[log in]

« all threads

Librewolf deprecated on brew due to signing requirements

[lounge] Anonymous @ 2026-07-24 00:16:28 [#11767] [87 replies]

[report]

brew reinstall librewolf
==> Would reinstall 1 cask:
librewolf
Warning: librewolf has been deprecated because it does not pass the macOS Gatekeeper check! It will be disabled on 2026-09-01.


Why do they do this fucking bullshit to us? Apprently it's not enough to pay the Mac OS developer fee anymore and librewolf and the like are no longer kosher, so you have to do some fucking voodoo with the quarantine to use it.

I know, I know

>Mac OS
>Homebrew
>Found yer fuckin problem

But still they have no fucking right to prevent me from using libre software.
Anonymous · 2026-07-24 00:18 [#11770] [report]
>they have no fucking right to prevent me from using libre software
I bet their terms of service say they do.
Anonymous · 2026-07-24 00:19 [#11773] [report]
>>25576
>they have no fucking right
Yes they do, you signed a eula and accepted the TOS.
Now shut the fuck up and up your iCloud subscription because you're running out of space.
Anonymous · 2026-07-24 00:25 [#11776] [report]
>>25576
you bought hardware from the famously walled garden philosophy company and you are saying they need to let you out.
you arent this retarded are you ?
Anonymous · 2026-07-24 00:30 [#11778] [report]
>>25579
Microsoft also does it, is PC hardware also walled garden?
Anonymous · 2026-07-24 00:31 [#11779] [report]
>>25580
>Microsoft also does it
Compared to apple microsoft is a massive open green field.
Apple went inside the walled garden and built even smaller locked play areas for their retarded userbase to stay locked inside.
Anonymous · 2026-07-24 00:32 [#11780] [report]
>>25580
does microshit stop you from installing ANY other OS you actual fucking retard
Anonymous · 2026-07-24 00:33 [#11782] [report]
>macsissies BTFO
Anonymous · 2026-07-24 00:34 [#11783] [report]
>>25580
kill yourself
Anonymous · 2026-07-24 00:38 [#11786] [report]
>>25582
They would if things worked the way they want. Never give an inch.
Anonymous · 2026-07-24 01:06 [#11804] [report]
>>25576
Sir? Why do you even want the best and most private browser, right afer TOR, when you are using it in an unsafe env (MacOS), where every keystroke is logged anyway? And every IP you ever connect to is tied to your AppleID and of course your ISP.

But that aside... fuck, that sucks. Hmm.. in that case I'd just use Zen browser, honestly.
Anonymous · 2026-07-24 01:42 [#11817] [report]
>>25576
>librewolf
>Mac OS
like water and lard
Anonymous · 2026-07-24 02:04 [#11821] [report]
>>25582
Not today, but can you be sure of that tomorrow?
Anonymous · 2026-07-24 02:08 [#11823] [report]
>>25582
>does microshit stop you from installing ANY other OS
Apple doesn't either, Asahi Linux exists. The only thing "stopping" you is the lack of driver support.
Anonymous · 2026-07-24 02:13 [#11825] [report]
>>25586
>Zen browser,
I remember there being a post of someone showing how many connections zen browser makes straight out of the box and If I remember correctly it is more than regular firefox, if you want a private browser just harden firefox with user.js.
Anonymous · 2026-07-24 02:16 [#11826] [report]
>>25590
and if you want zero connections ootb use icecat
Anonymous · 2026-07-24 02:37 [#11829] [report]
>>25576
>he uses brew
lol
Anonymous · 2026-07-24 02:39 [#11830] [report]
>>25582
yes enable secure boot and now you can't boot anything that wasn't signed by microsoft issued certificate
Anonymous · 2026-07-24 02:42 [#11831] [report]
>>25593
Not entirely true, you can add your own platform key and sign the bootloader yourself as long as the firmware trusts it.
https://wiki.cachyos.org/configuration/secure_boot_setup/

