Live data from Hacker News

Apple's apps bypass firewalls like LittleSnitch and LuLu on macOS Big Sur

twitter.com

581–590 of 649 posts

Re: Apple's apps bypass firewalls like LittleSnitch and LuLu on macOS Big Sur

#582
post #28

Earlier quoted context omitted.

Dont pray, just dont buy Apple Products

Yeah, I don't think so. I fought with technology since my late teens, and I'm just too old for that shit now. I have maybe an hour to spend on freetime every day and I want to spend exactly 0 seconds of it battling with my devices. Apple gives me that. Ubuntu gives me that these days in some limited sense too, but not when you factor in AppleTV , phone, pad, homepod and airpod and the watch.

Have Fun then, i have fun with my even less fiddli tech..like a normal watch, a real stereo and no pods....

Re: Apple's apps bypass firewalls like LittleSnitch and LuLu on macOS Big Sur

#583
post #502

Earlier quoted context omitted.

That's the exactly the thing - they are, indeed, chasing me off. When this Mac dies, I'll be replacing it with something running Debian. It is too bad - the Mac hit this sweet-spot where it was pretty much my perfect machine for several years - a kickass Unix workstation in a decently built laptop, with a decent GUI, with access to consumer apps, too. It was great while it lasted. Thing is, this is a reasonable thing…

I really thought about this yesterday, and the one program i really miss on linux would be Little Snitch. I need a good application firewall on linux.

Sounds like a business opportunity...

Re: Apple's apps bypass firewalls like LittleSnitch and LuLu on macOS Big Sur

#585
post #6

This is one of those tough cases where software cuts both ways. Some people are smart, informed developers that install a trusted tool to monitor their traffic and have legitimate reasons to want to inspect Apple traffic. They're dismayed. Most people are the opposite and this move protects the most sensitive data from being easily scooped up or muddled in easily installed apps, or at least easily installed apps that…

Actually, I don't think this is about trust. I mean, when I use an Apple OS, I (should) trust them, as their software has access to all my most sensitive digital information.

However, making it impossible to route the traffic of the system apps through a VPN of my choice (whatever the reason), is just broken functionality.

Re: Apple's apps bypass firewalls like LittleSnitch and LuLu on macOS Big Sur

#586
post #334

Earlier quoted context omitted.

Eventually I don't think little snitch will even have apis to access stuff like that in the kernel as a kext as macos updates continue on.

Kexts are used by Apple internally, so I'd be shocked if they were removed from the OS completely. Third party kexts may be deprecated, but as long as SIP can be disabled it will always be possible to load your own.

Apple could stop allowing you to load kexts they don’t sign, like they do on iOS.

Re: Apple's apps bypass firewalls like LittleSnitch and LuLu on macOS Big Sur

#587
post #510

"You have to trust Apple", it's said. But I suspect that if you actually knew how much your Apple devices were phoning home to Cupertino, you wouldn't trust Apple anymore. Using Little Snitch (the kernel extension) was a real eye opener for me. Especially when I allowed Little Snitch to block all Apple processes (by disabling the built-in iCloud Services and macOS Services rule groups). This may be a good time to rem…

Even for shell scripts? I'm still on Mojave, and now I've got even less appetite to upgrade.

Re: Apple's apps bypass firewalls like LittleSnitch and LuLu on macOS Big Sur

#588
post #527
post #510

"You have to trust Apple", it's said. But I suspect that if you actually knew how much your Apple devices were phoning home to Cupertino, you wouldn't trust Apple anymore. Using Little Snitch (the kernel extension) was a real eye opener for me. Especially when I allowed Little Snitch to block all Apple processes (by disabling the built-in iCloud Services and macOS Services rule groups). This may be a good time to rem…

Apply Occam's Razor. Why would the most successful company in history—a success gained in no small part through protecting users, selling hardware and services instead of their data, and promoting and enhancing privacy as a first-class feature—do that sort of thing? What possible benefit could such a centralized database serve? How's that gonna make them more money?

That quote—“Apple now theoretically has a centralized database of every Mac user who's ever used youtube-dl.”—is somewhat misleading.

Apple doesn’t get script contents, it only gets a hash. Of course, if Apple really wanted, they could maintain a DB of hashed contents of every possible version of youtube-dl script, and do their best to match it up with what users execute. However, even that far-fetched scenario falls apart the moment you wrap youtube-dl invocation in a convenience script—as only the hashed content of the script you invoke is submitted for notarization check, not every binary or script further launched by it.

Re: Apple's apps bypass firewalls like LittleSnitch and LuLu on macOS Big Sur

#589
post #394

Earlier quoted context omitted.

There is another - and I'd argue better - alternative for Linux and Windows: Portmaster by Safing https://safing.io/portmaster/ Not only is it an application firewall, but also gives you DNS filtering (ie. Pi-Hole basics) and DNS-over-TLS. Full Disclosure: I'm one of the founders.

But has it added pop-up per-app (and then per domain/port/ip) block/allow functionality in the Linux DE GUI yet? Thanks to your whole team for the awesome work.

This is already implemented, but was broken during an important refactor. We hope to fix it soon.

Re: Apple's apps bypass firewalls like LittleSnitch and LuLu on macOS Big Sur

#590

Earlier quoted context omitted.

Yeah if you want to wipe a laptop, make sure you unlink your user account first. It's Apple's theft protection, same as with their phones. It'll want to see a successful login with the Apple ID.

This is the worst. So many people seem to forget their apple ID password but remember their screen unlock password. I saw a case recently where someone had an attacker get access to their apple account as well as everything else. I was able to do a fresh install of their windows laptop but I was unable to reset the persons iphone because the attacker had changed the apple id password. I have also seen many android de…

Yep we have a whole box full of perfectly good phones and that's just for one office :(

However Apple does unlock them if you can prove ownership. You need an invoice with serial number. It's a lot of hassle but it works. The reason for that box is that we didn't get serial numbers on the invoices for a long time :(

It's another one of those things that are supposedly for the benefit of the consumer but also really supports the company's bottom line by having to buy a new product. I'm always a bit dubious of their motives. I do see the benefit of such features. But they should have some kind of workaround for unlocking it. Such as a card with a QR code that you get with the phone and keep on file or something. Because theft isn't the only way you can get locked out. And since the fappening Apple is really difficult with resetting passwords, in some cases people just can't make it happen.

Android is even tougher but our local carrier can send them for repair to unblock them. Also, Samsung KME overrides the lock, which makes sense because it proves the device is company owned. I wish Apple DEP could do this too.

Post reply on HN