Live data from Hacker News

macOS has checked app signatures online for over 2 years

eclecticlight.co

401–410 of 458 posts

Re: macOS has checked app signatures online for over 2 years

#401
post #201
post #52

Earlier quoted context omitted.

Whilst I agree with the sentiment, it does occur to me just how many kindles I see with ads. Is there any data released on ads Vs no ads versions? That's the closest comparator I can think of.

I've never had a non-eInk Kindle, so maybe it is different for them, but I've had eInk Kindles both with and without ads. My first was without ads. Since you can add the "without ads" option to a "with ads" Kindle later by paying the difference, I bought my second with ads to see how bad it was. Here are the only differences I've noticed: • With ads, the sleep screen displays some artwork from a book Amazon is sellin…

On the eink kindle, I paid for ad removal just in general principles. I probably could have lived with the lock screen ads, but the home screen ad was unacceptable. Vast majority of my book purchases over the past ten years have been ebooks. I’ve gone a bit sentimental in thinking of the book list as my library. And I didn’t want a billboard of any sort in my library. Real or virtual. Have a feeling there are at least dozens of us who are that allergic to ads.

I have also purchased a Fire during a Black Friday sale. Got rid of the ads on that one too, but for free since some nice person over at xda made an automated process for that. On a side note, with Termux it isn’t entirely horrible as a 7 inch laptop when paired with a hinged keyboard case. A portable system at a similar price to a Pi.

Re: macOS has checked app signatures online for over 2 years

#402
post #47

I sometimes wonder if the mods won't end up banning "political" talk on HN. Because these days everything becomes political, even if it really is a technical issue. Case to the point: online signature check was a technical decision, to fight malware. It was implemented similarly by other OS vendors (Microsoft) and it's been this way for years. Now we discover that it has the unfortunate side-effect that it lessens pr…

When a giant like Apple makes a decision to disallow installing apps that were not downloaded from the macOS-app store (and by preventing me to open the app, what Apple does is basically disallowing the app; my retired father does not know how to circumvent this), then this is a political descision that effects the lives of thousands of mac users. Computers have become a gateway to the digital world, which makes up a…

I've recently downloaded quite a number of Mac programs directly from the web, as well as from Steam. They work just fine, as long as they've been signed.

What makes you say that Apple has made a "decision to disallow installing apps that were not downloaded from the macOS-app store"? That seems kind of obviously untrue.

I mean, I myself sell Mac software outside the Mac App Store and have never had a complaint.

Maybe you were thinking of the iOS app store?

Re: macOS has checked app signatures online for over 2 years

#403
post #51

Earlier quoted context omitted.

Because when you browse the Internet you know you are browsing it. When you run software, you do not expected "unexpected" Internet use. You go for a walk, you carry an umbrella, or go dressed. You are at home, you do not expect it to "rain" or for someone to "watch you".

That seems incredibly naive. I can’t think of a single program off the top of my head that doesn’t use the Internet to some extent while running. Even many CLI tools I use for development do update checks (and sometimes analytics) in the background.

Others have already pointed out this is an exaggeration but still, there is truth to it.

I wonder how the field of software development has changed so radically that this is somehow considered acceptable and even perhaps normal?

Back in the 90s to mid 00s even, it was considered a clear violation of user expectations and not even remotely acceptable. Back then at Sun it was a big rule to never initiate such opaque network activity that wasn't directly related to user action and the purpose of the code. Requesting exceptions to that would have to be escalated pretty high up and generally rejected. It was something you Just Don't Do.

Even running half a dozen machines at home, my networks connection was entirely silent except for the occasional NTP packets, unless I was actively doing some user-initiated network activity.

These days, well, the outgoing pipe is always active even when no machine is doing anything. Most of that traffic is just variants of spyware, reporting back to HQ on what the user is doing at all times. This should not be considered normal and its on us as the software industry to try to claw back on this problem.

Re: macOS has checked app signatures online for over 2 years

#404
post #368

Earlier quoted context omitted.

> A common refrain in arguments that we don't need laws to protect privacy is that the market will take care of it. Stronger privacy laws hurt Google, Facebook, and Amazon far more than Apple. Most of Apple's privacy gaffs are just bonehead moves like this one which shouldn't happen, but also don't drive revenue.

I don't look at it that way. I think privacy is secondary to Apple, and that they use privacy as a selling point when it suits them. Their overall goal is tight control over the entire computing experience, and in places where that degrades privacy, so be it.

Their goal is making money.

