Live data from Hacker News

Disable sharing of Spotlight searches with Apple

fix-macosx.com

101–110 of 137 posts

Re: Disable sharing of Spotlight searches with Apple

#101

Earlier quoted context omitted.

Could this be considered overthinking it? A domain, a python script, to effectively achieve tapping a couple toggles in sys prefs? And this is quite difficult for the average non terminal using person. > This site _criticizes_ Apple for certain privacy-invading features of Mac OS X and teaches users how to fix them. So, obviously, the site is not approved by Apple. Snark!

Howdy. Author here. By way of introduction, I'm also the author of PLCrashReporter ( https://www.plcrashreporter.org/ ), ported Java 6 to Mac OS X (a.k.a Soylatte), and -- this might lower some folk's estimation of me here -- started the MacPorts project almost 15 years ago at Apple, along with co-workers Jordan Hubbard and Kevin Van Vechten. That slightly snarky disclaimer you quoted actually has a serious backstory…

So at first I was wondering why it was python. Then I saw that you could import Foundation and directly edit settings. Needless to say now I'm intrigued and kinda want to write an ansible plugin for this as I already use ansible to set this junk up as it is.

Thanks for the awareness!

Re: Disable sharing of Spotlight searches with Apple

#102
post #93
post #81

Earlier quoted context omitted.

No power user ever uses spotlight to launch apps? Those are some awe-inspiring mental gymnastics you're doing to take Apple's side here.

A flippant response to a flippant response. But thanks for the hyperbole there. Really, this thread just looks like a bunch of paranoid conspiracy nuts, thinking Apple is out to steal your searches. I get it, privacy is important. I don't disagree. But you're* acting like they installed a keylogger on your computer (in point of fact, someone on IRC accused Apple of making "something that sends all of their local quer…

You see it as conspiracy nuts, but I just see a bunch of people complaining that it's not explained well enough. I see no comment on motivation at all.

By the way, there's a perfectly good English word that means "plural you minus you personally," which is "they."

Re: Disable sharing of Spotlight searches with Apple

#103
post #88

"Verification is required. Please click Billing Info to approve your billing information for use in the iTunes Store. If you cancel you will not be able to buy until you have approved your billing information." For a FREE upgrade? I'm sure Apple has data showing that people with a credit card on file are more likely to buy paid apps/songs/etc, but this is fucking annoying.

One of the payment types is 'None'.

http://i.imgur.com/oCqZf2b.png

Re: Disable sharing of Spotlight searches with Apple

#104

Earlier quoted context omitted.

Could this be considered overthinking it? A domain, a python script, to effectively achieve tapping a couple toggles in sys prefs? And this is quite difficult for the average non terminal using person. > This site _criticizes_ Apple for certain privacy-invading features of Mac OS X and teaches users how to fix them. So, obviously, the site is not approved by Apple. Snark!

Howdy. Author here. By way of introduction, I'm also the author of PLCrashReporter ( https://www.plcrashreporter.org/ ), ported Java 6 to Mac OS X (a.k.a Soylatte), and -- this might lower some folk's estimation of me here -- started the MacPorts project almost 15 years ago at Apple, along with co-workers Jordan Hubbard and Kevin Van Vechten. That slightly snarky disclaimer you quoted actually has a serious backstory…

> 4) Serve the whole lot over TLS.

But your server is configured to allow SSLv3[0]

[0] https://www.ssllabs.com/ssltest/analyze.html?d=fix%2dmacosx....

Re: Disable sharing of Spotlight searches with Apple

#105
post #93

Earlier quoted context omitted.

A flippant response to a flippant response. But thanks for the hyperbole there. Really, this thread just looks like a bunch of paranoid conspiracy nuts, thinking Apple is out to steal your searches. I get it, privacy is important. I don't disagree. But you're* acting like they installed a keylogger on your computer (in point of fact, someone on IRC accused Apple of making "something that sends all of their local quer…

You see it as conspiracy nuts, but I just see a bunch of people complaining that it's not explained well enough. I see no comment on motivation at all. By the way, there's a perfectly good English word that means "plural you minus you personally," which is "they."

My argument is that it is explained well enough, but most people complaining in here haven't even looked at the feature beyond seeing the original article talking about how to disable it with scripting. For example, as near as I can tell, eropple doesn't use Spotlight for anything except as a quick app launcher, which is a usage that doesn't involve Spotlight Suggestions (and AFAICT doesn't even try to send any queries to Apple). And yet he's been extremely argumentative, making wild assumptions about what's going on and then publicly complaining about it. Anyone who doesn't even look at the feature hardly has any grounds to complain about what it does and doesn't do, since they don't even know what it does or doesn't do. And their lack of knowledge is entirely their fault.

