Live data from Hacker News

Apple removes first-party firewall exemption in macOS 11.2 beta 2

twitter.com

321–330 of 354 posts

Re: Apple removes first-party firewall exemption in macOS 11.2 beta 2

#321
post #290

In Case You Didn't Know: Big Sur on M1 (and possibly on Intel) maintains a persistent, hardware-serial-number linked TLS connection to Apple (for APNS, just like on iOS) at all times when you are logged in, even if you don't use iCloud, App Store, iMessage, or FaceTime, and have all analytics turned off. There's no UI to disable this. This means that Apple has the coarse location track log (due to GeoIP of the client…

How do you know that apple is logging GeoIPs and performing this association with appleIDs? Or are you just saying it’s possible to do so?

With a datetime and IP, you can geoIP any time in the future. It's a single ETL operation. So you treat it like they do, one way or another.

Re: Apple removes first-party firewall exemption in macOS 11.2 beta 2

#322
post #290

In Case You Didn't Know: Big Sur on M1 (and possibly on Intel) maintains a persistent, hardware-serial-number linked TLS connection to Apple (for APNS, just like on iOS) at all times when you are logged in, even if you don't use iCloud, App Store, iMessage, or FaceTime, and have all analytics turned off. There's no UI to disable this. This means that Apple has the coarse location track log (due to GeoIP of the client…

How do you know that apple is logging GeoIPs and performing this association with appleIDs? Or are you just saying it’s possible to do so?

"There's a camera in your bathroom, but how do you know it's recording?"

Re: Apple removes first-party firewall exemption in macOS 11.2 beta 2

#323
post #187
post #156

Earlier quoted context omitted.

ironically, most of these companies are out of China because they don't want to comply with Chinese laws. Not apple https://applecensorship.com/

> ironically, most of these companies are out of China Of the three companies named: - Google's user-facing services (search, email, app store, docs, ...) are blocked, but Google Ads (which are censored) and Android (which comes without any content that would require censorship) are still sold. - Microsoft: I'm not aware of any of their products being unavailable. Windows is the dominant desktop operating system in C…

no idea why I thought facebook is on that list too... There is AWS in China, but you need to sign "special agreement"

Re: Apple removes first-party firewall exemption in macOS 11.2 beta 2

#324
post #290

In Case You Didn't Know: Big Sur on M1 (and possibly on Intel) maintains a persistent, hardware-serial-number linked TLS connection to Apple (for APNS, just like on iOS) at all times when you are logged in, even if you don't use iCloud, App Store, iMessage, or FaceTime, and have all analytics turned off. There's no UI to disable this. This means that Apple has the coarse location track log (due to GeoIP of the client…

How do you know that apple is logging GeoIPs and performing this association with appleIDs? Or are you just saying it’s possible to do so?

He’s just saying it’s possible to do so.

This claim that Apple are tracking your location because they use TCP/IP to receive connections, has been made many times now.

Nobody has so far presented evidence that Apple does in fact geolocate people or even that they persistently store IP address information related to user accounts.

I don’t know for sure that they do not, but I do know that they are aware that keeping IP addresses is a potential privacy leak, and so at least some of their services are definitely designed to scrub ip addresses from records at the point of ingestion and replace them with anonymized keys before they are passed on to services within the company.

So they know that keeping IP address logs is a potential privacy issue and are working to alleviate that.

I would be surprised if they do this for everything yet, but as far as I can see Sneak is making only a theoretical accusation, and not one which he has more than speculation about.

As far as I can see, statements like these...

“Apple knows when you leave home, or arrive at the office, or travel to a different city, all with no Apple ID, no iCloud, and no location services. This has always been the case on all devices using iOS, too.”..

...are complete bullshit as written, even though we can’t rule out the possibility.

“ Apple doesn’t retain a history of what you’ve searched for or where you’ve been.” is on Apple’s privacy page here: https://www.apple.com/privacy/features/

So if someone can find evidence for such accusations, perhaps there is some legal liability for Apple.

Re: Apple removes first-party firewall exemption in macOS 11.2 beta 2

#325
post #321

Earlier quoted context omitted.

How do you know that apple is logging GeoIPs and performing this association with appleIDs? Or are you just saying it’s possible to do so?

With a datetime and IP, you can geoIP any time in the future. It's a single ETL operation. So you treat it like they do, one way or another.

This assumes they don’t scrub it before storing it, which we know they do for some services, and we have no information about others.

We can’t in fact treat it like they do. We can only treat it like they might be able to.

Re: Apple removes first-party firewall exemption in macOS 11.2 beta 2

#326
post #324

Earlier quoted context omitted.

How do you know that apple is logging GeoIPs and performing this association with appleIDs? Or are you just saying it’s possible to do so?

He’s just saying it’s possible to do so. This claim that Apple are tracking your location because they use TCP/IP to receive connections, has been made many times now. Nobody has so far presented evidence that Apple does in fact geolocate people or even that they persistently store IP address information related to user accounts. I don’t know for sure that they do not, but I do know that they are aware that keeping I…

Perhaps Apple doesn't log your hardware UUID + IP. You'll have to take their word for it.

