news.volyx.in

Apple memory holed its broken promise for an OCSP opt-out (lapcatsoftware.com)

422 points by latexr · 732 days ago · 108 comments on HN

Article summary

Apple made a promise in 2020 to introduce a preference for users to opt out of security protections, including OCSP checks, but this promise was never implemented and has since been removed from Apple's support documents. The OCSP service checks if an app's Developer ID code signing certificate has been revoked by Apple. The removal of the promise has raised concerns about Apple's commitment to user privacy. Users can use a firewall like Little Snitch to block these connections.

Main themes

  • Apple's privacy promises
  • OCSP checks
  • User opt-out options
  • Security vs. privacy
  • Trust in tech companies

What commenters say

  • Apple's failure to implement the promised opt-out option is a breach of trust and a shameful behavior.
  • The company's commitment to privacy is questionable, and its actions do not match its marketing claims.
  • Homomorphic encryption is a promising technology for protecting user privacy, but its implementation and effectiveness are still unclear.
  • Apple's business model is based on controlling user data, which raises concerns about its ability to prioritize user privacy.
  • Google's business model is also based on collecting user data, making it a privacy antagonist, whereas Apple's approach is seen as more privacy-focused by some.
  • The definition of privacy is nuanced, and having a single company control user data does not necessarily mean it is private.
  • The trade-offs between security, privacy, and usability are complex, and companies often prioritize the latter two for convenience.
  • Some argue that Apple's actions are not malicious, but rather a result of the tension between security, privacy, and usability.