21 ms·
Does Apple really log every app you run? A technical look
- izacus 6y agoWhen it comes to these article, you should really apply the following "smell" test: Replace "Apple" with "Google", "Facebook", "Verizon". Re-read the article. If it sounds horrifying, then it's also horrifying if Apple does it. There's no such thing as "trust" into a single corporation - especially the one which just argued that you not paying 30% to them is "theft". Applying this test helps weed out the marketing bias these corpos constantly try to push at you.
- open-source-ux 6y agoThe tech industry is rife with hypocrisy when it comes to matters of privacy and online tracking. It's something rotten at the very heart of this profession. Developers are more likely to rush to defend companies - rather than scrutinise them. We'd all be better off if we stopped defending these companies. You can like - even love - a company product without feeling you owe the company any loyalty or defence. And we'd all be better off for it.
- d0mine 6y agoBetter replace "Apple" with "TikTok", "Zoom" otherwise people might think about "Google", "Facebook" that (paraphrasing) «they may be sons of bitches, but they are our sons of bitches» (regardless the reality).
- izacus 6y agoGood point there.
- Nightshaxx 6y agoThe idea that sending information about the cert is somehow not exposing the app is crazy. An attacker could easily download apps and sniff the network traffic to correlate cert info with an app. Also i don't get the argument for using HTTP. Aren't these two separate systems?
- tedd4u 6y agoSeems like the solution is just put a short timeout on the OCSP call and fail positive? Nets the same behavior as when you’re offline.
- saagarjha 6y agoThat’s what they do.
- supernova87a 6y agoI think it would help if someone could quote or reference Apple's official position / explanation on this (if there is one). You know, before declaring the end of the world, is there any information from the source (Apple)? Discussions here seem to have had several thousand comments without obtaining this basic info. It would be good to know, I would think?
- saagarjha 6y agoApple rarely posts their official positions on things.
- paultopia 6y agoHas anyone used a pi-hole to block apple privileged servers, like the OCSP one, while running Big Sur? I'm thinking of setting one up---not necessarily to block OCSP, because the points in this post about actually wanting to know when a certificate has been revoked are sensible---but to at least have the option in case of another disaster... Relatedly, does anyone know if Big Sur allows one to use a custom DNS server on the device level with those privileged destinations? (He says, mulling the complexities of getting a pi-hole working with his mesh system.)
- cybralx 6y agoCustom DNS servers are available on Big Sur. My home network uses pfSense as a gateway for LAN. This gives more options blocking outbound connections or routing connections thru a VPN connection based on certain conditions. https://www.pfsense.org https://www.pfsense.org
- heavyset_go 6y agoVendors are already baking in DoH into their apps and systems, and that entirely bypass your DNS servers altogether. I went from blocking about 45% of my entire network's traffic at the DNS level two years ago, to only blocking 10% of the traffic today.
- GekkePrutser 6y agoBut how are those apps finding the DoH server's IP then? If they use public DoH servers you could just block those at the network level. Andv if they're running their own DoH service on a fixed IP, they could simply run the app itself over that IP and avoid the whole DNS lookup altogether.
- heavyset_go 6y ago> But how are those apps finding the DoH server's IP then? I don't know, I haven't dug deep enough to find the answer for myself. However, after blocking Google's DNS servers on my network and designating my own DNS servers via DHCP, my Chromecast ceased to function, and certain Android apps that serve ads had functionality that ceased to work correctly. That leads me to believe that apps and systems with DoH baked in are actively hostile to mitigations against their DoH implementations.
- Technically 6y agoOh look, another asshole wading into journalism with zero training. If you can't interpret sources don't comment on them! It's not clear which standards are enforced by the mods here. It seems like the "don't start trouble" standard....
- intricatedetail 6y agoApple should change their name to "Peeping Tim".
- chpmrc 6y agoDid you even read the article? It clearly shows that all that's being sent to Apple is some opaque info about the dev certificate used for the app(s).
- justinclift 6y agoIt clearly shows that Apple is getting fed the dev certificate info for each application being launched. For developers with multiple applications, then sure, that's not going to be as clear as individually identifying the application. But there are plenty of developers around with just one popular application. Sending the dev certificate for them is effectively the same as sending the application hash itself.
