25 ms·
Sincerely and without any intention to troll or be sarcastic: I'm puzzled that people are willing buy a computer/OS where (apparently) software can/will fail to
by elmo2you 6y ago
Sincerely and without any intention to troll or be sarcastic: I'm puzzled that people are willing buy a computer/OS where (apparently) software can/will fail to launch if some central company server goes down. Maybe I'm just getting this wrong, because I can honestly not quite wrap my head around this. This is such a big no-go, from a systems design point of view.
Even beyond unintentional glitches at Apple, just imagine what this could mean when traffic to this infra is disrupted intentionally (e.g. to any "unfavorable" country). That sounds like a really serious cyber attack vector to me. Equally dangerous if infra inside the USA gets compromised, if that is going to make Apple computers effectively inoperable. Not sure how Apple will shield itself from legal liability in such an event, if things are intentionally designed this way. I seriously doubt that a cleverly crafted TOS/EULA will do it, for the damage might easily go way beyond to just users in this case.
Again, maybe (and in fact: hopefully) I'm just getting this all wrong. If not, I might know a country or two where this could even warrant a full ban on the sale of Apple computers, if there is no local/national instance of this (apparently crucial) infrastructure operating in that country itself, merely on the argument of national security (and in this case a very valid one, for a change).
All in all, this appears to be a design fuck-up of monumental proportions. One that might very well deserve to have serious legal ramifications for Apple.
- thewindowmovie4 6y agoI think it is because a lot of people still believe and repeat old trope which are demonstrably false these days. Despite having the worst keyboard, buying third party apps to have features which most of the other OS in the market provide as standard, more lock down of their OS every year, Apple fans continue to buy them. Appke's powerful marketing, which is full of weasel words, keeps them in their own bubble.
- wait_a_minute 6y agoWhich third party apps do you mean? And the worst keyboard? I understand it being subjective as a taste, but the worst? Idk...
- frompdx 6y agoI'm puzzled that people are willing buy a computer/OS where (apparently) software can/will fail to launch if some central company server goes down. I really had no idea until today.
- swiley 6y agoI think the problem is that almost all the software you buy a mac for (or even things that mac users like) has this built in but calls to the developer's servers instead. Consumer and commercial software is just all bad.
- strawberrypuree 6y agoThis is a soft failure. If the computer didn't have access to the Internet, it would still open.
- elmo2you 6y agoThat's all nice and well, but what if some country decides that your country will still have Internet access, but a "degraded experience" to Apple's central infrastructure? Still sounds to me like Apple rolled out a huge (logical) trojan horse, as a potential weapon in terms of nation state cyber warfare. Probably not at all with that intention. But I doubt that any government willing to abuse this "opportunity" will give a fuck about that. Don't underestimate the power (and disruptive) effects of being able to practically disable a whole brand of popular computer hardware. Heck, even the ability to threaten with it (privately, through diplomatic channels) can (and probably should) be considered a serious weapon. So yeah .. "thank you" Apple.
- nnwright 6y agoFrom my experience during this outage, the ability for the computer to "open" may not actually mean much. While trying to fix what I assumed was a localized software issue I rebooted my machine. Typically this takes a minute or two. However during Apple's systems outage my rebooting took approximately an hour before my computer was in any way functional again.
- Aperocky 6y agoso you can't even reboot without phoning home. Or can you still reboot without wifi?
- pacificmint 6y agoIn this case, any app would take five to ten minutes to open. While that technically means "it still opens", it effectively renders the computer unusable. (And that's after I realized that they will eventually open. Originally I rebooted the machine before any app had had a chance to open.)
- AngusH 6y agoApple, for some reason, didn't advertise this change very widely, so it isn't precisely an informed decision. Like so much of the modern security activity, it doesn't seem to be fully thought out, nor was the possibility of failure considered. Or maybe such failures were considered and then dismissed? I don't know.
- sroussey 6y agoIt times out and the app runs, so the failure mode was considered. They may move to edge servers instead of centralized datacenters now though...
