Live data from Hacker News

My Mac contacted 63 different Apple owned domains in an hour, while not is use

appaddict.app

171–180 of 218 posts

Re: My Mac contacted 63 different Apple owned domains in an hour, while not is use

#171

Earlier quoted context omitted.

No Apple can unlock your phone with the master key they used to generate your phone hardware enclave key. This is how the FBI has pressured them in the past to unlock devices.

Apple claims what you’re describing is impossible https://support.apple.com/en-ge/guide/security/sec59b0b31ff/...

Which specific part of the enclave doc refutes it?

This Quora claims otherwise: https://www.quora.com/How-can-we-unlock-our-iPhones-if-we-fo...

Re: My Mac contacted 63 different Apple owned domains in an hour, while not is use

#172

Earlier quoted context omitted.

Still need your password to use the key

No Apple can unlock your phone with the master key they used to generate your phone hardware enclave key. This is how the FBI has pressured them in the past to unlock devices.

The exact section is "Root Cryptographic Keys," here is the key passage:

``` A randomly generated UID is fused into the SoC at manufacturing time. Starting with A9 SoCs, the UID is generated by the Secure Enclave TRNG during manufacturing and written to the fuses using a software process that runs entirely in the Secure Enclave. This process protects the UID from being visible outside the device during manufacturing and therefore isn’t available for access or storage by Apple or any of its suppliers. ```

Re: My Mac contacted 63 different Apple owned domains in an hour, while not is use

#173
One of the things that really put me off about Apple's computers, namely their pre-installed OS, was how "chatty" they have become when attached to a local network, let alone the internet.

As such, I stopped buying Apple. I have not owned a Mac since the G4 days. I never attached it to the internet. I would use TCP/IP and a crossover cable to move files.

I always see a high vollume of traffic from other peoples' Apple computers on the wire that is not intitiated by the computer owner. To my sensibilities, this is cringeworthy. Because there is no way to turn if off. The computer owner has no control over it.

Apple fans can argue this is useful and convenient. That may be true. But that does not explain why it is mandatory, on by default and impossible to disable. I am not against useful options and convenience. I am in favor of control.

When I compile and install a NetBSD image the amount of mandatory network traffic is zero. It is up to me to decide what to enable. That's how I like it.

Re: My Mac contacted 63 different Apple owned domains in an hour, while not is use

#174

Earlier quoted context omitted.

No Apple can unlock your phone with the master key they used to generate your phone hardware enclave key. This is how the FBI has pressured them in the past to unlock devices.

The exact section is "Root Cryptographic Keys," here is the key passage: ``` A randomly generated UID is fused into the SoC at manufacturing time. Starting with A9 SoCs, the UID is generated by the Secure Enclave TRNG during manufacturing and written to the fuses using a software process that runs entirely in the Secure Enclave. This process protects the UID from being visible outside the device during manufacturing…

[deleted]

Re: My Mac contacted 63 different Apple owned domains in an hour, while not is use

#175
post #141

Earlier quoted context omitted.

that works in a lot of cases, but unfortunately it seems sometimes you get these popups about nsurlsessiond (for example) where you know where the connection goes, but no idea where it comes from (especially if it's trying to connect to to some generic AWS hostname) And as much as you can use little snitch for programs you install, these days it seems an endless whack-a-mole to block Apple's stuff as there's so many…

> unfortunately it seems sometimes you get these popups about nsurlsessiond (for example) where you know where the connection goes, but no idea where it comes from (especially if it's trying to connect to to some generic AWS hostname) Little Snitch might be able to tell which process triggered that, if you press the info button in the alert. I'll have to check next time it happens.

Nope. Triggered by `launchd` last time i checked…

Re: My Mac contacted 63 different Apple owned domains in an hour, while not is use

#176

Earlier quoted context omitted.

I don't have a story but Little Snitch is the kind of tool most corporate users don't need, but that many malicious actors love to use. Sort of like running nmap on your computer, yeah there are legitimate reasons to do so, but you will get a call from IT if you try it.

interesting. don't malicious actors use much more advanced tools than little snitch?

Malicious actors use every tool you can imagine, and many you can't.

Re: My Mac contacted 63 different Apple owned domains in an hour, while not is use

#177
post #62

Earlier quoted context omitted.

When Microsoft has telemetry: * Windows is a spyware machine - how can anyone use it? Year of Linux baby! When Apple has telemetry: * It's working as expected. So... to be fair, is there a thorough comparison of the two? How are they the same, and how are they different?

But the things mentioned in the post above yours have nothing to do with telemetry. They're more like core functions to make the system work at all.

> Which then becomes a question of how much time/money to they invest in features for 1% of users? Now how much time do they invest in those same features when the 99% will stumble in there, turn a bunch of stuff off, then call support and ask why their weather widget isn't updating?

That sounds like telemetry?

Re: My Mac contacted 63 different Apple owned domains in an hour, while not is use

#178

Earlier quoted context omitted.

The whole point is that a 3rd party (Apple) doesn’t have the key. It’s not real E2E and it’s still susceptible to government overreach.

Not every Apple service is E2E encrypted, but some of them (like iMessage) are, and it's 100% real E2E.

If you do a forgot password and move to a new device do you lose all your chats?

Re: My Mac contacted 63 different Apple owned domains in an hour, while not is use

#179
post #62

Earlier quoted context omitted.

But the things mentioned in the post above yours have nothing to do with telemetry. They're more like core functions to make the system work at all.

> Which then becomes a question of how much time/money to they invest in features for 1% of users? Now how much time do they invest in those same features when the 99% will stumble in there, turn a bunch of stuff off, then call support and ask why their weather widget isn't updating? That sounds like telemetry?

The features I was referring to would be a control panel to list all the various remote calls to let uses micromanage what calls they wanted and which ones they didn’t.

Inside of those settings could be options to enable/disable telemetry, sure. But also push notifications, weather updates, virus definition updates, etc.

Re: My Mac contacted 63 different Apple owned domains in an hour, while not is use

#180

Earlier quoted context omitted.

Windows telemetry is way more insane Small sample of telemetry and spying domains (out of date): https://raw.githubusercontent.com/crazy-max/WindowsSpyBlocke... https://raw.githubusercontent.com/crazy-max/WindowsSpyBlocke... https://raw.githubusercontent.com/crazy-max/WindowsSpyBlocke... https://raw.githubusercontent.com/Strappazzon/teleme7ry/mast...

How does one verify all those domains are not essential to the OS?

Microsoft explains what all (most?) of the domains are for

https://learn.microsoft.com/en-us/windows/privacy/windows-11...

Post reply on HN