Live data from Hacker News

Bypassing Firewalls in macOS Big Sur

twitter.com

61–70 of 251 posts

Re: Bypassing Firewalls in macOS Big Sur

#61
post #40

Of course when this possibility was raised 25 days ago on HN [1] there was a swarm of apologists who figured the superior Apple services needed no firewall interception (and just 2 days ago we learned that hell yes, they do!) and that this was all by design and impervious to abuse by other apps. Turns out, no, macOS is still written by the same old skeleton crew at Apple and they still introduce trivial problems in m…

>"Turns out, no, macOS is still written by the same old skeleton crew at Apple"

I didn't understand this reference. Who is the "same old skeleton crew"?

Re: Bypassing Firewalls in macOS Big Sur

#62

I hope this proof-of-concept is the last straw that gets Apple to walk this design decision back. Because if it doesn’t, I'm not looking forward to whatever it is that does.

I expect Apple to take the opposite path, not immediately, but eventually: disable sideloading and enforce a Mac App Store only policy on macOS, similar to iOS. After all, if all apps are reviewed and approved by Apple, there is no malware that can use this weakness or the future ones. And I am sure the 30% cut and $100 annual fee has nothing to do with the decision either. Apple only cares about customers, not money…

> I expect Apple to take the opposite path, not immediately, but eventually: disable sideloading and enforce a Mac App Store only policy on macOS, similar to iOS

Yep. And when Apple does it, HN will celebrate. There's a certain type of person who's terrified by independence and freedom and who craves the comforting safety of rules and control. macOS will be the OS for that kind of person.

Re: Bypassing Firewalls in macOS Big Sur

#63

I hope this proof-of-concept is the last straw that gets Apple to walk this design decision back. Because if it doesn’t, I'm not looking forward to whatever it is that does.

I expect Apple to take the opposite path, not immediately, but eventually: disable sideloading and enforce a Mac App Store only policy on macOS, similar to iOS. After all, if all apps are reviewed and approved by Apple, there is no malware that can use this weakness or the future ones. And I am sure the 30% cut and $100 annual fee has nothing to do with the decision either. Apple only cares about customers, not money…

There are numerous excellent reasons why that will never happen. And why it’s not in Apple’s interest to do so.

The most obvious reason is that it would utterly destroy the Mac among influencer communities and developers.

But perhaps the most underrated reason is that Apple already has a managed computing platform in the iPad. Rather than the Mac becoming more locked down, I expect the iPad will become ever-more desktop-like and take over more and more market share from traditional computers.

I’d contend that an iMac-like desktop iPad is a more likely future product than a fully locked down Mac.

Re: Bypassing Firewalls in macOS Big Sur

#66
post #20

"If Microsoft had done something like this circa 1999, it would have been used as evidence in the antitrust suit."

They did do something like this. They did lot of things like this. And now thanks to them we now also have case law saying that this is legal. :c The government has its work cut out.

I’ve used both windows and Apple developed operating systems for a long time, generally I agree with you - Microsoft is the trailblazer in user-hostile self interested decisions.

This however is something that Microsoft has absolutely dreamed about doing, but never had the power to actually make it happen. Apple wants to have the same power on the desktop that they have on iOS - no code not blessed (and taxed) by Apple run. This is what Apple wants, total control of everything executed by the cpu.

Re: Bypassing Firewalls in macOS Big Sur

#68
post #40

Of course when this possibility was raised 25 days ago on HN [1] there was a swarm of apologists who figured the superior Apple services needed no firewall interception (and just 2 days ago we learned that hell yes, they do!) and that this was all by design and impervious to abuse by other apps. Turns out, no, macOS is still written by the same old skeleton crew at Apple and they still introduce trivial problems in m…

>"Turns out, no, macOS is still written by the same old skeleton crew at Apple" I didn't understand this reference. Who is the "same old skeleton crew"?

GP is saying that the same teams have been working on macOS as before, implying they are just as fallible as previous iterations of macOS authors were by "same old", and implying that they are understaffed for the task by calling them a "skeleton crew"[0]

[0] https://en.m.wiktionary.org/wiki/skeleton_crew#:~:text=skele....

Re: Bypassing Firewalls in macOS Big Sur

#69

You play with fire you will get burned. Same thing will happen with an encryption backdoor like the EU is now thinking of forcing down our throats...

I guess it's will be to late when some "hackers from country X" gonna start to leak sensetive information on EU politicians and their relatives just before elections.

Re: Bypassing Firewalls in macOS Big Sur

#70

Earlier quoted context omitted.

I’m not sure it’s sensible to call these “protections” - they’re closer to security theater.

Can you give an example of what you consider proper protections?

You get industrial grade security solutions out of the box with many Linux distributions. You get namespaces, firewalls and seccomp for free with any Linux kernel, and any Linux system with systemd gets unprivileged containers and sandboxes for free, too. AppArmor exists for MAC, and there are userspace sandboxes.
Post reply on HN