15 ms·
Mac OS calls home every time you execute an application. Apple is well on its way to ensure you can only run things they allow via app store, they would probab
by dmz73 2y ago
Mac OS calls home every time you execute an application.
Apple is well on its way to ensure you can only run things they allow via app store, they would probably already be there if it wasn't for the pesky EU.
If you send your computer/phone to Apple for repair you may get back different physical hardware.
Those things very much highlight that "your" Apple hardware is not yours and that privacy on Apple hardware does not actually exist, sure they may not share that data with other parties but they definitely do not respect your privacy or act like you own the hardware you purchased.
Apple marketing seems to have reached the level indoctrination where everyone just keeps parroting what Apple says as an absolute truth.
- leokennis 2y agoAt the very least Apple are better than Microsoft, Windows and the vendors that sell Windows laptops when it comes to respecting user experience and privacy.
- HeckFeck 2y agoI switched to iPhone after they added the tracker blocking to the OS. Everything is a tradeoff. I’d love to live in the F droid alt tech land, but everything really comes down to utility. Messaging my friends is more important than using the right IM protocol. Much as I wish I could convince everyone I know and have yet to meet to message me on Signal or whatever, that simply isn’t possible. Try explaining that I am not on Whatsapp or insta to a girl I’ve just met… Also it is nice to spend basically no time maintaining the device, and have everything work together coherently. Time is ever more valuable past a certain point.
- bboygravity 2y agoThat's a low bar for girls IMO (not being able to grasp that someone might not want to use Whatsapp or Instagram).
- FuturisticGoat 2y ago[dead]
- geysersam 2y agoBut why do we have to choose between convenient and open? Why are these companies allowed to continue having these protected "gardens"? I don't believe a free and truly open ecosystem for mobile devices would actually be less convenient than iOS or Android. If anything it would be vastly better.
- stephenr 2y agoHas it occurred to you that the stronger control of the ecosystem is a feature that supports the convenience and integration that's possible? This is just the "Why not Linux desktop" argument from the past two decades. Sure, in theory it can be configured to do a lot of different things. But you're probably gonna have to work out the details yourself because the downside of theoretically supporting everything is that it's impossible to just have it work out of the box with every single scenario.
- cryptoegorophy 2y agoThey have big numbers. Big numbers tell that 95% of people would need to be in closed protected gardens rather than getting slaughtered by open source wolves.
- lukev 2y agoI mean, the security features are pretty well documented. The FBI can't crack a modern iPhone even with Apple's help. A lot of the lockdowns are in service of that. I'm curious: what hardware and software stack do you use?
- misiek08 2y agoFBI and Apple „can't”, but 3rd party do and they do it cheaper every day.
- lukev 2y agoThey do not. Edit: I have not posted a source for this claim, because what sort of source would be acceptable for a claim of the form "X has not occurred"? If you are going to claim Apple's security model has been compromised, you need not only evidence of such a compromise but also an explanation for why such an "obvious" and "cheap" vulnerability has not been disclosed by any number of white or grey-hat hackers.
- dankwizard 2y agoYes they do.
- lukev 2y agoIf you're going to claim that random hacking groups routinely do something the FBI and NSA claim to be unable to do... citation needed.
- makeitdouble 2y agoAn issue with taking their claim at face value is they have no incentive to say they can: - they can keep asking for backdoors to "stop terrorists" - they're not on the hook if for whatever reason they can't access a particular phone in a very mediatized case - most targets (the not so sophisticated ones at least) keep using a device the agencies have proper access to Regardless of their actual technical means, I don't expect we ever get a "we sure can!" kind of public boasting any time soon.
- hilux 2y ago> If you send your computer/phone to Apple for repair you may get back different physical hardware. I happen to be in the midst of a repair with Apple right now. And for me, the idea that they might replace my aging phone with a newer unit, is a big plus. As I think it would be for almost everyone. Aside from the occasional sticker, I don't have any custom hardware mods to my phone or laptop, and nor do 99.99% of people. Can Apple please every single tech nerd 100% of the time? No. Those people should stick to Linux, so that they can have a terrible usability experience ALL the time, but feel more "in control," or something.
- onepointsixC 2y agoWhat makes you think it would be a new one as opposed to a refurbished used one.
- Cthulhu_ 2y agoIf the parts show no signs of wear and tear, what is the difference? Theseus' iPhone.
- schmidtleonard 2y agoI've seen a few Rossman streams with officially "refurbished" macbooks that were absolutely foul inside. Boards that looked like they had been left on a preheater over lunch, rubber wedges to "cure" a cracked joint, all sorts of awful shit. The leaked stories from the sweatshop that did the work were 100% consistent with the awful quality. Admittedly this was a few years ago. Has apple mended their ways or are they still on the "used car salesman" grindset?
