• Home
  • Cryptocurrency
    • Bitcoin
    • Ethereum
    • XRP
    • Litecoin
    • Altcoin
    • Cardano
    • Tether
    • DOGE
    • Solano
    • XLM
    • DOT
    • XDC
    • SHIBA
    • BNB
    • Ape
    • HBAR
    • QNT
  • Blockchain
  • Regulation
  • Market
  • Live
    • Prices
    • ICO
  • Meta
    • NFT
  • Technical Analysis
    • XRP
    • BTC
    • XLM
    • ADA
    • TETHER
    • ETC
    • ETH
    • DOGE
    • LTC
  • Exchange
  • Mining
Wednesday, May 21, 2025
  • Login
  • Register
Coin24h.com
  • Home
  • Cryptocurrency
    • Bitcoin
    • Ethereum
    • XRP
    • Litecoin
    • Altcoin
    • Cardano
    • Tether
    • DOGE
    • Solano
    • XLM
    • DOT
    • XDC
    • SHIBA
    • BNB
    • Ape
    • HBAR
    • QNT
  • Blockchain
  • Regulation
  • Market
  • Live
    • Prices
    • ICO
  • Meta
    • NFT
  • Technical Analysis
    • XRP
    • BTC
    • XLM
    • ADA
    • TETHER
    • ETC
    • ETH
    • DOGE
    • LTC
  • Exchange
  • Mining
No Result
View All Result
  • Home
  • Cryptocurrency
    • Bitcoin
    • Ethereum
    • XRP
    • Litecoin
    • Altcoin
    • Cardano
    • Tether
    • DOGE
    • Solano
    • XLM
    • DOT
    • XDC
    • SHIBA
    • BNB
    • Ape
    • HBAR
    • QNT
  • Blockchain
  • Regulation
  • Market
  • Live
    • Prices
    • ICO
  • Meta
    • NFT
  • Technical Analysis
    • XRP
    • BTC
    • XLM
    • ADA
    • TETHER
    • ETC
    • ETH
    • DOGE
    • LTC
  • Exchange
  • Mining
No Result
View All Result
Coin24h.com
No Result
View All Result
Ledger Nano X - The secure hardware wallet
ADVERTISEMENT

Mac Update Leaves Users No Room to Escape Data Collection

17 November 2020
in Blockchain
Reading Time: 6 mins read
A A
0
189
SHARES
1.5k
VIEWS
Share on FacebookShare on Twitter
cryptotrader
ADVERTISEMENT


  • Apple’s most recent update, Big Sur, makes a feature that logs device activity for offline (and online) applications practically impossible for privacy solutions to bypass. 
  • The monitoring is yet another example of Apple’s privacy-compromising design choices, despite the company’s efforts to present itself as a privacy ally.
  • VPNs and other firewalls cannot circumvent the feature. 
  • Security researchers suggest that users who care about their digital privacy explore other, open-source alternatives. 

On Nov. 12, Mac users complained their computers were acting sluggish. This sluggishness coincided with the release of Big Sur, the latest Mac update fro Apple. 

After the update was released, a technical error disrupted the servers Apple uses for OCSP requests, the packets of data that verify a computer’s SSL certificate when it accesses online applications. Apple devices were shutting down because these OCSP requests weren’t reaching Apple servers

As some users looked closer, it became very clear why the devices failed when the OCSP servers were failing: Every time a user opens an application (even an offline one), that action is being tagged and traced by Apple’s OCSP servers.

This feature was introduced in Apple’s Catalina update, but certain tools (like Little Snitch) could be used to bypass it. Now, with Big Sur, there’s no practical way for average Mac users to thwart the feature. 

Apple has touted itself as pushing privacy as the core of its mission, perhaps most publicly by rebuffing law enforcement demands to unlock one of the San Bernardino, Calif., shooter’s iPhones after the December 2015 attack.

But these new revelations demonstrate some of the inherent flaws in centralized data collection – you have to trust Apple not to share this information (or trust them to not be coerced into revealing it to a government agency). In this case, though, Apple’s siloing of data through Big Sur may not even be the primary issue because these OCSP requests are transmitted unencrypted, meaning the contents can be read by any surveilling party that intercepts them.

Thus, if Mac users want out from under Apple’s eye, they’re going to need to explore alternatives.

Mac update enables offline activity logging

“On modern versions of macOS, you simply can’t power on your computer, launch a text editor or eBook reader, and write or read without a log of your activity being transmitted and stored,” hacker and security researcher Jeffrey Paul writes in a blog post.