- oneplane 6y agoThey already know they exist (they sign them) and most of those are downloaded via the AppStore (they run that) and people tend to log in using iCloud (which they own). I get it, we're all supposed to trust nobody and have 7 billion independent islands where you don't have to trust anyone or work with anyone. I have not seen any solution, just people piling on. Having PKI and signatures using a central authority is the least-worst solution we have right now, and until something better is created we don't really have a lot of places to go (unless we accept downgrading common user's security and usability).
- justinclift 6y agoI'm not sure what you're getting at. ;) "They already know they exist ..." doesn't really seem to match up? Like, of course they do. Anyway, I was just pointing out that the communication still seems pretty close to sending Apple the list of applications being run. At least, for applications created by dev's with only one major program for their certificate.
- ravenstine 6y ago> macOS does actually send out some opaque information about the developer certificate of those apps, and that’s quite an important difference on a privacy perspective. Yes, and no. If you're using software that the state deems to be subversive or "dangerous", a developer certificate would make the nature of the software you are running pretty clear. They don't have to know exactly which program you're running, but just enough information to put you on a list. > You shouldn’t probably block ocsp.apple.com with Little Snitch or in your hosts file. I never asked them to do that in the first place, so I'll be blocking it from now on.
- josephcsible 6y ago> I never asked them to do that in the first place, so I'll be blocking it from now on. Apple's working on making sure you can't block it. They already keep you from blocking their own traffic with Little Snitch and similar tools: https://news.ycombinator.com/item?id=24838816 https://news.ycombinator.com/item?id=24838816
- api 6y agoThe hosts file works for now. Use 127.0.0.1 and ::1 on two separate lines. Used tcpdump to verify.
- ravenstine 6y agoIsn't that just with Big Sur? Also, I'm using the hosts file method.
- anamexis 6y agoThe OP is about Big Sur.
- claudeganon 6y agoI don’t think it’s actually just in Big Sur. At the bottom of this post describing how to stop them from hiding traffic, they mention someone did a test on Catalina and ran into an issue with the Messages app: https://tinyapps.org/blog/202010210700_whose_computer_is_it.html https://tinyapps.org/blog/202010210700_whose_computer_is_it....
- deleted 6y ago[deleted]
- sz4kerto 6y agoCan someone explain my why is this significantly less problematic than sending out app hashes? If we accept that most developers don't have many similarly popular apps, then isn't this enough to infer what apps are users running? In the example from the article: if Mozilla's certificate is sent, then it's very likely that the app that has been opened is Firefox, as the a priori likelihood of using Firefox is way higher than eg using Thunderbird. If the developer is Telegram LLC, then ... and so on.
- api 6y agoThere are two issues here. One is the privacy problem which I agree is not quite as bad as some think. The second is the stupid fact that if some server goes down you can’t launch apps. That is just awful.
- the_duke 6y agoWhile other posts on this topic are too alarmist, this one is way too Apple apologetic for my taste. * There is no information on how often the validation happens. All this investigation concludes is that it doesn't happen when closing and immediately re-opening an app. Is it every week? Every reboot? Every hour? If it's less, that's essentially the same as doing it on every launch. * There is no justification for sending this information in cleartext. I don't follow the "browsers and loops" argument. This is a system-service that only has to trust a special Apple certificate, which can be distributed via other side-channels. * Many developers only publish a single app or a certain type of app. So it still is a significant information leak. It's really not much different from sending a app-specific hash. Think: remote therapy/healthcare apps, pornographic games, or Tor - which alone could get you into big trouble or on a watchlist in certain regions. I assume they will push a fix with better timeouts and availability detection. But Apple simply has to find a more privacy-aware system designs for this problem which does not leak this kind of data without an opt-in and also does not impact application startup times. (revocation lists?) I imagine this data might just be too attractive not to have. Such a "lazy" design is hard to imagine coming out of Apple otherwise.
- throwawayg123 6y agoWait. Is it not common knowledge that Android and iOS log every application you open down to the exact millisecond you open and close them? Is it not common knowledge how telemetry works for the operating systems? They generally batch up a bunch of logs like this, encrypt them, compress them, and then send them to the mothership (hopefully when you're on WiFi).
- randyrand 6y agodon’t you need to enable analytics?
- deleted 6y ago[deleted]
- kenniskrag 6y agofirst compressed and then encrypted. A good encryption is indistinguishable from random data.
- dmitriid 6y ago> Maybe the hash is computed only once (e.g. the first time you run the app) and it is stored somewhere. This would explain why some games take minutes to launch the first time to run them. I've experienced this many times with Steam. You install a game, you launch it, and nothing happens for up to several minutes, and then the game runs. No delays after in launching after that.
