17 ms·
Application trust is hard, but Apple does it well
- hellcow 6y ago> there are a lot of folks reasonably asking if they can trust Apple to be in the loop of deciding what apps should or should not run on their Macs. My argument is - who better than Apple? ... The user?
- nojito 6y agoAnyone who has programmed or developed anything....knows that the end user can never be trusted.
- hellcow 6y agoI have programmed and developed things. I am also a user. I want to run the apps I want to run, thank you very much. No one else should have any say in that. It's my computer.
- ben_w 6y agoLikewise, I am a developer, a user, and I have fond memories of the old days of 2003 when I could download and run whatever I wanted on my Mac without any fear or security concerns. Unfortunately, that world is no longer the one we live in. One of the things I’ve learned about software security is the need to minimise the attack surface of your systems — don’t keep a database running on your web server unless you actually need it, don’t keep ports open unless they’re important, don’t install packages or dependencies you can do without — because everything has the potential for a zero-day exploit. Likewise for my own productive output: the only code guaranteed to be bug free is the absence of code. For any computer not attached to the public internet, I agree that you should be free to run whatever you want. For anything networked? That’s anarchy, and although I would like the freedom of anarchy I experienced in 2003, unfortunately I don’t like the consequences of everyone else having the freedoms of anarchy in 2020. I don’t have any fun, easy, side-effect free, solutions.
- ZanyProgrammer 6y agoSo many serious, power user-ish Mac users will just put up with SO much. That’s it.
- zepto 6y agoDon’t buy a Mac.
- alpaca128 6y agoThat alone isn't a justification to take away the user's rights and responsibilities. Let people make mistakes, they'll learn from it.
- zepto 6y agoIf they want to make painful mistakes and learn from them, they can buy a Linux box. If they don’t, they can buy a Mac. Don’t force them to choose an unsafe tool when they don’t want to.
- alpaca128 6y agoShould we also get rid of photoshop because users could lack practice drawing and feel frustrated while trying to improve? After all they could just google a couple nice images and be done with it. We learn from mistakes, not from success.
- xvector 6y agoMistakes in the modern world can have devastating consequences. It’s not as simple as your computer freezing up and becoming part of a bot net. Your files will be stolen, your accounts hacked, you will lose money. Most users would gladly take protection from that as opposed to “learning” by making mistakes (getting infected).
- deleted 6y ago[deleted]
- zepto 6y agoA mistake in securing your personal data and ending up the victim of fraud or blackmail is very different from a mistake learning to draw. But, more importantly - people use photoshop because they want to edit images. Most people do not buy computers because they want to learn how to defeat cyberattacks. You know what some users learn after dealing with insecure systems? They learn to buy a Mac.
- black_puppydog 6y agoI was really torn on whether to up or downvote here... On the one hand, no. Probably, statistically, apple will know better. On the other hand, despite the above, if you want to call apple devices "owned" (vs "leased") then yes, the user must be the ultimate decision maker. They might want to delegate these things to apple (or someone else for that matter) most of the time. But they must have the possibility to simply run what they want. I think we're seeing the "HN crowd" be so frustrated about this because it is a pretty transparently anti freedom thing to do, and HN folks do love themselves some freedom.
- Someone 6y agoSo, if they started leasing their hardware to users, it would be fine? I can see the argument, but at the same time, if they really did, I’m not sure I would agree. I also am not sure that’s completely theoretical. Apple (almost?) has the money to do so (yearly revenues about $260 billion, cash reserves about $190 billion), and I think ‘the world’ is getting used to not owning stuff more and more. Many users already pay per month for their phones, anyways.
- black_puppydog 6y agoPersonally I'd be very much more fine with them honestly stating: you get a compute resource, don't expect to control it, pay a monthly fee. Would I sign up for that? Certainly not. But if that sounds unattractive, then they should just accept that when you sell something and the buyer owns it, you don't control over anymore. I keep pushing this distinction in DRM contexts, too. It's kinda my personal soapbox. :)
- zepto 6y agoThe issue I have with this, is that anyone who is technical enough to install an operating system from source, must necessarily have an understanding what hardware they will be able to install it on. I’m curious if you have ever done this. No such person would have any illusion about what Mac hardware they could use. Everyone else, reasonably expects Apple to take care of the OS for them. Indeed that is arguably the selling point and key differentiator of the Mac. Nobody is misled. See elsewhere where I respond to the distinction you are making about ownership: https://news.ycombinator.com/item?id=25093873 https://news.ycombinator.com/item?id=25093873
- jariel 6y agoUsers will never have the vast operational knowledge that most organizations do, and are generally very unsophisticated. This is why there is no 'File Access' API in the browser, because it'd be like giving guns to teenagers, even with 'safety training' it would get out of hand. So the issue then becomes one of 'power' as much as 'knowledge' of security, and of course all the peripherial abuse surrounding the 'security rules' that have nothing to do with security. Involving 3rd parties, giving proper security notifications but still letting users have the final say etc. etc. there are definitely middle paths and reasonable choices we coudl make. But there's just too much money on the table for the powers that be to look the other way, they will continue to infringe until they are stopped.
