-
-
Notifications
You must be signed in to change notification settings - Fork 2.2k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
ocsp.apple.com #1460
Comments
for reference: https://support.apple.com/en-us/HT210060 Also this: https://www.reddit.com/r/pihole/comments/e4kdhp/what_is_ocspapplecom/ |
Hi! This domain I have tracked, it is used to check certificates on Apple devices. It is not used for ad tracking or serving. In some countries (including Vietnam), users install 3rd party apps, modded apps (like Youtube Cercuber, Youtube ++ to block ads..) or modded games. The developer signs the application to be able to install IPA files on iOS iPadOS devices, when Apple discovers that it will revoke the certificate through this domain. As a result, the installed application will not be able to open. On iOS and iPadOS devices, blocking this domain name will prevent the system from checking for a valid certificate. And the installed application still opens, even though the certificate is revoked on the Apple server. Here are some of the links I have captured |
Now, Apple has created a new domain name
|
Hi @bigdargon, would you mind to share from which application or service did you make a screenshot? Thank you ❤️ |
@crssi The application above I am using is Surge 4. However, the license price with decrypt HTTPS is very expensive and has to subscribe every month. https://apps.apple.com/vn/app/surge-4/id1442620678 And another application with the same function as above, but only need to buy 1 time to use is Quantumlt X https://apps.apple.com/vn/app/quantumult-x/id1443988620 |
Thank you @bigdargon ❤️ |
I wouldn't recommend adding ocsp.apple.com - it's a valuable security feature for most users. |
Steve @StevenBlack why is this still open? I hope you're not considering blocking this domain. |
Thanks fr the reminder Dan @dnmTX. Closing. |
A place to assess this, and decide what we do.
Reference Jeff Johnson tweet thread: https://twitter.com/lapcatsoftware/status/1326990296412991489
Counterpoint: Does Apple really log every app you run? A technical look
The text was updated successfully, but these errors were encountered: