Why not take a more privacy-centric approach? Antivirus companies have been working with “virus definitions” for ages. Ad blockers use the same model, but for locally stored blacklists. Why can Apple not regularly download a list of revoked certificates and maintain it locally?
Does Apple really log every app you run? A technical look
311–320 of 355 posts
Re: Does Apple really log every app you run? A technical look
#312Earlier quoted context omitted.
Apple hasn’t banned any developers who stand against them.
They have used security features of their OSs to ban developers who were simply in breach of contract with Apple, but not distributing malware or any other kind of content harmful to users. Sure, Apple was completely in the right to stop distributing Epic software after they breached their contract with Apple. But Epic didn't breach any contract with their users, so there was no reason to remove Epic's software from…
Epic lied about the content of their software. If Apple doesn’t remove software from suppliers who lie about the contents, people will continue to exploit this.
There was no overreach. This was the consequence of Epic intentionally lying about the content a software update.
It’s also worth pointing out that Epic expected this result, and caused it on purpose. Both Apple, and the court gave them the chance to rectify the situation which they refused.
That makes Epic responsible for the outcome. No one else.
Re: Does Apple really log every app you run? A technical look
#313Earlier quoted context omitted.
You'd be more aligned with HN values by refuting parent's point with examples than making ad hom attacks.
It is nevertheless the case that some users are VERY LOUD on particular topics, essentially repeating themselves on many leafs of the discussion. I find this very tiresome. It isn't an ad hom to point this out.
I find myself repeating certain points, usually because I am responding to repeated points.
Having said this, I do it because sometimes the person I am responding to says something new. It sounds like their point is a repeat, but they turn out to have a point of view that is different when you challenge them about it.
Re: Does Apple really log every app you run? A technical look
#314Earlier quoted context omitted.
Incorrect - zoom exposed a serious vulnerability, and Apple shut it down, using another mechanism but nonetheless the same effect. It’s relevant because you argue that there is no value to having the ability to do this. It is also a problem which occurred every time the app was launched. Something you have dismissed as a non problem. https://www.theverge.com/2019/7/10/20689644/apple-zoom-web-s...
> using another mechanism > It’s relevant because you argue that there is no value to having the ability to do this. No, I did not. We haven't talked about that other mechanism, so I've said nothing about it here either positively or negatively. > Something you have dismissed as a non problem. I said "Zoom had a serious uninstaller bug". So no, I did not dismiss it as a non problem. It just has nothing to do with Dev…
You said “But if you have a cached OCSP response for the cert of a malware author, then you've already launched their app, so it's probably too late.”
I.e. once you have launched the app, the damage is done.
This is not the case, and the Zoom situation is a clear counterexample. Even if a problematic app has been launched one or more times, it is still worth preventing subsequent launches if you can.
It doesn’t matter what mechanism is used to prevent the subsequent launch. This applies to any mechanism including OCSP. The Zoom example is a refutation of the particular point you made, a point which dismisses a real security concern.
It demonstrates that there is value in Apple having the ability to prevent harmful software from running, no matter how many times it has already been run.
Re: Does Apple really log every app you run? A technical look
#315Earlier quoted context omitted.
Vendors are already baking in DoH into their apps and systems, and that entirely bypass your DNS servers altogether. I went from blocking about 45% of my entire network's traffic at the DNS level two years ago, to only blocking 10% of the traffic today.
But how are those apps finding the DoH server's IP then? If they use public DoH servers you could just block those at the network level. Andv if they're running their own DoH service on a fixed IP, they could simply run the app itself over that IP and avoid the whole DNS lookup altogether.
I don't know, I haven't dug deep enough to find the answer for myself.
However, after blocking Google's DNS servers on my network and designating my own DNS servers via DHCP, my Chromecast ceased to function, and certain Android apps that serve ads had functionality that ceased to work correctly. That leads me to believe that apps and systems with DoH baked in are actively hostile to mitigations against their DoH implementations.
Re: Does Apple really log every app you run? A technical look
#316Earlier quoted context omitted.
> using another mechanism > It’s relevant because you argue that there is no value to having the ability to do this. No, I did not. We haven't talked about that other mechanism, so I've said nothing about it here either positively or negatively. > Something you have dismissed as a non problem. I said "Zoom had a serious uninstaller bug". So no, I did not dismiss it as a non problem. It just has nothing to do with Dev…
No warping going on. You said “But if you have a cached OCSP response for the cert of a malware author, then you've already launched their app, so it's probably too late. ” I.e. once you have launched the app, the damage is done. This is not the case, and the Zoom situation is a clear counterexample. Even if a problematic app has been launched one or more times, it is still worth preventing subsequent launches if you…
I was talking about MALWARE. As I said before, Zoom is not malware, so no, it's not a counterexample.
This is my last reply to you. You're clearly not interested in having a good faith conversation, you continue to misinterpret me and want to score "internet points" or something. I'm done.
Re: Does Apple really log every app you run? A technical look
#317Earlier quoted context omitted.
Apple has programmed macOS to make it appear to users as if un-Notarized apps either don't work or are malicious. This is bad for users that download apps to solve problems, or to get work done, because then they can't those apps without having an expert tell them what the magic ritual to run un-Notarized apps is. If they don't have an expert around to show them how to perform the magic ritual, then they just think t…
I don't think anyone trying to 'solve problems' or 'get work done' has encountered a notarization issue since the types of software they use is always notarized (since they still are only running software distributed by million dollar corporations).
Users frequently comment that the apps are now "broken" because they don't understand the changes Apple made to macOS to treat un-Notarized apps as if they're radioactive.
Re: Does Apple really log every app you run? A technical look
#318Earlier quoted context omitted.
Ah yes, the fear angle. "We need to restrict what you can do with your computer in order to keep you safe!" No thanks, I'll pass. I do imagine that some people would go for that bargain, but it strikes me as short-sighted.
You do realize that there are millions of satisfied Mac, iPhone, and iPad customers out there, right? The profits speak for themselves: clearly there is value both for freedom and for security. And it never was a binary question anyway. Besides, you can still run non-notarized binaries if you want to. The UI does make it difficult, but not impossible. If you want a totally open computer, that's fine (to the extent yo…
I think a good goal would be to scream it as loud as possible and make sure people are buying it based on this dimension as well.
Re: Does Apple really log every app you run? A technical look
#319Earlier quoted context omitted.
Apple has programmed macOS to make it appear to users as if un-Notarized apps either don't work or are malicious. This is bad for users that download apps to solve problems, or to get work done, because then they can't those apps without having an expert tell them what the magic ritual to run un-Notarized apps is. If they don't have an expert around to show them how to perform the magic ritual, then they just think t…
Most mainstream apps are notarized already.
Re: Does Apple really log every app you run? A technical look
#320Not sure whether the non-privacy related aspect about OCSP is less worrying. Officially Apple does this to protect innocent users from malware, but as we've seen it also allows them to remotely disable any developers' software. Not really something that I'd want on my machine.
I mean I guess I already know the answer, "marketing". "Look, macOS doesn't require antivirus!"
Personally I don't want Apple verifying or revoking anything. I bought the computer, it's mine. You don't get to tell me what I can run, period. Inform me, sure, give me links to go learn why you don't want me to run something, sure. Don't prevent me from choosing to do with my machine what I want.