Live data from Hacker News

Bypassing Firewalls in macOS Big Sur

twitter.com

51–60 of 251 posts

Re: Bypassing Firewalls in macOS Big Sur

#51
post #32
post #28

This seems so negligent it's difficult for me to believe this was a mistake. Perhaps it could be argued that Apple doesn't want applications blocking the network traffic of trusted applications because there is limited upside to doing so and doing so may restrict core functionality such as system updates, etc. But surely the most reasonable explanation here is that Apple wants a back door to guarantee they can monito…

No, that is not the most reasonable expectation. Fails both Occam's Razor and the laugh test. To believe this, one has to believe that a $2 trillion company did this on purpose, knowing it would be revealed within hours and that it would take a major hit on the very reputation for user privacy and security that they have spent years building. There are a lot of better explanations available than "Apple decided user s…

> laugh test.

This seems a little rudely dismissive. GP's skepticism sounds totally reasonable and healthy to me.

Re: Bypassing Firewalls in macOS Big Sur

#52
post #40

Of course when this possibility was raised 25 days ago on HN [1] there was a swarm of apologists who figured the superior Apple services needed no firewall interception (and just 2 days ago we learned that hell yes, they do!) and that this was all by design and impervious to abuse by other apps. Turns out, no, macOS is still written by the same old skeleton crew at Apple and they still introduce trivial problems in m…

In the Vault 7 leaks, Little Snitch was mentioned as something three letter people had problems with circumventing. I think it's worth considering whether this new attack surface is there by design: https://blog.obdev.at/little-snitch-on-vault-7/

I didn't follow up on the Reuters news piece from January titled "Exclusive: Apple dropped plan for encrypting backups after FBI complained - sources". Has it been confirmed? If yes, then your assertion is most probably correct.

https://www.reuters.com/article/us-apple-fbi-icloud-exclusiv...

Re: Bypassing Firewalls in macOS Big Sur

#53

I hope this proof-of-concept is the last straw that gets Apple to walk this design decision back. Because if it doesn’t, I'm not looking forward to whatever it is that does.

I expect Apple to take the opposite path, not immediately, but eventually: disable sideloading and enforce a Mac App Store only policy on macOS, similar to iOS. After all, if all apps are reviewed and approved by Apple, there is no malware that can use this weakness or the future ones.

And I am sure the 30% cut and $100 annual fee has nothing to do with the decision either. Apple only cares about customers, not money. /s

Re: Bypassing Firewalls in macOS Big Sur

#54
post #48
post #7

How to disable this feature: https://tinyapps.org/blog/202010210700_whose_computer_is_it.... And a humorous guide on disabling protections like code signing and notarization: https://www.naut.ca/blog/2020/11/13/forbidden-commands-to-li...

Why _should_ you have to disable this feature? Sigh. My point: opting out should be much, much easier.

All you need to do is to know about the linked page and have it open on another computer, disable some initial disk protections, reboot into recovery while holding down some unmentioned key combinations, disable further restrictions by typing in cryptic Terminal commands that don't match the public names of the features they affect, reboot again, type in more cryptic commands as root to modify deeply nested system files and perform filesystem voodoo, and then reboot yet again with an optional prayer. Repeat for every OS update.

What could be easier?

Re: Bypassing Firewalls in macOS Big Sur

#55

Earlier quoted context omitted.

In the Vault 7 leaks, Little Snitch was mentioned as something three letter people had problems with circumventing. I think it's worth considering whether this new attack surface is there by design: https://blog.obdev.at/little-snitch-on-vault-7/

I didn't follow up on the Reuters news piece from January titled "Exclusive: Apple dropped plan for encrypting backups after FBI complained - sources". Has it been confirmed? If yes, then your assertion is most probably correct. https://www.reuters.com/article/us-apple-fbi-icloud-exclusiv...

That Reuter's piece is original reporting that Apple never responded to, so I would say that it's all but confirmed that they did in fact do this at the FBI's request.

Re: Bypassing Firewalls in macOS Big Sur

#56

"You can’t have a back door in the software because you can’t have a back door that’s only for the good guys." — Tim Cook

Does it look like the software part of Apple has been consistently grappled with controversial decisions? I heard Apple has been very secretive in its development. Maybe it works for hardware, but software is an area where collaboration across teams are very important, isolated bubble breeds incompetence and politics.

I don’t think there’s any secrecy left nowadays with Apple’s hardware, just a theatre. Their presentations are the least surprising of all tech firms - partly due leaks part due to super conservative feature development (if any).

Re: Bypassing Firewalls in macOS Big Sur

#57

I hope this proof-of-concept is the last straw that gets Apple to walk this design decision back. Because if it doesn’t, I'm not looking forward to whatever it is that does.

I expect Apple to take the opposite path, not immediately, but eventually: disable sideloading and enforce a Mac App Store only policy on macOS, similar to iOS. After all, if all apps are reviewed and approved by Apple, there is no malware that can use this weakness or the future ones. And I am sure the 30% cut and $100 annual fee has nothing to do with the decision either. Apple only cares about customers, not money…

Amazing how pretty much all tech companies get away with same arguments when they try to protect their monopoly

Apple - "we want to keep it simple to our users"

Google - "AI doesn't have any control over data we've collected"

Facebook - "Every company is spying on their users"

Amazon - "we control mere 10% of global economy"

Salesforce - "you can ‘easily’ export your data from our completely proprietary platform"

Re: Bypassing Firewalls in macOS Big Sur

#58
post #7

How to disable this feature: https://tinyapps.org/blog/202010210700_whose_computer_is_it.... And a humorous guide on disabling protections like code signing and notarization: https://www.naut.ca/blog/2020/11/13/forbidden-commands-to-li...

Although possible to disable the feature, those steps are crazy complicated, and probably impossible for anyone who isn't a developer. (Apart from anything else, regular users should never be advised to disable SIP.)

Re: Bypassing Firewalls in macOS Big Sur

#60
post #48
post #7

How to disable this feature: https://tinyapps.org/blog/202010210700_whose_computer_is_it.... And a humorous guide on disabling protections like code signing and notarization: https://www.naut.ca/blog/2020/11/13/forbidden-commands-to-li...

Why _should_ you have to disable this feature? Sigh. My point: opting out should be much, much easier.

The easier it is to opt out, the more likely it is for sketchy developers to guide tech-novice users through that process, the more likely it is for malicious actors to take advantage of those who opted out.
Post reply on HN