Live data from Hacker News

macOS has checked app signatures online for over 2 years

eclecticlight.co

391–400 of 458 posts

Re: macOS has checked app signatures online for over 2 years

#391
post #17

Another fun fact about this system: something changed in how the binaries are evaluated and one VST plugins I've downloaded months ago was marked as malware. The plugin is quite popular in community so I think it's unlikely it contains actual malicious code (in fact I've contacted the developer and he said he has done some fixes for Apple's security policies recently). Imagine my shock when I open an old project in A…

It's been good practice for a long time to "freeze" or "render" the tracks out after the song is finished so that the song can be loaded without the plugins.

That's often done for producing a static performance and mix for distribution.

But when returning to a digital musical work months or years later, oftentimes the idea is to improve or otherwise rework it ... just as live bands do constantly. A non-working essential plug-in (filter, synth, VCO, whatever) might make that much more difficult.

One of the biggest headaches in computer music-making is how much time fighting the tech takes away from the creative process. Noone needs their OS to be adding to their distress. Let alone switching serial-port designs every few years (obsoleting trusted and often expensive equipment).

Re: macOS has checked app signatures online for over 2 years

#392
post #69
post #17

Another fun fact about this system: something changed in how the binaries are evaluated and one VST plugins I've downloaded months ago was marked as malware. The plugin is quite popular in community so I think it's unlikely it contains actual malicious code (in fact I've contacted the developer and he said he has done some fixes for Apple's security policies recently). Imagine my shock when I open an old project in A…

I assume you upgraded OS, in which case it's annoying but not unusual that plugins stop working. A machine that's used for making professional music should not be upgraded or connected to the internet. If it's for a hobby... I think we will have to live with the compromise if we want to have the latest security fixes and connect to the internet.

>should not be upgraded

Most DAW-makers are constantly upgrading their software. And they often obsolete their older versions to get in sync with new OS's. 'Keeping the old stuff' sometimes isn't an option.

Physical instruments keep working for decades ... but thanks to OS upgrades, valued digital hardware and/or software instruments (say by Opcode or Native) can be lost to stupid or cavalier changes. Anyone who's been making 'professional music' for long has been bitten many times.

Re: macOS has checked app signatures online for over 2 years

#395
post #86

Earlier quoted context omitted.

Lying to the customer about what your product does, or having secret functionality, should be a criminal offence in the same way as breaking and entering or stalking are. Then, we would find out very quickly what people value. I firmly believe this ecosystem (as in privacy violating ad and data selling business model) is only dominant because companies are able to mislead with impunity, so it's basically a form of fr…

The act of breaching privacy is technically difficult to prohibit in a way many of us would find palatable. What should be targeted is the product of said breaches. Something like the blood diamond approach. If your company has PII, then you by law must be able to produce a consented attestation chain all the way back to the source. If you do not, then you're charged a fine for every piece of unattested PII on every…

Or perhaps change the system that incentivizes companies to violate privacy over and over again

Re: macOS has checked app signatures online for over 2 years

#396
post #102

Earlier quoted context omitted.

Apple has said they plan to do this, and also encrypt the checking payload. Sounds good to me, though definitely a privacy failure that they didn't do this in the first place. The other thing I'd like to see is the app open immediately, w/ the check happening asynchronously in the background. (This seems like super-basic good engineering to me.) No idea if they're planning to fix that or not.

> The other thing I'd like to see is the app open immediately, w/ the check happening asynchronously in the background. (This seems like super-basic good engineering to me.) No idea if they're planning to fix that or not. How would this work? The point of the check is to block malware from running, and opening without the check would, by definition, negate the entire system. If malware authors get wise to the async s…

Fair question. My thinking was the system is already not designed to be failproof, just mitigitive (it turns off entirely if no internet), and that malware would be pretty limited in what it could do in just a few hundred ms.

Waiting to open an app based on a network request is basically just guaranteed to give you a terrible experience some % of the time.

Maybe fancier solutions like a local blacklist are needed. (Which weirdly it looks like Apple had and then moved away from?)

Re: macOS has checked app signatures online for over 2 years

#397
post #29

Earlier quoted context omitted.

> A common refrain in arguments that we don't need laws to protect privacy is that the market will take care of it Seriously, who has ever been successful at defending that idea ?

Many lobbyists and lawmakers, unfortunately.

It doesnt count as winning the argument if you paid them to agree with you

Re: macOS has checked app signatures online for over 2 years

#398
post #2

A common refrain in arguments that we don't need laws to protect privacy is that the market will take care of it. The market can't act against what it can't see. Privacy loss is often irreversible. A common refrain in arguments that we don't need to reject closed source software to protect privacy is that being closed source doesn't hide the behaviour, and people will still notice backdoors and privacy leaks. Sometim…

Ya no thanks. Top down regulation will just make startups less likely to enter new disruptive tech. The solution is choice, stop using Apple products and all their shadyness stops being an issue.

> Top down regulation will just make startups less likely to enter new disruptive tech

Im ok with this

Re: macOS has checked app signatures online for over 2 years

#399
What I find a lot scarier is that macOS seems to store your local user's password as a hash with Apple.

A few months ago I was signing in on my MacBook, and it asked me (assuming because I did not have a mobile number attached) for my Hackintosh local user's password to 2FA.

May be buried in the depths of the EULA, but I most definitely never agreed for my LOCAL account password to be uploaded to Apple.

At least signature checks can be blocked (for now) on a DNS level. What about my passwords?

Re: macOS has checked app signatures online for over 2 years

#400
post #194

Earlier quoted context omitted.

No-Logo by Naomi Klein outlined how brands work. One factor in the irrational defence could be a kind of psychological protection of investment. Apple isnt just another company, its an entire lifestyle ecosystem. Those invested in Apple have the watch, tv, laptop, itunes etc. And together they really do "just work" - the user experience is great! So to admit that Apple is flawed, that their investment was a bad idea…

The article points out that while there are drawbacks to checking app signatures, there have also been documented benefits in terms of uncovering vulnerabilities and making systems more secure, which also has direct privacy benefits to the users whose systems don't become compromised by malware. The balancing act between freedom and security is never going to not be a debate. Engaging in it in good faith as in the li…

Signature checking is not what people are mad about, the only way to get anything not bad from this situation is in the most abstract view that signature checking is not bad

thats the problem with people who dismiss Klein and her "oeuvre" you are so desperate to stay in the middle you refuse to see evidence right in front of your face

Post reply on HN