Live data from Hacker News

Bypassing Firewalls in macOS Big Sur

twitter.com

81–90 of 251 posts

Re: Bypassing Firewalls in macOS Big Sur

#81
I'm done with Apple. It's incredibly restrictive for no real gain at this point. I have a really old MB Air I only ever use to compile apps for the App Store for clients, but otherwise there's no clear path towards improvement from them, so I'm voting with my wallet for the foreseeable future.

Re: Bypassing Firewalls in macOS Big Sur

#82
post #40

Of course when this possibility was raised 25 days ago on HN [1] there was a swarm of apologists who figured the superior Apple services needed no firewall interception (and just 2 days ago we learned that hell yes, they do!) and that this was all by design and impervious to abuse by other apps. Turns out, no, macOS is still written by the same old skeleton crew at Apple and they still introduce trivial problems in m…

In the Vault 7 leaks, Little Snitch was mentioned as something three letter people had problems with circumventing. I think it's worth considering whether this new attack surface is there by design: https://blog.obdev.at/little-snitch-on-vault-7/

Why is this comment greyed out? It's an entirely valid question to arrive at.

Re: Bypassing Firewalls in macOS Big Sur

#83
post #13

This whole release cycle is just one gigantic facepalm after another. I am feeling pretty heavily smug that I got rid of my Apple kit earlier this year because I wasn't happy with the direction of the platform.

What did you move to?

Thinkpad T460p on arch linux for me (after getting macbook pro 2017 15 inch keyboard issues followed with cablegate immediately afterwards).

The T460p is a 2016/17 secondhand machine which cost USD235 which I then added a ram upgrade and a new 72Wh battery to. I don't miss the mbp at all and prefer the linux OS anyway.

It probably took me until this moment to realise I was largely falling for marketing in thinking only the best specs would do ...

Re: Bypassing Firewalls in macOS Big Sur

#84

Earlier quoted context omitted.

In the Vault 7 leaks, Little Snitch was mentioned as something three letter people had problems with circumventing. I think it's worth considering whether this new attack surface is there by design: https://blog.obdev.at/little-snitch-on-vault-7/

Why is this comment greyed out? It's an entirely valid question to arrive at.

Possibly someone(s) not familiar with the reporting that implicates the possibility that speculation is correct.

Re: Bypassing Firewalls in macOS Big Sur

#85
I commented on your Twitter post already, but I'll reiterate here. This is not a vulnerability, it is as intended. By default, you can only install Applications via the App Store on Big Sur, and AppProxyProvider only affects Applications installed via this method.

This has the dual-benefit of protecting casual users, and allowing power-users flexibility with any binaries that aren't sandboxed. From what I understand of your example, you used the bundled python installation to make the connection, the python binary is not sandboxed and is not affected by AppProxyProvider. This will be the case with any other binaries as well -- ping, ssh, etc...

The relevant documentation is at: https://developer.apple.com/documentation/networkextension/a...

Specifically the section I've highlighted here: https://share.getcloudapp.com/Z4uyONmJ

Re: Bypassing Firewalls in macOS Big Sur

#86
post #72

This reminds me of the old saying that it's impossible to work within an infected system to clean it --- and now that corporations have been "infecting" systems with such telemetry/spyware by default, that's even more true. I believe Win10 was the first to do something like this --- it ignores the hosts files and firewall for certain hardcoded domain names and IPs.

https://en.wikipedia.org/wiki/Hosts_(file) If you want to block something use a firewall.

"use a firewall" -> "use an external firewall". :)

Re: Bypassing Firewalls in macOS Big Sur

#87

This reminds me of the old saying that it's impossible to work within an infected system to clean it --- and now that corporations have been "infecting" systems with such telemetry/spyware by default, that's even more true. I believe Win10 was the first to do something like this --- it ignores the hosts files and firewall for certain hardcoded domain names and IPs.

See also: https://wiki.c2.com/?TheKenThompsonHack

Re: Bypassing Firewalls in macOS Big Sur

#88

Earlier quoted context omitted.

Does it look like the software part of Apple has been consistently grappled with controversial decisions? I heard Apple has been very secretive in its development. Maybe it works for hardware, but software is an area where collaboration across teams are very important, isolated bubble breeds incompetence and politics.

I don’t think there’s any secrecy left nowadays with Apple’s hardware, just a theatre. Their presentations are the least surprising of all tech firms - partly due leaks part due to super conservative feature development (if any).

Yeah, I remember when their hardware announcements were pretty much airtight. Up to Apple black-balling Gizmodo from all events after Gizmodo got ahold of an unreleased iPhone an employee had lost. Even then the phone was disguised inside the shell of an older model. [0]

The person that found the phone only poked around after he was confused when it went bricked a few hours later (remotely done by Apple). Then they actually tried to get it back to Apple, and got blown off. That's when they contacted Gizmodo. I think Apple was pissed that Gizmodo paid $5,000 to get it from the finder and didn't return it immediately to Apple without question or inspection.

[0] https://gizmodo.com/how-apple-lost-the-iphone-4-5520438

Re: Bypassing Firewalls in macOS Big Sur

#89

Earlier quoted context omitted.

Former name for macOS.

I just call it A/UX 2.0 I try to forget those in between years of of System 7 / OS8 / OS9. They all gave me deep scars through countless hours spent troubleshooting extension conflicts. All while seeing the unhelpful, literal bomb icon dozens of times in a row [0]. The windows BSOD was bad, but at least it never mocked you about the OS blowing up. [0] https://www.versionmuseum.com/images/operating-systems/class... Mo…

Come on downvoters, you can do better than -2. I know, I criticized Apple's old OS, I deserve it.

Re: Bypassing Firewalls in macOS Big Sur

#90

Earlier quoted context omitted.

I expect Apple to take the opposite path, not immediately, but eventually: disable sideloading and enforce a Mac App Store only policy on macOS, similar to iOS. After all, if all apps are reviewed and approved by Apple, there is no malware that can use this weakness or the future ones. And I am sure the 30% cut and $100 annual fee has nothing to do with the decision either. Apple only cares about customers, not money…

> I expect Apple to take the opposite path, not immediately, but eventually: disable sideloading and enforce a Mac App Store only policy on macOS, similar to iOS Yep. And when Apple does it, HN will celebrate. There's a certain type of person who's terrified by independence and freedom and who craves the comforting safety of rules and control. macOS will be the OS for that kind of person.

Some people maybe.

Apple has all but guaranteed that my current Mac will be my last. I have been using Macs since the Mac IIx, and my first Mac laptop was the Powerbook 190.

The only reason that I have my Mid 2018 Macbook Pro, is that I bought it in Budapest after my previous machine died, and the reseller Apple store was the only one that stocked English keycaps for the keyboard (they did have to unbox and change the keycaps).

My technology choices are starting to feel frustratingly niche. I am using Apple over Linux because I tired of having to mess around with the systems constantly to get things working. ItJustWorks™ is a powerful driver.

If I'm being honest with myself, it's also a question of access to paid apps. If I list all the apps I use on a daily basis, a bunch of them are Mac only, and an even smaller set run on Linux (even if they have a Windows version as well).

Post reply on HN