Live data from Hacker News

macOS has checked app signatures online for over 2 years

eclecticlight.co

61–70 of 458 posts

Re: macOS has checked app signatures online for over 2 years

#61

Earlier quoted context omitted.

What does that even mean? Of course they can identify you, you are knocking their door with the same IP with your iCloud account. Maybe the file you are giving them does not have your uid, but as long as you have connected your Mac to your Apple account you are uniquely identified.

Plenty of computers share a single public IP address. Plenty of computers jump IP addresses constantly. It is not at all reliable trying to tie IP addresses together that way. If they wanted the information, they would need to send it.

Every time you change network locations, all of these daemons contact apple again. There are plenty of push services on your machine and apple keeps track of where you are.

also ipv6

Re: macOS has checked app signatures online for over 2 years

#62
post #17

Another fun fact about this system: something changed in how the binaries are evaluated and one VST plugins I've downloaded months ago was marked as malware. The plugin is quite popular in community so I think it's unlikely it contains actual malicious code (in fact I've contacted the developer and he said he has done some fixes for Apple's security policies recently). Imagine my shock when I open an old project in A…

It's been good practice for a long time to "freeze" or "render" the tracks out after the song is finished so that the song can be loaded without the plugins.

True, but this shouldn't be necessary in response to anti-consumer behavior.

Re: macOS has checked app signatures online for over 2 years

#63

"Privacy is not a feature".

Directly contradicting current Apple Marketing. I lothe Apple(and other unethical companies) for lying in their ads. Any benefits of macOS are instantly gone because you cannot Trust Apple to tell the truth. It's as unreliable as Google keeping a service around.

I first started getting an idea that something was amiss with apple years and years ago.

"Apple machines don't get viruses"

Everyone "knew" that. Everyone knew that apple machines were secure.

Turns out there were plenty of things going on with apple just like other companies. The difference was that apple would actively persecute (even prosecute) people who explored or discovered these things. Basically apple marketing was able to prevent a lot of vulnerabilities from publicity. Probably marketing 101, protect your brand.

Re: macOS has checked app signatures online for over 2 years

#64
post #57

Earlier quoted context omitted.

The requests contain only app hashes. They do not contain the unique hardware identifier that Apple computers have. They do not contain your Apple ID, identifying you as a user. Why would you not interpret this charitably as them not actually trying to spy on you? If they wanted to spy on you, why on Earth would they not send the actual valuable information?

I believe you are trying to think about this rationally, but this is not the only thing going on. When a mac boots up or changes network location, a long list of processes on your machine (like AppleIdAuthAgent, identityservicesd, , and maybe 10 or 20 more) connect to various apple servers associating your actual identity with the ip address. It will continue to do these kinds of things while you are online. And all…

Do you have sources for this? I don’t doubt you, I’d just be interested to read some details about what exactly those services are doing/sending.

Re: macOS has checked app signatures online for over 2 years

#65
post #51

Earlier quoted context omitted.

Because when you browse the Internet you know you are browsing it. When you run software, you do not expected "unexpected" Internet use. You go for a walk, you carry an umbrella, or go dressed. You are at home, you do not expect it to "rain" or for someone to "watch you".

That seems incredibly naive. I can’t think of a single program off the top of my head that doesn’t use the Internet to some extent while running. Even many CLI tools I use for development do update checks (and sometimes analytics) in the background.

> That seems incredibly naive. I can’t think of a single program off the top of my head that doesn’t use the Internet to some extent while running.

It is not.

Imagine that I don't have that great wifi coverage in all places around the house. But I take my laptop there.

You know what happens when you have poor wifi connection and you wake up laptop? Even the keyboard+mouse are unresponsive. I was wondering why on earth my keyboard stoppe working on a brand new laptop.

All suddenly started to work when I moved to a different room.

I don't have issues with notarization if and only if it does behave normally when the internet connection is spotty - it is a laptop for gods sake, not a desktop with ethernet.

Re: macOS has checked app signatures online for over 2 years

#66
post #52

Earlier quoted context omitted.

The market only acts fairly when the product is a commodity. The time for the market to react for a product with the complexity of a mac is decades. As the ecosystem grows, the cost of switching increases. Therefore market starts acting more and more inefficiently. This is why countries have state intervention in such cases. And anti trust exists. If the option was a mac with privacy vs a mac without privacy but $10…

Whilst I agree with the sentiment, it does occur to me just how many kindles I see with ads. Is there any data released on ads Vs no ads versions? That's the closest comparator I can think of.

I think its worthwhile trying to test the hypothesys, but i dont think anyone takes privacy on a book reader with the same passion as they do on a mobile phone.

Re: macOS has checked app signatures online for over 2 years

#67
post #2

A common refrain in arguments that we don't need laws to protect privacy is that the market will take care of it. The market can't act against what it can't see. Privacy loss is often irreversible. A common refrain in arguments that we don't need to reject closed source software to protect privacy is that being closed source doesn't hide the behaviour, and people will still notice backdoors and privacy leaks. Sometim…

So, we should take away the market's incentive to infringe upon our privacy: by making user-tracking illegal.

Re: macOS has checked app signatures online for over 2 years

#68
post #25

Interesting, but reading the conclusion I'm fascinated in this affaire how technically knowledgeable people loose common sense to defend their favorite brand: - Per launch verification is terrible for privacy, vis-a-vis Apple and the whole network when it happens in plain text - "They should also explain how, having enjoyed their benefits for a couple of years, they’ve suddenly decided they were such a bad idea after…

I think there's an element of people desperately wanting to believe that apple is their tribe, rather than just another company.

I can believe Apple do care about privacy, but ultimately they're just another company. For example, I'm sure apple would love the Epic lawsuit to be decided based on a poll of HN users - "I would rather not have the freedom to run whatever I want, because [insert bizarre anecdote]".

Don't project your own beliefs onto apple, vote with your wallet if they annoy you - it's just a trackpad.

Re: macOS has checked app signatures online for over 2 years

#69
post #17

Another fun fact about this system: something changed in how the binaries are evaluated and one VST plugins I've downloaded months ago was marked as malware. The plugin is quite popular in community so I think it's unlikely it contains actual malicious code (in fact I've contacted the developer and he said he has done some fixes for Apple's security policies recently). Imagine my shock when I open an old project in A…

I assume you upgraded OS, in which case it's annoying but not unusual that plugins stop working.

A machine that's used for making professional music should not be upgraded or connected to the internet. If it's for a hobby... I think we will have to live with the compromise if we want to have the latest security fixes and connect to the internet.

Re: macOS has checked app signatures online for over 2 years

#70
post #57

Earlier quoted context omitted.

The requests contain only app hashes. They do not contain the unique hardware identifier that Apple computers have. They do not contain your Apple ID, identifying you as a user. Why would you not interpret this charitably as them not actually trying to spy on you? If they wanted to spy on you, why on Earth would they not send the actual valuable information?

I believe you are trying to think about this rationally, but this is not the only thing going on. When a mac boots up or changes network location, a long list of processes on your machine (like AppleIdAuthAgent, identityservicesd, , and maybe 10 or 20 more) connect to various apple servers associating your actual identity with the ip address. It will continue to do these kinds of things while you are online. And all…

It is not possible to accurately connect an identity with an IP address. Many computers share IP addresses, and many others jump IP addresses frequently.
Post reply on HN