3 ms·
It may be worth noting that we do not really know what do they mean by "logs". These can be either database records or simply text logs generated by a web serve
by evercast 6y ago
It may be worth noting that we do not really know what do they mean by "logs". These can be either database records or simply text logs generated by a web server sitting in front of the OCSP backend and logging the requests, regardless of what those requests are referring to. In other words, it does not have to be a conscious decision to "harvest IP addresses" but could easily be a side-effect of what the infrastructure does.
Still, it is no excuse for them as one would expect clear and thorough security/privacy audits before rolling out such features. Especially from companies like Apple.