惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

MyScale Blog
MyScale Blog
博客园 - 叶小钗
小众软件
小众软件
宝玉的分享
宝玉的分享
Apple Machine Learning Research
Apple Machine Learning Research
Jina AI
Jina AI
Last Week in AI
Last Week in AI
量子位
腾讯CDC
罗磊的独立博客
酷 壳 – CoolShell
酷 壳 – CoolShell
博客园 - Franky
博客园 - 【当耐特】
Hugging Face - Blog
Hugging Face - Blog
有赞技术团队
有赞技术团队
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
V
Visual Studio Blog
爱范儿
爱范儿
月光博客
月光博客
博客园 - 三生石上(FineUI控件)
雷峰网
雷峰网
V
V2EX
WordPress大学
WordPress大学
Google DeepMind News
Google DeepMind News
阮一峰的网络日志
阮一峰的网络日志
K
Kaspersky official blog
Vercel News
Vercel News
L
LINUX DO - 热门话题
The Hacker News
The Hacker News
The Register - Security
The Register - Security
IT之家
IT之家
C
Cybersecurity and Infrastructure Security Agency CISA
Threat Intelligence Blog | Flashpoint
Threat Intelligence Blog | Flashpoint
人人都是产品经理
人人都是产品经理
Martin Fowler
Martin Fowler
S
SegmentFault 最新的问题
N
News | PayPal Newsroom
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
Attack and Defense Labs
Attack and Defense Labs
S
Securelist
T
The Blog of Author Tim Ferriss
GbyAI
GbyAI
Microsoft Security Blog
Microsoft Security Blog
H
Hacker News: Front Page
博客园 - 聂微东
Exploit-DB.com RSS Feed
Exploit-DB.com RSS Feed
Project Zero
Project Zero
I
InfoQ
K
KPMG report finds enterprise disconnect between AI and its ROI | CIO
PCI Perspectives
PCI Perspectives

