Wire:
In many ways, Tim Walz is the person J.D. Vance pretends to be. He’s an authentic, decent and normal guy.
Nate Silver:
This was a choice designed to maintain the social fabric of the Democratic Party, and avoid news cycles about a disappointed left and Democrats’ internal squabbling over the War in Gaza. Or at least, that’s what I think it was: we’ll need to learn more about Harris’s deliberation process. I’m not inclined to be too deferential to any political candidate, but it’s plausible that there were vetting issues with the runner-up, Gov. Josh Shapiro of Pennsylvania. Harris certainly has more information about the internal feeling within the Democratic caucus than I do, or she may just have thought the chemistry of a Harris-Shapiro ticket wouldn’t work.
It’s a nice pick: Walz, a two-term governor and six-term U.S. Representative, is from the family of Tim Kaine-style VP choices: inoffensive, unlikely to cause any harm, “safe”. Although maybe that’s unfair: Walz is likely to be better on the stump than Kaine. If you surveyed Democratic members of Congress, he’d probably be who they’d choose. But I believe he’s probably the wrong choice, a step back toward the Democratic Party’s instincts to triangulate instead of the boldness the Harris campaign has displayed so far. [...]
On Saturday, I made the case that Harris should pick Shapiro. And nothing has really changed since then — although you could argue that Harris’s increasingly strong position in the polls compels greater risk-aversion than when she’d initially appeared to be an underdog against Donald Trump. The basic reasons for picking Shapiro are that he increases the likelihood you win Pennsylvania, he has a demonstrated track record of popularity in the most important swing state, he’s obviously an extremely talented politician and perhaps a future standard-bearer for the party himself. And also, the reasons for not picking Shapiro aren’t great. Democrats in the political bubble overstate the salience of the Gaza issue and understate the benefits of moderation, and that’s before getting into the issue of Shapiro’s Jewishness.
My fear is that Walz is, as Silver also worries, another Tim Kaine. Tim Kaine didn’t lose the 2016 election but he didn’t help win it either. Kaine is a fine senator but a total milquetoast. Zero charisma. As soon as the 2016 election was over he completely disappeared from the national stage. It’s been 8 years and I’ve only seen Kaine in the news once in that entire stretch, and that was because he got stuck on I-95 for 27 hours because of a snowstorm. Bill Clinton picked a running mate who had the charisma and gravitas to run for and win the presidency on his own. (Gore lost by like 600 votes in Florida, of course, but clearly he could have won.) Barack Obama picked a running mate who went on to run for president and beat Donald Trump. Hillary Clinton picked a running mate with the personality of a wet towel.
I’m thinking Walz is more like Biden in 2008 though. Reassuring in-his-60s white guy with a solid career, thorough knowledge of the issues, and good zip on his political-barbs fastball.
CNN:
During recent remarks at a “White Dudes for Harris” fundraiser, Walz made a rough-and-ready case for [Harris] before would-be small-dollar donors.
“How often in 100 days do you get to change the trajectory of the world? How often in 100 days do you get to do something that’s going to impact generations to come?” Walz asked. “And how often in the world do you make that bastard wake up afterwards and know that a Black woman kicked his ass, sent him on the road?”
I was hoping for Buttigieg or Shapiro, but that quote alone makes me like the cut of Walz’s jib. Also, Walz is the guy who got the whole “they’re weird” thing going.
My thanks to 1Password — which, earlier this year, acquired longtime DF sponsor Kolide — for sponsoring last week at DF. In a 2023 survey of IT and security professionals, 50 percent of respondents said that their organization’s vulnerability management program had support from leadership to “a large/great extent”. That’s good for them. But it also leaves a full half of respondents without enough support from leadership.
If you’re trying to get buy-in at your own organization, come equipped with the facts about the risks you’re facing, and come with a clear plan to remediate them. To learn more about how vulnerability management is changing, read 1Password’s blog post, and come prepared.
David McCabe, reporting for The New York Times:
Google acted illegally to maintain a monopoly in online search, a federal judge ruled on Monday, a landmark decision that strikes at the power of tech giants in the modern internet era and that may fundamentally alter the way they do business.
Judge Amit P. Mehta of U.S. District Court for the District of Columbia said in a 277-page ruling that Google had abused a monopoly over the search business. The Justice Department and states had sued Google, accusing it of illegally cementing its dominance, in part, by paying other companies, like Apple and Samsung, billions of dollars a year to have Google automatically handle search queries on their smartphones and web browsers.