- throw0101a 6y ago> ... The user? As someone who works in IT: not for most users. Certainly not for any of my relatives, as successful/smart as they may be in other fields. Certainly have manual overrides for Alpha Geeks (to use O'Reilly's term), but even if a person is on the right-hand side of the Bell curve generally, that doesn't necessarily mean they can make informed software decisions specifically. I'm fine with automatic seatbelts as long as there's a Terminal.app command I can run to disable them on an as-needed basis.
- sneak 6y agoThen the fake tech support call center scammers just add having the user enter that command to their script. This is why 1TR became a thing, I imagine.
- zepto 6y agoHow many users would have the ability to do something about this: https://www.theverge.com/2019/7/10/20689644/apple-zoom-web-server-automatic-removal-silent-update-webcam-vulnerability https://www.theverge.com/2019/7/10/20689644/apple-zoom-web-s...
- AshWolfy 6y agoyes, because at least the user is trying to act in their own best interest, even if they fail
- NikxDa 6y agoThis is exactly my point of view on this. I've seen people complain about Apple on HN about this in all the other posts, but to be fair, this is actually a really good thing. It protects users, and it works well 99.9% of the time (actually, I am not aware of a previous outage of this system). So, why bother? It's been like this for a while, it is actually very useful to the vast majority of users, and Apple being Apple, even if they collected data, it wouldn't be up for sale like it would on a Google machine. All the people saying they need to look for alternatives now that they found out that Apple is sending information about applications to its servers will need to think about this post. It's not like Apple is doing this to track users.
- Aldipower 6y agoBesides the privacy implications, 99.9% means per definition that it does not work for 8.77 hours per year. This is way too much. It is my computer and it should just work how it is meant to be without any external dependencies.
- macintux 6y agoComputers haven’t worked well without external dependencies in a very long time. How long can you perform useful work without DNS?
- centimeter 6y ago> How long can you perform useful work without DNS? Is this a serious question? My entire dev toolchain works without internet...
- blowfish721 6y agoWithout DNS a lot of my workflows would stop workong since they include various machines/services which all communicate though hostnames/URLs rather than IP addresses, yet almost all are local to my network. So for me this is a valid question.
- saagarjha 6y agoThe problem with the argument given is that it basically gives up to Apple because it thinks that the situation that Apple provides is the best default experience for the majority of users. It probably is, but the problem is that 1. Apple doesn’t really explain any of this stuff anywhere so a technical user may read about it and make an informed decision nor 2. do they really provide a way to alter the process to use someone who isn’t Apple: just because they are a good default shouldn’t mean they should be the only provider that your computer will ever trust. And I think 3. is anger that a system Apple put in place failed in an entirely foreseeable fashion and essentially knocked a bunch of people’s livelihoods offline without warning or explanation and people are sick and tired of their things breaking for opaque “security” reasons.
- zepto 6y agoI agree with 1 and 3 completely. I think 2 is much more complicated and the solution is not obvious, but it’s still a very valid issue, indeed I would say it is the most important issue in the industry today. However much of what I saw in the comments was none of these. Most of it was intended to dishonesty brand Apple a ‘spyware’ company, or to brand anyone who uses Apple hardware or software as a participant in some great evil. Neither of these are intellectually honest paths.
- arvindamirtaa 6y agoThat may be true. But Apple themselves started us down the path of zero trust. This is what I was promised - https://www.youtube.com/watch?v=BZmeZyDGkQ0 https://www.youtube.com/watch?v=BZmeZyDGkQ0 This isn't what Apple is doing. If we're to take Apple's words that the govt agencies aren't 100% trustable just because they have a trustable setup today, why should we trust Apple just because they seem to be the good guys today?
