Live data from Hacker News

macOS has checked app signatures online for over 2 years

eclecticlight.co

211–220 of 458 posts

Re: macOS has checked app signatures online for over 2 years

#211
post #37

Earlier quoted context omitted.

Is it even app hashes, or developer certificate hashes?

The larger the program, the longer it takes to verify the first time you run it. I can only interpret that as meaning they are basing the whole program. Source: me, downloading and running various apps

Apparently the initial launch delay is Gatekeeper, which is something different.

Re: macOS has checked app signatures online for over 2 years

#212
post #204

Earlier quoted context omitted.

Sorry, you seem to have deviated into an unrelated axe you're grinding. Try again, this time with the axe you were originally grinding, which I'll help with: > [Online signature check] is also a move to protect certain streams of Apple services revenue, in addition to protecting users from malware, and it always has been. To restate and avoid drifting into another non sequitur, this ascribes intent ; that is, it sugg…

I have no axe to grind with Apple. I'm a happy Apple customer and have been for most of 30 years. The same code that keeps malware from running on a mac (or iphone) keeps non-app-store apps from running on an iphone, or prompts you to move non-notarized apps to the trash on a mac. It's not some separate thing: the exact same code path that protects the consumer store revenue and developer notarization service revenue…

Which is the same code that keeps unsigned bootloaders from running on PCs which is the same code that keeps unsigned packages from being installed on Linux systems which is the same code that keeps unsigned browser extensions from running on Firefox which is the same code that shows the scary warning on Windows.

Everyone seems to like code signing.

Re: macOS has checked app signatures online for over 2 years

#213

Earlier quoted context omitted.

Lying to the customer about what your product does, or having secret functionality, should be a criminal offence in the same way as breaking and entering or stalking are. Then, we would find out very quickly what people value. I firmly believe this ecosystem (as in privacy violating ad and data selling business model) is only dominant because companies are able to mislead with impunity, so it's basically a form of fr…

Yes because there are never unwanted side effects from more laws.

That's human nature. As soon as something beneficial to few and detrimental to others is banned, those who benefit seek to find other ways to continue benefitting, again to the detriment of others.

This doesn't mean we shouldn't continue trying to stop them.

And we stop them through laws.

Common sense is not that common and human decency doesn't scale.

Re: macOS has checked app signatures online for over 2 years

#214
post #2

A common refrain in arguments that we don't need laws to protect privacy is that the market will take care of it. The market can't act against what it can't see. Privacy loss is often irreversible. A common refrain in arguments that we don't need to reject closed source software to protect privacy is that being closed source doesn't hide the behaviour, and people will still notice backdoors and privacy leaks. Sometim…

Ya no thanks. Top down regulation will just make startups less likely to enter new disruptive tech. The solution is choice, stop using Apple products and all their shadyness stops being an issue.

How do you provide choice? How do you commoditize an entire hardware and software ecosystem, vertically integrated?

Just like Standard Oil or AT & T were displaced, right? By customers going to their competitors? I'm being sarcastic, obviously :-)

Re: macOS has checked app signatures online for over 2 years

#215
post #185
post #72

Earlier quoted context omitted.

The technical issue is "can we provide these features without weakening privacy?" The political issue is "if we can't provide these features without weakening privacy, should we still provide them?" Aren't they both important points to discuss?

They are, but the difference is that we can fix technical issues, or at least improve them. We can (mostly) agree about what's right and wrong and what's better or worse. Political issues on the other hand, just end up antagonizing us ever more. We argue endlessly, go on countless tangents and nobody agrees on anything because we see the very issues under different lights, experiences, values and cultures. I am tired…

I think this is a terrible attitude. We can improve political issues and we do it by defending our opinions in the public sphere, which has the power to change others' opinions. If you don't work to present your ideas to the world in the best possible light then you will just allow other, weaker ideas to become more convincing in comparison, thus doing a disservice to anyone who could have been convinced otherwise.

