It's less that desktop OSes are feature complete, and more that vendors want recurring cloud subscription fees from users for new features these days.
You can turn off all the telemetry in macOS and they ask you if you want it on when you setup the computer.
Agree to disagree on Big Sur, I love the new look. Keep in mind they’re calling it macOS 11, so there are probably bigger and less superficial changes down the road.
That's false. You can turn off OS analytics but there is tons of telemetry built into almost every Apple app, separate from that, that you cannot disable. It tells you about it on first app launch. Open Maps, for example, and it will tell you about the unique, rotating identifier it uses to track your searches. Opting out of OS analytics does not disable telemetry for the other Apple services now deeply integrated in the OS. Even disabling these features doesn't prevent the mac from talking to the services, such as in the case of Siri.
Additionally gatekeeper OCSP checks on app launches serve as telemetry in practice, and this has no preference or setting to disable it.
https://www.obdev.at/support/littlesnitch/245913651253917
It's 5.x that uses the new restricted APIs.
I'm going to contact the developers and ask for an ARM build of 4.x so the same trick will work on M1, at least until Apple forbids all kexts some time in the future.
If you're trying to prevent data exfiltration, you don't trust the client at all — confine it to a dedicated locked-down system on a restricted network which only allows egress to the minimal subset of trusted services. That's a much more winnable battle than trying to prevent every possibility on a general purpose computer running tons of things which are allowed to connect to the internet and legitimately uses lots of outside services.
Similarly, a lot of the data breaches you hear about are caused by people with legitimate access saving the data somewhere insecurely. Spending time on that is a lot more beneficial to most organizations than tracking every TCP socket.
Telemetry doesn't imply intent. Many things serve great as telemetry that aren't intended to be such. There's no way to limit the way the raw data collected can be mined later, offline.
https://github.com/kholia/OSX-KVM if you need an easy way to fire up a fresh install.
This is just a check that the developer's certificate hasn't been revoked or expired. I wouldn't call it telemetry.
Apple has said they're working on allowing users to opt-out of Gatekeeper checks if that's what people want.
Details—https://eclecticlight.co/2020/11/16/checks-on-executable-cod...
It's an unencrypted network transmission of a unique identifier, at the time of an app launch, that maps to a single app for 99% of cases (due to the fact that almost all developers publish only a single app). That's objectively telemetry no matter what you call it, irrespective of the intent of the designers.
Approximately 0% of all users of macOS will change this setting, so Apple adding a preference toggle (that defaults to "send my local app launches to Apple via the network") is irrelevant from a privacy perspective.
There's no objective definition of "telemetry" that I know of, though, and this is a purely functional feature implemented straightforwardly. They are moving towards encrypting the requests, too.
Whether or not you can toggle something is absolutely relevant from a privacy perspective. Gatekeeper is something that should be on by default anyways, and I personally am more concerned about my endpoint security than Apple getting pinged with a signature when I open an app.
As the article states [1], Apple is changing to an encrypted connection, the IP addresses are no longer logged and the checks never included the Apple ID of the user or the identity of the user's device. Definitely not telemetry.
[1] For those concerned with protecting their privacy, Apple makes it clear that “these security checks have never included the user’s Apple ID or the identity of their device”, and that it has stopped logging IP addresses.
The fact that Apple isn't logging the IPs any longer is irrelevant. The data is unencrypted, and your ISP and their ISP and everyone in between can log the data.
The fact that it doesn't include the Apple ID or device identity is similarly irrelevant. The IP address also communicates unique identifiers to other services (including at Apple), so the IP address is sufficient unique identifier in this instance. Additionally, even if one doesn't have any access to those other records mapping the IP address to the user (held by Apple, the carrier, and many others), simply monitoring the specific set of apps that are opened (again, because the data is unencrypted) is sufficient in many cases to fingerprint and uniquely identify the device.
PS. Emacs is great, and I am thankful that Apple decisions have pushed me to replace Devonthink and start using Org Mode instead.:)
Agree. Hardcore Linux user (custom KDE theme) here, and I have to say that macOS 11 is easily the most aesthetically appealing desktop theme I've ever seen. Just completely mops the floor with everything else, especially the previous version of macOS. The changed margins / white space are great, colors fantastic (eerily similar to the ones I use on KDE), perfect font rendering (as always), and I really love the changes to Finder.
In terms of actual usage I have quite a few issues, of course. Requires some heavy work with Karabiner and settings changes to make it usable, in my opinion, and you still can't beat KDE because of its customizability. But in terms of pure visual appeal it's unmatched. Apple's visual design team is the best.
That said, I don't use the App Store at all (at least as far as I can help it), nor do I really use any Mac specific apps (Photos, QuickTime, iTunes, etc) since this is a development machine, so a lot of rough edges are probably invisible to me.