52 ms·
macOS unable to open any non-Apple application
- submeta 6y agoUnbelievable. When I read the tweet (tried to post here as well), I suddenly realized why my Mac was unresponsive an hour ago. Here is another tweet that describes the problem in more detail: https://mobile.twitter.com/llanga/status/1326989724704268289 https://mobile.twitter.com/llanga/status/1326989724704268289 > I am currently unable to work because macOS sends hashes of every opened executable to some server of theirs and when `trustd` and `syspolicyd` are unable to do so, the entire operating system grinds to a halt. EDIT: As others pointed out, I put this to my `/etc/hosts` file and refreshed it like so: sudo emacs /etc/hosts # add `0.0.0.0 ocsp.apple.com` sudo dscacheutil -flushcache; sudo killall -HUP mDNSResponder # refresh hosts
- vsskanth 6y agoCan apple not use security certificates to verify publishers ? why does it need to go to their servers ?
- fpoling 6y agoThey are checking for revoked certificates.
- loeg 6y agoThe URL mentioned in sibling comments suggests this has to do with certificate revocation (OCSP): https://en.wikipedia.org/wiki/Online_Certificate_Status_Protocol https://en.wikipedia.org/wiki/Online_Certificate_Status_Prot... I agree that breaking system availability when an OCSP server isn't available is user-hostile and unnecessary.
- freeone3000 6y agoThe alternative is OCSP being allowed if internet isn't available, which is a security risk for reasonable defense-in-depth strategies.
- gruez 6y agoMost OSCP implementations fail-open, not fail-closed. I get the benefits of having it fail-closed, but it should be opt in, because having an always-online requirement for using a mac is ridiculous.
- jrochkind1 6y agoThe OP literally says if you disallow connection or unplug the intenret it does fail open. I think it's probably an unintended bug that this failure mode was fail-closed. The costs of this unintended bug are going to be huge to Apple's reputation, as demonstrated in this whole HN thread, where many assuming what's going on is even WORSE than it really is. (Personally I think having signed certs (with opt-in ability to run unsigned apps, as MacOS has) is fine. And fail-open OSCP revocation check is also fine-ish, although it would annoy me if it's making it slower to launch apps on the regular. The problem here is a bug, not one of design. But most of this thread is assuming Apple was doing something different than this. Of course, how often a company produces fairly catastrophic bugs is also on them).
- closeparen 6y agoIf your Mac is unambiguously offline it fails open. What it's handling poorly is the fail-slow case.
- bentcorner 6y agoUgh. IMO the network should not be on the critical path to running an executable.
- Spivak 6y agoMost browser vendors agree because they all stopped checking CRLs (like they technically should) when verifying certs. I don’t think the design is wrong, I just think it’s tuned a little too cautious. If you’re going to verify certs then checking the CRL is something you really should do before approval. And you can’t sync the database entirely because it’s too big. There really aren’t any good solutions to this unless you can solve the cache invalidation problem.
- valuearb 6y agoWhat’s the alternative tho?
- LgWoodenBadger 6y agoPublish revocations as security updates to the OS?
- valuearb 6y agoSecurity updates take too long. How bout each copy of MacOS keeps local copy of revocation database, and updates in background? Much faster, updates relatively quickly, and not subject to network outages.
- cromka 6y agoI'd imagine that revocations don't happen often. And when they do, Apple has a perfectly capable infrastructure to push those small incremental changes on demand. It's almost as if they intentionally ignored such superior solution and chose calling home for other reasons...
- throwaway888abc 6y agoThat way (current) Apple also has the app usage statistic ?
- jimmaswell 6y agoYou don't need an alternative. The entire concept is totally unnecessary.
- loeg 6y agoA limited change would be to fail-open more of the time, e.g., if the OCSP server does not respond within a few milliseconds. (MacOS already fails-open in some internet scenarios.) A better option is to asynchronously update a Certificate Revocation List ("CRL") and perform any check local to the machine. This avoids disclosing to Apple every single time you run a program, which program it is, and what network you're on. It could also emergency-revoke certificates just as quickly as the OCSP design by polling at the same frequency (every app startup).
- deleted 6y ago[deleted]
- LinusS1 6y agoNormally if there's no internet Gatekeeper instead checks the "stapled" notarization ticket from the notarization process. But since there is internet, and the ocsp server is technically "up" gatekeeper isn't checking the tickets.
- merb 6y agoactually I think the problem is not that it is not available, heck /etc/hosts fixes wouldn't work than. it's that it is unresponsive as hell, and they have no system wide circuit breaker, if it is slow.
- jrochkind1 6y ago> I agree that breaking system availability when an OCSP server isn't available is user-hostile and unnecessary. Based on the OP tweet... depending on the way it is unavailable, the failure is indeed ignored in some cases. "Denying that connection fixes it, because OCSP is a soft failure (Disconnect internet also fixes.)" So it may be an actual unintended bug that a particular failure path results in a DoS instead?
- deleted 6y ago[deleted]
- burlesona 6y agoIt does go locally if you are not on wifi. I thought the issue was my slow internet so I turned off wifi and suddenly everything launched just fine.
- draebek 6y agoNote that it's ocsp.apple.com, not oSCp.apple.com.
- merb 6y agodns is case insensitive
- ajford 6y agoOP was commenting on the order of the S and C
- fipar 6y agoparent is using case to highlight a typo in the domain name, not to imply that the problem is with the case.
- jolux 6y ago"oSCp".ToLower() != "oCSp".ToLower()
- deleted 6y ago[deleted]
- deleted 6y ago[deleted]
- mediaman 6y agoit's transposed, not case difference
- labster 6y agoI'm sure if the SCP Foundation gets involved in filtering our applications, they have a very good reason, like keeping Zalgo out of our reality.
- Commodore_64 6y agoI would want to see what applications foundation is hiding from us. Like a FOSS version of Windows 10
- read_if_gay_ 6y agoI started panicking mildly thinking my drive was failing or something. And just before this, I finally managed to fix Spotlight pegging one core at 100% constantly. Next thing, I reboot into a laggy system. macOS is my favorite OS, but the shit I put up with... it's basically an abusive relationship at this point.
- jrib 6y agoyeah, I had spotlight thrashing my disk too. Odd.
- rootsudo 6y agoHow interesting...Apple, couldn't, be doing a pied piper, right? /s obviously.
- SoSoRoCoCo 6y ago> macOS is my favorite OS, but the shit I put up with... Right there with ya.
- 27182818284 6y agoSame. Panic attack. Thought the SSD was dying. I ran Disk Utility diagnostics and started coming up with plans to reformat and restore as a last resort. Apple folks in this thread, this was terrible
- deleted 6y ago[deleted]
- webvictim 6y agoI genuinely thought the same thing. I opened my MBP and it was sluggish, felt like it was dead. Browser wouldn't load, Zoom wouldn't load, I rebooted and the same problems persisted. I honestly thought the hardware was giving out. I almost cannot believe the actual cause. Absolutely awful experience.
- tudelo 6y ago
- deleted 6y ago[deleted]
- charwalker 6y agoI thought this was an old issue that was known or resolved months ago. Is this still an ongoing security practice that kills devs on MacOS? This is about when I remember seeing it: https://medium.com/@acecilia/apple-is-sending-a-request-to-their-servers-for-every-piece-of-software-you-run-on-your-mac-b0bb509eee65 https://medium.com/@acecilia/apple-is-sending-a-request-to-t...
- vishesh92 6y agoFound another reason for me to not get a Mac
- miguelmota 6y agoYou can't go wrong with a ThinkPad. I switched from Mac to a T480 with Arch for dev work and it's been great.
- jagger27 6y agoIf they brought back taller displays I’d be right there with you.
- scns 6y agoCheck the article on anandtech about the new Razer laptop. Disclaimer: not affiliated.
- michalf6 6y agoThey are, next crop will be 16:10
- dotancohen 6y agoAnother poster mentioned the Huawei Matebook Pro has a 3:2 screen. I'm now looking into getting one for that reason alone.
- m4rtink 6y agoI'm running a bunch of ThinkPads with Fedora & all works fine (and worked fine for years).
- VyperCard 6y agoWe’re running Thinkpads at work with fedora and they really don’t.
- 6y ago
- jrochkind1 6y agoHuh apparently I win by still being on an old OS version?
- pgt 6y agoMy policy is to never upgrade anything until everyone I know has upgraded to the next version and not downgraded after N weeks.
- sjwright 6y agoMy policy is to upgrade my secondary/personal/low importance computer on day one and my primary computer a few weeks later.
- JKCalhoun 6y agoLOL, my policy is to never major-upgrade the OS the machine came with. I have machines around the house with OS'es going back a ways...
- trophycase 6y agoThis is the correct policy. I upgraded my mac because I couldn't install a certain application on the version I was running and now it runs crazy hot and the fans run on full blast whenever I watch a video on the internet.
- wtetzner 6y agoDepends on how old, I guess. I'm running Mojave, and ran into the problem.
- SnowflakeOnIce 6y agoRight around this same time, I had 1 macBook hard reboot (watchdogd timeout) and shortly thereafter, a second macBook froze, fan maxed out, with the display not coming up. Then it rebooted into recovery mode. Yeah, these _could_ be unrelated issues to what has been going on in Apple land today, but it's uncanny...
- dylan604 6y agoI keep reading in the tweets how all Macs are unusable. Is this an OS bug that doesn't effect older OSes? I'm on Mojave on my 2017 MBP, and have had zero issues at all. When was `trustd` introduced?
- TMWNN 6y ago`/usr/libexec/trustd` exists on Mojave, too. There's a (very unhelpful) manpage. I think you were just lucky to not open non-Apple applications during the outage.
- plorkyeran 6y agoChecking for notarization on each launch was introduced in catalina. Older versions have trustd, but it was only used for the gatekeeper checks added in 10.8.
- ericd 6y agoI ran into this on trying to load a new video file on VLC, with Mojave, so I guess it's not just apps, but maybe any new file load.
- jwineinger 6y agoMy 2018 MPB on Mojave had some serious issues launching apps for a little while yesterday (3PM central) afternoon. It seemed to resolve within an hour though. Not sure how that lines up with the outage described here.
- jbergstroem 6y agoI discovered this by running unbound – a DNS server – locally (block some unwanted hosts and do dns over TLS). I guess the rest of the story is pretty obvious; having your default dns server not being able to resolve because you're trying to verify it – since you cannot resolve your verify hostname – is obviously Not Great. As you can imagine, there is no waiting in the world that fixes this. I couldn't kill (-9) the process either; had to reboot into safe mode, rename the binary and switch the default dns on the network.
- areoform 6y agoSo yesterday I wrote about the blurring lines of ownership, and people came back with some fairly disparate responses. It's fair to say that I was mostly dismissed. https://news.ycombinator.com/item?id=25058952 https://news.ycombinator.com/item?id=25058952 And this is why I won't be moving to Apple silicon. Apple already has the ability to restrict whats apps I can run (they can simply toggle a switch for all users to "no unsigned binaries"), and congrats! Apple is the sole decider of what we get to use on our computers. Of course Apple's Craig Federighi assures us that the people making such assertions are "tools" (https://youtu.be/Hg9F1Qjv3iU?t=3177 https://youtu.be/Hg9F1Qjv3iU?t=3177 , timestamp 53:33) and they have no intention whatsoever of taking away our ability to do general compute on the machines we buy and own. Except... Apple can already decide what binaries you can execute. Should they choose to. Apple is now restricting what other OSes you can boot into. As they've chosen to. Apple can now make their machine reject a new, third-party repair part like a bad transplant. Should they choose to. It's clear where they're going. And I'm jumping ship. It's painful to do so, given how invested I am in the ecosystem, but we're already beyond the threshold that many of us would have left earlier in the decade. --- edit - It's also really hard as a designer + developer + would-be researcher in the making to find a good computer. Most non-Apple laptops don't have very good color accuracy. They also don't have good trackpads, and their keyboard + trackpad alignment is wonky (it's off-center in a lot of cases! How weird is that???) I'm trying to find a laptop with good build quality, long battery life, a good display that I can design on, a good trackpad so that I don't have to carry around a mouse, good speakers would be a plus, and light enough that I don't feel like I'm lifting weights while working on my laptop. And this package should ideally come with 512GB of SSD storage and, at least, 16GB to 32GB of RAM. Oh and it shouldn't be more expensive than a Mac as many of these laptops are! Any suggestions?
- acomjean 6y agoMy partner bought a razer 13 inch to replace a MacBook Air. It wasn’t cheap, the build quality is excellent and it handles everything (she’s in an orchestra and records her parts on it, does graphic design and sometimes plays fortnite.). The screen is quite nice and the build quality is better than my system 76 (onyx pro) which I really like too. Dave2d on YouTube gives pretty short and decent laptop reviews. I think he has a discord channel discussing the machines too
- phkahler 6y ago> I am currently unable to work because macOS sends hashes of every opened executable to some server of theirs and when `trustd` and `syspolicyd` are unable to do so, the entire operating system grinds to a halt. That's another case of a product not doing its primary function - OS running apps - because company placed their own (data gathering) objective above it. See thermostats not turning on heat when the internet connection is down and other equally stupid examples...
- octoberfranklin 6y agoSee also: all electric vehicles (except a few very old designs).
- Faaak 6y agoTesla is not all electric vehicles. My Twizy and Ioniq haven't got a single touch of data gathering neither a SIM card/wifi connectivity.
- octoberfranklin 6y agoYeah those are golf carts.
- fastball 6y agoPretty sure Apple is doing this for security reasons, not data gathering reasons.
- mister_hn 6y agoand people was shocked at Windows 10 doing telemetry. MacOS isn't doing it better as I see
- duncanc4 6y agoThere is a mistake here. It should be “ocsp.apple.com”
- playcache 6y agoHa! So that's what it was. Last night (I just woke up in the UK) my macbook pro started to crawl, I started to threat that it might be the SSD starting to fail.
- chimen 6y agoUsing a premium DNS with filtering features make sense: https://dnsadblock.com https://dnsadblock.com
- lucasverra 6y agoor https://nextdns.io/ https://nextdns.io/
- sildur 6y agoThat oscp server must be compiling a huge set of stats on application usage. That doesn't sound right, privacy-wise.
- masklinn 6y agoIt probably just gets a fingerprint, or the cert’ information. But when the endpoint is dying and it gets called every time you try to run any binary…
- Cthulhu_ 6y agoWelp, I won't be updating today then, not unless they fix that.
- antihero 6y agoThe server is called OSCP which suggests to me that if we look at Apple in the most positive light - they sign and certify binaries as safe. If an app gets later reported as malicious, they need to revoke the certificate that has been used to sign said binary. So when you open an app, how else are they going to check whether the certificate is still valid or whether it has been revoked? Can anyone confirm whether this lookup applies to unsigned as well as signed binaries? As far as I know if I build a brand new binary with cargo, and run it, it doesn't do any checks.
- habosa 6y agoHere's an idea: log all opened binaries somewhere and then every hour or so check them against the list. Never block me from opening something, but warn me about bad stuff on a regular basis.
- WhiteWestie 6y agoThey could also keep the current solution and just use a CRL as a backup to OCSP to check the revoked certificates and update it every other hour...
- antihero 6y agoYes but with your solution if an app is malicious, and did malicious things, it now has a whole hour to fuck your shit up before being disabled.
- jojobas 6y agoHere's a wild idea: don't block executables from running. Or if you do, only do it for a set of known bad ones, as antivirus products do. Do not put a cloud service (or anything for that matter) between the users and their ability to run what they want.
- antihero 6y agoSure but how does that work? If a cert-revoked app is allowed to run, the damage is already done. I think perhaps a better tradeoff would be if a revocation list could be synced hourly or so and the app could be checked sync locally and then asyncronously on open. And of course, always give the power user an option to ignore things.
- LinuxBender 6y agoWhy isn't apple doing OCSP stapling & caching? Reverse proxies have long since solved OCSP availability with stapling and caching.
- neop1x 6y agoCurrently the workaround seems to be /etc/hosts override or firewall-level blocking. Just a small reminder that this can soon stop working: Apple's apps bypass firewalls like LittleSnitch and LuLu on macOS Big Sur - https://news.ycombinator.com/item?id=24838816 https://news.ycombinator.com/item?id=24838816
- rpastuszak 6y agoThis might be a stupid question, but is there a downside to blocking this "feature"? I can't think of any. I've been using Big Sur beta for some time and one of the things that annoyed me a bit was the sudden lack of responsiveness, which is a tad annoying given that I upgraded to a 16inch MBP earlier this year and everything felt so snappy.
- Bondi_Blue 6y agoOCSP not OSCP You can also run these commands to disable ocsp (and crl) since it can no longer be accomplished in Keychain Access → Preferences: defaults write /Library/Preferences/com.apple.security.revocation.plist CRLStyle None defaults write /Library/Preferences/com.apple.security.revocation.plist OCSPStyle None defaults write com.apple.security.revocation.plist CRLStyle None defaults write com.apple.security.revocation.plist OCSPStyle None
- ummonk 6y agoI had both my personal and work laptop become unresponsive at the same time. I was wondering what kind of problem could cause that - was thinking EM interference or possibly something on my network. This explains it.
- deleted 6y ago[deleted]
- passwordreset 6y agoocsp.apple.com also has an IPv6 address. Firefox connects to it even with 0.0.0.0 in the hosts file and a flushed cache (you need to also clear firefox's internal cache if you're testing with it), so I'd assume that trustd could connect to the ocsp site as well. I don't think this will work without ensuring there is no IPv6 traffic on your network, or otherwise dumping both IPv4 and v6 packets to ocsp.apple.com. Disable IPv6: sudo networksetup -setv6off Wi-Fi (where Wi-Fi is the name of the network service)
- hxtk 6y agoCan you not just add an IPv6 entry for it in your hosts file, e.g., ::1? That would work in Linux and seems like a much less nuclear option than disabling ipv6 all together, but admittedly I've never worked with ipv6 networking on Macs. Last time I played with a Mac they also had the BSD `ipfw` command for kernel packet filtering [1]. Could try something there if it still exists. [1]: https://www.unix.com/man-page/FreeBSD/8/ipfw/ https://www.unix.com/man-page/FreeBSD/8/ipfw/
- passwordreset 6y agoJust to confirm: Yes, that works fine. It's probably the better solution here.
- alexanderchr 6y agoMy MacBook is basically unusable right now. This appears to be the reason. Is there any way to fix it without installing little snitch? Edit: working as usual now, moments after i wrote this. But seriously Apple, how can you allow this to happen? Your services hanging should _never_ prevent my device from running things locally. This is seriously making me reconsider my next computer purchase.
- pwinnski 6y agoApparently you can set ocsp.apple.com to 127.0.0.1 in your /etc/hosts This is really terrible, but at least the workaround is simple.
- tlunter 6y agoAdd the `127.0.0.1 ocsp.apple.com` line to your /etc/hosts file.
- jonheller 6y agoThank you, this fixed it for me. (What a mess!)
- FanaHOVA 6y agoTurn off your internet, open the app, turn it back on.
- twoodfin 6y agoI don't know if the slow downloads of Big Sur are related, but the underlying problem is that ocsp.apple.com[1] is fubar, and certificate revocation lookups are failing. EDIT: This might indeed be Big Sur-release-day related. Most certificate revocation failures are "soft", but with ocsp.apple.com black-holed in /etc/hosts I can't resume downloading the update. [1] https://twitter.com/lapcatsoftware/status/1326990296412991489 https://twitter.com/lapcatsoftware/status/132699029641299148...
- Aperocky 6y agoTalking about a cluster. Now when I get my new mac, I'm going to find a way to opt out of this.
- minimaxir 6y agoI successfully downloaded all 12GB of the update; however I am getting an Installation Failed error, which is apparently common and likely related: https://twitter.com/zollotech/status/1326994718744571914 https://twitter.com/zollotech/status/1326994718744571914
- commonturtle 6y agoYou should never, ever, install a MacOS update the moment it comes out. There is a high chance (> 30% from my experience) that something will be wrong with it. iOS too for that matter. Wait for at least one week and check out other people's experiences first.
- saagarjha 6y agoThis applies to every Mac, with or without an update.
- Someone 6y agoNot only Macs. “There is a high chance that something will be wrong with it” applies to almost all software of the size of modern OSes.
- tonyedgecombe 6y agoYes, Windows 10 forced updates have broken so many things for me.
- rvz 6y agoThis. To save yourself the headaches and frustrations, wait for the bug fix releases and updates to come first before installing this very first new release. It makes no sense to immediately update the system and then risk your computer being rendered unusable with such bugs and problems whilst having a deadline hanging over your head.
- dawnerd 6y agoI ran the beta over the summer and it was awful. I loved the changes but it was just unstable as hell. And people kept saying it was the most stable is yet, I don’t get it.
- jen20 6y agoI’ve been running it as a daily driver since the first day of the developer betas and have found it to be vastly more stable than the previous version, with basically no issues before this. I don’t know what to tell you, beyond the fact that all use cases are not the same, apparently.
- rubatuga 6y agoDoes anybody now how to disable all hashing on macOS? The best I could do was disable GateKeeper with `sudo spctl --master-disable`.
- LeoNatan25 6y agoYou can also disable code signing enforcement and amfi by adding the following boot args: cs_enforcement_disable=1 amfi_get_out_of_my_way=1
- Wowfunhappy 6y agoWould anyone be able to explain more specifically how cs_enforcement_disable is is different from disabling Gatekeeper?
- saagarjha 6y agoI believe GateKeeper only works on first launch.
- rubatuga 6y agoThanks, you can also disable library code signing validation too: `sudo defaults write /Library/Preferences/com.apple.security.libraryvalidation.plist DisableLibraryValidation -bool true`
- staz 6y agoInstall another OS? * There are some work around in this thread but in reality you don't know how and when Apple may choose to automatically re-enable it without your consent. * You should probably just smack you Mac with a rock just to be sure ;)
- augustl 6y agoThe title is slightly misleading. ALL macs with a recent macOS (Catalina?) are freezing, since the security checks that happens when you launch a binary is down. Even if you don't update to Big Sur.
- huseyinkeles 6y agoMy Mojave was also affected.
- _joel 6y agoIndeed, I was bouncing a session in Logic and even that crawled, activity monitor showed a blank screen when it finally opened and iterm2 was unresponsive. I thought the machine was under load but the fans weren't even on.
- huseyinkeles 6y agoYeah, that's the weird thing. CPU load etc. were all normal in the Activity Monitor.
- deleted 6y ago[deleted]
- patrec 6y agoHilarious. I wonder if any of the downvoters of https://news.ycombinator.com/item?id=25068229 https://news.ycombinator.com/item?id=25068229 now experience cognitive dissonance.
- rubatuga 6y agoYou mean cognitive resonance?
- pritambaral 6y ago> downvoters of ...
