5 ms·
The log censorship _has_ to be because sketchy / malicious apps are reading private data from the log. And it seems pretty obvious that the greater good is achi
by e28eta 3y ago
The log censorship _has_ to be because sketchy / malicious apps are reading private data from the log. And it seems pretty obvious that the greater good is achieved by blocking that personal data.
As a user, I certainly wish there was a logging level / filter / setting of “things that are broken that you can do something about”, along with the ability to dig into the underlying trace data that helps you better understand details about the problem. But I think it’s pretty clear to everyone that’s not the user that Apple is solving for. Even if you did have a clear bug & root cause, good luck getting it acknowledged & fixed through their public-facing bug tracker.
- lapcat 3y ago> The log censorship _has_ to be because sketchy / malicious apps are reading private data from the log. No, they aren't: "Currently, the only way to see unmasked log entries is through a special profile."
- zshrc 3y agoThese profiles are provided by Apple for the explicit use of debugging... what makes you think bad faith actors wouldn't take advantage of harvesting such juicy data? Especially at the verbose rate macOS provides...
- lapcat 3y ago(1) Very few Mac users have installed the private log debugging profile. (2) The number of Mac users who have both installed the private log debugging profile and also installed malware without knowing it is vanishingly small. (3) People mostly use the profile temporarily and then uninstall it, so even in the vanishingly small number of cases, the window of opportunity is a lot smaller. It would be a lot of effort for no return. Bad faith actors are looking for easy, plentiful targets. Expert users who comb the logs are the opposite of that. In fact, it's a great deal of effort to find useful information in the logs even for good faith actors looking at their own machines, because of the loquaciousness of the OS.
- hirsin 3y ago> Bad faith actors are looking for easy, plentiful targets Citation needed, especially when we know that spear phishing is the simplest of the known exceptions to this. I.e. https://news.ycombinator.com/item?id=37720580 https://news.ycombinator.com/item?id=37720580
- alpaca128 3y agoHave you ever looked into the average email inbox? 99% of bad actors are simply casting a net as wide as they can to find the most gullible people. Targeted, specialized attacks are rare.
- dspillett 3y ago> Targeted, specialized attacks are rare. But people basing their routines around the assumption that it won't happen to them, is why some notable attacks have succeeded. Obviously you need to base your practises around your own risk profile and their will be a point of limited likelihood of useful return on effort that will be different for different people/organisations, but some should be paranoid enough to worry about that other 1% of attempts.
- lapcat 3y agoHow exactly is a bad faith actor going to spearfish [people who have temporarily installed the Apple private logging profile]? And why? What exactly do people like Howard, the article author, and me have in our private debugging logs that's interesting, useful, and worth spearfishing specifically people like us? Keep in mind, crucially, that the aerospace employees were publicly known via LinkedIn to be aerospace employees. How is it publicly known who has temporarily installed the Apple private logging profile? Who besides the article author would even announce that publicly? Also, the value of hacking an aerospace company is known. You can come up with any conspiracy theory you like, but the level of plausibility in this case is nonexistent.
- j16sdiz 3y agoThose profiles need user interaction to enable. (unless that is a enterprise managed device)
- saagarjha 3y agoNope, it’s so when you send them a sysdiagnose it doesn’t obviously contain your email and your entire browsing history