Ghostmoon.app – The Swiss Army Knife for your macOS menu bar
87 points
2 hours ago
| 20 comments
| mgrunwald.com
| HN
ctmnt
2 hours ago
[-]
This looks cool enough, but it’s starting to drive me crazy how people are in such a rush to put out their macOS apps they can’t be bothered to get a developer account and run a one line command. It’s not hard.

I used to be sympathetic to complaints about not wanting to pay the developer account fee. But when you’re vibe coding, you’re probably paying a good chunk of change to your LLM supplier of choice every month, and the yearly developer account fee seems minor in comparison

Also, it’s just such a bad security precedent. This page describes the error you get as “the typical macOS Gatekeeper warning”, as though it were just another piece of corporate silliness, like clicking through a EULA.

reply
0x3f
1 hour ago
[-]
If you don't want your name, address, phone number on public display you need to either set up a company or set up some forwarding. If you set up a company, you'll need to get a DUNS number. If you haven't done it before and don't know about the secret shortcut way to do that, it is very annoying to get one.

Anyway, I don't see a problem with getting it out the door. People can just choose not to install it if they don't like it. I mean that's the whole idea of being early anyway, isn't it? Don't like a crappy bodged together UI? Don't like a lack of support? Don't like an unsigned app? You can wait until it has those things according to your preferences. In the meantime, the creator gets real users and feedback ASAP.

reply
mgrunwald_
1 hour ago
[-]
Thank you for saying this! As stated on the website, this is a pre-release. Those who are not sure, absolutely do not have to install this and can wait for the official, notarized release. In the meantime, the app gets tested in the real world.
reply
mcjiggerlog
1 hour ago
[-]
You don't need to do any of that to sign and notarize an app that you are distributing yourself.
reply
coffeecantcode
38 minutes ago
[-]
Still unbelievable that they require a DUNS number and not a simple EIN, that fact alone set our app launch back weeks.
reply
vyaa
1 hour ago
[-]
Secret shortcut?!?
reply
michaelmior
51 minutes ago
[-]
This article[0] provides some details. Basically if you go through the lookup process on Apple's website and you don't have an existing D-U-N-S number, you can request one from D&B for free via Apple.

[0] https://support.pushpay.com/s/article/Acquire-your-D-U-N-S-n...

reply
0x3f
1 hour ago
[-]
I don't know how obvious it is these days, but the default path through D&B's website is the terrible one. They will try to extract money from you and harass you forever. You had to find Apple's own embedded form for it by using their search and going through some flow.
reply
jrmg
57 minutes ago
[-]
don't want your name, address, phone number on public display

Where are these displayed?

reply
marci
46 minutes ago
[-]
when you sign an app with your personal dev account.
reply
throwaway290
1 hour ago
[-]
It's free so why not just publish it on github then so that people could read the code and compile it themselves.

Right now it's closed source binary with a big fat "DOWNLOAD FOR FREE" button and instructions casually telling you to disable the last barrier between your system and persistent malware. Nobody should recommend this to anybody

reply
0x3f
1 hour ago
[-]
Well, depends what the author's plans are for the future. Maybe it's not always going to be free as in beer, either.
reply
moralestapia
1 hour ago
[-]
>secret shortcut

I see vagueposting has found its way into HN.

reply
0x3f
1 hour ago
[-]
I haven't done it in a while, so didn't want to give out possibly wrong directions, but:

> I don't know how obvious it is these days, but the default path through D&B's website is the terrible one. They will try to extract money from you and harass you forever. You had to find Apple's own embedded form for it by using their search and going through some flow.

reply
mgrunwald_
1 hour ago
[-]
Gatekeeper and notarization are not silliness. They exist for a reason. I thought it would be a good idea to release the app during development when I am sure that it works correctly and then maybe get some feedback from early users.
reply
LatencyKills
1 hour ago
[-]
Ex-Apple macOS/Xcode dev here.

I just downloaded your app and ran it through hopper. There is a LOT of embedded Apple Script. I would never run an app like this with SIP disabled or without an active network blocker.