- jeffbee 6y agoThis behavior drives me crazy. The only way to figure out what's going on is to open the Activity Monitor. On my 2015 iMac (top-of-the-line, at the time) initial launch of some large games has taken tens of minutes, and it happens whenever the game is updated, not just after it is initially installed.
- pubkraal 6y agoIf anyone is concerned with ocsp activity and verifications being requested all over the web, then oh boy stay away from https. OCSP is a good thing, and the web - and your signed applications - are better off with it.
- feanaro 6y agoI guess you haven't heard of OCSP stapling? https://en.wikipedia.org/wiki/OCSP_stapling https://en.wikipedia.org/wiki/OCSP_stapling Active OCSP is far from being considered a good thing universally.
- brendoelfrendo 6y agoYeah, I feel like I'm taking crazy pills; did everyone just not know about OCSP until Apple did it? Spoiler alert, you've probably already used OCSP on the web.
- saagarjha 6y agoMost of the people affected by the issue have no idea what OCSP is.
- iso947 6y agoMost browsers are stopping ocsp because of the privacy use and the triviality to block it. Did Chrome ever do it? That’s why CT came around. Some background for those unfamiliar. https://scotthelme.co.uk/revocation-is-broken/ https://scotthelme.co.uk/revocation-is-broken/
- cute_boi 6y agoClearly this article doesn't reveal every truth. Certificates authority should have been decentralized but is it happening? And just by looking ip address, and app usage and other data they receive they can connect the data and identify its me. And what security has apple provided till now? "You shouldn’t probably block ocsp.apple.com with Little Snitch or in your hosts file." That's far better than freezing computer which doesn't work, doesn't run any apps. If I don't need apple mercy and protection please don't force me. Already installed Linux and its a start.
- vmateixeira 6y agoSo, not only apple, but pretty much everyone, can eavesdrop on the HTTP request and find out from which developer I'm running apps from?
- ThePhysicist 6y agoNot sure whether the non-privacy related aspect about OCSP is less worrying. Officially Apple does this to protect innocent users from malware, but as we've seen it also allows them to remotely disable any developers' software. Not really something that I'd want on my machine.
- judge2020 6y agoOCSP also allows CAs to revoke random websites’ certificates, yet nobody is making a big fuss about that (presumably because no OCSP server has encountered what Apple’s did and prevented websites from opening).
- ThePhysicist 6y agoYeah but the thing is that there are many CAs. The main problem is (IMHO) when you have a single party with conflicting commercial interests that controls all certificates for a given platform.
- tialaramex 6y agoYour reasoning is wrong. Other than Internet Explorer (and maybe Edge? I honestly have no idea) browsers don't do OCSP. This is because it's a huge privacy problem (as we saw here for Apple) and because the OCSP servers have too often been unreliable. Firefox has OCSP Must Staple, but in that scenario the remote web server is responsible for periodically ensuring it has a sufficiently up-to-date OCSP response about its own certificate which it then "staples" to the certificate to prove its identity. So if the OCSP server fails for an hour a good quality stapling implementation just keeps using older responses until it comes back. Also it's optional, most people haven't chosen to set Must Staple anyway. Everybody else has various CRL-based strategies, so your browser learns about certain important revocations, eventually, but it doesn't pro-actively check for them on every connection and thus destroy your privacy.
- cute_boi 6y agois there any statistics of how many innocent users have become victim? Clearly Apple just want control. Just like there is old saying More truth less trust is needed.
- musicale 6y ago> You should be aware that macOS might transmit some opaque information about the developer certificate of the apps you run. This information is sent out in clear text on your network. Wow, that is bad from a privacy perspective! Since certificate revocation is rare, it makes more sense to simply periodically update a list of revoked certificates instead of repeatedly checking each certificate. That would solve the privacy issue while still allowing certificates to be revoked. OCSP seems like a bad idea for web browsing for similar reasons.
- dabeeeenster 6y agoI don't quite understand why anyone would send data in clear text anymore, let alone Apple.
- douglasdrumz 6y agoIt's explained in the article, there's a loop if you want to verify a certificate and you need the certificate to verify the certificate
- pedro2 6y agoCheck server certificate OCSP first, send subsequent queries via SSL.
- lstamour 6y agoPrecisely. This would require more work, but it would only leak the OCSP server’s revocation request, and would make OCSP both more secure (caching OCSP server validity rather than the original certificates) and more private (due to SSL).
