8 ms·
Interesting, but reading the conclusion I'm fascinated in this affaire how technically knowledgeable people loose common sense to defend their favorite brand: -
by xalava 6y ago
Interesting, but reading the conclusion I'm fascinated in this affaire how technically knowledgeable people loose common sense to defend their favorite brand:
- Per launch verification is terrible for privacy, vis-a-vis Apple and the whole network when it happens in plain text
- "They should also explain how, having enjoyed their benefits for a couple of years, they’ve suddenly decided they were such a bad idea after all", another key issue: user information, consent and control.
- Additionally, the public was made aware because it malfunctioned, which is also a security issue.
- Considering the current corporate culture, there are legitimate concerns of what those choices might lead towards
- netsharc 6y agoYeah, the article's last paragraph irks me... to reformulate it in the context of domestic spying, it'd be like saying "NSA's communication monitoring have kept you safe for years, now that you've heard of it, you decide it's a bad idea?". Most people probably never noticed this phone-home feature existed, just like they never knew that NSA was recording everything. (Obviously anyone who bothered to look under the hood could've seen it, but hey, how many people do that).
- Ar-Curunir 6y agoThe Apple thing was not designed for explicit mass-surveillance; NSA’s programs are. That’s kind of a big difference.
- mhh__ 6y agoI think there's an element of people desperately wanting to believe that apple is their tribe, rather than just another company. I can believe Apple do care about privacy, but ultimately they're just another company. For example, I'm sure apple would love the Epic lawsuit to be decided based on a poll of HN users - "I would rather not have the freedom to run whatever I want, because [insert bizarre anecdote]". Don't project your own beliefs onto apple, vote with your wallet if they annoy you - it's just a trackpad.
- blub 6y agoCould the people that vote with their wallet please also stop caring about Apple so much, to the extent that they have to rescue those that are still Apple customers and nitpick anything Apple-related to bits? Take a clean break, it's healthier that way.
- thinkingemote 6y agoNo-Logo by Naomi Klein outlined how brands work. One factor in the irrational defence could be a kind of psychological protection of investment. Apple isnt just another company, its an entire lifestyle ecosystem. Those invested in Apple have the watch, tv, laptop, itunes etc. And together they really do "just work" - the user experience is great! So to admit that Apple is flawed, that their investment was a bad idea is to admit they were wrong and that their time and money was wasted. No-one wants to be a sucker. Far better therefore to protect your investment. Apple really are genius to pull this off. Apple is part of people's identity.
- nbzso 6y ago"One factor in the irrational defence could be a kind of psychological protection of investment." The Author of this publication is clearly invested deeply in Apple ecosystem as a developer. One of the reasons that I consider using Mac OS behind hardware firewall in the future is clear realisation of this process. This telemetry malpractice clearly must be prevented by legislative measures. Trust is earned by transparency, not by some kind of Security slogans.
- blub 6y agoBut they're not wrong at all and their time and money was well invested. The ecosystem does just work and the user experience is great compared to the alternatives. It's also possible to use only specific products and switch off various cloud or telemetry options. There's still a long way to go to reach a private OS, but Apple has by far the best privacy stance when compared to Google or Microsoft and there is nobody who offers such an OS right now. The best one can hope for is build their own Linux-based distro or use BSD and then one has to be prepared to invest a significant amount of time. Apple didn't get challenged through the GDPR yet because everyone's busy with Google and Facebook still. But, if you or anyone else would like to lodge a complaint, maybe this will be decided for the customers (I think it's borderline) and we'll get an option to switch it off.
- krrrh 6y agoThe article points out that while there are drawbacks to checking app signatures, there have also been documented benefits in terms of uncovering vulnerabilities and making systems more secure, which also has direct privacy benefits to the users whose systems don't become compromised by malware. The balancing act between freedom and security is never going to not be a debate. Engaging in it in good faith as in the linked article is a reasonable approach (that you don't usually see represented in Klein's oeuvre): consider tradeoffs, counterarguments, and historical context from different perspectives. Apple is flawed sure, because all complex solutions are inherently flawed. They have a responsibility to be more open and transparent, and I'd prefer to see more details and updates to their otherwise laudable security whitepaper [1], and clearer more accessible user-definable toggles. But your or my preferred solution probably isn't the ideal default for most users, or for the ecosystem as a whole. [1] https://manuals.info.apple.com/MANUALS/1000/MA1902/en_US/apple-platform-security-guide.pdf https://manuals.info.apple.com/MANUALS/1000/MA1902/en_US/app...
- rootusrootus 6y ago> how technically knowledgeable people loose common sense to defend their favorite brand Someone who says this usually holds an opposing position and simply has their own tribal allegiance. Perhaps assume good faith on the part of those who do not make the same choices you do.
- valuearb 6y agoHow is certificate checking a terrible idea? It doesn’t leak the application name or any personal information, and Apple doesn’t store it permanently.
- ogre_codes 6y agoIt initially logged IP address and the associated developer ID which was a genuinely bad idea. They've stopped logging IP address now. The concept here is fine, they just screwed the pooch a bit on implementation. And as usual, HN blew it out of proportion.
- saagarjha 6y agoDeveloper ID is an extremely good proxy for application name.
- ogre_codes 6y ago> I'm fascinated in this affaire how technically knowledgeable people loose common sense to defend their favorite brand What I find weird is regardless of what the discussion is involving Apple, someone needs to pop in with one of these theories about Apple tribalism. Very very few people are in fact "defending" Apple here. Even among those few, the sentiment is largely that this is bad and Apple is fixing it.
- saurik 6y agoI presume the comment is about the article, which it quotes, so it doesn't matter how few such people exist.
- ogre_codes 6y agoIt takes some serious mental gymnastics to see how that part of his comment relates to the article.
- athms 6y ago>I'm fascinated in this affaire how technically knowledgeable people loose common sense to defend their favorite brand...when it happens in plain text I'm fascinated how technically knowledgeable people don't understand OCSP. Checking the revocation status of certificates is why OCSP was created. It happens via HTTP. Why? Because you cannot check a certificate used for the HTTPS connection when you are using HTTPS for the connection. Apple leveraged OCSP for Gatekeeper since it does the same thing, checking certificates, in this case a developer certificate. That is all it does.
- moduspol 6y agoIt's also easy to imagine what the blog posts would look like if they did the same thing except over TLS--in a way that the harmlessness / purpose of the request was not immediately apparent. I agree with you, though--it seems like they solved a valid problem with the most obvious, commonly-used solution. The real debate is probably just over whether or not the problem is a sufficiently large threat to justify the downsides.
- deleted 6y ago[deleted]