- sgerenser 2y agoAre these Apple refurbished, or bought from a third party like Best Buy or Amazon? I’ve bought plenty of Apple refurbished products (directly from Apple) over the years and they always look like new (including 100% battery health). Third parties and resellers though I’m convinced just call their returns/open box units that appear to be in decent condition “refurbished.”
- wslh 2y agoEven if I have analytics disabled? Genuinely asking: are there any specifics on this? I understand that blocking at the firewall level is an option, but I recall someone here mentioning an issue where certain local machine rules don’t work effectively. I believe this is the issue [1]. Has it been “fixed”? [1] https://appleinsider.com/articles/21/01/14/apple-drops-exclusion-list-which-allowed-its-own-apps-to-bypass-firewalls https://appleinsider.com/articles/21/01/14/apple-drops-exclu...
- angott 2y agoThey're probably referring to the certificate verification that happens when you open any notarized application. Unless something changed recently, the system phones home to ensure its certificate wasn't revoked.
- astrange 2y agoIt doesn't do that on every app launch; there's a cache. It does it on the first launch of a binary from a new team. (So multiple binaries with the same team don't check either.) And I'd expect all logging is disabled on the CDN.
- FireBeyond 2y agoI have no reason to expect that it is.
- jq-r 2y agoIt does kind of suck if the binary is frequently updated, big and you have a slow internet connection. So some program which normally takes seconds to open can take 20 or more seconds to open after an update. Or if you don't use that program frequently, you always get a very slow start of a program.
- weikju 2y ago> Even if I have analytics disabled? Yeah because what’s being sent is not analytics but related to notarizarion, verifying the app’s integrity (aka is it signed by a certificate known to Apple?) This came to light a few years ago when the server went down and launching apps became impossible to slow… https://www.macrumors.com/2020/11/12/mac-apps-not-opening/ https://www.macrumors.com/2020/11/12/mac-apps-not-opening/
- robenkleene 2y ago> Apple is well on its way to ensure you can only run things they allow via app store I don't think Apple's behavior actually reflects this if you look closely (although I can certainly see how someone could form that opinion): As a counter example, Apple assisted with their own engineers to help port Blender to Metal (https://code.blender.org/2023/01/introducing-the-blender-metal-viewport/ https://code.blender.org/2023/01/introducing-the-blender-met...): > Around one year ago, after joining the Blender Development Fund and seeding hardware to Blender developers, Apple empowered a few of its developers to directly contribute to the Blender source code. I'm assuming similar support goes to other key pieces of software, e.g., from Adobe, Maxon, etc... but they don't talk about it for obvious reasons. The point being Apple considers these key applications to their ecosystem, and (in my estimation at least) these are applications that will probably never be included in the App Store. (The counterargument would be the Office Suite, which is in the App Store, but the key Office application, Excel, is a totally different beast than the flagship Windows version, that kind of split isn't possible with the Adobe suite for example.) Now what I actually think is happening is the following: 1. Apple believes the architecture around security and process management that they developed for iOS is fundamentally superior to the architecture of the Mac. This is debatable, but personally I think it's true as well for every reason, except for what I'll go into in #2 below. E.g., a device like the Vision Pro would be impossible with macOS architecture (too much absolute total complete utter trash is allowed to run unfettered on a Mac for a size-constrained device like that to ever be practical, e.g., all that trash consumes too much battery). 2. The open computing model has been instrumental in driving computing forward. E.g., going back to the Adobe example, After Effects plugins are just dynamically linked right into the After Effects executable. Third party plugins for other categories often work similarly, e.g., check out this absolutely wild video on how you install X-Particles on Cinema 4D (https://insydium.ltd/support-home/manuals/x-particles-video-manual/installation-guide-osx/ https://insydium.ltd/support-home/manuals/x-particles-video-...). I'm not sure if anyone on the planet even knows why, deep down, #2 is important, I've never seen anyone write about it. But all the boundary pushing computing fields I'm interested in, which is mainly around media creation (i.e., historically Apple's bread-and-butter), seems to depend on it (notably they are all also local first, i.e., can't really be handled by a cloud service that opens up other architecture options). So the way I view it is that Apple would love to move macOS to the fundamentally superior architecture model from iOS, but it's just impossible to do so without hindering too many use cases that depend on that open architecture. Apple is willing to go as close to that line as they can (in making the uses cases more difficult, e.g., the X-Particles video above), but not actually willing to cross it.
- GeekyBear 2y ago> Mac OS calls home every time you execute an application Consulting a certificate revocation list is a standard security feature, not a privacy issue.