- zepto 6y agoWhether this is what they are doing or not, is a very good argument. For example, not end to end encrypting iCloud backups is a major problem, especially if it is at the FBI’s request. However, this has nothing to do with the certificate server outage. Trust is not binary, and no matter what harmful things Apple does, nothing they do justifies intellectual dishonesty and lies from their critics. If we want to critique them, let’s critique them for the things they are actually doing, and compare them to real alternatives or technical solutions.
- kd913 6y agoCan this site maybe consider specifying a better contrasting font colour between the text and the background? On my firefox browser both on the desktop and mobile it looks like a rather light grey on white background. That is just plain difficult to read and is just terrible UX.
- werber 6y agoyeah, it's not sufficient for accessibility, ran lighthouse and outside of the title it's not ok
- redvenom 6y agoLuckily it works with Firefox reader mode. I use that for nearly all sites that try and be different or have too many sidebars, etc.
- Mister_Snuggles 6y agoThanks to uMatrix, this site just renders as a completely blank page. Fortunately Reader Mode can pull the text out in a perfectly readable format.
- SilasX 6y agoAgreed, the entire article text looks like what you’d use for a greyed out option to de-emphasize it.
- bobince 6y agoIf this unacceptable mess is "doing it well", perhaps the whole idea is doomed and should not be attempting to do it at all. > It comes down to an argument of trust - do you trust Apple is acting in your best interests No. I mean really very obviously no. Neither Microsoft. Nor Google. Why would I assume any company would act in my interests when they have clear incentives to increase their profits and control by acting counter to them? It's great that the author loves to exist within the limits and restrictions imposed by Apple, but don't expect me to go along with your Stockholm Syndrome and belittle me for differing.
- macintux 6y agoWhere does the author belittle those who prefer a different answer?
- craigsmansion 6y agoBy posing false dichotomies: "do you trust Apple is acting in your best interests, or do you believe they're a malevolent entity?" It's perfectly reasonable to believe that Apple is acting in Apple's best interest without attributing malevolence. By downplaying rational arguments: "I think the privacy arguments are far-fetched (because others are worse)" By using loaded terms: "Dogwhistles The privacy squad mobilised" Presenting strawmen: "if I have the code, build the code, nothing can hide in the code. This is a fallacy that people buy in to thanks to effective marketing " Lying by omission: "It's not feasible for an individual to maintain the list of trustworthy or untrustworthy parties that Apple does." It's perfectly feasible for a group of individuals. I'll take any group distro maintainers over Apple's word. He really doesn't just sound like an Apple apologist; he is one.
- macintux 6y agoFair points, I should have re-read it after seeing the GP’s comment.
- zepto 6y agoYou’re exaggerating, and then falling into the same traps you are accusing him of. A lot to people are claiming Apple is a malevolent entity. In context, it is reasonable for him to rebut that. I agree with you about his use of loaded terms, and the dismissiveness. The straw man you cite isn’t a straw man. It is a solid argument. https://www.bunniestudios.com/blog/?p=5706 https://www.bunniestudios.com/blog/?p=5706 The lie of omission you assert isn’t a lie. No group of distro maintainers has solved the problem Apple is solving. The author used the word ‘feasible’. This is currently true, but doesn’t need to remain so. The fact that you are technically literate enough to know about distro maintainers, and trust them does not mean it is feasible for everyone to do so. “He really doesn’t just sound like an Apple apologist; he is one.” If that isn’t a loaded term, I don’t know what is.
- FpUser 6y ago> "there are a lot of folks reasonably asking if they can trust Apple to be in the loop of deciding what apps should or should not run on their Macs. My argument is - who better than Apple?" My argument: sod off and let me decide what I want with my own hardware. Luckily I have no business case to deal with Apple products and as a private person I do not care what they do as I am not in their "ecosystem" or whatever they call it.
- clajiness 6y agoSo, basically, you have nothing useful to add to this conversation. You're just here to let everyone know you don't use Apple products. Cool.
- FpUser 6y agoMy point was that I am very much against of such control disregarding of who implements it. Since I only use Windows and Linux as desktop / server OS I am lucky not to be a victim of such tactics (at least for now). I know MS does collect telemetry but it is not known to be down to this level.