Some firmware might be locked down to prevent this though but that's not Microsoft's fault.
Anonymous · 2026-07-24 03:22 [#11833] [report]
iTODDLERS BTFO
Anonymous · 2026-07-24 05:09 [#11834] [report]
>>25576
it's a dogshit package manager. They don't even keep binaries for programs if you aren't on the latest version of mac and force you to compile everything from source.
Anonymous · 2026-07-24 05:19 [#11835] [report]
Why do you use homebrew to install software? It's not a robust package manager that's well-maintained like something you'd see on Linux. Just go download your browser directly.
Anonymous · 2026-07-24 05:22 [#11836] [report]
>>25595
Baste!
Anonymous · 2026-07-24 06:14 [#11839] [report]
>>25576
>Apprently it's not enough to pay the Mac OS developer fee anymore and librewolf and the like are no longer kosher,
fake news.
librewolf isn't paying any developer fee and that's why it's not notarized & fails gatekeeper.
Anonymous · 2026-07-24 06:23 [#11840] [report]
>>25597
homebrew is literally deprecating non-signed official casks because it's well-maintained. make your own repo if you want unsigned casks.
https://github.com/Homebrew/brew/issues/20755
Anonymous · 2026-07-24 06:25 [#11841] [report]
>>25581
librewolf being unsigned is an issue for both windows and macos:
https://codeberg.org/librewolf/issues/issues/2664
Anonymous · 2026-07-24 06:41 [#11844] [report]
>>25576
librewolf never paid apple's dev program though, they were quite vocal about it on their webpage
Anonymous · 2026-07-24 06:54 [#11846] [report]
>>25576
Application signatures should be mandatory. Imagine thinking they shouldn't. How the fuck would you know if your software comes from a verified source or not?

>>25580
>Microsoft also does it
And so does Linux and Android.
Anonymous · 2026-07-24 06:56 [#11847] [report]
>>25576
>uses proprietary OS
>gets mad that it does proprietary things
i don't get it
Anonymous · 2026-07-24 06:58 [#11848] [report]
>>25603
>How the fuck would you know if your software comes from a verified source or not?
yes, how do you?
Is there even one single software that you contacted the developer for to compare signing keys? If not, then how the fuck would you know?
Anonymous · 2026-07-24 07:00 [#11849] [report]
>>25576
It is really hard to comprehense how one free browser could provide privacy and security for users at all. It's inpossible task even for entire systems of free software
Anonymous · 2026-07-24 07:03 [#11850] [report]
>>25606
what?
this post makes no sense
Anonymous · 2026-07-24 07:04 [#11851] [report]
>>25605
>Is there even one single software that you contacted the developer for to compare signing keys?
... is this a joke or are you THAT ignorant
Anonymous · 2026-07-24 07:05 [#11852] [report]
>>25608
answer the question
Anonymous · 2026-07-24 07:08 [#11853] [report]
>>25609
the signing key is published alongside a given release, so you can check whether you install the unmodified application or some crypto miner
it's almost impossible to miss that there has been a number of attacks of late (especially in the shitpile that is npm) where the publisher gets pwned to steal his signing keys and THEN the third party posts some malware because otherwise things like brew, dnf and the like will reject it
it's also common to post keys or checksums on many releases, be it on github or on independent download sites like ffmpeg
Anonymous · 2026-07-24 07:11 [#11854] [report]
>>25610
Everybody can pay those few shekels and let apple sign his app.
The AppStore is full with malware.
Unless you check the keys by actually asking the developer about which one is his, you can't tell.
There are over 34 million people with paid. Apple developer accounts who can sign apps.
Anonymous · 2026-07-24 07:11 [#11855] [report]
>>25576
Good riddance.
Anonymous · 2026-07-24 07:14 [#11856] [report]
>>25611
>Unless you check the keys by actually asking the developer about which one is his, you can't tell.
what in the world are you even talking about
>There are over 34 million people with paid. Apple developer accounts who can sign apps.
yes, the apps they release! you don't get some magical signing key that lets you sign apps of other people
Anonymous · 2026-07-24 07:16 [#11857] [report]
>>25613
of course you can sign apps of other people, how the fuck would Apple know eho originally wrote it, lol?
Anonymous · 2026-07-24 07:17 [#11858] [report]
>>25611
You're fucking retarded. A signing key is private to each individual and has nothing to do with Apple. The ability to see if a signing key is changed or if 2 versions of the app you've downloaded have totally different signing keys is all you need. You don't need to contact the developer at all, the KEY itself is the developer/distributor.

