Live data from Hacker News

macOS has checked app signatures online for over 2 years

eclecticlight.co

421–430 of 458 posts

Re: macOS has checked app signatures online for over 2 years

#421

Earlier quoted context omitted.

> How about $348 billion dollars that says he's wrong about his take on Bitcoin? Market bubbles are a thing. For a while there everyone was convinced that small plush toys were going to help them retire. The market also convinced itself for nearly a decade that "housing prices never go down". Lots of people can be wrong for a surprisingly long time.

Market bubbles are a thing. For a while there everyone was convinced that small plush toys were going to help them retire. Yes, bubbles are a thing, but Bitcoin appears to be something different. It's passed ever test and attack. It's now being taken seriously by mainstream financial professionals, CEOs of publicly traded companies and Wall Street. These facts themselves can't prove that Bitcoin is not a bubble but i…

> Also, Bitcoin has been the best performing asset of the past 10 years in which most people didn't take it seriously

You're literally describing the bubble. An asset that is worth $20k one day, and worth $6k 6 months later, is worthless to anyone except speculators, speculating on... a bubble.

Disclaimer: I am long BTC.

Re: macOS has checked app signatures online for over 2 years

#422
> They should also explain how, having enjoyed their benefits for a couple of years, they’ve suddenly decided they were such a bad idea after all, and what should replace them.

I mean, this is very very presumptuous... the people I know who were "in the know" on this--including myself--never upgraded to Catalina (in addition to doing a SIP disable), in no small part to avoid this intrusive behavior.

(Further, there actually was outcry about this a year ago, when a similar issue happened: just, instead of the system not running software at all, it ran all new software super slowly.)

Re: macOS has checked app signatures online for over 2 years

#423
post #25

Interesting, but reading the conclusion I'm fascinated in this affaire how technically knowledgeable people loose common sense to defend their favorite brand: - Per launch verification is terrible for privacy, vis-a-vis Apple and the whole network when it happens in plain text - "They should also explain how, having enjoyed their benefits for a couple of years, they’ve suddenly decided they were such a bad idea after…

> I'm fascinated in this affaire how technically knowledgeable people loose common sense to defend their favorite brand What I find weird is regardless of what the discussion is involving Apple, someone needs to pop in with one of these theories about Apple tribalism. Very very few people are in fact "defending" Apple here. Even among those few, the sentiment is largely that this is bad and Apple is fixing it.

I presume the comment is about the article, which it quotes, so it doesn't matter how few such people exist.

Re: macOS has checked app signatures online for over 2 years

#424
post #2

A common refrain in arguments that we don't need laws to protect privacy is that the market will take care of it. The market can't act against what it can't see. Privacy loss is often irreversible. A common refrain in arguments that we don't need to reject closed source software to protect privacy is that being closed source doesn't hide the behaviour, and people will still notice backdoors and privacy leaks. Sometim…

> Parts of the US Governments unlawful massive domestic surveillance apparatus were described in the open in IETF drafs and patent documents for years.

References?

Re: macOS has checked app signatures online for over 2 years

#426
post #353

Earlier quoted context omitted.

> This was no secret, it was advertised as a feature. I wish you could prove this.

https://developer.apple.com/videos/play/wwdc2019/703/ The second half of the talk is about the "hardened runtime" And in the wider tech press https://appleinsider.com/articles/19/06/03/apples-macos-cata... "Mac apps, installer packages, and kernel extensions that are signed with Developer ID must also be notarized by Apple in order to run on macOS Catalina" Even on hacker news https://news.ycombinator.com/item?id=211…

Firstly, this is not 'advertised' - this is not a material average apple consumer reads.

Secondly, it does not actually say anything about the OS phoning home and preventing the user from launching an app. The appleinside talks vaguelt of 'Notarisation', something thay can be inplemented in a variety of ways, like signing application with a certificate

Re: macOS has checked app signatures online for over 2 years

#427

Earlier quoted context omitted.

I think the main reason for the dissonance is that Schneier talks about the trust that happens (and maybe has to happen in real-world scenarios) while the bitcoin community likes to talk about the minimum amount of trust necessary. You don't have to trust the software, you can verify it or implement your own. You don't have to trust your internet uplink, the protocol would work over carrier pigeons or with dead drops…

> You don't have to trust the software, you can verify it or implement your own. This is a common refrain among software people, but in reality approximately 0% of the market actually rewrites such software on their own. Most people can't code, and the percentage of those who have the time, interest, and specialized programming skills to rewrite their own financial software is an incredibly tiny pool. In practice, yo…

> If your system counts on either telling people to avoid the most convenient option to accomplish the task, your advice will continually fail.

Louder please - this is applicable far beyond cryptocurrency.

Re: macOS has checked app signatures online for over 2 years

#428
post #247

Earlier quoted context omitted.

I've been wondering why CRL couldn't be used if the OCSP goes down or no reply is received. That way you get the benefits of both. Any reason why this would be a bad idea? Also are CRLs really that bad in practice? I know it would be a bad idea on a smartphone but is it really an issue on a laptop?

The other main issue is bandwidth. For a CRL, Apple has to serve the full list of revoked serial numbers (or some shard of it), even if 90% of users don’t have 90% of the revoked apps installed. I can’t remember where I read this, but I recall that after the Heartbleed disclosure one CA saw their CRL traffic grow by some number in the gigabits per second. Bandwidth is relatively cheap, but still not free (without eve…

They have the bandwidth for some pretty big firmware/OS updates, though. This would be a fraction of that size. They download blacklists already for their inbuilt AV. Also if they use something like Git then only the changes will be downloaded rather than the entire CRL.

I can’t help but feel that the issue is something else, not bandwidth.

Re: macOS has checked app signatures online for over 2 years

#430
post #367
post #341

Earlier quoted context omitted.

This is pretty much how I interpret it as well, in regards to trust. One detail Schneier misses though is: > Honestly, cryptocurrencies are useless. They’re only used by speculators looking for quick riches, people who don’t like government-backed currencies, and criminals who want a black-market way to exchange money. The second statement contradicts the first. People who don't like/trust government-backed currencie…

This just feels like moving the goalposts, though. Bitcoin has been pushed as this revolutionary thing that's going to fundamentally change currency and payments for everyday people. It hasn't. It likely won't. Maybe some other blockchain-based currency will at some point, but I'm skeptical of that claim. Beyond that, Bitcoin as a simple store of value is an incredibly risky proposition. Someone upthread posted a lin…

Not arguing any of that. Bitcoin is not very useful as a currency. But I trust bitcoin as a concept more than I trust USD, which is currently being devalued/inflated in favor of the stock market, solely for the gain of people who are more well off than most. I'm not a doomsday prophet nor an economist but the future of the world economy is not looking great.

Bitcoin was created as something that governments/banks/corporations couldn't control or manipulate and that's something that's worth a lot in itself, I think.

And as I mentioned Monero is quite convenient for shopping on the dark web, without government intervention.

If you trust your government, banks, politicians, and agree with all the laws and taxes, then yeah, you might truthfully state that cryptocurrencies are useless. But some believe and argue that governments shouldn't have that kind of control and people should have a higher degree of freedom and privacy.

This went a bit off topic perhaps.

Post reply on HN