- eric_h 6y ago> the failure mode was considered Considered but not tuned. I've never noticed any delay launching or using software that doesn't require an internet connection while not being connected to the internet. (I definitely did notice slowdowns today - Zoom in particular which I tend to quit out of when I'm not using it because I don't trust it one bit but am compelled to use it for work) Seems like apple was accepting connections for the signature check but were unable to actually service the connections, leading to the timeout/failover. I honestly like the idea of signature checks on software that give me some confidence that the code that is running is the code that it claimed to be when it was published/installed and has not been manipulated via some other vector. Whether apple is the appropriate steward of that system is certainly up for debate, but certainly other companies that run app stores have similar systems and similar risk. It certainly doesn't seem obvious to me what a secure, anonymous, performant and federated system to solve such a problem would actually look like.
- simonbarker87 6y agoI have no problem with checking binaries when I launch them for security. I imagine many of the virus checking apps for windows probably call home with similar information. I doubt very much I’m leaky in any personal information. What is frustrating is they didn’t handle this situation like they do if I’m offline - don’t get a ping back in less than 500ms or whatever? Go ahead and open anyway. would have solved this eventuality
- zmmmmm 6y ago> don’t get a ping back in less than 500ms or whatever? Go ahead and open anyway how do you do that without defeating the security? Now a malicious attacker just has to wait for a moment when you aren't connected before launching their payload.
- initplus 6y agoThe feature needs to be implemented using some kind of regularly updated local database, rather than requiring a phone home every time.
- colejohnson66 6y agoA program signature database, perhaps? We could even call it: antivirus! No, that’s a bad name... In seriousness though, the problem with offline databases that are changed a lot is a problem antivirus programs always had: they need updating. You can’t have the “latest and greatest” protection if you don’t know about the newest threat. That’s probably what Apple is doing here: using a database on their end that they wouldn’t have to distribute to end users. It’s not the best way around it, but there isn’t really a “best” way.
- btown 6y agoI think it's an exaggeration to say that it's impossible to keep local AV databases up to date in a meaningful way. Use compressed probabilistic data structures and ship minimal diffs to save bandwidth and storage; you can fall back to phoning home if there's a possibility of a collision with a known-bad hash. Apple's solved push messages at scale; it could piggyback an update mechanism on that, or use the techniques Dropbox uses to notify about file updates. It can do this at the OS level so there's no threat of a user process not being active to pull updates. And the check is already soft-failing (per the OP) so it won't break if the system is offline, so they're already not caring about threats that are so new, they were found while the computer was offline. You need to solve a lot of timing diagrams and race conditions (and, if we're being snarky, maybe it's for the best that Apple isn't trying to do this!) but it should be doable.
- damnencryption 6y agoThis has been happening for a long time. Hardware and software that you can't control is becoming normalized. If they had done this 10 years ago with the same customers, those customers would be shocked or weirded out but right now, many of them will just wait it out or change their host. Don't limit freedom at once. Do it one by one so the impact seems low. What are the chances that any of the big tech companies take orders from a fascist to block all the harmful software in their country? Non zero. People in HK know this. I want to know how they felt about their choice to buy iPhone at that moment.
- horsawlarway 6y agoPeople chose to use Apple because it seems like a benevolent dictatorship. And frankly, a benevolent dictatorship is basically the best government you can have, as long as you're part of the "in-group" who doesn't push boundaries, doesn't cause trouble, and supports the supreme ruler, Kim jon... cough* Apple. --- The problem is that no matter how good the dictatorship might be today, it will eventually bite you. You will either develop a need that isn't addressed, or they will change the rules so you are no longer able to satisfy an existing need. We're seeing this now with Google - Their motto was literally "don't be evil" for a long time. And during that golden period their users loved them. But as Google has shifted from "don't be evil" to "Make lots of money" people are starting to shift away. Apple is still in the golden phase, but I'm not really convinced they're going to be there much longer.