Your app requires direct access to major OS components: code signing, even during alpha should be a requirement.

reply
s3p
1 hour ago
[-]
I guess OP's point is still pretty valid though, what's the harm in signing and notarizing it?
reply
71bw
2 hours ago
[-]
The truth is that Gatekeeper should go the way of the devil.

It is my machine and I paid for it, why does the OS care about what I do with it? The only thing this leads to is making sure your customers grow into good little lemmings.

reply
piva00
1 hour ago
[-]
You can do whatever you want if you are a power user, the tools are there to get around Gatekeeper.

For everyone else it's probably sane to have it, works as a decent filter so someone not tech-savvy don't get hurt by installing malware disguised as an app, one would just need to state incredible features that almost any normal user would like to have, and make them click to install. Gatekeeper diminishes that risk by a lot unless you learn how to bypass it, which requires you having decent skills and probably wouldn't fall for the bullshit that malware apps try to bait people with.

reply
leshenka
23 minutes ago
[-]
I really don't understand what the issue is? Gatekeeper is merely a warning that introduces a minimal friction if what are you trying to run is created by an entity that chose not to present itself. It only happens once per application, not per launch. I've spent more time reading this thread than I have removing quarantine flags in the last five years.

Apple has a lot to be criticized for but gatekeeper (and SIP) isn't that.

reply
jacobrast
1 hour ago
[-]
So that you don't accidentally run malware. MacOS is not iOS, you can run unsigned code if you really want to, but it will make you jump through a few hoops.
reply
71bw
1 hour ago
[-]
How is this better than trying to eliminate the problem between the keyboard and the computer? The user won't learn if the computer handholds them through everything.
reply
piva00
31 minutes ago
[-]
The user also shouldn't need to potentially suffer massive financial impacts from not being good enough at using a computer... Even more if it's a problem that can be solved by the computer itself as it's done already.

It's like you are saying that potentially dangerous tools shouldn't have safety guards whenever possible, with little impact for the common use of the tool. Kinda absurd to think that way... If some advanced use-cases require safety guards to be removed that's when the user should be trained enough to know the risks.

People want to use a computer for their tasks, the whole motto of Apple was to make technology accessible to normal people without requiring them to be tech-savvy, what you want goes in complete opposition to that mission.

reply
anamexis
1 hour ago
[-]
Because the vast majority of users have no interest in learning how to safely vet apps and just want to easily use their computers and not worry about malware.
reply
alsetmusic
1 hour ago
[-]
> The user won't learn

Full stop. I still talk to people every working day who don't realize that rebooting a computer is actually a real troubleshooting step. They seem to think it's bunk tech support mumbo jumbo rather than a genuinely useful step. It's 2026 and they're still surprised when that works.

reply
newsclues
1 hour ago
[-]
I want to be a power user on my Mac, I don’t want my mom’s Mac to function like my devbox.

People like and need the apple sandbox. Others need an unlocked *nix machines

reply
TeMPOraL
1 hour ago
[-]
It's fine as long as both exist and third parties are not allowed to know which one you're running.

Otherwise, you have banks and MAFIAA and others off-loading their own security and compliance costs to users by flat out discriminating based on the status of the sandbox.

reply
seany
6 minutes ago
[-]
Gatekeeper should be banned. It's my machine, let me use it
reply
karimf
1 hour ago
[-]
Totally agree. There are significantly more new apps being released. I've been visiting the /r/macapps subreddit and they're having trouble filtering new submissions. I generally like the direction that they're taking https://www.reddit.com/r/macapps/comments/1ryaeex/rmacapps_m...

Even though it's more troublesome to submit apps to App Store, it's one signal that the app is not a malware.

reply
g947o
34 minutes ago
[-]
Wow, this subreddit looks like the apocalypse of vibe coded projects/apps. Kind of similar to what happened to "show HN". Too many ideas, not enough problems to solve, and likely bad implementations. The result is that nobody uses any of the apps.

In AI conversations, people often forget that at the end of a day, an actual human needs to use your stuff.

reply
thisislife2
29 minutes ago
[-]
> they can’t be bothered to get a developer account and run a one line command

I applaud that they didn't kowtow to Apple's attempt to exercise control over their app and extort money from them. Why should we accede to policies that are designed to exploit us developers?

