Live data from Hacker News

Does Apple really log every app you run? A technical look

blog.jacopo.io

301–310 of 355 posts

Re: Does Apple really log every app you run? A technical look

#301

Earlier quoted context omitted.

devs aren't already forced to buy the hardware for the platform they're targeting?

For apple they are 100% forced to. Not sure what you’re getting at but have you ever seen an iphone simulator on windows or linux?

What platforms don’t force devs to buy developer kits or use their hardware? PlayStation and Xbox used to force devs to buy exotic hardware. Consoles are similar to phones and they lack simulators or emulators for the newer stuff.

Re: Does Apple really log every app you run? A technical look

#302
post #288
post #256

When it comes to these article, you should really apply the following "smell" test: Replace "Apple" with "Google", "Facebook", "Verizon". Re-read the article. If it sounds horrifying, then it's also horrifying if Apple does it. There's no such thing as "trust" into a single corporation - especially the one which just argued that you not paying 30% to them is "theft". Applying this test helps weed out the marketing bi…

Better replace "Apple" with "TikTok", "Zoom" otherwise people might think about "Google", "Facebook" that (paraphrasing) «they may be sons of bitches, but they are our sons of bitches» (regardless the reality).

Good point there.

Re: Does Apple really log every app you run? A technical look

#303
post #285

While other posts on this topic are too alarmist, this one is way too Apple apologetic for my taste. * There is no information on how often the validation happens. All this investigation concludes is that it doesn't happen when closing and immediately re-opening an app. Is it every week? Every reboot? Every hour? If it's less, that's essentially the same as doing it on every launch. * There is no justification for se…

> this one is way too Apple apologetic for my taste. I'm not surprised. Apple fanatics routinely deny evidence to support their sorta-religion.

> Apple fanatics routinely deny evidence to support their sorta-religion.

As do anti-Apple fanatics. That’s what being a “fanatic” means. You can say the same about gun fanatics, or meat fanatics, or vegetarian fanatics, or Android fanatics. It’s staggering how often people who are anti something fail to perceive the irony in behaving exactly in the manner they are decrying. Someone having a contrary opinion doesn’t make them a fanatic.

Re: Does Apple really log every app you run? A technical look

#304
post #184

Earlier quoted context omitted.

Ah yes, the fear angle. "We need to restrict what you can do with your computer in order to keep you safe!" No thanks, I'll pass. I do imagine that some people would go for that bargain, but it strikes me as short-sighted.

You do realize that there are millions of satisfied Mac, iPhone, and iPad customers out there, right? The profits speak for themselves: clearly there is value both for freedom and for security. And it never was a binary question anyway. Besides, you can still run non-notarized binaries if you want to. The UI does make it difficult, but not impossible. If you want a totally open computer, that's fine (to the extent yo…

That is fine. And now, because of this, many of us are now considering not having Apple in our tech future. And that is fine too.

Re: Does Apple really log every app you run? A technical look

#305

> You should be aware that macOS might transmit some opaque information about the developer certificate of the apps you run. This information is sent out in clear text on your network. Wow, that is bad from a privacy perspective! Since certificate revocation is rare, it makes more sense to simply periodically update a list of revoked certificates instead of repeatedly checking each certificate. That would solve the p…

I was initially shocked by this as well so I did some more reading on OCSP and it seems this is being addressed through OCSP stapling.

According to Wikipedia "[OCSP stapling] allows the presenter of a certificate to bear the resource cost involved in providing Online Certificate Status Protocol (OCSP) responses by appending ("stapling") a time-stamped OCSP response signed by the CA to the initial TLS handshake, eliminating the need for clients to contact the CA, with the aim of improving both security and performance."

