Live data from Hacker News

macOS has checked app signatures online for over 2 years

eclecticlight.co

151–160 of 458 posts

Re: macOS has checked app signatures online for over 2 years

#151
post #2

A common refrain in arguments that we don't need laws to protect privacy is that the market will take care of it. The market can't act against what it can't see. Privacy loss is often irreversible. A common refrain in arguments that we don't need to reject closed source software to protect privacy is that being closed source doesn't hide the behaviour, and people will still notice backdoors and privacy leaks. Sometim…

> A common refrain in arguments that we don't need to reject closed source software to protect privacy is that being closed source doesn't hide the behaviour, and people will still notice backdoors and privacy leaks. Sometimes they do, sometimes they don't.

And there are cases where it's not practical for "people to notice." For instance: a privacy leak that only uses the cell network connection of a phone, which would avoid easily-sniffed connections.

Re: macOS has checked app signatures online for over 2 years

#152
post #86

Earlier quoted context omitted.

Lying to the customer about what your product does, or having secret functionality, should be a criminal offence in the same way as breaking and entering or stalking are. Then, we would find out very quickly what people value. I firmly believe this ecosystem (as in privacy violating ad and data selling business model) is only dominant because companies are able to mislead with impunity, so it's basically a form of fr…

The act of breaching privacy is technically difficult to prohibit in a way many of us would find palatable. What should be targeted is the product of said breaches. Something like the blood diamond approach. If your company has PII, then you by law must be able to produce a consented attestation chain all the way back to the source. If you do not, then you're charged a fine for every piece of unattested PII on every…

I thonk we are both arguing that clear consent must be present, and the customer must have clearly agreed to whatever you are doing with the data - that appears similar to GDPR.

However, how do you prove John Doe has actually agreed to this? What if John says he did not click accept button? Do we require digital signature with certificates, given that most people don't have them or know how to use them?

I think the problem is more tractable for physical products running firmware - there you have real proof of purchase, and, at present, firmware that does whatever it wants.

Re: macOS has checked app signatures online for over 2 years

#153
post #135

Earlier quoted context omitted.

Accurately. The key word in there was "accurately".

The real key word is "legally". IP addresses + other metadata (browser fingerprinting and the like) can be enough to sufficiently identify an individual, or at least a household, for some purposes, such as making a more effective advertising profile.

Coulda woulda shoulda isn’t evidence.

Re: macOS has checked app signatures online for over 2 years

#154
post #108

Earlier quoted context omitted.

Income inequality and stagnant wages etc are not the consequences of Apple and Google.

No one suggested they are. But they still make it much less likely for the average Joe to put money and effort to protect their privacy, and this is known to those that make major pricing decisions.

We’re talking about Apple here. People who can afford a Mac over a cheap pc/chrome book already have disposable income and are making trade-offs with it.

Re: macOS has checked app signatures online for over 2 years

#155

The only charitable understanding of this program is that Apple has no actual table connecting software to hashes, but that they could use the information to understand outbreaks of botnets/spyware that they could then help inform ISPs/global law enforcement to help stop. Is this even reasonable?

OCSP requests don’t identify software, they identify certificates. Each certificate can be used for dozens of different apps.

Re: macOS has checked app signatures online for over 2 years

#156
post #52

Earlier quoted context omitted.

Whilst I agree with the sentiment, it does occur to me just how many kindles I see with ads. Is there any data released on ads Vs no ads versions? That's the closest comparator I can think of.

> Whilst I agree with the sentiment, it does occur to me just how many kindles I see with ads. > Is there any data released on ads Vs no ads versions? Do they offer a tracking vs no tracking option too? The absence of adverts does not mean the absence of tracking.

[deleted]

Re: macOS has checked app signatures online for over 2 years

#157
post #126

Earlier quoted context omitted.

> Case to the point: online signature check was a technical decision, to fight malware. This is an oversimplification. It also helps protect Apple's business model: you must pay Apple a fee for services (and show ID) to be able to sign your apps for distribution on this platform. Imagine if you had to show ID to get a TLS certificate for your website. Don't conflate the issue - this is also a move to protect certain…

Without facts, your thoughts are merely conspiracy theories. There is no difference between them and claims the US presidential election was stolen.

I've not posted any theories, only widely-accepted and recognized facts.

Re: macOS has checked app signatures online for over 2 years

#158
post #17

Another fun fact about this system: something changed in how the binaries are evaluated and one VST plugins I've downloaded months ago was marked as malware. The plugin is quite popular in community so I think it's unlikely it contains actual malicious code (in fact I've contacted the developer and he said he has done some fixes for Apple's security policies recently). Imagine my shock when I open an old project in A…

>I don't want to worry about whether my music will work five or ten years from now This is exactly what Apple has already done to the iTunes world, music you had a decade ago is suddenly inaccessible

Do you have an example of this?

Re: macOS has checked app signatures online for over 2 years

#159
post #51

Earlier quoted context omitted.

Because when you browse the Internet you know you are browsing it. When you run software, you do not expected "unexpected" Internet use. You go for a walk, you carry an umbrella, or go dressed. You are at home, you do not expect it to "rain" or for someone to "watch you".

That seems incredibly naive. I can’t think of a single program off the top of my head that doesn’t use the Internet to some extent while running. Even many CLI tools I use for development do update checks (and sometimes analytics) in the background.

>I can’t think of a single program off the top of my head that doesn’t use the Internet to some extent while running.

Ok but will those programs magically break if there is no internet? I would then argue nearly all applications work offline just fine. It's the exception that a program REQUIRES an internet connection..

Re: macOS has checked app signatures online for over 2 years

#160
post #151
post #2

A common refrain in arguments that we don't need laws to protect privacy is that the market will take care of it. The market can't act against what it can't see. Privacy loss is often irreversible. A common refrain in arguments that we don't need to reject closed source software to protect privacy is that being closed source doesn't hide the behaviour, and people will still notice backdoors and privacy leaks. Sometim…

> A common refrain in arguments that we don't need to reject closed source software to protect privacy is that being closed source doesn't hide the behaviour, and people will still notice backdoors and privacy leaks. Sometimes they do, sometimes they don't. And there are cases where it's not practical for "people to notice." For instance: a privacy leak that only uses the cell network connection of a phone, which wou…

Even with traffic monitoring, how do you distinguish bad TLS traffic from a machine you don't control to a cloudflare IP to good TLS traffic?
Post reply on HN