Live data from Hacker News

macOS has checked app signatures online for over 2 years

eclecticlight.co

21–30 of 458 posts

Re: macOS has checked app signatures online for over 2 years

#21

The only charitable understanding of this program is that Apple has no actual table connecting software to hashes, but that they could use the information to understand outbreaks of botnets/spyware that they could then help inform ISPs/global law enforcement to help stop. Is this even reasonable?

The requests contain only app hashes. They do not contain the unique hardware identifier that Apple computers have. They do not contain your Apple ID, identifying you as a user.

Why would you not interpret this charitably as them not actually trying to spy on you? If they wanted to spy on you, why on Earth would they not send the actual valuable information?

Re: macOS has checked app signatures online for over 2 years

#23

Any opt out protection racket should be illegal. Even if it is "anonymous", someone could be identified from their behavioural patterns which are unique to each human. I hope that Apple gets at least hundred billion fine for such brazen violation of privacy so they will learn their lesson and they should be ordered to delete all personal data they don't have legitimate business need for.

Why would they try to identify you from your "behavioural patterns", when they already have the device identifier and your Apple ID, which identify you are your computer uniquely?

Which, to be very specific, they _do not send_. They COULD identify you extremely easily, and they specifically chose not to do that.

Re: macOS has checked app signatures online for over 2 years

#24
post #9
post #2

A common refrain in arguments that we don't need laws to protect privacy is that the market will take care of it. The market can't act against what it can't see. Privacy loss is often irreversible. A common refrain in arguments that we don't need to reject closed source software to protect privacy is that being closed source doesn't hide the behaviour, and people will still notice backdoors and privacy leaks. Sometim…

> The market can't act against what it can't see. Privacy loss is often irreversible. You're not wrong, but on the other hand has "the market" shown any serious signal that it cares about privacy? From what I can see people seem more than glad to trade privacy and personal information for free services and cheaper hardware. Take Samsung putting ads on their "smart" TV's UI and screenshotting what people are watching…

>that's been known for a while now

Ask a representative sample and I wager only a very small percentage of people are actually aware of (1) the breaches of privacy that are happening (e.g. your TV sending mic dumps and screenshots of what you're watching), and (2) the hard consequences of those invasions (that is, beyond the immediate fact that you're being snooped upon), like higher insurance premiums on auto and health, being targeted by your opinions, etc.

Re: macOS has checked app signatures online for over 2 years

#25
Interesting, but reading the conclusion I'm fascinated in this affaire how technically knowledgeable people loose common sense to defend their favorite brand: - Per launch verification is terrible for privacy, vis-a-vis Apple and the whole network when it happens in plain text - "They should also explain how, having enjoyed their benefits for a couple of years, they’ve suddenly decided they were such a bad idea after all", another key issue: user information, consent and control. - Additionally, the public was made aware because it malfunctioned, which is also a security issue. - Considering the current corporate culture, there are legitimate concerns of what those choices might lead towards

Re: macOS has checked app signatures online for over 2 years

#26
post #2

A common refrain in arguments that we don't need laws to protect privacy is that the market will take care of it. The market can't act against what it can't see. Privacy loss is often irreversible. A common refrain in arguments that we don't need to reject closed source software to protect privacy is that being closed source doesn't hide the behaviour, and people will still notice backdoors and privacy leaks. Sometim…

which IETF drafts and patents? Can you point me to some links?

tia

Re: macOS has checked app signatures online for over 2 years

#27

The only charitable understanding of this program is that Apple has no actual table connecting software to hashes, but that they could use the information to understand outbreaks of botnets/spyware that they could then help inform ISPs/global law enforcement to help stop. Is this even reasonable?

The requests contain only app hashes. They do not contain the unique hardware identifier that Apple computers have. They do not contain your Apple ID, identifying you as a user. Why would you not interpret this charitably as them not actually trying to spy on you? If they wanted to spy on you, why on Earth would they not send the actual valuable information?

Is it even app hashes, or developer certificate hashes?

Re: macOS has checked app signatures online for over 2 years

#28

How does Windows check executables? I hope they don't do the same. Does it come with a master list of public keys from manufacturers to check the signature against? How does that work for new vendors?

>Does it come with a master list of public keys from manufacturers to check the signature against? That won't handle revocations.

It will if you update it frequently.

Re: macOS has checked app signatures online for over 2 years

#29
post #2

A common refrain in arguments that we don't need laws to protect privacy is that the market will take care of it. The market can't act against what it can't see. Privacy loss is often irreversible. A common refrain in arguments that we don't need to reject closed source software to protect privacy is that being closed source doesn't hide the behaviour, and people will still notice backdoors and privacy leaks. Sometim…

> A common refrain in arguments that we don't need laws to protect privacy is that the market will take care of it

Seriously, who has ever been successful at defending that idea ?

Re: macOS has checked app signatures online for over 2 years

#30
post #17

Another fun fact about this system: something changed in how the binaries are evaluated and one VST plugins I've downloaded months ago was marked as malware. The plugin is quite popular in community so I think it's unlikely it contains actual malicious code (in fact I've contacted the developer and he said he has done some fixes for Apple's security policies recently). Imagine my shock when I open an old project in A…

It's been good practice for a long time to "freeze" or "render" the tracks out after the song is finished so that the song can be loaded without the plugins.
Post reply on HN