Live data from Hacker News

macOS has checked app signatures online for over 2 years

eclecticlight.co

81–90 of 458 posts

Re: macOS has checked app signatures online for over 2 years

#81
post #50

Earlier quoted context omitted.

Plenty of computers share a single public IP address. Plenty of computers jump IP addresses constantly. It is not at all reliable trying to tie IP addresses together that way. If they wanted the information, they would need to send it.

Maybe you have a funny network situation, but my network situation is solid, and my IP address rarely changes. IP addresses are absolutely identifiable information.

They are SOMETIMES identifiable information. They are not RELIABLE for identification.

If you are going to be collecting information, you are not going to choose unreliable information when you have the option to collect reliable information. That would not make sense.

Re: macOS has checked app signatures online for over 2 years

#82
post #51

Earlier quoted context omitted.

That seems incredibly naive. I can’t think of a single program off the top of my head that doesn’t use the Internet to some extent while running. Even many CLI tools I use for development do update checks (and sometimes analytics) in the background.

Your choice, not mine. Like: Houdini Emacs Latex A file manager Audacity A Terminal ... Off the tip of my head, used almost daily.

I didn’t mean to imply that one could not name programs that don’t communicate. Of course they exist. I’m not arguing for this type of behavior, just pointing out that it is pretty much the norm. On macOS I use Little Snitch to find and shutdown must of this extra traffic.

Re: macOS has checked app signatures online for over 2 years

#83
post #52

Earlier quoted context omitted.

The market only acts fairly when the product is a commodity. The time for the market to react for a product with the complexity of a mac is decades. As the ecosystem grows, the cost of switching increases. Therefore market starts acting more and more inefficiently. This is why countries have state intervention in such cases. And anti trust exists. If the option was a mac with privacy vs a mac without privacy but $10…

Whilst I agree with the sentiment, it does occur to me just how many kindles I see with ads. Is there any data released on ads Vs no ads versions? That's the closest comparator I can think of.

> Whilst I agree with the sentiment, it does occur to me just how many kindles I see with ads.

True, although the price difference for the Kindle is about 20%. If the discount on a Macbook Air was similar, I'm sure it would be well subscribed.

Re: macOS has checked app signatures online for over 2 years

#84
post #80

Earlier quoted context omitted.

The MacOS OCSP feature has been documented to be non-functional when there is no internet connection, it does not interrupt or slow down any functioning in that case.

Slow Internet and no Internet are different things though. I have experienced this issue as well — sometimes after boot my regular apps will just bounce and bounce (in the macOS dock) and never start. Then when I plug in to ethernet and shut off my wifi everything all of a sudden fires up and starts working.

If there isn't a reasonable timeout set, that does sound like a bug. More than 2 seconds sounds pretty unreasonable to me (possibly should be even less), for a service that is willing to no-op give up when there is no network. Someone would have to do some reverse engineering/debugging maybe by observing/manipulating network traffic to be sure what is going on there, unless Apple wants to tell us but I suspect the suspicious wouldn't believe them.

Missing or too-high timeout should be fixed, but I don't think that'd be enough to to satisfy critics in this thread? Would it you?

[Not setting a timeout on a network request is a common bug in, say, web development. It does make me lose some confidence in Apple's technical abilities if they make that bug in a place with such high consequences. But that's different than ill-intent or a privacy violation]

People seem to object to the basic idea of OCSP, which I think means objecting to the basic idea of app signing.

App signing seems reasonable to me (although it is important to me there be a way for users to choose to launch un-signed apps; there still is in MacOS). And OCSP seems important part of a app signing implementation. Improvements to the particular OCSP implementation for both privacy and performance may be advisable though.

Re: macOS has checked app signatures online for over 2 years

#85
post #65

Earlier quoted context omitted.

> That seems incredibly naive. I can’t think of a single program off the top of my head that doesn’t use the Internet to some extent while running. It is not. Imagine that I don't have that great wifi coverage in all places around the house. But I take my laptop there. You know what happens when you have poor wifi connection and you wake up laptop? Even the keyboard+mouse are unresponsive. I was wondering why on eart…

The MacOS OCSP feature has been documented to be non-functional when there is no internet connection, it does not interrupt or slow down any functioning in that case.

Just like the sibling poster replied, it is not the issue of "no Internet".

You have three cases here: 1. Working internet connection 2. Slow internet connection 3. No internet connection

Everything works fine in 1 and 3, but breaks the OS when in 2 (and it is very common, just walk further from your router and you'll notice it - e.g. when waking up the mac from sleep).

