Live data from Hacker News

macOS has checked app signatures online for over 2 years

eclecticlight.co

51–60 of 458 posts

Re: macOS has checked app signatures online for over 2 years

#51

Honest question I'm not an expert: The initial commments in this thread are painting it as a severe privacy violation. (The actual OP article author does not necessarily share this perspetive). How is what is being done with OCSP different in more concerning way for privacy (if it is) from Firefox or Chrome's use of OCSP?

Because when you browse the Internet you know you are browsing it. When you run software, you do not expected "unexpected" Internet use. You go for a walk, you carry an umbrella, or go dressed. You are at home, you do not expect it to "rain" or for someone to "watch you".

That seems incredibly naive. I can’t think of a single program off the top of my head that doesn’t use the Internet to some extent while running. Even many CLI tools I use for development do update checks (and sometimes analytics) in the background.

Re: macOS has checked app signatures online for over 2 years

#52
post #2

A common refrain in arguments that we don't need laws to protect privacy is that the market will take care of it. The market can't act against what it can't see. Privacy loss is often irreversible. A common refrain in arguments that we don't need to reject closed source software to protect privacy is that being closed source doesn't hide the behaviour, and people will still notice backdoors and privacy leaks. Sometim…

The market only acts fairly when the product is a commodity. The time for the market to react for a product with the complexity of a mac is decades. As the ecosystem grows, the cost of switching increases. Therefore market starts acting more and more inefficiently. This is why countries have state intervention in such cases. And anti trust exists. If the option was a mac with privacy vs a mac without privacy but $10…

Whilst I agree with the sentiment, it does occur to me just how many kindles I see with ads.

Is there any data released on ads Vs no ads versions?

That's the closest comparator I can think of.

Re: macOS has checked app signatures online for over 2 years

#53
post #51

Earlier quoted context omitted.

Because when you browse the Internet you know you are browsing it. When you run software, you do not expected "unexpected" Internet use. You go for a walk, you carry an umbrella, or go dressed. You are at home, you do not expect it to "rain" or for someone to "watch you".

That seems incredibly naive. I can’t think of a single program off the top of my head that doesn’t use the Internet to some extent while running. Even many CLI tools I use for development do update checks (and sometimes analytics) in the background.

Your choice, not mine.

Like: Houdini Emacs Latex A file manager Audacity A Terminal ... Off the tip of my head, used almost daily.

Re: macOS has checked app signatures online for over 2 years

#54
post #47

I sometimes wonder if the mods won't end up banning "political" talk on HN. Because these days everything becomes political, even if it really is a technical issue. Case to the point: online signature check was a technical decision, to fight malware. It was implemented similarly by other OS vendors (Microsoft) and it's been this way for years. Now we discover that it has the unfortunate side-effect that it lessens pr…

It's possible that the technical discussion about online signature checking was subsumed by the political discussion--the two are interrelated and if we don't get into these discussions here I don't really see another place for them to happen.

It's easy to shrug it off as simply a technical issue, and it's very convenient for the PR department as well.

Re: macOS has checked app signatures online for over 2 years

#55

"Privacy is not a feature".

Directly contradicting current Apple Marketing.

I lothe Apple(and other unethical companies) for lying in their ads.

Any benefits of macOS are instantly gone because you cannot Trust Apple to tell the truth. It's as unreliable as Google keeping a service around.

Re: macOS has checked app signatures online for over 2 years

#56

Earlier quoted context omitted.

What does that even mean? Of course they can identify you, you are knocking their door with the same IP with your iCloud account. Maybe the file you are giving them does not have your uid, but as long as you have connected your Mac to your Apple account you are uniquely identified.

Plenty of computers share a single public IP address. Plenty of computers jump IP addresses constantly. It is not at all reliable trying to tie IP addresses together that way. If they wanted the information, they would need to send it.

And Apple updates your ip continuously in their server as evidenced in the “find my” service.

Re: macOS has checked app signatures online for over 2 years

#57

The only charitable understanding of this program is that Apple has no actual table connecting software to hashes, but that they could use the information to understand outbreaks of botnets/spyware that they could then help inform ISPs/global law enforcement to help stop. Is this even reasonable?

The requests contain only app hashes. They do not contain the unique hardware identifier that Apple computers have. They do not contain your Apple ID, identifying you as a user. Why would you not interpret this charitably as them not actually trying to spy on you? If they wanted to spy on you, why on Earth would they not send the actual valuable information?

I believe you are trying to think about this rationally, but this is not the only thing going on.

When a mac boots up or changes network location, a long list of processes on your machine (like AppleIdAuthAgent, identityservicesd, , and maybe 10 or 20 more) connect to various apple servers associating your actual identity with the ip address. It will continue to do these kinds of things while you are online. And all this is interleaved with oscp requests.

Re: macOS has checked app signatures online for over 2 years

#59
post #51

Earlier quoted context omitted.

Because when you browse the Internet you know you are browsing it. When you run software, you do not expected "unexpected" Internet use. You go for a walk, you carry an umbrella, or go dressed. You are at home, you do not expect it to "rain" or for someone to "watch you".

That seems incredibly naive. I can’t think of a single program off the top of my head that doesn’t use the Internet to some extent while running. Even many CLI tools I use for development do update checks (and sometimes analytics) in the background.

All of that is of course bad. Ask around if people know their CLI tool is phoning home, most people aren't even aware. Let me control if I want to update something. Let me control what information goes out, and when.

There is just no way to defend an underhand tactic that you didn't know about. If it was so necessary and so good and so pure, why does it have to be revealed like that?

Re: macOS has checked app signatures online for over 2 years

#60
post #9

Earlier quoted context omitted.

> The market can't act against what it can't see. Privacy loss is often irreversible. You're not wrong, but on the other hand has "the market" shown any serious signal that it cares about privacy? From what I can see people seem more than glad to trade privacy and personal information for free services and cheaper hardware. Take Samsung putting ads on their "smart" TV's UI and screenshotting what people are watching…

> has "the market" shown any serious signal that it cares about privacy? Depends on what you consider a serious signal of care. If 'voting with you wallet' is the measure, increasing levels of income inequality, stagnant wages, weakening employee rights through the gig-economy, etc. are effectively taking away that choice, as most market participants cannot afford to make the choice. Also, what is the paid alternativ…

[deleted]
Post reply on HN