The future for general-purpose computing
The future for general-purpose computing
Posted Dec 17, 2020 6:26 UTC (Thu) by lysse (guest, #3190)Parent article: The future for general-purpose computing
> the hash being sent is for the developer certificate, not the application itself. In many cases, that may amount to the same thing... but the OCSP check is not directly sending a hash that uniquely identifies the application
In isolation, that's true. But when you have a stream of such checks emanating from a single IP address, and you can already uniquely identify some of the applications, in many cases you'll be able to take a pretty good guess at many of the rest of them once you know their developers. So I'm not persuaded that Paul's concerns are as flawed as they've been painted here.