Live data from Hacker News

macOS has checked app signatures online for over 2 years

eclecticlight.co

191–200 of 458 posts

Re: macOS has checked app signatures online for over 2 years

#191
post #157

Earlier quoted context omitted.

Without facts, your thoughts are merely conspiracy theories. There is no difference between them and claims the US presidential election was stolen.

I've not posted any theories, only widely-accepted and recognized facts.

> this is also a move to protect certain streams of Apple services revenue

That's a theory, not a fact, nor is it widely recognized.

By any reasonable accounting of costs, the $99 Apple Developer Program fee isn't meant to be a profit center that Apple is trying to "protect". It mainly helps prevent spam accounts and helps offset the cost of reviewing and distributing free apps in the Mac and iOS app stores.

Re: macOS has checked app signatures online for over 2 years

#192
post #175

Earlier quoted context omitted.

I see you asserting this over and over. What I don't see is you providing any real evidence that this is a core part of the decision-making process. Apple isn't particularly incentivized to find a different way that avoids the tools they already have that already make it harder and costlier for parties to get around their security mechanisms. That is not the same as making decisions because they protect the business…

Apple charges 10x the market rate for credit card processing on the purchase of mobile apps on iOS. Why do you think this is possible? Take it from dhh if you don't believe me: https://mobile.twitter.com/dhh/status/1328339591389175808

Sorry, you seem to have deviated into an unrelated axe you're grinding. Try again, this time with the axe you were originally grinding, which I'll help with:

> [Online signature check] is also a move to protect certain streams of Apple services revenue, in addition to protecting users from malware, and it always has been.

To restate and avoid drifting into another non sequitur, this ascribes intent; that is, it suggests that part of the reason online signature check was added, and part of how it has been evolved, is to protect certain streams of Apple services revenue. That would be your argument, which has no evidence to support it, but you suggest is backed by “facts”[1], which appear to be nowhere to be found.

Are these facts somewhere to be found? Or are you stating hypotheses as facts?

[1] https://news.ycombinator.com/item?id=25210475

Re: macOS has checked app signatures online for over 2 years

#193
post #47

I sometimes wonder if the mods won't end up banning "political" talk on HN. Because these days everything becomes political, even if it really is a technical issue. Case to the point: online signature check was a technical decision, to fight malware. It was implemented similarly by other OS vendors (Microsoft) and it's been this way for years. Now we discover that it has the unfortunate side-effect that it lessens pr…

I think informing the vendor of an OS about every program you run has necessarily a political component and is of relevance for discussion about security. It is the first step to define the threat model and there certainly are additional threats you are exposed to. This data is highly valuable to anyone that might want to infiltrate computer systems.

The technical discussion of signatures is well documented.

Re: macOS has checked app signatures online for over 2 years

#194
post #25

Interesting, but reading the conclusion I'm fascinated in this affaire how technically knowledgeable people loose common sense to defend their favorite brand: - Per launch verification is terrible for privacy, vis-a-vis Apple and the whole network when it happens in plain text - "They should also explain how, having enjoyed their benefits for a couple of years, they’ve suddenly decided they were such a bad idea after…

No-Logo by Naomi Klein outlined how brands work. One factor in the irrational defence could be a kind of psychological protection of investment. Apple isnt just another company, its an entire lifestyle ecosystem. Those invested in Apple have the watch, tv, laptop, itunes etc. And together they really do "just work" - the user experience is great! So to admit that Apple is flawed, that their investment was a bad idea…

The article points out that while there are drawbacks to checking app signatures, there have also been documented benefits in terms of uncovering vulnerabilities and making systems more secure, which also has direct privacy benefits to the users whose systems don't become compromised by malware.

The balancing act between freedom and security is never going to not be a debate. Engaging in it in good faith as in the linked article is a reasonable approach (that you don't usually see represented in Klein's oeuvre): consider tradeoffs, counterarguments, and historical context from different perspectives. Apple is flawed sure, because all complex solutions are inherently flawed. They have a responsibility to be more open and transparent, and I'd prefer to see more details and updates to their otherwise laudable security whitepaper [1], and clearer more accessible user-definable toggles. But your or my preferred solution probably isn't the ideal default for most users, or for the ecosystem as a whole.

