Unpopular opinion follows. Apparently Patrick Wardle describes a security hole, which uses the NetworkExtension framework to make it as if his code is Apple code, and thus ignores the firewall rules. My guess is, that it'll get patched and that will be that. If you think about it, blocking OS stuff makes less sense. You're already trusting the OS to a great degree. (I can understand the need for most people to contro…
I'm sure there are advantages to system processes avoiding the firewall (inept admins unable to block updates for example) but does that outweigh the downsides?