Live data from Hacker News

Does Apple really log every app you run? A technical look

blog.jacopo.io

321–330 of 355 posts

Re: Does Apple really log every app you run? A technical look

#321
post #316
post #314

Earlier quoted context omitted.

No warping going on. You said “But if you have a cached OCSP response for the cert of a malware author, then you've already launched their app, so it's probably too late. ” I.e. once you have launched the app, the damage is done. This is not the case, and the Zoom situation is a clear counterexample. Even if a problematic app has been launched one or more times, it is still worth preventing subsequent launches if you…

> This is not the case, and the Zoom situation is a clear counterexample. I was talking about MALWARE. As I said before, Zoom is not malware, so no, it's not a counterexample. This is my last reply to you. You're clearly not interested in having a good faith conversation, you continue to misinterpret me and want to score "internet points" or something. I'm done.

Accusations of bad faith are unhelpful, especially in a technical discussion like this.

Zoom is not malware in that as far as we know it isn’t Zoom’s intent to cause harm.

However in this instance it exhibited a behavior which many forms of malware exhibit - opening an insecure or exploitable port. It was shut down because it was behaving the way some malware behaves.

It’s a perfectly reasonable example of using these types of mechanism to mitigate a real security issue.

You can’t seriously be claiming that malware never opens ports, or that malware always does all of its harm on the first run.

Therefore the use of the distinction ‘malware’ is arbitrary and irrelevant.

The mechanism is useful to protect against vulnerabilities, regardless of whether the vulnerabilities were intentional or not.

Re: Does Apple really log every app you run? A technical look

#322
post #137

Earlier quoted context omitted.

The standard does not specify plaintext. It says the client may use encryption. Even doing unauthenticated TLS is better than what they do now, because the current situation allows for full passive monitoring.

The problem with 'may' is that a network intermediary might block TLS connections to ocsp.apple.com knowing it would fall back to plaintext. Apple could encrypt the payload though, using the Apple public key, which would solve the snooping by intermediaries problem.

A network intermediary blocking or altering the TLS is an active attack. Plain HTTP is also vulnerable to that, so unauthenticated TLS is no worse than the current situation.

TLS encrypts the payload just fine if you want that. That’s what TLS is for.

PS: You don’t encrypt something to someone else using your own public key.

Re: Does Apple really log every app you run? A technical look

#324
post #238
post #191

Earlier quoted context omitted.

You'd be more aligned with HN values by refuting parent's point with examples than making ad hom attacks.

The accuser should also be held to the same standard. Without evidence those are just empty words.

Just look at our comment history, it's pretty easy lol

Re: Does Apple really log every app you run? A technical look

#325
post #312

Earlier quoted context omitted.

They have used security features of their OSs to ban developers who were simply in breach of contract with Apple, but not distributing malware or any other kind of content harmful to users. Sure, Apple was completely in the right to stop distributing Epic software after they breached their contract with Apple. But Epic didn't breach any contract with their users, so there was no reason to remove Epic's software from…

“Simply in breach of contract with Apple” Epic lied about the content of their software. If Apple doesn’t remove software from suppliers who lie about the contents, people will continue to exploit this. There was no overreach. This was the consequence of Epic intentionally lying about the content a software update. It’s also worth pointing out that Epic expected this result, and caused it on purpose. Both Apple, and…

Didn't Epic actually create an entire presentation video advertising the contents of their update?

Again, I fully agree that Epic was knowingly in breach of their contract with Apple, and wanted to use the public as leverage. But that doesn't, in any way, make their update malicious for the end user.

Re: Does Apple really log every app you run? A technical look

#326

Earlier quoted context omitted.

The Soviet Union didn't have even 1 worker owned factory, unless you're talking about the time before Lenin ever came to power. The factories were owned by the state, which in turn was owned by a dictator and his political apparatus - workers had less freedom to control the factory than Amazon warehouse workers.

But they told people they had been worker-owned, and many actually believed it!

Yes, they were a despicable regime, and unfortunately their name still mars the idea of socialism. They also claimed they were democratic, and surely many believed that as well, but we haven't let that ruin democracy, so we shouldn't let their laughable claims to socialism ruin socialism.