- throwii 6y agoThe tracking is not new, from Reddit: https://www.reddit.com/r/netsec/comments/gp52pe/apple_is_tracking_hashes_of_all_executables/ https://www.reddit.com/r/netsec/comments/gp52pe/apple_is_tra...
- modeless 6y agoYou've got to be kidding me. When Apple's servers are down, all Macs worldwide start freezing randomly? My XCode is hanging during builds, is this why? This code signing enforcement stuff has gone way too far. Heads should roll for this.
- augustl 6y agoThat's correct. AFAIK Catalina will check online for everything, even binaries you compile yourself.
- Aperocky 6y agowait what, how?
- szhu 6y agohttps://news.ycombinator.com/item?id=23281564 https://news.ycombinator.com/item?id=23281564
- jrochkind1 6y agoThe behavior documented there is on FIRST run of a new executable. You can like that behavior or find it unacceptable, but the issue in OP is not that, it was applying to executables that had already been launched plenty of times on the machine.
- SolarUpNote 6y ago[deleted]
- jrochkind1 6y agoRight. The recent problem (in top-level OP, and that you were presumably experiencing) was not just first run, but the behavior explained at the GP link (https://news.ycombinator.com/item?id=23281564 https://news.ycombinator.com/item?id=23281564 , HN thread for https://lapcatsoftware.com/articles/catalina-executables.html https://lapcatsoftware.com/articles/catalina-executables.htm...) is just about first-run, so the behavior explained at the GP link is not sufficient explanation for the recent problem, it's not talking about the same thing.
- SkyPuncher 6y agoThis is brutal. I've found a work around for now. * Turn off wifi * Reboot * Open everything you need * Turn wifi back on
- j4_hnews 6y agoAdding: 0.0.0.0 http://ocsp.apple.com http://ocsp.apple.com to /private/etc/hosts solves it. Can't believe Big Sur is somehow affecting my Mohave Mac! Yikes!
- domh 6y agoHaving this issue on a 13' MBP. Running this to append ocsp.apple.com to the hosts file did the trick: echo '127.0.0.1 ocsp.apple.com' | sudo tee -a /etc/hosts
- LeoNatan25 6y agoApple software quality and design is a joke.
- viro 6y agoDude you work at Wix.
- LeoNatan25 6y agoAnd? I am the first to admit Wix quality isn't great either. But yes, let's compare the 2T$ OS vendor to a website builder. That makes sense.
- dang 6y agoMaybe so, but please don't post unsubstantive comments here. We're trying for something a bit different. https://news.ycombinator.com/newsguidelines.html https://news.ycombinator.com/newsguidelines.html
- LeoNatan25 6y agoYou are right. I was just letting off some steam. I am just really frustrated with a company that I respected for so many years, going downhill so much over the last 5-6 years.
- pengaru 6y agoChampions of privacy, phoning home a hash of every executable your computer runs!
- hk__2 6y ago> Champions of privacy, phoning home a hash of every executable your computer runs! What’s the matter with privacy? That’s a basic signature check, and you can do so while preserving privacy by using salted hashes or a similar solution.
- jl2718 6y agoI don’t understand how salted hashes would obfuscate the query. Private information retrieval is much more complicated than private password storage, and how do we know what the protocol is?
- root_axis 6y agoA centralized repository of all your executable hashes is a high precision fingerprint.
- strogonoff 6y agoThere are two major somewhat misleading bits of buzz around macOS “phoning home” all of our executables. 1: among Windows, macOS and Linux only Linux distros don’t do such checks, and most of end-user Linux installations are arguably secure in spite of this—mostly because they are very rare and thus not a priority target for malware. 2: this only concerns files you launch. If you wrap your binary invocation in a shell script, that shell script’s hash will be sent, not your binary’s.
- circularfoyers 6y agoWhat does the author of the operating system phoning home have to do with Linux not being a target for malware? It seems like you're mixing up two different issues with this.
- deleted 6y ago[deleted]
- Lammy 6y agoMaybe it's just me but the idea that my computer lets Apple (+ any LE organizations) surveil my app launches seems so much scarier than any malware.
- brundolf 6y agoI don't know about you, but hashes of the binaries I run don't exactly reveal any sensitive personal information about me. That said, obviously they should have much more graceful degradation in place for when something is wrong with the service.
- djsumdog 6y agoIn this case, isn't the hash of the binary consistent across all devices, so Apples can in fact derive exactly which binary you're running (assuming they have a large database of application binary and hashes)?
- ardy42 6y ago> assuming they have a large database of application binary and hashes A database like an "app store"?
- deleted 6y ago[deleted]
- refulgentis 6y agoyup! and the variety of ways to leak that information along the way...Privacy(tm)!
- brundolf 6y agoYes. My personal data involves what I do within those apps, not which ones they are.
- thelean12 6y ago
- DavideNL 6y agoThis is horrible. How can launching apps be depending on a cloud service being available...
- saagarjha 6y agoGateKeeper.
- papaf 6y agoIt takes courage. Think different.
- Wowfunhappy 6y ago> How can launching apps be depending on a cloud service being available... It's not, per se. The apps will launch if you block the specific subdomain, or turn off internet. The problem is if the computer thinks it can connect and keeps trying.
- DaiPlusPlus 6y agoAh yes - the “poor X is worse than no X”-problem. It’s a huge problem on Windows where Explorer.exe still blocks the UI thread while it checks SMB shares if it thinks it can connect to them, but it skips them if it knows the computer is disconnected from a network. So using a Windows computer on a very spotty WLAN is actually more painful than being disconnected due to all the timeouts and dropped packets. Office Outlook is another main offender. I have a Windows Firewall rule just for Outlook.exe when I know it’s going to lock-up a lot.
- Rebelgecko 6y agoIt's like no one at Apple has ever had sporadic internet access and they don't plan for it. The Apple Music app does the same thing, if you are connected to wifi but don't have internet access it takes 60 seconds for a song to start playing every time you click one. Because apparently that is a reasonable timeout for a UI action
- pfortuny 6y agoSo, yes: they do depend on the local (to the user) availability of that service. So they depend on that.
- liquidise 6y agoBoth my Hackintosh and MBAir are on Catalina and have been freezing repeatedly for the last hour. Definitely is effecting Catalina.
- Aaronstotle 6y agoSad state of affairs that apps are slow because it can't phone home to a server to verify it's okay.
- kzrdude 6y agoUnacceptable ecosystem, for both 3rd party app devs and users. What I guess we won't see - but need - is an apology from apple and a commitment to quickly fixing this bug.
- lovelyviking 6y agoIs it a bug really or design problem where they are trying to do something they should not do in the first place.
- heavyset_go 6y agoAgain, it turns out that Stallman[1] and others[2] were prescient. [1] https://www.gnu.org/philosophy/can-you-trust.en.html https://www.gnu.org/philosophy/can-you-trust.en.html [2] https://www.cl.cam.ac.uk/~rja14/tcpa-faq.html https://www.cl.cam.ac.uk/~rja14/tcpa-faq.html
- narrator 6y agoDon't forget the World Economic Forum, but they're happy about all this: https://www.weforum.org/agenda/2016/11/shopping-i-can-t-really-remember-what-that-is/ https://www.weforum.org/agenda/2016/11/shopping-i-can-t-real...
- deadbunny 6y agoHardly "happy about all this". From the end of the linked article: Author's note: Some people have read this blog as my utopia or dream of the future. It is not. It is a scenario showing where we could be heading - for better and for worse. I wrote this piece to start a discussion about some of the pros and cons of the current technological development. When we are dealing with the future, it is not enough to work with reports. We should start discussions in many new ways. This is the intention with this piece.
- MperorM 6y agoThe author, Ida Augen is without a doubt one of Denmark's most respectable and intelligent politicians. The article sohuld not be read as an endorsement of that future. It's her prediction of what the world is going to look like, for better or for worse.
- pgt 6y agoEvery year Stallman seems less crazy.
- sjwright 6y agoOnly in relation to the wider world which is getting progressively more crazy.
- deleted 6y ago[deleted]
- FriendlyNormie 6y ago>But seriously Apple, how can you allow this to happen? Picture a faggy fucking fruitcake like Tim Cook. Now imagine such a person actually being in charge of running Apple. There’s your answer.
- fsflover 6y agoSee also: https://news.ycombinator.com/item?id=24217116 https://news.ycombinator.com/item?id=24217116.
- _qulr 6y agoOCSP is Online Certificate Status Protocol. The connection to ocsp.apple.com is checking the status of the certificate used to code sign the launching app. I wrote an article about this a couple weeks ago because of the temporary revocation of HP's signing cert for printer drivers on the Mac: https://lapcatsoftware.com/articles/revocation.html https://lapcatsoftware.com/articles/revocation.html
- nomel 6y agoSo is checking for security certificates good or bad, now?
- sjwright 6y agoIf you've suffered inconvenience from having checks but not suffered inconvenience from no checks, then it's bad. If you've suffered inconvenience from no checks but not suffered inconvenience from having checks, then it's good.
- juliend2 6y agoSince this check is currently done _unencrypted_ (as lapcatsoftware said in his post), I'd say it's objectively bad.
- ehsankia 6y agoI'm sorry if this was answered elsewhere, but can someone explain me how this works when you don't have internet connection? I assume you can still launch apps without internet connection. So then, what stops bad actors to just either block connection to ocsp or straight up turn off your connection entirely when running malware?
- Spivak 6y agoThrough the very mechanism people are complaining about today. If your machine is offline then it switches to a fail-open system and uses its cache to verify the binary and if it's not in the cache then it skips the check and allows it. If your machine is online then it switches to a fail-closed system so that if you can't reach the servers because of something malicious then it blocks.
- deleted 6y ago[deleted]
- yalogin 6y agoIs it possible that we (the internet) don't understand this properly because by this logic, the apps shouldn't run when there is no internet connection. I don't believe that is the case.
- londons_explore 6y agoNo connection -> Fine Good connection -> Fine Spotty connection -> Problematic. Basically, they didn't include a timeout in their network code.
- themgt 6y agoIt's funny how many apps have this problem, you don't realize until you're on a spotty connection. Often disabling/cycling the wifi/network fixes an app freeze.
- ls65536 6y agoA "manual" test case I've seen before actually involved trying various things in the software while literally walking into an elevator and having all network connectivity suddenly cut out (no WiFi and no cell radio), in order to simulate what so many people do (or at least did anyway, pre-COVID) regularly throughout the day. I suppose this is also a bit different than just toggling connectivity on the device, since for some time the app and OS both still think the connection is in tact when it's already physically gone, so it may even be useful to help expose other issues this way. One of the things that's easy to take for granted these days when working on desktop or server software is a mostly stable network connection, but on mobile this goes completely out the window, or down the elevator shaft as the case may be. :)
- londons_explore 6y agoFor one bit of software I'm writing expected to be 'network robust', there is actually a test case that, in any network state, from any screen in the app, any button can be clicked, and the resulting screen must be the same as if there were network connectivity, within 100ms. The 'network states' are online, offline, all packets dropped, and various simulated network connections. This is achieved by preloading the next click everywhere.
- pedalpete 6y agoBut with the new M1 chips, it will freeze 2.6x faster than before!
- michaelvillar 6y agoUpdate to the original tweet: https://twitter.com/michaelvillar/status/1327004693361549312?s=20 https://twitter.com/michaelvillar/status/1327004693361549312... > A better fix to this is: > - Turn off Wifi (to be usable) > - Add "0.0.0.0 http://ocsp.apple.com http://ocsp.apple.com" to `/etc/hosts` > - Turn on Wifi > This is temporary, don't forget to remove it tomorrow.
