OS X Mountain Lion Limits Apps to Mac App Store, Signed Apps by Default

One of the significant new features in OS X Mountain Lion is Gatekeeper, a new security system to help keep users from installing nefarious applications on their machines.

The new system relies not only on Mac App Store distribution as means of vetting apps, but also on a new "identified developer" program under which developers distributing their applications outside of the Mac App Store can register with Apple and receive a personalized certificate they can use to sign their applications. Apple can then use that system to track developers and disable their certificates if malicious activity is detected.

gatekeeper preferences
As Macworld notes in its review of Gatekeeper, OS X Mountain Lion's default setting will be to only allow initial launching of apps either downloaded from the Mac App Store or which are digitally signed under Apple's identified developer program. Users will be able to access Gatekeeper's settings in the Security & Privacy section of System Preferences, where they will also be able to choose from an even stricter setting that will allow for installation of Mac App Store apps only or a looser setting that will allow all applications to be installed and launched.

Located in the General tab of the Security & Privacy preference pane is a setting called “Allow applications downloaded from,” with three options:

Anywhere: This choice uses the same set of rules as every previous version of Mac OS X. If an app isn’t known malware and you approve it, it opens.

Mac App Store: When this choice is selected, any apps not downloaded from the Mac App Store will be rejected when you try to launch them.

Mac App Store and identified developers: This is the new default setting in Mountain Lion. In addition to Mac App Store apps, it also allows any third-party apps that have been signed by an identified developer to run.

For users on the default setting, they can bypass the initial Gatekeeper check the first time they launch an unsigned third-party app by right clicking on the app itself and choosing the "Open" command. Once the application has been opened one time, Gatekeeper no longer has any control over it.

As for apps that are signed by an identified developer, Macworld notes that OS X Mountain Lion will perform a daily check with Apple's servers for blacklisted developer signatures, and if an app from a blacklisted developer is installed on the user's system it will not open.

Importantly, Apple's identified developer program does not involve any sort of vetting on Apple's part, as certificates are automatically issued upon request and can be freely used by the developers. But what the program does do is provide a way for Apple to link specific developers to specific apps and use Gatekeeper to revoke application functionality should a developer be discovered to be distributing malware.

Top Rated Comments

KingJosh Avatar
122 months ago
Why do some people take half the facts and cry?
Score: 32 Votes (Like | Disagree)
GenesisST Avatar
122 months ago
Well we all knew this was coming. After Mountain Lion we'll have to jailbreak to run apps from outside the App Store.

No we won't. You just need to turn down the setting to allow all apps.
Score: 22 Votes (Like | Disagree)
ppilone Avatar
122 months ago
I knew I shouldn't have looked at this thread... immediately full of "Goodbye OS X" posts.

Gatekeeper really does seem like an intelligent approach to security in OS X. If anything, I think it re-affirms that OS X will not be Mac App Store only for the foreseeable future. Apple is giving developers an opportunity to play nice, without all the headache and restrictions placed on distributing through the Mac App Store.

Gatekeeper, IMHO, feels like a "we get it - it's not iOS" from Apple. In fact, I'm hoping for Gatekeeper to show up in iOS 6.
Score: 18 Votes (Like | Disagree)
GenesisST Avatar
122 months ago
Why do some people take half the facts and cry?

Complaining is fun! :D
Score: 16 Votes (Like | Disagree)
dethmaShine Avatar
122 months ago
Image (http://obamapacman.com/wp-content/uploads/2011/02/Bill-Gates-Big-Brother-Apple-1984.jpg)
********.

You may wanna go and check the Gatekeeper developer meaning again.

As much as a geek I am, I am probably gonna run the OS in Mac App Store only Gatekeeper mode and revert to Anywhere when I need to install some stuff on the web.

This is the best Apple can do for the very vast number of users. Caters to us geeks, caters to normal people and caters to those who don't know the **** they are doing.

This is unbelievably awesome.


Well we all knew this was coming. After Mountain Lion we'll have to jailbreak to run apps from outside the App Store.
On the contrary, this is evidence that Apple is NOT going to close the Mac. Things cannot be much more obvious for those who really wish to see without bias and hatred.

Short story for those interested:
Just a couple of days back, one of my friends referred to this concept in general and I was so blown away (shame I couldn't figure out myself). This also prevented Apple from changing the underlying UNIX system to an extent where they would revoke installation permissions from the user or admin or even the super-user. Maybe an additional private kernel model only used for app installations.

This is absolutely surreal. Best ****in feature ever. People don't realise this but this makes me believe that Apple is running for the geeks too. Long live Apple.
Score: 13 Votes (Like | Disagree)
deputy_doofy Avatar
122 months ago
Yes, in Mountain Lion. But I was saying that Apple will silently phase that out in the next release.

I will remain an optimist for now. In some respects, I like the GateKeeper concept. However, if Apple removes (or hides) the "anywhere" feature in 10.9 or higher, I will re-think my OS of choice (but *still* won't consider Windows). When malware can get onto my machine and install like machine-gun fire (this is on a corporate network with "enterprise-level" anti-malware software) when I don't even have admin access myself to install anything, MS will never have my business. I guess I'll revisit (and learn) Linux at that point.
Score: 10 Votes (Like | Disagree)

Top Stories

16 inch macbook pro m2 render

When Can We Expect the Redesigned MacBook Pros Now?