“Google is a monopolist, and it has acted as one to maintain its monopoly,” Judge Mehta said in his ruling. [...]
Monday’s ruling did not include remedies for Google’s behavior. Judge Mehta will now decide that, potentially forcing the company to change the way it runs or to sell off part of its business.
It’s worth a reminder that under U.S. antitrust law, having a monopoly is not in and of itself illegal. It’s just that monopolies must operate under different rules, and Mehta has ruled that Google broke (and continues now to break) those rules.
And you don’t have to be an expert to know that Google Search is a monopoly. By market share it’s possibly the biggest monopoly in all of computing today. Maybe it’s still Windows, but most estimates peg the Mac’s share of the U.S. PC market at about 15 percent. I wouldn’t be surprised if fewer than 10 percent of Americans even know there exist search engines other than Google, let alone use one as their default.
What the remedies should — or even could — be for Google here, I don’t know. Microsoft lost a similarly huge antitrust case in the U.S. in the 1990s and effectively escaped unscathed.
One possible outcome is that Apple winds up paying a bigger penalty, effectively, than Google. Let’s say the remedies include Google being banned from paying for traffic acquisition. Then Apple changes Safari from making Google the default search engine to prompting users with a choice for default search, and 90 percent of Safari users choose Google — the search engine they’ve been using since forever ago, and for many people the only one they even recognize by name. Now Google gets that search traffic for free and Apple gets bupkis.
Jason Snell, “Existential Thoughts About Apple’s Reliance on Services Revenue”:
The intersection of hardware and software has been Apple’s home address since the 1970s. And yet, a few years ago, Apple updated its marketing language and began to refer to Apple’s secret sauce as the combination of “hardware, software, and services.” [...]
Last quarter, Apple made about $22 billion in profit from products and $18 billion from Services. It’s the closest those two lines have ever come to each other.
This is what was buzzing in the back of my head as I was going over all the numbers on Thursday. We’re not quite there yet, but it’s hard to imagine that there won’t be a quarter in the next year or so in which Apple reports more total profit on Services than on products.
When that happens, is Apple still a products company? Or has it crossed some invisible line?
What a great column from Snell. One way to look at it — as Snell points out in the first paragraph quoted above — is that Apple has always been a two-sided coin. They are the company that best exemplifies Alan Kay’s adage: “People who are really serious about software should make their own hardware.” Apple has always been like one of those optical illusions that looks like one thing at first, but looks like another if you stare at it for a few seconds. A hardware company that makes great software. A software company that makes great hardware.
Coins only have two sides though. If services constitute a new third dimension for the company, and we carry this analogy through, it’s like a coin whose edge just keeps getting thicker. If the edge gets thick enough, it’s no longer a coin — it’s something else. A stick or a baton.
But another way to look at it is that services are just another form of software. Software that runs not on the personal computing devices Apple sells to customers, but which run on servers in the cloud. And, importantly, is sold to users via lucrative recurring subscriptions. Content often isn’t what we think of as software (like say music, movies, and TV shows) but content from the App Store is. But the key is that it’s all stuff that the users of Apple’s devices consume on those devices. Apple’s core business is designing, engineering, producing, and selling those devices. Services are just a huge, and growing, part of what users do and consume on those devices.
To extend Kay’s axiom for today’s world, I suspect Apple’s leadership sees things this way: People who are really serious about device platforms should make their own services. Viewed that way, Apple’s success with services is no more a distraction from their core business than their success with their own chain of retail stores has been. It’s just a necessary evolution. ★
Charlotte Klein, who wrote the New York Magazine piece over the weekend reporting on how Bloomberg shit the bed by publishing news of Evan Gershkovich’s release in a prisoner swap before he was actually released from Russian custody:
Jennifer Jacobs — one of the two Bloomberg reporters who bylined the embargo-breaking Gershkovich piece — has been fired, according to a source familiar with the situation.
Accountability comes for every organization, eventually.
Update: Jacobs, on X, credibly claims it was her editors at Bloomberg who published the story too early, not her:
In reporting the story about Evan’s release, I worked hand in hand with my editors to adhere to editorial standards and guidelines. At no time did I do anything that was knowingly inconsistent with the administration’s embargo or that would put anyone involved at risk.
