Apple Addresses Privacy Concerns Surrounding App Authentication in macOS
macrumors.com
macrumors.com
To them this is natural, they get away doing anything with the Iphone. Doing it to macos is the natural result of that precedent.
There's a downvote brigade in this thread. The downvote button is not a "I disagree" button.
I don't think most people can realistically use a Mac (or PC) without ever connecting to the internet.
But for the vast majority of people, a system that warns them their software has been compromised will help keep things secure.
I mean I don't agree with them phoning home for every application startup; they could have implemented it like the https certificate system, where you have a database on your own system with signatures that the OS can check against. They can install the signature (or fetch it) on application installation / update, no additional phone home required. They could even put it in a secure enclave or whatever so that in theory, no malicious software can update it.
I propose only giving the right to downvote after a comment reply is posted because as commenter a -3 value doesn't contain any information about the comment itself.
100% agree...
That’s what not requiring comments prevents: useless comments that are just posted so people can downvote. So now your comment section is flooded by “I disagree” comments and you can’t downvote those without leaving a comment as well. It’s a self-serving cycle.
I took a karma hit of -4 on the comment above just because people disagree with an idea I proposed.
Reddit doesn't any restrictions at all, and of course that's a massive echo-chamber. But Facebook and Instagram only have upvotes (likes) and the communities are either massive hugboxes or ghettoes.
Another example: Forcing people to use an E-mail address as their user ID. This is a security and practicality disaster. Not only do people now have multiple Apple IDs (which Apple huffily refuses to consolidate) that split their iCloud and App Store purchases into a mess, but a large proportion of the public undoubtedly thinks that they have to use the same password for this ID as they do for their E-mail account itself.
Everyone's E-mail address is on spammers' lists. When you combine that with a list of the top passwords, you get thousands if not millions of compromised accounts.
STUPID.
An equally annoying "Apple policy enforcement" is you cannot downgrade apps on iOS; So you're using some app and an important part of your daily workflow is based on using this app, and all of a sudden out of nowhere Apple or the Developer decides to radically change/update the app and now your workflow is broken. No way to go back to your previous workflow.
So frustrating... we do not own our devices anymore. Apple enforces what we may and may not do with our devices.
That is very annoying. There should be at least the possibility of "return to previous good old version"
Non-hypotetical example: Latest app update breaks in some weird way on older iPhones/iPads. While developers need to figure that out, users are left unable to use their apps.
Or worse, the developers get stuck in App Review Hell for over a week and are unable to release their fix to their users.
This happened to me when the reviewer took umbrage with our screenshots (which have passed numerous previous reviews) and kept rejecting our update. Meanwhile the app was bricked in some configurations with nothing anyone could do about it.
I had an app called gas cubby, which let me locally - on the phone - keep track of all my vehicles. I could enter detailed information about each car such as year, make, model, vin, insurance policy, gas purchases, oil changes and the like. It would tell you gas mileage and remind you of upcoming maintenance.
One day, the app was updated and all my local data was uploaded to the cloud.
Another app I had was camscanner from tencent that basically did the same thing. Think of all the PDFs you scan going to their cloud.
Another app that let you take a photo of a wine bottle and show you reviews of the wine. They added a social media login too. My list of favorite wines was gone unless I logged in.
I don't use those apps anymore.
So, you'd then have to manually click like 100 apps individually/one by one to update them.
IMHO, it would then be very beneficial from the user's perspective to have a system-wide default policy for updates along the lines of "install nothing without asking", "install essential updates automatically, ask about others" and "install all updates automatically".
Of course, this would require software developers to actually fix older versions of the software they sold when it was broken, as they used to, instead of trying to make it the user's problem as the developers move on to whatever they want to do next, which has become a popular business model as we've moved to online updates being widely accessible and to web and mobile apps where "latest" is often the only version available to users. So it's obvious why developers aren't so keen. What's less obvious to me is why, given the damage caused by the more recent model, the rest of society tolerates that behaviour instead of holding developers accountable for their earlier mistakes like anyone else who sells us a defective product.
