Live data from Hacker News

macOS has checked app signatures online for over 2 years

eclecticlight.co

131–140 of 458 posts

Re: macOS has checked app signatures online for over 2 years

#131
post #52

Earlier quoted context omitted.

Whilst I agree with the sentiment, it does occur to me just how many kindles I see with ads. Is there any data released on ads Vs no ads versions? That's the closest comparator I can think of.

> Whilst I agree with the sentiment, it does occur to me just how many kindles I see with ads. > Is there any data released on ads Vs no ads versions? Do they offer a tracking vs no tracking option too? The absence of adverts does not mean the absence of tracking.

[deleted]

Re: macOS has checked app signatures online for over 2 years

#132
post #2

A common refrain in arguments that we don't need laws to protect privacy is that the market will take care of it. The market can't act against what it can't see. Privacy loss is often irreversible. A common refrain in arguments that we don't need to reject closed source software to protect privacy is that being closed source doesn't hide the behaviour, and people will still notice backdoors and privacy leaks. Sometim…

Ya no thanks. Top down regulation will just make startups less likely to enter new disruptive tech. The solution is choice, stop using Apple products and all their shadyness stops being an issue.

> Ya no thanks. Top down regulation will just make startups less likely to enter new disruptive tech. The solution is choice, stop using Apple products and all their shadyness stops being an issue.

And since people have demonstrated that they're not appropriately incentivized to stop, that's where the regulations snap in, which brings us back to where we started: there's a need for it.

Solution could just be to regulate based on a tightly managed definition of age. Enable younger companies to have a bit more flexibility in determining their business model as controls slowly snap in as the company ages. There are some pretty clear loopholes that immediately come to mind (e.g. re-chartering the company every few years and transferring assets) that'll need to somehow be managed, but it should be enough to give companies runway to figure out how to disrupt and monetize while coming into compliance with consumer protections.

Re: macOS has checked app signatures online for over 2 years

#133
post #2

A common refrain in arguments that we don't need laws to protect privacy is that the market will take care of it. The market can't act against what it can't see. Privacy loss is often irreversible. A common refrain in arguments that we don't need to reject closed source software to protect privacy is that being closed source doesn't hide the behaviour, and people will still notice backdoors and privacy leaks. Sometim…

Probably no one cares because Apple’s OCSP checks don’t reduce your privacy.

Re: macOS has checked app signatures online for over 2 years

#134
post #63

Earlier quoted context omitted.

Directly contradicting current Apple Marketing. I lothe Apple(and other unethical companies) for lying in their ads. Any benefits of macOS are instantly gone because you cannot Trust Apple to tell the truth. It's as unreliable as Google keeping a service around.

I first started getting an idea that something was amiss with apple years and years ago. "Apple machines don't get viruses" Everyone "knew" that. Everyone knew that apple machines were secure. Turns out there were plenty of things going on with apple just like other companies. The difference was that apple would actively persecute (even prosecute) people who explored or discovered these things. Basically apple market…

Please cite evidence for these extraordinary claims. Who, precisely, did Apple "prosecute" for "exploring" security issues?

Please don't post made-up things in public.

As an aside, no, everyone did not "know" that Macs don't get viruses. But yes, most informed people were aware that Macs were somewhat less susceptible to malware for a while. Please don't exaggerate wildly.

Re: macOS has checked app signatures online for over 2 years

#135

Earlier quoted context omitted.

Shoot, apparently those Tor devs have been completely wasting their time. Somebody in the security industry should let them know that their work on the network level is useless and unnecessary because leaking IP addresses isn't a real privacy threat.

Accurately. The key word in there was "accurately".

The real key word is "legally". IP addresses + other metadata (browser fingerprinting and the like) can be enough to sufficiently identify an individual, or at least a household, for some purposes, such as making a more effective advertising profile.

Re: macOS has checked app signatures online for over 2 years

#136
post #80

Earlier quoted context omitted.

Slow Internet and no Internet are different things though. I have experienced this issue as well — sometimes after boot my regular apps will just bounce and bounce (in the macOS dock) and never start. Then when I plug in to ethernet and shut off my wifi everything all of a sudden fires up and starts working.

If there isn't a reasonable timeout set, that does sound like a bug. More than 2 seconds sounds pretty unreasonable to me (possibly should be even less), for a service that is willing to no-op give up when there is no network. Someone would have to do some reverse engineering/debugging maybe by observing/manipulating network traffic to be sure what is going on there, unless Apple wants to tell us but I suspect the su…

>People seem to object to the basic idea of OCSP, which I think means objecting to the basic idea of app signing.

I am. It's one of the reasons I ditched OS X when 10.7 came out despite using Mac OS since 7.6. It's nobody else's business what I run on my machine.

Re: macOS has checked app signatures online for over 2 years

#137
post #119

Earlier quoted context omitted.

You don’t have any evidence to support the claim that they are lying.

First time on HN? There are like 2 new Apple security or privacy issues every week. You know about PRISM/edward snowden? You can verify all of this with almost no effort. Any links I post you won't believe. It's up to you.

Not one of those security or privacy issues substantiates that Apple has a hidden agenda to collect data on you.

They do substantiate that Apple has a long way to go in terms of technically solving privacy problems.

Yes, the NSA has an agenda to track you.

Re: macOS has checked app signatures online for over 2 years

#138
post #2

A common refrain in arguments that we don't need laws to protect privacy is that the market will take care of it. The market can't act against what it can't see. Privacy loss is often irreversible. A common refrain in arguments that we don't need to reject closed source software to protect privacy is that being closed source doesn't hide the behaviour, and people will still notice backdoors and privacy leaks. Sometim…

Lying to the customer about what your product does, or having secret functionality, should be a criminal offence in the same way as breaking and entering or stalking are. Then, we would find out very quickly what people value. I firmly believe this ecosystem (as in privacy violating ad and data selling business model) is only dominant because companies are able to mislead with impunity, so it's basically a form of fr…

Yes because there are never unwanted side effects from more laws.

Re: macOS has checked app signatures online for over 2 years

#139
post #128
post #58

I give up on Hacker News. Go ahead and wallow in your ignorance, downvoting experts.

It has been widely known that these checks were happening. Not only that, this isn’t the first server problem that impacted launch performance. It’s just the most severe. The main difference is that this time around there are people who are claiming that Apple is using the OCSP checks for some kind of nefarious tracking purposes. These people have no evidence.

[deleted]

Re: macOS has checked app signatures online for over 2 years

#140
post #25

Interesting, but reading the conclusion I'm fascinated in this affaire how technically knowledgeable people loose common sense to defend their favorite brand: - Per launch verification is terrible for privacy, vis-a-vis Apple and the whole network when it happens in plain text - "They should also explain how, having enjoyed their benefits for a couple of years, they’ve suddenly decided they were such a bad idea after…

How is certificate checking a terrible idea?

It doesn’t leak the application name or any personal information, and Apple doesn’t store it permanently.

Post reply on HN