Security and privacy are not parallel concerns, they’re orthogonal. Strong security absolutely does not imply utmost privacy. I find this to be the most dangerous misconception of the late privacy trend. You can’t just turn security and privacy dials to 11. They’re actually two ends of the same dial, or opposing poles of the same sphere. To increase privacy you must move away from perfect security. Why? Because secur…
So we need to look at every scenario in particular because a general rule might not exist. I think the mechanism of signature checking and its consequences should be more transparent.
> If you don’t trust Apple then stop pretending you do by using their hardware/ecosystem.
Fair point, but the trust I put in Apple is that I know their intentions which are quite obvious. They want to sell their products. They want their users being safe and content. I trust them for that. Can this trust be extended to not creating barriers that might increase their revenue? Or share user info for profit? Certainly not. I think Apple is better here than competitors, but it is a common error to not attach restricted scopes to security tokens.
edit: To this case there are trivial solutions for signatures that solve the problem without any privacy violation. Maybe Apples process does preserve privacy because they don't cross reference any data. Maybe they just use it for statistical purposes to determine which apps are used. I would be fine with that. But your statement suggest there is no privacy preseving alternative and I think that is technically wrong.