- itp 6y agoFrom https://en.wikipedia.org/wiki/Don%27t_be_evil https://en.wikipedia.org/wiki/Don%27t_be_evil > "Don't be evil" is a phrase used in Google's corporate code of conduct, which it also formerly preceded as a motto. > Following Google's corporate restructuring under the conglomerate Alphabet Inc. in October 2015, Alphabet took "Do the right thing" as its motto, also forming the opening of its corporate code of conduct.[1][2][3][4][5] The original motto was retained in Google's code of conduct, now a subsidiary of Alphabet. In April 2018, the motto was removed from the code of conduct's preface and retained in its last sentence.[6] I know saying Google removed Don't Be Evil is something of a trope, but the truth is a little more complicated. And, of course, the presence or absence of this phrase has no necessary bearing on the degree to which they are perceived as evil or not!
- jjoonathan 6y agoRight, but it's funny how these things tend to correlate. For example, the US Department of War became the US Department of Defense in 1949, arguably around the time when its primary business switched from Defense to War.
- nmlnn 6y ago
- mlindner 6y ago> software can/will fail to launch if some central company server goes down The central company server didn't go down. If it was down there would be no problem. The problem is that the server is slow.
- AsyncAwait 6y agoAnd I keep hearing how Linux is a toy whereas macOS 'just works'.
- damnencryption 6y agoA lot of it is just people parroting the same old boring tropes. They couldn't believe Linux had gotten easier to use than windows. I know this. I installed Windows few days ago. I can't install steam or chromium without getting blocked by windows. I have to download it from external sites while both of these are available in the software store on Ubuntu. It didn't nag me to login, switched my browser to edge after updates, forced me to read a marketing manual before starting the OS. The search is useless. On Linux, it's so much better. I had to download and run a bunch of scripts to get rid of the amount of data it was sending back home. I had to remove the bloat and ads it came with. Give https://pop.system76.com/ https://pop.system76.com/ a try if you don't believe that Linux is easier to use. Most people don't need to open the terminal anymore.
- evilos 6y ago> I know this. I installed Windows few days ago. I can't install steam or chromium without getting blocked by windows. Sorry what do you mean you can't install steam or chromium in Windows? Millions of people run this software on Windows. - A mint user.
- damnencryption 6y agoWindows smart screen. I can install it but sometimes it is trigger happy so I have to go through a pop up.
- Biganon 6y agoThat's not really the same as not being able to run these apps, don't you think? But besides this bad example, I agree with you. Windows has always been a black box, but as time goes by it's become a stupid black box. It feels so incredibly refreshing when I go back to Linux and I feel in control of the entire system. Almost like a physical sensation.
- deleted 6y ago[deleted]
- tshaddox 6y ago> I'm puzzled that people are willing buy a computer/OS where (apparently) software can/will fail to launch if some central company server goes down. Maybe I'm just getting this wrong, because I can honestly not quite wrap my head around this. This is such a big no-go, from a systems design point of view. The answer is pretty simple: these problems are extremely rare, they don't last very long, and they tend to have fairly simple workarounds. You seem to have a principle that any non-zero chance of being affected by a problem of a certain type is a complete deal-breaker, but most people when buying a computer probably just subconsciously estimate the likelihood and impact of this type (and all other types) of problems and weigh that against other unrelated factors like price.
- satisfaction 6y ago> rare, very long, simple in this context those are simply weasel words in my opinion
- tshaddox 6y agoIt's true that I don't have data on how often this type of problem happens, how long they last, and what the workarounds are, but I'm using those words not to be intentionally vague, but to reflect my own impression from my own experience, and I strongly suspect my impression matches most people's.
- kbenson 6y agoThe problem is that this is not an issue that should be viewed only in the current context. Just because things are rare now, don't last very long doesn't mean that they will continue to be that way, or that it will work at all in the future if Apple decides that only EOL OSs could be using this system at some future point where it's mostly changed. Not caring about this now is like not caring about government or corporate privacy invasions because "I have nothing to hide". It completely ignores all the variables that have to align to make this benign that happen to at this point, but are in now was assured for the future.
