Live data from Hacker News

macOS has checked app signatures online for over 2 years

eclecticlight.co

451–458 of 458 posts

Re: macOS has checked app signatures online for over 2 years

#451
post #366

Earlier quoted context omitted.

I think people who have this viewpoint are largely ignorant of the amount of tracking data that comes out of a mac or iphone, even in first party apps, that you cannot turn off at all. This is not an isolated incident, and their own OS services are explicitly whitelisted to bypass firewalls and VPNs in Big Sur. There’s telemetry in most Apple apps, now, and you can’t disable it or opt out, or even block or VPN it in…

This is a good example of what I mean - it’s a rant about telemetry that has nothing to do with the issue in question and as a result conflates a whole mess of different issues. I am pretty well-informed about most of the data that is being generated and transmitted by my machine. This is an issue where it it totally reasonable to pressure Apple and all other companies to design for privacy as a priority and ensure t…

System services bypassing VPN and firewall because they're on a vendor whitelist (that can't be modified due to OS cryptographic protections) is a) fact not rant and b) nothing to do with telemetry.

Re: macOS has checked app signatures online for over 2 years

#452
post #449
post #314

Earlier quoted context omitted.

It’s actually not at all obvious how a local list of locations used to power suggestions in maps or Siri, is in any way a compromise of privacy or technically bad. The only thing that made it sound bad were people saying things like “Apple stores your location history”, knowing that it would create the false impression that Apple was uploading location data to their servers. This situation is similar in that there ar…

Every iOS device connects to Apple's push service and stays connected. The client certificate it uses is tied to the serial number of the device itself, when it registers for the push service. Apple sees the client IP of the push connection, naturally. Therefore, based on IP geolocation, Apple really does have coarse location history for every single iOS device by serial number. Apple is indeed storing your (coarse)…

> Therefore, based on IP geolocation, Apple really does have coarse location history for every single iOS device by serial number.

This conflates technical possibility with an implemented system which stores that data and the insinuation that this is used for purposes other than what the user enabled. Do you have an evidence that Apple stores this data and uses it in violation of their privacy policy? You're apparently in Europe so you should be able to file a GDPR request to see exactly what they're storing.

Re: macOS has checked app signatures online for over 2 years

#453

Earlier quoted context omitted.

Then the question is, "how much do I trust my ISP/DNS provider?" Those DNS lookups tell your ISP 1) that you use a mac and 2) that you have an application from a specific developer installed. I think I trust my ISP less than I trust Apple, here. Am I wrong to do so?

Well, back to the state right now where your ISP can see your plaintext HTTP packets if they want to, so it wouldn't be any worse than the current situation. I guess you could get much the same effect by configuring your company Macs to point at a shared Squid server to cache the GET requests from the OCSP server, but in practice almost no one does that.

Apple says they're going to move to an HTTPS based system, so the relevant comparison is between HTTPS and DNS, not HTTP and DNS.

Re: macOS has checked app signatures online for over 2 years

#454

Earlier quoted context omitted.

> Also, Bitcoin has been the best performing asset of the past 10 years in which most people didn't take it seriously You're literally describing the bubble. An asset that is worth $20k one day, and worth $6k 6 months later, is worthless to anyone except speculators, speculating on... a bubble. Disclaimer: I am long BTC.

You're literally describing the bubble. An asset that is worth $20k one day, and worth $6k 6 months later, is worthless to anyone except speculators, speculating on... a bubble. This is short term thinking and a general mischaracterization. First, we've never seen a new form of money created in realtime, so it's hard to say how it's supposed to perform. However, nobody should expect something that will fairly soon ha…

> First, we've never seen a new form of money created in realtime.

Call me when I can buy my latte and groceries with bitcoin, or pay my mortgage. Until then you've made an investment vehicle, not money.

> The tech darlings of today—Apple, Google, Twitter, etc. were also quite volatile as they grew.

Survivorship bias. Pointing to a handful of random successful companies and trying to draw conclusions is literally meaningless.

> As you may know, the mantra in the bitcoin community is to HODL—hold on for dear life, not to time the market. For long term investors, the ups and downs don't matter.

Yeah, this isn't something you actually say about money. Honestly, it would be a kind of cultish thing to say about an investment too. I don't need a mantra for how I invest in my 401k, why does Bitcoin need one?

