Live data from Hacker News

macOS has checked app signatures online for over 2 years

eclecticlight.co

331–340 of 458 posts

Re: macOS has checked app signatures online for over 2 years

#331
post #213

Earlier quoted context omitted.

That's human nature. As soon as something beneficial to few and detrimental to others is banned, those who benefit seek to find other ways to continue benefitting, again to the detriment of others. This doesn't mean we shouldn't continue trying to stop them. And we stop them through laws. Common sense is not that common and human decency doesn't scale.

In the US, the typical citizen commits an average of a felony a day. The legal code and associated regulations are so lengthy no one can read all of them. The tax code alone is 2,600 pages and associated rulings 70,000 pages. When you have so many laws, they can be applied selectively depending on your political status, or to benefit the regulators or their friends. We just caught the sheriff of Santa Clara extorting…

For your argument to make sence you have to demonstrate that this amounts to nanny state.

I don't think it does, I think is fraud. For it to be consequences of of my choices, what choice do I make to select a mobile phone carrier that does not sell data of my location? Such choice does not exist.

You can't 'non-disclose' some 'small feature' of a mortgage contract, of a loan, etc. Personal data deserves similar respect.

Lastly, we can and do have different laws for individuals and multi-billion dollar corporations - you cant use this as an argument when we are discussing securities fraud and banking regulations.

Re: macOS has checked app signatures online for over 2 years

#332
post #225

Earlier quoted context omitted.

The market only acts fairly when the product is a commodity. The time for the market to react for a product with the complexity of a mac is decades. As the ecosystem grows, the cost of switching increases. Therefore market starts acting more and more inefficiently. This is why countries have state intervention in such cases. And anti trust exists. If the option was a mac with privacy vs a mac without privacy but $10…

> The time for the market to react for a product with the complexity of a mac is decades. This makes me think of the 2 slit experiment as applied to basketballs. There is a period of time that decisions need to be properly considered, presumably simple decisions need little time, and complex decisions need more time. There is also a period of time that is required to make a decision, and a level at which the decision…

> It's like trying to pass a basketball through a slit. Yes, there's a theoretical interference pattern, and you can calculate it, but you can't do the experiment because you can't pass the basketball through a slit that small (in the case of basketballs, if I recall, the largest slit is angstroms if not smaller).

I know this doesn't have too much to do with the core of your post, but I want to mention it nevertheless: QM does not imply that there is an interference pattern for basketballs. There might or might not exist one, but we would need an answer to the question of measurement to predict one way or the other.

Re: macOS has checked app signatures online for over 2 years

#333
post #52

Earlier quoted context omitted.

The market only acts fairly when the product is a commodity. The time for the market to react for a product with the complexity of a mac is decades. As the ecosystem grows, the cost of switching increases. Therefore market starts acting more and more inefficiently. This is why countries have state intervention in such cases. And anti trust exists. If the option was a mac with privacy vs a mac without privacy but $10…

Whilst I agree with the sentiment, it does occur to me just how many kindles I see with ads. Is there any data released on ads Vs no ads versions? That's the closest comparator I can think of.

They sold a lot of the ad enabled tablets one black friday for like $80 which seemed like a good deal at the time despite not running google apps which most people desire, having ads on the lock screen, and having the worlds shittiest home screen app for android. I bought one for my wife. If you are lazy or not inclined you can actually pay after the fact to remove ads.

Alternatively you can deliberately break the ad functionality, install google apps, and android lets you change your home screen.

1 and 2 worked but they broke the ability to set your own home so the fix is a hacky app to hijack the home button to show the right home of your choosing. This worked for over a year then they repeatedly blacklisted such apps, then it worked but with a 2 second delay which is basically horrible and extensions started crashing the gmail app.

Worst piece of shit ever.

Re: macOS has checked app signatures online for over 2 years

#334
post #86

Earlier quoted context omitted.

The act of breaching privacy is technically difficult to prohibit in a way many of us would find palatable. What should be targeted is the product of said breaches. Something like the blood diamond approach. If your company has PII, then you by law must be able to produce a consented attestation chain all the way back to the source. If you do not, then you're charged a fine for every piece of unattested PII on every…

I thonk we are both arguing that clear consent must be present, and the customer must have clearly agreed to whatever you are doing with the data - that appears similar to GDPR. However, how do you prove John Doe has actually agreed to this? What if John says he did not click accept button? Do we require digital signature with certificates, given that most people don't have them or know how to use them? I think the p…

This is civil law. You find out by asking employees in court. They aren’t going to risk perjury, a criminal offense, to spare their employer.

Re: macOS has checked app signatures online for over 2 years

#335

Earlier quoted context omitted.