Reporters don’t have the final say over when a story is published or with what headline. The chain of events here could happen to any reporter tasked with reporting the news. This is why checks and balances exist within the editorial processes.
I knew RFK Jr. was nuts but I had no idea this nuts. You really ought to watch Kennedy’s own video, which, I swear, costars Roseanne Barr. That’s his side of the story, for chrissake. Jiminy.
But. This whole thing — to wit, that it was this shithead RFK Jr. who did this a decade ago, and that it’s coming out 93 days before an election in which he’s a possible Nader-esque siphon-off-some-votes-from-the-fellow-nutjobs spoiler — might be the funniest story ever.
Jason Snell, at Six Colors on Thursday:
On Thursday, Apple announced results for its financial third quarter. Total company revenue was $85.8 billion, a record for its fiscal third quarter, which is traditionally the company’s quietest quarter. Services revenue reached an all-time revenue high of $24.2 billion.
iPhone revenue was down 1%, iPad revenue spiked 24% after major new product releases, and Mac revenue ticked up 2%.
Check out our transcript of Apple’s quarterly conference call with analysts and our video recap of the results.
Charlotte Klein, reporting for New York Magazine:
According to multiple sources at the Journal and other major outlets, the Bloomberg scoop left journalists and government officials fuming. With a prisoner swap, you don’t know if it’s going to happen until it happens. (As one Journal reporter put it: “We literally had Yaroslav Trofimov on the ground with binoculars waiting to see Evan come off the plane, and we pubbed as soon as that happened.”) Which means that Bloomberg’s story proclaiming Gershkovich was free was inaccurate, given that the Russian plane was still in the air at the time of publication. That plane could have just turned around and gone back to Moscow, which is why the Journal and other publications had agreed to hold off.
“Incensed” is how one reporter, whose outlet had agreed to an embargo — delaying publishing what they knew — reacted to Bloomberg’s decision. “People are very, very disappointed in Bloomberg. And not just the embargo breaking, but the football spiking.” (The Bloomberg editor’s X post was later deleted.) Another reporter added, “We all want to break stories. We also need to consider the risks of breaking those stories. I hope editors and reporters thought long and hard about the risks of revealing the details of a hostage transfer before the hostages were back in U.S. custody.”
There is no accountability at Bloomberg. I’ve fumed for years regarding their refusal to retract “The Big Hack”. But this is so much worse. As bad as “The Big Hack” was, journalistically, it wasn’t life-and-death. The exchange of these prisoners was.
What a disgrace, driven by their institutional obsession with being the first to report scoops.
Christina Warren (a.k.a. “Mary Brown”) returns to the show. Topics include Apple’s new iOS 18.1 and MacOS 15.1 betas (featuring Apple Intelligence), a little reminiscing about Gil Amelio and Steve Jobs, and the bizarre saga of TUAW, resurrected as a zombie AI slopsite.
Sponsored by:
Look closely.
Tim Sweeney on X, with what can only be described as a weird take on Find My:
This feature is super creepy surveillance tech and shouldn’t exist. Years ago, a kid stole a Mac laptop out of my car. Years later, I was checking out Find My and it showed a map with the house where the kid who stole my Mac lived. WTF Apple? How is that okay?!
Responding to arguments that Find My only allows people to track devices that they own, Sweeney dug deeper:
A lot of people are saying this here. While technically true, it misses the point: you can’t track the location of a device that’s in someone’s possession without tracking that person, and people have a right to privacy. This right applies to second hand device buyers and even to thieves.
Thieves deserve privacy too is quite the take.
When you reset a Mac, iPhone, or iPad before selling it, the original owner can no longer track it. Find My poses no problem at all for legitimately transferred pre-owned devices. It only poses a problem for thieves — a group Sweeney perhaps has an affinity for.
Update: Benjamin Mayo, on Threads:
If Find My didn’t exist, he’d says it’s a racket that Apple doesn’t help users recover their lost devices in order to sell more new hardware.
Interesting new site, offering AI-powered answers to WWDC-related developer questions. Ask a question, it tries to answer (some answers seem great, some not), and offers links to relevant WWDC sessions.
The small print at the bottom of the page disclaims “Ask WWDC is not affiliated with Apple Inc.” Instead it’s the work of developer Matt Spear, using a new tool he’s building that aims to allow anyone to build a similar “ask site”.
