Live data from Hacker News

PSA: macOS updates often modify your System Preferences to violate your Privacy

news.ycombinator.com

31–40 of 43 posts

Re: PSA: macOS updates often modify your System Preferences to violate your Privacy

#31
post #8
post #7

This has been discussed here: https://news.ycombinator.com/item?id=26303946

This is very different from a sudoers file though. Apple has full control of how those things are configured, so they could easily migrate the values if they want, for example. The fact that they doesn't shows either a malice from them, or at least very sloppy engineering/product management. Because this kinda of attitude is really bad, and if it was a product from any other company (like Google) I am sure that peopl…

Yes, that is exactly the point - there are so many such incidents (and not just with Apple but with Google and Microsoft OS / apps too) that leak users personal data, and when someone publicly points it, the ready-made excuse is that it is a "bug".

Re: PSA: macOS updates often modify your System Preferences to violate your Privacy

#32
post #6
post #5

Apple also tries to trick you into enabling Siri every time you install a security update.

Same thing with iOS updates. Every major update will force you to go through all of the options that Apple wants you to use like having a passcode and using Siri and other such things. If you don't choose the options that Apple wants you to choose – they will put a notification on the Settings app that you did not finish setup. Then you have to go through the entire setup again choosing the same exact options that yo…

Yeah, for all the privacy and restriction features iOS provides, disabling it all and resetting some or all of it everytime you update your OS makes it really meaningless! I've come to realise that this is all Apple's own security theatre approach to mislead their users.

Re: PSA: macOS updates often modify your System Preferences to violate your Privacy

#34

Earlier quoted context omitted.

By "trick you into enabling" do you mean "asks"?

Asking multiple times to get a different answer is trickery.

Trickery is opt-in by default and making it hard to opt-out.

Re: PSA: macOS updates often modify your System Preferences to violate your Privacy

#35
post #6
post #5

Apple also tries to trick you into enabling Siri every time you install a security update.

Same thing with iOS updates. Every major update will force you to go through all of the options that Apple wants you to use like having a passcode and using Siri and other such things. If you don't choose the options that Apple wants you to choose – they will put a notification on the Settings app that you did not finish setup. Then you have to go through the entire setup again choosing the same exact options that yo…

Well, I actually think that forcing, or encouraging the average user to use a pin code to unlock the phone is a good thing.

I can't get my mother to use one, and she has a lot of information about me in his phone (emails, conversations, etc).

Re: PSA: macOS updates often modify your System Preferences to violate your Privacy

#36
In my case, I didn't see any reset in Firewall settings or Limit Ad Tracking as I just updated one of my macOS Big Sur from v11.2.2 to v11.2.3 (on a MacBook Pro 2015).

P.S.: I checked these settings after reading your post and before updating my laptop.

Re: PSA: macOS updates often modify your System Preferences to violate your Privacy

#37

This sounds exceedingly uncharacteristic of Apple and almost certainly a bug, not intentional. I know it’s hard to get their attention filing bugs so upvoting in case anyone can help get this to the right eyes. But I definitely don’t think there was malice or even conscious intent on this one.

To be honest, it doesn't even sound like a privacy threat as much as it as a potential security (and respect of user choice) question to me.

If software that's already running on the system wants to e.g. exfiltrate something from the system, or to phone home or whatever, it could do that just as well by making an outwards connection as by accepting an incoming one. (I'm assuming the OS or firewall isn't limiting or reporting on outgoing connections.) Denying incoming connections is more useful for reducing attack surface in case of security vulnerabilities in the running software, and generally not so useful for limiting what the software can intentionally do.

Resetting firewall settings to accept incoming connections to listed or built-in apps overrides user security choices with a more lax policy, and that's concerning whether it's intentional or not. But I'm not sure it's really so much about privacy as it's about respecting user choice.

Re: PSA: macOS updates often modify your System Preferences to violate your Privacy

#38
post #35
post #6

Earlier quoted context omitted.

Same thing with iOS updates. Every major update will force you to go through all of the options that Apple wants you to use like having a passcode and using Siri and other such things. If you don't choose the options that Apple wants you to choose – they will put a notification on the Settings app that you did not finish setup. Then you have to go through the entire setup again choosing the same exact options that yo…

Well, I actually think that forcing, or encouraging the average user to use a pin code to unlock the phone is a good thing. I can't get my mother to use one, and she has a lot of information about me in his phone (emails, conversations, etc).

Dark patterns aren't encouragement.

Encouragement would be a statement of why they recommend some action. Instead they try to trick you.

Re: PSA: macOS updates often modify your System Preferences to violate your Privacy

#40

Earlier quoted context omitted.

Asking multiple times to get a different answer is trickery.

That would normally be called "hassling" someone. It's annoying but not dishonest.

Normally, yes, but in the context of an operating system nagging to enable invasive voice recognition features every time a minor update is installed, I think “trickery” is an accurate descriptor. It is dishonest to ignore that I already said no and to put a check mark where I previously removed one, particularly when the request is to enable an always-on microphone. Anyone acting this way in real life would be called out for malice.
Post reply on HN