- sneak 6y agoYou can do unauthenticated TLS, which is no worse than plaintext HTTP, and foils passive listeners by providing privacy. You could also trust your existing trusted certs (prior to OCSP update) when doing the OCSP update, which, again, is no worse than plaintext HTTP. Apple knows this. They have cryptography experts. Taken in context with their backdooring of their e2e messenger and collaboration with military intelligence on FISA 702, I tend not to give them the benefit of the doubt any longer. Apple knows how to take pcaps. There are only so many times the OS design gets to leak either keys or plaintext remotely before you need to stop assuming ignorance over malice. I don’t know how many times that is, but it’s less than ten, probably less than 5, and because it’s a count of legitimate “assume ignorance”, then “goto fail”[2] also counts in the tally. Between this OCSP plaintext telemetry leak, and iMessage default key escrow, scrapping their plan for e2e backups at the behest of the FBI that fixes the key escrow backdoor[3], and “goto fail” not authenticating TLS, we’re at 4. I’m not even counting the recent story about Apple’s history of willing collaboration with intelligence agencies to make a custom classified firmware for the iPod to aid in espionage.[1] As Goldfinger’s famous saying goes: “Once is happenstance. Twice is coincidence. The third time it’s enemy action.” [1]: https://news.ycombinator.com/item?id=24212520 https://news.ycombinator.com/item?id=24212520 [2]: https://www.zdnet.com/article/apples-goto-fail-tells-us-nothing-good-about-cupertinos-software-delivery-process/ https://www.zdnet.com/article/apples-goto-fail-tells-us-noth... [3]: https://www.reuters.com/article/us-apple-fbi-icloud-exclusive/exclusive-apple-dropped-plan-for-encrypting-backups-after-fbi-complained-sources-idUSKBN1ZK1CT https://www.reuters.com/article/us-apple-fbi-icloud-exclusiv...
- neolog 6y agoSo Apple sends an app-developer identifier in clear text each time you open an app? That sounds really bad.
- lifeisgood99 6y agoBeing able to identify the developer of any app I run on my own machine is already too far. You have to assume all these requests are logged and available for state actors on legal demand. I wonder how big a local revocation list would be. I would support a on-by-default local check.
- jrockway 6y agoOCSP doesn't seem like the right protocol for this. Apple should probably just ship you a list of hashes of revoked certificates once a day, and should do the check locally. (Obviously, the global certificate database is too big to send to every user, but Apple should be able to determine the subset of certificates they trust, and the even smaller subset of those that are revoked or compromised.) To me, it sounds like they decided to take the quick-and-easy path of reusing an existing protocol for the use case of stopping malware, but it doesn't really fit. The latency, privacy, and availability guarantees of OCSP just don't match with the requirements for "run a local application".
- m463 6y agoThere might also be usage data they collect conveniently.
- Nightshaxx 6y agoI agree, how is sending a list of revoked certs not the best idea?
- ben509 6y agoGoing back to a CRL (certificate revocation list) for code-signing certs makes more sense. And, really, there shouldn't be a huge number of developer certs being revoked. If that's happening, they need to put more work up front into certifying them in the first place.
- wiml 6y agoThis does seem like a situation where a CRL would be a better fit than OCSP. On the other hand, CRLs have been pretty thoroughly deprecated for browser usage, so Apple probably just reached for the first tool that was already available to them.
- viraptor 6y agoIs actually the other way. Active ocsp checks have been removed some time ago: https://www.computerworld.com/article/2501274/google-chrome-will-no-longer-check-for-revoked-ssl-certificates-online.html https://www.computerworld.com/article/2501274/google-chrome-... Stapling and crl-shipped-with-browser still works.
- m463 6y ago> As you probably have already learned during Apple’s OCSP responder outage, you can block OCSP requests in several ways, the most popular ones being Little Snitch Uninformed advice - apple prevents little snitch from blocking this traffic in big sur.
- miles 6y ago>> you can block OCSP requests in several ways, the most popular ones being Little Snitch > Uninformed advice - apple prevents little snitch from blocking this traffic in big sur. You can prevent Apple from preventing Little Snitch from blocking that traffic: https://tinyapps.org/blog/202010210700_whose_computer_is_it.html https://tinyapps.org/blog/202010210700_whose_computer_is_it....
- istjohn 6y agoKeep reading. >If you use macOS Big Sur, blocking OCSP might not be as trivial.