Paul told CoinDesk in an email he doesn’t think “Apple has ill intent here,” but that its goal is to monitor malware and other illicit software on its devices. 

The problem, though, is these OCSP requests are unencrypted and so “vulnerable to passive monitoring.” This leaves the data open to collection and parsing at the hands of “large-scale passive monitoring organizations” such as the U.S. National Security Agency (NSA). 

“This is, of course, terrible practice, and despite being the industry standard, Apple should know better, as they are cryptography experts (who run their own certificate authority and regularly use relatively advanced cryptographic tools like client certificates and cert pinning),” Paul wrote over email.

Telemetry is a diagnostic process by which servers track how a device is used. Paul said the problem with Apple’s system here is that because this data is not encrypted, third parties can read it. Any entity tapping into these lines of communication can see what applications someone is using and when they use them.

“The real privacy risk here is not that Apple might be collecting this data. They’re likely not, as I believe that this is an attempt by Apple to prevent malware from being able to execute on their platform. The problem is that it serves as *inadvertent* telemetry to anyone who’s listening on the wire, which, in the United States, is every major ISP and the national military,” he continued.

These kinds of concerns have led to arguments against centralized servers for contact tracing in the European Union. They’ve also encouraged recent pushes for mixnets, which mix network traffic specifically to avoid passive metadata observation. 

Apple’s devices have always been a walled garden of sorts. Applications and software from unverified publishers, for instance, must be manually approved by users. The ostensible aim of such controls is to protect the user, but as Cory Doctorow recently emphasized to CoinDesk over email, these controls can override agency in certain scenarios (for example, when Apple removed thousands of apps from its Chinese app store). 

“I think this is a great example of what Bruce Schneier calls “feudal security,” Doctorow told CoinDesk, commenting on the activity logging feature. “The idea that our systems no longer give us the power to protect ourselves, but rather require us to surrender our destiny to one of the great techno-warlords of the age (Facebook, Google, Apple, Msft, etc.), who will protect us … from everyone except [t]hemselves.”

Data privacy solutions

For any Mac users hoping to escape the surveillance, solutions are going to have to come from outside Apple’s locus of influence. 

Before the Big Sur Mac update, VPNs or firewalls like Little Snitch would have kept your computer from leaking information. But Big Sur trumps this, said Valdas Petrulis, co-founder and lead software engineer at Mysterium Network, a decentralized VPN protocol..

“MacOS Big Sur (version 11.0) allows traffic to bypass usual routing and firewall rules. Which simply means Little Snitch won’t be able to monitor and block this, and neither can a VPN be able to help or hide you. MacOS has now simply forbidden that.”

Sean O’Brien, the principal researcher at ExpressVPN’s Digital Security Lab, said that ultimately a VPN will not “prevent Apple from being able to collect this data, but [it] “would at least protect it from other network intermediaries as it travels over the internet.”

There is a way to disable the feature, though Paul said only MacOS experts should try this. Apple changes which system services you can disable with each update, Paul said, so this may be changed in the future. 

“Really, though, the #1 thing that consumers can do to protect their privacy when using Apple devices is to *never* use iCloud, and to not use iMessage,” Paul continued. iCloud data is unencrypted, he said, allowing “the FBI or U.S. military to read pretty much everyone’s complete iMessage history without ever touching the device.”

Alternatives?

The only way to escape Apple’s panopticon, according to Paul? “Open-source software that doesn’t spy on you.” This used to mean tools like Little Snitch, Tor and VPNs, but now that Apple has a tighter grip on personal privacy, those seriously worried about their privacy can only change hardware and software providers.

Perhaps as testament to users making a change, Mysterium CMO Sharmini Ravindran said the service has experienced “8 to 10 times as much interest” in its Windows application versus its Mac version.

Of course, Microsoft is no privacy saint either, meaning the free and open-source Linux software, long the choice of most privacy advocates, could be the safest bet.

But that’s only going to work if your typical Mac user cares enough about the privacy-leaking feature. And if he or she does care, there’s also the matter of knowing enough about computers to boot and maintain Linux. One of Apple’s key selling points is that it’s user friendly for even the most tech-averse individuals, which can be appealing given privacy tech is sometimes full of friction for people who are used to logging into everything using Face ID. 

Then again, Apple has also been praised as a privacy-conscious company, and public perception is always changing. 

“Not only is Apple exposing its customers to risk from the company’s own executives and corporate decisions, but it’s also creating a moral hazard for governments, inviting them to coerce Apple into (ab)using this facility to harm – not help – its users,” said Doctorow.