>>25614
Learn how GPG works.
Anonymous · 2026-07-24 07:18 [#11859] [report]
>>25614
anon you might want to have a clue about what you're arguing before making a clown of yourself at the anonymous basket weaving forum
Anonymous · 2026-07-24 07:19 [#11860] [report]
>>25614
>of course you can sign apps of other people, how the fuck would Apple know eho originally wrote it
/g/ - Technology
Anonymous · 2026-07-24 07:20 [#11861] [report]
>>25616
>>25615
so how do you know that the origunal developer signed it and not ranjeet?
Oh, by asking the original developer for it.
Which is what the initial question to you was: Did you ever, in your whole life, verify a signature?
Anonymous · 2026-07-24 07:21 [#11862] [report]
>>25615
>Learn how GPG works.
you mean, the software that tells you to meet in RL to share keys, because you otherwise cant be sure that the signature is from the person you want?
Anonymous · 2026-07-24 07:23 [#11863] [report]
>>25618
Because each key is unique to a given publisher, so ranjeet can only sign applications and updates he himself publishes
I am baffled anyone would assume otherwise. Surely you can intuit that if anyone could sign anything then the whole concept would be unworkable?
Anonymous · 2026-07-24 07:24 [#11864] [report]
>>25620
yes, each signature is unique, but how do you know that the unique signature you see belongs to the person you want?
Because Apple verified that he paid the humiliation fee?
Anonymous · 2026-07-24 07:26 [#11865] [report]
>>25620
>ranjeet can only sign applications and updates he himself publishes
which would include his own librewolf upload.. or anything else...
Anonymous · 2026-07-24 07:27 [#11866] [report]
and people wonder why g is dying
Anonymous · 2026-07-24 07:36 [#11867] [report]
>>25620
Still didnt answer the question:
Did you ever, in your whole life, verify a signature of an app you installed?

You do understand that Apples verification of "yes, this person paid us" isn't enough, right?
Apple isn't visiting the upstream repo to ask the developers if they are ok with this guy publishing their software. No such verification is ever done, YOU would have to do that. If you never did that, then no app signing ever improved your security, it only ever verified that Apple got some shekels.
Anonymous · 2026-07-24 07:36 [#11868] [report]
>>25622
yes, and? the discussion has nothing to do with what an update might contain, only that you can verify the source.

>>25621
i mean yeah, there's always the possibility that the original dev gets disappeared and his key ends up being stolen. i'm willing to bet (((apple verification))) does not include protection from such an event, for the dev or the user.
Anonymous · 2026-07-24 07:40 [#11869] [report]
>>25625
The original developer doesnt need his key to be stolen.
Any random dude who gives apple money can sign with his own signature and publish his copy.
Lets say three people publish the same software with their own keys, how do you know who the original upstream approved one is?
You dont, unless you VERIFY IT YOURSELF by asking the developer. The Apple signature check does fucking nothing to help you here.

Which gets us back to the original question:
Did you ever, in your whole life, verify a signature of an app you installed?
Anonymous · 2026-07-24 07:41 [#11870] [report]
>>25624
Yes I do it all the time, sometimes manually and most often automatically since checking whether they keys match before installing and updating is standard practice in almost all terminal utilities like brew
>Apple isn't visiting the upstream repo to ask the developers if they are ok with this guy publishing their software
this isn't the own you think it is. you might find the recent publishing of notepad++ for macos instructive
Anonymous · 2026-07-24 07:42 [#11871] [report]
>this fucking argument
nuke india
Anonymous · 2026-07-24 07:43 [#11872] [report]
>>25576
do you think you can just own things and be happy ?
Anonymous · 2026-07-24 07:44 [#11873] [report]
>>25627
>most often automatically
no such thing exists, no automatic signature check goes to the upstream repository to check who the original developer is

They operate on a chain of trust, and you gave it the trust the first time you installed it.
Just because the update is verified to come from the same source as the original install, doesn't mean that the original install didnt come from a scammer.
Anonymous · 2026-07-24 07:47 [#11874] [report]
>>25630
Yes and if somebody replaced the original dev with a clone you'd never know so I guess the whole process is pointless. You sure got me here
>no automatic signature check goes to the upstream repository to check who the original developer is
which is why AUR is a shitpile where you're essentially rawdogging the internet
most other repos, like homebrew, don't work like that. I can't upload "whatsapp 2 (totally legit)" whenever I want
Anonymous · 2026-07-24 07:50 [#11875] [report]
>>25618
>>25624
>Did you ever, in your whole life, verify a signature?
The OS does it for you. Your app store (software repo / package manager) is in charge of that. Any normal OS blocks the installation of an app or at least warns you in case of a signature mismatch compared to your already installed version.