- olliej 6y agoI get that a dev cert isn't the same as identifying the software itself... but that only applies for developers that have multiple apps, and I suspect most do not. Then unencrypted requests are also a Bad Thing, because anyone has access to the same info - it may require a lot of work to get general knowledge of what apps someone is using, but if you were looking for a specific one then I don't see any real difficulty identifying that. e.g. if I wanted to know if someone was using signal I just look for the signal cert being queried. That's a much easier problem, and can be dangerous to the end user.
- banachtarski 6y agoThere will be a day when all apps on a mac will only be installable from the app store. Developers will be forced to buy macs and subscribe to Apple’s developer program to support it. Customers will be trained to not care. And HN Apple fanboys and fangirls will try to justify why this is a Good Thing(TM).
- john_alan 6y agoTell me more about the future?
- macintux 6y agoWe’ve been hearing that for years, yet it hasn’t happened. Apple seems to recognize the value of the Mac as an general computing platform.
- banachtarski 6y agoIt keeps inching closer. You now have a unified arch between mobile and desktop. You were never officially able to cross compile before and now there’s yet another barrier. Phoned signing verification is another thing that is a precursor to distribution to Apple-only distribution.
- p2detar 6y agoNotarization was IMO the first big step towards this. To this day I have not heard anyone, neither devs nor users, wanting this feature. And to devs it has only costed misery and money.
- otterley 6y agoCustomers, for the most part, don't even know or care it exists. But customers will find value in it when Apple is able to quickly disable malware if it proves necessary. As for developers... I mean, how much of a big deal is it, really? I looked at the documentation and it didn't seem like a huge hassle. It even looks like it is automatable in your CI/CD processes via `altool` and `stapler`.
- jgilias 6y agoSo the takeaways are: * Your Mac periodically sends plain text information about the developer of all apps you open, which in most cases makes it trivial for anyone able to listen to your traffic to figure out what apps you open. Better not use a Mac if you're a journalist working out of an oppressive country. * Because of this Macs can be sluggish opening random applications. * A Mac is not a general purpose computing device anymore. It's a device meant for running Apple sanctioned applications, much like a smartphone. Which may be fine, depends on the use case. Yeah... No Mac for me anytime soon then.
- theodric 6y agoBy default, Android logs every app you use. You have to disable - bafflingly - features including saving locations in Google Maps and fully-functional voice recognition to (supposedly) disable that behavior. What I'm saying is: don't look so surprised.
- AntiImperialist 6y ago"By default" is key here. Apple doesn't allow to change this at all, unless you do a hosts file hack.
- dpacmittal 6y agoWhy compare a phone OS which is much more tightly controlled to a desktop OS?
- lern_too_spel 6y agoYou seem to be confusing sharing "usage and diagnostics" with enabling location history.
- theodric 6y agoTurn off usage and diagnostics and try to save a location in Google Maps. Alternatively, open up the usage and diagnostics stats and see just how much they harvest. It's, frankly, a ridiculous non-sequitur on the part of Google.
- lern_too_spel 6y agoIt is already off. I've always had it off. I have multiple locations saved in Google Maps.
- theodric 6y agoWeb & App Activity Saves your activity on Google sites and apps, including associated info like location, to give you faster searches, better recommendations, and more personalized experiences in Maps, Search, and other Google services. https://support.google.com/websearch/answer/54068 https://support.google.com/websearch/answer/54068
- pkuhar 6y agoi feel this is irrelevant. apple offers app analytics to developers. which means app usage data is going to apple anyway. https://developer.apple.com/app-store-connect/analytics/ https://developer.apple.com/app-store-connect/analytics/
- sneak 6y agoApp analytics is opt-in, and requires explicit advance consent.
- withinboredom 6y agoNow just waiting for the trolls to write some software that makes the response always cause it to be invalid. With a wee bit of ARP magic, you could make a bunch of mac users very unhappy at the cafe's.
- sneak 6y agoNo joke, this would get a fix published very quickly. I’m embarrassed I didn’t think of it myself.
- ArchOversight 6y agoOCSP responses are signed, so no, that doesn't work.
- SheinhardtWigCo 6y agoEvidently it does work if you simply suppress the response.
- jzer0cool 6y agoThere is a local save which manages your app Screen Time (App Settings -> Screen Time) but did not imagine hashes sent. How does one go about setting up (easy) server of some sort to see what servers are being connected say when investigating a different area?