I’m actually curious what’s wrong about it? I read it from an outsider perspective and it’s full of very convincing arguments against “blockchains.” You’re absolutely correct that he’s writing from his understanding, but Schneider’s been in the field for decades (more than many Bitcoin proponents are old ), so I’m more inclined to believe he knows what he’s talking about than some other random person on the internet.

I think the main reason for the dissonance is that Schneier talks about the trust that happens (and maybe has to happen in real-world scenarios) while the bitcoin community likes to talk about the minimum amount of trust necessary. You don't have to trust the software, you can verify it or implement your own. You don't have to trust your internet uplink, the protocol would work over carrier pigeons or with dead drops…

[deleted]

Re: macOS has checked app signatures online for over 2 years

#336
post #213

Earlier quoted context omitted.

That's human nature. As soon as something beneficial to few and detrimental to others is banned, those who benefit seek to find other ways to continue benefitting, again to the detriment of others. This doesn't mean we shouldn't continue trying to stop them. And we stop them through laws. Common sense is not that common and human decency doesn't scale.

In the US, the typical citizen commits an average of a felony a day. The legal code and associated regulations are so lengthy no one can read all of them. The tax code alone is 2,600 pages and associated rulings 70,000 pages. When you have so many laws, they can be applied selectively depending on your political status, or to benefit the regulators or their friends. We just caught the sheriff of Santa Clara extorting…

> In the US, the typical citizen commits an average of a felony

Sorry but that’s just obvious BS. If it were true, you’d include examples and far more people a certain world leader doesn’t like would be “locked up”.

Re: macOS has checked app signatures online for over 2 years

#337

The only charitable understanding of this program is that Apple has no actual table connecting software to hashes, but that they could use the information to understand outbreaks of botnets/spyware that they could then help inform ISPs/global law enforcement to help stop. Is this even reasonable?

That is not correct. It does a live check when presented with a certificate, to make sure that certificate has not been revoked for signing malware. It doesn’t store anything. Apple are not saving information. It’s just an online blacklist check. That’s how OCSP works everywhere, it isn’t an Apple thing. They are using the standard protocol as documented in the RFC.

There is nothing in the plain OCSP that prevents the responder server from logging the request along with the originating IP. Any claims that a particular server doesn't do so is either just an assumption or based on trust alone. This is why OCSP-stapling is preferred against plain OCSP in browsers and also why plain OCSP can be disabled. In this particular case, trustd and other system daemons are known to skip VPN and firewall blocks - so it's mandatory information leak.

Re: macOS has checked app signatures online for over 2 years

#338

Earlier quoted context omitted.

There's so much wrong with this post I'm not even sure where to start. Literally almost every paragraph starts something untrue. The whole article is written from a false understanding.

If you’re going to claim Schneier is wrong on crypto stuff, you’ll want to bring a suitcase of evidence along if you want people to take your claim seriously.

Well, he does think that one is unable to establish the integrity and authenticity of a message by using DKIM, so...

He does seem to have a weird cult of personality around him but I can't really understand why. He has been irrelevant for quite a while now.

Re: macOS has checked app signatures online for over 2 years

#339
post #322

Earlier quoted context omitted.

Epic violated the Terms of Use for their developer agreement which applies to all platforms. They knew that and they violated it willingly. The court order only prevented it temporarily to reduce the damages that may be incurred and until a determination was made in the initial case. That is not anti-consumer.

Apple promised it would only be used for security related stuff on desktop. I wouldn't want my desktop audio project to break because the VSTs were unsigned due to an iOS app business dispute. That's anti-consumer.

I agree that it's anti-consumer. I disagree that it's Apple that's being anti-consumer. The company developing the app would be anti-consumer for knowingly violating the Terms of Use to try and pull a PR stunt.

Re: macOS has checked app signatures online for over 2 years

#340

Earlier quoted context omitted.

Epic violated the Terms of Use for their developer agreement which applies to all platforms. They knew that and they violated it willingly. The court order only prevented it temporarily to reduce the damages that may be incurred and until a determination was made in the initial case. That is not anti-consumer.

Well even if Epic are the bad guys by violating the ToU willingly, it still impacts the user. As a user I don't want my apps (which I depend on) to stop working, because of a business disagreement. Revoking signatures and disabling the apps on user devices to protect your business model is definitely anti-consumer in my book. You could easily see Apple revoking signatures because of DMCA claims. Even faulty ones, lik…

Of course it impacts the user... And if Epic was found doing something illegal and was shut down or bankrupted, that would also impact the user. Your over-simplification that it's a "business disagreement" is disingenuous and incomplete. The signature revocation system you're claiming is simply to "protect their business model" is the same system that allows Apple to immediately shut down any malware that makes its way into the App Store inadvertently. It's the same system that's been used in the past to protect users from private key leaks.

The only anti-consumer behavior in your situation came from Epic who knowingly violated the rules as a PR stunt.

Post reply on HN