- greensoap 6y agoIs there a reason I shouldn't leave this address in a blackhole?
- michaelvillar 6y agoIt depends if you care about this: https://en.m.wikipedia.org/wiki/Gatekeeper_(macOS) https://en.m.wikipedia.org/wiki/Gatekeeper_(macOS)
- po1nter 6y ago> This is temporary, don't forget to remove it tomorrow. or maybe don't depend on apple to allow you to run programs on your OWN computer. that hosts rule should stay in place...
- untog 6y agoI heard that's also the server that Apple uses for SSL cert validation, so you're going to want it again.
- goatinaboat 6y agoAdd "0.0.0.0 http://ocsp.apple.com http://ocsp.apple.com" to `/etc/hosts` Do you put URLs in /etc/hosts now? The mind boggles at the ways of Apple
- mekster 6y agoMore likely that's a typo.
- beamatronic 6y agoDefine “taking down”
- saagarjha 6y agoYou can't launch things.
- lkxijlewlf 6y agoMaking you want to slam your mac on the desk over and over and over and over ...
- Thomaschaaf 6y agoThe computer is completely unresponsive as the OS is blocking all apps from starting. The best part was that the "keyboard" was not found.. in my macbook.
- FireBeyond 6y agoHad that too. Apparently it checks keyboard firmware? Always-on VPN connections can cause that same issue too. Wake up, can't type. OS eventually prompts you to connect a BT keyboard as none is detected, then that goes away.
- elitepleb 6y agoYpu have to send a hash of every program you run. Unix workflows like to call hundreds of small programs. If Apple doesn't respond in time, your system halts.
- beervirus 6y ago.
- theonemind 6y agoI don't think everyone is experiencing it. My Mac became nearly completely unresponsive. Rebooting didn't help, it took forever to finish rebooting. ocsp.apple.com 127.0.0.1 in /private/etc/hosts got it moving again.
- beamatronic 6y agoSame, but I thought it was my backup software. I didn’t think my version of the OS was sending back the hashes.
- szhu 6y agoI remember this discussion from a few months ago where people foresaw that phoning home every time an program launches might be an issue: https://news.ycombinator.com/item?id=23281564 https://news.ycombinator.com/item?id=23281564
- molszanski 6y agoThe rabbit hole goes to https://sigpipe.macromates.com/2020/macos-catalina-slow-by-design/ https://sigpipe.macromates.com/2020/macos-catalina-slow-by-d...
- bognition 6y agohttps://mobile.twitter.com/hypatiadotca/status/1327000209445056513 https://mobile.twitter.com/hypatiadotca/status/1327000209445...
- Daniel_sk 6y agoIs it referring to this? https://mobile.twitter.com/lapcatsoftware/status/1326990296412991489 https://mobile.twitter.com/lapcatsoftware/status/13269902964...
- submeta 6y agoRelated: https://news.ycombinator.com/item?id=25074959 https://news.ycombinator.com/item?id=25074959
- Pensacola 6y agoI did experience a very strange slowdown earlier today, and other odd behavior - first, a massive slowdown and then on a reboot, the keyboard wasn't found. After some tinkering, it's all better now - though I don't know that the tinkering actually did anything.
- nateberkopec 6y agoExplanation of the keyboard behavior: https://news.ycombinator.com/item?id=24839101 https://news.ycombinator.com/item?id=24839101
- rubatuga 6y agoSame, keyboard and trackpad stopped working momentarily.
- Alex3917 6y ago> a massive slowdown and then on a reboot, the keyboard wasn't found. That seems to happen on MacBook Pros when the computer boots or wakes from sleep with the WiFi turned on, but the WiFi router can't connect to the Internet for whatever reason.
- spike021 6y ago
- djsumdog 6y agoI run Linux on my work machine, but everyone was talking about this problem in our chatroom for all of it. I got some co-worker karma.
- clem 6y agoIf my employer offered anything for Linux use than a 10lb Dell laptop I would consider it. I primarily choose MacBooks because I know what to expect in terms of hardware.
- mikestew 6y agoCaptain Pedantic checking in, should not the title simply be "Macs unable..."? I don't see anything MacBook Pro-specific.
- read_if_gay_ 6y agoYeah, I had this issue on a Hackintosh.
- projektfu 6y ago"If you're now experiencing hangs launching apps on the Mac, I figured out the problem using Little Snitch." Well, how interesting that Apple's software is going to be bypassing Little Snitch, making it harder to discover and fix this sort of issue.
- wa1987 6y ago> Well, how interesting that Apple's software is going to be bypassing Little Snitch, making it harder to discover and fix this sort of issue. Source?
- ciarannolan 6y agohttps://news.ycombinator.com/item?id=24838816 https://news.ycombinator.com/item?id=24838816
- TheKarateKid 6y agoApple themselves: https://support.apple.com/en-us/HT210999 https://support.apple.com/en-us/HT210999 They are disallowing custom kernel extensions and instead requiring apps like Little Snitch to use their system API. This means that Apple has total control of how these apps function and what they can see.
- protoman3000 6y agoWith the new Apple Silicon devices you can’t boot your own OSes anymore so the process of putting the desktop in a walled garden is complete. But where is the issue though? While you won’t be able to “own” your MacBook Air there are so many alternatives available such that crowding-out computers with open Bootloaders seems implausible. EDIT: Apparently there is a way to load your own os using bputil
- sjwright 6y ago> With the new Apple Silicon devices the you can’t boot your own OSes anymore I'm not sure this is confirmed. Though either way it's somewhat moot as Linux drivers for key Apple Silicon components (e.g. GPU, radios) are unlikely to be available any time soon.
- usaphp 6y agoTurning off wifi/ internet connection fixes the slow start for me
- olivierlacan 6y agoAdd ocsp.apple.com to your Pi-Hole blocklist if you have one and the issue goes away. You can also add this to your /etc/hosts file: 0.0.0.0 ocsp.apple.com
- kliwo 6y agoI do get the same problem with my macbook pro 2018. It's so irritating :(
- jrib 6y agoI wasn't even able to change my brightness — pretty amusing, but also not, at the same time
- deleted 6y ago[deleted]
- makz 6y agoThey use a server like in one server like in single point of failure?!
- ben509 6y agodig ocsp.apple.com reports: ;; ANSWER SECTION: ocsp.apple.com. 3593 IN CNAME ocsp-lb.apple.com.akadns.net. ocsp-lb.apple.com.akadns.net. 53 IN CNAME ocsp.g.aaplimg.com. ocsp.g.aaplimg.com. 8 IN A 17.253.21.201 ocsp.g.aaplimg.com. 8 IN A 17.253.119.201 "ocsp-lb.apple.com.akadns.net" is an entry indicating DNS based load balancing, done by Akamai. Even with lots of redundancy, there are still lots of ways all that can fall over. You can have a batch of servers that soft-fail: they're not responding to real queries but the load balancer thinks they're healthy.
- elitepleb 6y agoDon't you love it the ability to compile and run software on your hardware is controlled by a third party over the internet? I sure love the SAAS future we are heading forwards.
- MeinBlutIstBlau 6y agoI will be a full on linux junkie when that happens.
- paxys 6y agoBy then it will be too late
- cle 6y agoCan you elaborate?
- MeinBlutIstBlau 6y agoI highly doubt corporate interests could eliminate linux. It just will be very difficult to use though no doubt.
- burnthrow 6y agoI've gotten quite good at recognizing crosswalks, fire hydrants, chimneys and the like. Though I refuse to identify that one mailbox as a "parking meter" even if it means another trial to prove my humanity. Users of the platform get treated as spammers already.
- olyjohn 6y agoYou don't like that?! I love teaching self-driving cars how to drive!
- higerordermap 6y ago
- dnhz 6y agoI'm on Mojave and had problems.
- sirjonathan 6y agoI was on a Zoom call a few minutes ago and my machine was struggling with responsiveness, which I haven’t seen happen - and there’s been a lot of Zoom usage this year. I assumed it was Zoom related but this makes more sense.
- rubatuga 6y agoalso saw problems with zoom as well
- ChrisMarshallNY 6y agoHeck, it couldn’t even open Apple apps. In my case, Finder hung badly.
- mraison 6y agoAnother discussion about trustd from a few months ago: https://news.ycombinator.com/item?id=23273247 https://news.ycombinator.com/item?id=23273247
- dragandj 6y agoMost people trade their freedom for more convenience, but we don't think how we put all our eggs in one basket that we don't control at all. All Apple users are at the mercy of a megacorp. Better don't offend someone online, your Mac may be cancelled...
- Solvitieg 6y agoOne moment Apple is inserting U2 into your iTunes and the next...
- Aperocky 6y agoPathetic. Apps don't need to have internet connection until they actually do. I bought the new mac, but I'm planning to dwell in the terminal and browser. My exposure to Apple's closed garden is very limited but I dread the day when it's forced upon me. Then I would need to switch hardware despite Apple's form factor being my ideal type (light and battery life+++).
- Aperocky 6y agoPathetic. Apps don't need to have internet connection until they actually do. I bought the new mac, but I'm planning to dwell in the terminal and browser. My exposure to Apple's closed garden is very limited but I dread the day when it's forced upon me. Then I would need to switch hardware despite Apple's form factor being my ideal type (light and battery life+++).
- habitue 6y agoI feel like even Richard Stallman would have had a hard time imagining non-free operating systems would result in this. Use linux folks! It doesn't communicate with a third party when a process starts up!
- Aperocky 6y agoIt's just sad that we don't have the corresponding form factor in a similar laptop. The biggest draw of mac: 1. slim, light 2. long battery life. 3. track pad. That's all I want, but nobody else offers it on the same spec, the difference is even bigger with M1.
- Symbiote 6y agoIt is strange how many people will sacrifice so much for free speech and the right to bear arms (like tolerating school shootings and foreign interference in elections), but offer them the "freedom OS" and they'll pick the slightly better trackpad. Does no one here have principles?
- Aperocky 6y agoI didn't say I was that kind of people. Your description of them was also not exactly flattering.
- Symbiote 6y agoDefending fundamental (in the USA, constitutional) rights is a generalization of people on HN. I thought your reply to a "Stallman was right" comment with "but trackpad!" had the most contrast between principles and minor convenience.
- Aperocky 6y agoHaha my principles are few but those I do hold up. For things like computers though, I don't tend to hold a big grudge - I do whatever is the most comfortable and productive. I have the opinion that if someone have too many principles, either they'll suffer an unhappy life or they will end up violating many of it.
- jonplackett 6y agoThis just seems wrong on multiple levels. Phoning home on every app launch seems insane to begin with. But if you're gonna go there, at least be prepared for the inevitable.
- _iyig 6y agoThis is the reason I needed to switch to a Linux laptop. I cannot be beholden to Apple’s - or anyone’s - servers when it comes to running applications on my own machine. Any recommendations? I’ve heard good things about System76.
- valuearb 6y agoLinux performs similar checks.
- burnthrow 6y agoThis is _FUD_. it emphatically does not perform similar checks by phoning home to a third party. The closes you will find are SELinux/AppArmor policies, which do not involve the network at all.
- sojournerc 6y agoYou've stated this several times in this thread. Do you have a source for your claim?
- Dahoon 6y agoStop spamming FUD.
- mhh__ 6y agoShow us the kernel patch then
- the_duke 6y agoLinux runs perfectly fine on most laptops nowadays - pick whatever you like. (it's still prudent to Google for compatibility before the purchase though, since sometimes peripherals (like the webcam) on new models can be problematic)
- eulers_secret 6y agoSystem 76 makes a nice looking thin/light 14" laptop (Lemur pro). Dell's XPS 13 line has Linux support (the Dev Edition comes with Ubuntu), I bought one of these and it's great. Only big problem was thermald/RAPL would keep the SOC at 15W after a very short 'boost' - updating to master fixed this problem... but Linux still requires 'tweaking'. Another example: sleep on the XPS is not S3, but S2Idle - so it uses extra power when sleeping (A compromise so it wakes up faster). This can be fixed with some tweaking, if desired. I've also heard good things about Lenovo laptops running Linux. I'd check the archwiki (even if you don't want to run arch) for any laptop you're considering. There's good advice in the articles. If I had to buy again, I'd look closer at what S76 offers. I really liked my old Chromebook Pixel 1 because of its open firmware (after I re-flashed) and excellent Linux support. I wish I had looked closer at S76, honestly.
- post_break 6y agoAlmost reinstalled OSX. I thought my SSD was failing.
- burnthrow 6y agoUnacceptable showstopper. Professionals can't afford this nonsense. If I'd not already left the platform, the decision would be forced today.
- stefan_ 6y agoCan't wait until they port the Facebook SDK and we can have these "stuff doesn't work because a computer 3000 kms away is wrong" moments on the desktop.
- tpush 6y agoAlways wondered why it checks for cert revocation when starting an app instead of periodically checking in the background. Hm, that might require some sort of central cert database or something? Just spitballing here.
- skuthus 6y agoWow this is a huge cluster - threw a complete wrench in my work for almost an hour. Is this what we should be expecting from Apple going forward?
- Aperocky 6y agoApple want to be the closed garden, this will eventually happen. tbh, I'm a huge fan of macs but only really because I use it as a client/screen.
- deleted 6y ago[deleted]
- Havoc 6y agoNot just Apple. The entire world is heading in this direction
- fsflover 6y agoThis is not true: https://news.ycombinator.com/item?id=24881988 https://news.ycombinator.com/item?id=24881988.
- paxys 6y agoThis is the kind of stuff that makes me laugh at their (very successful) "Apple respects privacy" PR campaigns.
- valuearb 6y agoHow is this not congruent with strong privacy protections? Your iPhone knows everywhere you’ve been, but when it sends that info to Apple it doesn’t include any personally identifiable information.
- Symbiote 6y agoStrong privacy would be not sending that information to Apple at all. (Do iPhones really send the current location to Apple?)
- arvinsim 6y agoI agree. I thought iPhones do theirs on-device.
- whywhywhywhy 6y agoiPhone doesn’t need to do this as long as the system integrity is there because you can only install signed apps from them anyway so they already know what you’re running.
- valuearb 6y agoMaps does for sure, it’s how they build traffic measures. They need to know how many (relatively) are using specific routes, but have no need to know who. Another case is WiFi mapping. Your phone helps build a database of WiFi network locations to improve your location accuracy, again they don’t need your personal identity to build that.
- deleted 6y ago[deleted]
- ianmobbs 6y agoWe had 70 engineers at in a Slack channel work trying to figure out the issue before someone found a Twitter thread about it
- tonyztan 6y agohttps://en.wikipedia.org/wiki/Online_Certificate_Status_Protocol https://en.wikipedia.org/wiki/Online_Certificate_Status_Prot...
- charwalker 6y agoI though this was known as early as May? https://medium.com/@acecilia/apple-is-sending-a-request-to-their-servers-for-every-piece-of-software-you-run-on-your-mac-b0bb509eee65 https://medium.com/@acecilia/apple-is-sending-a-request-to-t...
- jb775 6y agoYou need to be playing the iPhone U2 album while opening each application for it to work
- MoreenDichele 6y agoCan confirm this worked for me.
- marcinzm 6y agoThis is the future Apple wants I guess, you don't really own your hardware, you simply have a limited license to use it under their very strict terms. It's just a matter of time before Macs become just like iOS.
- jason0597 6y agoI've been trying to sound the alarm over "Secure Boot" and the absolute torture it will be to run other operating systems on these ARM Macbooks but very few people seem to care. I guess as long as the display is shiny and the trackpad is big then we're all good.
- qayxc 6y agoIt might get worse: now that they're switching to their own SoCs, they might even block APIs and allow access only to certified parties. Basically Final Cut Pro and Logic Pro might forever be faster than any 3rd party software package by having access to IP blocks that aren't exposed to other developers complete with signature check to prevent reverse-engineered use...
- kinghajj 6y agoIf they really tried that, wouldn't the DoJ bring an anti-trust case against them? That's exactly what Microsoft was doing in the 90s, using undocumented internal APIs for their own software that let it run faster than competitors'.
- qayxc 6y agoWell, unlike Microsoft in the 90s, Apple doesn't hold a monopoly in the PC space. The current Oracle API-debacle also doesn't give me much hope that this would hold up in court. It's their hardware and by now they could even argue that Macs aren't general computing devices anymore. After all, what's the difference between the M1 and AMDs SoCs that power XBox and Playstation? (I should be careful - I can always hear Apple's lawyers taking notes;)
- geophile 6y agotl;dr: Apple no longer builds computers. After 11 years of MBPs as my main computer, I left because of crappy hardware (keyboards, missing Esc and Fn keys). I'm now very happy on a System76 laptop running PopOS. With each new release of the OS, getting more and more locked down, I am happier that I moved on when I did. The long term trend with Apple is for their computers to get more and more closed. First hardware, and now software. I get that for a phone, but it is completely antithetical to what a COMPUTER is supposed to be. They really should stop calling these things computers. Huh. After typing the above, I decided to check. THEY DO NOT call Macs "computers". I searched the pages for MBPs, iMacs, and Mac Pros. They use the word "computer" in connection with trade-ins, (for the thing you are trading in), and they use the phrase "computer system" in fine print, and never to refer to their products directly. APPLE, IN THEIR OWN WORDS, NO LONGER BUILDS COMPUTERS. That explains so much.
- jason0597 6y agoI hope people finally realise what a terrible company Apple is and stop buying their products once and for all. I cannot understand why such atrocious decisions are magically forgotten when they release a new iPhone or a new Macbook. Every time there is a new Apple launch (service or product), it is almost always projected onto the front page of HN with hundreds if not thousands of upvotes.
- zitterbewegung 6y agoWas this already fixed? I just opened up Aquamacs.
- atonse 6y agoWe were in the final steps of a really major demo and my laptop shit a brick, I kid you not, I ate about 50 pistachios while rebooting and killing mds_stores, thinking Spotlight was losing its mind.
- nardux 6y agoI am really curious about how people realized this was the issue. Any ideas about the thought process?
- jlokier 6y agoPossibilities: - Turned off wifi and everything started working again. - While watching network stats, noticed a little burst of network traffic on each attempt to launch an application.
- riazrizvi 6y agoI guess the future is Linux.
- smcleod 6y agoThe way trustd works has annoyed me since Catalina was released, I do hope that it's improved in Big Sur. I get what they were trying to do with it to improve security/privacy, but the execution fell flat (as we've now witnessed).
- 1_2__4 6y agoThis is a nightmare in so many respects. I can’t believe my ability to run software on my own machine requires successful network calls. I spent two hours today thinking my hardware was failing catastrophically.
- daptaq 6y agoA perfect example of how with non-free software, the user is controlled by the software.
- elmo2you 6y agoSincerely and without any intention to troll or be sarcastic: I'm puzzled that people are willing buy a computer/OS where (apparently) software can/will fail to launch if some central company server goes down. Maybe I'm just getting this wrong, because I can honestly not quite wrap my head around this. This is such a big no-go, from a systems design point of view. Even beyond unintentional glitches at Apple, just imagine what this could mean when traffic to this infra is disrupted intentionally (e.g. to any "unfavorable" country). That sounds like a really serious cyber attack vector to me. Equally dangerous if infra inside the USA gets compromised, if that is going to make Apple computers effectively inoperable. Not sure how Apple will shield itself from legal liability in such an event, if things are intentionally designed this way. I seriously doubt that a cleverly crafted TOS/EULA will do it, for the damage might easily go way beyond to just users in this case. Again, maybe (and in fact: hopefully) I'm just getting this all wrong. If not, I might know a country or two where this could even warrant a full ban on the sale of Apple computers, if there is no local/national instance of this (apparently crucial) infrastructure operating in that country itself, merely on the argument of national security (and in this case a very valid one, for a change). All in all, this appears to be a design fuck-up of monumental proportions. One that might very well deserve to have serious legal ramifications for Apple.
- thewindowmovie4 6y agoI think it is because a lot of people still believe and repeat old trope which are demonstrably false these days. Despite having the worst keyboard, buying third party apps to have features which most of the other OS in the market provide as standard, more lock down of their OS every year, Apple fans continue to buy them. Appke's powerful marketing, which is full of weasel words, keeps them in their own bubble.
- wait_a_minute 6y agoWhich third party apps do you mean? And the worst keyboard? I understand it being subjective as a taste, but the worst? Idk...
- frompdx 6y ago
- api 6y agoThis constant OCSP banging is absurd.
- deleted 6y ago[deleted]
- deleted 6y ago[deleted]
- fortran77 6y agoIt's outrageous that Apple designed their system this way. (And it's curious why they seem to have so many fans on Hacker News that will defend this type of design.) Your Mac hardware is a brick if Apple's servers aren't running!
- UhDev 6y agoSounds about right. What would you expect from a walled garden ecosystem?
- NicoJuicy 6y agoSo... An easy fix would be to disconnect internet and then your MacBook "just works".
- saint-loup 6y agoIt reminds me of this comment and its parent link from one month ago, wich already were heavily upvoted: Apple seems to do all kinds of weird networking _stuff_ [...] https://news.ycombinator.com/item?id=24838816 https://news.ycombinator.com/item?id=24838816
- gspr 6y agoWake up, people. Free software is the last line of defense we have left before technological tools are completely taken away from us, and we all have to live our digital lives at the behest of Giant Megacorps.
- tpmx 6y agoThe arrogance required to actually implement this. It's staggering.
- at_a_remove 6y agoRemember how everyone was so insistent on certificates everywhere? We must have them, no matter what you think, no matter how trivial the transmission of information. As it turns out, there are some downsides.
- yes_man 6y agoThe tragedy here is that likely the retrospective on this at Apple internally will not be "why do we even need our customers MacBooks to send all this data to us", but "how can we keep on doing this without something similar happening again"
- jariel 6y agoThis issue + the inevitable platform switching costs may wipe out the momentum gained from the new offer. Esp. rational corporate buyers are not going to want some 'cool new hardware' if they can't do basic things. Makes you think about MS's existential 'always backwards compatible' philosophy.
- drilldrive 6y agoThis demonstrates the limits of Apple's campaign towards vertical integration of their services. Once they make a simple mistake on their part, you are at the mercy of Apple to make it right again.
- bitL 6y agoI am wondering if this wasn't done by some Apple engineer on purpose to warn us all that each app is now phoning home upon start?
- Dahoon 6y agoIt wasn't a secret (not that it makes it any better): https://medium.com/@acecilia/apple-is-sending-a-request-to-their-servers-for-every-piece-of-software-you-run-on-your-mac-b0bb509eee65 https://medium.com/@acecilia/apple-is-sending-a-request-to-t...
- protomyth 6y agoThey need to find another way, because this is just pure crud. So today, everyone gets to experience what a person with a poor internet connection deals with when using a Macintosh.
