Live data from Hacker News

Application trust is hard, but Apple does it well

security-embedded.com

81–90 of 213 posts

Re: Application trust is hard, but Apple does it well

#81

This argument assumes that companies are unchanging. Apple will never become greedy and use their increased control to raise prices, never stop caring about security and only use the system for market control, etc.

Honestly, THIS!

Apple used this same argument when talking about security agencies - https://www.youtube.com/watch?v=BZmeZyDGkQ0.

You may trust them now. But what's to say they'll remain the good guys forever?

By that logic, what's to say Apple will remain the good guys forever?

Re: Application trust is hard, but Apple does it well

#82
post #28

Earlier quoted context omitted.

This owned vs leased analogy is not a valid one. The user is the ultimate decision maker - the user gets to decide whether they want MacOS or not. The only people talking about constraining this freedom are the ones asking for the government to regulate software distribution. What you are asking for is for Apple to make a design change to their software to support your use case. That is a very reasonable thing to wan…

> Obviously I still own the car. Do you still own the car if it'll just turn off the engines when attempt to drive into a sketchy neighbourhood? Let's assume the car manufacturer knows the city/town's crime rates well and they have your best intentions in mind. They want you to be safe. Do you still own the car?

If I bought a car knowing that is how it worked, then of course I do.

Note: I agree that scenario isn’t desirable. However there is no slippery slope.

Re: Application trust is hard, but Apple does it well

#83
post #70

The article goes over the horrors of X.509, pulls the typical open source cliche that I actually don't see anybody spreading around, contrary to the article's claim, then argues that the privacy part is fine so long as there is a third-party audit. If the best thing the security community can do is install a global mass surveillance network of devices that come at every expense of users' computing freedoms, then I th…

It's not even that. This is a distraction from the real issue which is this technology exists not to improve the security posture but to enforce market control.

So go back a few weeks and you buy a copy of Fortnite, Apple and Epic lock horns on a dispute and they revoke Epic's certificate. Next thing you get a shiny new M1 equipped Mac and go to install it and it's gone from the app store. Slightly deflated, you go back to your Mac and copy the files off it onto your new one, thinking you circumvented this slyly, it does an OCSP check and refuses to run the binary. Eventually the OCSP check will be done, probably after an OS upgrade on your old Mac and that's gone too. So you're deprived of something you paid for and have no control over the hardware you paid for.

This is an example of what could happen.

If it improved security posture the signing infrastructure wouldn't be used to sign any old shit from millions of developers doing all sorts of nefarious things that Apple didn't pick up during the review process...

Edit: this has already been demonstrated if you refer to the Flappy Bird mess a few years back.

Re: Application trust is hard, but Apple does it well

#84
post #70

The article goes over the horrors of X.509, pulls the typical open source cliche that I actually don't see anybody spreading around, contrary to the article's claim, then argues that the privacy part is fine so long as there is a third-party audit. If the best thing the security community can do is install a global mass surveillance network of devices that come at every expense of users' computing freedoms, then I th…

Agreed, and furthermore the article calls the privacy arguments "far-fetched" and "dogwhistles", while only tackling a strawman version of the other side's view. The article doesn't for instance investigate the fact that the OCSP requests go over port 80 (i.e. unencrypted HTTP), or discuss the reliability issues that come into play when everyone's computers depend on a single service to have 100% uptime.

Finally, I think the writer should be more careful with their use of the term "dogwhistle". It's a politically-loaded term that isn't used correctly in this piece.

Re: Application trust is hard, but Apple does it well

#86
>It comes down to an argument of trust - do you trust Apple is acting in your best interests, or do you believe they're a malevolent entity?

No, that's a completely false dichotomy. These are not alternatives at all. I can absolutely trust Apple to act in my best interests in some regards while distrusting them in others.

I do trust Apple to make a good effort to keep malware off my device, a better effort than I could ever hope to make myself. I do trust them not to spy on me to target ads.

But I also know that Apple has a business interest in keeping software off my device that is not malware. I don't trust them to act in my best interest where it conflicts with their best interest.

I also know that their interest in tightly controlling what software goes on my devices creates an opening for authoritarian governments to take control. If and and when end-to-end encryption gets banned, who decides whether or not I can still use Signal? Is it going to be me or is it going to be Apple?

This is definitely not a simple question of trusting Apple or not trusting Apple.

Re: Application trust is hard, but Apple does it well

#88
post #74
post #72

Earlier quoted context omitted.

It’s unfortunate that this is a response to a bulveristic comment. This really is a very important problem, indeed perhaps the most important problem in computer science today.

The real solution is a least privilege hardened operating system that limits the damage both in terms of malicious effects and data exfiltration/ surveillance. Exposing permissions to users is also a hard UI/UX problem. Code signing and OCSP and such are band aids to cover the fact that our OSes have deeply inadequate security models. They all date back to the days when the net was far less hostile or in some cases b…

I’d say this is only one half.

Many malicious effects involve social engineering, fraud, etc, and are not about exfiltration of files.

Re: Application trust is hard, but Apple does it well

#89

This article must have been written before this week's spectacular meltdown in Big Sur, which resulted because Apple emphatically did not handle application trust well.

I’m not sure how you could come to that conclusion given the first paragraph acknowledges the meltdown.

“ On November 12, 2020 Apple released macOS Big Sur. In the hours after the release went live, somewhere in Apple's infrastructure an Online Certificate Status Protocol (OCSP) responder cried out in pain, dropping to its knees, begging for mercy as load increased beyond what it could handle.”

Re: Application trust is hard, but Apple does it well

#90
post #25
post #11

If this unacceptable mess is "doing it well", perhaps the whole idea is doomed and should not be attempting to do it at all. > It comes down to an argument of trust - do you trust Apple is acting in your best interests No. I mean really very obviously no. Neither Microsoft. Nor Google. Why would I assume any company would act in my interests when they have clear incentives to increase their profits and control by act…

Your tone here does not seem proportionally appropriate to the level of discourse this article is attempting. The fact of the matter is that computers offer myriad ways to compromise your life and behave maliciously, and avoiding that is a tall challenge for any company. Apple is trying it their way, and you can try it yours. But to call it Stockholm Syndrome is an unfortunate take on these efforts.

>Your tone here does not seem proportionally appropriate to the level of discourse this article is attempting.

You mean this level of discourse?

>The privacy squad mobilised on this one - in fact, one blog post recieved a lot of attention for decrying such systems with the dogwhistle "you no longer own your computer!"

Post reply on HN