Dan Moren, writing at Six Colors:
Not all features, as I said, will be available to try out in this release. Among those included are the systemwide Writing Tools features to help proofread and rewrite text; inbox prioritization, summaries, and smart reply in Mail; the new Reduce Interruptions focus mode; natural language search for photos and videos as well as the ability to create Memories movies on demands; summaries for transcriptions; and, perhaps most enticingly, improved Siri functionality, including the ability to move between voice and typing, more resilient requests for when you stumble over your words, and answering questions about Apple products.
As for what you won’t find here, don’t expect the contentious image generation features like Image Playground, the ability to clean up and remove unwanted details from photos, and integration with ChatGPT. It’s unclear if those will appear in future builds of these betas, or as subsequent updates after public release. Also unclear is whether there will be a public beta of these versions down the road for non-developers.
I wish I would have predicted that Apple was going to start seeding these .1 OS betas previewing Apple Intelligence features while the .0 versions remain in beta until (presumably) release in September, because in hindsight it seems obvious. Will there be public betas of these Apple Intelligence OS versions soon? Unknown at the moment.
See also: MacRumors: “Here Are All of the Apple Intelligence Features in the iOS 18.1 Developer Beta”.
My thanks to 1Password — which, earlier this year, acquired longtime DF sponsor Kolide — for sponsoring last week at DF. When the EU enacted GDPR in 2018, executives and security professionals waited anxiously to see how the law would be enforced. And then they kept waiting ... and waiting ... but the Great European Privacy Crackdown never came.
But the days of betting that you’re too big or too small to be noticed by GDPR are over. Recently, EU member nations (plus the UK) have started taking action against data controllers of all sizes–from the big (Amazon), to the medium (a trucking company), to the truly minuscule (a Spanish citizen whose home security cameras bothered their neighbors).
If you’re an IT or security professional, you may be wondering what to do. Unfortunately, GDPR compliance isn’t the kind of thing you can solve by buying a tool or scheduling a training session. The best place to start is to adopt a policy of data minimization: collect only the data you truly need to function, on both customers and employees. After that, your second priority should be securing the data you have — keeping it only as long as you absolutely need to, and then destroying it.
1Password can help with all aspects of GDPR compliance. To learn more about GDPR compliance, check out this post at 1Password’s blog.
Apple Newsroom, last week:
Today, Apple Maps on the web is available in public beta, allowing users around the world to access Maps directly from their browser.
Now, users can get driving and walking directions; find great places and useful information including photos, hours, ratings, and reviews; take actions like ordering food directly from the Maps place card; and browse curated Guides to discover places to eat, shop, and explore in cities around the world. Additional features, including Look Around, will be available in the coming months.
All developers, including those using MapKit JS, can also link out to Maps on the web, so their users can get driving directions, see detailed place information, and more.
Apple Maps is one of the best examples of the power of persistence I can think of. It started as a laughing stock, but now, for people in many countries, it’s arguably the best maps service.
Lorenzo Franceschi-Bicchierai, writing for TechCrunch:
CrowdStrike, the cybersecurity firm that crashed millions of computers with a botched update all over the world last week, is offering its partners a $10 Uber Eats gift card as an apology, according to several people who say they received the gift card, as well as a source who also received one. [...]
On Wednesday, some of the people who posted about the gift card said that when they went to redeem the offer, they got an error message saying the voucher had been canceled. When TechCrunch checked the voucher, the Uber Eats page provided an error message that said the gift card “has been canceled by the issuing party and is no longer valid.”
CrowdStrike spokesperson Kevin Benacci confirmed to TechCrunch that the company sent the gift cards. “We did send these to our teammates and partners who have been helping customers through this situation. Uber flagged it as fraud because of high usage rates,” Benacci said in an email.
I’d say the odds are pretty high that CrowdStrike renames itself, like ValuJet and Philip Morris did. That’ll solve the problem.
Mark Zuckerberg, in an essay extolling the virtues of Meta’s open source approach to AI development:
People often ask if I’m worried about giving up a technical advantage by open sourcing Llama, but I think this misses the big picture for a few reasons:
First, to ensure that we have access to the best technology and aren’t locked into a closed ecosystem over the long term, Llama needs to develop into a full ecosystem of tools, efficiency improvements, silicon optimizations, and other integrations. If we were the only company using Llama, this ecosystem wouldn’t develop and we’d fare no better than the closed variants of Unix.
Second, I expect AI development will continue to be very competitive, which means that open sourcing any given model isn’t giving away a massive advantage over the next best models at that point in time. The path for Llama to become the industry standard is by being consistently competitive, efficient, and open generation after generation.
