Live data from Hacker News

macOS has checked app signatures online for over 2 years

eclecticlight.co

441–450 of 458 posts

Re: macOS has checked app signatures online for over 2 years

#441
post #52

Earlier quoted context omitted.

Whilst I agree with the sentiment, it does occur to me just how many kindles I see with ads. Is there any data released on ads Vs no ads versions? That's the closest comparator I can think of.

They sold a lot of the ad enabled tablets one black friday for like $80 which seemed like a good deal at the time despite not running google apps which most people desire, having ads on the lock screen, and having the worlds shittiest home screen app for android. I bought one for my wife. If you are lazy or not inclined you can actually pay after the fact to remove ads. Alternatively you can deliberately break the ad…

> having the worlds shittiest home screen app for android...Worst piece of shit ever.

> I bought one for my wife.

Aww, that's so sweet! ;)

Re: macOS has checked app signatures online for over 2 years

#442
post #260

Earlier quoted context omitted.

I'm having trouble figuring out your meaning in this context. Care to explain?

There is no evidence Apple is storing any information collected via OCSP for advertising, or collecting metadata along with it. Effectively all they know is an IP address and a hash identifying a developer certificate that can correspond to any of dozens of apps.

How does "coulda woulda shoulda" mean that?

Re: macOS has checked app signatures online for over 2 years

#443

Earlier quoted context omitted.

They sold a lot of the ad enabled tablets one black friday for like $80 which seemed like a good deal at the time despite not running google apps which most people desire, having ads on the lock screen, and having the worlds shittiest home screen app for android. I bought one for my wife. If you are lazy or not inclined you can actually pay after the fact to remove ads. Alternatively you can deliberately break the ad…

> having the worlds shittiest home screen app for android...Worst piece of shit ever. > I bought one for my wife. Aww, that's so sweet! ;)

Prior experience had led me to believe that crappy default experience was relatively common in Android but easy to rectify.

Mea culpa but her replacement is so nice I got one too. Moto g7 powers.

Re: macOS has checked app signatures online for over 2 years

#444

Honest question I'm not an expert: The initial commments in this thread are painting it as a severe privacy violation. (The actual OP article author does not necessarily share this perspetive). How is what is being done with OCSP different in more concerning way for privacy (if it is) from Firefox or Chrome's use of OCSP?

Chrome doesn't use online OCSP checking, and it's optional in Firefox. Both browsers support OCSP stapling, which doesn't violate privacy and has better failure modes, as well as certificate revocation lists.

Because online OCSP checks damage privacy and don't help much with security, browsers are moving away from them:

https://www.ssl.com/article/how-do-browsers-handle-revoked-s...

Re: macOS has checked app signatures online for over 2 years

#445

Earlier quoted context omitted.

Of course, it would. IPs are required data to be gathered. They can be almost all the time correlated with real identities using other requests, but under many data regulation laws they wouldn't be allowed to send personal identifying information that isn't necessary.

GDPR would not agree with you there, I gather.

How does the GDPR agree with the collection of personally identifying data that is not necessary to operation?

Re: macOS has checked app signatures online for over 2 years

#446

Earlier quoted context omitted.

Market bubbles are a thing. For a while there everyone was convinced that small plush toys were going to help them retire. Yes, bubbles are a thing, but Bitcoin appears to be something different. It's passed ever test and attack. It's now being taken seriously by mainstream financial professionals, CEOs of publicly traded companies and Wall Street. These facts themselves can't prove that Bitcoin is not a bubble but i…

> Also, Bitcoin has been the best performing asset of the past 10 years in which most people didn't take it seriously You're literally describing the bubble. An asset that is worth $20k one day, and worth $6k 6 months later, is worthless to anyone except speculators, speculating on... a bubble. Disclaimer: I am long BTC.

You're literally describing the bubble. An asset that is worth $20k one day, and worth $6k 6 months later, is worthless to anyone except speculators, speculating on... a bubble.

This is short term thinking and a general mischaracterization.

First, we've never seen a new form of money created in realtime, so it's hard to say how it's supposed to perform.

However, nobody should expect something that will fairly soon have the same market cap as gold (about $10 trillion dollars) to not have a lot volatility as it grows. The tech darlings of today—Apple, Google, Twitter, etc. were also quite volatile as they grew.

There's a lot of ups and downs for Apple as it went from darling startup to nearly going out of business in the mid-90's to a $2 trillion dollar market cap today.

As you may know, the mantra in the bitcoin community is to HODL—hold on for dear life, not to time the market. For long term investors, the ups and downs don't matter.

A publicly traded company that puts its treasury of $425 million into Bitcoin isn't speculating: https://www.microstrategy.com/en/bitcoin.

Re: macOS has checked app signatures online for over 2 years

#447

Earlier quoted context omitted.

Who knows, may be they can start to send id too by a special request from the server or send those hashes by other channels in addition to this one, but much later. And server can make such request based on some heuristics or based on some 'black list' of hashes. How can you know for sure? We can only guess to the certain degree without looking into sources.