Source link

Related articles

Maldives Unveils B Crypto Investment Haven

Maldives Unveils $9B Crypto Investment Haven

5 May 2025
Blockchain in the Ballot Box? NY Assembly Considers Tech to Fight Election Fraud

Blockchain in the Ballot Box? NY Assembly Considers Tech to Fight Election Fraud

10 April 2025
Cryptohopper
ADVERTISEMENT
[crypto-donation-box]
Tags: CollectionDataEscapeleavesMacroomupdateUsers
Share76Tweet47
Ledger Nano X - The secure hardware wallet
Previous Post

Gold Lags Far Behind Bitcoin as Vaccine Optimism Buoys Markets

Next Post

South Korean Exchange Foblgate Supporting XRP Flare Spark Airdrop

Related Posts

Maldives Unveils B Crypto Investment Haven

Maldives Unveils $9B Crypto Investment Haven

5 May 2025
0

Trusted Editorial content, reviewed by leading industry experts and seasoned editors. Ad Disclosure Malé, the Maldives capital, may soon be...

Blockchain in the Ballot Box? NY Assembly Considers Tech to Fight Election Fraud

Blockchain in the Ballot Box? NY Assembly Considers Tech to Fight Election Fraud

10 April 2025
0

Trusted Editorial content, reviewed by leading industry experts and seasoned editors. Ad Disclosure New York State may soon explore the...

Trump Administration Push for Blockchain-Powered USAID Overhaul—Here’s What Could Change

Trump Administration Push for Blockchain-Powered USAID Overhaul—Here’s What Could Change

22 March 2025
0

Trusted Editorial content, reviewed by leading industry experts and seasoned editors. Ad Disclosure A newly surfaced proposal concerning blockchain is...

Sony Launches Soneium, Its Own Blockchain Platform

Sony Launches Soneium, Its Own Blockchain Platform

14 January 2025
0

Sony has formally introduced its blockchain platform, Soneium, marking a substantial advancement toward decentralized technology. Sony Block Solutions Labs has...

Adopsi Blockchain Mencapai Titik Tertinggi dengan Pencapaian  Triliun pada 2024 – Detail Lengkapnya

Adopsi Blockchain Mencapai Titik Tertinggi dengan Pencapaian $10 Triliun pada 2024 – Detail Lengkapnya

3 January 2025
0

Indikator utama seperti tingkat adopsi, volume transaksi, dan tingkat aktivitas menunjukkan rekor tertinggi pada 2024, memberikan dorongan signifikan bagi teknologi...

Load More
Next Post

South Korean Exchange Foblgate Supporting XRP Flare Spark Airdrop

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Plugin Install : Widget Tab Post needs JNews - View Counter to be installed
  • Trending
  • Comments
  • Latest
Ethereum Exchange Supply Drops To Record Low Of 4.9%

Ethereum Exchange Supply Drops To Record Low Of 4.9%

21 May 2025
Near Protocol Price Prediction: 2025, 2026

Near Protocol Price Prediction: 2025, 2026

21 May 2025
SpacePay Lets You Spend Bitcoin and Ethereum Like Cash

SpacePay Lets You Spend Bitcoin and Ethereum Like Cash

21 May 2025
Ethereum Exchange Supply Hits Historic Low Below 4.9% — Is Price Breaking ,000 Soon?

Ethereum Exchange Supply Hits Historic Low Below 4.9% — Is Price Breaking $3,000 Soon?

21 May 2025

About Us

We publish a comprehensive news feed covering all news relevant to the crypto user, covering main industry news, politics and regulation as well as consumer-level “news you can use” (practical stuff), including handy DIY tips, links to useful tools, unbiased reviews and opinions revolving around cryptocurrency. Simple logic and real-world examples are preferred before technical jargon and personal rants.

Categories

  • Altcoin
  • ApeCoin
  • Bitcoin
  • Blockchain
  • BNB
  • Cardano
  • Cryptocurrency
  • DOGE
  • DOT
  • Ethereum
  • HBAR
  • Litecoin
  • Market
  • Meta News
  • Mining
  • NFT
  • QNT
  • Regulation
  • SHIBA
  • Solano
  • Tether
  • Uncategorized
  • XDC
  • XLM
  • XRP

What’s New Here!

