The Talk Show with John Gruber
The Talk Show with John Gruber

257: ‘A Beautiful Sandwich’ With Daniel Jalkut

Special guest Daniel Jalkut returns to the show. Topics include app notarization, nonconsensual technology (including Zoom, Dropbox, and Superhuman), and more.

Featured Speakers

John Gruber Host

Topics Discussed

Episode Summary

Executive Summary: The conversation centers on how Apple’s tightening Mac security measures—especially notarization and Gatekeeper—are changing software distribution, often forcing developers into unwanted App Store-adjacent compliance. It broadens into a critique of “non-consensual technology,” using Zoom, Dropbox, and email tracking pixels as examples of products that override user intent or privacy, and argues that modern platforms should protect users more aggressively without breaking legitimate workflows.

Main Topics: Mac notarization, Gatekeeper, and developer autonomy (Priority: 5/5): Discussion of Apple’s notarization system for Mac apps, how it works through App Store infrastructure, and why it may unintentionally force non–App Store developers to accept App Store terms to ship software directly. Security vs. usability on macOS (Priority: 5/5): The speakers debate Apple’s security hardening on Catalina and beyond, noting that while the protections help typical users, they increasingly inconvenience power users, scripters, and developers with legitimate advanced workflows. “Non-consensual technology” and product ethics (Priority: 5/5): A broader theme emerges around software that does things users did not explicitly authorize, from Zoom’s hidden localhost server to Dropbox’s background behavior and email clients’ tracking capabilities. Zoom’s deceptive install behavior (Priority: 4/5): Zoom is criticized for installing a persistent local web server and for enabling reinstall/auto-launch behavior even after deletion, with the discussion framing this as a serious ethical breach despite product popularity. Dropbox’s shift from utility to platform bloat (Priority: 4/5): Dropbox is praised for its original elegant sync model but criticized for adding intrusive features, kernel extensions, and broader platform ambitions that undermine its simplicity and trust. Email privacy and read-tracking abuse (Priority: 5/5): The talk examines Superhuman and email tracking pixels, arguing that invisible read receipts are fundamentally contrary to the spirit of email and should be blocked by mail clients or providers. Apple’s role as privacy gatekeeper (Priority: 4/5): The speakers consider whether Apple should apply Safari-like privacy protections to Mail and broader web/email content handling, potentially proxying remote resources to prevent tracking while preserving useful features.

Key Arguments: Apple’s notarization system may require agreement to App Store developer contracts even for apps distributed outside the App Store, which could slow or block releases for some developers. Mac security is becoming more restrictive over time; the platform is not iOS, but Apple is clearly increasing its control over what can run and how. Many security changes are justified because users and companies often underestimate real-world threats; Apple frequently sees vulnerabilities that ordinary users and even developers would miss. Zoom’s hidden localhost server and reinstall behavior are presented as an example of software crossing a moral line by persisting after deletion and bypassing user intent. Dropbox’s value came from a simple, reliable folder-sync experience, but its newer ambitions and kernel-level requests erode the trust that made it special. Email tracking via invisible pixels is a privacy violation that most users do not expect or understand, and email clients should make such tracking impossible or at least opt-in. The problem is not just individual apps like Superhuman; the entire modern email ecosystem has normalized behavior that was never part of email’s original design. Apple’s Safari team is held up as a model for proactive privacy defense, and the Mail team should adopt similarly aggressive protections. A good security model should preserve legitimate expert workflows while making abuse impossible, rather than relying on users to manually police every interaction.

Data Points: Episode number: 256 - Mentioned as a special nerdy milestone because 256 is a power-of-two/binary number. Heat index: 106°F - Described as the temperature in Philly during a heat wave. Air temperature / feels-like: 91°F / feels like 99°F - Current weather mentioned while discussing summer heat. Dropbox market cap: $10 billion - Referenced while discussing Dropbox’s size and ambitions. Twitter market cap: $28.8 billion - Used as a comparison point for market valuation and mind share. Facebook market cap: $577 billion - Used to illustrate how a $5 billion FTC fine is small relative to Facebook’s scale. FTC fine: $5 billion - Discussed as the record-breaking penalty imposed on Facebook. Fine-to-worth ratio: 1/100th - Used to argue that the Facebook fine is proportionally small relative to its net worth. Superhuman price: $30/month - Described as the subscription price for the email client front end to Gmail. Dropbox shared-folder use: 1 shared folder - The speakers note a single shared folder as the main reason to keep Dropbox installed. Ocean time under water: at least 30 seconds - A personal anecdote about being trapped underwater by a wave while growing up in Santa Cruz.

Pivotal Quotes: "non-consensual technology" — John Gruber: A phrase coined to describe software behavior that violates user intent or consent, applied to Zoom, Dropbox, and email tracking. "You're not an app. You're a feature." — Steve Jobs: Referenced in the discussion of Dropbox, illustrating how it was once seen as a simple sync utility rather than a platform. "email was never, ever, ever meant for something where, when you read a message, the person who sent it to you could tell when you did it without your compliance in any way." — John Gruber: Core argument against invisible tracking pixels and read-receipt abuse in email.

Implications: Developers may face more friction shipping Mac software, while users gain stronger default protections. The bigger lesson is that platforms and clients should prevent privacy abuses by design, not rely on users to notice and opt out.

🔓 Sign Up for Unlimited Episode Search

About The Talk Show with John Gruber

The director’s commentary track for Daring Fireball. Long digressions on Apple, technology, design, movies, and more.

View all episodes from The Talk Show with John Gruber