Not sure whether the non-privacy related aspect about OCSP is less worrying. Officially Apple does this to protect innocent users from malware, but as we've seen it also allows them to remotely disable any developers' software. Not really something that I'd want on my machine.
Does Apple really log every app you run? A technical look
51–60 of 355 posts
Re: Does Apple really log every app you run? A technical look
#52Re: Does Apple really log every app you run? A technical look
#53While other posts on this topic are too alarmist, this one is way too Apple apologetic for my taste. * There is no information on how often the validation happens. All this investigation concludes is that it doesn't happen when closing and immediately re-opening an app. Is it every week? Every reboot? Every hour? If it's less, that's essentially the same as doing it on every launch. * There is no justification for se…
I feel Apple has done privacy well in so many cases, that the way this works is really disappointing :-/
Re: Does Apple really log every app you run? A technical look
#54While other posts on this topic are too alarmist, this one is way too Apple apologetic for my taste. * There is no information on how often the validation happens. All this investigation concludes is that it doesn't happen when closing and immediately re-opening an app. Is it every week? Every reboot? Every hour? If it's less, that's essentially the same as doing it on every launch. * There is no justification for se…
Is it not common knowledge how telemetry works for the operating systems? They generally batch up a bunch of logs like this, encrypt them, compress them, and then send them to the mothership (hopefully when you're on WiFi).
Re: Does Apple really log every app you run? A technical look
#55You know, before declaring the end of the world, is there any information from the source (Apple)? Discussions here seem to have had several thousand comments without obtaining this basic info. It would be good to know, I would think?
Re: Does Apple really log every app you run? A technical look
#56While other posts on this topic are too alarmist, this one is way too Apple apologetic for my taste. * There is no information on how often the validation happens. All this investigation concludes is that it doesn't happen when closing and immediately re-opening an app. Is it every week? Every reboot? Every hour? If it's less, that's essentially the same as doing it on every launch. * There is no justification for se…
I feel Apple has done privacy well in so many cases, that the way this works is really disappointing :-/
Re: Does Apple really log every app you run? A technical look
#57If anyone is concerned with ocsp activity and verifications being requested all over the web, then oh boy stay away from https. OCSP is a good thing, and the web - and your signed applications - are better off with it.
Active OCSP is far from being considered a good thing universally.
Re: Does Apple really log every app you run? A technical look
#58Earlier quoted context omitted.
Learn about Big Sur(veillance). You can't block telemetry and it bypasses any VPN.
Seems to work fine here, nothing bypasses my VPN nor does it bypass my firewall. Perhaps that's because my VPN and my firewall aren't running inside the computer but external to it, as it should.
Re: Does Apple really log every app you run? A technical look
#59While other posts on this topic are too alarmist, this one is way too Apple apologetic for my taste. * There is no information on how often the validation happens. All this investigation concludes is that it doesn't happen when closing and immediately re-opening an app. Is it every week? Every reboot? Every hour? If it's less, that's essentially the same as doing it on every launch. * There is no justification for se…
I wrote a blog post about this. My analysis indicates that Developer ID OCSP responses were previously cached for 5 minutes, but Apple changed it to half a day after Thursday's outage, probably to reduce traffic:
Re: Does Apple really log every app you run? A technical look
#60Relatedly, does anyone know if Big Sur allows one to use a custom DNS server on the device level with those privileged destinations? (He says, mulling the complexities of getting a pi-hole working with his mesh system.)