Live data from Hacker News

Bypassing Firewalls in macOS Big Sur

twitter.com

151–160 of 251 posts

Re: Bypassing Firewalls in macOS Big Sur

#151
post #138

Unpopular opinion follows. Apparently Patrick Wardle describes a security hole, which uses the NetworkExtension framework to make it as if his code is Apple code, and thus ignores the firewall rules. My guess is, that it'll get patched and that will be that. If you think about it, blocking OS stuff makes less sense. You're already trusting the OS to a great degree. (I can understand the need for most people to contro…

For me that begs the question as to why this mechanism exists in the first place, though. Maybe apple will patch this vulnerability but people will find a way to exploit it again.

I'm sure there are advantages to system processes avoiding the firewall (inept admins unable to block updates for example) but does that outweigh the downsides?

Re: Bypassing Firewalls in macOS Big Sur

#152
post #48
post #7

How to disable this feature: https://tinyapps.org/blog/202010210700_whose_computer_is_it.... And a humorous guide on disabling protections like code signing and notarization: https://www.naut.ca/blog/2020/11/13/forbidden-commands-to-li...

Why _should_ you have to disable this feature? Sigh. My point: opting out should be much, much easier.

First boot: “Do you wish Apple to receive ... for your security?”

Most users will say yes.

Technical ones at least can say no.

Easier than setting up bluetoooth.

Re: Bypassing Firewalls in macOS Big Sur

#153
post #7

How to disable this feature: https://tinyapps.org/blog/202010210700_whose_computer_is_it.... And a humorous guide on disabling protections like code signing and notarization: https://www.naut.ca/blog/2020/11/13/forbidden-commands-to-li...

Although possible to disable the feature, those steps are crazy complicated, and probably impossible for anyone who isn't a developer. (Apart from anything else, regular users should never be advised to disable SIP.)

Why should they not? Linux for example doesn't have any such features and somehow is okay to use like that.

Re: Bypassing Firewalls in macOS Big Sur

#154

Earlier quoted context omitted.

> and that's just not an option for a pro. get 2 machines then. Who says you need to have a single machine for everything? Get a Mac for your design work, treat it like an appliance, and use Linux for everything else on another machine. Problem solved.

While I like your solution in principle, I can imagine it complicating life awfully... People email you assets/images for use in your production work: are you going to get that on your 'designer' machine or on your Linux box? Most likely the latter, now you have to transfer it over to the 'work' box. Not technically difficult, but a definite speed-bump in your workflow. Awkward. Your online document-sharing/demos (sa…

Syncthing, so you get the files even on your phone.

Re: Bypassing Firewalls in macOS Big Sur

#155
post #135

This is "bypassing firewalls in macOS BigSur" by adding an address to the firewall bypass whitelist. I can hack ipf in a similar way, adding an ACCEPT rule... Nothing to see here, move along...

Pssst, lets not turn off the Apple hate. /s I love this though, finally the GNU/Linux crowd that has been giving money to Apple for convinience, instead of sponsoring Linux OEMs gets the message.

Wouldn't you rather they give money to Apple, so there's an alternative OS to pure UNIX/Linux conformance (with Mach, file hierarchy changes, and tons of added stuff), Swift, and so on? That puts some actual pressure to those Linux OEMs and distros...

With sponsoring Linux OEMs instead we'd still have more of the same beige boxes, no new major architecture like ARM on the desktop, a Windows-2005 state of desktop environments (Linux DEs and Windows have both not just copied but dragged behind OSX/macOS changes ever since Aqua, like adding compositors, expose view, and so on, instead of coming up with their own ideas, GNOME/KDE advertise and redo on every new release stuff that was already in Windows in 2002), and so on.

Re: Bypassing Firewalls in macOS Big Sur

#156
post #48

Earlier quoted context omitted.

Why _should_ you have to disable this feature? Sigh. My point: opting out should be much, much easier.

All you need to do is to know about the linked page and have it open on another computer, disable some initial disk protections, reboot into recovery while holding down some unmentioned key combinations, disable further restrictions by typing in cryptic Terminal commands that don't match the public names of the features they affect, reboot again, type in more cryptic commands as root to modify deeply nested system fi…

It just works!

Re: Bypassing Firewalls in macOS Big Sur

#157
On my system:

  % cd /System/Library/Frameworks/
  % cd NetworkExtension.framework/
  % cd Versions/A/Resources/
  % ls -l Info.plist
  -rw-r--r--  1 root  wheel   8.9K Jan  1  2020 Info.plist
⇒ I think this requires root. That, IMO, would make it less of an issue (maybe even a good thing, given the complaints people have about Apple not giving them control over their hardware)

Re: Bypassing Firewalls in macOS Big Sur

#158

Earlier quoted context omitted.

Although possible to disable the feature, those steps are crazy complicated, and probably impossible for anyone who isn't a developer. (Apart from anything else, regular users should never be advised to disable SIP.)

Why should they not? Linux for example doesn't have any such features and somehow is okay to use like that.

What stops a Linux program altering the system? I guess you need root access to change things outside of /usr/local this could easily be done on macOS too but the wheel had to be reinvented by Apple in a way that is probably less trustworthy.

Re: Bypassing Firewalls in macOS Big Sur

#159

Ugh. I'd love to switch to Linux, but as a designer, I'm stuck. It's not a lack of understanding of how it works— Before I was a designer I was a developer, worked in IT for a while, worked in upper-level support for a while, and Linux was my primary personal and professional OS from the late 90s to like 2010. Why don't I just run a closed-source OS in a VM? They are fussy. Having some weird graphics tablet driver pr…

Freedom is hard, and thingsbcosts money if you're not willing to put willpower - more news at 11

Jokes aside you don't have to do it if you're scared, and if you want to try you can always switch back and forth between machines / OSs so you use the most suited environment according to the limits of context and the job you need to do.

Much like you can aim at 0% environment pollution by gradually removing excess stuff instead of going full off the grid, you don't have to do a radical move. Use the tools you need for the job, aiming at result production while keeping a liquid approach.

Depending on your skills, willpower, effort, and willingness to abandon uninventive corporations you can be faster and more efficient. You're just not feeling comfortable investing time and effort, which is a sacred choice.

Please consider that things have changed since 2019, VMs support of tablets and color grading tools are a breeze and using tools that your competitors are scared to use will make you innovative. Godspeed~

Re: Bypassing Firewalls in macOS Big Sur

#160

Earlier quoted context omitted.

Although possible to disable the feature, those steps are crazy complicated, and probably impossible for anyone who isn't a developer. (Apart from anything else, regular users should never be advised to disable SIP.)

Why should they not? Linux for example doesn't have any such features and somehow is okay to use like that.

A year ago, a Chrome update (its Keystone auto-update agent) corrupted system files in Macs which had SIP disabled [1]. The result was that they didn't boot anymore. Mac users who had SIP enabled were not affected.

I won't disable SIP and I'll avoid installing Google Chrome on my new Macs, if possible.

[1] https://support.google.com/chrome/thread/15235262?hl=en

Post reply on HN