These are defensive measures to protect the general user base from malware. Yes, using HTTP in 2020 is worthy of scrutiny, but not using every such incident as a new piece of armour for this tedious narrative. Apple’s entire platform offering is based around curation. If you disagree with it, there are many other platforms out there you can elect to use. The bitterness that flies around whenever Apple comes up around here is almost inexplicable.
or more specifically, not so much inexplicable (as actually I think it is quite predictable), but rather it is just exhausting.
I'm never going to buy a Windows computer. Period. I'm probably never going to switch to Linux either. I don't go around shouting my reasons why I won't, and I think most Apple users behave this way.
But for a certain segment of the non-Apple crowd, yelling consistently about their opinions is an odd recurrence.
Almost as bizarre as loyalty to a single brand even when they stop treating you well.
I can understand smugness from those who contribute/maintain (what I understood by FOSS community), I don't understand the entitlement money brings.
I misread this initially and I suspect others are as well based on the downvoting. But I think what you mean is that impulsive and/or unconditional bashing is the cognitive error here, right?
The sentiment expressed is basically the same as in 'Your Computer Isn't Yours' mentioned in the article, which has already caused Apple to respond and enact change. That criticism directly caused real improvement.
>I think most Apple users behave this way
No, that’s not it all what I meant, and I’m sorry if it came across that way. I meant it is exhausting to see the same fairly shallow criticisms shouted on a regular basis. It’s a different product with a different philosophy and people don’t have to buy their products, and it’s exhausting just to see the same things regurgitated over and over.
You'll have to back that up with a meaningful citation because all the evidence I've seen is to the contrary.
Here, I'll offer one example:
> Android devices 50 times more infected with malware compared to iOS.
https://www.pandasecurity.com/en/mediacenter/mobile-security...
https://www.macrumors.com/2015/09/20/xcodeghost-chinese-malw...
Unlike Google and Amazon, who do both static and dynamic analysis of uploaded apps for malware, Apple relies on very basic code scanning and manual review, leaving infected apps up until they were reported externally.
https://www.zdnet.com/article/xcodeghost-ios-malware-leaves-...
Even worse, Apple does not let third party security research release apps on the App Store, making it harder for them to find and report malware to Apple.
So we have that iOS is worse than Google and Amazon Android devices as a whole. Users who care about security will not randomly choose from that whole set of devices but instead choose among those that receive rapid security updates. That subset makes the difference in security even more stark meaning that iOS users give up their privacy and get worse security.
Thanks for the info on XcodeGhost, I hadn't heard that before. But to stake your evidence on this one single event from over five years ago is not so convincing.
I appreciate your effort to dig up an example that is an exception, but we're talking about the industry overall here, worldwide, and in recent years.
> The lack of fragmentation, and the centralized control and ease over updates
As I said, if you're choosing a device to run, you don't select one at random from the set of all Android devices. You select one that receives timely updates. On the subject of ease of updates, Android is even better because system app updates do not require a reboot and instead happen silently in the background while the user continues to use the device. This is especially important for apps with large attack surfaces like web browsers, and this is why malware markets have priced mobile Safari exploits as essentially too cheap to meter.
https://mobile.twitter.com/saurik/status/1295024384596312064
There is no such thing as a perfect computer. Every purchase involves tradeoffs, including Linux. I, personally, started out on Macs in late 1995 and then switched to Windows in 2002. A few years later I switched to Linux and then ran Arch until summer 2017. I switched back to Macs with a MacBook in fall 2017, just as I began university.
Why did I switch back to Mac after all those years learning Linux? Because I was tired of my computer breaking all the time. I wanted something that would just keep working and not randomly boot to the system console, unable to start the graphical shell, after an update. This tradeoff in stability came at the price of customization, something I was glad to give up anyway since I knew I’d have a ton of actual work to worry about in school.