Third, a key difference between Meta and closed model providers is that selling access to AI models isn’t our business model. That means openly releasing Llama doesn’t undercut our revenue, sustainability, or ability to invest in research like it does for closed providers. (This is one reason several closed providers consistently lobby governments against open source.)
Zuckerberg’s argument makes numerous references to Linux winning the war against proprietary Unix variants. I’m not sure how good an analogy that is. Perhaps a better analogy is to programming languages, where instead of one winner (like Linux in the field of operating systems) there are dozens, but they’re all open source, even the ones spearheaded by commercial companies. I’ve been on board with the argument that there is no moat with LLMs, and if there’s no moat, there’s little reason to bank on proprietary solutions. Proprietary solutions require a moat.
One of my formative experiences has been building our services constrained by what Apple will let us build on their platforms. Between the way they tax developers, the arbitrary rules they apply, and all the product innovations they block from shipping, it’s clear that Meta and many other companies would be freed up to build much better services for people if we could build the best versions of our products and competitors were not able to constrain what we could build. On a philosophical level, this is a major reason why I believe so strongly in building open ecosystems in AI and AR/VR for the next generation of computing.
Apple’s App Store payments commission — which most definitely is not a “tax” — is what it is. But it’s just about money. As for the “product innovations they block from shipping”, one man’s product innovation is another man’s CrowdStrike.
I realize this is an aside in an essay that otherwise has nothing to do with Apple or iOS, but to me it speaks to how obsessed Zuckerberg is with the subordinate role Meta has been relegated to on mobile platforms — which of course are the platforms where Meta’s platforms are primarily used. But what exactly are the innovations Apple has blocked Meta from shipping? Why haven’t they shipped those same innovations on Android, which is significantly more open? Why doesn’t Meta just ship its own phone? Oh wait.
As frustrating as Apple’s control over iOS can be at times — for users, for developers, and for the fifth-wealthiest man on the planet — there are really compelling arguments that iOS has succeeded, and remained so popular for so long, not despite Apple’s opinionated control over the platform but because of it.
Emanuel Maiberg, reporting for 404 Media:
If you use Bing, DuckDuckGo, Mojeek, Qwant or any other alternative search engine that doesn’t rely on Google’s indexing and search Reddit by using “site:reddit.com,” you will not see any results from the last week. DuckDuckGo is currently turning up seven links when searching Reddit, but provides no data on where the links go or why, instead only saying that “We would like to show you a description here but the site won’t allow us.” Older results will still show up, but these search engines are no longer able to “crawl” Reddit, meaning that Google is the only search engine that will turn up results from Reddit going forward. Searching for Reddit still works on Kagi, an independent, paid search engine that buys part of its search index from Google.
The news shows how Google’s near monopoly on search is now actively hindering other companies’ ability to compete at a time when Google is facing increasing criticism over the quality of its search results. This exclusion of other search engines also comes after Reddit locked down access to its site to stop companies from scraping it for AI training data, which at the moment only Google can do as a result of a multi-million dollar deal that gives Google the right to scrape Reddit for data to train its AI products.
“They’re [Reddit] killing everything for search but Google,” Colin Hayhurst, CEO of the search engine Mojeek told me on a call.
I have to blame Reddit for this, not Google. But it’s not a good look for Google, either.
Marco Arment, introducing the 10th-anniversary re-write of Overcast:
Most of Overcast’s core code was 10 years old, which made it cumbersome or impossible to easily move with the times, adopt new iOS functionality, or add new features, especially as one person.
That’s why there haven’t been many new features or changes in years.
You saw it, and I saw it. I wasn’t able to serve my customers as well as I wanted.
For Overcast to have a future, it needed a modern foundation for its second decade. I’ve spent the past 18 months rebuilding most of the app with Swift, SwiftUI, Blackbird, and modern Swift concurrency.
Now, development is rapidly accelerating. I’m more responsive, iterating more quickly, and ultimately making the app much better.
Promotions for podcasts will often end with a call to action along the lines of “Available wherever you get your podcasts.” As Anil Dash noted a few months ago, that’s a radical statement. Using whatever client software you want to access content published using open standards on the internet is the way the internet was designed to be. But it’s not the way it’s worked out, by and large. Streaming video is largely available only via proprietary apps from each individual service. Same with streaming music.