- sbussard 6y agoApple has always been a gated community, but now there’s a guard at the gate checking everything that goes in and out. This is something most users probably don’t want. It has me personally considering what a future without Apple would look like.
- pram 6y agoIt's literally called Gatekeeper lol
- freeAgent 6y agoI’m more and more convinced that I’ve got to learn and find a way to make Linux work for me.
- sneak 6y agoThey’re not mutually exclusive. I have several macs and several linux machines. One of the linux machines (my router) even keeps the macs safe and (relatively) trustworthy. It’s a good thing to do regardless. I also know way more than I want to about Windows, too, and could make do if given only that for a workweek. Learn languages, learn OSes, learn architectures. Get more computers. :)
- heavyset_go 6y agoCheck out these posts I posted about transitioning to Linux from macOS and feeling at home[1]. I made the switch and I'm not looking back. [1] https://news.ycombinator.com/item?id=23607374 https://news.ycombinator.com/item?id=23607374
- hawski 6y agoThe guard is also shouting brand names of things you carry in your bag.
- bitmunk 6y agoYeesh, "It's not THAT bad, it ONLY leaks the developer of every app you open, via cleartext. Oh, and it cripples your offline software when someone spills coffee over Apple's servers" This is the reason people laugh at this website.
- sneak 6y ago“It doesn’t send a hash of the app, it sends a thing that is a encoded hash that uniquely identifies the app! Totally different!” It wasn’t a misunderstanding, it was a simplification so that people could understand the issue without me explaining OCSP and app signing and x509 and the PKI. Dozens of people wrote me to thank me for explaining it in a way that they could understand. It is indeed a hash, and it does indeed uniquely identify most apps, and it is indeed sent in plaintext, when you launch the app (and is cached for a half day IIRC). I very deliberately didn’t claim it is a hash of the content of the app file. It also doesn’t send a unique identifier, but I would be willing to wager that the set of apps that you launch in 48h is probably enough to uniquely identify your machine in the vast majority of cases.
- kzrdude 6y agoYour text was understood that way because of something in the words you chose, maybe "hash of the application" for example.
- arexxbifs 6y agoITT: Arguing what semantics to use when whitewashing a massive breach of trust, privacy and security with no officially solicited opt out.
- Syzygies 6y agoWe need a version of Little Snitch that allows these reports to reach Apple, modified so the app appears to always be "Go fuck yourself".
- bitL 6y agoAre there any pi-hole settings to prevent Apple from phoning home? And the same for Windows 10? I can't trust my computers any longer so I need to rely on external enforcement.
- _qulr 6y agoA caveat to blocking ocsp.apple.com is that I discovered Apple is running more than one service on that domain. http://ocsp.apple.com/ocsp-devid01 http://ocsp.apple.com/ocsp-devid01 is Developer ID, but http://ocsp.apple.com/ocsp03-apevsrsa2g101 http://ocsp.apple.com/ocsp03-apevsrsa2g101 is something else, which if blocked can prevent the Mac App Store from loading.
- Cloudef 6y agoWouldn't it be hilarious to mitm these requests at open hotspot and basically cripple everyone's macs while connected.
- spullara 6y agoI have always been annoyed by OCSP being HTTP. It is really the fault of the standard that this is the way we revoke certificates. I basically agree that Apple should just be downloading revoked certificates and checking them locally. This is what we are doing at various SaaS companies that have to check these in order to avoid downtime. We have also mistakenly failed-closed. We now default to fail-open but customers have the option to change that if they are paranoid.
- gjsman-1000 6y agoI would be surprised if Apple doesn't make changes to this system after this incident.
- chimen 6y agoDo they bypass/circumvent firewalls doing that? That's the question you have to ask, not what they send (now).
- 29athrowaway 6y agoOut of the loop: How does this compare to MS Windows telemetry?
- stmfreak 6y agoYes.
- jijji 6y agowhatever happened to letting the user decide which application they wanted to run? now the mothership has to give their blessing before they let you run it... sounds insane.
- orionblastar 6y agoWe have been warned and ignored the warning: https://prism-break.org/en/ https://prism-break.org/en/
- sildur 6y agotldr: no, but yes. It logs app certificate requests which in real life is pretty much equivalent to logging app runs. And that line about only calling the server from time to time is bullcrap. I have years of experience on this issue because my internet is pretty shitty. And that "from time to time" is every couple of hours.
