Live data from Hacker News

macOS has checked app signatures online for over 2 years

eclecticlight.co

411–420 of 458 posts

Re: macOS has checked app signatures online for over 2 years

#411
post #231

Security and privacy are not parallel concerns, they’re orthogonal. Strong security absolutely does not imply utmost privacy. I find this to be the most dangerous misconception of the late privacy trend. You can’t just turn security and privacy dials to 11. They’re actually two ends of the same dial, or opposing poles of the same sphere. To increase privacy you must move away from perfect security. Why? Because secur…

One major security concern is identity theft so your statement of privacy being orthogonal to security is very likely not generally true, because the amount of parties you share information with increase the risk.

So we need to look at every scenario in particular because a general rule might not exist. I think the mechanism of signature checking and its consequences should be more transparent.

> If you don’t trust Apple then stop pretending you do by using their hardware/ecosystem.

Fair point, but the trust I put in Apple is that I know their intentions which are quite obvious. They want to sell their products. They want their users being safe and content. I trust them for that. Can this trust be extended to not creating barriers that might increase their revenue? Or share user info for profit? Certainly not. I think Apple is better here than competitors, but it is a common error to not attach restricted scopes to security tokens.

edit: To this case there are trivial solutions for signatures that solve the problem without any privacy violation. Maybe Apples process does preserve privacy because they don't cross reference any data. Maybe they just use it for statistical purposes to determine which apps are used. I would be fine with that. But your statement suggest there is no privacy preseving alternative and I think that is technically wrong.

Re: macOS has checked app signatures online for over 2 years

#412

Earlier quoted context omitted.

It would do absolutely nothing whatsoever for the legality of any collection they might want to do.

Of course, it would. IPs are required data to be gathered. They can be almost all the time correlated with real identities using other requests, but under many data regulation laws they wouldn't be allowed to send personal identifying information that isn't necessary.

GDPR would not agree with you there, I gather.

Re: macOS has checked app signatures online for over 2 years

#413

Earlier quoted context omitted.

They would not be accurately tied together, though, since these requests are not sent with any kind of identifier.

Who knows, may be they can start to send id too by a special request from the server or send those hashes by other channels in addition to this one, but much later. And server can make such request based on some heuristics or based on some 'black list' of hashes. How can you know for sure? We can only guess to the certain degree without looking into sources.

Why would they NOT want the data now but would want it in some unspecified future?

Re: macOS has checked app signatures online for over 2 years

#414
post #185
post #72

Earlier quoted context omitted.

The technical issue is "can we provide these features without weakening privacy?" The political issue is "if we can't provide these features without weakening privacy, should we still provide them?" Aren't they both important points to discuss?

They are, but the difference is that we can fix technical issues, or at least improve them. We can (mostly) agree about what's right and wrong and what's better or worse. Political issues on the other hand, just end up antagonizing us ever more. We argue endlessly, go on countless tangents and nobody agrees on anything because we see the very issues under different lights, experiences, values and cultures. I am tired…

People are "tired of politics" until it affects something they care about.

Re: macOS has checked app signatures online for over 2 years

#415
post #272

Earlier quoted context omitted.

While security and privacy are not parallel, they are not orthogonal either. You can have both. Integrity checks can be done anonymously (e.g.: you could have a p2p network of devices sharing a signed database of certificate revocations). Encrypting something gives me privacy. Signing something gives me security. Encrypting a signed package gives me both.

They _are_ orthogonal, you’re just saying that you can have some of both which is exactly my my point about them existing on a spectrum. And it’s not as simple as encrypting data. You have to trust somebody to determine what good integrity looks like and to then verify the integrity information is fresh. The same privacy concern exists if you run OCSP against cypher-text as it does plaintext. You still have a stream…

You're using the extreme cases of each to argue they are "orthogonal". Perhaps at some extreme no one actually lives in, they are orthogonal. Most people don't need extreme privacy or extreme security, so in the cases that matter, this observation (which seems to be a major crux in your argument) is not important.

Re: macOS has checked app signatures online for over 2 years

#416

Earlier quoted context omitted.

