Earlier quoted context omitted.
The requests contain only app hashes. They do not contain the unique hardware identifier that Apple computers have. They do not contain your Apple ID, identifying you as a user. Why would you not interpret this charitably as them not actually trying to spy on you? If they wanted to spy on you, why on Earth would they not send the actual valuable information?
The request also contains your ip address. Charitable would be distributing a bloom filter and checking matches locally.
macOS has checked app signatures online for over 2 years
71–80 of 458 posts
Re: macOS has checked app signatures online for over 2 years
#72I sometimes wonder if the mods won't end up banning "political" talk on HN. Because these days everything becomes political, even if it really is a technical issue. Case to the point: online signature check was a technical decision, to fight malware. It was implemented similarly by other OS vendors (Microsoft) and it's been this way for years. Now we discover that it has the unfortunate side-effect that it lessens pr…
The political issue is "if we can't provide these features without weakening privacy, should we still provide them?"
Aren't they both important points to discuss?
Re: macOS has checked app signatures online for over 2 years
#73Earlier quoted context omitted.
That seems incredibly naive. I can’t think of a single program off the top of my head that doesn’t use the Internet to some extent while running. Even many CLI tools I use for development do update checks (and sometimes analytics) in the background.
> That seems incredibly naive. I can’t think of a single program off the top of my head that doesn’t use the Internet to some extent while running. It is not. Imagine that I don't have that great wifi coverage in all places around the house. But I take my laptop there. You know what happens when you have poor wifi connection and you wake up laptop? Even the keyboard+mouse are unresponsive. I was wondering why on eart…
Re: macOS has checked app signatures online for over 2 years
#74"Privacy is not a feature".
Directly contradicting current Apple Marketing. I lothe Apple(and other unethical companies) for lying in their ads. Any benefits of macOS are instantly gone because you cannot Trust Apple to tell the truth. It's as unreliable as Google keeping a service around.
Re: macOS has checked app signatures online for over 2 years
#75Earlier quoted context omitted.
The requests contain only app hashes. They do not contain the unique hardware identifier that Apple computers have. They do not contain your Apple ID, identifying you as a user. Why would you not interpret this charitably as them not actually trying to spy on you? If they wanted to spy on you, why on Earth would they not send the actual valuable information?
>They do not contain the unique hardware identifier that Apple computers have Different part of MacOS can send it and you would have no idea until it malfunction like in this case.
Re: macOS has checked app signatures online for over 2 years
#76Earlier quoted context omitted.
That seems incredibly naive. I can’t think of a single program off the top of my head that doesn’t use the Internet to some extent while running. Even many CLI tools I use for development do update checks (and sometimes analytics) in the background.
> That seems incredibly naive. I can’t think of a single program off the top of my head that doesn’t use the Internet to some extent while running. It is not. Imagine that I don't have that great wifi coverage in all places around the house. But I take my laptop there. You know what happens when you have poor wifi connection and you wake up laptop? Even the keyboard+mouse are unresponsive. I was wondering why on eart…
Re: macOS has checked app signatures online for over 2 years
#77A common refrain in arguments that we don't need laws to protect privacy is that the market will take care of it. The market can't act against what it can't see. Privacy loss is often irreversible. A common refrain in arguments that we don't need to reject closed source software to protect privacy is that being closed source doesn't hide the behaviour, and people will still notice backdoors and privacy leaks. Sometim…
I'm not sure if it's infringing though. If Apple says that they do not collect personal data and that the information is thrown away and this is done for a legitimate business purpose or for the customers (i.e. protecting customers), it may well be fine according to the GDPR.
Re: macOS has checked app signatures online for over 2 years
#78A common refrain in arguments that we don't need laws to protect privacy is that the market will take care of it. The market can't act against what it can't see. Privacy loss is often irreversible. A common refrain in arguments that we don't need to reject closed source software to protect privacy is that being closed source doesn't hide the behaviour, and people will still notice backdoors and privacy leaks. Sometim…
Then, we would find out very quickly what people value.
I firmly believe this ecosystem (as in privacy violating ad and data selling business model) is only dominant because companies are able to mislead with impunity, so it's basically a form of fraud
Re: macOS has checked app signatures online for over 2 years
#79The only charitable understanding of this program is that Apple has no actual table connecting software to hashes, but that they could use the information to understand outbreaks of botnets/spyware that they could then help inform ISPs/global law enforcement to help stop. Is this even reasonable?
The requests contain only app hashes. They do not contain the unique hardware identifier that Apple computers have. They do not contain your Apple ID, identifying you as a user. Why would you not interpret this charitably as them not actually trying to spy on you? If they wanted to spy on you, why on Earth would they not send the actual valuable information?
Has a third party verified they don’t keep track of IP addresses?
Re: macOS has checked app signatures online for over 2 years
#80Earlier quoted context omitted.
> That seems incredibly naive. I can’t think of a single program off the top of my head that doesn’t use the Internet to some extent while running. It is not. Imagine that I don't have that great wifi coverage in all places around the house. But I take my laptop there. You know what happens when you have poor wifi connection and you wake up laptop? Even the keyboard+mouse are unresponsive. I was wondering why on eart…
The MacOS OCSP feature has been documented to be non-functional when there is no internet connection, it does not interrupt or slow down any functioning in that case.