By continuing to use the site or forum, you agree to the use of cookies, find out more by reading our GDPR policy

Last Thursday afternoon, Mac users everywhere began complaining of a crippling slowdown when opening apps. The cause: online certificate checks Apple performs each time a user opens an app not downloaded from the App Store. The mass upgrade to Big Sur, it seems, caused the Apple servers responsible for these checks to slow to a crawl. Apple quickly fixed the slowdown, but concerns about paralyzed Macs were soon replaced by an even bigger worry—the vast amount of personal data Apple, and possibly others, can glean from Macs performing certificate checks each time a user opens an app that didn’t come from the App Store. For people who understood what was happening behind the scenes, there was little reason to view the certificate checks as a privacy grab. Just to be sure, though, Apple on Monday published a support article that should quell any lingering worries. More about that later—first, let’s back up and provide some background. Before Apple allows an app into the App Store, it must first pass a review that vets its security. Users can configure the macOS feature known as Gatekeeper to allow only these approved apps, or they can choose a setting that also allows the installation of third-party apps, as long as these apps are signed with a developer certificate issued by Apple. To make sure the certificate hasn’t been revoked, macOS uses OCSP—short for the industry-standard Online Certificate Status Protocol — to check its validity. Checking the validity of a certificate—any certificate—authenticating a website or piece of software sounds simple enough, but it has long presented problems industrywide that aren’t easy to solve. The initial means was the use of certificate revocation lists, but as the lists grew, their size prevented them from working effectively. CRL gave way to OCSP, which performed the check on remote servers. OCSP, it turned out, had its own drawbacks. Servers sometimes go down, and when they do, OCSP server outages have the potential to paralyze millions of people trying to do things like visit sites, install apps, and check email. To guard against this hazard, OCSP defaults to what’s called a “soft fail.” Rather than block the website or software that’s being checked, OCSP will act as if the certificate is valid in the event that the server doesn’t respond. Somehow, the mass number of people upgrading to Big Sur on Thursday seems to have caused the servers at ocsp.apple.com to become overloaded but not fall over completely. The server couldn’t provide the all-clear, but it also didn’t return an error that would trigger the soft fail. The result was huge numbers of Mac users left in limbo. Apple fixed the problem with the availability of ocsp.apple.com, presumably by adding more server capacity. Normally, that would have been the end of the issue, but it wasn’t. Soon, social media was awash in claims that the macOS app-vetting process was turning Apple into a Big Brother that was tracking the time and location whenever users open or reopen any app not downloaded from the App Store. The post Your Computer Isn’t Yours was one of the catalysts for the mass concern. It noted that the simple HTML get-requests performed by OCSP were unencrypted. That meant that not only was Apple able to build profiles based on our minute-by-minute Mac usage but so could ISPs or anyone else who could view traffic passing over the network. (To prevent falling into an infinite authentication loop, virtually all OCSP traffic is unencrypted, although responses are digitally signed.) Fortunately, fewer alarmist posts like this one provided a more helpful background. The hashes being transmitted weren’t unique to the app itself but rather the Apple-issued developer certificate. That still allowed people to infer when an app such as Tor, Signal, Firefox, or Thunderbird was being used, but it was still less granular than many people first assumed. In an attempt to further assure Mac users, Apple Monday published a post. It explains what the company does and doesn’t do with the information collected through Gatekeeper and a separate feature known as notarization, which checks the security even of non-App Store apps. The post went on to say that in the next year, Apple will provide a new protocol to check if developer certificates have been revoked, provide “strong protections against server failure,” and present a new OS setting for users who want to opt-out of all of this. The controversy over behavior that macOS has been doing since at least the Catalina version was introduced last October underscores the tradeoff that sometimes occurs between security and privacy. Gatekeeper is designed to make it easy for less experienced users to steer clear of apps that are known to be malicious. To make use of Gatekeeper, users have to spend a certain amount of information to Apple. Not that Apple is completely without fault. For one thing, developers haven’t provided an easy way to opt-out of OCSP checks. That has made blocking access to ocsp.apple.com the only way to do that, and for less experienced Mac users, that’s too hard.For more turn to OUR FORUM.