Anyway I would hope that 'incessant drone' is often about more than customisation, it is because people are concerned about the impacts on general purpose computing a la Cory Doctorow [1]. Moaning about that being annoying is like moaning about the 'incessant drone' of climate change commentary.
Cory’s arguments ultimately boil down to a slippery slope argument. Apple says it is locking things down in order to protect people against malware. Cory says this will lead to a lockdown against general purpose computing (ability to run any software you want). This hasn’t yet come to pass, so it’s a matter of waiting at this point.
I don’t think climate change is an appropriate analogy. Climate change is a physical process which we can model and predict via the scientific method. It’s pretty clear at this point that if we maintain the status quo and don’t change our behaviour then catastrophe will ensue.
You can’t say the same thing about Apple. They’re a company full of people and you can’t predict what they’re going to do next. Plenty of people try, of course, but they’re wrong every year.
I’m curious, what part of my wording suggested I was taking this as a personal attack? Things can be exhausting (annoying) without being personal.
> I'm never going to buy a Windows computer. Period. I'm probably never going to switch to Linux either.
This sounds to me as if you were saying "since I won't be switching away from Apple, I find criticism of Apple tiring because it won't change my mind". Which seemed to imply to me that you were taking Apple criticism as an invalidation of your personal beliefs / preferences. But I don't think it should be construed that way. It's just criticism of a company.
I apologise if I misconstrued your position.
I'm a windows user primarily and linux user by choice. To my dismay, at my workplace I have to use MacOS because everyone uses iMacs which belong to the company and have no choice in that regard. This means MacOs is tied directly and non-trivially to my livelihood. My complaint of apple and what I percieve as shenanigans by Apple are due to that very fact that it is tied to my livelihood. Ofcourse you can say switch jobs because you dont like the brand the company uses and I will concede that as a somewhat valid point- but a reasonable person may look askance at the suggestion. We can agree it's a stupid reason to plunge myself into financial uncertainty. There is a non-zero chance that there are others in my position and who must exercise the right if not courtesy to complain.
> But for a certain segment of the non-Apple crowd, yelling consistently about their opinions is an odd recurrence.
There is a certain group which self identifies as fanboys which is their right and that group is not comprised of Windows or * nix users. This segment of fanboys I can assure is equally if not more vocal. Amusing if nothing else.
I agree that it is a bit amusing at times.
It really was similar to what I hear today from a couple people who I know that refuse to use an iPhone or any apple product. The Apple hating passion from people who have never used them is very real and has been for decades.
Weird how I feel the same about all the pro-Apple comments in every Linux thread, specifically to the effect of:
'Unlike Linux, macOS just works. When I was younger I used to play with Linux too, but now I do actually work I just need shit to work and macOS does that', followed by a bunch of outdated, showing knows nothing about what they're talking about shit about PulseAudio.
But when Apple completely and utterly screws up, to the point when you can't even launch non-Apple apps on a machine you paid thousands of dollars for, then people are all too sudden overreacting?
Funny how that works.
> I'm never going to buy a Windows computer. Period. I'm probably never going to switch to Linux either.
Good. And most FLOSS people don't want you to either. What is my problem is when people have crazy high expectations of FLOSS maintainers, but a trillion dollar company screwing up is filled under the category of 'shit happens' so to speak.
Especially considering Apple's a commercial entity that DOES NOT and WILL NOT care about you or what you think and does not need anyone's advocacy as they have a massive marketing budget of their own. Aside from that, there is a feeling in the FLOSS community that Apple's conducting a war on general purpose computing as we know it, which is not an unreasonable thing to be fearful of considering their influence.
> I don't go around shouting my reasons why I won't,
I am glad to hear that, but there's an awful number of your fellow Applers who are doing exactly the opposite.
> But for a certain segment of the non-Apple crowd, yelling consistently about their opinions is an odd recurrence.
Right, which is totally not a thing for the Apple crowd, is that it?
