LibreWolf Returns to macOS through Homebrew
LibreWolf is back on macOS. I was happy to see it can be installed through Homebrew again. In fact, it’s easier to install than ever, as it is now fully recognized by macOS’s Gatekeeper — no need for the awkward --no-quarantine option that was once needed to skip Gatekeeper and then later became the reason it was no longer supported.
I discussed LibreWolf and its installation issues on macOS before. The short version: The LibreWolf maintainers refuse to buy a developer account membership from Apple (basically $100 a year), which is understandable. Unfortunately, if you don’t pay to join the Apple club you don’t get a developer ID and you don’t get an Apple certificate. Without those, the user gets a misleading message saying the app is flagged as “damaged” and that they should move it to the trash.
However, if you try to download and install LibreWolf through Homebrew now it works just fine.
Have the maintainers caved in and paid Apple? Not at all. They used OSSign, which now offers an option to purchase licenses from Apple for FOSS projects like LibreWolf (they are not receiving new applicants for the time being, but those who already signed up like LibreWolf are already in the program to stay). It is effectively what Let’s Encrypt does for Indieweb folks to obtain HTTPS certificates, like the one on the blog you’re reading right now (which I get through Micro.blog).
- The “damaged” message is misleading because it’s a fraction of a potential truth. Apple requires developers to pay a yearly fee to get a license. The other part Apple does is a scan for malicious software (malware), which happens on Apple’s servers. But to upload to Apple’s servers, the developer needs the license first. On macOS, Gatekeeper checks for a license and for a notarization ticket — the approval from Apple’s servers that the software is “free of known malicious content, and hasn’t been altered.” In the case of LibreWolf, because the developers refused to join Apple’s paid developer program, LibreWolf never got the chance to be uploaded to Apple for a scan — it was rejected outright. To call such software damaged then is a big stretch. This is exactly the kind of lack of transparency I dislike about Apple.