This is spot on. I recognize that the purpose of the service from Apple is to prevent malware from running on your Mac, but it doesn’t sit right with me. Especially that the data is sent unencrypted over the net. Combined with not being able unsigned code on the M1, I’m wondering if my mid-2014 Mac might not be my last.

  1. @JeremyWxBaker Which part? It appears that the Apple service validates the certificate that was used to sign the app, right? That alone could identify you are running some apps (like Tor). Since it’s sent in clear text, any entity between you and that service can tell that you’re running Tor. Depending on that entity that could put you on some black lists.