>>25621
>>25626
>how do you know that the unique signature you see belongs to the person you want?
Your question is irrelevant. It's not the person that matters, it's the key that matters. You're verifying if a key is trusted. The person behind it can be anyone. You can have multiple people re-distributing the same app with different signatures. What matters is that there's a database of keys which are verified to not distribute malicious software, and keys that are known for distributing malicious software.
Signatures are not meant to be a bulletproof solution to fight against malware, since any dev can go rogue or get their private keys stolen if they're incompetent.

But to answer your question: Publishers verify their signatures in the app stores they publish their software to. Software distributed on it's official github/gitlab is signed by the devs. Keys are attached to developers' Apple, Google, Microsoft, Github, Gitlab, etc. accounts. You literally cannot publish your app onto an app store without passing signature verification.

You're speaking in circles when you say
>how do you know who the original upstream approved one is?
>VERIFY IT YOURSELF by asking the developer
How would you even know who to ask in the first place?

>how do you know
>You dont
Again, you have no idea how anything works. 3 people publishing an identical application would result in 3 different apps being on the app store. You're literally shown which user uploaded it and what the registered domain of the app is. That's more than enough to verify who the original owner is, unless you're sideloading in which case you need to do key verification or a hash check.
Anonymous · 2026-07-24 07:51 [#11876] [report]
>>25631
you are just being dishonest now

maybe learn gpg, especially why you have to give someone trust and how to do that
Anonymous · 2026-07-24 07:51 [#11877] [report]
>>25630
>no such thing exists, no automatic signature check goes to the upstream repository to check who the original developer is
Then it sounds like your repository is dogshit and shouldn't be used.
Anonymous · 2026-07-24 07:52 [#11878] [report]
>>25634
I run arch btw
Anonymous · 2026-07-24 07:52 [#11879] [report]
>>25632
>It's not the person that matters, it's the key that matters.
when did you verify that the key belongs to the person that developed the software?
Anonymous · 2026-07-24 07:54 [#11880] [report]
>>25636
Read >>25632
Anonymous · 2026-07-24 07:55 [#11881] [report]
>>25636
IfnApple verified that he paid the developer fee, he must be the original developer. Because nobody who pays Apple would ever lie.
Anonymous · 2026-07-24 08:03 [#11882] [report]
>>25636
Never, because it's irrelevant if the official developer is the distributor or not as long as the software is not maliciously tampered with.

Software distribution is all about trust no matter how you look at it. Signatures and certificates just help you know if your software is always coming from the same source that you already trust.
Anonymous · 2026-07-24 08:04 [#11883] [report]
>>25610
>dnf
Don't compare Apples bullshit with a Linux repository! They work fundamentally different.
The signing keys in dnf verify that it's coming from the official repository, even if the distributing server is some random university that donates resources. The Fedora repository only consists of vetted package maintainers who all had to go through some elaborate process where other maintainers had to vow for them. There are 300 of those.

Meanwhile the signature check that Apple does only verifies that the key is from someone who paid the Apple fee, which is over 30 million people, and that it went through an automatic virus scan (lol).
It is YOUR responsibility to check if this app comes from upstream or has upstream approval. Nobody else can do that for you. YOU have to check that.
Therefor the question is justified: Did you ever do that?
If you don't, the signature might as well not exist.
Anonymous · 2026-07-24 08:07 [#11884] [report]
kek librewolf screeching about muh apple signature being useless hasn't bothered to get into the official dnf either, you need to add his own third party repo
Anonymous · 2026-07-24 08:12 [#11885] [report]
>>25641
Which is why you should just use Flatpak on Linux. Librewolf is verified there.
Anonymous · 2026-07-24 08:18 [#11886] [report]
>>25639
>because it's irrelevant if the official developer is the distributor or not as long as the software is not maliciously tampered with
...which is trust that you can give to a small circle of vetted package maintainers of a linux repository, but not trust that you can give to some random ass person who paid the Apple fee.

At that point you are just installing random software from a random person and the signing did absolutely nothing to make you secure.
Anonymous · 2026-07-24 08:28 [#11887] [report]
>>25626
it obviously depends on what Apple chooses their verification process to entail. they could just use the same upstream public keys / signatures as everyone else, but presumably there's more to it, possibly real identities being tied to it, judging from the resistance that this initiative has been met with.
Anonymous · 2026-07-24 08:30 [#11888] [report]
>>25580
>>25603
Not to this extent. Microsoft has a "be careful bro" warning or might false flag it as a virus if it does something out of the ordinary. Android just has an "I know what I'm doing" checkbox buried in the system. On Linux it's integrated in your package manager so it doesn't update if the domain gets hijacked.
Anonymous · 2026-07-24 08:33 [#11889] [report]
>>25643
>which is trust that you can give to a small circle of vetted package maintainers of a linux repository
who says I trust them either?

