Live data from Hacker News

macOS has checked app signatures online for over 2 years

eclecticlight.co

321–330 of 458 posts

Re: macOS has checked app signatures online for over 2 years

#321

Earlier quoted context omitted.

In the US, the typical citizen commits an average of a felony a day. The legal code and associated regulations are so lengthy no one can read all of them. The tax code alone is 2,600 pages and associated rulings 70,000 pages. When you have so many laws, they can be applied selectively depending on your political status, or to benefit the regulators or their friends. We just caught the sheriff of Santa Clara extorting…

> In the US, the typical citizen commits an average of a felony a day This is surprising to me. Could you provide examples of such common felonies US citizens commit in ignorance?

I think felony is the more serious one? Misdemeanor being stuff like parking violation? I'd definitely want to see some examples for felonies, too :-)

Re: macOS has checked app signatures online for over 2 years

#322
post #278

Earlier quoted context omitted.

Some signatures are invalidated due to business disputes on entirely different platforms (Epic dispute on iOS, signatures invalidated, or threatened to be before court order prevented it, on OS X, for no security reason).

Epic violated the Terms of Use for their developer agreement which applies to all platforms. They knew that and they violated it willingly. The court order only prevented it temporarily to reduce the damages that may be incurred and until a determination was made in the initial case. That is not anti-consumer.

Apple promised it would only be used for security related stuff on desktop. I wouldn't want my desktop audio project to break because the VSTs were unsigned due to an iOS app business dispute. That's anti-consumer.

Re: macOS has checked app signatures online for over 2 years

#323
post #258

Earlier quoted context omitted.

>I don't want to worry about whether my music will work five or ten years from now This is exactly what Apple has already done to the iTunes world, music you had a decade ago is suddenly inaccessible

> [...] music you had a decade ago is suddenly inaccessible Music bought via iTunes doesn't have any DRM since 2009.

But even without DRM, if you go with the default settings and don't download your music locally, you lose access to it if they decide to remove it from their catalog. Same goes for movies/TV shows; I've had both disappear from my iTunes library at various points.

Re: macOS has checked app signatures online for over 2 years

#324
post #282

Earlier quoted context omitted.

That’s true of every single organization and every single individual. You can always justify a conspiracy theory on the basis that you can’t prove a negative like this. Let’s consider another conspiracy theory: “A state actor wants to install spyware, and Apple’s OCSP is a barrier to their goal. They are running an influence campaign to get users to opt out of security protections.” There is no evidence for this theo…

> You can always justify a conspiracy theory on the basis that you can’t prove a negative like this. Its not about definitively claiming they are being nefarious, its about they CAN be, and Apple isn't transparent enough for us to know if they're not. So its about risk. People can use Apple products, I don't really care, but they risk their privacy when they do, and thats not a risk people should have to take when us…

[deleted]

Re: macOS has checked app signatures online for over 2 years

#325
post #206

Earlier quoted context omitted.

I'm sure it probably doesn't to an Apple Cultist with their head in the sand. But for those people, gesturing broadly at all of the evidence available doesn't seem to work either.

Gesturing broadly doesn’t work because it’s not evidence . It is only innuendo. If you had evidence you’d be able to be specific.

"Apple dropped plan for encrypting backups after FBI complained" doesn't sound privacy oriented to me.

https://www.reuters.com/article/us-apple-fbi-icloud-exclusiv...

Re: macOS has checked app signatures online for over 2 years

#326
post #282

Earlier quoted context omitted.

That’s true of every single organization and every single individual. You can always justify a conspiracy theory on the basis that you can’t prove a negative like this. Let’s consider another conspiracy theory: “A state actor wants to install spyware, and Apple’s OCSP is a barrier to their goal. They are running an influence campaign to get users to opt out of security protections.” There is no evidence for this theo…

> You can always justify a conspiracy theory on the basis that you can’t prove a negative like this. Its not about definitively claiming they are being nefarious, its about they CAN be, and Apple isn't transparent enough for us to know if they're not. So its about risk. People can use Apple products, I don't really care, but they risk their privacy when they do, and thats not a risk people should have to take when us…

Any software vendor CAN be nefarious.

It is just innuendo to claim it about a particular one without evidence.

People don’t risk their privacy by trusting Apple any more than they do by trusting anyone else. Almost certainly less so than by trusting a company that makes money out of personal information.

Singling Apple out without evidence is misleading innuendo.

If we want people to have the option not to trust private corporations, we need to create infrastructure that currently doesn’t exist.

Re: macOS has checked app signatures online for over 2 years

#327
post #74

Earlier quoted context omitted.

Directly contradicting current Apple Marketing. I lothe Apple(and other unethical companies) for lying in their ads. Any benefits of macOS are instantly gone because you cannot Trust Apple to tell the truth. It's as unreliable as Google keeping a service around.

Apple's marketing basically boils down to "please trust us that we respect your privacy because we tell you so". You can at least reverse engineer the hardware you own and the software on it, but what about cloud services they're pushing so hard? You don't, and can't, know what happens to your data in someone else's infrastructure.

Well we do know they dropped iCloud end-to-end ecryption after FBI complained.

https://www.reuters.com/article/us-apple-fbi-icloud-exclusiv...

We also know that Apple handed all chinese cloud data to the goverment by changing host to a state firm.

https://www.theverge.com/2018/2/28/17055088/apple-chinese-ic...

Re: macOS has checked app signatures online for over 2 years

#328

Earlier quoted context omitted.

It's quite obvious. That way you can't get nailed for breaching privacy. It's exactly the same concept as the NSA saying that they are only collecting metadata and not doing any spying.

It would do absolutely nothing whatsoever for the legality of any collection they might want to do.

Of course, it would. IPs are required data to be gathered. They can be almost all the time correlated with real identities using other requests, but under many data regulation laws they wouldn't be allowed to send personal identifying information that isn't necessary.

Re: macOS has checked app signatures online for over 2 years

#329
post #122

Apple also makes apps themselves, and, just like AmazonBasics, has a tendency to clone popular apps (such a tendency that it has a name: to be "sherlocked"). To ignore the fact that Apple receives global platform app popularity data, which provides them a competitive advantage over every other app developer, is somewhat foolish. Gatekeeper has security benefits, yeah. But this data, just like 3P sales stats to Amazon…

[deleted]

Re: macOS has checked app signatures online for over 2 years

#330
post #32

Earlier quoted context omitted.

Does it matter? Would anyone (but the most paranoid) care? My guess is that OCSP is supposed to be part of a defense in depth strategy, so it doesn't have to be 100% airtight to achieve its goals

I care that Apple or Microsoft don't get to know what executables I run. That is information highly relevant to security. And what do mean with paranoid? I think computing is in danger of getting locked down and that would be such a large overall detriment for everybody. It is a matter of having a broad perspective. It is also political because you create information asymmetry. To be honest, to dismiss it as paranoia…

> I care that Apple or Microsoft don't get to know what executables I run. That is information highly relevant to security.

I think you missed the context of this comment thread. The "Does it matter" and "Would anyone care?" questions were directed at the question of what happens (presumably from a security point of view), if OSCP requests were being blocked. It's not related to the discussion about whether OSCP queries violate privacy or not.

Post reply on HN