Live data from Hacker News

macOS has checked app signatures online for over 2 years

eclecticlight.co

291–300 of 458 posts

Re: macOS has checked app signatures online for over 2 years

#291

Earlier quoted context omitted.

There's so much wrong with this post I'm not even sure where to start. Literally almost every paragraph starts something untrue. The whole article is written from a false understanding.

I’m actually curious what’s wrong about it? I read it from an outsider perspective and it’s full of very convincing arguments against “blockchains.” You’re absolutely correct that he’s writing from his understanding, but Schneider’s been in the field for decades (more than many Bitcoin proponents are old ), so I’m more inclined to believe he knows what he’s talking about than some other random person on the internet.

I think the main reason for the dissonance is that Schneier talks about the trust that happens (and maybe has to happen in real-world scenarios) while the bitcoin community likes to talk about the minimum amount of trust necessary.

You don't have to trust the software, you can verify it or implement your own. You don't have to trust your internet uplink, the protocol would work over carrier pigeons or with dead drops. You don't have to trust exchanges, just exchange bitcoin for local currency with your neighbor. And even if you use an exchange you shouldn't store money there anyways. The minimum required trust is tiny (basically you yourself), but of course as Schneier points out the amount of trust involved in practise isn't nearly as low, and for many people the failure cases are much worse

Re: macOS has checked app signatures online for over 2 years

#292
post #218

Earlier quoted context omitted.

I hear this argument a lot but I think it is exactly OPs point when he says, “The market can’t act against what it can’t see”. Your average consumer doesn’t know the extent of what they’re trading. Take Facebook, even with high profile stories and documentaries it’s reasonable for your average consumer to assume that what Facebook tracks about them is what they actively give to Facebook themselves. I’ve had conversat…

It's ok, if they will be educated they will care. Just like they care now about not using single use plastics, buying the biggest and most gas guzzling SUV or flying on holidays across the globe. They won't care even when they'll know. And they might not ever know.

Yes exactly. I don't think an abstract understanding of the costs is enough. If the cost isn't physically or viscerally felt, it just doesn't factor into people's decision making.

This is where the pricing system really comes into great effect. People buy and drive fewer SUVs when gas is more expensive. If we want people to buy fewer SUVs, increase the fuel tax.

Education is not enough, and in fact might not even be necessary at all. Just introduce real costs to capture the "abstract" costs (externalities) and the problem will likely correct itself.

Re: macOS has checked app signatures online for over 2 years

#293
post #2

A common refrain in arguments that we don't need laws to protect privacy is that the market will take care of it. The market can't act against what it can't see. Privacy loss is often irreversible. A common refrain in arguments that we don't need to reject closed source software to protect privacy is that being closed source doesn't hide the behaviour, and people will still notice backdoors and privacy leaks. Sometim…

The market only acts fairly when the product is a commodity. The time for the market to react for a product with the complexity of a mac is decades. As the ecosystem grows, the cost of switching increases. Therefore market starts acting more and more inefficiently. This is why countries have state intervention in such cases. And anti trust exists. If the option was a mac with privacy vs a mac without privacy but $10…

I imagine it more as a tragedy of commons situation. I don't care that much about my privacy right now to sacrifice a lot of convenience. However if enough consumers rejected products that encroach on privacy, we’d get privacy and keep most of convenience.

Re: macOS has checked app signatures online for over 2 years

#294
post #52

Earlier quoted context omitted.

The market only acts fairly when the product is a commodity. The time for the market to react for a product with the complexity of a mac is decades. As the ecosystem grows, the cost of switching increases. Therefore market starts acting more and more inefficiently. This is why countries have state intervention in such cases. And anti trust exists. If the option was a mac with privacy vs a mac without privacy but $10…

Whilst I agree with the sentiment, it does occur to me just how many kindles I see with ads. Is there any data released on ads Vs no ads versions? That's the closest comparator I can think of.

I wish i could pay for no ads on everything. If there are only like three ad networks for 99 percent of the internet, and they can track me easily, and they know how much I'm worth to them, can't they just email me every month and say, "if you want a no-Doubleclick ad experience next month, it will cost you $4.65, click here to pay." Not like they aren't already doing the tracking, and this would increase the value to their ad customers since they wouldn't pay for views from people who don't want to see ads.