> A publicly traded company that puts its treasury of $425 million into Bitcoin isn't speculating

That's the literal definition of speculation, a risky one at that.

Re: macOS has checked app signatures online for over 2 years

#455
post #452
post #449

Earlier quoted context omitted.

Every iOS device connects to Apple's push service and stays connected. The client certificate it uses is tied to the serial number of the device itself, when it registers for the push service. Apple sees the client IP of the push connection, naturally. Therefore, based on IP geolocation, Apple really does have coarse location history for every single iOS device by serial number. Apple is indeed storing your (coarse)…

> Therefore, based on IP geolocation, Apple really does have coarse location history for every single iOS device by serial number. This conflates technical possibility with an implemented system which stores that data and the insinuation that this is used for purposes other than what the user enabled. Do you have an evidence that Apple stores this data and uses it in violation of their privacy policy? You're apparent…

Everything I described is implemented today, and is required for APNS to work. Whether Apple does or does not mine the data in some way that you personally find offensive is not relevant; the fact is that they are presently logging IPs for APNS connections, which have unique identifiers that are related directly to hardware serial numbers in their database. Because IPs generally equal location, they are in possession of location history for each iOS device serial number.

I'm not sure why these (plainly factual) statements are controversial.

Re: macOS has checked app signatures online for over 2 years

#456
post #455
post #452

Earlier quoted context omitted.

> Therefore, based on IP geolocation, Apple really does have coarse location history for every single iOS device by serial number. This conflates technical possibility with an implemented system which stores that data and the insinuation that this is used for purposes other than what the user enabled. Do you have an evidence that Apple stores this data and uses it in violation of their privacy policy? You're apparent…

Everything I described is implemented today, and is required for APNS to work. Whether Apple does or does not mine the data in some way that you personally find offensive is not relevant; the fact is that they are presently logging IPs for APNS connections, which have unique identifiers that are related directly to hardware serial numbers in their database. Because IPs generally equal location, they are in possession…

There’s no question that they need connections to operate the service but they do not need to retain that information, however, and while you have repeatedly asserted that they do, you have been unable to support that claim. This would be covered by privacy laws in many places so it should be easy to point to their privacy disclosures or the result of an inquiry showing that they do in fact retain connection logs for more than a short period of time.

Re: macOS has checked app signatures online for over 2 years

#457
post #456
post #455

Earlier quoted context omitted.

Everything I described is implemented today, and is required for APNS to work. Whether Apple does or does not mine the data in some way that you personally find offensive is not relevant; the fact is that they are presently logging IPs for APNS connections, which have unique identifiers that are related directly to hardware serial numbers in their database. Because IPs generally equal location, they are in possession…

There’s no question that they need connections to operate the service but they do not need to retain that information, however, and while you have repeatedly asserted that they do, you have been unable to support that claim. This would be covered by privacy laws in many places so it should be easy to point to their privacy disclosures or the result of an inquiry showing that they do in fact retain connection logs for…

It stands to reason that user of the service who has agreed to the TOS that governs APNS and App Store sending unique device hardware serial numbers to Apple has also (legally) consented to IP address collection. IP addresses are less unique identifiers than globally unique device serials, so I assume Apple has already secured what passes for "consent" under the relevant privacy laws.

Re: macOS has checked app signatures online for over 2 years

#458
post #457
post #456

Earlier quoted context omitted.

There’s no question that they need connections to operate the service but they do not need to retain that information, however, and while you have repeatedly asserted that they do, you have been unable to support that claim. This would be covered by privacy laws in many places so it should be easy to point to their privacy disclosures or the result of an inquiry showing that they do in fact retain connection logs for…

It stands to reason that user of the service who has agreed to the TOS that governs APNS and App Store sending unique device hardware serial numbers to Apple has also (legally) consented to IP address collection. IP addresses are less unique identifiers than globally unique device serials, so I assume Apple has already secured what passes for "consent" under the relevant privacy laws.

Again, nobody is questioning their access to that information. Where you typically go wrong is by asserting without evidence that they are performing additional activities without disclosing that. Surely you understand that having IPs be visible does not automatically mean retaining those records, much building a searchable database?
Post reply on HN