I’m glad that I don’t have a direct relationship with shady 3rd party developers.
I’m glad that I don’t have a direct relationship with shady 3rd party developers.
Google is LITERALLY a fucking ad company.
Apple is tracking the exact time and location you use any piece of software on their systems (Don't worry guys, it's just for security purposes! /s)
----
I'm no longer sympathetic to the "They're securing my device from the boogeyman!" argument.
It has the same overtures as "Won't anyone think of the children!!!!" in policy debates - It's rhetoric designed to obfuscate the true intentions of the parties involved, and short-circuit real discussion with an immediate emotional response.
Source?
https://news.ycombinator.com/item?id=23273247 https://news.ycombinator.com/item?id=23281564
True, but it didn't make much difference, since the reports from the thread showed it had a bizarrely short cache time.
>the server didn't keep any logs
Well, that's the rub isn't, it? Part of privacy-centric design is that you shouldn't have to risk such information being exposed or trust such reassurances; if they don't need the information, they shouldn't get it at all. There are privacy-respecting ways to do what they wanted to, which are also more efficient. For example, periodically update the machine's local revoked cert list, and check signatures against that (as several users recommended).
>etc
Was there anything substantively different from my characterization?
>To make sure the certificate hasn’t been revoked, macOS uses OCSP—short for the industry standard Online Certificate Status Protocol—to check its validity.
https://arstechnica.com/gadgets/2020/11/mac-certificate-chec...
There is no information tracking the application that is sent.
The protocol is only used to check and see if the developer's certificate is still valid, if the app hasn't been run in some time.
To enable background locations update, a sales rep has to open a check-in screen, wait 10 seconds to see their location on the map and then press the big check-in button. Because people were often forgetting to check-out, my customers requested auto check-out feature which requires background location updates. Once a sales rep leaves the check-in area, background location updates are stopped. Managers and employees see exactly the same time reports. And if some sales rep is suspicious then it is always possible to disable that GPS icon in the quick menu settings after work hours. It is almost like using your batch card to open doors in a workplace.
A popular alternative solution to my app is to use GSP devices which are installed in all corporate cars. And there managers see their employees background location updates 24/7.
It amounts to not being able to use features that are available in the API.
So the argument then becomes an appeal to protect less knowledgeable users that would be tricked to enable advanced features for some eye candy. It has some merit; but there has to be some compromise there for advanced users, short of relegating then to APK install with no security updates, like in the Windows days.