I meant to say that we don't want you to switch to Linux if you're clearly happy with what you have already, not that we don't want [to have anything to do with] you, sorry if that wasn't clear.
If the solution was always just ‘show your code’, anyone could make up an allegation against them as a way to get them to reveal source code.
Also - arguing that if you’ve done nothing wrong you should have nothing to hide, is a bizarre position to take in an argument about privacy.
If we were to apply it to Apple, we would need to apply it to everyone.
If someone actually produced evidence of Apple lying here, that would be a different matter.
Nobody has produced any evidence at all.
I'm not saying "Tim Cook has something to hide because he won't show us his private life". I'm saying "Apple wants to send a machine to come live in other people's homes; if they won't show the machine's insides, I wouldn't trust that they've got nothing to hide".
This is the understatement of the year.
It's one thing for Apple to "curate" their offerings and not allow you to do everything with their devices. It's quite another thing for them to pretend they're about "privacy" and then sending confidential information over the wire unencrypted.
When businesses use macOS, they might be fine with the "curation" and "you're not allowed to do everything" aspects (that everybody was aware of), but certainly not with something like this.
... Or Google, or Facebook, or Amazon.
When a community has so much resentment about all these different companies, it says less about the companies and more about the community.
"Apples platform is based on curation" yep, here it is. That's the iphone developer Mantra. Except were talking macos. What you're saying is nobody can create and run applications without apples signature. That apple gets to control it all.
Whatever happened to developer freedom? The ability to create and share? That disrespect software development, that disrespects it's origins, and instead of seeing how hypocritical that is you create excuses for the company that chokes the life out of it.
These are terrible apologies for the world's richest company. You advocate against yourself by thinking "it's apples way or it's the highway". You willingly give up consumer control and make logical fallacies to ignore having to address the cognitive dissonance.
This is why right to repair is being chosen by voters. If you won't be a responsible consumer then the others who have work to do have no choice but to force apples hand.
1) What if, and bear with me here, what if Apple's explanation for why they are doing this is legit? What if they are successfully preventing some malware from running on macs?
2) "They don't believe you should own your computer" -- it appears Apple is planning to offer a feature that allows you to turn this behavior off.
It's easy to assume Apple has malicious intentions here. But I think there is a larger issue which is that all kinds of bad stuff can in fact run on your machine without your intention. You could try to throw anti-virus software at the problem, and that's one approach, and Apple is taking this approach. Which is the best approach? That's a much more complicated discussion.
If I do want to rely on anti-virus instead of Apple, it still doesn't matter.
Apple doesn't give you a choice.
That is completely incorrect. You have the most important choice of all: Just don't buy Apple.
For everyone else, assume they've already made that choice and are very comfortable with Apple's strategy of curating everything on the machine, not because they are evil or control-freaks, but because they do genuinely want the platform as safe and high-quality as they can make it. Whether it works or not is perhaps a matter of opinion, but if it's not your opinion, move along. No need to spend the days fussing about things you don't own.
1. Opt-out is not necessarily sticky. I don't have confidence that when I opt out, my preference will get rolled forward every time there's an update to the way the feature works. I have noticed this in the past with Facebook and Google.
2. What's good for the goose is good for the gander. If Apple needs to implement opt-out to placate sophisticated users who actually understand what the problem is, then what about the poor saps who don't really know why this is a bad thing in the first place?
If this is truly a "feature," let people decide for themselves at time of device setup whether they want to opt in.
They may very well do this. On startup installation, macOS and iOS do have opt-in screens for certain things like analytics, improving Siri, stuff like that. With the introduction of this feature, I wouldn't be surprised if they add that as well.
It's easy to find fault in retrospect but it doesn't make sense to have opt-in screen for every conceivable feature. Apple's philosophy, which is wildly successful for most users, is to choose sensible defaults about how the OS works. When those are challenged, they expose them more explicitly, as they have done in the past. No company can easily predict if their defaults are going to cause a divide, so sometimes they have to be reactive on some features. Apple generally has a great track record of responding to criticisms like this and making things clearer for users.