- derefr 2y agoFurther, there is a CRL/OCSP cache — which means that if you're running a program frequently, Apple are not receiving a fine-grained log of your executions, just a coarse-grained log of the checks from the cache's TTL timeouts. Also, a CRL/OCSP check isn't a gating check — i.e. it doesn't "fail safe" by disallowing execution if the check doesn't go through. (If it did, you wouldn't be able to run anything without an internet connection!) Instead, these checks can pass, fail, or error out; and erroring out is the same as passing. (Or rather, technically, erroring out falls back to the last cached verification state, even if it's expired; but if there is no previous verification state — e.g. if it's your first time running third-party app and you're doing so offline — then the fallback-to-the-fallback is allowing the app to run.) Remember that CRLs/OCSP function as blacklists, not whitelists — they don't ask the question "is this certificate still valid?", but rather "has anyone specifically invalidated this certificate?" It is by default assumed that no, nobody has invalidated the certificate.
- phs318u 2y agoThis reply is very informative and should be much more visible given the extent of general ignorance about the "zomg it phones home" feature.
- sooheon 2y agoWhy is it that non app store apps refuse to run until I explicitly allow it in settings then?
- spacedcowboy 2y agoI have literally never experienced that and I use homebrew apps a lot Perhaps you turned some "make things ultra-secure" setting on at some point ?
- sgarland 2y agoWith the sheer number of devs who use Macs, there is a 0% chance they’re going to outright prevent running arbitrary executables. Warn / make difficult, sure, but prevent? No.
- beeflet 2y agoThe strategy is to funnel most users onto an ipad-like platform at most where they have basic productivity apps like word or excel but no ability to run general purpose programs. Meanwhile you have a minimal set of developers with the ability to run arbitrary programs, and you can go from there with surveillance on MacOS like having every executable tagged with the developer's ID. The greater the distance between the developer and the user, the more you can charge people to use programs instead of just copying them. But you can go much further under the guise of "quality control".
- m-s-y 2y ago> The strategy is to funnel most users onto an ipad-like platform at most where they have basic productivity apps like word or excel but no ability to run general purpose programs. And you know this how? This reads like every macOS fan’s worst nightmare, but there’s zero actual evidence that Apple is going in this direction. Please share sources if you disagree.
- ddingus 2y agoIf so, they are executing it badly. As for every executable being tagged, that is not required. People can build binaries with open tools and other people can run them. A hash gets created for Apple to play same or different with binaries found to be nefarious somehow. Seems like a reasonable proposition.
- robotresearcher 2y ago> The strategy is to funnel most users onto an ipad-like platform They make the best selling laptop in the world, and other most-popular-in-class laptops. If their strategy is to have people not use laptops, they are going about it funny.
- abrookewood 2y agoTheir repair policy, from what I can see, is a thinly veiled attempt to get you to either pay for Apple Care or to upgrade. I got a quote to repair a colleague's MacBook Pro, less than 2 years old, which has apparent 'water damage' and which they want AUD $2,500 to repair! Of course that makes no sense, so we're buying a new one ...
- traceroute66 2y ago> to get you to either pay for Apple Care The problem with many self-repair people is they effectively value their time at zero. I value my time realistically, i.e. above zero and above minimum wage. It is therefore a no brainer for me to buy AppleCare every ... single ..time. It means I can just drop it off and let someone else deal with messing around. I also know how much hassle it is. Like many techies, I spent part of my early career repairing people's PCs. Even in big PC tower cases with easy accessibility to all parts its still a fucking horrific waste of time. Hence these days I'm very happy to let some junior at Apple do it for the cost of an AppleCare contract.
- codazoda 2y agoThat is not why I didn’t buy Apple Care. My hope is that the machine will work for a long while, like most of them do. In my case it’s a ~$1200 machine so I prefer to self-insure. I’m taking the chance that if it goes bad, I’ll pay to fix or replace it. This makes sense, for me, when I do it on everything that I buy.
- jorvi 2y ago> The problem with many self-repair people is they effectively value their time at zero. Back in 2010 Apple quoted me €700 for a topcase replacement because of shattered display glass. Instead I paid €50 for a third party replacement pane and did 15 minutes of work with a heat gun. What's more, they fold most of the cost of the repair into the price of parts. So you can either get a replacement screen for €499 and install it yourself, or have it officially repaired for €559. This effectively subsidizes official repairs and makes DIY repairs more expensive. Apple does extreme gouging with repairs, its hogwash to claim anything else.
- traceroute66 2y ago> Apple is well on its way to ensure you can only run things they allow via app store I'm very happy to only run stuff approved on Apple's app store... ESPECIALLY following their introduction of privacy labels for all apps so you know what shit the developer will try to collect from you without wasting your time downloading it. Also have you seen the amount of dodgy shit on the more open app stores ?
