Live data from Hacker News

macOS has checked app signatures online for over 2 years

eclecticlight.co

101–110 of 458 posts

Re: macOS has checked app signatures online for over 2 years

#101

Earlier quoted context omitted.

Shoot, apparently those Tor devs have been completely wasting their time. Somebody in the security industry should let them know that their work on the network level is useless and unnecessary because leaking IP addresses isn't a real privacy threat.

Accurately. The key word in there was "accurately".

If IP addresses couldn't in some cases accurately track users, then it wouldn't be a priority to build a network that obscured them.

Re: macOS has checked app signatures online for over 2 years

#102

> "Those who consider that Apple’s current online certificate checks are unnecessary, invasive or controlling should familiarise themselves with how they have come about, and their importance to macOS security. They should also explain how, having enjoyed their benefits for a couple of years, they’ve suddenly decided they were such a bad idea after all, and what should replace them." A simple opt-out toggle, for priv…

Apple has said they plan to do this, and also encrypt the checking payload. Sounds good to me, though definitely a privacy failure that they didn't do this in the first place.

The other thing I'd like to see is the app open immediately, w/ the check happening asynchronously in the background. (This seems like super-basic good engineering to me.) No idea if they're planning to fix that or not.

Re: macOS has checked app signatures online for over 2 years

#103

> "Those who consider that Apple’s current online certificate checks are unnecessary, invasive or controlling should familiarise themselves with how they have come about, and their importance to macOS security. They should also explain how, having enjoyed their benefits for a couple of years, they’ve suddenly decided they were such a bad idea after all, and what should replace them." A simple opt-out toggle, for priv…

This is turning out to be a bit of a similar case as the iPhone battery degradation performance throttling issue. Instead of clearly messaging what they were doing to your phone, they did things behind the scenes because they knew better, and decided not to give the user the choice to run the phone at full performance.

Re: macOS has checked app signatures online for over 2 years

#104
post #25

Interesting, but reading the conclusion I'm fascinated in this affaire how technically knowledgeable people loose common sense to defend their favorite brand: - Per launch verification is terrible for privacy, vis-a-vis Apple and the whole network when it happens in plain text - "They should also explain how, having enjoyed their benefits for a couple of years, they’ve suddenly decided they were such a bad idea after…

No-Logo by Naomi Klein outlined how brands work. One factor in the irrational defence could be a kind of psychological protection of investment. Apple isnt just another company, its an entire lifestyle ecosystem. Those invested in Apple have the watch, tv, laptop, itunes etc. And together they really do "just work" - the user experience is great! So to admit that Apple is flawed, that their investment was a bad idea…

"One factor in the irrational defence could be a kind of psychological protection of investment." The Author of this publication is clearly invested deeply in Apple ecosystem as a developer. One of the reasons that I consider using Mac OS behind hardware firewall in the future is clear realisation of this process. This telemetry malpractice clearly must be prevented by legislative measures. Trust is earned by transparency, not by some kind of Security slogans.

Re: macOS has checked app signatures online for over 2 years

#105
post #50

Earlier quoted context omitted.

Maybe you have a funny network situation, but my network situation is solid, and my IP address rarely changes. IP addresses are absolutely identifiable information.

They are SOMETIMES identifiable information. They are not RELIABLE for identification. If you are going to be collecting information, you are not going to choose unreliable information when you have the option to collect reliable information. That would not make sense.

I can right now open my vpn, change my ip address, go to my apple account and it will report that my Mac is "Online", meaning that apple knows that my particular machine is on with a given IP address. It would be completely useless (redundant at the very least) to also include the uid in the signature file.

Re: macOS has checked app signatures online for over 2 years

#106
post #86

Earlier quoted context omitted.

Lying to the customer about what your product does, or having secret functionality, should be a criminal offence in the same way as breaking and entering or stalking are. Then, we would find out very quickly what people value. I firmly believe this ecosystem (as in privacy violating ad and data selling business model) is only dominant because companies are able to mislead with impunity, so it's basically a form of fr…

The act of breaching privacy is technically difficult to prohibit in a way many of us would find palatable. What should be targeted is the product of said breaches. Something like the blood diamond approach. If your company has PII, then you by law must be able to produce a consented attestation chain all the way back to the source. If you do not, then you're charged a fine for every piece of unattested PII on every…

By the time someone is charged with a crime, the damage is already done.

And, there will be many scammers who are simply out of reach of meaningful legal remedies.

Re: macOS has checked app signatures online for over 2 years

#107

> "Those who consider that Apple’s current online certificate checks are unnecessary, invasive or controlling should familiarise themselves with how they have come about, and their importance to macOS security. They should also explain how, having enjoyed their benefits for a couple of years, they’ve suddenly decided they were such a bad idea after all, and what should replace them." A simple opt-out toggle, for priv…

But that would defeat the purpose. Apple can be thought of as the equivalent of the NSA: they "care" about your privacy in the sense that they don't want anybody but themselves to have access to it.

Unfortunately we don't have an Apple competitor that cares enough about your privacy to not want anybody, including themselves, to have access to it.

Re: macOS has checked app signatures online for over 2 years

#108
post #9

Earlier quoted context omitted.

> The market can't act against what it can't see. Privacy loss is often irreversible. You're not wrong, but on the other hand has "the market" shown any serious signal that it cares about privacy? From what I can see people seem more than glad to trade privacy and personal information for free services and cheaper hardware. Take Samsung putting ads on their "smart" TV's UI and screenshotting what people are watching…

> has "the market" shown any serious signal that it cares about privacy? Depends on what you consider a serious signal of care. If 'voting with you wallet' is the measure, increasing levels of income inequality, stagnant wages, weakening employee rights through the gig-economy, etc. are effectively taking away that choice, as most market participants cannot afford to make the choice. Also, what is the paid alternativ…

Income inequality and stagnant wages etc are not the consequences of Apple and Google.

Re: macOS has checked app signatures online for over 2 years

#109
post #47

I sometimes wonder if the mods won't end up banning "political" talk on HN. Because these days everything becomes political, even if it really is a technical issue. Case to the point: online signature check was a technical decision, to fight malware. It was implemented similarly by other OS vendors (Microsoft) and it's been this way for years. Now we discover that it has the unfortunate side-effect that it lessens pr…

> It was never about privacy. It was never a political issue. Can we please just discuss it from a technological standpoint?

No. Unintended consequences are important. There are privacy issues, therefore we need to discuss privacy.

Post reply on HN