Wednesday June 16, 2021 7:11 am PDT by
With no sign of redesigned MacBook Pro models at this year's WWDC, when can customers expect the much-anticipated new models to launch? A number of reports, including investor notes from Morgan Stanley and Wedbush analysts, claimed that new MacBook Pro models would be coming during this year's WWDC. This did not happen, much to the disappointment of MacBook Pro fans, who have been...
2021 back t0 school

Apple Launches 2021 Back to School Promotion: Free AirPods With Eligible Mac or iPad Purchase

Thursday June 17, 2021 4:56 am PDT by
Apple today launched its seasonal back-to-school sale for the upcoming school year in the United States and Canada, offering students free AirPods alongside purchases of select Macs and iPad models. Similar to last year's promotion, this year's offer includes free AirPods alongside the purchase of a MacBook Air, MacBook Pro, the new 24-inch iMac, the Mac Pro, Mac mini, and the new M1-powered ...
maxresdefault

Apple CEO Tim Cook: Sideloading Apps Would 'Destroy the Security' of the iPhone

Wednesday June 16, 2021 10:49 am PDT by
Apple CEO Tim Cook this morning participated in a virtual interview at the VivaTech conference, which is described as Europe's biggest startup and tech event. Cook was interviewed by Guillaume Lacroix, CEO and founder of Brut, a media company that creates short-form video content. Much of the discussion centered on privacy, as it often does in interviews that Cook participates in. He...
YouTube Picture in Picture Feature

YouTube Says iOS Picture-in-Picture Coming to All US Users

Friday June 18, 2021 9:41 am PDT by
After a long wait, YouTube for iOS is officially gaining picture-in-picture support, allowing all users, non-premium and premium subscribers, to close the YouTube app and continue watching their video in a small pop-up window. In a statement to MacRumors, YouTube says that picture-in-picture is currently rolling out to all premium subscribers on iOS and that a larger rollout to all US iOS...
applecare lower prices

Apple Lowers Prices of AppleCare+ Plans for M1 MacBook Air and MacBook Pro

Thursday June 17, 2021 7:33 am PDT by
Apple today lowered the prices of AppleCare+ plans for MacBook Air and 13-inch MacBook Pro models equipped with the M1 chip. Coverage offered by the plans, as well as accidental damage fees, appear to remain unchanged. In the United States, AppleCare+ for the MacBook Air now costs $199, down from $249. The new price applies to both M1 and Intel-based MacBook Air models, although Apple no...
m1 v intel thumb

Intel Processor Market Share May Fall to New Low Next Year Due to Apple Silicon

Friday June 18, 2021 2:06 am PDT by
Intel may see its market share fall to a new low next year, in large part thanks to Apple's decision to move away from using Intel processors in its Mac computers and instead use Apple silicon. Apple announced last year that it would embark on a two-year-long journey to transition all of its Mac computers, both desktops, and laptops, to use its own in-house processors. Apple is expected to...
apple watch edition series 5 ceramic black prototype

Apple Planned Black Ceramic Apple Watch Edition Series 5

Wednesday June 16, 2021 5:45 am PDT by
Apple considered offering a black version of the ceramic Apple Watch Edition Series 5, according to newly-shared images of the prototype casing. The images, shared on Twitter by the prototype collector and leaker known as "Mr. White," show a prototype black ceramic Apple Watch casing, alongside the white ceramic version. The ceramic Apple Watch Edition Series 5 was never available in a...
maxresdefault

Demo: Check Out AirPlay 2 on a Mac in macOS Monterey

Tuesday June 15, 2021 11:57 am PDT by
With macOS Monterey, Apple has introduced expanded AirPlay 2 support, so you can AirPlay content from an iPhone, iPad, or even another Mac to your main Mac. We thought we'd do a quick demo of this handy new feature in our latest YouTube video. Subscribe to the MacRumors YouTube channel for more videos. With AirPlay to Mac, you can extend or mirror an Apple device's display to a Mac, and since ...
app store blue banner

U.S. Antitrust Legislation Would Require Users to Be Able to Delete All Pre-Installed Apple Apps [Updated]

Wednesday June 16, 2021 11:26 am PDT by
Update: Bloomberg inaccurately interpreted the original comments and has since drastically changed the wording of its article. The original Bloomberg piece said that Apple would be prohibited from pre-installing its own apps on iPhones. The updated Bloomberg article has been rewritten to clarify that the antitrust legislation prohibits Apple from preventing users from removing Apple-created...
3nm apple silicon feature

Apple Supplier TSMC Readies 3nm Chip Production for Second Half of 2022

Friday June 18, 2021 6:59 am PDT by
Apple supplier TSMC is preparing to produce 3nm chips in the second half of 2022, and in the coming months, the supplier will begin production of 4nm chips, according to a new report from DigiTimes. Apple had previously booked the initial capacity of TSMC's 4nm chip production for future Macs and more recently ordered TSMC to begin production of the A15 chip for the upcoming iPhone 13,...