Get the latest tech news

Apple memory holed its broken promise for an OCSP opt-out


Feedback Assistant Boycott When you launch an app, macOS connects to Apple's OCSP service to check whether the app's Developer ID code signing certificate has been revoked by Apple. In November 2020, Apple's OCSP service experienced a mass outage, preventing Mac users worldwide from launching apps.

In November 2020, Apple's OCSP service experienced a mass outage, preventing Mac users worldwide from launching apps. In response and remedy to this outage, Apple made several explicit promises to Mac users in a support document, which can still be seen in a Wayback Machine archive from September 24, 2023. The last item, "A new preference for users to opt out of these security protections", has never been implemented in macOS, and two years ago I wrote that Apple reneged on OCSP privacy.

Get the Android app

Or read this on Hacker News

Read more on:

Photo of Apple

Apple

Photo of broken promise

broken promise

Photo of OCSP

OCSP

Related news:

News photo

Apple Releases macOS Sonoma 14.6.1 With Bug Fixes

News photo

Apple Releases iOS 17.6.1 With Advanced Data Protection Bug Fix

News photo

Apple to Address '0.0.0.0' Security Vulnerability in Safari 18