Live data from Hacker News

macOS has checked app signatures online for over 2 years

eclecticlight.co

181–190 of 458 posts

Re: macOS has checked app signatures online for over 2 years

#181
post #137

Earlier quoted context omitted.

First time on HN? There are like 2 new Apple security or privacy issues every week. You know about PRISM/edward snowden? You can verify all of this with almost no effort. Any links I post you won't believe. It's up to you.

Not one of those security or privacy issues substantiates that Apple has a hidden agenda to collect data on you . They do substantiate that Apple has a long way to go in terms of technically solving privacy problems. Yes, the NSA has an agenda to track you.

Ahh my book doesn't actually make you a millionaire in a day,but that's just because I failed technically. Anyway-

"Buy my book, make 1 million dollars in a day".

It's not a hidden agenda, I just suck.

Re: macOS has checked app signatures online for over 2 years

#182
post #22

The irony of arguing that the rapid rate of certificate revocations is proof of the system being necessary and secure. No, it's proof that the system is useless. Code signing is a dead end, and we have known that latest with Stuxnet.

With the system checking for certificate validity Stuxnet would have stopped shortly after its certificate was revoked.

Regardless, Stuxnet example is way off the mark. It was designed to work in air-gapped network and defeat particular set of obstacles.

Re: macOS has checked app signatures online for over 2 years

#183
post #126

Earlier quoted context omitted.

> Case to the point: online signature check was a technical decision, to fight malware. This is an oversimplification. It also helps protect Apple's business model: you must pay Apple a fee for services (and show ID) to be able to sign your apps for distribution on this platform. Imagine if you had to show ID to get a TLS certificate for your website. Don't conflate the issue - this is also a move to protect certain…

I see you asserting this over and over. What I don't see is you providing any real evidence that this is a core part of the decision-making process. Apple isn't particularly incentivized to find a different way that avoids the tools they already have that already make it harder and costlier for parties to get around their security mechanisms. That is not the same as making decisions because they protect the business…

I agree that there is no direct evidence that this decision was part of their formal decision-making process. But there is still something to be said for designing systems where it's not possible for those negative incentives to exist, whether or not there is any current intention of taking advantage of them.

Of the tens of thousands of people who had a hand in shaping macOS today, it's impossible to say what their collective intentions were in all the decisions they made. So I think it's useless to talk only about the intentions you can prove just by looking at their formal decision-making process. That is why we need to be working to protect privacy at every level with a "defense in depth" approach.

And of course it goes without saying that all major vendors have issues like this and could be working harder to make sure that these incentives don't get created.

Re: macOS has checked app signatures online for over 2 years

#184
post #171

Earlier quoted context omitted.

> Whilst I agree with the sentiment, it does occur to me just how many kindles I see with ads. > Is there any data released on ads Vs no ads versions? Do they offer a tracking vs no tracking option too? The absence of adverts does not mean the absence of tracking.

The tracking is somewhat inherent to the software — syncing what page you've read up to in a book between devices (a feature many people find crucial!), cannot really be divorced from having the raw data to create server-side metrics about people's reading habits. Even if you E2E-encrypt each user's data for cloud storage and have devices join a P2P-keybag, ala iMessage, consider the ad-tech department of your same c…

ofcourse it can be divorced, keep the data client-side, as kindle does?

Re: macOS has checked app signatures online for over 2 years

#185
post #72
post #47

I sometimes wonder if the mods won't end up banning "political" talk on HN. Because these days everything becomes political, even if it really is a technical issue. Case to the point: online signature check was a technical decision, to fight malware. It was implemented similarly by other OS vendors (Microsoft) and it's been this way for years. Now we discover that it has the unfortunate side-effect that it lessens pr…

The technical issue is "can we provide these features without weakening privacy?" The political issue is "if we can't provide these features without weakening privacy, should we still provide them?" Aren't they both important points to discuss?

They are, but the difference is that we can fix technical issues, or at least improve them. We can (mostly) agree about what's right and wrong and what's better or worse.

Political issues on the other hand, just end up antagonizing us ever more. We argue endlessly, go on countless tangents and nobody agrees on anything because we see the very issues under different lights, experiences, values and cultures.

I am tired of politics. I just want to get stuff done. Hopefully good stuff, but I’d settle for slightly better.

Re: macOS has checked app signatures online for over 2 years

#186
post #171

Earlier quoted context omitted.

> Whilst I agree with the sentiment, it does occur to me just how many kindles I see with ads. > Is there any data released on ads Vs no ads versions? Do they offer a tracking vs no tracking option too? The absence of adverts does not mean the absence of tracking.

The tracking is somewhat inherent to the software — syncing what page you've read up to in a book between devices (a feature many people find crucial!), cannot really be divorced from having the raw data to create server-side metrics about people's reading habits. Even if you E2E-encrypt each user's data for cloud storage and have devices join a P2P-keybag, ala iMessage, consider the ad-tech department of your same c…

> syncing what page you've read up to in a book (a feature many people find crucial!), cannot really be divorced from having the raw data to create server-side metrics about people's reading habits.

Sure it can. You encrypt the data so the client can read it and the server can't. When you add a new device, you e.g. scan a QR code on your old device so that it can add the decryption key to the new device, and the server never knows what it is.

Re: macOS has checked app signatures online for over 2 years

#187
post #47

I sometimes wonder if the mods won't end up banning "political" talk on HN. Because these days everything becomes political, even if it really is a technical issue. Case to the point: online signature check was a technical decision, to fight malware. It was implemented similarly by other OS vendors (Microsoft) and it's been this way for years. Now we discover that it has the unfortunate side-effect that it lessens pr…

> everything becomes political, even if it really is a technical issue

I'm being reminded of an old song by Tom Lehrer [https://www.youtube.com/watch?v=QEJ9HrZq7Ro]

Re: macOS has checked app signatures online for over 2 years

#188
post #119

Earlier quoted context omitted.

You don’t have any evidence to support the claim that they are lying.

First time on HN? There are like 2 new Apple security or privacy issues every week. You know about PRISM/edward snowden? You can verify all of this with almost no effort. Any links I post you won't believe. It's up to you.

You must be new yourself not to have seen how quickly those claims are debunked or shown to be far less exciting than claimed. For example, you’re repeating Greenwald’s misunderstanding of the PRISM report seemingly unaware of the last decade of discussion.

Re: macOS has checked app signatures online for over 2 years

#189

Earlier quoted context omitted.

Citation needed.

Citation to what? The fact that if you're a journalist in Belarus with a Macbook right now, the kind of apps you open can point you out to authorities controlling the local internet infrastructure in no time? Or do you expect repressive governments to make press releases explaining in detail how they came to rounding up someone?

OCSP doesn’t send app signatures.

Re: macOS has checked app signatures online for over 2 years

#190
post #157

Earlier quoted context omitted.

Without facts, your thoughts are merely conspiracy theories. There is no difference between them and claims the US presidential election was stolen.

I've not posted any theories, only widely-accepted and recognized facts.

“ this is also a move to protect certain streams of Apple services revenue”

Citation needed please, Mr. Giuliani.

Post reply on HN