- epistasis 6y agoThe alternative to a poor binary checking and cert revocation process isn't to get rid of binary signing and cert revocation. I don't want that. I don't think it would serve Apple's customers to get rid of binary signing either. Since there are no legal ramifications for security bugs that cause downtime, or for bugs that cause other functionality that goes down, I'm not sure why this particular bug would be any different. It's certainly not as bad as losing one's Google account permanently without recourse.
- jungletime 6y agoThis is almost as bad as relying China on Personal Protective Equipment and quickly running out during the pandemic earlier this year. Imagine if the USA actually comes under an attack.The apple spaceship would be high on the list of targets. All of sudden hospitals can't run their computers or communications. Disaster!
- outworlder 6y agoPlease stop fear mongering. If Apple servers actually go down, there's no issue.
- elmo2you 6y agoReferring to the USA, this might indeed be leaning towards fear mongering .. on the other hand, for any other country .. the "opportunity" to systemically disrupt Apple computers in that country might now be considered a (diplomatic) soft power (of the USA), from this day forward.
- outworlder 6y agoStill, this doesn't follow: > All of sudden hospitals can't run their computers or communications. If the scenario is an attack by the USA, there are so many better avenues. If a country wants to defend from this (assuming they are heavily invested in Apple hardware), they just have to block at their firewalls. Done.
- Yetanfou 6y agoThat is why a smart attacker would not make them go down, instead they'd degrade performance to such an extent that it'd cripple Apple-encumbered products.
- outworlder 6y agoAt which point Apple would turn the service off.
- ineedasername 6y agoIn short, the vast majority of users never need or want fine-grained control over their computers. In the HN community, we are mostly edge cases in terms of computer usage & functionality requirements. I believe this is why there has never been any mass pushback against iOS/Android (even if Android is slightly better in this respect). Further, neither iOS nor Android (and now OS X) have instituted huge restrictive changes all at once. Restrictions are gradual & creeping, basically moving the overton window of what is accepted.
- laurent92 6y ago> fine-grained control over their computer Or just run BlueStacks, which is necessary to run Among Us (the popular game since lockdown), which isn’t signed because it’s an emulator. And it requires the “Control this mac” permission. Unsigned. There are many, many cases in which users are faced with unsigned apps.
- ineedasername 6y agoI thought BlueStacks was just to emulate Android on a Mac/PC? Though I suppose you could run Virtualbox on a Mac to get an OS you "own"
- alwillis 6y agoWelcome to 2020. Because we can't have nice things, Apple has to check that apps are signed with a current certificate for safety and security reasons. OCSP tells the client if the certificate has been revoked or not. Try opening a non-https web page; you'll get a bunch of ominous warnings from all major browsers. Browser certificates need to be OSCP signed for the browser to trust them. You can't even get a new cert if the issuer’s OCSP server goes down, which does happen on occasion. There are so many dependencies to ensure we're not running malware infected apps that sometimes things break. Let’s not get carried away; every major tech company has had some version of this happen at one time or another. FWIW, I haven't experienced any issues with my iMac running Big Sur running Apple or 3rd party apps all day.
- jiggawatts 6y agoThis used to be true, but neither Chrome nor Firefox actually check CRLs or OCSP that much. They'll accept OCSP-stapling, but that's about it. This is a very serious concern for Enterprise PKI systems: revoking certificates is now virtually impossible. CRLs and OCSP do practically nothing. Google especially has unilaterally decided that Enterprise PKI systems don't matter. They have established a new "standard" called Certificate Transparency, which they use to make CRLSets that they publish as Chrome updates. Which is fine I suppose for public CAs, but utterly useless on internal-use private CAs on local networks, especially those with lots of BYOD or guest/partner systems. Think universities or hospitals. Google has become a juggernaut with more control over computing in general (not even just the Internet!) than all of the world governments put together. They're getting truly terrifying.
- alwillis 6y agoThis is all true; OCSP-stapling is the thing these days. But these browsers won't trust a cert if it can't be found a Certificate Transparency log. Yes, a cert should be in at least two of them but if there's a networking problem or infrastructure issue, you're SOL.