- Pelam 6y agoTechnically AFAIK, the revocation list could be turned into a Bloom filter (or one of its alternatives) and updated from the servers periodically. edit: on 2nd thought just a list of hashed cert ids could suffice because it is hard to imagine there ever being thousands of revocations. That way the provider would have no knowledge of which certs are being verified.
- omk 6y agoIf this is just a matter of revoked certificates, Apple could very easily setup a subscription for developer certificates on the machine when an app is installed. Why wait to check if a certificate is revoked once an app is launched?
- Thomaschaaf 6y agoBecause it allows to revoke certificates at a later time. E.g. epicgames certificate was revocable after they noticed that they built in something that was not supposed to be allowed.
- randomtree 6y agoVery curious, what's opaque about a uniq developer id of an app you start? Sure looks like gaslighting. "You should be aware that macOS might transmit some opaque information..."
- polack 6y agoThe request obviously sends lots more information than just the serial number of the developer certificate. Is it "harmless" data or could they have more info about the executable in there? Why don't the author post the OCSP request of Thunderbird too? And how about another request for Firefox so we can compare the data? This article really doesn't clear anything up for me...
- xalava 6y agoThe fact that this was included in the OS without raising alarms is quite revealing in terms of privacy concerns. Question, is there a good justification to use not use hierachical certificates like web browsers or other OSes ?
- rStar 6y agoin my opinion, this seems like Apple, once a computer company that catered to computer users and the expectations of computer users, is now a mobile phone company catering to and responsive to the lower expectations of phone users. to engineer these plain text surveillance communications over the public internet between a users private computer and the company responsible for building that computer is like if my home informed the company that built my home every time I started any unique activity while inhabiting said home, as long as I hadn’t been engaged in that activity for some amount of time. It’s extremely disrespectful to Apples users, who are also Apples customers, who are also mostly all of us on this message board. My goal is to one day grow a backbone and stop putting up with this.
- bywaterstreet 6y agoGood write-up. I write a lot of Go on my Mac at home. The first run is _always_ slow, but I've never measured it or bothered to find out why. This is a real "lightbulb moment" for me. I just built a Go executable and timed it: 0.194 for the first, and ~0.018 for subsequent. I haven't signed code on Mac platforms before, so I figured I'd give it a go using the Apple code signing guide [0]. So, I created a self-signed certificate using Keychain, changed and built a Go project, signed the executable [1], and ran it: ~0.400 for the first run, and ~0.018 for subsequent. It... doubled? Will this happen on every first run still? Is there a way to exclude executables? [0] https://developer.apple.com/library/archive/documentation/Security/Conceptual/CodeSigningGuide/Procedures/Procedures.html https://developer.apple.com/library/archive/documentation/Se... [1] codesign -s <cert_id> <path>
- kzrdude 6y agoTo be generous, Apple has unwittingly created an app use surveillance possibility. All from the idea of developer certificates and diligent revocation checks.
- xbar 6y agoApple's decisions about OCSP decry two indisputable facts that contradict Apple marketing: Apple does not prioritize privacy. Apple does not prioritize availability.
- treeman79 6y agoWorked a major virus company. This was the same Basic technique. W e would download a list of all md5 hashes. All executables would have to match against it. Periodically there would be an issue downloading the updates. Would result in similar problems. Managing size of updates was a big issue. Just checking against an online server is certainly a more up to date approach
- micheljansen 6y agoThis still allows Apple (and ISPs, employers etc) to correlate very sensitive information: developer certificates and IP addresses. Plenty of developers only create one application, and most Macs will be used most frequently on a small number of (ranges of) IP addresses. In essence that still let’s Apple see way more than a self-proclaimed “privacy conscious” company should. Why not take a more privacy-centric approach? Antivirus companies have been working with “virus definitions” for ages. Ad blockers use the same model, but for locally stored blacklists. Why can Apple not regularly download a list of revoked certificates and maintain it locally?
- mcnichol 6y agoIt feels like this is the type of response where we were at with Windows when they were forcing updates etc. They backpedaled a little bit when you were forced to log in through a Microsoft account and people semi-rioted but came back pretty strong.
- mrcybermac 6y agoI see no reason why OCSP checks on developer certificates cannot be encrypted. This whole "oh no there could be a loop for a SSL cert check" argument seems like gaslighting. Why can't the client know if it wants to access an OCSP server using HTTP or HTTPS, and default to HTTPS when possible?