Live data from Hacker News

macOS has checked app signatures online for over 2 years

eclecticlight.co

201–210 of 458 posts

Re: macOS has checked app signatures online for over 2 years

#201
post #52

Earlier quoted context omitted.

The market only acts fairly when the product is a commodity. The time for the market to react for a product with the complexity of a mac is decades. As the ecosystem grows, the cost of switching increases. Therefore market starts acting more and more inefficiently. This is why countries have state intervention in such cases. And anti trust exists. If the option was a mac with privacy vs a mac without privacy but $10…

Whilst I agree with the sentiment, it does occur to me just how many kindles I see with ads. Is there any data released on ads Vs no ads versions? That's the closest comparator I can think of.

I've never had a non-eInk Kindle, so maybe it is different for them, but I've had eInk Kindles both with and without ads. My first was without ads. Since you can add the "without ads" option to a "with ads" Kindle later by paying the difference, I bought my second with ads to see how bad it was.

Here are the only differences I've noticed:

• With ads, the sleep screen displays some artwork from a book Amazon is selling [1] and some text suggesting you come to the store and buy books,

• The home screen has an ad at the bottom.

Since when I'm not using the Kindle the sleep screen is hidden behind the cover, and when I am using it I'm somewhere other than the home screen 99.9% of the time, I never saw any reason to add the "without ads" option, and when it was time to replace that Kindle I again went with ads.

I suspect that the vast majority of people that buy the "no ads" option up front do so because when they see "with ads" they are envisioning a web-like experience where the ads are all over the place and intrusive and animated and distracting.

[1] Usually a romance novel for me, even though I've never bought any romance novels from Amazon, nor anything even remotely like a romance novel. In fact, I don't think any book I've bought from them even had any romantic relations between any of its characters.

Re: macOS has checked app signatures online for over 2 years

#202
post #186
post #171

Earlier quoted context omitted.

The tracking is somewhat inherent to the software — syncing what page you've read up to in a book between devices (a feature many people find crucial!), cannot really be divorced from having the raw data to create server-side metrics about people's reading habits. Even if you E2E-encrypt each user's data for cloud storage and have devices join a P2P-keybag, ala iMessage, consider the ad-tech department of your same c…

> syncing what page you've read up to in a book (a feature many people find crucial!), cannot really be divorced from having the raw data to create server-side metrics about people's reading habits. Sure it can. You encrypt the data so the client can read it and the server can't. When you add a new device, you e.g. scan a QR code on your old device so that it can add the decryption key to the new device, and the serv…

That scenario is addressed in the next few paragraphs.

Re: macOS has checked app signatures online for over 2 years

#203
post #32
post #5

Is there any UI indication that OCSP checks have been consistently failing for some period of time? My concern is less local malware (if something malicious has gained the privileges to filter OCSP, it's probably already game over) but rather networks filtering ocsp.apple.com (for whatever reason).

Does it matter? Would anyone (but the most paranoid) care? My guess is that OCSP is supposed to be part of a defense in depth strategy, so it doesn't have to be 100% airtight to achieve its goals

I care that Apple or Microsoft don't get to know what executables I run. That is information highly relevant to security.

And what do mean with paranoid? I think computing is in danger of getting locked down and that would be such a large overall detriment for everybody. It is a matter of having a broad perspective.

It is also political because you create information asymmetry. To be honest, to dismiss it as paranoia might not be a really valuable assessment. Subjective, but I think it fairly lacking.

Re: macOS has checked app signatures online for over 2 years

#204
post #175

Earlier quoted context omitted.

Apple charges 10x the market rate for credit card processing on the purchase of mobile apps on iOS. Why do you think this is possible? Take it from dhh if you don't believe me: https://mobile.twitter.com/dhh/status/1328339591389175808

Sorry, you seem to have deviated into an unrelated axe you're grinding. Try again, this time with the axe you were originally grinding, which I'll help with: > [Online signature check] is also a move to protect certain streams of Apple services revenue, in addition to protecting users from malware, and it always has been. To restate and avoid drifting into another non sequitur, this ascribes intent ; that is, it sugg…

I have no axe to grind with Apple. I'm a happy Apple customer and have been for most of 30 years.

The same code that keeps malware from running on a mac (or iphone) keeps non-app-store apps from running on an iphone, or prompts you to move non-notarized apps to the trash on a mac.

It's not some separate thing: the exact same code path that protects the consumer store revenue and developer notarization service revenue also protects users against malware.

