Live data from Hacker News

macOS has checked app signatures online for over 2 years

eclecticlight.co

31–40 of 458 posts

Re: macOS has checked app signatures online for over 2 years

#31

Honest question I'm not an expert: The initial commments in this thread are painting it as a severe privacy violation. (The actual OP article author does not necessarily share this perspetive). How is what is being done with OCSP different in more concerning way for privacy (if it is) from Firefox or Chrome's use of OCSP?

Because when you browse the Internet you know you are browsing it. When you run software, you do not expected "unexpected" Internet use.

You go for a walk, you carry an umbrella, or go dressed. You are at home, you do not expect it to "rain" or for someone to "watch you".

Re: macOS has checked app signatures online for over 2 years

#32
post #5

Is there any UI indication that OCSP checks have been consistently failing for some period of time? My concern is less local malware (if something malicious has gained the privileges to filter OCSP, it's probably already game over) but rather networks filtering ocsp.apple.com (for whatever reason).

Does it matter? Would anyone (but the most paranoid) care? My guess is that OCSP is supposed to be part of a defense in depth strategy, so it doesn't have to be 100% airtight to achieve its goals

Re: macOS has checked app signatures online for over 2 years

#33
post #29
post #2

A common refrain in arguments that we don't need laws to protect privacy is that the market will take care of it. The market can't act against what it can't see. Privacy loss is often irreversible. A common refrain in arguments that we don't need to reject closed source software to protect privacy is that being closed source doesn't hide the behaviour, and people will still notice backdoors and privacy leaks. Sometim…

> A common refrain in arguments that we don't need laws to protect privacy is that the market will take care of it Seriously, who has ever been successful at defending that idea ?

Many lobbyists and lawmakers, unfortunately.

Re: macOS has checked app signatures online for over 2 years

#34
post #9

Earlier quoted context omitted.

> The market can't act against what it can't see. Privacy loss is often irreversible. You're not wrong, but on the other hand has "the market" shown any serious signal that it cares about privacy? From what I can see people seem more than glad to trade privacy and personal information for free services and cheaper hardware. Take Samsung putting ads on their "smart" TV's UI and screenshotting what people are watching…

I hear this argument a lot but I think it is exactly OPs point when he says, “The market can’t act against what it can’t see”. Your average consumer doesn’t know the extent of what they’re trading. Take Facebook, even with high profile stories and documentaries it’s reasonable for your average consumer to assume that what Facebook tracks about them is what they actively give to Facebook themselves. I’ve had conversat…

[deleted]

Re: macOS has checked app signatures online for over 2 years

#35
post #22

The irony of arguing that the rapid rate of certificate revocations is proof of the system being necessary and secure. No, it's proof that the system is useless. Code signing is a dead end, and we have known that latest with Stuxnet.

A nation state virus that stole a cert is not a good argument against this , windows only started checking certs very recently please get your head out of the sand. It’s worked great for many years for us Mac users.

Re: macOS has checked app signatures online for over 2 years

#36

Any opt out protection racket should be illegal. Even if it is "anonymous", someone could be identified from their behavioural patterns which are unique to each human. I hope that Apple gets at least hundred billion fine for such brazen violation of privacy so they will learn their lesson and they should be ordered to delete all personal data they don't have legitimate business need for.

Why would they try to identify you from your "behavioural patterns", when they already have the device identifier and your Apple ID, which identify you are your computer uniquely? Which, to be very specific, they _do not send_. They COULD identify you extremely easily, and they specifically chose not to do that.

May be they have other channels which could or already do send device identifiter and Apple ID. How do you know what _else_ they do ?

Who knew they were sending hashes till the recent malfunctioning? What _esle_ we do not know now?

Re: macOS has checked app signatures online for over 2 years

#37

Earlier quoted context omitted.

The requests contain only app hashes. They do not contain the unique hardware identifier that Apple computers have. They do not contain your Apple ID, identifying you as a user. Why would you not interpret this charitably as them not actually trying to spy on you? If they wanted to spy on you, why on Earth would they not send the actual valuable information?

Is it even app hashes, or developer certificate hashes?

The larger the program, the longer it takes to verify the first time you run it. I can only interpret that as meaning they are basing the whole program.

Source: me, downloading and running various apps

Re: macOS has checked app signatures online for over 2 years

#38
post #25

Interesting, but reading the conclusion I'm fascinated in this affaire how technically knowledgeable people loose common sense to defend their favorite brand: - Per launch verification is terrible for privacy, vis-a-vis Apple and the whole network when it happens in plain text - "They should also explain how, having enjoyed their benefits for a couple of years, they’ve suddenly decided they were such a bad idea after…

Yeah, the article's last paragraph irks me... to reformulate it in the context of domestic spying, it'd be like saying "NSA's communication monitoring have kept you safe for years, now that you've heard of it, you decide it's a bad idea?".

Most people probably never noticed this phone-home feature existed, just like they never knew that NSA was recording everything. (Obviously anyone who bothered to look under the hood could've seen it, but hey, how many people do that).

Re: macOS has checked app signatures online for over 2 years

#39
post #24
post #9

Earlier quoted context omitted.

> The market can't act against what it can't see. Privacy loss is often irreversible. You're not wrong, but on the other hand has "the market" shown any serious signal that it cares about privacy? From what I can see people seem more than glad to trade privacy and personal information for free services and cheaper hardware. Take Samsung putting ads on their "smart" TV's UI and screenshotting what people are watching…

>that's been known for a while now Ask a representative sample and I wager only a very small percentage of people are actually aware of (1) the breaches of privacy that are happening (e.g. your TV sending mic dumps and screenshots of what you're watching), and (2) the hard consequences of those invasions (that is, beyond the immediate fact that you're being snooped upon), like higher insurance premiums on auto and he…

To be honest I would expect if you told people "your TV will report what you're watching" they will think "wait, doesn't my cable company already know what I'm watching???"

If you tell them it's the manufacturer this time in addition to the cable company, I'm not sure how many would freak out over the extra entity.

Re: macOS has checked app signatures online for over 2 years

#40

The only charitable understanding of this program is that Apple has no actual table connecting software to hashes, but that they could use the information to understand outbreaks of botnets/spyware that they could then help inform ISPs/global law enforcement to help stop. Is this even reasonable?

The requests contain only app hashes. They do not contain the unique hardware identifier that Apple computers have. They do not contain your Apple ID, identifying you as a user. Why would you not interpret this charitably as them not actually trying to spy on you? If they wanted to spy on you, why on Earth would they not send the actual valuable information?

What does that even mean? Of course they can identify you, you are knocking their door with the same IP with your iCloud account. Maybe the file you are giving them does not have your uid, but as long as you have connected your Mac to your Apple account you are uniquely identified.
Post reply on HN