> By the way, there's a perfectly good English word that means "plural you minus you personally," which is "they."

If I was talking to you personally, one-on-one, I'd use "they". I used "you" because I was speaking to the larger audience of the people involved in this thread.

Re: Disable sharing of Spotlight searches with Apple

#106
post #30

Earlier quoted context omitted.

Could this be considered overthinking it? A domain, a python script, to effectively achieve tapping a couple toggles in sys prefs? And this is quite difficult for the average non terminal using person. > This site _criticizes_ Apple for certain privacy-invading features of Mac OS X and teaches users how to fix them. So, obviously, the site is not approved by Apple. Snark!

Not to mention that it encourages possibly not technically inclined users to execute random scripts from the internet, which should be a capital crime.

What like downloading a tarball over http? Watch your own binary/source traffic for a day, we are downloading random ass executable content all day long.

Re: Disable sharing of Spotlight searches with Apple

#107

Earlier quoted context omitted.

You see it as conspiracy nuts, but I just see a bunch of people complaining that it's not explained well enough. I see no comment on motivation at all. By the way, there's a perfectly good English word that means "plural you minus you personally," which is "they."

My argument is that it is explained well enough, but most people complaining in here haven't even looked at the feature beyond seeing the original article talking about how to disable it with scripting. For example, as near as I can tell, eropple doesn't use Spotlight for anything except as a quick app launcher, which is a usage that doesn't involve Spotlight Suggestions (and AFAICT doesn't even try to send any queri…

How does the new Spotlight know whether or not you're using it as a quick app launcher without communicating back to the mothership? I would have thought that it would send every query and then display the result or not depending on what comes back. I don't see how you could reasonably do it otherwise, unless you want to block internet searches for any term that matches an app name.

Re: Disable sharing of Spotlight searches with Apple

#109
post #100

I have zero issue with this, and it's clearly labelled and explained. Of all the breaches in my privacy, this isn't one I'm worried about. Google gets 100% of my searches and email messages, so it's a question of who you trust.

To each his own, but I just want to point out that your examples of web searches and email require that SOME third party be involved because they are, by definition, attempts to reach a computer somewhere else on the internet. In contrast, searching the local files on one's own computer or launching applications on one's own computer are private, local events that need not be shared with any third party. Inherently p…

Everything you put on your computer should be assumed to be public the moment you connect to the internet. With air gap jump technology starting to become proven, you should assume that all digital content is public. To think otherwise is hubris and stupidity all wrapped up with a tiny little bow. Every company and government agency has been compromised to one degree or another, and targeted attacks are 100% effective given even slight competence on the part of the hacker. I've been around since before the modem, I've seen everyone hacked.

Regardless, it doesn't matter. It's simply ignorant to bitch about this, when the NSA literally intercepts all of this and exploits or introduces exploits into the software you use. This is fact. Apple at it's worst will present you an advertisement, big fucking whoop. Seriously, what is the risk? Annoyance? The NSA can wrap you around a pole and make it appear you were snorting 12kilos of coke a day. I am quite literally baffled by the sentiment on HN when I see people up in arms over convenience like this trumped up as if it were in violation of your rights. They added a 'learn more' link and explain what is going on. Yet the same people simply ignore the actual threat, repeatedly. Cowards.

Keep fighting them windmills. Because the real enemy fights back.

Re: Disable sharing of Spotlight searches with Apple

#110

Earlier quoted context omitted.

Howdy. Author here. By way of introduction, I'm also the author of PLCrashReporter ( https://www.plcrashreporter.org/ ), ported Java 6 to Mac OS X (a.k.a Soylatte), and -- this might lower some folk's estimation of me here -- started the MacPorts project almost 15 years ago at Apple, along with co-workers Jordan Hubbard and Kevin Van Vechten. That slightly snarky disclaimer you quoted actually has a serious backstory…

> 4) Serve the whole lot over TLS. But your server is configured to allow SSLv3[0] [0] https://www.ssllabs.com/ssltest/analyze.html?d=fix%2dmacosx....

If you're referring to the POODLE SSLv3 bug, it doesn't break authentication/key exchange or MAC, but instead, confidentiality of the symmetric encryption.

In other words (assuming an attacker can modify a sufficient amount of SSL traffic in transit), they could decrypt the python source code, but they can't insert new data without triggering a MAC validation failure on the client.

https://www.openssl.org/~bodo/ssl-poodle.pdf

Post reply on HN