We developers add the real value to a platform. Don't believe me? Look up on how popular Sailfish OS or Windows Mobile OS is and why they failed or struggle. Apple should be grateful to this developer that they seek to add value to their platform instead of trying to figure out money grubbing ways on how to control and exploit them. (Of course, ultimately it is the users of the platform who are exploited - all charges by Apple are ultimately bore by them when they purchase an app through the App Store).

It's just sad that whether you are a user or a developer, Apple Fanbois would rather (ignorantly) place Apple's interest over their own consumer rights.

reply
eviks
1 hour ago
[-]
> and the yearly developer account fee seems minor in comparison

Do you not realize that spending money on other useful services makes it harder, not easier, to waste on dev fees?

reply
user3939382
1 hour ago
[-]
Gatekeeper is a travesty and assault on user freedom. Apple should not be in charge of what you run on your computer, at all. Any exception to this should be opt in. If a user wants to insert a third party between themselves and a programmer they can elect to do that.

Let’s not forget when Apple’s certificate server was down and suddenly you couldn’t launch apps on macOS, to say nothing of the abuse of user rights.

reply
drfloyd51
1 hour ago
[-]
Users used their freedom to choose macOS. Gatekeeper is a desirable feature. They opted-in with their purchase.
reply
foltik
1 hour ago
[-]
Speak for yourself, I used my freedom to disable it.
reply
hspmn
1 hour ago
[-]
you're saying security should be optional and up to users?

lol

reply
foltik
1 hour ago
[-]
Except it is just another piece of corporate silliness.

Why don’t you purchase your own developer account and sign it yourself if you trust it? Or are you saying them paying Apple $100/yr in perpetuity is what will make you trust it?

reply
nehal3m
2 hours ago
[-]
Hmm, green account, no comments or submissions, generated website for an unsigned app with power user features. That’s a no from me dawg.
reply
foltik
1 hour ago
[-]
You forgot closed source. It’s a closed source dropdown menu.
reply
xattt
2 hours ago
[-]
There are only two donors, and one of them sounds like an Amazon review?
reply
mgrunwald_
1 hour ago
[-]
The donors are 100% real, early supporters of the app.
reply
mgrunwald_
1 hour ago
[-]
Understandable! This is a pre-release of the app. You can come back later when everything is in place and the app is officially released, signed and notarized :)
reply
nehal3m
1 hour ago
[-]
The idea seems cool so I’ll keep an eye on it, but as a paranoid sysadmin I’ll wait for the flags to turn green.
reply
gsibble
1 hour ago
[-]
Yep, this is a no from me.
reply
virajk_31
1 hour ago
[-]
That should not be a problem. I also used to just skim through posts and comments here without really interacting.
reply
nehal3m
1 hour ago
[-]
It’s not a show stopper on it’s own, but taking everything together raises my eyebrows
reply
andersonpico
41 minutes ago
[-]
and if you published software here it would also be suspicious
reply
menno-dot-ai
1 hour ago
[-]
I'm getting an invalid SSL certificate too to complete the bingo card
reply
mgrunwald_
1 hour ago
[-]
The SSL certificate is issued through Cloudflare. What issues are you having?
reply
jofzar
2 hours ago
[-]
Interestingly to me this is what raycast actually is for me now. Most of my common workflows are just raycast keybinds now or quickly typed in.

An example is I have my airpods bound to ctrl+alt+b to connect via Bluetooth. This is to have it yank back control from my android phone.

reply
incanus77
23 minutes ago
[-]
A similar app in this space that I discovered recently is Supercharge.

https://sindresorhus.com/supercharge

I was skeptical that I’d find it useful since I can do all of these shell commands and such, but one feature I like is being able to effectively pare the feature set down to just what you need, making for a small but very useful menu.

reply
apples_oranges
2 hours ago
[-]
Nice, but, and this is not personal, I would not trust this app with my computer internals. Probably also asks for sudo from time to time.. but I might ask Claude to make something similar for myself.. (sorry but just being honest)
reply
mgrunwald_
1 hour ago
[-]
Understandable. Yes, it asks for sudo from time to time, but it is designed to be as safe as possible in what it does.
reply
alsetmusic
1 hour ago
[-]
I get that there's a market to put command line preferences in a GUI wrapper, but wasn't HN going to limit posts from new accounts? Oh, it's not in Show HN. They found a loophole.

