Earlier quoted context omitted.
But why? Why go to these ridiculous lengths to try to extract information from an unreliable source? Apple already has the device identifier and Apple ID. These are reliable. They do not need combining different data sources and algorithm and machine learning. They are the accurate data already. If they wanted it, they could just send it. They don't. Why not? If they wanted this information, why on god's green earth…
It's quite obvious. That way you can't get nailed for breaching privacy. It's exactly the same concept as the NSA saying that they are only collecting metadata and not doing any spying.
macOS has checked app signatures online for over 2 years
301–310 of 458 posts
Re: macOS has checked app signatures online for over 2 years
#302Earlier quoted context omitted.
Some signatures are invalidated due to business disputes on entirely different platforms (Epic dispute on iOS, signatures invalidated, or threatened to be before court order prevented it, on OS X, for no security reason).
Epic violated the Terms of Use for their developer agreement which applies to all platforms. They knew that and they violated it willingly. The court order only prevented it temporarily to reduce the damages that may be incurred and until a determination was made in the initial case. That is not anti-consumer.
Revoking signatures and disabling the apps on user devices to protect your business model is definitely anti-consumer in my book.
You could easily see Apple revoking signatures because of DMCA claims. Even faulty ones, like the claim RIAA made against youtube-dl on GitHub.
Re: macOS has checked app signatures online for over 2 years
#303Earlier quoted context omitted.
That scenario is addressed in the next few paragraphs.
The next few paragraphs were not originally in the post. And you obviously get less information from knowing the user has updated some encrypted data than having the specific page of the specific book. It is also not inherently necessary for the server to have even that information; it could be sent directly from one device to the other(s) or via an independent third party relay (e.g. Tor).
Re: macOS has checked app signatures online for over 2 years
#304Earlier quoted context omitted.
May be they have other channels which could or already do send device identifiter and Apple ID. How do you know what _else_ they do ? Who knew they were sending hashes till the recent malfunctioning? What _esle_ we do not know now?
If they wanted that information tied together, they would send it together. Otherwise they have to keep guessing about what goes together with what. That would make no sense. And it was known this data was being sent.
Hiding such feature without option to turn it off would also make no sense to me but they did it.
>If they wanted that information tied together, they would send it together.
sure, unless they wanted to hide the fact they wanted information tied together. In that case they can always provide the line of argument you provide once they caught and say "Oh, if we wanted to spy we would do it openly and brutally. There is no sense for us to make it complicated." But something is telling me that one who wish to spy would do it in some sophisticated manner. The bottom line we do not know and we _can_not_ know since we did not see _all_ sources.
You also cannot know what they wanted, so your guess is as good as any other? Or somehow you know something we don't?
The bottom line here is the same: who knows.
But I think if they wanted to make it open and secure they would simply put option in GUI with clear text explaining what it does and how it does it with ability to turn this thing off. And they didn't do it this way. For me it can mean 'they are hiding something' possibly. What else they hide and why we simply do not know.
Re: macOS has checked app signatures online for over 2 years
#305Earlier quoted context omitted.
Accurately. The key word in there was "accurately".
The real key word is "legally". IP addresses + other metadata (browser fingerprinting and the like) can be enough to sufficiently identify an individual, or at least a household, for some purposes, such as making a more effective advertising profile.
Re: macOS has checked app signatures online for over 2 years
#306The only charitable understanding of this program is that Apple has no actual table connecting software to hashes, but that they could use the information to understand outbreaks of botnets/spyware that they could then help inform ISPs/global law enforcement to help stop. Is this even reasonable?
Re: macOS has checked app signatures online for over 2 years
#307Earlier quoted context omitted.
The point is, this information is UNRELIABLE. Apple has access to information that is ACTUALLY RELIABLE. However, they choose to not use the reliable information. Why would you see this, and assume that they, on purpose, decided to NOT use the reliable information, but instead use unreliable information to spy on you? Why would they do something so bone-headedly stupid?
Do you reject the possibility that they combine the reliable information with the unreliable information to strengthen the latter? I mean, if you have logs stating that a specific Apple ID connected from a specific IP address at a specific time, and they know the identity tied to that Apple ID, it seems reasonable that it would strengthen the claim of "the user at this IP address is most likely this person" quite a b…
Re: macOS has checked app signatures online for over 2 years
#308Earlier quoted context omitted.
> I can’t think of a single program off the top of my head that doesn’t use the Internet to some extent while running. What OS are you using? Purely off the top of my head, Linux programs I don't expect to be regularly connecting to the overall Internet in the background (at least unless I set an explicit opt-in setting or use a user-initiated action): - Keepassxc - Krita - Blender - Nearly all of my CLI tools - digi…
> Admittedly, I'm kind of cheating by using Linux instead of Windows/Mac. I don’t think that is cheating. I was primarily thinking of my own work development environment in macOS but comparing that to Linux is perfectly valid. Again though, I didn’t mean to say, “I bet you can’t name a single program that doesn’t use the Internet!” I just meant to point out that programs using the Internet are probably a fairly consi…
Programs like Spacemacs (updating ELPA repos on boot, which I actually kind of think is a mistake) and Calibre (just kind of doing its own thing) are the exception to that rule, but they're pretty rare in my personal experience. Even Firefox doesn't update itself on my Linux box.
That's kind of why I was thinking of Linux as cheating on some level. Windows/Mac programs basically can't do the same thing, since they don't have the same infrastructure.
> I just meant to point out that programs using the Internet are probably a fairly considerable majority for most regular users.
I would push back a tiny bit on this -- I don't think regular users would be surprised by a native program contacting the Internet, but I do think they would be surprised if that rest request failing meant that the program couldn't launch.
Re: macOS has checked app signatures online for over 2 years
#309Earlier quoted context omitted.
>They do not contain the unique hardware identifier that Apple computers have Different part of MacOS can send it and you would have no idea until it malfunction like in this case.
They would not be accurately tied together, though, since these requests are not sent with any kind of identifier.
Re: macOS has checked app signatures online for over 2 years
#310Earlier quoted context omitted.
Very few. I'm not sure how you'd measure it, but there seems to be a huge disconnect between techie privacy advocates and the rest of the world. The former keeps claiming the latter just doesn't understand, or needs to be informed, but I just don't think that's realistic. I think it's pretty common knowledge that these companies are harvesting all imaginable data to serve users more / better advertisements and to kee…
In my anecdotical experience, that's not remotely true. Yes there is a disconnect between techies and regular people, in that for us it's obvious that these companies are harvesting all this data and processing it in all this ways and sharing it with all these people, but for the majority of people it's not. Even for you, do you think you fully understand how your data is being utilised and what the consequences are?
> Even for you, do you think you fully understand how your data is being utilised and what the consequences are?
I don't think anyone can say with certainty, but I read these threads so I'm quite aware they're collecting and monetizing every imaginable thing they can. It's difficult to articulate any measurable / real negative consequences to me, personally.