- lifty 6y agoI agree that app signing is good, but I disagree that we have to give in and accept the potential risks of fully trusting Apple. I think there is a practical middle way that protects non-technical users without usurping their privacy, and also a way to give same extra control to power users. I think it's fairly straightforward: - instead of OCSP use CRLs or a better technique that allows MacOS to verify locally if a certificate is valid. This would preserve user privacy and wouldn't risk slowing down the user's computer in case things go wrong. It would also introduce slightly bigger risk because of the increase in the validity window, but I think that's a price worth paying. Regarding the size of the CRL's, there should be some cryptographic techniques like accumulators, bloom filters etc. that could improve the size. - allow power users to add separate trust anchors in cases where they deem appropriate. The same way you go to Control Center to allow an app that was downloaded from the Internet to run, you could also be allowed to add another certificate from a developer you trust. I think these 2 improvements could go a long way in restoring goodwill for Apple.
- gastonc 6y agoIt all comes down to configuration/choice. Its not bad to have OSCP to improve security, but there should be a simple way to turn it off (without those /etc/hosts or similar hacks).
- lifty 6y agoBut I don't want to turn it off. I want to benefit from checking the revocation list without sending my data to Apple on every app start, even if I am vulnerable for a few hours, until my computer syncs the revocation list. I want a middle way, not an ON or OFF button.
- ArchOversight 6y agoAs this article here: https://blog.jacopo.io/en/post/apple-ocsp/ https://blog.jacopo.io/en/post/apple-ocsp/ showcases, Apple doesn't send "my data" on every app start. It sends a hash of the certificate in use to Apple, which happens to be an Apple certificate that is used to sign many applications running on your system. None of your data is being sent to Apple.
- werber 6y agoI have trusted Apple with my phone for basically forever, but my work and personal computer going on the fritz made me seriously reconsider this relationship. I do not want my laptop to be like my cell phone. I frequently write crappy programs on my computer, and I've been totally fine with the earlier implementation of warnings unless you navigate to the application directory and explicitly open it and accept the warnings. As per the question, "Who better than Apple?", I wanna do bad all on my own. I do not have the technical ability to make a Linux laptop as good in terms of industrial design or hardware responsiveness (the touchpad on the laptop and the desktop version are the best user input devices ever for me), and that is what keeps me on their products. Otherwise, I'd be full time Linux again. I'm so confused as to whether or not to jump ship, and I feel like if I do I will be walking the plank
- heavyset_go 6y ago> It comes down to an argument of trust - do you trust Apple is acting in your best interests Stallman had a lot to say about this[1] over a decade ago. [1] https://www.gnu.org/philosophy/can-you-trust.en.html https://www.gnu.org/philosophy/can-you-trust.en.html
- SAI_Peregrinus 6y agoThis argument assumes that companies are unchanging. Apple will never become greedy and use their increased control to raise prices, never stop caring about security and only use the system for market control, etc.
- arvindamirtaa 6y agoHonestly, THIS! Apple used this same argument when talking about security agencies - https://www.youtube.com/watch?v=BZmeZyDGkQ0 https://www.youtube.com/watch?v=BZmeZyDGkQ0. You may trust them now. But what's to say they'll remain the good guys forever? By that logic, what's to say Apple will remain the good guys forever?
- _qulr 6y ago"I always advocate against opt-outs for security features like this" The author conveniently overlooks the fact that customers pay literally thousands of dollars for Apple computers. We're not talking about a free online service here. This is why "you no longer own your computer" has so much traction. Shouldn't we own the devices that we buy? The tech companies are trying to destroy the very concept of product ownership, and consumers ought to fight to the end over this. It's why "right to repair" is so important too.
- zepto 6y ago“You no longer own your computer” has no traction outside of ideology. There are a few people who bring it up, and then use manipulative rhetoric: “Shouldn’t we own the devices we buy?” Of course, who would disagree with that! But this is manipulative because you are affirming the consequent. I.e. leading the reader into accepting the conclusion that you don’t own your computer. “The tech companies are trying to destroy the very concept of product ownership” This is an ideological claim with no factual basis, there are no memos or recordings supporting that anyone is trying to do this. It’s just you claiming to know the plans of ‘the tech companies’. It could just be that Apple is trying to stop malware. Perhaps not a secret plot! Maybe there is no conspiracy! It’s also a laughable exaggeration, as well as black and white thinking . Do you own your house? Presumably not since there are many legal restrictions on what you can do with it. Do you own your car? Presumably not, since you can’t install your own software on its computers. Do you own your toaster oven? Presumably not since you can not reprogram the microcontrollers. Perhaps the conspiracy is deeper than I realized! “Consumers ought to fight to the end over this” More manipulative language. Frame things in terms of a fight between corporations and consumers, and a ‘fight to the end’. Are you a ‘consumer’? But more importantly, what is ‘this’? It seems like you are asking to fight over the belief that ‘Tech companies are trying to destroy the concept of product ownership’. I.e. divide people and exhort them to fight over an ideological claim you are making about intentions that you haven’t substantiated. How about examining some of the technical issues instead of ideological rhetoric? Here’s one: If the security features can be disabled, how can I trust a Mac I haven’t maintained custody of the whole time? Here’s another: If people don’t want their computer software to come from Apple, they can buy something else. What is wrong with that? I have to assume you neither own nor lease any Apple devices. Why are you trying to control what other people do?