But not so with podcasts. Podcasts, more than any other medium, exemplify the original spirit of the open internet. “Wherever you get your podcasts”, for me, has meant Overcast for the last decade. And I feel confident that will be true for the next decade. I’ve got a few small gripes with this major update, but overall it’s clear that Overcast is better than ever.
Margi Murphy and Katrina Manson, reporting for Bloomberg:
The local FBI bureau in Pittsburgh held a license for Cellebrite software, which lets law enforcement identify or bypass a phone’s passcode. But it didn’t work with Crooks’ device, according to the people, who said the deceased shooter owned a newer Samsung model that runs Android’s operating system.
The agents called Cellebrite’s federal team, which liaises with law enforcement and government agencies, according to the people.
Within hours, Cellebrite transferred to the FBI in Quantico, Virginia, additional technical support and new software that was still being developed. The details about the unsuccessful initial attempt to access the phone, and the unreleased software, haven’t been previously reported.
Once the FBI had the Cellebrite software update, unlocking the phone took 40 minutes, according to reporting in the Washington Post, which first detailed the FBI’s use of Cellebrite.
Reporting it like this is like running a commercial advertisement for Cellebrite. What kind of passcode was Crooks using on his phone? Digits only or alphanumeric? How many characters? Did they crack the passcode or get in some other way?
Without that information all that should have been reported here is that the FBI was able to get access to his phone’s contents, and that the phone was from Samsung. That’s it. I totally understand why the FBI — and Cellebrite — might not want to say how they got in, but without that context, there’s no reason to sing their praises for having gotten in.
My thanks to WorkOS for sponsoring last week at Daring Fireball. WorkOS is a modern identity platform for B2B SaaS. Start selling to enterprise customers with just a few lines of code. Ship complex features like SSO and SCIM (pronounced skim) provisioning in minutes instead of months.
Today, some of the fastest growing startups are already powered by WorkOS, including Perplexity, Vercel, and Webflow.
For SaaS apps that care deeply about design and user experience, WorkOS is the perfect fit. From high-quality documentation to self-serve onboarding for your customers, it removes all the unnecessary complexity for your engineering team.
Joe Biden, in a letter to the nation (same post, on Instagram):
It has been the greatest honor of my life to serve as your President. And while it has been my intention to seek reelection, I believe it is in the best interest of my party and the country for me to stand down and to focus solely on fulfilling my duties as President for the remainder of my term.
And in a follow-up post on X:
My fellow Democrats, I have decided not to accept the nomination and to focus all my energies on my duties as President for the remainder of my term. My very first decision as the party nominee in 2020 was to pick Kamala Harris as my Vice President. And it’s been the best decision I’ve made. Today I want to offer my full support and endorsement for Kamala to be the nominee of our party this year. Democrats — it’s time to come together and beat Trump. Let’s do this.
I’ve been ambivalent about Biden dropping out since The Debate. I see clearly that he’s diminished. He’s lost his fastball. Watch Biden on 60 Minutes from just four years ago, on the cusp of the 2020 election. That’s Joe Biden. Biden today, even at his best, doesn’t have that zip. He’s no longer able to serve as a compelling communicator but a communicator is first and foremost what a candidate needs to be. I admire Biden more than ever for coming to grips with and accepting this inconvenient truth, and putting both his country and party above his own ambition. More than any other fissure in our fractious, highly-polarized politics today, the difference between Democrats and Republicans is that Democrats tend to face and address inconvenient truths, and Republicans are nothing more than a weird, gross, terrifying personality cult worshipping one old corrupt man.
Here’s how I think it will play out. This might be wishful thinking, but it’s what I’d bet on. The entire Democratic establishment will get behind Kamala Harris as the nominee. Ambitious and popular Democratic leaders like Gavin Newsom, Gretchen Whitmer, Josh Shapiro, Andy Beshear, and Pete Buttigieg won’t challenge her for the nomination. They’ll compete only to be her pick for VP. (Except Newsom, who, coming from the same state as Harris, wouldn’t work). My top two picks for VP would be Buttigieg and Whitmer. Watch Buttigieg on Bill Maher’s show this weekend, talking about J.D. Vance and why Peter Thiel backs him. He’s so smart, and so good at explaining things.
