Live data from Hacker News

My Mac contacted 63 different Apple owned domains in an hour, while not is use

appaddict.app

141–150 of 218 posts

Re: My Mac contacted 63 different Apple owned domains in an hour, while not is use

#141
post #34

Little Snitch can detect and block connections at the process level. https://www.obdev.at/products/littlesnitch/index.html

that works in a lot of cases, but unfortunately it seems sometimes you get these popups about nsurlsessiond (for example) where you know where the connection goes, but no idea where it comes from (especially if it's trying to connect to to some generic AWS hostname) And as much as you can use little snitch for programs you install, these days it seems an endless whack-a-mole to block Apple's stuff as there's so many…

> unfortunately it seems sometimes you get these popups about nsurlsessiond (for example) where you know where the connection goes, but no idea where it comes from (especially if it's trying to connect to to some generic AWS hostname)

Little Snitch might be able to tell which process triggered that, if you press the info button in the alert. I'll have to check next time it happens.

Re: My Mac contacted 63 different Apple owned domains in an hour, while not is use

#142

Earlier quoted context omitted.

Apple is nowhere near as evil as Microsoft, so I’m willing to put up with it.

Apple has been involved in all the same government spying programs as Microsoft. They do not offer any services or products with E2E encryption that they do not control the key too.

> They do not offer any services or products with E2E encryption that they do not control the key too.

That’s way off the mark from reality. You can look at Advanced Data Protection. It’s not enabled by default for the sake of convenience, but it’s an option available to the users.

Re: My Mac contacted 63 different Apple owned domains in an hour, while not is use

#143

Earlier quoted context omitted.

Apple does too! Drives me crazy, although it’s not nearly as bad as Windows.

I have never seen this. What ads are you referring to in MacOS?

They keep trying to get me to buy iCloud space in the settings menu

Re: My Mac contacted 63 different Apple owned domains in an hour, while not is use

#144

The way I see it is either you trust Apple or you don’t. To be clear, I think it’s perfectly reasonable to arrive at either conclusion, as it relates to your own needs and security posture. Personally I choose to trust them. My trust is not blind, and they could lose my trust very quickly. But as it stands right now, they have my trust. If you say that you don’t trust Apple, I don’t see how you could tolerate running…

> The way I see it is ...

That's one way to view it.

One might also view the large number of Apple-owned domains here as evidence that Apple's infrastructure is a sprawling mess, and reduce trust accordingly.

Re: My Mac contacted 63 different Apple owned domains in an hour, while not is use

#145

Earlier quoted context omitted.

The whole point is that a 3rd party (Apple) doesn’t have the key. It’s not real E2E and it’s still susceptible to government overreach.

Still need your password to use the key

No Apple can unlock your phone with the master key they used to generate your phone hardware enclave key. This is how the FBI has pressured them in the past to unlock devices.

Re: My Mac contacted 63 different Apple owned domains in an hour, while not is use

#146
post #116
post #59

Earlier quoted context omitted.

How do you think push should work? Any push service works this way. The client contacts the server to be updated. The server gives a no data or a data response. The server cannot magically contact the client.

What do you think the word "push" means in the word "push"? It doesn't mean "pull", btw.

I think this is one of those many cases where how the technology works doesn't match the actual meaning of the English word, but for whatever reason the word has stuck.

For better or worse, a lot of things on the Internet now assume that only "servers" can accept incoming connections, and therefore anything that needs to be "sent" to clients needs to be done by making the client poll a server over and over. True P2P apps (with no intermediary server) are pretty rare now, for a variety of reasons: some good reasons, some stupid reasons.

Re: My Mac contacted 63 different Apple owned domains in an hour, while not is use

#147
post #42

For fun, compare and contrast the comments here to this post on Windows 10 from 5 days ago: https://news.ycombinator.com/item?id=44208050

An important variable, the titles of the posts set the stage. That post's title was "Windows 10 _spies_ on your use of System Settings" whereas this one is "My Mac _contacted_ 63 different Apple owned domains in an hour, while not is use." It would be interesting to, in a month or so when everyone has forgotten this conversation, repost this with a more critical title and see if that reshapes the comments or influenc…

Apple gets a lot of benefit of doubt here and in the tech press, some of it having been earned. When other vendors' OSs phone home dozens of time, it's nefarious. When Apple phones home dozens of times, it's for innocent "core functionality" or other reasons that sound acceptable.

Re: My Mac contacted 63 different Apple owned domains in an hour, while not is use

#148

It's even better that quite a few of those connections are unencrypted (and are actively used by some vendors to profile devices).

From my understanding this isnt correct. While a DNS resolution may or may not be encrypted, which is highly dependent on the local client's environment. Data being sent to apple is not being sent via DNS, as these DNS connections are only the beginning of negotiating a conneciton to Apple's servers. The connections themselves where data is transfered, are negotiated using TLS and thus encrypted. The only point where…

> Data being sent to apple is not being sent via DNS

Obviously I'm talking about what follows the name resolution.

> The connections themselves where data is transfered, are negotiated using TLS and thus encrypted.

They're not, as I said there are quite a few unencrypted ones. Last time I couldn't even set up a HomePod without allowing insecure connections.

> but none of these would be capable of portraying anything more than simple metadata, like your ip address.

Just the captive portal check alone contains things like the User-Agent, which has plenty more than just your IP.

Re: My Mac contacted 63 different Apple owned domains in an hour, while not is use

#149

Earlier quoted context omitted.

Apple does too! Drives me crazy, although it’s not nearly as bad as Windows.

Uh…where?

You don't see them if you're already paying for all Apple services.

But otherwise, you get constantly nagged to get iCloud and also sometimes for their media and gaming subscriptions

Finally, what people for some reason ignore: Apple has been an advertisement company ever since their app store became the majority share of their revenue.

Re: My Mac contacted 63 different Apple owned domains in an hour, while not is use

#150

Earlier quoted context omitted.

No it isn't. The context is telemetry and spying, not built in advertising.

And none of the items in the original thread post were about telemetry. They were about functional requirements.

I guess you didn't read the article then, there are entries for telemetry. He even helpfully listed the official use case next to the domain name that was accessed.
Post reply on HN