Re: Does Apple really log every app you run? A technical look

#327
post #223

Earlier quoted context omitted.

I think that's one of the big problems with public companies, especially those that have "regular people" as their main money maker (the "consumers") - invariably, the company's needs (duty) to make money for their real customers (the shareholders) will take precedence over what would be "the best thing" for consumers. I wish we could do away with the whole "public company" thing - just imagine how much better Facebo…

private companies are still accountable to their shareholders. But I do think that the very public number of share price encourages slightly different behavior than a private, illiquid, and probably out of date number

Yeah not sure what the poster is trying to say here. Both distinctions almost invevitably result in doing anything that is legal to maximize profits (and oftentimes illegal or gray at best). However I haven't seen anyone propose a decent alternative to corporation status for such large entities. The other option is state owned and that is almost always an utter failure. Even China allows their "state owned" businesses a lot of leeway to account for the ups and downs of capitalism and market forces.

Re: Does Apple really log every app you run? A technical look

#328
post #322

Earlier quoted context omitted.

The problem with 'may' is that a network intermediary might block TLS connections to ocsp.apple.com knowing it would fall back to plaintext. Apple could encrypt the payload though, using the Apple public key, which would solve the snooping by intermediaries problem.

A network intermediary blocking or altering the TLS is an active attack. Plain HTTP is also vulnerable to that, so unauthenticated TLS is no worse than the current situation. TLS encrypts the payload just fine if you want that. That’s what TLS is for. PS: You don’t encrypt something to someone else using your own public key.

I'm talking about when they block just the ocsp host TLS port. Heaps of places whitelist https for particular sites, and inspect the content to prevent TLS. Appliances that block TLS via packet inspection are dime a dozen. But the query/response fields can be an opaque encrypted blob and it would get through. Every Apple device obviously has the Apple pub key, and hence they can send encrypted messages back to Apple without needing any further PKI.

Re: Does Apple really log every app you run? A technical look

#329
post #312

Earlier quoted context omitted.

“Simply in breach of contract with Apple” Epic lied about the content of their software. If Apple doesn’t remove software from suppliers who lie about the contents, people will continue to exploit this. There was no overreach. This was the consequence of Epic intentionally lying about the content a software update. It’s also worth pointing out that Epic expected this result, and caused it on purpose. Both Apple, and…

Didn't Epic actually create an entire presentation video advertising the contents of their update? Again, I fully agree that Epic was knowingly in breach of their contract with Apple, and wanted to use the public as leverage. But that doesn't, in any way, make their update malicious for the end user.

The presentation video was released after the update was submitted to the store with the contents hidden and activated later.

As for whether the update was malicious for the end user, we could say we trust epic to operate a payment method, and therefore the update was not malicious.

But there are many actors who would use this exact same methodology, and the update is malicious. Such Trojans exist on Android.

Security policies always prevent behaviors that could be used for non-malicious purposes.

If the argument is that the end users should be the ones to decide, it’s really just another way of saying that Apple shouldn’t be allowed to enforce any security policy.

Of course there are those who believe that Apple shouldn’t be able to enforce security policies, but there is no overreach here.

Re: Does Apple really log every app you run? A technical look

#330

Earlier quoted context omitted.

It's convention. With browsers, you wouldn't want to introduce a recursion point in TLS (we already have certificate chains, and now we'd get OCSP check chains and where does that terminate?). Apple just did what everyone else does for OCSP, in a way which is accepted practice for good reasons. Now in this specific instance, OCSP is being used in quite a different use case. For one, the plaintext issue is not a probl…

Correct. Want to point out that certs are encrypted with TLS1.3, and DNSSEC+DoT/DoH makes ESNI/ECH possible by putting keys in the DNS. Ultimately maybe OSCP could do something similar, or fall back to DANE or some alternate validation method that wouldn’t cause a “loop.”

No browser supports DANE, or has any plan to do so; in fact, Chrome tried supporting DANE, and stopped.
Post reply on HN