EDIT, for clarity: I am speaking of Apple-developed, Apple-owned platform security code, where root keys are not held by anyone other than Apple, not generic crypto primitives or the concept of code signing in general (where we have a P-as-in-public PKI).

Re: macOS has checked app signatures online for over 2 years

#205
post #159
post #51

Earlier quoted context omitted.

That seems incredibly naive. I can’t think of a single program off the top of my head that doesn’t use the Internet to some extent while running. Even many CLI tools I use for development do update checks (and sometimes analytics) in the background.

>I can’t think of a single program off the top of my head that doesn’t use the Internet to some extent while running. Ok but will those programs magically break if there is no internet? I would then argue nearly all applications work offline just fine. It's the exception that a program REQUIRES an internet connection..

Sure. I totally agree. That statement was in response to this from OP though:

> When you run software, you do not expect (sic) "unexpected" Internet use.

When I run software, I _do_ expect unanticipated Internet use. That’s why I use and love Little Snitch on macOS.

Re: macOS has checked app signatures online for over 2 years

#206
post #169

Earlier quoted context omitted.

That article contains no evidence that Apple has a hidden agenda.

I'm sure it probably doesn't to an Apple Cultist with their head in the sand. But for those people, gesturing broadly at all of the evidence available doesn't seem to work either.

Gesturing broadly doesn’t work because it’s not evidence. It is only innuendo.

If you had evidence you’d be able to be specific.

Re: macOS has checked app signatures online for over 2 years

#207

Earlier quoted context omitted.

The market only acts fairly when the product is a commodity. The time for the market to react for a product with the complexity of a mac is decades. As the ecosystem grows, the cost of switching increases. Therefore market starts acting more and more inefficiently. This is why countries have state intervention in such cases. And anti trust exists. If the option was a mac with privacy vs a mac without privacy but $10…

>maybe blockchain will solve the problem of trust among humans Absolutely not. https://www.schneier.com/blog/archives/2019/02/blockchain_an...

There's so much wrong with this post I'm not even sure where to start. Literally almost every paragraph starts something untrue. The whole article is written from a false understanding.

Re: macOS has checked app signatures online for over 2 years

#208
post #25

Interesting, but reading the conclusion I'm fascinated in this affaire how technically knowledgeable people loose common sense to defend their favorite brand: - Per launch verification is terrible for privacy, vis-a-vis Apple and the whole network when it happens in plain text - "They should also explain how, having enjoyed their benefits for a couple of years, they’ve suddenly decided they were such a bad idea after…

How is certificate checking a terrible idea? It doesn’t leak the application name or any personal information, and Apple doesn’t store it permanently.

It initially logged IP address and the associated developer ID which was a genuinely bad idea. They've stopped logging IP address now.

The concept here is fine, they just screwed the pooch a bit on implementation. And as usual, HN blew it out of proportion.

Re: macOS has checked app signatures online for over 2 years

#209
post #144
post #82

Earlier quoted context omitted.

I didn’t mean to imply that one could not name programs that don’t communicate. Of course they exist. I’m not arguing for this type of behavior, just pointing out that it is pretty much the norm. On macOS I use Little Snitch to find and shutdown must of this extra traffic.

> I can’t think of a single program off the top of my head that doesn’t use the Internet to some extent while running > I didn’t mean to imply that one could not name programs that don’t communicate. Can you understand how people would read your first comment that way, though?

Yes, definitely! But in my defense, it is simply not what I tapped out (:

I was trying to think of a regular program I use on my macOS (work) laptop that doesn’t connect to the Internet “unexpectedly” and I came up blank.

Re: macOS has checked app signatures online for over 2 years

#210
> Those who consider that Apple’s current online certificate checks are unnecessary, invasive or controlling should familiarise themselves with how they have come about, and their importance to macOS security. They should also explain how, having enjoyed their benefits for a couple of years, they’ve suddenly decided they were such a bad idea after all, and what should replace them.

I agree that anyone critiquing Apple's OCSP design should understand it, and the critique should be more nuanced than "just turn that feature off." Computers are now skeleton keys to our lives and we have to go forward rather than back in figuring out how to design them so they can safely do everything we need them to do.

But it's not hard to justify the sudden criticism here -- it happened after Apple's bad design of the OCSP feature broke local applications, drawing a lot more attention to how it worked. It's reasonable to then ask whether other parts of the design were also poor, as Apple itself obviously is from the changes it's already announced.

To take the author up on what should replace OCSP checks -- how about using something like bloom filters for offline checks, and something like haveibeenpwned's k-anonymity for online checks, to remove the possibility that either Apple or a third party could use OCSP for surveillance?

Post reply on HN