Re: macOS has checked app signatures online for over 2 years

#295
post #2

A common refrain in arguments that we don't need laws to protect privacy is that the market will take care of it. The market can't act against what it can't see. Privacy loss is often irreversible. A common refrain in arguments that we don't need to reject closed source software to protect privacy is that being closed source doesn't hide the behaviour, and people will still notice backdoors and privacy leaks. Sometim…

Ya no thanks. Top down regulation will just make startups less likely to enter new disruptive tech. The solution is choice, stop using Apple products and all their shadyness stops being an issue.

Nothing shady about this. It isn’t logged and it protects customers from malware. That was the purpose. Most customers want that.

Re: macOS has checked app signatures online for over 2 years

#296
post #212
post #204

Earlier quoted context omitted.

I have no axe to grind with Apple. I'm a happy Apple customer and have been for most of 30 years. The same code that keeps malware from running on a mac (or iphone) keeps non-app-store apps from running on an iphone, or prompts you to move non-notarized apps to the trash on a mac. It's not some separate thing: the exact same code path that protects the consumer store revenue and developer notarization service revenue…

Which is the same code that keeps unsigned bootloaders from running on PCs which is the same code that keeps unsigned packages from being installed on Linux systems which is the same code that keeps unsigned browser extensions from running on Firefox which is the same code that shows the scary warning on Windows. Everyone seems to like code signing.

Lol you have never had to deal with apple's over complicated code signing as a developer.

Adds a lot of wrenches when your just trying to do basic stuff like codesign and push test builds onto a USB connected device from a bash script and it is flaky and undocumented as fuck.

I am honestly jealous of my android counterparts with their far simpler system and first class command line support via adb.

Re: macOS has checked app signatures online for over 2 years

#297

"Privacy is not a feature".

Privacy is a currency you pay hidden charges with.

Privacy is a thing you only get to choose once per a line of events. Once you commit to the non-private option, you are out of luck. No amount of postcautions will fix that.

Re: macOS has checked app signatures online for over 2 years

#298

It kind of feels like there's a bit too much noise around this topic. I'm getting the same feeling I did years ago when it was discovered that the iPhone had a historical database of all the locations you'd been to. There were rather a lot of articles about how Apple were "tracking you everywhere you went" and so on. The reason it's similar – they are both dumb, technically bad, and privacy-compromising decisions, an…

This is a basic by-the-RFC implementation. The developer who was assigned this just used existing libraries and followed the protocol. This was a rational move on their part. Especially when mucking with x509 has been historically fraught with vulnerabilities.

OCSP has since been improved to increase privacy and security, but the extensions to enable that only considered OCSP in the context of TLS.

Re: macOS has checked app signatures online for over 2 years

#299

Earlier quoted context omitted.

To be honest I would expect if you told people "your TV will report what you're watching" they will think "wait, doesn't my cable company already know what I'm watching???" If you tell them it's the manufacturer this time in addition to the cable company, I'm not sure how many would freak out over the extra entity.

Very few. I'm not sure how you'd measure it, but there seems to be a huge disconnect between techie privacy advocates and the rest of the world. The former keeps claiming the latter just doesn't understand, or needs to be informed, but I just don't think that's realistic. I think it's pretty common knowledge that these companies are harvesting all imaginable data to serve users more / better advertisements and to kee…

In my anecdotical experience, that's not remotely true. Yes there is a disconnect between techies and regular people, in that for us it's obvious that these companies are harvesting all this data and processing it in all this ways and sharing it with all these people, but for the majority of people it's not. Even for you, do you think you fully understand how your data is being utilised and what the consequences are?

Re: macOS has checked app signatures online for over 2 years

#300
post #17

Another fun fact about this system: something changed in how the binaries are evaluated and one VST plugins I've downloaded months ago was marked as malware. The plugin is quite popular in community so I think it's unlikely it contains actual malicious code (in fact I've contacted the developer and he said he has done some fixes for Apple's security policies recently). Imagine my shock when I open an old project in A…

>I don't want to worry about whether my music will work five or ten years from now This is exactly what Apple has already done to the iTunes world, music you had a decade ago is suddenly inaccessible

What is this referring to? Mine seems to work fine.
Post reply on HN