I am sorry that politics is tiring but I think that is just a reality of politics being a manifestation of natural forces. The natural world is competitive, it's competitive on the cellular level, the food chain is competitive, and human societies are competitive too. Looking the other way doesn't change the reality, it just guarantees that the opinions of others will become more significant to the world than your own. Just like how our cells compete to form the best possible body, I think we are obligated to compete with our ideas to form the best possible society.

Re: macOS has checked app signatures online for over 2 years

#216

Earlier quoted context omitted.

Many computers don't share IP addresses too. And there are times when there is only one macOS under an IP. This is not something to just wave away.

The point is, this information is UNRELIABLE. Apple has access to information that is ACTUALLY RELIABLE. However, they choose to not use the reliable information. Why would you see this, and assume that they, on purpose, decided to NOT use the reliable information, but instead use unreliable information to spy on you? Why would they do something so bone-headedly stupid?

Do you reject the possibility that they combine the reliable information with the unreliable information to strengthen the latter? I mean, if you have logs stating that a specific Apple ID connected from a specific IP address at a specific time, and they know the identity tied to that Apple ID, it seems reasonable that it would strengthen the claim of "the user at this IP address is most likely this person" quite a bit, especially if the same IP shows up regularly with that Apple ID? I'm not saying they do this currently, but I'm just drawing attention to the fine line between privacy and security. Vigilance isn't necessarily a bad thing, as long as it's grounded in the full reality. It's always possible that one day, Apple's focus in this area may change. When it does, it helps if part of that discussion is already being had.

Re: macOS has checked app signatures online for over 2 years

#217

Earlier quoted context omitted.

Probably no one cares because Apple’s OCSP checks don’t reduce your privacy.

They should care. The checks are sent unencrypted over HTTP to Apple's OCSP.

HTTP is specified in the RFC. Only the developer certificate is checked. OCSP is also used by web browsers to check the revocation status of certificates used for HTTPS connections. Apple leveraged OCSP for its Gatekeeper functionality. This is not the same thing as notarization, which is checked over HTTPS.

https://blog.jacopo.io/en/post/apple-ocsp/

Perhaps you should learn about OCSP before complaining about its use of HTTP.

Re: macOS has checked app signatures online for over 2 years

#218
post #9

Earlier quoted context omitted.

> The market can't act against what it can't see. Privacy loss is often irreversible. You're not wrong, but on the other hand has "the market" shown any serious signal that it cares about privacy? From what I can see people seem more than glad to trade privacy and personal information for free services and cheaper hardware. Take Samsung putting ads on their "smart" TV's UI and screenshotting what people are watching…

I hear this argument a lot but I think it is exactly OPs point when he says, “The market can’t act against what it can’t see”. Your average consumer doesn’t know the extent of what they’re trading. Take Facebook, even with high profile stories and documentaries it’s reasonable for your average consumer to assume that what Facebook tracks about them is what they actively give to Facebook themselves. I’ve had conversat…

It's ok, if they will be educated they will care. Just like they care now about not using single use plastics, buying the biggest and most gas guzzling SUV or flying on holidays across the globe.

They won't care even when they'll know. And they might not ever know.

Re: macOS has checked app signatures online for over 2 years

#220
post #25

Interesting, but reading the conclusion I'm fascinated in this affaire how technically knowledgeable people loose common sense to defend their favorite brand: - Per launch verification is terrible for privacy, vis-a-vis Apple and the whole network when it happens in plain text - "They should also explain how, having enjoyed their benefits for a couple of years, they’ve suddenly decided they were such a bad idea after…

> I'm fascinated in this affaire how technically knowledgeable people loose common sense to defend their favorite brand

What I find weird is regardless of what the discussion is involving Apple, someone needs to pop in with one of these theories about Apple tribalism.

Very very few people are in fact "defending" Apple here. Even among those few, the sentiment is largely that this is bad and Apple is fixing it.

Post reply on HN