- ubercow13 6y ago>Finally, there's the open source argument - if I have the code, build the code, nothing can hide in the code No, but you can modify the code, add your own code..
- ubercow13 6y agoApple uses their authority to revoke certificates on macOS to further their own business interests in direct conflict with those of their users [1]. They have already demonstrated that they will abuse this trust, and use it to control what software people will use on their macs in a similar way as they do on iOS. So no, they don't do it well. [1] https://news.ycombinator.com/item?id=24190556 https://news.ycombinator.com/item?id=24190556
- 3gg 6y agoThe article goes over the horrors of X.509, pulls the typical open source cliche that I actually don't see anybody spreading around, contrary to the article's claim, then argues that the privacy part is fine so long as there is a third-party audit. If the best thing the security community can do is install a global mass surveillance network of devices that come at every expense of users' computing freedoms, then I think these guys need to go back to the drawing board.
- qz2 6y agoIt's not even that. This is a distraction from the real issue which is this technology exists not to improve the security posture but to enforce market control. So go back a few weeks and you buy a copy of Fortnite, Apple and Epic lock horns on a dispute and they revoke Epic's certificate. Next thing you get a shiny new M1 equipped Mac and go to install it and it's gone from the app store. Slightly deflated, you go back to your Mac and copy the files off it onto your new one, thinking you circumvented this slyly, it does an OCSP check and refuses to run the binary. Eventually the OCSP check will be done, probably after an OS upgrade on your old Mac and that's gone too. So you're deprived of something you paid for and have no control over the hardware you paid for. This is an example of what could happen. If it improved security posture the signing infrastructure wouldn't be used to sign any old shit from millions of developers doing all sorts of nefarious things that Apple didn't pick up during the review process... Edit: this has already been demonstrated if you refer to the Flappy Bird mess a few years back.
- 3gg 6y agoYes, thanks for the reply. I was giving the author the benefit of the doubt, but their arguments just have no solid grounds. And like you said, this is about market control, not security, the latter just being a distraction. Another thing in line with what you mentioned is the ability for the company to squash competition. Not only do they have the last word to veto programs from running, they also get a global view of what everyone is running that nobody else has. This kind of information has been abused by Amazon to drive out competition in favour of their own "Amazon essentials" products, for example.
- 6y ago
- arvindamirtaa 6y ago> It comes down to an argument of trust - do you trust Apple is acting in your best interests, or do you believe they're a malevolent entity? I'll just leave this here - https://stallman.org/apple.html https://stallman.org/apple.html
- fauigerzigerk 6y ago>It comes down to an argument of trust - do you trust Apple is acting in your best interests, or do you believe they're a malevolent entity? No, that's a completely false dichotomy. These are not alternatives at all. I can absolutely trust Apple to act in my best interests in some regards while distrusting them in others. I do trust Apple to make a good effort to keep malware off my device, a better effort than I could ever hope to make myself. I do trust them not to spy on me to target ads. But I also know that Apple has a business interest in keeping software off my device that is not malware. I don't trust them to act in my best interest where it conflicts with their best interest. I also know that their interest in tightly controlling what software goes on my devices creates an opening for authoritarian governments to take control. If and and when end-to-end encryption gets banned, who decides whether or not I can still use Signal? Is it going to be me or is it going to be Apple? This is definitely not a simple question of trusting Apple or not trusting Apple.
- gamblor956 6y agoThis article must have been written before this week's spectacular meltdown in Big Sur, which resulted because Apple emphatically did not handle application trust well.
- alphabettsy 6y agoI’m not sure how you could come to that conclusion given the first paragraph acknowledges the meltdown. “ On November 12, 2020 Apple released macOS Big Sur. In the hours after the release went live, somewhere in Apple's infrastructure an Online Certificate Status Protocol (OCSP) responder cried out in pain, dropping to its knees, begging for mercy as load increased beyond what it could handle.”