They don't currently.
> It's easy to find fault in retrospect but it doesn't make sense to have opt-in screen for every conceivable feature.
Privacy isn't "every conceivable feature" and the reason Apple is taking heat for this in the first place is that they buried it, and many people discovered it for themselves when the server slow-down happened. It takes some mental gymnastics to refer to that as "wildly successful."
My view is that Apple has no business knowing when and how frequently I run programs, nor circumventing my VPN. If these things are really a "wildly successful" "feature," then why bury them in the first place? Offer them to me as an option and let me bask in the glory of all that Mac OS has to offer.
...That is, unless this is just an intrusion into my privacy.
And yet there is some data stored in my iCloud account, even though the first thing I did when I bought an iPhone was spend an hour turning off every setting that I could see that would permit uploading anything. How did that happen? Apple introduced some new settings in a subsequent iOS update, and defaulted them to being turned on.
It's easy to find fault in retrospect but it doesn't make sense to have opt-in screen for every conceivable feature.
OK. Just provide a single, clearly marked option to enable or disable telemetry globally, and require that all Apple software and all apps in the App Store use APIs that are gated by that option for all relevant data uploads. That would be very clear about user intent, if you want to be seen to support user privacy as a genuine goal.
Apple generally has a great track record of responding to criticisms like this and making things clearer for users.
And yet huge amounts of data uploaded to iCloud still isn't end-to-end encrypted, even optionally. A lot of Apple users don't realise this, but plenty who do have called Apple out on it for a long time, and it hasn't been fixed. You can read whatever conspiracy theories and subjective arguments you like about why that might be, but the insecurity is an objective weakness in the system that hasn't been fixed.
I suspect a lot of online communications and data hosting services now have a barrier to implementing E2E simply because they already have established infrastructure and software architecture but everything was originally specified to support a centralised system. You can't just drop in a different library or edit a handy configuration file to turn one type of system into the other. Fundamentally, you need to build something new and with a different architecture to work on an E2E basis, which is a major investment and a significant risk if you already have an otherwise successful product operating on a large scale.
The main challenge with E2E, as far as I'm aware, is still how to scale up the basic principle effectively as the number of participants increases.
However, none of this affects the iCloud functionality I've been referring to, where essentially you're only storing data for one party anyway.
[1] This statement is made in the context that encryption in general is a field where you really want people who know what they're doing implementing everything and if you don't have experts in-house then you should probably use someone else's tried and tested implementation instead of attempting a home-grown version.
So, you may be right, may not make much difference. I don’t accept malicious data-mining intent, however.
They didn't.
Either they are just completely, blitheringly incompetent, or: They actually, truly, didn't intend to harvest any data.
It's not the Apple exclusive problem; Microsoft, Google are also guilty of datamining our activity and so are many others. The story is always same saying they're respecting our privacy, data is anonymized and it's being used for good cause of improving software and services. But then, suddenly we're learning that someone somewhere is sucking more than it promised in a way that is far from private.
But, don't worry, your HN rep is safe because these types of rants appear in ALL the Apple threads, there are many that feel the same.
And dang himself has backed up the "downvote button as a disagree button" idea, so if you really want to make that argument, I think you'll find the site admins against the idea (frustrating as it is.)
You’re 1 in 7 billion and not every one wants to be a car mechanic. To customers this is natural. This is a tiring attitude to encounter in society, from car guys to computer guys.
An individual or a minority does not dictate market behaviors. To everyone except control freaks that’s natural.
Social memes of yesterday are fading. Should we revive pagan ritual and return the land to Native Americans? How to avoid harm in a reality that erodes on auto-pilot?
Your words are outdated software, programmed in decades ago. You’re over the hill and new ideas are following up as usual. Move along.
If you have real ideas act on them. The market for low effort bleating online is saturated. Such ideas aren’t even worth a dime a dozen anymore.
This news is on the HN front page with a reasonable amount of votes. Based on past discussion here and elsewhere a lot of people care.
