Live data from Hacker News

Does Apple really log every app you run? A technical look

blog.jacopo.io

161–170 of 355 posts

Re: Does Apple really log every app you run? A technical look

#161

Has anyone used a pi-hole to block apple privileged servers, like the OCSP one, while running Big Sur? I'm thinking of setting one up---not necessarily to block OCSP, because the points in this post about actually wanting to know when a certificate has been revoked are sensible---but to at least have the option in case of another disaster... Relatedly, does anyone know if Big Sur allows one to use a custom DNS server…

Vendors are already baking in DoH into their apps and systems, and that entirely bypass your DNS servers altogether.

I went from blocking about 45% of my entire network's traffic at the DNS level two years ago, to only blocking 10% of the traffic today.

Re: Does Apple really log every app you run? A technical look

#162
post #136

Earlier quoted context omitted.

What does "participation" in PRISM mean? > Apple: "We have never heard of PRISM"[115] "We do not provide any government agency with direct access to our servers, and any government agency requesting customer data must get a court order."[115] * https://en.wikipedia.org/wiki/PRISM_%28surveillance_program%... Certainly American companies are subjects to warrants and NSLs, but Google (to give one example) had its dark f…

> had its dark fibre connections between data centres tapped by the NSA. Is that the "participation" that was referred to by the Snowden documents? No, that's a separate thing. They do both. See the "you should use both" slide. https://github.com/iamcryptoki/snowden-archive/blob/master/d... As to the apple claims that they didn't participate in PRISM, I think they were just lying. Clapper lied to congress as well, so…

Apple was not lying because “PRISM” was an internal source identifier at the NSA for the process of acquiring data through the FISA warrant process. Apple never heard the word PRISM; they got FISA warrants and replied to them as required by law.

This is clearly indicated on the PRISM Wikipedia page that was linked above.

> PRISM is a code name for a program under which the United States National Security Agency (NSA) collects internet communications from various U.S. internet companies.[1][2][3] The program is also known by the SIGAD US-984XN.[4][5] PRISM collects stored internet communications based on demands made to internet companies such as Google LLC under Section 702 of the FISA Amendments Act of 2008 to turn over any data that match court-approved search terms.

Re: Does Apple really log every app you run? A technical look

#164

Earlier quoted context omitted.

We’ve been hearing that for years, yet it hasn’t happened. Apple seems to recognize the value of the Mac as an general computing platform.

Apple has programmed macOS to make it appear to users as if un-Notarized apps either don't work or are malicious. This is bad for users that download apps to solve problems, or to get work done, because then they can't those apps without having an expert tell them what the magic ritual to run un-Notarized apps is. If they don't have an expert around to show them how to perform the magic ritual, then they just think t…

Most mainstream apps are notarized already.

Re: Does Apple really log every app you run? A technical look

#165
post #76

Earlier quoted context omitted.

Their iMessage situation?

They backup the private key to iCloud unless you manually disable backups. So even though iMessage is advertised as E2E encrypted, for the vast majority of users, Apple can read each and every message. (And even if you disable backups, Apple can still read most if not all of your messages, because the persons on the other side of the conversations have not disabled backups)

This stance undermines the point of E2E. The messaging system is still E2E even if people backup their plaintext messages or their key on non-E2E storage.

Having you messages deleted because you forgot your iCloud password is good security but a terrible default.

Re: Does Apple really log every app you run? A technical look

#166
post #127

Apple has always been a gated community, but now there’s a guard at the gate checking everything that goes in and out. This is something most users probably don’t want. It has me personally considering what a future without Apple would look like.

I’m more and more convinced that I’ve got to learn and find a way to make Linux work for me.

Check out these posts I posted about transitioning to Linux from macOS and feeling at home[1].

I made the switch and I'm not looking back.

[1] https://news.ycombinator.com/item?id=23607374

Re: Does Apple really log every app you run? A technical look

#167

While other posts on this topic are too alarmist, this one is way too Apple apologetic for my taste. * There is no information on how often the validation happens. All this investigation concludes is that it doesn't happen when closing and immediately re-opening an app. Is it every week? Every reboot? Every hour? If it's less, that's essentially the same as doing it on every launch. * There is no justification for se…

Most "alarmist" articles have two points you cannot really ignore, not if you don't want to end up living in interesting times one day. 1) Even plain access logs — basically what a HTTP request, or a TCP connection can tell you — is a lot . Gather those for a couple of days, and you have a good map of the user. More so if you have an ID of machine and the actual executable hash. 2) "But we are the good guys" is a non…

>"But we are the good guys"

Also, this is what every bad guy believed him or herself to be throughout the history of humanity.

Re: Does Apple really log every app you run? A technical look

#168

While other posts on this topic are too alarmist, this one is way too Apple apologetic for my taste. * There is no information on how often the validation happens. All this investigation concludes is that it doesn't happen when closing and immediately re-opening an app. Is it every week? Every reboot? Every hour? If it's less, that's essentially the same as doing it on every launch. * There is no justification for se…

Most "alarmist" articles have two points you cannot really ignore, not if you don't want to end up living in interesting times one day. 1) Even plain access logs — basically what a HTTP request, or a TCP connection can tell you — is a lot . Gather those for a couple of days, and you have a good map of the user. More so if you have an ID of machine and the actual executable hash. 2) "But we are the good guys" is a non…

> "But we are the good guys" is a non-defense. Good guys can turn bad, they can be coerced by the bad guys,

That’s true, but not very useful, since if Apple turns bad or is coerced by the bad guys, they could just issue an OS update that begins doing new bad things anyway.

Re: Does Apple really log every app you run? A technical look

#169

Earlier quoted context omitted.

Most "alarmist" articles have two points you cannot really ignore, not if you don't want to end up living in interesting times one day. 1) Even plain access logs — basically what a HTTP request, or a TCP connection can tell you — is a lot . Gather those for a couple of days, and you have a good map of the user. More so if you have an ID of machine and the actual executable hash. 2) "But we are the good guys" is a non…

> "But we are the good guys" is a non-defense. Good guys can turn bad, they can be coerced by the bad guys, That’s true, but not very useful, since if Apple turns bad or is coerced by the bad guys, they could just issue an OS update that begins doing new bad things anyway.

But they can’t retroactively gain data. So it’s not the same. Besides, security is something you apply in layers.

Re: Does Apple really log every app you run? A technical look

#170
post #136

Earlier quoted context omitted.

> had its dark fibre connections between data centres tapped by the NSA. Is that the "participation" that was referred to by the Snowden documents? No, that's a separate thing. They do both. See the "you should use both" slide. https://github.com/iamcryptoki/snowden-archive/blob/master/d... As to the apple claims that they didn't participate in PRISM, I think they were just lying. Clapper lied to congress as well, so…

Apple was not lying because “PRISM” was an internal source identifier at the NSA for the process of acquiring data through the FISA warrant process. Apple never heard the word PRISM; they got FISA warrants and replied to them as required by law. This is clearly indicated on the PRISM Wikipedia page that was linked above. > PRISM is a code name for a program under which the United States National Security Agency (NSA)…

> Apple was not lying because “PRISM” was an internal source identifier at the NSA for the process of acquiring data through the FISA warrant process. Apple never heard the word PRISM

As I've said, that's a detail and splitting hairs. If a sentence has multiple interpretations and one of them is true, but you phrase it in a way that most people interpret the sentence in the wrong way, you are intentionally deceiving people. They should have said "we have never heard the name PRISM" or something like this.

Post reply on HN