[1] https://manuals.info.apple.com/MANUALS/1000/MA1902/en_US/app...

Re: macOS has checked app signatures online for over 2 years

#195

Earlier quoted context omitted.

Probably no one cares because Apple’s OCSP checks don’t reduce your privacy.

They should care. The checks are sent unencrypted over HTTP to Apple's OCSP.

Since they don’t identify specific apps you use, so what’s your point?

Re: macOS has checked app signatures online for over 2 years

#196
post #137

Earlier quoted context omitted.

Not one of those security or privacy issues substantiates that Apple has a hidden agenda to collect data on you . They do substantiate that Apple has a long way to go in terms of technically solving privacy problems. Yes, the NSA has an agenda to track you.

Ahh my book doesn't actually make you a millionaire in a day,but that's just because I failed technically. Anyway- "Buy my book, make 1 million dollars in a day". It's not a hidden agenda, I just suck.

Apple is actually checking certificates. That is the agenda.

Claiming they are doing more requires evidence.

Re: macOS has checked app signatures online for over 2 years

#197
post #125
post #106

Earlier quoted context omitted.

By the time someone is charged with a crime, the damage is already done. And, there will be many scammers who are simply out of reach of meaningful legal remedies.

That's true of virtually all criminal laws, though. If you're beat up and your assailant is charged with assault, you've already been beat up.

Yes, which is why you need both laws, and prevention methods.

Re: macOS has checked app signatures online for over 2 years

#198
post #2

A common refrain in arguments that we don't need laws to protect privacy is that the market will take care of it. The market can't act against what it can't see. Privacy loss is often irreversible. A common refrain in arguments that we don't need to reject closed source software to protect privacy is that being closed source doesn't hide the behaviour, and people will still notice backdoors and privacy leaks. Sometim…

Ya no thanks. Top down regulation will just make startups less likely to enter new disruptive tech. The solution is choice, stop using Apple products and all their shadyness stops being an issue.

> The solution is choice

Correct. Among apple, MS and google you have no choice. That is why regulation is necessary.

Re: macOS has checked app signatures online for over 2 years

#199

Earlier quoted context omitted.

Citation to what? The fact that if you're a journalist in Belarus with a Macbook right now, the kind of apps you open can point you out to authorities controlling the local internet infrastructure in no time? Or do you expect repressive governments to make press releases explaining in detail how they came to rounding up someone?

OCSP doesn’t send app signatures.

Developer certificates are enough to figure out you're opening, say Tor, or Telegram.

See this thread for people discussing this: https://news.ycombinator.com/item?id=25095438

When they implement a toggle for switching this off, along with data encryption, then this particular concern becomes a non-issue.

Re: macOS has checked app signatures online for over 2 years

#200
post #51

Earlier quoted context omitted.

That seems incredibly naive. I can’t think of a single program off the top of my head that doesn’t use the Internet to some extent while running. Even many CLI tools I use for development do update checks (and sometimes analytics) in the background.

> I can’t think of a single program off the top of my head that doesn’t use the Internet to some extent while running. What OS are you using? Purely off the top of my head, Linux programs I don't expect to be regularly connecting to the overall Internet in the background (at least unless I set an explicit opt-in setting or use a user-initiated action): - Keepassxc - Krita - Blender - Nearly all of my CLI tools - digi…

> Admittedly, I'm kind of cheating by using Linux instead of Windows/Mac.

I don’t think that is cheating. I was primarily thinking of my own work development environment in macOS but comparing that to Linux is perfectly valid. Again though, I didn’t mean to say, “I bet you can’t name a single program that doesn’t use the Internet!” I just meant to point out that programs using the Internet are probably a fairly considerable majority for most regular users.

I use KeepassXC on macOS and it definitely does check for updates. Does it not do that on Linux?

Post reply on HN