- aquova 6y agoAsking for a friend, what's the experience installing Linux onto a 2018 MacBook? Last I heard it was nothing short of torture, but I'm hoping the situation has gotten better as time goes by.
- trey-jones 6y agoAppalling to be sure, but you can't even log into a Chromebook if Google auth goes down, unless I'm mistaken.
- kyzn 6y agoYou can login to a chromebook (unless it's a first time setup) even if it's offline. Login stuff seems to be handled locally. Eg: if you update your Google password, you need to log in to your chromebook with your old password one more time and re-sync.
- bla3 6y agoAre you sure? I thought they cached login stuff locally so you can sign in while you're offline. Not sure though.
- trey-jones 6y agoI admit that I don't have a Chromebook in front of me to test and that I'm not sure. This comment will likely be stricken from the record.
- em500 6y agoI do have a Chromebook in front of me and I can certainly login without any network connection. Contrary to popular belief, ChromeOS devs do know that people might want to use Chromebooks on airplane or train trips without network. Google Docs / Sheets / Slides work on a cached copy and sync when online again.
- gazsp 6y agoWow. Guess it's time to finally move to Linux.
- __ryan__ 6y agoI thought I was going crazy earlier because of this. Strange though, flushing my network cache completely fixed my issue.
- outworlder 6y agoWhy the heck do they have to reach to central servers? Anti-virus software have been working with "definition files" ever since the dial up days. Check locally. Update when you can. This is a completely brain dead implementation.
- ben509 6y agoYou could absolutely use a simple certificate revocation list instead of OCSP. I don't know how large that would be, though. It could run into problems if there was a heartbleed like issue that required revoking many certs. All the extra connections are enough of an issue that there's OCSP stapling, where a web server attaches a copy of the OCSP check to the response. Seems like it'd be possible to inject a file into Cool.app/Contents/ocsp.staple in a downloaded .dmg. That could be considered valid for a few days so that, for the common case of "download app and try it out", there's no need to phone home.
- foofoo4u 6y agoAll of my personal Macs became unusable about an hour ago. Fan would kick up, CPU gets loaded, and every operation comes to a crawl. Thankfully it seems a PRAM and SMC reset solved the issue. Wondering if what's going on here is related. It would be quite the coincidence if not.
- alwillis 6y agoI've been on my Mac all day and haven't experienced any problems.
- frompdx 6y agoI wonder if this explains why I was unable to print something for several minutes around the time this tweet was published? The printer manager refused to open each time I tried to print. Frankly, that's unacceptable. I have preferred Apple/MacOS since 2007. However, my 2019 MBA suffered the infamous shaky keypress issue, randomly inserting an extra space when I typed. After 6 trips to the Apple store to fix under warranty I told myself it is my last Apple product. I wanted the MBA for the portable form factor. Now I work from home and portability is no longer a consideration. I will mostly likely ditch this device in favor of a linux system. What a disappointment.
- friendlybus 6y agoBack to terminal clients and mainframe in the sky? Apples on the great tree of knowledge.
- kmonsen 6y agoDidn't this happen once before?
- Shorel 6y agoThis only reinforces my desire to run Linux in their new ARM processors.
- foofoo4u 6y agoSidebar topic, but something that is always in the back of my head. Cars are becoming evermore connected to the web. If something as simple as this can brick my Mac, then what will it be like in a vehicle? Will all cars simultaneously go haywire at the same time around the world? This of course assumes software or hardware safety overrides are not in place to overcome such a situation.
- canjobear 6y agoInternet connectivity should be seen as an undesirable feature, a risk to be minimized.
- meekrohprocess 6y agoMost cars use separate buses for the critical control systems and the infotainment/GPS/etc. They learned that lesson after the infamous demonstration of hacking a Jeep on the highway several years ago. It's conceivable that someone could push bad updates to Tesla autopilot software, or briefly stop peoples' radios from working, but quiet OTA systems like that are the exception rather than the rule.
- pgt 6y agoStuff like this will push me off Apple no matter what the performance of the M1 chip is. Privacy trumps performance.
- makz 6y agoBut, is this literally one server?
- cblconfederate 6y agoMacbook as a service
- somehnguy 6y agoSo this is what was happening to my MBP a couple hours ago? Right before a meeting my Mac started glitching out - extremely slow to do anything and spinning beach ball. Launching any app would take literal minutes. Spent the next hour rebooting & diagnosing. Then it suddenly went back to normal. That's great.
- aptgetrekt 6y agoThere goes any temptation I had to buy an M1 Mac. Thanks for the warning Apple!
- nomel 6y agoIt's completely unrelated to M1 and also affecting Mojave and Catalina, apparently. It's a security signature check service problem. Some might argue that it should be easy to disable security signature checks, system wide (which is what the provided instruction achieve). Many more would probably argue that disabling these checks would be bad for security, especially for the average user. I'm curious what security researchers think of this. Further evidence that security is a doomed endeavor, since it's necessarily at odds with convenience?
- aptgetrekt 6y agoI know it's unrelated. I have a Mac and was unable to do any work for around an hour, had no idea why. Windows has smart screen, but if the service is unreachable you get a popup. This is just completely unacceptable, if it's possible that a server issue could cause all apps to fail locally, there should at least be a popup explaining that's why nothing is working. I'm fed up with far more than just this. I'm saying any temptation I had for an M1 Mac is now gone.
- yingw787 6y ago2021: The year of the Linux desktop? But seriously, I have installed Ubuntu 20.04.1 LTS on my personal Lenovo ThinkPad P1 Gen 2, and work Dell Precision 5550, and it works fine in both cases. Stick with it for a month and macOS becomes old news. Also I think OEMs are wising up to "Linux = free" and charging for Windows on their laptops again, so you can also save some money on OS licensing going forwards.
- chmaynard 6y agoI don't see MacBook Pro mentioned in the @lapcatsoftware tweet. Seems like this screw-up would affect all Macs, no?
- chrysoprace 6y agoThis is bad. As bad as DRM. A simple test for whether a product will stand the test of time is whether it'll cease to work once their creator's servers go down. Imagine Apple goes bankrupt tomorrow. Is your overpriced device suddenly useless?
- protoman3000 6y agoThis widespread outrage is proof that only few knew of this. Why is it that such a single point of failure and such a vector for unexpected data disclosure goes unnoticed for so long?
- hikerclimb 6y agoGood.
- pgt 6y agoA compelling way to enact change at large corporates is to vocally communicate when and why you are forced back into a buying position as a customer. Apple VPs who are listening, especially Craig Federighi - here is an early warning for you. The HN crowd may seem fringe, but they are living in the future. I de-Googled my entire life over similar transgressions by Google and several of my friends are gradually going through the same process, albeit more slowly. And even though I just bought an MBP16, Apple monitoring every binary I run makes me want to sell it immediately and never buy another iPhone, Watch or Macbook. No one is going to catch Apple on performance and form factor for a long time, but I'm willing to invest in a long-term ecosystem that won't allow things like this...as long as I don't need to debug audio drivers. I am done with that phase of my life. So if I had to choose an alternate path, what would such a path look like that could eventually approach the build quality of an Apple Macbook Pro? That product doesn't have to exist yet, it just has to be on the path. (I looked at Alienware's M2 and M3, but it cost about the same as an MBP16 but with more blue LEDs.)
- russelg 6y agoThe Dell XPS range is probably the closest available currently.
- ls65536 6y agoI had the pleasure of installing Ubuntu on a modern Dell XPS recently. I was happy to discover that everything seems to work flawlessly upon install without any additional fiddling: WiFi, trackpad, touchscreen, display scaling, and really everything else I've tried so far worked great. It's an absolute joy! There was a time I remember when various things with Linux installations were often quirky or troublesome to get working well with certain laptop hardware, but I'm convinced now that this situation has improved tremendously since then...at least from my recent experience and hearing other good things about the Dell XPS and various ThinkPad models, and of course System76 (although I haven't had a chance to try one of those myself yet).
- dlgeek 6y ago
- LinuxBender 6y agoA temporary work around that helped me was to use sudo route add -net 17.253.17.207 255.255.255.255 -blackhole; sudo route add -net 17.253.17.202 255.255.255.255 -blackhole; based on dig +short ocsp.apple.com |grep -E ^[1-9] 17.253.17.207 17.253.17.202 That shortens the delay. Others here found adding ocsp.apple.com to /etc/hosts using a private address also helps. Whichever is easiest for you. To remove: sudo route delete -net 17.253.17.207 255.255.255.255; sudo route delete -net 17.253.17.202 255.255.255.255; or reboot.
- technicolorwhat 6y agoThis is outrageous. Can we sue apple for damages? What if you were about to do something literally life critical? I pretty quickly debugged the issue but man and added a host line but this is absolutely horrible. I have no words for it.
- nbzso 6y agoI don't care for downvotes:) Welcome to Jailbreak your Mac. Third time: I hate to repeat my self but this articles keep piling up. Vote with your money first, then if you have a way search legislative measures. They will never stop to search a way to profit more. This is just a beginning. Fully closed macs are coming. I don't care anymore for iPhones, my professional problem is with apple desktops and laptops. If we follow Apple logic in near future I will have to Jailbreak my personal computer that costs arm and a leg and cannot do 3rd party repairs on it. I am filling now very good about the decision to invest in multi platform software and avoid mac only apps. On a phone side someone suggested Fairphone (https://www.fairphone.com/en/ https://www.fairphone.com/en/) as an alternative. I can see a lot a value in this proposition, after rooting and removing Google crap/spyware.
- ExcavateGrandMa 6y agoApple's plan to make you very very dependent, Enjoy
- nbzso 6y agoLittle Snitch is working under Catalina, I have blocked apple telemetry all the way. My graphic workflow is on multi platform apps, people are using Figma instead of Sketch, coding for web is beautiful under Linux, Resolve and Blender are working beautifully (I don't use prores). The only hassle will be Windows (under WM) with no internet and Logic (searching to switch to new DAW but not with subscription based licensing like ProTools). Apple is actively working on making developers "go away", the days of "Great Mac for developers" are gone. Bottomline: Users of Apple platform are exited, they will have powerful machines with M-soc, closed and secured.:)
- ChadMoran 6y agoI'm also seeing ocsp-lb.apple.com.akadns.net pop up in my PiHole.
- alwillis 6y agoJust downloaded Pages, Keynote, Numbers and Garage Band from the Mac App Store. All updated for M1 and Big Sur. So maybe things are improving?
- boltefnovor 6y agoOut come all the people who think this sort of thing is planned by Apple.
- blacklight 6y agoThis isn't anything surprising. A handful of companies out there have been working hard for the past few years to kill the personal computer and turn it back into a dumb terminal that connects to a mainframe owned by them, and they've managed to do it. Nomenclature also matters - they've stopped calling them "computers", now they're just "devices". Enjoy your $1500 dumb terminal. If you're still buying Apple products, then you're simply unforgivable.
- Aperocky 6y agotbh I do see these macs as dumb terminals, what else are they? These sweet dumb terminals can last 15 hours on a charge? nice, I'll just update the /etc/hosts when I get it.
- CathedralBorrow 6y ago"If you're still buying Apple products, then you're simply unforgivable." What does this even mean? Are you unable to forgive me for buying an Apple product? Why exactly should that matter to me?
- yamrzou 6y agoLong live Linux!
- ksajadi 6y agoWith things like this, docker not running on apple silicon (because it doesn’t support virtualisation) etc there surly should be a market for developer laptops running Linux but with an OS that gets out of the way most of the time. Who’s selling those?
