removed by mod
fedilink
@Dnn@lemmy.world
link
fedilink
English
81Y

The video is basically some dude reading a blog post (boy, I hate those, provide no value). The blog post he reads is this: https://sneak.berlin/20201112/your-computer-isnt-yours/

The author comments to the blog post you linked and it partially makes sense: if you fetch the developer’s certificate, Apple knows when you started an application of that developer (and which public IP address you have).

Whether or not there are many devs that only made one application, so you can identify this, I cannot estimate, I’m not an Apple user. But you don’t need to send a hash calculated in client side to get this info.

@octalfudge@lemmy.world
link
fedilink
English
31Y

You’re absolutely right that it’s still an issue to transmit information about the developer certificate. Apple published a response to this, which admittedly is not ideal:

https://support.apple.com/en-us/HT202491#view:~:text=Privacy protections

We have never combined data from these checks with information about Apple users or their devices. We do not use data from these checks to learn what individual users are launching or running on their devices.

These security checks have never included the user’s Apple ID or the identity of their device. To further protect privacy, we have stopped logging IP addresses associated with Developer ID certificate checks, and we will ensure that any collected IP addresses are removed from logs.

In addition, over the the next year we will introduce several changes to our security checks:

A new encrypted protocol for Developer ID certificate revocation checks

Strong protections against server failure

A new preference for users to opt out of these security protections

Create a post

This is a most excellent place for technology news and articles.


Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related content.
  3. Be excellent to each another!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, to ask if your bot can be added please contact us.
  9. Check for duplicates before posting, duplicates may be removed

Approved Bots


  • 1 user online
  • 218 users / day
  • 607 users / week
  • 1.39K users / month
  • 4.49K users / 6 months
  • 1 subscriber
  • 7.41K Posts
  • 84.7K Comments
  • Modlog