Apple is responding to what the vast majority of the market wants. Most customers want a computer that "just works" and is secure, and they want Apple to do security for them. Having the OS/machine vendor do security for you is a gigantic value-add for most users. Most people either don't know enough to handle it themselves or don't have time.
There is a minority base of users who explicitly don't want this, and that includes many of the users on HN. Product development tends to be a quasi-democracy in that what most of the market wants, most of the market gets.
That being said the implementation here is badly designed. What Apple should do is have an advanced dialog in the security/privacy preference panel that allows these things to be configured, but with a warning that doing so will disable certain Apple-provided security features. Also: Macs have plenty of space. Why not download the entire f'ing CRL list? It's just a bunch of hashes and timestamps. Download the whole thing and then update it with patches at a configurable rate: every 15 minutes, every hour, every day, or "on request." That would fix many problems.
Unfortunately it is. Verified by email with dang
I thought it wasn't. I made a suggestion. I was told I was wrong. Downvoting for disagreeing is fine on HN.
If Snowden taught us anything it's that seemingly innocent metadata can be used at scale for a variety of unexpected things.
This combined with Apple system services avoiding Little Snitch / Lulu and VPN software in Big Sur is a very dangerous step.
How long is it going to be a until a journalist/activist is arrested or killed in an Authoritarian state because the VPN was sending most of the information except the Apple information?
What concerns me is that I can't travel with confidence that my non-web activity is obscured from host governments and ISPs.
The US intelligence is just an example anyway. You could insert any relatively competent and well resourced nation state.
This also does nothing for privilege they are affording their own apps to avoid VPNs and Firewalls, which has already been shown to be a security flaw (malicious software will then masquerade as the privileged software).
The proper way to implement their feature without causing privacy issues would be to periodically update a list of authorized certificates and check against that list locally when launching apps. That would probably also increase performances.
It's just plain text. If I can have a local dump of wikipedia, I'm pretty sure I can store a list of developer IDs. Especially when I'm a company controlling the hardware and knowing what is the minimum amount of space the hard drives have in my computers.
Think about antivirus definitions - those are many, many times larger, and still they have been kept up to date over the internet for decades.
So they were harvesting IP information in their logs. Just wow this is what i expect from company that advocates privacy. Privacy is just marketing game for them.
Bypassing vpn etc has made all your privacy claims invalid apple?
We want less trust more truth. If you cannot do that you are not privacy friendly you are hypocrite.
I don’t get to that conclusion from the text you cited. Sure, it’s possible. But I give Apple the benefit of the doubt here that what they are doing is logging IP addresses of HTTP requests like pretty much any other HTTP server does and now they are going to stop doing even that in response to privacy concerns. Seems reasonable.
The other, arguably bigger, problem here is that the data is apparently being sent unencrypted, so regardless of whether Apple discards some of the data after receiving it, others might not.
I would expect a company that goes out of their way to claim they care about user privacy to at least make some trivial configuration changes on how their web servers log requests by their users.
*In my opinion, in the content-blocker instance the result is a much poorer user experience (ad-blocking effectiveness, flexibility) when compared with e.g. uBlock Origin, and one of the reasons I continue to use Firefox instead.
The free developer account does not allow you to notarize apps. And Apple gives no free passes to open-source apps. Everybody must pay.
I'm still debating if I'll renew the certificate.
Ah, and I also have to buy another certificate for HTTPS so that the browsers don't show a scary popup when the user opens my website.
For HTTPS I manage with LetsEncrypt. Wouldn't that work for you?
Why do I care about what they say? Its marketing speak. Why not just not do it at all? Let me decide how I want my data to be sent. Which ideally, is zero.
- a new preference for users to opt out of these security protections
The current headline* hints Apple has already made changes, while the article only says Apple 'plans' on making changes over the next year. Any other company would have been torn to shreds on HN if it kept sending cleartext logs and merely 'planned' to sometime patch this out.
The plan is odd too - why does Apple need 'a new encrypted protocol for Developer ID certificate revocation checks' when existing encryption protocols can do this?
* "Apple Addresses Privacy Concerns Surrounding App Authentication in macOS"
I have seen this argument a few times now without any references.
Were, for instance, Microsoft or Amazon torn to shreds over similar claims?
> think about and begin to deal with (an issue or problem)
It doesn't imply that the solution has been fully implemented.
[EDIT: every definition of 'address' I've found suggests it's a synonym for 'deal with' not 'begin to deal with']
Seems like they have begun to deal with it.
[EDIT: Perhaps it's because my definition came from Apple's dictionary app /s]
And "deal with" does not mean "fix" -- the word "addresses" makes perfect sense for this headline.
Look at the certificates on sites you use, like this one. The OCSP server is http://ocsp.digicert.com . Http, so no encryption.
Apple is a major hardware manufacturer and software developer, and it seems totally appropriate to suggest that Apple is responsible for how it chooses to implement certain features. Saying "well, we just took it off the shelf" may work for a small-potatoes business, but not the largest public company in the world.
Additionally, it's like the Nuremberg Defense of software.
Any protocol (or tool in general) is appropriate for certain situations, and inappropriate (in this case, vulnerable) in other ones. You shouldn't suggest that others must bend over backwards semantically to try to pass the buck away from Apple, because Apple is responsible for using the protocol. Saying "Apple's protocol" indicates that Apple made the conscious choice to use that protocol, and that Apple has ownership of the consequences of using that protocol.
"a new encrypted protocol for Developer ID certificate revocation checks"
Not the current Apple implementation.
I didn't read the headline that way at all, because the word "addresses" doesn't mean what you are suggesting it means.
And yet, this thread and every other Apple thread is full of comments like yours assuming negative intent. Check out other comments in this thread, you'll see comments asserting that of COURSE this feature is for harvesting or that Apple doesn't want you to own your devices any more. You comment is another critique based entirely on what they might do: that are not going to do what they promised.
Any attempt to claim that they do nothing with this data, and choose not to store it for future use, are red herrings: they will do whatever what their shareholders, the government, et al. tell them to do with it, and will do so without notifying users, and do so retroactively if possible.
There is also no way to audit their backend to prove that they are, indeed, doing exactly what they claim to be doing, ergo, the only safe OSX system is one that has Gatekeeper entirely disabled in leu of a local-only switch.
Due to enterprise security concerns with leaking attack targets via signed binaries cert chain/OCSP checking, Windows since Vista already allowed disabling of this obvious hole.
I know a lot of Cult of Apple are going to climb up my ass for saying this, but this continues to highlight that OSX is not, and probably never will be, enterprise ready. Apple needs their own Nadella-type of CEO before I'll change my opinion on this.
Apple clearly signalled its lack of interest in enterprise offerings when it canned Xserve back in 2010, so don’t hold your breath waiting for these features.
This can't be easily bypassed. Magisk Hide is useless. For now I've had to disable auto-updates in the Play Store and manually install an older app APK, but it's only a matter of time before they deprecate that version. I do essentially all of my banking via my phone, so when this happens I intend to close all my accounts and move banks.
The sooner someone leaks a hardware key (preferably one that Google can't revoke without cripplingly bad PR for breaking millions of products) the better.
I honestly think 'appification', app stores, and locked down hardware via key chains will be the end of an era in hacker-friendly consumer electronics. Perhaps the end of personal computing entirely.
[0] https://developer.android.com/training/safetynet/attestation...
[1] https://groups.google.com/g/safetynet-api-clients/c/lpDXBNeV...
Both white and black hat hackers friendly? The vast majority of consumers don't want to 'hack' their device. They just want to watch Youtube and do bank payments without getting hacked and robbed of their savings. Recently there was another case in the news where someone was phished via an insecure platform (PC).