- noisy_boy 6y agoSystem76 / Dell XPS developer edition
- tonymet 6y agoOSs have been doing something similar for a while. Even since the 90s I remember Windows NT checking SSL Cert revocation lists every time you right-clicked. When you disable that option, right click goes from 400ms to 5ms response time. Synchronous remote calls should not exist in the OS like this
- interestica 6y agoOh, so this is that dark future.
- ZacharyPitts 6y agoThis may sound hyperbolic. Oh well. I was deeply considering one of the new M1 MacBooks last night, but held off on completing the order. Now today, I can't use my computer for nearly an hour. And my daughter as well during school time... all because a remote server can't respond. I just do not find that acceptable for a computer I own to simply stop working because of remote non-response. I am now deeply considering not getting a new m1 machine.
- wait_a_minute 6y agoI'm in a similar spot. Now I'm hesitant to purchase any Apple products.
- brailsafe 6y agooof. I used to do this kind of thing to get around Adobe's DRM stuff. Not a good look Apple.
- tsycho 6y ago"But won't you think of the children." -- Apple apologists
- torstenvl 6y agohttps://mobile.twitter.com/itsluncht1me/status/1326996963649175553 https://mobile.twitter.com/itsluncht1me/status/1326996963649... Huh. Interesting. https://news.ycombinator.com/item?id=23278103 https://news.ycombinator.com/item?id=23278103
- ericd 6y agoFor anyone who wants to disable gatekeeper, this appears to do the trick, at least on mojave: sudo spctl --master-disable
- Yabood 6y agoIts even worse, after Apple's service recovered I was left with what seemed to be a corrupted installer/updater that kept throwing "An error occurred while installing the selected updates" when I clicked on the upgrade now. I had to boot in recovery mode, run "csrutil disable" so I can delete the update directory from Library/Updates.
- dang 6y agoAll: there are multiple pages of comments; if you're curious to read them, click More at the bottom of the page, or like this: https://news.ycombinator.com/item?id=25074959&p=2 https://news.ycombinator.com/item?id=25074959&p=2 https://news.ycombinator.com/item?id=25074959&p=3 https://news.ycombinator.com/item?id=25074959&p=3 https://news.ycombinator.com/item?id=25074959&p=4 https://news.ycombinator.com/item?id=25074959&p=4
- liendolucas 6y agoWe are slowly loosing ownership (and in many cases we've already lost) of the tech that we think we own (mobile devices, laptops, gadgets, etc). And the thing is that is hard to make people aware about this issue, especially elder people. I have just helped an old lady with her own new laptop and I was completely shocked the number of steps that we had to go through to get her Windows 10 working for her brand new Acer laptop (asked for PIN number, fingerprint, Microsoft account and don't know what else mumbo jumbo just to get it running). Proprietary software definitely is going in the wrong direction and people generally are ok with it. 15 or 20 years ago you got a CD and that was more than enough to get things running. Sometimes I think how lucky I'm to be able to put a FreeBSD/OpenBSD/Linux in my computers and do whatever the f* I want with it and get rid of all the nonsense and bs that multi-billion companies are putting in front of us to consume.
- kingaillas 6y agoI always wonder about the after action in a situation like this. Obviously, it makes Apple look bad but it isn't like they are going to flog the responsible team (and I mean responsible in the sense that various teams are in charge of the components of the overall system: the os service that issues the request, the website responding to the request, etc.) I'm sure some devops folks were getting screamed at while running around with their hair on fire, but what's the cause and response. Hopefully they'll issue a public after action report that isn't jammed with marketing talk like "we were unfortunately caught by surprise and due to the unprecedented massive interest in the latest macOS with its great features for users and developers, blah blah".
- rbernardes 6y agohttp://swcdn.apple.com/content/downloads/50/49/001-79699-A_93OMDU5KFG/dkjnjkq9eax1n2wpf8rik5agns2z43ikqu/InstallAssistant.pkg http://swcdn.apple.com/content/downloads/50/49/001-79699-A_9...
- nicetryguy 6y ago11 Gigs?!
- jonnycomputer 6y agoAbout 4 hours ago my Mac crawled to a stop. I rebooted, but it remained incredibly sluggish, uncharacteristically so. This definitely was not normal operation (and I use this many hours daily). Then about 1/2 hour later, it began to operate normally again. But I'm running Mojave. So ... huh.
- pinacarlos90 6y agoI experienced this earlier today. I ended up creating a reddit post (https://www.reddit.com/r/macbook/comments/jt3pqx/third_party_apps_slow_launch_when_wifi_turned_on/ https://www.reddit.com/r/macbook/comments/jt3pqx/third_party...) I also noticed that the symptoms go way if you manually disable WIFI. Who architected this solution? Imagine an OS that needs to ping a server every time you launch an application and if the server down it renders your system useless. The dev-community needs to push back on this issue and perhaps apple will re-think this solution
- paultopia 6y agoUgh, I don't want to upgrade to Big Sur now. How much more dictator garbage is hidden in the new OS, I wonder?
- 3131s 6y agoYou all seriously should have spent the last 20 years helping us make Linux better. What a waste.
- __MatrixMan__ 6y agoBut since that's not in the cards, how about starting today? Once you get over the lack of polish, you'll find that it was hiding seams that are useful to know about.
- tonyedgecombe 6y agoSorry, I can't and won't work for free.
- __MatrixMan__ 6y agoIt doesn't have to be any more work than you're already doing. Just stop putting cycles into working around bad decisions by people who are trying to control you and put those very same cycles into working around bad decisions by people who are trying to help you. A couple years later, snippets of code worth sharing will be lying around. Which you can share, or not.
- enobrev 6y agoTaking "Dog Fooding" to a whole new level.
- pmarreck 6y agoI knew this would be the nail in the macOS coffin as the "iOSening" of macOS is now complete
- nautilus12 6y agoAlright Apple crossed waaaay over the line here. I think i'm done.
- innagadadavida 6y agoIt took almost 6 hrs to fully resolve: macOS Software Update - Resolved Issue Today, 10:00 AM - 5:15 PM Some users were affected Users may not have been able to download macOS Software Updates on Mac computers.
- xenadu02 6y agoThis is a bug. The intent is that if the malware check takes too long the system fails "open" and allows the launch. That obviously didn't work correctly in this case.
- deleted 6y ago[deleted]
- mamborambo 6y agoThis reminds me of the recent news about Lets Encrypt expiring one of their root certificate and warning that old Android systems may not be able to validate SSL if they were not updated. We have increasing moved our world into an interconnected web of trusts and taken out failsafes and overrides, so we are very much entering an age of brittle systems --- one in which the vulnerability of one key subsystem (Google, Facebook, Apple, a key SSL validation cert etc) can escalate towards disabling the entire world, when you cannot get your TV to turn on, car to start, power grid to switch on. What are we doing to prevent that?
- Ansil849 6y agoWhy is this not getting any media attention? Why is there no formal statement from Apple? Why is this behavior justifiable.
- GiorgioG 6y agoThis is the iOSification of macOS. They can keep all their fancy new Apple Silicon laptops. Fuck Apple.
- deleted 6y ago[deleted]
- stryker7001 6y agoI just excitedly told my wife about this issue, because its a big deal, I didnt know about it, and she was complaining her macbook pro was very slow today. Her response ‘oh wow, so is it fixed now?’ Thats the difference between HN and the real world.
- a_c 6y agoI wonder if there are startup attempting to challenge the Mac dominance? Good trackpad, good battery, good screen, with (some) Linux supported out of the box,and no wonky configuration seems to be the problem to solve
- brbrodude 6y agoSeems youve been locked in. I never bought apple in my life, snap decision when I saw I had to pay to try developing for their system 10 years ago(developers license), I remain pretty safistied with this decision.
- throw_m239339 6y agoMac dominates nothing, the great majority of PC out there are running Windows. If you are talking about hardware then DELL, Lenovo, Asus and co all have excellent high end computers. Becoming slave to Apple is 100% a choice.
- 1023bytes 6y agoIt's a software problem, not a hardware problem.
- fsflover 6y agohttps://puri.sm/products/ https://puri.sm/products/
- adib 6y agoPSA to developers: Notarization alone won't be sufficient. You'll need to staple that notarization ticket as well so that your users' Macs doesn't need to go online to validate whether your app has been tampered (among other things). How? Have a look here: https://cutecoder.org/programming/notarize-disk-image-developer-id-distribution/ https://cutecoder.org/programming/notarize-disk-image-develo...
- yarcob 6y agoThis mechanism is also what recently broke all HP printer drivers on macOS. HP accidentally revoked their certificate, and since macOS automatically checks it before loading code printing and scanning with my HP printer no longer works. My mom called me with the same issue. She didn't do anything, but all of the sudden her printer stopped working. There is no way I know of to override the accidental revocation. Installing updates from Apple and HP didn't help. Online certificate revocation is a really bad idea for desktop software.
- ece 6y agoMaybe apps should be signed and issued certs by neutral authorities like SSL certs are issued (like Let's Encrypt).. Maybe also issue bulk cert updates with OS updates or virus scan updates like browser updates bring SSL root cert updates..
- supernova87a 6y agoIs there any official or even unofficial Apple information that can confirm all the explanations here correct and this was intended behavior? Or explain their position on it?
- fastball 6y agoThis seems like a case of Apple engineers only testing these features on Apple networks and such, where obviously the pings are very fast and unlikely to fail.
- unnouinceput 6y agoSo all Russia/China would need to drive Apple into bankruptcy is to DDoS Apple's servers and brick their laptops worldwide? This must be hilarious. Imagine the meeting at Apple HQ when they took that decision, probably that KGB agent must be very proud to make Apple shoot themselves :)
- wishysgb 6y agoDon't forget to go ahead and buy more Macs in the future. That will teach them
- dschuetz 6y agoMore Macs means even more "Trust and Security" traffic for Apple to handle. So, yeah, that'll teach them!
- ashtonian 6y agoI hate when my keyboard hangs and because I'm connected but dns isn't working. Like I need internet for my keyboard. So so frustrating has me seriously considering bailing to some nix flavor if this shit continues.
- mehrdada 6y agosudo spctl --master-disable Should disable gatekeeper. Have not verified with little snitch though.
- apatheticonion 6y agoAfter AMD released their Zen 2 lineup and the prospect of considerably faster compile times became attainable, I re-evaluated my relationship with MacOS. I bought a new AMD PC and initially hackntoshed it. This actually worked out great but after some time I decided to jump over and see if I could live with WSL under Windows. Windows is not as nice as MacOS, but WSL1 (tried WSL2 for a few months but still prefer WSL1) has allowed me take advantage of affordable high performance hardware and maintain support for the software I use daily. I may buy a low powered MacBook laptop in future (because there are no Windows laptops with a trackpad that compares) but I don't think I will ever use it as a primary desktop environment again.
- envolt 6y agoInitially I noticed this behaviour on my work laptop (where I've joined recently); where I was able to get the app working as soon as I used to switch my location to Home (non-VPN/Proxy). I though it has something to do with work configuration. For past few days I'm also experiencing the similar behaviour on my personal laptop.