>At that point you are just installing random software from a random person
that's exactly how installing any software works

>the signing did absolutely nothing to make you secure.
it does prevent me from accidentally installing something from a different source

>>25645
>Android just has an "I know what I'm doing" checkbox buried in the system.
yes and no. as previously stated, android blocks you from installing the same app with a different signature on top of an existing app.
Anonymous · 2026-07-24 08:36 [#11890] [report]
>nooo why would the wholesome multinational company betray me like this
your favourite companies are NOT immune
Anonymous · 2026-07-24 08:44 [#11891] [report]
>>25646
>who says I trust them either?
Then you don't install their distribution and go with a different one of those thousands out there.
If you don't trust Microsoft, you shouldn't install Windows.
If you don't trust Apple, you shouldn't use MacOs.
It's the most basic level of trust you can't get around.
>actually, signing is pointless anyway
ok...
Anonymous · 2026-07-24 08:46 [#11892] [report]
>>25644
>depends on what Apple chooses their verification process to entail
what it entails already got mentioned multiple times:
>paid money and went through an automated malware scan
This is what your signature verification guarantees you, not more and not less.
Anonymous · 2026-07-24 08:50 [#11893] [report]
>>25648
>Then you don't install their distribution
why not? I need an OS
>actually, signing is pointless anyway
never said this and this is not the case at all, signing is absolutely important and even you admitted it when it comes to linux repositories
Anonymous · 2026-07-24 08:53 [#11894] [report]
Using a Mac is owning nothing and being happy, if you want to use real browsers, use a real OS.
Anonymous · 2026-07-24 09:02 [#11895] [report]
>>25648
You can run windows fine if you dont trust ms just dont do things on it that can compromise you on them like log into an online account on the OS or use external network hardware to outright deny some outgoing datastreams
Anonymous · 2026-07-24 09:06 [#11896] [report]
>the people endlessly crying about applel are clueless about technology
how unexpected
Anonymous · 2026-07-24 09:08 [#11897] [report]
>>25650
>why not? I need an OS
You will have to chose a distributor to trust.
The thought that you could run Windows without trusting Microsoft, Mac without trusting Apple or Android without trusting Google is ridiculous and dumb. And it's only spread by corporate drones and goycattle who cope about their serfdom.
You don't trust Fedora maintainers? Then don't use Fedora.
>i didn't say that
if you reduce the purpose of a signature to "the one who signed the update is the same who signed the initall software i installed", the signature might as well not exist. You can achieve the same thing without signing. You could install an unsigned exe from a website that uses SSL and ACME-CAA, with an updater using the same domain, and that's it.
Anonymous · 2026-07-24 09:09 [#11898] [report]
>>25651
>use a real OS.
Like what? red star os?
Anonymous · 2026-07-24 09:12 [#11899] [report]
>>25652
Some sleeping ransomware or kill switch could work without internet connection
>MS Word nuking your system if it detects that you wrote "nigger" in a docx
you have to trust them
Anonymous · 2026-07-24 09:29 [#11900] [report]
>>25654
>security, verifiability and validation is irrelevant because you can achieve the same thing without it
great argument
Anonymous · 2026-07-24 09:32 [#11901] [report]
>>25657
>verifiability and validation
Is there even one single software that you contacted the developer for to compare signing keys?
Anonymous · 2026-07-24 09:49 [#11903] [report]
>>25658
of course
Anonymous · 2026-07-24 11:18 [#11907] [report]
>>25576
Because ublock and ads.
Manifest3 is a cardinal steps of the antiworld to come.
Anonymous · 2026-07-24 11:37 [#11909] [report]
>>25576
>it does not pass the macOS Gatekeeper check
lol
Anonymous · 2026-07-24 12:52 [#11917] [report]
>>25576
>they have no fucking right to prevent me from using libre software
They have every right. It is their system. You don't like it? Leave.
Anonymous · 2026-07-24 12:56 [#11918] [report]
>>25612
>zased

Reply


formatting guide

max 5 MB; images get thumbnails.