Live data from Hacker News

Apple: Developer ID Certificate Revocation (OCSP)

lapcatsoftware.com

31–35 of 35 posts

Re: Apple: Developer ID Certificate Revocation (OCSP)

#31

Earlier quoted context omitted.

I want this to be big news. Apple lately pretends that they care about user privacy. They might fix it.

Sorry, what, exactly, should be fixed? If you're referring to OCSP requests / responses being unencrypted, I would be interested in hearing what your solution to this problem is. Also, I would recommend that you do not perform any packet captures (as mentioned earlier) to observe your OCSP traffic. You're gonna have a heart attack when you realize that this isn't just an Apple thing and that nobody encrypts OCSP. Onc…

They could switch to a CRL.

Re: Apple: Developer ID Certificate Revocation (OCSP)

#32

> The check consists of an HTTP GET request (port 80, unencrypted!) to ocsp.apple.com with a path that is both Base64 encoded and URL encoded. Interesting. This means OSX leaks which apps you run unencrypted on the network.

windows and web browsers do this as well via OSCP.

Linux distros also do this via package manager traffic and update checks. Apt/rpm traffic is unencrypted, relying on a separate payload signature scheme for authenticity (same as OSCP).

Re: Apple: Developer ID Certificate Revocation (OCSP)

#33

Earlier quoted context omitted.

Sorry, what, exactly, should be fixed? If you're referring to OCSP requests / responses being unencrypted, I would be interested in hearing what your solution to this problem is. Also, I would recommend that you do not perform any packet captures (as mentioned earlier) to observe your OCSP traffic. You're gonna have a heart attack when you realize that this isn't just an Apple thing and that nobody encrypts OCSP. Onc…

They could switch to a CRL.

OCSP exists because CRLs don’t scale as you build an ever growing list of revoked certificates

Re: Apple: Developer ID Certificate Revocation (OCSP)

#34

Earlier quoted context omitted.

They could switch to a CRL.

OCSP exists because CRLs don’t scale as you build an ever growing list of revoked certificates

With certificate age limits, the list is not ever-growing.

Re: Apple: Developer ID Certificate Revocation (OCSP)

#35

This entire thing is likely related to Apple’s engineered obsolescence cycle. They have already been busted intentionally causing issues on their platforms prior to the release of new products in order to drive sales. It’s a grey area legally and difficult to prove, but it’s essentially a form of racketeering.

It seems a lot of your comments garner downvotes on this site. Your comments are sound, or at least very reasonable, and thus my opinion of this site and the community has faltered significantly.
Post reply on HN