- 3gg 6y agoThey read the headline and all of the article except for the starting paragraph.
- gamblor956 6y agoI stand by my statement. The article itself was clearly written before Big Sur. Adding one paragraph at the beginning doesn't change when the rest of it was written.
- jrsala 6y ago>I always advocate against opt-outs for security features like this [...] Because most users are not capable of evaluating the impact of opting out of a security process. I agree fully with the author's characterizations of the dangers of disabling features or ignoring warnings, but I can't possibly agree with the conclusion that users should not be given a choice. So what if the user cannot understand the technical terms of a popup warning them about malware risk? How does that justify taking away their freedom to proceed anyway and run the program? The author's attitude is patronizing (and also intellectually dishonest as explained already by another commenter [1]). There are lots of domains in life where we're out of our depth and make decisions anyway that might be dangerous, and we don't have anyone trying to hold or hand or to stop us altogether. Imagine you get into your Apple Car and plot a course on the GPS. The computer's voice says "there is a dangerous stretch of road on the plotted itinerary; please wait for your assigned Formula 1 driver to drive you to your destination". The car refuses to move no matter what you do. Half an hour later a small guy with a thick neck shows up, enters the car (because they've got the keys apparently) unlocks it so it can finally move and explains to you "oh yeah, a car fell down a cliff on that road back in 93". You complain about them not even apologizing for the delay. "You accepted the Terms and Conditions, didn't you?" I get that the lack of freedom to run potentially malicious programs might be a feature, not a bug of Apple's systems. But I don't see them advertising it as what it is in practice. The notion of "false advertising" is well known and understood, but what about the notion of absence of advertising for a feature that might be unwanted to the point of making at least some potential buyers balk? Is there even a name for that? Whether before the purchase of an Apple system or later at program startup time, the user should be able to make a decision as to whether to give Apple control of their computer in the fashion we've seen. All the necessary information and data should be provided to them. Whatever choice they make should be respected and they should not be judged for it, even if they did not understand the provided information. But the decision should not be made by some security nerd on a massive ego and power trip, imparting their enlightened guidance to "the lowest common denominator". [1] https://news.ycombinator.com/item?id=25093906 https://news.ycombinator.com/item?id=25093906
- tonyedgecombe 6y agoOne of the reasons Apple has been so successful is because they make these decisions for the users. Customers were tired of their system breaking and getting malware because of confusing options and too much flexibility.
- NautilusWave 6y agoThe low contrast gray font is obnoxious; the font should really be about twice the size if they're really committed to using the color.
- cute_boi 6y ago"Windows has made amazing strides, bounding past controls afforded by other OSes, providing a great deal of simplicity for users while focusing on verifying who compiled code that is running on a user's PC" By installing Candy Crush in every home user Windows hasnot made any amazing strides. In fact I would say windows 7/8/8.1 was far far better. What we have now? Candy Crush, Dumb Antivirus taking 20% CPU wasting unnecessary cpu time, Telemetry which sends data even if you opt out. "I think the privacy arguments are far-fetched" Really?? Just because there are other bad players in market. Just because apple rivals/friends are doing bad thing doesn't mean you have to go and say privacy arguments are far-fetched. Clearly the article is just white washing of apple
- Technically 6y agoI don't trust a damn bit of code Apple sends me. Thankfully for them, that's only marginally worse than other operating systems with functional drivers and I am addicted to usable interfaces.
- klyrs 6y agoIrony that this shares the front page with Apple's firewall sploit today. https://news.ycombinator.com/item?id=25095972 https://news.ycombinator.com/item?id=25095972
- amelius 6y agoThis reminds me of Stripe, which logs every action of a user on any webpage (even non-checkout pages), in the name of fraud detection. Not sure what to think of it, but I would turn it off if I could.
- admax88q 6y agoThe Apple defenses are all over HN today. Honestly feels like astroturfing after the OCSP fiasco. If it's not astrptufing, I don't think I can understand the mindset of a consumer who feels the need to defend the world richest corporation from criticism.
- deleted 6y ago[deleted]
- tonyedgecombe 6y agoIt's not surprising when those customers are repeatedly criticised and insulted for buying a product they like. It's the same as that Clinton comment about Trump voters being deplorables. Insulting people won't change their mind, rather it entrenches their views.
- admax88q 6y agoWoah. Is there much if any criticism of Apple customers? I can't recall a single instance in all the Apple threads I've read here. Plenty of criticism of Apple itself, but that is not a criticism of their customers.