Live data from Hacker News

macOS has checked app signatures online for over 2 years

eclecticlight.co

351–360 of 458 posts

Re: macOS has checked app signatures online for over 2 years

#351

I don't agree with the article's statement that this is necessary. I'm sure it serves a purpose. But it should be more transparent to the user what's going on, and it should be possible to switch it off if the user decides they don't want this. And really, the article also mentions Apple used to do this with a local cache but stopped doing this in Catalina. The question should be asked why. A local cache arguably off…

> And really, the article also mentions Apple used to do this with a local cache but stopped doing this in Catalina

This exactly. Local cache works fine, certificate revocation is rare, and a marginal to nonexistent improvement in security is not worth the slowdown, denial of service, and privacy invasion.

Chrome uses a certificate revocation list for basically the entire internet; certainly macOS can (and indeed should) go back to using such a list for developer certificates, as they did in Mojave.

Re: macOS has checked app signatures online for over 2 years

#352

Earlier quoted context omitted.

I wonder how hard it'd be to serve this data via DNS, like "dig -t TXT 0xdeadbeef.ocsp.apple.com". Then you get a nice, distributed architecture with lots of built-in cache handling, and since the data is currently served via HTTP, it wouldn't expose any more data to your ISP than already is today. It would also mean that if you have 100 people in the office and a local DNS cache, then each OCSP query would be made e…

That still tells people what you’re running, though.

Imagine you have a shared office DNS resolver (which is pretty common). That resolver would aggregate all of the requests into one shared, cached stream. Then the question becomes "hey Apple, one person of how ever many thousand are behind me would like to know if Adobe's certificate is still valid". That's reasonably anonymized, I think.

Re: macOS has checked app signatures online for over 2 years

#353

Earlier quoted context omitted.

I agree with this, to some degree. But I've also known that macOS verifies signatures for as long as it's been doing it. This was no secret, it was advertised as a feature . I assumed it wasn't being done in plaintext, because who would be so foolish as to code it that way? and I'm still plenty mad about that. Anyone could have checked this at any time, presumably people did, and the only reason it became a story is…

> This was no secret, it was advertised as a feature. I wish you could prove this.

https://developer.apple.com/videos/play/wwdc2019/703/ The second half of the talk is about the "hardened runtime"

And in the wider tech press

https://appleinsider.com/articles/19/06/03/apples-macos-cata...

"Mac apps, installer packages, and kernel extensions that are signed with Developer ID must also be notarized by Apple in order to run on macOS Catalina"

Even on hacker news https://news.ycombinator.com/item?id=21179970

Re: macOS has checked app signatures online for over 2 years

#355

Earlier quoted context omitted.

I agree with this, to some degree. But I've also known that macOS verifies signatures for as long as it's been doing it. This was no secret, it was advertised as a feature . I assumed it wasn't being done in plaintext, because who would be so foolish as to code it that way? and I'm still plenty mad about that. Anyone could have checked this at any time, presumably people did, and the only reason it became a story is…

It was mentioned in a developer presentation with very few details as to how it worked. Apple did not go into details; the information presented here was mostly reversed by app developers and security engineers.

What details were missing from the WWDC talk that you would've liked to have seen?

Re: macOS has checked app signatures online for over 2 years

#356
post #171

Earlier quoted context omitted.

> Whilst I agree with the sentiment, it does occur to me just how many kindles I see with ads. > Is there any data released on ads Vs no ads versions? Do they offer a tracking vs no tracking option too? The absence of adverts does not mean the absence of tracking.

The tracking is somewhat inherent to the software — syncing what page you've read up to in a book between devices (a feature many people find crucial!), cannot really be divorced from having the raw data to create server-side metrics about people's reading habits. Even if you E2E-encrypt each user's data for cloud storage and have devices join a P2P-keybag, ala iMessage, consider the ad-tech department of your same c…

My position on data privacy is slightly different from other people on this site—unlike some, I don’t care all that much if Amazon knows my reading habits, but I do not want it to show ads, provide recommendations, or otherwise tailor my experience based on what it knows. I’m concerned that this “tailoring” puts me in a filter bubble, and locks me in to a narrow set of preferences for the rest of my life.

In this regard, Amazon is among the worst of the big tech companies that I interact with. Google lets me turn off personalization—when I go to Youtube, I see an extremely generic set of recommended videos. But I can’t do it on Amazon.

(I don’t use Facebook, not sure what can be switched off.)

Re: macOS has checked app signatures online for over 2 years

#357
> explain how, having enjoyed their benefits for a couple of years, they’ve suddenly decided they were such a bad idea after all

I didn't "enjoy their benefits" - I hated this change when I switched from Mojave to Catalina, and it severely impacted my workflow.

Catalina's change to OCSP and online validation adds little if any value, compromises privacy, reduces performance, and introduces unnecessary new failure modes. It's simply a bad idea whose negatives greatly outweigh any minimal positives.

> what should replace them

Very obviously a Certificate Revocation List, like we had in Mojave.

This is the right approach and should not have changed in the first place.

Re: macOS has checked app signatures online for over 2 years

#358

Earlier quoted context omitted.

That still tells people what you’re running, though.

Imagine you have a shared office DNS resolver (which is pretty common). That resolver would aggregate all of the requests into one shared, cached stream. Then the question becomes "hey Apple, one person of how ever many thousand are behind me would like to know if Adobe's certificate is still valid". That's reasonably anonymized, I think.

Then the question is, "how much do I trust my ISP/DNS provider?"

Those DNS lookups tell your ISP 1) that you use a mac and 2) that you have an application from a specific developer installed.

I think I trust my ISP less than I trust Apple, here. Am I wrong to do so?

Re: macOS has checked app signatures online for over 2 years

#359
post #325
post #206

Earlier quoted context omitted.

Gesturing broadly doesn’t work because it’s not evidence . It is only innuendo. If you had evidence you’d be able to be specific.

"Apple dropped plan for encrypting backups after FBI complained" doesn't sound privacy oriented to me. https://www.reuters.com/article/us-apple-fbi-icloud-exclusiv...

Navigating the complexities of dealing with different governments is not the same as having their own anti-privacy agenda.

Of course they should encrypt the backups, but perhaps the alternative was going to be some kind of legislation that would be even worse.

Re: macOS has checked app signatures online for over 2 years

#360

Earlier quoted context omitted.

If you’re going to claim Schneier is wrong on crypto stuff, you’ll want to bring a suitcase of evidence along if you want people to take your claim seriously.

If you’re going to claim Schneier is wrong on crypto stuff, you’ll want to bring a suitcase of evidence along… How about $348 billion dollars that says he's wrong about his take on Bitcoin? Look, I get it. I respect Schneier's knowledge on encryption but he is wrong about blockchains and about Bitcoin in particular. But he wouldn't be the first establishment technologist/economist/politician to be wrong about Bitcoin…

> How about $348 billion dollars that says he's wrong about his take on Bitcoin?

Market bubbles are a thing. For a while there everyone was convinced that small plush toys were going to help them retire. The market also convinced itself for nearly a decade that "housing prices never go down". Lots of people can be wrong for a surprisingly long time.

Post reply on HN