- sleevi 6y agohttps://cloud.google.com/docs/chrome-enterprise/policies/?policy=RequireOnlineRevocationChecksForLocalAnchors https://cloud.google.com/docs/chrome-enterprise/policies/?po...
- csallen 6y ago> I'm puzzled that people are willing buy a computer/OS where (apparently) software can/will fail to launch if some central company server goes down. For the same reason every human frequently makes decisions with greater-than-zero risk: because we're either unaware of the risk, or because we believe the tradeoff is a good one, and the benefits are worth the risk-adjusted costs.
- miguelmota 6y agoI think it comes down to humans being creatures of habit and conservation of energy. I've seen people buy macs even after seeing all the flaws because it's what they're used to and don't want to exert energy learning a new OS and environment. Apple used to make great products and I think people still cling on to that thought, even though their quality has been degrading these past years. Something needs to be 10x better (or at least perceived that way) for people to switch and switching to a new OS for them is probably like a 1x improvement so not worth the time cost.
- NoPicklez 6y agoTo your first paragraph, how many people globally do you think know that this is how it works? Apple don't publicly go out of their way to tell you that this is how it works. You make a great point that the way it works is bad and I think everyone agrees with that. But it's the limited knowledge that the OS operates this way that keeps consumers purchasing their products.
- api 6y agoThe amount of time you save by having a computer that "just works" 99%+ of the time is far greater than the occasional time lost by shit like this. I'd love it if someone other than Apple made a competent PC that was as clean, reliable, and comparatively free of bullshit. Unfortunately Apple has a monopoly on cleanly designed computers.
- jms703 6y agoI don't think most people are aware that this could happen or even understand what happened and how it was Apple's fault.
- Aperocky 6y agoI just ordered one, and let me tell you something - I didn't expect this to happen. If I knew - I might still have ordered one, because I like ARM and battery life. But this reaffirms the observed trend of Apple becoming more of an owner of the machine that supposedly I own. I'll attempt to shut it down (at least now, it still observes /etc/hosts) - but when I can no longer do that, I'll leave Apple forever, hopefully by then other hardware manufacturers have caught up in UX.
- test001only 6y agoThe worst part of this is that Apple could have easily predicted this, that there would be demand to download the new OS, and put in place measures to prevent this from happening. I guess they just do not care.
- bootcampwhere 6y agoBitcoin people (like me) feel the same about currency. Why out your entire life savings in the hands of a single government when they have proven again and again that the can't be trusted.
- yhoneycomb 6y agoI buy em cause apple laptops just maintain their quality way longer than other laptops. All the other laptops I’ve had start losing all their charge within 30 mins after a year or two. My 5 year old MacBook still can go probably 2 or 3 hours on a full battery charge
- runawaybottle 6y agoHey, it can never happen. Similar to a global pandemic.
- peterkelly 6y agoI don't like this behaviour at all, and find it frustrating at times (e.g. apps slow to launch when my internet connection drops out temporarily). Having said that, it's not enough to get me to switch platforms. I'm able to work around the problem (using Little Snitch, see other replies), and there are a ton of factors that go into my decision of which hardware/OS to use, all of them involving tradeoffs. The only viable alternatives, Windows and Linux, have their downsides too. Some people prefer those over macs and that's fine; it's a choice people make based on their particular situation.
- sneak 6y agoEven when it works right, it’s transmitting the apps that you use, as well as your timestamped coarse geolocation (from client IP) to Apple, which logs all of it. It’s good for city-level location. They know what times you're at home, and what apps you're using there. They know what times you're at work. They know what times you're tethered. They know when you travel, and to which cities. They know when you're on a friend's Wi-Fi, and they know which apps you open from that connection. Apple is a partner in the US military’s PRISM spying program, so this log is available to US military intelligence at any time without a warrant. Thanks to API changes in Big Sur, it’s impossible to use Little Snitch to block these system level connections, and they will also bypass any configured VPN. To control this, you’ll need to use external network hardware, like a travel router that you can operate a vpn/firewall on. Big Sur is the only OS that will run on the new Apple Silicon macs, so it’ll be impossible to use the new machines without leaking your track log and app usage history in a way that is available to the FBI/CIA/et al whenever they want it. Note also that Apple recently backdoored iMessage’s end-to-end encryption by defaulting the non e2e-encrypted iCloud Backup to on for all users: it backs up (to Apple) your device’s complete plaintext iMessage history, as well as your device’s iMessage keys, using Apple keys, each night when you plug it in. You should immediately stop using iMessage as a result of this, because even if you have disabled iCloud or iCloud Backup, your conversation partners likely have it enabled. iMessage is no longer meaningfully encrypted. Apple’s marketing about privacy is lip service, not real.
