Live data from Hacker News

macOS has checked app signatures online for over 2 years

eclecticlight.co

171–180 of 458 posts

Re: macOS has checked app signatures online for over 2 years

#171
post #52

Earlier quoted context omitted.

Whilst I agree with the sentiment, it does occur to me just how many kindles I see with ads. Is there any data released on ads Vs no ads versions? That's the closest comparator I can think of.

> Whilst I agree with the sentiment, it does occur to me just how many kindles I see with ads. > Is there any data released on ads Vs no ads versions? Do they offer a tracking vs no tracking option too? The absence of adverts does not mean the absence of tracking.

The tracking is somewhat inherent to the software — syncing what page you've read up to in a book between devices (a feature many people find crucial!), cannot really be divorced from having the raw data to create server-side metrics about people's reading habits.

Even if you E2E-encrypt each user's data for cloud storage and have devices join a P2P-keybag, ala iMessage, consider the ad-tech department of your same company as if they were an external adversary for a moment. What would an external adversary do in that situation? Traffic analysis of updates to the cloud-side E2E-encrypted bundle. That alone would still be enough to create a useful advertising profile of the customer's reading habits, since your app is single-purpose — the only reason for that encrypted bundle to be updated, is if the user is flipping pages!

And, together with the fact that your ad-tech department also knows what books the customer is reading (because your device can only be used to read books you sell, and thus books you have transaction records for selling them), this department can probably guess what the user is reading anyway. No matter how much your hardware-product department tries to hide it.

Re: macOS has checked app signatures online for over 2 years

#172

It seems that many tend to overlook the main issue with this. Because of this feature, there are people on this lovely planet of ours who may be in actual physical danger at this very moment .

Citation needed.

Citation to what?

The fact that if you're a journalist in Belarus with a Macbook right now, the kind of apps you open can point you out to authorities controlling the local internet infrastructure in no time?

Or do you expect repressive governments to make press releases explaining in detail how they came to rounding up someone?

Re: macOS has checked app signatures online for over 2 years

#173
post #2

A common refrain in arguments that we don't need laws to protect privacy is that the market will take care of it. The market can't act against what it can't see. Privacy loss is often irreversible. A common refrain in arguments that we don't need to reject closed source software to protect privacy is that being closed source doesn't hide the behaviour, and people will still notice backdoors and privacy leaks. Sometim…

Probably no one cares because Apple’s OCSP checks don’t reduce your privacy.

They should care. The checks are sent unencrypted over HTTP to Apple's OCSP.

Re: macOS has checked app signatures online for over 2 years

#174
post #169

Earlier quoted context omitted.

Oh, you mean the article up at the top of the fucking page? Yeah, I didn't think it was necessary.

That article contains no evidence that Apple has a hidden agenda.

I'm sure it probably doesn't to an Apple Cultist with their head in the sand. But for those people, gesturing broadly at all of the evidence available doesn't seem to work either.

Re: macOS has checked app signatures online for over 2 years

#175
post #126

Earlier quoted context omitted.

> Case to the point: online signature check was a technical decision, to fight malware. This is an oversimplification. It also helps protect Apple's business model: you must pay Apple a fee for services (and show ID) to be able to sign your apps for distribution on this platform. Imagine if you had to show ID to get a TLS certificate for your website. Don't conflate the issue - this is also a move to protect certain…

I see you asserting this over and over. What I don't see is you providing any real evidence that this is a core part of the decision-making process. Apple isn't particularly incentivized to find a different way that avoids the tools they already have that already make it harder and costlier for parties to get around their security mechanisms. That is not the same as making decisions because they protect the business…

Apple charges 10x the market rate for credit card processing on the purchase of mobile apps on iOS. Why do you think this is possible?

Take it from dhh if you don't believe me:

https://mobile.twitter.com/dhh/status/1328339591389175808

Re: macOS has checked app signatures online for over 2 years

#176
It kind of feels like there's a bit too much noise around this topic.

I'm getting the same feeling I did years ago when it was discovered that the iPhone had a historical database of all the locations you'd been to. There were rather a lot of articles about how Apple were "tracking you everywhere you went" and so on.

The reason it's similar – they are both dumb, technically bad, and privacy-compromising decisions, and in both cases much of the public discussion about it has been a little hysterical and off-base.

Apple should 100% be criticised for this particular failure. It's obviously a bad implementation from a technical and usability point of view; the privacy implications are bad, and this features should not have been able to make it out as-is.

But I've legitimately seen people describe this as "Apple's telemetry" which is just obvious nonsense and distracts from the actual problem – how did such a bad implementation of a useful feature end up in a major commercial product, and how are they going to make sure it doesn't happen again?

Re: macOS has checked app signatures online for over 2 years

#177
post #52

Earlier quoted context omitted.

The market only acts fairly when the product is a commodity. The time for the market to react for a product with the complexity of a mac is decades. As the ecosystem grows, the cost of switching increases. Therefore market starts acting more and more inefficiently. This is why countries have state intervention in such cases. And anti trust exists. If the option was a mac with privacy vs a mac without privacy but $10…

Whilst I agree with the sentiment, it does occur to me just how many kindles I see with ads. Is there any data released on ads Vs no ads versions? That's the closest comparator I can think of.

I bought a kindle. It didn't have ads. I did a factory reset. Now it does. This is the first time I've heard about a choice.

Re: macOS has checked app signatures online for over 2 years

#178
post #121

Earlier quoted context omitted.

Let's say you're one out of 10,000 users in a large network sharing a single public IP address. Anyone trying to identify you just needs to narrow that down from 10,000 to one. This can be done many different ways by combining data sources. You could automate it with algorithms and maybe some machine learning, but it'd also be pretty trivial for a dedicated human to do it. Browser fingerprint, mac address, software v…

But why? Why go to these ridiculous lengths to try to extract information from an unreliable source? Apple already has the device identifier and Apple ID. These are reliable. They do not need combining different data sources and algorithm and machine learning. They are the accurate data already. If they wanted it, they could just send it. They don't. Why not? If they wanted this information, why on god's green earth…

It's quite obvious. That way you can't get nailed for breaching privacy.

It's exactly the same concept as the NSA saying that they are only collecting metadata and not doing any spying.

Re: macOS has checked app signatures online for over 2 years

#179
post #2

A common refrain in arguments that we don't need laws to protect privacy is that the market will take care of it. The market can't act against what it can't see. Privacy loss is often irreversible. A common refrain in arguments that we don't need to reject closed source software to protect privacy is that being closed source doesn't hide the behaviour, and people will still notice backdoors and privacy leaks. Sometim…

This isn’t that. I’ve been aware of this for some time, pretty sure it was in the security white paper and talked about as a feature.

People forget about CRLs because browsers mostly ignore them.

People just go crazy for any Apple story because it attracts attention. People have been paying to send all sorts of app launch analytics to AV companies for example since the 90s.

Re: macOS has checked app signatures online for over 2 years

#180
post #52

Earlier quoted context omitted.

Whilst I agree with the sentiment, it does occur to me just how many kindles I see with ads. Is there any data released on ads Vs no ads versions? That's the closest comparator I can think of.

> Whilst I agree with the sentiment, it does occur to me just how many kindles I see with ads. True, although the price difference for the Kindle is about 20%. If the discount on a Macbook Air was similar, I'm sure it would be well subscribed.

The discount for what? There are no ads on the Mac.
Post reply on HN