I'm not aware how widely deployed OCSP stapling is in reality. I looked at my Firefox settings which seemed to be the default for OCSP and it looked like this:

  security.OCSP.enabled                     1
  security.OCSP.require                     false
  security.OCSP.timeoutMilliseconds.hard    10000
  security.OCSP.timeoutMilliseconds.soft    2000
  security.ssl.enable_ocsp_must_staple      true
  security.ssl.enable_ocsp_stapling         true
So I assume OCSP stapling is enabled but direct OCSP is disabled in Firefox by default but a positive OCSP response is not required in general. I tried to check what was really happening with Wireshark but regardless of the configuration and sites I visited, I couldn't get Firefox to emit an OCSP query.

I also don't know what other TLS implementations (like OpenSSL) do and how users of such libraries usually configure them.

Addendum: Oh and of course, OCSP stapling is useless when you weren't about to open a TLS connection (like in this case when checking software signing certificates). I'm also curious if and how this works for other applications of X.509 certificates such as mutual TLS authentication.

Re: Does Apple really log every app you run? A technical look

#306
Worked a major virus company. This was the same Basic technique. W e would download a list of all md5 hashes. All executables would have to match against it.

Periodically there would be an issue downloading the updates. Would result in similar problems.

Managing size of updates was a big issue. Just checking against an online server is certainly a more up to date approach

Re: Does Apple really log every app you run? A technical look

#307

Earlier quoted context omitted.

It seems like several people are assuming that Apple is storing the data now and that it is personally identifiable. My assumption was that, of course they would not do that. But of course I could be wrong.

I think the bigger point here is, if Apple started to store the data and make it personally identifiable, you would have no way of knowing that they had. They wouldn't need to install anything new on your computer to start tracking you in more detail or building a user profile on you, they could just start doing it invisibly behind the scenes on a server someplace. That's a big deal, because even though you're trusti…

I just don’t think that’s a very big deal. Did anyone notice when Apple shipped this update? Maybe so, but it certainly wasn’t a huge ongoing issue in the community. It seems pretty clear that they could get away with a minor evil update if they decided to turn evil.

Re: Does Apple really log every app you run? A technical look

#308

Earlier quoted context omitted.

Most mainstream apps are notarized already.

I think you're answering the wrong question?

Another commenter added more color, but what I was trying to say is that the scenario the parent poster described isn't a likely one for most Mac users.

Re: Does Apple really log every app you run? A technical look

#309

While other posts on this topic are too alarmist, this one is way too Apple apologetic for my taste. * There is no information on how often the validation happens. All this investigation concludes is that it doesn't happen when closing and immediately re-opening an app. Is it every week? Every reboot? Every hour? If it's less, that's essentially the same as doing it on every launch. * There is no justification for se…

> Such a "lazy" design is hard to imagine coming out of Apple otherwise.

That's my biggest issue personally. There's a bit of information leak, but most wouldn't care and would just do the standard and be done with it. Firefox still uses OCSP in some case...

My issue is that a company like Apple, which currently market itself as a company that care about privacy of their user, would have let this comes out of that same process that's supposed to care... and still hasn't said that was a mistake out of their process and that they are correcting it.

They could easily use k-anonymity like HaveIBeenPwned, or even as push, which would means no cache, which is even better for their argument of security.

There's nothing alarmist here, it's all alright, it would just means that this is the same false advertising that so many companies do, but still, is important to be aware of.

Re: Does Apple really log every app you run? A technical look

#310

Earlier quoted context omitted.

Privately owned companies are not accountable to their users, they are accountable to their owners, just like publically traded ones. It's just that they have fewer owners, and you sometimes get owners with really nice ideas. Other times, you get even more tyrannical owners. Instead, what would be really nice is imagining how those companies would fare as worker-owned companies. Especially with these big internet beh…

Or not, as Soviet Union with its workers-owned factories can tell. Ever rode a Soviet car that wasn’t copypasted from Fiat?

Wikipedia says:

> The Niva was described by its designers as a "Renault 5 put on a Land Rover chassis"

So I guess one example of a car that was not copypasted from fiat?

Post reply on HN