8 ms·
They should care. The checks are sent unencrypted over HTTP to Apple's OCSP.
by grupthink 6y ago
They should care. The checks are sent unencrypted over HTTP to Apple's OCSP.
- valuearb 6y agoSince they don’t identify specific apps you use, so what’s your point?
- throwaway525142 6y agoAs far as I understand it, most vendors ship a single digit amount of apps. If you start the Tor browser, everyone on your network will know. If you start Firefox, everyone on your network will know you started a Mozilla product, most likely Firefox. If you start the Zoom client, everyone on your network knows you started the Zoom client. I don't think the "it's only the vendor" defense of Apple is any good.
- athms 6y agoOn MacOS, developer certificate requests are NOT done for every application launch. Responses are cached for a period of time before a new check is done. FYI -- Both Firefox and Safari use OCSP to check server certificates. Anybody sniffing your network could figure out which websites you visit. Chrome still uses CRL; it trades precision for performance.
- pseudalopex 6y agoThat period of time was 5 minutes.
- athms 6y agoHTTP is specified in the RFC. Only the developer certificate is checked. OCSP is also used by web browsers to check the revocation status of certificates used for HTTPS connections. Apple leveraged OCSP for its Gatekeeper functionality. This is not the same thing as notarization, which is checked over HTTPS. https://blog.jacopo.io/en/post/apple-ocsp/ https://blog.jacopo.io/en/post/apple-ocsp/ Perhaps you should learn about OCSP before complaining about its use of HTTP.
- samatman 6y agoVendors MAY use TLS, and Apple didn't (though they say they'll start). You might want to read the RFC, rather than a blog post about it, before making such confident pronouncments.