European privacy activist noyb has filed a complaint to Data Protection Authorities in Germany and Spain against Apple due to its use of an opt-out tracking cookie on all iPhones. The issue is due to Apple’s tracking code “IDFA”.  IDFA (Apple’s Identifier for Advertisers) allows Apple and all apps on the phone to track a user and combine information about online and mobile behavior. Just like for cookies, this would require the users’ consent under EU law. Apple places these tracking codes without the knowledge or agreement of the users. By default, iOS automatically generates a unique “IDFA” (short for Identifier for Advertisers) for each iPhone. IDFA allows Apple and other third parties to identify users across applications and even connect online and mobile behavior (“cross-device tracking”). Apple’s operating system creates the IDFA without the user’s knowledge or consent. After its creation, Apple and third parties (e.g. application providers and advertisers) can access the IDFA to track users’ behavior, elaborate consumption preferences, and provide personalized advertising. noyb says such tracking is strictly regulated by the EU “Cookie Law” (Article 5(3) of the e-Privacy Directive) and requires the users’ informed and unambiguous consent. “EU law protects our devices from external tracking. Tracking is only allowed if users explicitly consent to it. This very simple rule applies regardless of the tracking technology used. While Apple introduced functions in their browser to block cookies, it places similar codes in its phones, without any consent by the user. This is a clear breach of EU privacy laws.” – Stefano Rossetti, privacy lawyer at noyb.eu. The system is currently Opt-out, meaning users are automatically tracked. Recently Apple announced plans for future changes to the IDFA system to Opt-in. Just like when an app requests access to the camera or microphone, the plans foresee a new dialogue that asks the user if an app should be able to access the IDFA. These changes seem to restrict the use of the IDFA for third parties, but crucially not for Apple itself. The initial storage of the IDFA and Apple’s use of it will still be done without the users’ consent and therefore in breach of EU law. It is also unclear when and if these changes will restrict 3rd party developers will be implemented by the company. “We believe that Apple violated the law before, now and after these changes. With our complaints we want to enforce a simple principle: trackers are illegal unless a user freely consents. The IDFA should not only be restricted but permanently deleted. Smartphones are the most intimate device for most people and they must be tracker-free by default.” – Stefano Rossetti, a privacy lawyer at noyb.eu Google uses a similar tracking system, which is currently being reviewed by noyb. As the complaint is based on Article 5(3) of the e-Privacy Directive and not the GDPR, the Spanish and German authorities can directly fine Apple, without the need for cooperation among EU Data Protection Authorities as under GDPR. “These cases are based on the “old” cookie law and do not trigger the cooperation mechanism of the GDPR. In other words, we are trying to avoid endless procedures like the ones we are facing in Ireland,” said Stefano Rossetti, a privacy lawyer at noyb.euFor more visit OUR FORUM.

For obvious reasons I was eager to install Big Sur on my Mac, so you can imagine my frustration after having deleted enough data on my Mac to make room for the 12.2GB Big Sur download, experienced all the issues with the download on the day it launched, I then found that My Mac was demanding that it needed another 10GB space - a total of 35GB free for it to complete the installation. We've covered some of the other problems we had while trying to install Big Sur in another article. I am hardly alone in having a Mac with just a 128GB SSD, until earlier this year the majority of Apple's Macs were being sold with no more than a 128GB SSD. I think we can safely assume that most Macs out there are similarly limited. I've been frustrated by the lack of space on my Mac for some time and had been considering buying a new one, but it is disappointing to feel forced into an upgrade by Apple. Most annoying of all, when it comes to compatibility Apple nowhere states that Big Sur will need 35GB of free space to install. Apple does make it easy to remove some of the things that are taking up space on your Mac. You can go to the Apple menu > About This Mac and look at Storage. Here you will see something like I did: GB of space attributed to Apps, Messages, Mail, … if you click on Manage you can choose from various options to take space back on your Mac: e.g. store in iCloud, Optimise Storage, and so on. The Reduce Clutter option allows you to easily delete some of the things taking up the most storage. Read more about how to free space on a Mac. One option that might be of interest here is the ability to delete the images from Messages. If you have set up Messages so that all your texts appear on your Mac as well as your other device, all the images that are sent to you will be stored on your Mac. It's easy to delete these potentially freeing up some GB of storage. The problem is that when you have done all this you are still confronted with the mysterious Other and Other Volumes in Container. The latter two are the ones taking up the most space on our Mac - and frustratingly Apple doesn't make it easy for you to delete from these. There's a reason why Apple doesn't make it easy to delete things that fall under these sections - doing so could stop things working on your Mac. For peace of mind, you could try a solution like Clean My Mac which will offer to delete things for you safely. There's a free trial that will at least scan your system to tell you how much space you can save and what can be deleted, but you'll need to pay for the full version if you want it to delete it all for you. If you don't want to pay for that then we do have a guide to deleting from Other on the Mac.  Clean My Mac suggested we could save 6GB if it deleted Caches. We need 10GB so frankly we'd still be faced with deleting things we wanted to keep in order to make space. Another option would be to do a clean install - basically, wipe our Mac completely in order to install Big Sur. Of course, if we did that we'd have to download Big Sur again or create a bootable installer first. Frankly, all these options are fine if you are familiar with Macs and have time on your hands. But the majority of people limited by 128GB storage will not be comfortable doing this. Learn more by visiting OUR FORUM.