- cute_boi 6y agoApple never gonna change right? Seems like we will see iphone style thing in future where we only can download app from their store. Switching to linux right now :/
- korethr 6y agoSo the block works for now, but what happens when a) macOS is changed such that Little Snitch doesn't work anymore, whether it is because the architecture changes in some critical way, or Little Snitch iself is blocked by trustd? b) failure of trustd to succeed in its call home becomes a hard failure that blocks execution? I can kinda see a noble intention behind this: protect system integrity by making sure no "known evil" application runs, like say a ransomware. But I have two problems with it. First, it seems to assume that the call-home server will always be available, which seems a bad assumption from an engineering standpoint. Even the mighty and holy Apple can suffer outages, for a myriad of possible reasons. Be it a fat-fingering of some parameter during an approved maintenance window, the criticality of of which was heretofore unappreciated, a cascade of on-their-own-innocuous failures transforming into a deadlocked hard-down situation, or the fact that the North-American Fiber-Seeking Backhoe is not and never will be an endangered species, the result is ultimately the same: the mother-may-I server is not available. The second reason, giving Apple further capability of evil shenanigans is already well covered by other comments here.
- Tepix 6y agoImagine you are a software developer and want to learn about the boot process and implement your own bootloader. A popular exercise. You can't boot your self-written software on your "own" Apple Silicon Mac. There is no way to disable the locked down boot process. You may argue that it's still your computer and you can do what you want with it. You're wrong.
- brailsafe 6y agoI've never heard of any software developer I know doing this, even the ones with deeper or more obscure knowledge, but do you have any interesting resources to point to?
- zepto 6y agoYou may want to reprogram the computer in your car too. You’ll discover there is no way to do so. You may argue that it’s still your car and you can do what you want with it. You’re wrong. Wait - what am I saying? - that makes no sense. Of course it’s your car. Ahh, this is a bogus argument! Just because there are things you don’t know how do with something doesn’t mean it isn’t yours. It turns that all objects are this way!
- aequitas 6y agoI'm curious if this falls under the "Check this box to send metrics to Apple to help us make things better" checkbox you get when you first login to your Mac after a reinstall. Anyways I don't understand why this process would not be completely asynchronous.
- Razengan 6y agoEeks, this should be communicated better, though to be fair, IF there was any malware with a tampered signature, you wouldn’t want it to run just because your network was unplugged. How would you prevent something like [0]? I think all the game consoles regularly verify downloaded games too. [0] https://blog.malwarebytes.com/threat-analysis/2016/09/transmission-hijacked-again-to-spread-malware/ https://blog.malwarebytes.com/threat-analysis/2016/09/transm...
- krychu 6y agoI’m a MBP owner. But I’m sad to see that Apple makes strong statements about privacy, on stage, while sending hashes of open apps.
- grezql 6y agoI am tired of this 2trillion company becoming too strong. Screw them. I aint gonna develop for them anymore. Parasites. Got this mail from Apple: Dear Developer, Compatible iOS and iPadOS apps will automatically appear on the Mac App Store when the first Apple silicon Macs become available this year. However, we noticed the following issues with one or more of your apps that are opted in to appear. The following apps will not be made available on the Mac App Store until you address the issues and select Make this app available on Mac in the app's Pricing and Availability section of App Store Connect.
- atrainedmonkey 6y agoMaybe I didn't parse the sarcasm tags, but they're opening up a whole new market of mac owners to your product with what's likely minimal effort?
- bluelu 6y agoHow can this be GDPR compliant? Apple tracks each users behaviour and know exactly what software they use and how often, so they can launch their own services and cut out competition on popular services. This is exactly the kind of application Facebook was called out for (https://techcrunch.com/2019/01/29/facebook-project-atlas/ https://techcrunch.com/2019/01/29/facebook-project-atlas/). Just here it's much more worse as it's installed and activated by default on all Macs.
- scoot_718 6y agoI mean, just sounds like Apple are skipping to the end of their game plan.
- musicale 6y agoThis seems to be a very bad design.
- sedeki 6y agoMy MBA is not responsive with my USB-mouse, but is with the touchpad. Like, just hovering over items is smooth with the touchpad, but lags with the mouse. Anyone else with this problem?
- ulrikrasmussen 6y agoIs MacOS sending these hashes to check whether they are revoked? That sounds like an insane excuse. Are there really so many revoked hashes that it is not feasible to mirror the database to every device for offline querying?
- whywhywhywhy 6y agoNot sure if this system replaces it but they’ve had a built in system for years called XProtect that keeps a malware hash database and checks locally.
- blauditore 6y agoSo many comments in here, but I haven't seen a single one mentioning a simple solution: Vote with your feet. For years now, I've seen a large portion of the HN crowd praising Apple for its (alleged) respect of privacy and cursing at Microsoft for Windows "calling home" all the time. Now that this has happened, the only comments I see are "heads should roll", and "we must complain and be heard by high-level execs", but never "let's move away". This just reinforces my impression of the Apple ecosystem as something akin to a cult: Once you get in, you never get out again. There are good alternatives - many people, including software engineers, use non-apple solutions on a daily basis and they are still productive. Why not give Linux a shot, or gasp even Windows? The age-old argument of "MS is evil, Apple good" is moot. Companies are generally not good or evil, they are profit-oriented. If the market demands privacy, they care about it, otherwise probably not so much.
- have_faith 6y ago> This just reinforces my impression of the Apple ecosystem as something akin to a cult That's very uncharitable. Suggesting Windows as a potential alternative also sounds slightly comical given their history with Windows 10 and many people's required workflows, required because of work or other outside influence, make Linux less tenable. A lot of people seem to suggest that if you have something to complain about then you should be moving on to something else, a vibe of 'appeal to perfection'. I think this is the same mentality that drives the distro hopping phenomenon. I'm not brainwashed because I live with the flaws of my OS choice and complain when things are changed that I don't like.
- breakfastduck 6y agoI can't vote with my feet (nor do I really want to), because there's no alternative I enjoy using as a desktop OS. Windows is no better for telemetry, and the user experience doesn't at all fit well with how I work. Linux I prefer to Windows but generally find the desktop experience lacking.
- framecowbird 6y agoI'm not sure which comments you are reading: one of the top threads that almost fills the whole first page is a long discussion about alternatives to macbooks...
- roboben 6y agoThere is also ocsp-lb.apple.com.akadns.net which looks like does the same and should be blocked too!
- daitangio 6y agoAnd so we demonstrate too much corporate control -out of user control- is not a nice thing. We have the Apple Big Brother here, I am sad to say.
- willyt 6y agoProbably best to read this to understand better what happened. TLDR The problem was due to a hung network connection. So the notarisation check thought it could go because it had network but then it hung because the connection to oscp was getting stalled. Hence why turning off network made the problem go away. I experienced a weird slowdown for about 20mins, then everything went back to normal. https://arstechnica.com/gadgets/2020/11/macos-big-sur-launch-appears-to-cause-temporary-slowdown-in-even-non-big-sur-macs/ https://arstechnica.com/gadgets/2020/11/macos-big-sur-launch...
- kruuuder 6y agoI followed OP's advice and blocked trustd from connecting to these servers. I noticed that there's also a process named ocspd that's whitelisted by default in Little Snitch. Can someone explain how these things are related?
- greggman3 6y agomy experience with upgrading today First, just trying to get the system updater to display: https://i.imgur.com/waEF4kc.png https://i.imgur.com/waEF4kc.png Second, after downloading 12gig of new OS: https://i.imgur.com/4HKMkPJ.png https://i.imgur.com/4HKMkPJ.png I guess I should wait a few weeks.
- koonsolo 6y agoOh boy, I'm so happy with my Linux Mint. It's way better than any Windows or Mac system I ever used or saw.
- greggman3 6y agoThis makes me wonder, I guess in the event of war the data centers of Google/Apple/Microsoft/Facebook must be at the top of the list. I wonder how close any of them are to being powned. I can only hope those companies are at the top of their game when it comes to this stuff though accidents like this don't give much confidence.
- quijoteuniv 6y agoOne of the «romantic» aspects of buying an Apple back in the day was that people that «knew» was buying them. Musicians, designers programmers must had one. It was stable and just enpowered you to do your job. I wonder if Apple has underestimated how important is having the «tech» guys on their side
- nbzso 6y agoWe are no longer the "target" audience. I will use Catalina with Little Snitch until it's possible. In 3-4 years time someone will finally realise that Linux is the future of professional work and will make Photoshop/Illustrator clone with quality performance. Resolve is working reasonably well under Linux, Blender works, the only Apple thing I cannot remove is Logic.
- deleted 6y ago[deleted]
- habosa 6y agoOk so let's say you actually want Apple to do this kind of security for you (I don't, but let's say). Currently they do a synchronous check before you launch any binary. Why don't they instead just log every binary signature and check them async on some regular schedule? Strict mode could be blocking the FIRST execution of a binary signature and after that you only recheck if that signature has been revoked on some regular interval. There's absolutely no good reason why an app which I've run 100 times needs to phone home before running the 101st time.
- Spivak 6y agoThis is already how it works. After the first check the result is cached and then it can verify locally.
- nvrspyx 6y agoThis is how it worked. The point of the tweet and others' experience is that this is now happening for apps that have already been launched plenty of times before. This is why nothing other than Apple's programs would launch during the short time that the OCSP was down.
- SkyPuncher 6y ago> this is now happening for apps that have already been launched plenty of times before. Have they launched the same executable before, though? I have a lot of automatic updates. I doubt week-to-week or day-to-day, even, the signature of the programs I run are the same.
- a3w 6y agoDo i need to use Little Snitch, or can LuLu block ocsp.apple.com., too?
- jacquesm 6y agoPlease note that most of your Apple computer hardware (except for the most recent iteration) will run Linux without any major problems.
- ionut-maxim 6y agoI just tought my laptop died
- binarycodedhex 6y agoThis seems like another signal of an overall trend. Post-sj, Cupertino seems to be getting progressively laxer about testing, quality, usability, and overall excellence in software and hardware. It's a shame. :'(
- ho_schi 6y agoI'm sad to see people buying things only because the look comfortable and nice. Here happens finally what was predicted a long time ago and it shows why everyone should use free and open-source operating-systems and applications. I tried to attach the notarization to every Mac App Bundle in the past but with MacOS 11 this doesn't help either?
- danilocesar 6y agoApple has been deciding what and how you are allowed to run apps in your phone for almost a decade now. It's bad and all, but no one can say this is a surprise.
- at_a_remove 6y agoI'll go a step further: what if someone decides, "Hey, I'll shut that website up by influencing someone to revoke their certificate." Remember everyone's eagerness to eliminate bare, unencrypted HTTP? How self-signed certs are "sketchy?" Has this been yet another way to pull the plug on certain parties? Could someone get Cloudflared by a maintainer of certs somewhere along the chain revoking a site's cert because they woke up in a bad mood?
- kwhitefoot 6y ago> macOS unable to open any non-Apple application Shouldn't it really say: macOS unwilling to open any non-Apple application or: macOS refuses to open any non-Apple application Saying unable makes it sound like a mistake or accident.
- outside1234 6y agoI have no idea why anyone immediately installs the new MacOS. It is literally like this with every major release now.
- egberts1 6y agoIt’s a far, far better thing to distribute the hash tables into each macOS, encrypted if need be.
- fattybob 6y agoI have been seeing a warning message for some time about something that won't work in next upgrade, I could never find whatever it was, maybe something I gave unnecessary pensions too long back, so I upgraded yesterday and so far all is running very smoothly, and most of what I use is open source and mostly free, and haven't found anything that doesn't work yet. my windows emulator I use for work stuff may have issues, but it's been dysfunctional for a while, I just refuse to get parallels again.
- john4532452 6y agoApple's products are both SASS and HASS. You dont own Apple products. You just rent it.
- lavp 6y agoHuh, this was the reason why my laptop was freezing every time. I thought it was the fact that my laptop got too old and so I wiped my laptop and installed Arch.