Live data from Hacker News

Yet another macOS privacy protections bypass

lapcatsoftware.com

61–70 of 94 posts

Re: Yet another macOS privacy protections bypass

#61
post #32
post #26

Earlier quoted context omitted.

"vote with your wallet" would say some purists.

I don’t know that voting with your wallet works with the richest company in the world, especially when a lot of professionals have to have their devices to do their jobs.

Voting with your wallet is the crudest & most direct form of power that people have. In a way, it surpasses democracy. So yes, if enough people do it, it does make a difference.

The HN crowd in particular has a sizeable influence on other people with regards to technology. Because we are the techies, people ask us what they should use/buy. People observe what knowledgeable people do, and they tend to learn from it. You have more influence than you think. It just takes time to see the changes take effect.

Re: Yet another macOS privacy protections bypass

#62
post #9

I would appreciate these disclosures a lot more if the author didn’t always include a flippant dismissal of security architecture improvements in macOS. Yes, it’s harder to write software with sandboxing and other modern security techniques, but that doesn’t mean we should go back to how things were.

It's not flippant, read through the author's history: https://lapcatsoftware.com/articles/index.html This is a serious stance of his, with a lot of serious data and arguments to back it up, from a serious engineer who has written an impressive list of Mac software both for Apple and for Apple's customers.

The biggest issue with the author is that he complains both about the controlling/locked down nature of Apple’s platforms and about any bugs that show up in that system.

I.e. His goal is to criticize Apple no matter what they do, because he dislikes the fact that they are no longer producing the kind of open system he prefers.

Re: Yet another macOS privacy protections bypass

#63

Earlier quoted context omitted.

> The only way I can interpret that is to conclude Apple doesn't really care about the integrity of their sandbox. There are many other ways to interpret it. Here is one completely made-up example that I created just now for this reply: "Apple can't lock this down further without breaking open() calls in the majority of existing applications; therefore, they made a pragmatic choice to allow this issue to exist until…

> while declining to share their decision with the reporter, as is completely normal for Apple This is completely normal for Apple, but that doesn’t make it OK for them to treat security fixes like product launches where they can choose an arbitrary timeline and keep the reporter hanging forever.

Sure but it also doesn’t justify innuendo about Apple not caring about privacy.

You know as well as I do that this stuff is complicated.

Re: Yet another macOS privacy protections bypass

#64
post #32

Earlier quoted context omitted.

I don’t know that voting with your wallet works with the richest company in the world, especially when a lot of professionals have to have their devices to do their jobs.

Voting with your wallet is the crudest & most direct form of power that people have. In a way, it surpasses democracy. So yes, if enough people do it, it does make a difference. The HN crowd in particular has a sizeable influence on other people with regards to technology. Because we are the techies, people ask us what they should use/buy. People observe what knowledgeable people do, and they tend to learn from it. Y…

> In a way, it surpasses democracy.

Is there any form of democracy in practice that doesn't involve money?

> The HN crowd in particular has a sizeable influence on other people with regards to technology. Because we are the techies, people ask us what they should use/buy.

See, many of us do recommend people to buy Apple. Because they're still very much the lesser evil among the Microsofts and Googles. If Apple does go bad, it's ridiculously easy to avoid Apple completely: Just don't buy any Apple hardware. Done. Not so easy with MSFT or GOOG, which is what we warn people about.

And that's something the other side on HN can't seem to be able to handle and tries to bury any opposing comments to give the impression of a homogenous echo chamber.

Re: Yet another macOS privacy protections bypass

#65
post #42

Earlier quoted context omitted.

A well behaved, codesigned app being able to list metadata about files in restricted directories is a sandbox compromise. In what viewpoint is it not?

As pointed out by the most voted top level comment it's a kernel issue.

A kernel issue where it fails to adequately enforce the sandbox?

Re: Yet another macOS privacy protections bypass

#66
post #35

Earlier quoted context omitted.

> Apple did the right thing by only adding warnings for more sensitive areas like your Downloads or Documents folder, but any more than that and I think it'll cause more harm than good. Browsing history is not sensitive‽

I think they are implying apple can’t control the sensitivity of third party tools across the board, so it’s up to chrome to figure out how to protect your browsing history, and they need to improve their file system layout or APIs to protect their users.

Safari uses APIs to protect its data directory that isn’t made available to third-party apps.

Re: Yet another macOS privacy protections bypass

#67
post #62
post #9

Earlier quoted context omitted.

It's not flippant, read through the author's history: https://lapcatsoftware.com/articles/index.html This is a serious stance of his, with a lot of serious data and arguments to back it up, from a serious engineer who has written an impressive list of Mac software both for Apple and for Apple's customers.

The biggest issue with the author is that he complains both about the controlling/locked down nature of Apple’s platforms and about any bugs that show up in that system. I.e. His goal is to criticize Apple no matter what they do , because he dislikes the fact that they are no longer producing the kind of open system he prefers.

I think the angle he has is “Apple should remove these protections because they can’t implement them correctly”.

Re: Yet another macOS privacy protections bypass

#68
post #63

Earlier quoted context omitted.

> while declining to share their decision with the reporter, as is completely normal for Apple This is completely normal for Apple, but that doesn’t make it OK for them to treat security fixes like product launches where they can choose an arbitrary timeline and keep the reporter hanging forever.

Sure but it also doesn’t justify innuendo about Apple not caring about privacy. You know as well as I do that this stuff is complicated.

Yeah, it probably is; maybe it requires substantial changes in the kernel or something. The issue is that Apple never communicates this, they just sit on bugs until they fix them. This is a really poor experience for people reporting issues.

Re: Yet another macOS privacy protections bypass

#69
post #63

Earlier quoted context omitted.

> while declining to share their decision with the reporter, as is completely normal for Apple This is completely normal for Apple, but that doesn’t make it OK for them to treat security fixes like product launches where they can choose an arbitrary timeline and keep the reporter hanging forever.

Sure but it also doesn’t justify innuendo about Apple not caring about privacy. You know as well as I do that this stuff is complicated.

[deleted]

Re: Yet another macOS privacy protections bypass

#70

> The only reason I was even looking for bugs here is that I could have really used the extra money, since it's difficult nowadays to make a living as a Mac developer in the face of ever increasing (and futile) macOS lockdown. Sadly, it's not very difficult to find bugs, though it's extremely difficult to get paid a bounty for them. Prepackage the scripts, weaponize and sell them on White House Market You incur no li…

Is this really the outcome you want?
Post reply on HN