On the iPhone, that means keeping the system's reputation for security and ease of use trumps more or less everything else. On the Mac? Not so much.

For Apple, privacy is a cheap giveaway because unlike Google or Facebook, the way Apple makes money doesn't require they know when my last BM was.

Re: macOS has checked app signatures online for over 2 years

#405

Earlier quoted context omitted.

Imagine you have a shared office DNS resolver (which is pretty common). That resolver would aggregate all of the requests into one shared, cached stream. Then the question becomes "hey Apple, one person of how ever many thousand are behind me would like to know if Adobe's certificate is still valid". That's reasonably anonymized, I think.

That only helps if you have a shared resolver.

Pretty much everyone has a shared resolver at some point. Almost no one’s running a local resolver on their laptop these days.

Re: macOS has checked app signatures online for over 2 years

#407
post #69

Earlier quoted context omitted.

I assume you upgraded OS, in which case it's annoying but not unusual that plugins stop working. A machine that's used for making professional music should not be upgraded or connected to the internet. If it's for a hobby... I think we will have to live with the compromise if we want to have the latest security fixes and connect to the internet.

>should not be upgraded Most DAW-makers are constantly upgrading their software. And they often obsolete their older versions to get in sync with new OS's. 'Keeping the old stuff' sometimes isn't an option. Physical instruments keep working for decades ... but thanks to OS upgrades, valued digital hardware and/or software instruments (say by Opcode or Native) can be lost to stupid or cavalier changes. Anyone who's be…

Yes they are obviously upgrading their software because they need to make money and adding features and fixing bugs is a great way to do that.

The only solution to not having a broken music workstation is to never connect that machine to the internet and never update it. Physical instruments keep working for decades because...they are never connected to the internet and never updated.

Re: macOS has checked app signatures online for over 2 years

#408
post #399

What I find a lot scarier is that macOS seems to store your local user's password as a hash with Apple. A few months ago I was signing in on my MacBook, and it asked me (assuming because I did not have a mobile number attached) for my Hackintosh local user's password to 2FA. May be buried in the depths of the EULA, but I most definitely never agreed for my LOCAL account password to be uploaded to Apple. At least sign…

If you’re using iCloud then that’s coming from keychain. That’s how you can reset the local password with your Apple ID.

Re: macOS has checked app signatures online for over 2 years

#409
post #25

Interesting, but reading the conclusion I'm fascinated in this affaire how technically knowledgeable people loose common sense to defend their favorite brand: - Per launch verification is terrible for privacy, vis-a-vis Apple and the whole network when it happens in plain text - "They should also explain how, having enjoyed their benefits for a couple of years, they’ve suddenly decided they were such a bad idea after…

No-Logo by Naomi Klein outlined how brands work. One factor in the irrational defence could be a kind of psychological protection of investment. Apple isnt just another company, its an entire lifestyle ecosystem. Those invested in Apple have the watch, tv, laptop, itunes etc. And together they really do "just work" - the user experience is great! So to admit that Apple is flawed, that their investment was a bad idea…

This is a good explanation about why people defend brands, but in case of Apple, my experience is that the anti-Apple crowd is more emotionally invested in being anti-Apple than the fans are for it. It used to be the other way around when Apple was the underdog, but after the iPhone took over and became a sort of default for certain regions and social circles, the most loyal brand warriors are the anything-but-Apple fans.

Re: macOS has checked app signatures online for over 2 years

#410
post #366

It kind of feels like there's a bit too much noise around this topic. I'm getting the same feeling I did years ago when it was discovered that the iPhone had a historical database of all the locations you'd been to. There were rather a lot of articles about how Apple were "tracking you everywhere you went" and so on. The reason it's similar – they are both dumb, technically bad, and privacy-compromising decisions, an…

I think people who have this viewpoint are largely ignorant of the amount of tracking data that comes out of a mac or iphone, even in first party apps, that you cannot turn off at all. This is not an isolated incident, and their own OS services are explicitly whitelisted to bypass firewalls and VPNs in Big Sur. There’s telemetry in most Apple apps, now, and you can’t disable it or opt out, or even block or VPN it in…

This is a good example of what I mean - it’s a rant about telemetry that has nothing to do with the issue in question and as a result conflates a whole mess of different issues.

I am pretty well-informed about most of the data that is being generated and transmitted by my machine. This is an issue where it it totally reasonable to pressure Apple and all other companies to design for privacy as a priority and ensure that any of this data collection can be disabled. I don’t think an effective means to do that is to deliberately conflate and mislead about issues like the one under discussion.

Post reply on HN