The knee-jerk reaction to my suggestion of picking Buttigieg or Whitmer is obvious: isn’t a black woman at the top of the ticket already asking a lot? Why go with two women, or a black woman and a gay man? Because they’re smart and they’re sharp and they’re good on TV. If you don’t like their message or platform, don’t vote for them. But if you don’t want to vote for a ticket with two women, or a ticket with gay man as VP, just because, then fuck you. Go vote for Trump, because you’re a bigot, and he’s the candidate for you. There are too many racists and sexists in America, but they’re not a majority.
Like I wrote last weekend after the assassination attempt against Trump: this will be old news by November. The reason why U.S. presidential candidates tend to announce their campaigns two years before elections is because unlike parliamentary systems, our election dates and presidential terms are set in stone. Candidates announce early in the U.S. simply because they can. It’s a good thing, in an election where the overwhelming majority of independent voters wanted both Biden and Trump to drop out of the race, for the Democrats to start fresh, with almost four full months to run a campaign emphasizing youth, intelligence, competence, honesty, and change. New is a positive adjective in America.
November is a long way out. Buckle up.
Sara Fischer, reporting this week for Axios:
Ad tech giant Taboola has struck a deal with Apple to power native advertising within the Apple News and Apple Stocks apps, Taboola founder and CEO Adam Singolda told Axios. The deal provides new validation for Taboola’s business, which has ballooned to over $1.4 billion in annual revenue as of 2023. [...]
As an authorized advertising reseller for Apple News and Apple Stocks, Taboola will power native advertising placements within those two apps in every market available. [...]
Most people know Taboola as the company responsible for placing chumbox ads at the bottom of many news stories online.
Regarding Taboola’s partnership with Apple: I’ve seen people claim that this is somehow hypocritical from a privacy perspective, assuming that Taboola’s somewhat obnoxious, clickbait-style ads must invasively target user profiles and browsing histories.
They don’t. They are targeted entirely contextually. That’s the point.
Want brash, garish advertising plastered all over the web? Reject ads personalization. Want relevant, informed advertising? Embrace ads personalization.
If you told me that the ads in Apple News have been sold by Taboola for the last few years, I’d have said, “Oh, that makes sense.” Because the ads in Apple News — at least the ones I see1 — already look like chumbox Taboola ads. Even worse, they’re incredibly repetitious.
Here’s an example. Today a friend sent me a link to an article at Rolling Stone. The article was behind a paywall on their website, so I used the Share sheet to open the article in Apple News. (Rolling Stone is one of many publications included with a News+ subscription, which I get through the Apple One bundle. This is pretty much the only reason I use Apple News — for reading stories that are paywalled on the web.) I made screen recordings showing me scrolling through the entire article, twice. I got different ads each time, but on both page loads there was at least one ad shown four times, and at least one other ad shown twice. That’s a lot of ads, and a lot of repetition.
And, by sheer coincidence, on the web Rolling Stone is a Taboola partner. Here’s a screenshot of the box of “suggested stories” chum that Taboola offered. It’s pretty much exactly the sort of stuff I see in the ads on Apple News.
So while I don’t think it’s good news that Apple is partnering with Taboola, I don’t expect it to make any discernible difference in the ad quality or frequency. Maybe it will improve the variety? ★
And, for what it’s worth (which might not be much), I do have “Personalized Ads” enabled in Settings → Privacy & Security → Apple Advertising. So I should be seeing the best ads Apple has to offer in Apple News. The half-dozen ads for Bellagio and MGM Resorts that you see in the second screen recording I made of that Rolling Stone article do seem personalized — I’ve read a couple of articles this week commemorating the closing of The Mirage. Bellagio is effectively Mirage 2.0 (and Wynn and Encore are 3.0). ↩︎
Sumit Chandel and Eldhose Mathokkil Babu, writing for the Google Developers blog:
In 2018, we announced the deprecation and transition of Google URL Shortener to Firebase Dynamic Links because of the changes we’ve seen in how people find content on the internet, and the number of new popular URL shortening services that emerged in that time. This meant that we no longer accepted new URLs to shorten but that we would continue serving existing URLs.
Today, the time has come to turn off the serving portion of Google URL Shortener. Please read on below to understand more about how this will impact you if you’re using Google URL Shortener.
Any developers using links built with the Google URL Shortener in the form
https://goo.gl/*will be impacted, and these URLs will no longer return a response after August 25th, 2025.
