A deep dive into OCSP responder Apple uses to verify integrity of Mac apps, which is a critical part of macOS security, but could benefit from more transparency
there were some popular but misleading tweets about the topic (because story > facts) also wikipedia on the protocol: https://en.wikipedia.org/... https://twitter.com/... @dhh : I don't see how this makes anything better? Sending a global unique hash of the developer certificate in the clear still allows both Apple to keep a log and anyone the power to snoop. This is fundamentally busted. Apple should send ban lists to the user. https://blog.jacopo.io/... Andree Toonk / @atoonk : Good follow up from the article I tweeted yesterday: Does Apple really log every app you run? A technical look https://blog.jacopo.io/... Phil Vachon / @pvachonnyc : Some Apple apologism to start this weekend. https://www.security-embedded.com/ ... - the recent #OCSP responder outage and the hysteria afterwards shows the tightrope Apple has to walk with respect to platform security. I haven't done this in a while. Dusting off the blog. #Apple #privacy
Security Embedded Phil Vachon
Related Coverage
- macOS does not send Apple a hash of a user's app executables each time the user runs them, but may send info relating to the app's developer certificate blog.jacopo.io/en
- View article KnowTechie
- macOS Big Sur telling Apple what app you've opened isn't a security or privacy issue AppleInsider
- MacOS Big Sur Launch Overwhelmed Apple's CDN, Which in Turn Triggered a Bug in ‘trustd’ That Ground App Launching to a Halt Daring Fireball
- Apple Developer ID OCSP lapcatsoftware.com
Discussion
-
@bcrypt
Yan
on x
don't block https://ocsp.apple.com/ forever because apple uses it to check for revoked notarizations https://twitter.com/...
-
@dhh
@dhh
on x
I don't see how this makes anything better? Sending a global unique hash of the developer certificate in the clear still allows both Apple to keep a log and anyone the power to snoop. This is fundamentally busted. Apple should send ban lists to the user. https://blog.jacopo.io/..…
-
@edbott
Ed Bott
on x
Ah, we have reached the “_NSAKEY” portion of the “Apple is spying on you” story. https://twitter.com/...
-
@techloreistaken
Techlore
on x
This is the best writeup I've seen so far regarding the recent MacOS Big Sur concerns. TLDR: It seems fine. Keeping an eye out for updates from others. Article here: https://blog.jacopo.io/...
-
@bcrypt
Yan
on x
here's a write up of how this works: https://blog.jacopo.io/...
-
@ianbetteridge
@ianbetteridge
on x
No, macOS does not send Apple a hash of your apps each time you run them. https://blog.jacopo.io/...
-
@rezendi
Jon Evans
on x
“No, macOS does not send Apple a hash of your apps each time you run them. You should be aware that macOS might transmit some opaque information about the developer certificate of the apps you run. This information is sent out in clear text” https://blog.jacopo.io/... via @bcrypt
-
@konklone
Eric Mill
on x
@mdhardeman @yoz @QuinnyPig I'll be more polite. The blog post that sparked this hyperbolically overstates the impact, and still appears to believe Greenwald's terrible misreporting on PRISM. And brings up an unrelated Apple decision not to support e2e in a cloud service. And bri…
-
@coralineada
Coraline Ada Ehmke
on x
OCSP facts, for the curious. After reading this, I'm unblocking https://ocsp.apple.com/. https://twitter.com/...
-
@yoz
Yoz Grahame
on x
The huge reaction to Paul's blog post demonstrates what happens if/when Apple gets this wrong. Imagine if it was Amazon. Sure, you would disapprove, but it'd be eye-roll number six in your morning coffee doomscroll. When it's Apple's screw-up, it's everywhere.
-
@alexlindsay
@alexlindsay
on x
@stphotos @scottbourne @dougdaulton The whole Apple ecosystem doesn't really work if you don't trust it. All the devices are connected, they would be potentially gathering incredible troves of information about health, location and interests. Apple keeps closing itself out of kno…
-
@atoonk
Andree Toonk
on x
Good follow up from the article I tweeted yesterday: Does Apple really log every app you run? A technical look https://blog.jacopo.io/...
-
@timbray
Tim Bray
on x
More on this. Apparently, Apple doesn't learn which app you're running, but they do learn who the developers are. I don't find the difference significant in the general case. How long does Apple keep this data? I'm still getting creepy-crawlies. More transparency please. https://…
-
@xeraa
Philipp Krenn
on x
“Does Apple really log every app you run? A technical look”: https://blog.jacopo.io/... good dive into what OCSP is actually (not) doing — there were some popular but misleading tweets about the topic (because story > facts) also wikipedia on the protocol: https://en.wikipedia.or…
-
@matthew_d_green
Matthew Green
on x
An algorithm to guess with overwhelming probability which app someone is using when you observe a Mozilla cert OCSP request from a Mac: Step 1: guess Firefox. Step 2: there is no step 2.
-
@yoz
Yoz Grahame
on x
If you want to understand why Apple keeps checking apps on your machine, just watch a bunch of smart technologists loudly encourage you to change your software based on valid-sounding misinformation from a complete stranger
-
@yoz
Yoz Grahame
on x
It's dangerous because it encourages people to abandon Apple's malware prevention systems, which are VITAL. The pretext is some bullshit about “not owning your computer”, i.e. not having total control over everything the computer is doing. Really? WELCOME TO FUCKING SOFTWARE
-
@pvachonnyc
Phil Vachon
on x
Some Apple apologism to start this weekend. https://www.security-embedded.com/ ... - the recent #OCSP responder outage and the hysteria afterwards shows the tightrope Apple has to walk with respect to platform security. I haven't done this in a while. Dusting off the blog. #Apple…