Peter Steinberger

OpenClaw, OpenAI and the future | Peter Steinberger Shipping at Inference-Speed | Peter Steinberger The Signature Flicker | Peter Steinberger Just Talk To It - the no-bs Way of Agentic Engineering | Peter Steinberger Claude Code Anonymous | Peter Steinberger Live Coding Session: Building Arena | Peter Steinberger My Current AI Dev Workflow | Peter Steinberger Essential Reading for Agentic Engineers - August 2025 | Peter Steinberger Just One More Prompt | Peter Steinberger Poltergeist: The Ghost That Keeps Your Builds Fresh | Peter Steinberger Don't read this Startup Slop | Peter Steinberger Essential Reading for Agentic Engineers - July 2025 | Peter Steinberger Self-Hosting AI Models After Claude's Usage Limits | Peter Steinberger VibeTunnel's first AI-anniversary | Peter Steinberger Making AppleScript Work in macOS CLI Tools: The Undocumented Parts | Peter Steinberger Peekaboo 2.0 – Free the CLI from its MCP shackles | Peter Steinberger Command your Claude Code Army, Reloaded | Peter Steinberger Essential Reading for Agentic Engineers | Peter Steinberger Slot Machines for Programmers: How Peter Builds Apps 20x Faster with AI | Peter Steinberger My AI Workflow for Understanding Any Codebase | Peter Steinberger stats.store: Privacy-First Sparkle Analytics | Peter Steinberger Showing Settings from macOS Menu Bar Items: A 5-Hour Journey | Peter Steinberger VibeTunnel: Turn Any Browser into Your Mac's Terminal | Peter Steinberger Vibe Meter 2.0: Calculating Claude Code Usage with Token Counting | Peter Steinberger llm.codes: Make Apple Docs AI-Readable | Peter Steinberger Automatic Observation Tracking in UIKit and AppKit: The Feature Apple Forgot to Mention | Peter Steinberger Peekaboo MCP – lightning-fast macOS screenshots for AI agents | Peter Steinberger Migrating 700+ Tests to Swift Testing: A Real-World Experience | Peter Steinberger Commanding Your Claude Code Army | Peter Steinberger Code Signing and Notarization: Sparkle and Tears | Peter Steinberger Vibe Meter: Monitor Your AI Costs | Peter Steinberger Claude Code is My Computer | Peter Steinberger Stop Over-thinking AI Subscriptions | Peter Steinberger Introducing Demark: HTML in. MD out. Blink-fast. | Peter Steinberger The Future of Vibe Coding: Building with AI, Live and Unfiltered | Peter Steinberger MCP Best Practices | Peter Steinberger Finding My Spark Again | Peter Steinberger Top-Level Menu Visibility in SwiftUI for macOS | Peter Steinberger Fixing keyboardShortcut in SwiftUI | Peter Steinberger Supporting Both Tap and Long Press on a Button in SwiftUI | Peter Steinberger On Using Apple Silicon Mac Mini for Continuous Integration | Peter Steinberger Apple Silicon M1: A Developer's Perspective | Peter Steinberger Gardening Your Twitter: Curating Your Timeline | Peter Steinberger Gardening Your Twitter: Growing Your Followers | Peter Steinberger Forbidden Controls in Catalyst: Optimize Interface for Mac | Peter Steinberger Disabling Keyboard Avoidance in SwiftUI's UIHostingController | Peter Steinberger The State of SwiftUI | Peter Steinberger Logging in Swift | Peter Steinberger Building with Swift Trunk Development Snapshots | Peter Steinberger Calling Super at Runtime in Swift | Peter Steinberger zld — A Faster Version of Apple's Linker | Peter Steinberger How to Fix LLDB: Couldn't IRGen Expression | Peter Steinberger Updating macOS on a Hackintosh | Peter Steinberger InterposeKit — Elegant Swizzling in Swift | Peter Steinberger The Great Mac Catalyst Text Input Crash Hunt | Peter Steinberger Jailbreaking for iOS Developers | Peter Steinberger Network Kernel Core Dump | Peter Steinberger How to macOS Core Dump | Peter Steinberger Kernel Panics and Surprise boot-args | Peter Steinberger The LG UltraFine 5K, kernel_task, and Me | Peter Steinberger Let's Try This Again | Peter Steinberger How We Work at PSPDFKit | Peter Steinberger Swizzling in Swift | Peter Steinberger WWDC for First-Timers, 2019 Edition | Peter Steinberger Challenges of Adopting Drag and Drop | Peter Steinberger Marzipan: Porting iOS Apps to the Mac | Peter Steinberger How to Use Slack and Not Go Crazy | Peter Steinberger Hardcore Debugging - Heavy Weapons for Hard Bugs | Peter Steinberger Binary Frameworks in Swift | Peter Steinberger Even Swiftier Objective-C | Peter Steinberger The Case for Deprecating UITableView | Peter Steinberger Running tests with Clang Address Sanitizer | Peter Steinberger UI testing on iOS, without busy waiting | Peter Steinberger Hiring a distributed team | Peter Steinberger Writing Good Bug Reports | Peter Steinberger Real-time collaboration, Apple, and you | Peter Steinberger Converting Xcode Test Runs to JUnit, the Fast Way | Peter Steinberger Efficient iOS Version Checking | Peter Steinberger Investigating Thread Safety of UIImage | Peter Steinberger Swifty Objective-C | Peter Steinberger Running UI Tests on iOS With Ludicrous Speed | Peter Steinberger A Pragmatic Approach to Cross-Platform | Peter Steinberger Surprises with Swift Extensions | Peter Steinberger Using ccache for Fun and Profit | Peter Steinberger UITableViewController designated initializer woes | Peter Steinberger Researching ResearchKit | Peter Steinberger The curious case of rotation with multiple windows on iOS 8 | Peter Steinberger UIKit Debug Mode | Peter Steinberger Retrofitting containsString: on iOS 7 | Peter Steinberger A Story About Swizzling "the Right Way™" and Touch Forwarding | Peter Steinberger Hacking with Aspects | Peter Steinberger Fixing UITextView On iOS 7 | Peter Steinberger Fixing What Apple Doesn't | Peter Steinberger How To Inspect The View Hierarchy Of Third-Party Apps | Peter Steinberger Fixing UISearchDisplayController On iOS 7 | Peter Steinberger Smart Proxy Delegation | Peter Steinberger Adding Keyboard Shortcuts To UIAlertView | Peter Steinberger How To Center Content Within UIScrollView | Peter Steinberger UIAppearance for Custom Views | Peter Steinberger Hacking Block Support Into UIMenuItem | Peter Steinberger
Logging Privacy Shenanigans | Peter Steinberger
Peter Steinberger · 2025-07-29 · via Peter Steinberger

TL;DR – Apple logs hide the juicy debugging bits as <private>. Drop plist files into /Library/Preferences/Logging/Subsystems/ for a simpler solution, or install a configuration profile as an alternative.