  • Ethereum Exchange Supply Drops To Record Low Of 4.9%
  • Near Protocol Price Prediction: 2025, 2026
  • SpacePay Lets You Spend Bitcoin and Ethereum Like Cash
  • Ethereum Exchange Supply Hits Historic Low Below 4.9% — Is Price Breaking $3,000 Soon?
  • Solana Chain Extension Sonic SVM Introduces New Token Burn Program – Bitcoin.com News

Subscribe Now

Our Partner

Round Main Logo
  • About Us
  • Privacy Policy
  • Contact Us

© 2022-2025 coin24h.com

No Result
View All Result
  • Home
  • Cryptocurrency
    • Bitcoin
    • Ethereum
    • XRP
    • Litecoin
    • Altcoin
    • Cardano
    • Tether
    • DOGE
    • Solano
    • XLM
    • DOT
    • XDC
    • SHIBA
    • BNB
    • Ape
    • HBAR
    • QNT
  • Blockchain
  • Regulation
  • Market
  • Live
    • Prices
    • ICO
  • Meta
    • NFT
  • Technical Analysis
    • XRP
    • BTC
    • XLM
    • ADA
    • TETHER
    • ETC
    • ETH
    • DOGE
    • LTC
  • Exchange
  • Mining

© 2020 coin24h.com

Welcome Back!

Login to your account below

Forgotten Password? Sign Up

Create New Account!

Fill the forms below to register

All fields are required. Log In

Retrieve your password

Please enter your username or email address to reset your password.

Log In
  • bitcoinBitcoin (BTC) $ 106,716.00
  • ethereumEthereum (ETH) $ 2,555.30
  • tetherTether (USDT) $ 1.00
  • xrpXRP (XRP) $ 2.35
  • bnbBNB (BNB) $ 653.97
  • solanaSolana (SOL) $ 168.92
  • usd-coinUSDC (USDC) $ 0.999827
  • dogecoinDogecoin (DOGE) $ 0.226937
  • cardanoCardano (ADA) $ 0.754528
  • tronTRON (TRX) $ 0.271263
  • staked-etherLido Staked Ether (STETH) $ 2,549.61
  • wrapped-bitcoinWrapped Bitcoin (WBTC) $ 106,380.00
  • suiSui (SUI) $ 3.85
  • wrapped-stethWrapped stETH (WSTETH) $ 3,072.69
  • chainlinkChainlink (LINK) $ 15.88
  • avalanche-2Avalanche (AVAX) $ 22.60
  • stellarStellar (XLM) $ 0.289288
  • hyperliquidHyperliquid (HYPE) $ 26.29
  • shiba-inuShiba Inu (SHIB) $ 0.000015
  • hedera-hashgraphHedera (HBAR) $ 0.196815
  • leo-tokenLEO Token (LEO) $ 8.79
  • bitcoin-cashBitcoin Cash (BCH) $ 399.36
  • the-open-networkToncoin (TON) $ 3.05
  • litecoinLitecoin (LTC) $ 94.82
  • polkadotPolkadot (DOT) $ 4.69
  • usdsUSDS (USDS) $ 0.999881
  • wethWETH (WETH) $ 2,547.54
  • moneroMonero (XMR) $ 365.44
  • wrapped-eethWrapped eETH (WEETH) $ 2,728.66
  • bitget-tokenBitget Token (BGB) $ 5.16
  • binance-bridged-usdt-bnb-smart-chainBinance Bridged USDT (BNB Smart Chain) (BSC-USD) $ 1.00
  • pi-networkPi Network (PI) $ 0.801819
  • pepePepe (PEPE) $ 0.000014
  • ethena-usdeEthena USDe (USDE) $ 0.999823
  • coinbase-wrapped-btcCoinbase Wrapped BTC (CBBTC) $ 106,505.00
  • whitebitWhiteBIT Coin (WBT) $ 30.25
  • aaveAave (AAVE) $ 260.74
  • uniswapUniswap (UNI) $ 6.34
  • bittensorBittensor (TAO) $ 419.84
  • daiDai (DAI) $ 0.999996
  • nearNEAR Protocol (NEAR) $ 2.81
  • aptosAptos (APT) $ 5.15
  • okbOKB (OKB) $ 52.08
  • jito-staked-solJito Staked SOL (JITOSOL) $ 203.61
  • ondo-financeOndo (ONDO) $ 0.945980
  • blackrock-usd-institutional-digital-liquidity-fundBlackRock USD Institutional Digital Liquidity Fund (BUIDL) $ 1.00
  • kaspaKaspa (KAS) $ 0.110691
  • tokenize-xchangeTokenize Xchange (TKX) $ 36.09
  • crypto-com-chainCronos (CRO) $ 0.096747
  • official-trumpOfficial Trump (TRUMP) $ 14.28