/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

A deep dive into OCSP responder Apple uses to verify integrity of Mac apps, which is a critical part of macOS security, but could benefit from more transparency

there were some popular but misleading tweets about the topic (because story > facts) also wikipedia on the protocol: https://en.wikipedia.org/... https://twitter.com/... @dhh : I don't see how this makes anything better? Sending a global unique hash of the developer certificate in the clear still allows both Apple to keep a log and anyone the power to snoop. This is fundamentally busted. Apple should send ban lists to the user. https://blog.jacopo.io/... Andree Toonk / @atoonk : Good follow up from the article I tweeted yesterday: Does Apple really log every app you run? A technical look https://blog.jacopo.io/... Phil Vachon / @pvachonnyc : Some Apple apologism to start this weekend. https://www.security-embedded.com/ ... - the recent #OCSP responder outage and the hysteria afterwards shows the tightrope Apple has to walk with respect to platform security. I haven't done this in a while. Dusting off the blog. #Apple #privacy

Security Embedded Phil Vachon

Discussion

  • @bcrypt Yan on x
    don't block https://ocsp.apple.com/ forever because apple uses it to check for revoked notarizations https://twitter.com/...
  • @dhh @dhh on x
    I don't see how this makes anything better? Sending a global unique hash of the developer certificate in the clear still allows both Apple to keep a log and anyone the power to snoop. This is fundamentally busted. Apple should send ban lists to the user. https://blog.jacopo.io/..…
  • @edbott Ed Bott on x
    Ah, we have reached the “_NSAKEY” portion of the “Apple is spying on you” story. https://twitter.com/...
  • @techloreistaken Techlore on x
    This is the best writeup I've seen so far regarding the recent MacOS Big Sur concerns. TLDR: It seems fine. Keeping an eye out for updates from others. Article here: https://blog.jacopo.io/...
  • @bcrypt Yan on x
    here's a write up of how this works: https://blog.jacopo.io/...
  • @ianbetteridge @ianbetteridge on x
    No, macOS does not send Apple a hash of your apps each time you run them. https://blog.jacopo.io/...
  • @rezendi Jon Evans on x
    “No, macOS does not send Apple a hash of your apps each time you run them. You should be aware that macOS might transmit some opaque information about the developer certificate of the apps you run. This information is sent out in clear text” https://blog.jacopo.io/... via @bcrypt
  • @konklone Eric Mill on x
    @mdhardeman @yoz @QuinnyPig I'll be more polite. The blog post that sparked this hyperbolically overstates the impact, and still appears to believe Greenwald's terrible misreporting on PRISM. And brings up an unrelated Apple decision not to support e2e in a cloud service. And bri…
  • @coralineada Coraline Ada Ehmke on x
    OCSP facts, for the curious. After reading this, I'm unblocking https://ocsp.apple.com/. https://twitter.com/...
  • @yoz Yoz Grahame on x
    The huge reaction to Paul's blog post demonstrates what happens if/when Apple gets this wrong. Imagine if it was Amazon. Sure, you would disapprove, but it'd be eye-roll number six in your morning coffee doomscroll. When it's Apple's screw-up, it's everywhere.
  • @alexlindsay @alexlindsay on x
    @stphotos @scottbourne @dougdaulton The whole Apple ecosystem doesn't really work if you don't trust it. All the devices are connected, they would be potentially gathering incredible troves of information about health, location and interests. Apple keeps closing itself out of kno…
  • @atoonk Andree Toonk on x
    Good follow up from the article I tweeted yesterday: Does Apple really log every app you run? A technical look https://blog.jacopo.io/...
  • @timbray Tim Bray on x
    More on this. Apparently, Apple doesn't learn which app you're running, but they do learn who the developers are. I don't find the difference significant in the general case. How long does Apple keep this data? I'm still getting creepy-crawlies. More transparency please. https://…
  • @xeraa Philipp Krenn on x
    “Does Apple really log every app you run? A technical look”: https://blog.jacopo.io/... good dive into what OCSP is actually (not) doing — there were some popular but misleading tweets about the topic (because story > facts) also wikipedia on the protocol: https://en.wikipedia.or…
  • @matthew_d_green Matthew Green on x
    An algorithm to guess with overwhelming probability which app someone is using when you observe a Mozilla cert OCSP request from a Mac: Step 1: guess Firefox. Step 2: there is no step 2.
  • @yoz Yoz Grahame on x
    If you want to understand why Apple keeps checking apps on your machine, just watch a bunch of smart technologists loudly encourage you to change your software based on valid-sounding misinformation from a complete stranger
  • @yoz Yoz Grahame on x
    It's dangerous because it encourages people to abandon Apple's malware prevention systems, which are VITAL. The pretext is some bullshit about “not owning your computer”, i.e. not having total control over everything the computer is doing. Really? WELCOME TO FUCKING SOFTWARE
  • @pvachonnyc Phil Vachon on x
    Some Apple apologism to start this weekend. https://www.security-embedded.com/ ... - the recent #OCSP responder outage and the hysteria afterwards shows the tightrope Apple has to walk with respect to platform security. I haven't done this in a while. Dusting off the blog. #Apple…