Why would they NOT want the data now but would want it in some unspecified future?

To avoid being caught could be one reason. Why would they hide the feature without option in GUI to turn it off? We do not know. Possibly they are hiding something else, something bigger, who knows.

Re: macOS has checked app signatures online for over 2 years

#448
post #272

Earlier quoted context omitted.

They _are_ orthogonal, you’re just saying that you can have some of both which is exactly my my point about them existing on a spectrum. And it’s not as simple as encrypting data. You have to trust somebody to determine what good integrity looks like and to then verify the integrity information is fresh. The same privacy concern exists if you run OCSP against cypher-text as it does plaintext. You still have a stream…

You're using the extreme cases of each to argue they are "orthogonal". Perhaps at some extreme no one actually lives in, they are orthogonal. Most people don't need extreme privacy or extreme security, so in the cases that matter, this observation (which seems to be a major crux in your argument) is not important.

The point is that the more private you make something the less ability you have to audit its integrity. If sending a 3rd party a list of hashes is a privacy problem, then security is what takes a hit in order to preserve privacy. That’s not an “extreme case”, it’s what’s being discussed in the essay and in this thread.

Similar examples include DNS over TLS vs DNS filtering for content security, and client certs for mutual TLS vs exposing personal information in said cert, and secure neighbor discovery, and IPv6 (can’t have a global IP because someone might track it), the list goes on.

I’m not saying we should pursue security at all costs or privacy at all costs, far from it. I am saying exactly that there’s a balance between the two and moreover that the balancing point may be different for individual people which leads to arguments like we’re seeing here between people who calibrate more on the security end vs people who prefer extreme privacy. And in my experience people very often conflate the two, which makes it hard to have a productive discussion.

Finally, I’d venture to say that the privacy push of late is having impacts on the ability to deploy strong identity because much of the privacy wave lacks the nuance to distinguish between entities you trust and hence with which it’s okay to maintain a stable secure identity, and those that aren’t. Instead the trend lately has been remove stable identifiers (e.g. Apple’s move to fake mac addresses and GDPR’s IPs are PII) and conceal everything no matter what (TLS 1.3 and DoT/DoH although props to Mozilla for making it possible to configure at the network level via DNs).

Re: macOS has checked app signatures online for over 2 years

#449
post #314

It kind of feels like there's a bit too much noise around this topic. I'm getting the same feeling I did years ago when it was discovered that the iPhone had a historical database of all the locations you'd been to. There were rather a lot of articles about how Apple were "tracking you everywhere you went" and so on. The reason it's similar – they are both dumb, technically bad, and privacy-compromising decisions, an…

It’s actually not at all obvious how a local list of locations used to power suggestions in maps or Siri, is in any way a compromise of privacy or technically bad. The only thing that made it sound bad were people saying things like “Apple stores your location history”, knowing that it would create the false impression that Apple was uploading location data to their servers. This situation is similar in that there ar…

Every iOS device connects to Apple's push service and stays connected. The client certificate it uses is tied to the serial number of the device itself, when it registers for the push service.

Apple sees the client IP of the push connection, naturally.

Therefore, based on IP geolocation, Apple really does have coarse location history for every single iOS device by serial number.

Apple is indeed storing your (coarse) location history.

Re: macOS has checked app signatures online for over 2 years

#450

Earlier quoted context omitted.

> Also, Bitcoin has been the best performing asset of the past 10 years in which most people didn't take it seriously You're literally describing the bubble. An asset that is worth $20k one day, and worth $6k 6 months later, is worthless to anyone except speculators, speculating on... a bubble. Disclaimer: I am long BTC.

You're literally describing the bubble. An asset that is worth $20k one day, and worth $6k 6 months later, is worthless to anyone except speculators, speculating on... a bubble. This is short term thinking and a general mischaracterization. First, we've never seen a new form of money created in realtime, so it's hard to say how it's supposed to perform. However, nobody should expect something that will fairly soon ha…

> First, we've never seen a new form of money created in realtime, so it's hard to say how it's supposed to perform.

This hasn't changed with Bitcoin. BTC is money like a gold bar, beanie baby, or block of IPv4 addresses is money.

> However, nobody should expect something that will fairly soon have the same market cap as gold (about $10 trillion dollars) to not have a lot volatility as it grows. The tech darlings of today—Apple, Google, Twitter, etc. were also quite volatile as they grew.

Nobody describes the tech darlings as money, or as an alternative form of currency. They're equities you can invest in, and comes with the expected volatility.

> As you may know, the mantra in the bitcoin community is to HODL—hold on for dear life, not to time the market. For long term investors, the ups and downs don't matter.

It's nice that there's a backcronym that's been created from a typo. I still don't invest in money, I use money to invest in assets.

Disclaimer: I remain long bitcoin (since 2012)

Post reply on HN