But there's even less guarantee that the government doesn't log that information.

After all, Apple dropped plans of implementing E2E encryption of iCloud backups after the FBI asked them [1]. So "Apple doesn't retain that info" might boil down to semantics since it might be allowing someone else to do it.

[1] https://www.cnbc.com/2020/01/21/apple-dropped-plan-for-encry...

Re: Apple removes first-party firewall exemption in macOS 11.2 beta 2

#327
post #71

An Apple employee tweeted after the news with 11.0 that this was a bug so I'm not surprised, but happy to see it fixed!

Link?

https://www.zdnet.com/article/apple-removes-feature-that-all...

"The bugs were related to Apple deprecating network kernel extensions (NKEs) in Big Sur and introducing a new system called Network Extension Framework, and Apple engineers not having enough time to iron out all the bugs before the Big Sur launch last fall."

Re: Apple removes first-party firewall exemption in macOS 11.2 beta 2

#328
post #326
post #324

Earlier quoted context omitted.

He’s just saying it’s possible to do so. This claim that Apple are tracking your location because they use TCP/IP to receive connections, has been made many times now. Nobody has so far presented evidence that Apple does in fact geolocate people or even that they persistently store IP address information related to user accounts. I don’t know for sure that they do not, but I do know that they are aware that keeping I…

Perhaps Apple doesn't log your hardware UUID + IP. You'll have to take their word for it. But there's even less guarantee that the government doesn't log that information. After all, Apple dropped plans of implementing E2E encryption of iCloud backups after the FBI asked them [1]. So "Apple doesn't retain that info" might boil down to semantics since it might be allowing someone else to do it. [1] https://www.cnbc.co…

Well the iCloud backups not being encrypted yet is a serious problem.

Weirdly, this isn’t news - anonymous sources have said before that it was due to FBI pressure.

But this doesn’t have anything to do with Apple logging locations.

If sneak’s claim was correct, there would be nothing we could do about it.

If we’re talking about iCloud backups, at the very least you can turn those off and do them locally.

I’m pretty sure that even if e2e backups do come, they won’t be on by default because of the problem of users managing their own keys.

Re: Apple removes first-party firewall exemption in macOS 11.2 beta 2

#329
post #324

Earlier quoted context omitted.

How do you know that apple is logging GeoIPs and performing this association with appleIDs? Or are you just saying it’s possible to do so?

He’s just saying it’s possible to do so. This claim that Apple are tracking your location because they use TCP/IP to receive connections, has been made many times now. Nobody has so far presented evidence that Apple does in fact geolocate people or even that they persistently store IP address information related to user accounts. I don’t know for sure that they do not, but I do know that they are aware that keeping I…

There are ways to communicate over the internet that don't disclose the source IP of the client doing the connecting. Tor also uses TCP/IP, so your oversimplification of my post is... not accurate.

> Nobody has so far presented evidence that Apple does in fact geolocate people or even that they persistently store IP address information related to user accounts.

We're talking about IP address logs related to hardware serials, which cannot be changed. User accounts can.

Re: Apple removes first-party firewall exemption in macOS 11.2 beta 2

#330
post #328
post #326

Earlier quoted context omitted.

Perhaps Apple doesn't log your hardware UUID + IP. You'll have to take their word for it. But there's even less guarantee that the government doesn't log that information. After all, Apple dropped plans of implementing E2E encryption of iCloud backups after the FBI asked them [1]. So "Apple doesn't retain that info" might boil down to semantics since it might be allowing someone else to do it. [1] https://www.cnbc.co…

Well the iCloud backups not being encrypted yet is a serious problem. Weirdly, this isn’t news - anonymous sources have said before that it was due to FBI pressure. But this doesn’t have anything to do with Apple logging locations. If sneak’s claim was correct, there would be nothing we could do about it. If we’re talking about iCloud backups, at the very least you can turn those off and do them locally. I’m pretty s…

Apple had at least a partial implementation of e2e backup that was resilient to users losing their passwords, via something like friends-and-family secret sharing to perform data recovery.

The implementation was scrapped.

There are ways of solving these problems, throwing up hands and saying "it can't be done anyway" is silly. Apple has done a lot of things that couldn't be done: a computer without a floppy or serial ports, a phone without a keyboard, a headset without cables between your ears.

Building the iPhone was difficult. Building APNS and iCloud was difficult. Building the App Store was difficult. Building the Apple Watch was fucking difficult. Building the Ax line of mobile chips was difficult. Building the M1 was difficult. Don't forget about airpods, homepods, and all the other mindbendingly hard shit Apple does all the time now.

Apple does insane technical achievements on a regular basis. Secret sharing for e2e backups is well within their capabilities. Google even managed to e2e encrypt Android backups.

The problem is that Apple serves at the pleasure of the US military intelligence apparatus, and they know it.

It doesn't take a weatherman to know which way the wind blows.

Post reply on HN