Well even if Epic are the bad guys by violating the ToU willingly, it still impacts the user. As a user I don't want my apps (which I depend on) to stop working, because of a business disagreement. Revoking signatures and disabling the apps on user devices to protect your business model is definitely anti-consumer in my book. You could easily see Apple revoking signatures because of DMCA claims. Even faulty ones, lik…

Of course it impacts the user... And if Epic was found doing something illegal and was shut down or bankrupted, that would also impact the user. Your over-simplification that it's a "business disagreement" is disingenuous and incomplete. The signature revocation system you're claiming is simply to "protect their business model" is the same system that allows Apple to immediately shut down any malware that makes its w…

I was not claiming the revocation system only has the purpose of protecting Apple's business model, but its one of the purposes.

Even though I agree that in the Epic case, most of the blame lies with Epic, I still have a problem with Apple: the signature revocation system is used for more things than removing malware. I think it is user hostile and anti consumer to disable installed apps on other grounds, because the users might be dependent on them.

I'd like to be able to run programs and apps on my machine that are not Apple-approved.

Re: macOS has checked app signatures online for over 2 years

#417
post #86

Earlier quoted context omitted.

Lying to the customer about what your product does, or having secret functionality, should be a criminal offence in the same way as breaking and entering or stalking are. Then, we would find out very quickly what people value. I firmly believe this ecosystem (as in privacy violating ad and data selling business model) is only dominant because companies are able to mislead with impunity, so it's basically a form of fr…

The act of breaching privacy is technically difficult to prohibit in a way many of us would find palatable. What should be targeted is the product of said breaches. Something like the blood diamond approach. If your company has PII, then you by law must be able to produce a consented attestation chain all the way back to the source. If you do not, then you're charged a fine for every piece of unattested PII on every…

> If your company has PII, then you by law must be able to produce a consented attestation chain all the way back to the source.

So...basically the GDPR? Well, not quite, since the GDPR doesn't require consent attestation, "merely" a legal basis. Of which consent is just one (the most useless one to use as a company).

Re: macOS has checked app signatures online for over 2 years

#418
post #407

Earlier quoted context omitted.

>should not be upgraded Most DAW-makers are constantly upgrading their software. And they often obsolete their older versions to get in sync with new OS's. 'Keeping the old stuff' sometimes isn't an option. Physical instruments keep working for decades ... but thanks to OS upgrades, valued digital hardware and/or software instruments (say by Opcode or Native) can be lost to stupid or cavalier changes. Anyone who's be…

Yes they are obviously upgrading their software because they need to make money and adding features and fixing bugs is a great way to do that. The only solution to not having a broken music workstation is to never connect that machine to the internet and never update it. Physical instruments keep working for decades because...they are never connected to the internet and never updated.

Completely agree, except I'd say physical electronic instruments have a lifetime of about 20-30 years now. Several synths I own are now non- or half-working because of fading displays, broken floppy drives, power supplies and even chips going bad. The relentless churn of music computer software and hardware setups has also existed since the 80s. I guess it is probably worse for photo & video production.

Re: macOS has checked app signatures online for over 2 years

#419

Earlier quoted context omitted.

Many lobbyists and lawmakers, unfortunately.

It doesnt count as winning the argument if you paid them to agree with you

It does if you convince people to vote for you though

Re: macOS has checked app signatures online for over 2 years

#420

Earlier quoted context omitted.

No-Logo by Naomi Klein outlined how brands work. One factor in the irrational defence could be a kind of psychological protection of investment. Apple isnt just another company, its an entire lifestyle ecosystem. Those invested in Apple have the watch, tv, laptop, itunes etc. And together they really do "just work" - the user experience is great! So to admit that Apple is flawed, that their investment was a bad idea…

This is a good explanation about why people defend brands, but in case of Apple, my experience is that the anti-Apple crowd is more emotionally invested in being anti-Apple than the fans are for it. It used to be the other way around when Apple was the underdog, but after the iPhone took over and became a sort of default for certain regions and social circles, the most loyal brand warriors are the anything-but-Apple…

The most vocal, emotionally invested anti-apple crowd are those who were once emotionally invested in Apple. Similar to an anti-smoker, ex-cult member, ex-mormon or vegan convert - those who have been burnt are often the loudest. The same psychological effects are in play - people will try to defend the hurt to their ego.

There is no brand of "anti-Apple" - that doesn't really exist as brands don't work like that BUT groups of people do though, and people can have identities of being in a group. (I can't really say I have noticed an anti-apple subreddit either)

One way groups defend themselves is to define the opposition - by defining the opposition to Apple fans as anti-apple-groups, it helps bolster the coherence of the Apple fan group and defend the brand and investment for the individual. We are under attack, close ranks and protect each other.

Post reply on HN