Meanwhile, I'm running Claude Code and asking it to make me stupid bespoke things that only I want and I'm not spamming the internet with those tools because they aren't novel or useful for most people and you can have Claude Code build a version for the way that you work.

Go away, green accounts. Everyone is pretty tired of your presence.

reply
mgrunwald_
1 hour ago
[-]
Not really just command line preferences. The app has many more features that use native macOS APIs. But thanks for your comment!
reply
heavyshark
18 minutes ago
[-]
This looks cool but I'd probably always prefer Raycast over this. The menubar gets crowded enough even with Ice, Bartender etc...
reply
RicDan
1 hour ago
[-]
Interesting how posts like these seem to be catapulted to #1 spot so quickly
reply
geerlingguy
1 hour ago
[-]
Along with a number of posts praising the "website design". Besides novel designs (I think of Acko.net) it's not often I see comments on that here.
reply
mgrunwald_
37 minutes ago
[-]
As the original poster and creator I am actually a little surprised, too!
reply
vivid242
2 hours ago
[-]
Lovely! Would appreciate a release via the App Store / notarization or so… is there a newsletter so I could get notified?
reply
antryu
1 hour ago
[-]
The pricing debate is interesting. I'm running a similar service and found that giving away as much as possible for free helps build initial trust — getting people to actually try it once is the hardest part.

Pre-release feedback from the community is definitely valuable though. I didn't know this part is the most diffcult.

reply
pieterhg
1 hour ago
[-]
Awesome. Can you add extra bright mode like Vivid? I'd love to get rid of Vivid cause it's so buggy and never re-enables after I close my MacBook Pro
reply
lukifer
46 minutes ago
[-]
Cool! Disappointing there's so much focus on the non-sandboxing, I think it's a reasonable trade-off to release early, and follow up with signing later.

- Website looks great overall, but the fixed and overlaid header title is awkward and hurts readability for not much benefit.

- Battery Health on my M3 Max MBP reads as "1%", when System Report shows Condition: Normal, Maximum Capacity: 100%. What is this reading from?

- Handy password generator is great; any chance of an option for "correct horse" [0] style passwords? I find these are preferable for reasonably secure passwords which can still be remembered or hand-typed as needed.

Looking forward to seeing how the app evolves!

[0] https://www.correcthorsebatterystaple.net

reply
qn9n
1 hour ago
[-]
This is cool but most of this stuff for me is just set and forget, I rarely need to change those things so frequently I need it in my menu bar.
reply
fouc
1 hour ago
[-]
in your "demo" image the menu bar is completely missing.. this seems like a very confusing choice. I can barely make out the menu bar icon against the background image.
reply
woadwarrior01
2 hours ago
[-]
This reminds of a similar windows shareware system tray app from ~25 years ago called Genius.
reply
gsibble
1 hour ago
[-]
Yeah, I'm not trusting some app like that randomly on my computer.
reply
mgrunwald_
1 hour ago
[-]
Understandable! You can come back later when everything is in place and the app is officially released, signed and notarized :)
reply
andersonpico
40 minutes ago
[-]
vibe coded bullshit; also why is it top of the front page? are we botting votes now?
reply
mgrunwald_
31 minutes ago
[-]
I understand your skepticism, but as the original poster and creator of this I am actually a little surprised, too!
reply
sosuke
1 hour ago
[-]
Unrelated to the app but I dig your website design.
reply
mgrunwald_
32 minutes ago
[-]
Thanks!
reply
subdomain
2 hours ago
[-]
Seems really useful -- I love the website design!
reply
mgrunwald_
1 hour ago
[-]
I'm very glad you like it! Thanks!
reply
vladde
1 hour ago
[-]
the website design is cool as h*ck
reply
mgrunwald_
1 hour ago
[-]
Thanks!
reply