- freefaler 2y agoIt's a reasonable choice to do so and you can do it now. The problem starts when Apple forbid it for people who want to install on their computer what they want.
- Razengan 2y ago> where everyone just keeps parroting what Apple says as an absolute truth. You are free to verify.
- deleted 2y ago[deleted]
- idontwantthis 2y ago> Apple is well on its way to ensure you can only run things they allow via app store, What are you talking about? I don’t run a single app from the app store and have never felt a need to.
- kcplate 2y ago> Apple is well on its way to ensure you can only run things they allow via app store I am totally ok with this. I have personally seen apple reject an app update and delist the app because a tiny library used within it had a recent security concerns. Forced the company to fix it.
- 1596025359 2y agoWhat about all those libs and executables you likely install via brew, npm, cargo etc? Those are all applications
- spacedcowboy 2y agoAnd, despite being an avid homebrew user, I've never had a problem there.
- ddingus 2y agoAll of us having this discussion are outliers. The things we talk about here which annoy us are for the much larger set of people who need them! Put another way, it is all about the set of us who cannot really participate in this discussion.
- sealeck 2y agoSure – Apple are trying to stop people who don't know what they're doing from getting hurt. Hence the strong scrutiny on what is allowed on the App Store (whether it's reasonable to charge 30% of revenue is an entirely different question). People who are installing things using a terminal are probably (a) slightly computer savvy and (b) therefore aware that this might not be a totally safe operation.
- eviks 2y agoNo one is stopping you from using only the app store if you value its protection, so you need a more relevant justification to ok forcing everyone else to do so
- spacedcowboy 2y agoThey send a hash of the binaries/libraries, and generate a cache locally so it's not sent again. That helps stop you from running tampered-with binaries and frameworks. No user-personal data is sent. There is no evidence at all that they are trying to ensure you can only run things from the App Store - I run a whole bunch of non-app-store binaries every single day. To make that claim is baseless and makes me de-rate the rest of what you write. There is always a trade-off between privacy and security. This still falls well under the Google/Android/Chrome level, or indeed the Microsoft/Windows level with its targeted ads, IMHO. Choose your poison, but this works for me.
- m463 2y ago> I run a whole bunch of non-app-store binaries every single day if you are in the US, you need to either register as a developer, or register an apple id and register your app to run it for a week. that's how you run non-app store code. Both of those require permission from apple. EDIT: Sorry, ios.
- tra3 2y agoThis is completely incorrect. You can download a random binary and execute it. You will get a warning dialog saying it’s not signed by a known developer. You are free to ignore that though.
- insane_dreamer 2y ago> not share that data with other parties but they definitely do not respect your privacy not sharing my data with other parties, or using it to sell me stuff or show me ads, is what I would define as respecting my privacy; Apple checks those boxes where few other tech companies do
- nox101 2y agoAgree. I recently went to an Apple store in Tokyo to buy an accessory. The Apple employee pulled up their store iPhone to take my payment (apple pay) and then asked me to fill out a form with my email address and there was a message about how my info would be shared with some company. I thought about going back and pretending to buy something else so I could film it. I questioned the store person, "It's apple supposed to be "Privacy first"". If it was privacy first they wouldn't have asked for the info in the first place and they certainly wouldn't be sharing it with a 3rd party.
- robertlagrant 2y ago> Apple is well on its way to ensure you can only run things they allow via app store, they would probably already be there if it wasn't for the pesky EU What has the EU done to stop Apple doing this? Are Apple currently rolling it out to everywhere but the EU?
- d_theorist 2y ago> Apple is well on its way to ensure you can only run things they allow via app store, they would probably already be there if it wasn't for the pesky EU. People have been saying this ever since Apple added the App Store to the Mac in 2010. It’s been 14 years. I wonder how much time has to go by for people to believe it’s not on Apple’s todo list.
- madeofpalk 2y agoIf there was a time Apple was going to do it, it would have been when they switched to Apple Silicon. And they didn't.
- lynx23 2y agoThe EU is center-right-wing, and laughs all the way to the bank whenever someone like you falls for their "we externally pretend to be the good guys" trope. Leyen is pretty much the worst leadership ever, but they still manage to convince the politically naiv that everything is fine, because of GDPR, AI laws and huge penalties for big tech. Its sad how simple it is to confuse people.
- randomcarbloke 2y ago>Apple is well on its way to ensure you can only run things they allow via app store that ship has well and truly sailed, this conspiracy might once have held water but Apple's machines are far too commercially ubiquitous for them to have any designs on ringfencing all the software used by all the industries that have taken a liking to the hardware.
- kranke155 2y agoYou’re way off base. Paranoid.
- deleted 2y ago[deleted]