- czbond 6y agoWhoa - thank you for sharing that.
- deleted 6y ago[deleted]
- lawnchair_larry 6y ago> Apple is a partner in the US military’s PRISM spying program, so this log is available to US military intelligence at any time without a warrant. False
- deleted 6y ago
- deleted 6y ago[deleted]
- city41 6y agoI used to be a MacOS user from System 7 to Sierra. I owned an iPhone from 2007 until a few months ago. I have completely switched away from Apple. It absolutely boggles my mind how popular Apple still is. Apple's quality is absolute garbage now, this latest incident is just a drop in the bucket. I'm sure I'll get downvoted, but I just had to get this off my chest. Why people still buy Apple today, I positively can not comprehend.
- kmlx 6y agobest os, best hardware. i really don’t get these kinds of comments.
- snowwrestler 6y agoThis issue is clearly a bug. It is an accidental denial of service attack on the client. It will get fixed pretty easily: Apple will add some combination of a timeout and a request back-off to their client, to properly handle the situation of a server that is reachable but not sufficiently responsive. Apple clearly does not mean to make their devices unresponsive if the server is offline, because pointing requests at localhost resolves the issue.
- rleigh 6y agoI disagree. It isn't a bug because it was explicitly designed to behave this way. The solution won't be to fix a defect, but to change the design, which is completely flawed. They should have pushed revocations from the beginning rather than requiring every system on the planet to poll a service. What were they thinking? And that does make one wonder whether there weren't other reasons for this behaviour besides "security".
- lovelyviking 6y agoThe main design fuck-up is that instead of independed Personal Computers we have terminals connected to one huge server which violates the whole idea and meaning of Personal Computer and what the word "Personal" should mean.
- Qahlel 6y agoWhat if the café you went just blocks Apple's domains or your ISP decides to do that until Apple pays them "connection tax"?
- ttiurani 6y agoI need XCode to build software for iOS and OSX, and there isn't to my knowledge any other feasible, performant and off-line capable way to do that beside running OSX on a Mac. This is the only reason I had to move away from (arch) linux and it saddens me every day.
- alwillis 6y agoAll in all, this appears to be a design fuck-up of monumental proportions. One that might very well deserve to have serious legal ramifications for Apple. Apple gave a detailed explanation. It was a server misconfiguration combined with a CDN issue which caused the OCSP certificate check to stop working, which caused Apple's system for ensuring certificates haven't been revoked to stop working: “We have never combined data from these checks with information about Apple users or their devices. We do not use data from these checks to learn what individual users are launching or running on their devices,” clarified the company. “Notarization checks if the app contains known malware using an encrypted connection that is resilient to server failures,” says Apple, further emphasizing, “These security checks have never included the user’s Apple ID or the identity of their device. To further protect privacy, we have stopped logging IP addresses associated with Developer ID certificate checks, and we will ensure that any collected IP addresses are removed from logs,” details Apple. https://news.ycombinator.com/item?id=25108108 https://news.ycombinator.com/item?id=25108108
- alwillis 6y agonot only do I see fewer macbooks every year among the affluent crowd… Turns our Apple's MacBook business grew 39% last quarter: https://appleinsider.com/articles/20/11/16/apples-macbook-business-grew-39-in-the-september-quarter https://appleinsider.com/articles/20/11/16/apples-macbook-bu...