Live data from Hacker News

macOS has checked app signatures online for over 2 years

eclecticlight.co

111–120 of 458 posts

Re: macOS has checked app signatures online for over 2 years

#111

Earlier quoted context omitted.

They are SOMETIMES identifiable information. They are not RELIABLE for identification. If you are going to be collecting information, you are not going to choose unreliable information when you have the option to collect reliable information. That would not make sense.

I can right now open my vpn, change my ip address, go to my apple account and it will report that my Mac is "Online", meaning that apple knows that my particular machine is on with a given IP address. It would be completely useless (redundant at the very least) to also include the uid in the signature file.

There might ten other, a hundred other people with the same public IP visible to Apple, if you ISP is running you through a NAT.

That fact that you have connected from an IP recently in no way guarantees that the next connection from that IP will be coming from you. That is exactly why you need to send an identifier for any data being collected.

Re: macOS has checked app signatures online for over 2 years

#112

Earlier quoted context omitted.

Accurately. The key word in there was "accurately".

If IP addresses couldn't in some cases accurately track users, then it wouldn't be a priority to build a network that obscured them.

If they can only do it "in some cases", then they can't do it accurately, is the entire point. It can do it SOMETIMES.

Apple has more accurate information. They are not sending it. Why?

Re: macOS has checked app signatures online for over 2 years

#113
post #2

A common refrain in arguments that we don't need laws to protect privacy is that the market will take care of it. The market can't act against what it can't see. Privacy loss is often irreversible. A common refrain in arguments that we don't need to reject closed source software to protect privacy is that being closed source doesn't hide the behaviour, and people will still notice backdoors and privacy leaks. Sometim…

The market only acts fairly when the product is a commodity. The time for the market to react for a product with the complexity of a mac is decades. As the ecosystem grows, the cost of switching increases. Therefore market starts acting more and more inefficiently. This is why countries have state intervention in such cases. And anti trust exists. If the option was a mac with privacy vs a mac without privacy but $10…

>maybe blockchain will solve the problem of trust among humans

Absolutely not.

https://www.schneier.com/blog/archives/2019/02/blockchain_an...

Re: macOS has checked app signatures online for over 2 years

#114

> "Those who consider that Apple’s current online certificate checks are unnecessary, invasive or controlling should familiarise themselves with how they have come about, and their importance to macOS security. They should also explain how, having enjoyed their benefits for a couple of years, they’ve suddenly decided they were such a bad idea after all, and what should replace them." A simple opt-out toggle, for priv…

But that would defeat the purpose. Apple can be thought of as the equivalent of the NSA: they "care" about your privacy in the sense that they don't want anybody but themselves to have access to it. Unfortunately we don't have an Apple competitor that cares enough about your privacy to not want anybody, including themselves , to have access to it.

And yet, this claim about Apple’s intent isn’t made with a shred of evidence.

Re: macOS has checked app signatures online for over 2 years

#115

> "Those who consider that Apple’s current online certificate checks are unnecessary, invasive or controlling should familiarise themselves with how they have come about, and their importance to macOS security. They should also explain how, having enjoyed their benefits for a couple of years, they’ve suddenly decided they were such a bad idea after all, and what should replace them." A simple opt-out toggle, for priv…

This is turning out to be a bit of a similar case as the iPhone battery degradation performance throttling issue. Instead of clearly messaging what they were doing to your phone, they did things behind the scenes because they knew better, and decided not to give the user the choice to run the phone at full performance.

The throttled performance is full performance. Without throttling the phone would simply crash.

Re: macOS has checked app signatures online for over 2 years

#117
> What has been puzzling me ever since is that these OCSP checks have been well-known for a couple of years, and only now have attracted attention.

It's not much of a puzzle. Everyone's Mac essentially froze simultaneously, and that's what drew all the initial attention. Then people were digging into why, and the cause of it got a lot of play. Privacy advocates took the opportunity to advocate privacy and had a large and annoyed audience.

Re: macOS has checked app signatures online for over 2 years

#118

How does Windows check executables? I hope they don't do the same. Does it come with a master list of public keys from manufacturers to check the signature against? How does that work for new vendors?

...Do people not know AV's randomly upload files to the cloud to be analyzed?

Re: macOS has checked app signatures online for over 2 years

#119

"Privacy is not a feature".

Directly contradicting current Apple Marketing. I lothe Apple(and other unethical companies) for lying in their ads. Any benefits of macOS are instantly gone because you cannot Trust Apple to tell the truth. It's as unreliable as Google keeping a service around.

You don’t have any evidence to support the claim that they are lying.

Re: macOS has checked app signatures online for over 2 years

#120

> "Those who consider that Apple’s current online certificate checks are unnecessary, invasive or controlling should familiarise themselves with how they have come about, and their importance to macOS security. They should also explain how, having enjoyed their benefits for a couple of years, they’ve suddenly decided they were such a bad idea after all, and what should replace them." A simple opt-out toggle, for priv…

This is turning out to be a bit of a similar case as the iPhone battery degradation performance throttling issue. Instead of clearly messaging what they were doing to your phone, they did things behind the scenes because they knew better, and decided not to give the user the choice to run the phone at full performance.

You clearly need to familiarize yourself with the actual facts of this case. Also, I'm pretty sure that for 99% of users, "full performance" is not characterized by "randomly crashing due to lack of intelligent power management".
Post reply on HN