What is strange to me is that I had an old Macbook Air with latest pre-BigSur macos, bought a new Macbook Air (early 2020) with the same OS and I saw the problem only on it - at first I thought it was broken.

Re: macOS has checked app signatures online for over 2 years

#86
post #2

A common refrain in arguments that we don't need laws to protect privacy is that the market will take care of it. The market can't act against what it can't see. Privacy loss is often irreversible. A common refrain in arguments that we don't need to reject closed source software to protect privacy is that being closed source doesn't hide the behaviour, and people will still notice backdoors and privacy leaks. Sometim…

Lying to the customer about what your product does, or having secret functionality, should be a criminal offence in the same way as breaking and entering or stalking are. Then, we would find out very quickly what people value. I firmly believe this ecosystem (as in privacy violating ad and data selling business model) is only dominant because companies are able to mislead with impunity, so it's basically a form of fr…

The act of breaching privacy is technically difficult to prohibit in a way many of us would find palatable.

What should be targeted is the product of said breaches. Something like the blood diamond approach.

If your company has PII, then you by law must be able to produce a consented attestation chain all the way back to the source.

If you do not, then you're charged a fine for every piece of unattested PII on every individual.

Re: macOS has checked app signatures online for over 2 years

#87
post #80

Earlier quoted context omitted.

Slow Internet and no Internet are different things though. I have experienced this issue as well — sometimes after boot my regular apps will just bounce and bounce (in the macOS dock) and never start. Then when I plug in to ethernet and shut off my wifi everything all of a sudden fires up and starts working.

If there isn't a reasonable timeout set, that does sound like a bug. More than 2 seconds sounds pretty unreasonable to me (possibly should be even less), for a service that is willing to no-op give up when there is no network. Someone would have to do some reverse engineering/debugging maybe by observing/manipulating network traffic to be sure what is going on there, unless Apple wants to tell us but I suspect the su…

> Missing or too-high timeout should be fixed, but I don't think that'd be enough to to satisfy critics in this thread? Would it you?

A fix in /etc/hosts is all I needed, but if there was a timeout of 2 seconds I wouldn't even notice the problem -> so I wouldn't block notarization.

Re: macOS has checked app signatures online for over 2 years

#88
post #25

Interesting, but reading the conclusion I'm fascinated in this affaire how technically knowledgeable people loose common sense to defend their favorite brand: - Per launch verification is terrible for privacy, vis-a-vis Apple and the whole network when it happens in plain text - "They should also explain how, having enjoyed their benefits for a couple of years, they’ve suddenly decided they were such a bad idea after…

No-Logo by Naomi Klein outlined how brands work.

One factor in the irrational defence could be a kind of psychological protection of investment. Apple isnt just another company, its an entire lifestyle ecosystem. Those invested in Apple have the watch, tv, laptop, itunes etc. And together they really do "just work" - the user experience is great!

So to admit that Apple is flawed, that their investment was a bad idea is to admit they were wrong and that their time and money was wasted. No-one wants to be a sucker. Far better therefore to protect your investment. Apple really are genius to pull this off. Apple is part of people's identity.

Re: macOS has checked app signatures online for over 2 years

#89
post #57

Earlier quoted context omitted.

I believe you are trying to think about this rationally, but this is not the only thing going on. When a mac boots up or changes network location, a long list of processes on your machine (like AppleIdAuthAgent, identityservicesd, , and maybe 10 or 20 more) connect to various apple servers associating your actual identity with the ip address. It will continue to do these kinds of things while you are online. And all…

It is not possible to accurately connect an identity with an IP address. Many computers share IP addresses, and many others jump IP addresses frequently.

Many computers don't share IP addresses too. And there are times when there is only one macOS under an IP. This is not something to just wave away.

Re: macOS has checked app signatures online for over 2 years

#90
post #2

A common refrain in arguments that we don't need laws to protect privacy is that the market will take care of it. The market can't act against what it can't see. Privacy loss is often irreversible. A common refrain in arguments that we don't need to reject closed source software to protect privacy is that being closed source doesn't hide the behaviour, and people will still notice backdoors and privacy leaks. Sometim…

Great points.

Related tangent: for those interested in this topic of "unlawful massive domestic surveillance", I heartily recommend Cory Doctorow's "Little Brother" novels -- esp the most recent, "Attack Surface". They get the technical details right while remaining accessible and engaging regardless of the reader's geek acumen.

Post reply on HN