I get that a lot of rights are taken away from us, but we should fight this with proper consumer protection laws. As it is demonstrated times again most consumers are to naive to take responsability of their security and criminals get away with it to easily.
Would you tolerate a bank that insisted on coming in to your house and forcing you to install Norton Antivirus on your computer before they allowed you to log on to your online banking via their website?
Banking security should be implemented on the server side. I shouldn't have to choose between running my own code as root on my device and being able to bank.
Not all problems can be solved server side. And no bank is going to come into anyones house. But they need a resonable assurance the environment the customer uses to conduct their bussines in safe and trustworthy. It's either that or no mobile customer service at all. Or everyone needs a "digital drivers licence" which I think some "IT people" I know wouldn't even pass for.
Phishing is a real threat. It might never ever happen to you. But a lot of people thought just that and got phished anyways because they where learned to trust certain signs (eg: green padlocks).
This is a false dichotomy. The hardware attestation for SafetyNet is orthogonal to being able to use hardware attestation for e.g. session/user keys, or even chain-of-trust down to the fingerprint sensor level.
Keys can be kept secure using secure enclaves even if the OS is rooted.
Blocking rooted phones with SafetyNet is just spite.
Not to mention, an ATM is property of the bank and is shared-use. The user is not the owner. The phone belongs to the user.
Serious question as somebody who is not an Apple developer and has zero clue: does the wording "Developer ID certificate checks" here mean locally-built binaries only? Would a 'Release' binary still be logged? Not trying to spread FUD, but I haven't touched Xcode since it was called Project Builder and legitimately don't quite understand.
I guess to phrase as a question: Does this stop the hypothetical logging of anyone who has downloaded and ran Tor Browser without compiling it themselves?
Going forward, we can promise a quick return to business as usual as we work to regain your confidence, starting today with the announcement of several meaningless token gestures alongside a new and more effective PR and marketing campaign.
https://web.archive.org/web/20201114024313if_/https://regmed...
https://ec.europa.eu/info/law/law-topic/data-protection/refo...
- Apple Inc. 2020
There are already solutions where this data is not (1) sent in plain text over the internet, where your ISP and anyone else along the way can see it, and (2) don't give even the endpoint information about the specific certificate you are checking.
It does create this risk of people opting out and spreading malware to others, but after last week's debacle Apple probably thought they should come clean here.
How do people tolerate this stuff?
Also, doesn't really work that great for security, as there are always relatively easy ways to fool the signature detection. That's why AVs usually moved to include much more complex behavioral checking.
Note: not claiming that AVs usually respected user privacy - a lot of them could be conisdered malware in and of themselves. But the malware protection scheme was simple and it did guarantee privacy - it's other parts of the AV that then went behind your back and sold your data more directly.
Just look at the heavy brigading happening here or any other Apple related thread. As soon as there is one negative article two positive must pop out to calm the Apple fanboys.
And no, saying "if you don't like the platform then don't use it" is not a valid argument. Thank God that it is not up to us on HN to decide what Apple can do, but to the court of law, at least I am putting my trust in the EU..
Sometimes, waiting to hear a response isn't unreasonable, don't you think? Maybe rethink the plan to abandon Mac for the rest of your life based on the story of the minute?
The technical facts are not interpretable: Apple chose to build the new MacOS in such a way that they leaked information about every app you chose to run on your system, in plaintext, over the internet, sending it to a third party. Whether they did this out of malice or bungling, the only conclusion is that you should not trust the new MacOS with caring about your privacy.
Whatever PR spin Apple would choose to put on this is mostly irrelevant. That they chose to simply pinky swear that they wouldn't log IPs as the main defense is even worse.
To further protect privacy, we have stopped logging IP addresses associated with Developer ID certificate checks, and we will ensure that any collected IP addresses are removed from logs.
Why would they ever have logged IP addresses, if the goal is simply to verify the user-side authenticity of an app?
Still, it is no excuse for them as one would expect clear and thorough security/privacy audits before rolling out such features. Especially from companies like Apple.