How much money could it possible cost to just keep this service running in perpetuity? Tim Berners-Lee wrote his seminal essay, “Cool URIs Don’t Change” back in 1998. It’s bad enough when companies go out of business, taking their web servers down with them. But Google isn’t struggling financially. In fact, they’re thriving.
Ina Fried, reporting for Axios:
“We will release a multimodal Llama model over the coming months, but not in the EU due to the unpredictable nature of the European regulatory environment,” Meta said in a statement to Axios.
Apple similarly said last month that it won’t release its Apple Intelligence features in Europe because of regulatory concerns. [...]
Meta plans to incorporate the new multimodal models, which are able to reason across video, audio, images and text, in a wide range of products, including smartphones and its Meta Ray-Ban smart glasses. Meta says its decision also means that European companies will not be able to use the multimodal models even though they are being released under an open license. It could also prevent companies outside of the EU from offering products and services in Europe that make use of the new multimodal models.
The company is also planning to release a larger, text-only version of its Llama 3 model soon. That will be made available for customers and companies in the EU, Meta said.
Another big win for Thierry Breton and Margrethe Vestager. I’m sure EU tech companies will do just fine sitting out the AI boom, and EU customers will be happy to wait for years before getting features available to the rest of the world.
Tom Warren, The Verge:
Thousands of Windows machines are experiencing a Blue Screen of Death (BSOD) issue at boot today, impacting banks, airlines, TV broadcasters, supermarkets, and many more businesses worldwide. A faulty update from cybersecurity provider CrowdStrike is knocking affected PCs and servers offline, forcing them into a recovery boot loop so machines can’t start properly. The issue is not being caused by Microsoft but by third-party CrowdStrike software that’s widely used by many businesses worldwide for managing the security of Windows PCs and servers.
Airlines are down, and hospitals are cancelling elective procedures. Unbelievable, to me, that this is not caused by a bug in Windows but from a third-party tool that I’d never really heard of until today.
The New York Times reports that while the overnight software update from CrowdStrike was automatic and “inescapable” (their word), fixing this might be painstaking and require each affected PC to be fixed manually: rebooting into safe mode, deleting the problematic data file, and then rebooting again to get a clean software update from CrowdStrike. The Times also waited until the 10th paragraph to make this important note:
Apple and Linux machines were not affected by the CrowdStrike software update.
See also: Techmeme’s roundup of coverage, commentary, and jokes.
I don’t post many affiliate links but here’s a great one: Amazon has second-gen AirPods Pro for just $169 for Prime Day, discounted a full third from the usual price of $249. AirPods Pro are not just my favorite earbuds ever, they’re one of my favorite products ever, full stop. Buy through this link and I’ll get rich.
Pete Wells:
The first thing you learn as a restaurant critic is that nobody wants to hear you complain. The work of going out to eat every night with hand-chosen groups of friends and family sounds suspiciously like what other people do on vacation. If you happen to work in New York or another major city, your beat is almost unimaginably rich and endlessly novel. [...]
So we tend to save our gripes until two or three of us are gathered around the tar pits. Then we’ll talk about the things nobody will pity us for, like the unflattering mug shots of us that restaurants hang on kitchen walls and the unlikable food in unreviewable restaurants.
One thing we almost never bring up, though, is our health. We avoid mentioning weight the way actors avoid saying “Macbeth.” Partly, we do this out of politeness. Mostly, though, we all know that we’re standing on the rim of an endlessly deep hole and that if we look down we might fall in.
It’s a funny thing about getting older. You put on weight yet you can’t eat nearly as much as you used to. Somehow, though, here in Philly, Craig Laban has been The Inquirer’s restaurant critic since 1998, and he’s still going strong.
Good critics — whether their beat is food, movies, books, whatever — review every genre, with an open mind. Some of Wells’s best writing was about the most approachable restaurants. This recent review of Hamburger America makes me hungry just glancing at it. His scathing review of Guy Fieri’s American Kitchen & Bar is famous, but don’t miss his review of the unsurprisingly-now-closed Señor Frog’s in Times Square:
Señor Frog’s is not a good restaurant by most conventional measures, including the fairly basic one of serving food. One night I got just two of the half-dozen appetizers I had asked for. Another time, the starters showed up on schedule, but after nearly two hours the main courses still had not appeared.
“What happened to our food?” we finally asked.
“That’s what I’m wondering!” our server said brightly. “Like, where is it?”
Getting just half of what you order at Señor Frog’s can be a blessing if it’s the right half.
One of the all-time great talk show guests.