If you’ve ever tried debugging a macOS app using the unified logging system, you’ve probably encountered the dreaded <private> redaction. Your carefully crafted log messages turn into cryptic puzzles where the most important debugging information is hidden. Let me show you what’s really going on and how to work around it.

The Privacy Problem

When you log something like this in Swift:

logger.info("User \(username) connected to session \(sessionId)")

You expect to see:

User john.doe connected to session ABC-123-DEF

But instead you get:

User <private> connected to session <private>

Not very helpful when you’re trying to debug an issue, right?

What Actually Gets Redacted

Here’s where it gets interesting. Through testing, I discovered that Apple’s redaction logic is not as straightforward as the documentation suggests:

What you logDocumentation saysReality
Simple strings ("user@example.com")RedactedUsually redacted!
File paths (/Users/username)Redacted✓ Redacted
UUIDs (ABC-123-DEF)Redacted✓ Redacted
Integers, booleans, floatsPublic✓ Public

The discrepancy comes from how Apple’s logging system is implemented. The os_log function requires format strings to be compile-time constants (C string literals) for performance optimization. When you use string interpolation with dynamic values, the compiler and logging library work together to mark these as runtime data that needs privacy protection.

Static strings embedded directly in your code are treated as part of the format string and assumed to be non-sensitive, while any runtime values (variables, computed properties, function returns) are automatically redacted to prevent accidental leakage of personal information.

Old Solutions That No Longer Work

Before we get to what works, let’s quickly cover what doesn’t work anymore:

❌ The private_data:on flag (Dead since Catalina)

# This returns "Invalid Modes 'private_data:on'" on macOS 10.15+
sudo log config --mode "private_data:on" --subsystem your.app.subsystem

This was completely removed in macOS Catalina (10.15) and later.

❌ sudo doesn’t reveal private data

You might think running with sudo would show everything:

sudo log show --predicate 'subsystem == "your.app"' --info

Nope! The privacy redaction happens at write time, not read time. Once logged as <private>, the actual data is gone forever.

The Plist Solution (Preferred Method)

Thanks to Rasmus Sten for pointing out this elegant solution! You don’t need to use .mobileconfig files – you can simply drop plist files directly into /Library/Preferences/Logging/Subsystems/. This is actually what happens when you install a configuration profile anyway.

Step 1: Create a Plist File

Create a file named after your subsystem (e.g., com.mycompany.myapp.plist) with this content:

<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd">
<plist version="1.0">
<dict>
    <key>DEFAULT-OPTIONS</key>
    <dict>
        <key>Enable-Private-Data</key>
        <true/>
    </dict>
</dict>
</plist>

Step 2: Install the Plist

# Create the directory if it doesn't exist
sudo mkdir -p /Library/Preferences/Logging/Subsystems/

# Copy your plist file
sudo cp com.mycompany.myapp.plist /Library/Preferences/Logging/Subsystems/

# Set proper permissions
sudo chmod 644 /Library/Preferences/Logging/Subsystems/com.mycompany.myapp.plist

Important Gotcha: When writing these plist files programmatically, you must write them atomically. Write to a temporary file first, then use mv to move it into place. This ensures the logging subsystem sees a complete, valid plist file.

Step 3: Generate Fresh Logs

The configuration only affects new log entries. Run your app to generate fresh logs.

Step 4: Remove After Debugging

sudo rm /Library/Preferences/Logging/Subsystems/com.mycompany.myapp.plist

Why This Method is Better

  • Scriptable: Can be added/removed programmatically from shell scripts
  • No UI interaction: No need to navigate System Settings
  • Granular control: Enable/disable specific subsystems instantly
  • CI/CD friendly: Perfect for automated testing environments

Documentation

This approach is documented in:

The Configuration Profile Solution (Alternative Method)

If you prefer a GUI approach or need to deploy settings across multiple machines, you can still use configuration profiles:

View Configuration Profile Template
<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd">
<plist version="1.0">
<dict>
    <key>PayloadContent</key>
    <array>
        <dict>
            <key>PayloadDisplayName</key>
            <string>ManagedClient logging</string>
            <key>PayloadEnabled</key>
            <true/>
            <key>PayloadIdentifier</key>
            <string>com.yourapp.logging.EnablePrivateData</string>
            <key>PayloadType</key>
            <string>com.apple.system.logging</string>
            <key>PayloadUUID</key>
            <string>GENERATE-UUID-1</string>
            <key>PayloadVersion</key>
            <integer>1</integer>
            <key>System</key>
            <dict>
                <key>Enable-Private-Data</key>
                <true/>
            </dict>
            <key>Subsystems</key>
            <dict>
                <key>your.app.subsystem</key>
                <dict>
                    <key>DEFAULT-OPTIONS</key>
                    <dict>
                        <key>Enable-Private-Data</key>
                        <true/>
                    </dict>
                </dict>
            </dict>
        </dict>
    </array>
    <key>PayloadDescription</key>
    <string>This profile enables logging of private data for debugging.</string>
    <key>PayloadDisplayName</key>
    <string>Your App Private Data Logging</string>
    <key>PayloadIdentifier</key>
    <string>com.yourapp.PrivateDataLogging</string>
    <key>PayloadOrganization</key>
    <string>Your Organization</string>
    <key>PayloadRemovalDisallowed</key>
    <false/>
    <key>PayloadType</key>
    <string>Configuration</string>
    <key>PayloadUUID</key>
    <string>GENERATE-UUID-2</string>
    <key>PayloadVersion</key>
    <integer>1</integer>
</dict>
</plist>

Customizing the Profile

Critical Components to Replace:

  1. UUIDs: Two unique identifiers are required:

    • Replace GENERATE-UUID-1 and GENERATE-UUID-2 with actual UUIDs
    • Generate with: uuidgen (run twice for two different UUIDs)
  2. Organization: Replace Your Organization with your actual organization or app name

  3. Subsystems: The most critical part! Replace your.app.subsystem with your actual logging subsystem(s):

    let logger = Logger(subsystem: "com.mycompany.myapp", category: "Network")

    In this example, "com.mycompany.myapp" is the subsystem you need to add.

  4. Multiple Subsystems: To enable private data for multiple subsystems, duplicate the subsystem structure:

    <key>Subsystems</key>
    <dict>
        <key>com.mycompany.myapp</key>
        <dict>
            <key>DEFAULT-OPTIONS</key>
            <dict>
                <key>Enable-Private-Data</key>
                <true/>
            </dict>
        </dict>
        <key>com.mycompany.myframework</key>
        <dict>
            <key>DEFAULT-OPTIONS</key>
            <dict>
                <key>Enable-Private-Data</key>
                <true/>
            </dict>
        </dict>
    </dict>

Key Implementation Details:

  • PayloadType values: The top-level PayloadType must be Configuration, while the inner PayloadType (in PayloadContent) must be com.apple.system.logging
  • PayloadRemovalDisallowed: Keep this as false so you can easily remove the profile after debugging
  • System section: Enables private data for system-level logs
  • DEFAULT-OPTIONS: Required wrapper for subsystem options

Save the customized file as EnablePrivateLogging.mobileconfig.

Installing Configuration Profiles

  1. Double-click the .mobileconfig file
  2. Navigate to:
    • macOS 15 (Sequoia) and later: System Settings → General → Device Management
    • macOS 14 (Sonoma) and earlier: System Settings → Privacy & Security → Profiles
  3. Click “Install…” and authenticate
  4. Wait 1-2 minutes for the system to apply changes

Removing Configuration Profiles

Go back to the Profiles/Device Management section and click the minus (-) button.

The Code-Level Solution

For production apps, mark specific non-sensitive values as public:

// This will always be visible
logger.info("Session: \(sessionId, privacy: .public)")

// This remains private by default
logger.info("Token: \(apiToken)")

This is the safest approach as you explicitly control what’s exposed.

Automating with Claude Code

Instead of manually editing configuration files, just give Claude Code this blog post URL and ask it to create a customized plist or profile for your app. Living in the future means your documentation can be both human-readable and agent-executable.

Summary

Apple’s log privacy is well-intentioned but can be frustrating during development. The plist approach is your best bet for debugging:

  1. Privacy redaction happens at write time
  2. sudo can’t recover what was never stored
  3. Direct plist files are simpler than configuration profiles
  4. Always remove debugging configurations when done

For more details on this topic, check out:

Happy debugging, and may your logs be forever unredacted (but only when you need them to be)!