Live data from Hacker News

Apple removes first-party firewall exemption in macOS 11.2 beta 2

twitter.com

21–30 of 354 posts

Re: Apple removes first-party firewall exemption in macOS 11.2 beta 2

#21
post #17

Earlier quoted context omitted.

This happened so quickly I suspect there was never a decision for or against. Pretty likely a boneheaded engineer did what us boneheaded engineers do and cut corners, likely with all of the fun boneheaded management and deadlines that come along for the ride. Why, you might ask, would this be a matter of cutting corners? Well, fault tolerance is hard . What happens when the OS can’t reach external services it depends…

The imagined timeline of this comment doesn't seem to align with reality. The exclusion list was already present in the first WWDC builds in summer 2020, as the Little Snitch developers noticed: https://blog.obdev.at/a-hole-in-the-wall/ The Mac "OSCP appocalypse" occurred in November on the day that Big Sur was released to the public, with the exclusion list still present, and a number of firewall developers were alr…

I don't think the comment you're replying to made specific claims about this timeline.

Re: Apple removes first-party firewall exemption in macOS 11.2 beta 2

#22
post #18

Earlier quoted context omitted.

Having worked at Apple and other big companies it's almost always Engineers and PMs making these decisions. It's not like Tim Cook or Craig Federighi is running around demanding people add Apple apps to a firewall exclusion list. They have much bigger things to worry about. It's just that as an engineer you are often in a bubble and can't foresee every implication of your decision. That's why Apple has the Developer…

> That's why Apple has the Developer and Public Beta releases for iOS/OSX so that external users can provide feedback. And on this occasion just like on many other they will take action if necessary. Except that Apple did not take action. Firewall developers such as Little Snitch did become aware of the issue during the beta releases and gave feedback to Apple, which Apple ignored and shipped it anyway to the public.…

It's reasonable not to take action based on the feedback from a developer who sells an app-level firewall - it's neither a broad nor disinterested constituency. Big Sur's been out for less than two months - for a bigass company, it's decent turnaround.

Re: Apple removes first-party firewall exemption in macOS 11.2 beta 2

#23

Earlier quoted context omitted.

Having worked at Apple and other big companies it's almost always Engineers and PMs making these decisions. It's not like Tim Cook or Craig Federighi is running around demanding people add Apple apps to a firewall exclusion list. They have much bigger things to worry about. It's just that as an engineer you are often in a bubble and can't foresee every implication of your decision. That's why Apple has the Developer…

> Having worked at Apple and other big companies it's almost always Engineers and PMs making these decisions. It's not like Tim Cook or Craig Federighi is running around demanding people add Apple apps to a firewall exclusion list. They have much bigger things to worry about. This more or less confirms my hunch. Thanks for inside perspective on it. That’s how literally every other org works but I know Apple got this…

> it’s good to have a reminder that at the end of the day it’s not the borg.

The impression I always got was more like a mid-to-late USSR than the Borg (in structure rather than efficacy, the USSR didn't work, apple does). Everyone in the Borg is (supposed to be) identical, whereas Apple seems like a structure of lots of groups of often brilliant people working in seperate-but-equal subtrees, working under a (especially under Jobs) ideologically-inspired dictator from the top down. The way Apple are fairly reticent to document what they make partly informs the comparison.

Re: Apple removes first-party firewall exemption in macOS 11.2 beta 2

#24
post #22
post #18

Earlier quoted context omitted.

> That's why Apple has the Developer and Public Beta releases for iOS/OSX so that external users can provide feedback. And on this occasion just like on many other they will take action if necessary. Except that Apple did not take action. Firewall developers such as Little Snitch did become aware of the issue during the beta releases and gave feedback to Apple, which Apple ignored and shipped it anyway to the public.…

It's reasonable not to take action based on the feedback from a developer who sells an app-level firewall - it's neither a broad nor disinterested constituency. Big Sur's been out for less than two months - for a bigass company, it's decent turnaround.

Who else would Apple take feedback from during the betas? Who else would even notice that there was a hole in the firewalls except the firewall developers?

Re: Apple removes first-party firewall exemption in macOS 11.2 beta 2

#25
post #18

Earlier quoted context omitted.

Having worked at Apple and other big companies it's almost always Engineers and PMs making these decisions. It's not like Tim Cook or Craig Federighi is running around demanding people add Apple apps to a firewall exclusion list. They have much bigger things to worry about. It's just that as an engineer you are often in a bubble and can't foresee every implication of your decision. That's why Apple has the Developer…

> That's why Apple has the Developer and Public Beta releases for iOS/OSX so that external users can provide feedback. And on this occasion just like on many other they will take action if necessary. Except that Apple did not take action. Firewall developers such as Little Snitch did become aware of the issue during the beta releases and gave feedback to Apple, which Apple ignored and shipped it anyway to the public.…

> Except that Apple did not take action.

Look, I don't mean to criticise. But how do you know that Apple didn't start working on a fix when they were told about it?

Apple doesn't exactly say when they start working on a fix for something, or else we would have known earlier.

Re: Apple removes first-party firewall exemption in macOS 11.2 beta 2

#26
post #18

Earlier quoted context omitted.

> That's why Apple has the Developer and Public Beta releases for iOS/OSX so that external users can provide feedback. And on this occasion just like on many other they will take action if necessary. Except that Apple did not take action. Firewall developers such as Little Snitch did become aware of the issue during the beta releases and gave feedback to Apple, which Apple ignored and shipped it anyway to the public.…

> Except that Apple did not take action. Look, I don't mean to criticise. But how do you know that Apple didn't start working on a fix when they were told about it? Apple doesn't exactly say when they start working on a fix for something, or else we would have known earlier.

There was a ContentFilterExclusionList key in the /System/Library/Frameworks/NetworkExtension.framework/Versions/Current/Resources/Info.plist file. macOS 11.2 beta 2 removed the ContentFilterExclusionList. Does that take 6 months?

Re: Apple removes first-party firewall exemption in macOS 11.2 beta 2

#27

So does this mean we won’t be seeing the behavior I just documented the other day on here? https://news.ycombinator.com/item?id=25746007 In sum, they’re intentionally circumventing DNS, /etc/hosts, and even IPv4 blackholing by attempting to send their phone-home packets through IPv6. Then if you block that as well your computer constantly freezes.

The screenshot shows init-p01st.push.apple.com and ##-courier.push.apple.com, none of which have IPv6 AAAA records that I can see.

Re: Apple removes first-party firewall exemption in macOS 11.2 beta 2

#28

So does this mean we won’t be seeing the behavior I just documented the other day on here? https://news.ycombinator.com/item?id=25746007 In sum, they’re intentionally circumventing DNS, /etc/hosts, and even IPv4 blackholing by attempting to send their phone-home packets through IPv6. Then if you block that as well your computer constantly freezes.

That's an odd one. If my Mac is offline it works just fine. Perhaps your filtering/firewalling isn't complete so it gets partial connections and then times out on the rest? If you do that in large quantities, any OS will start to show trouble.

Re: Apple removes first-party firewall exemption in macOS 11.2 beta 2

#30

So does this mean we won’t be seeing the behavior I just documented the other day on here? https://news.ycombinator.com/item?id=25746007 In sum, they’re intentionally circumventing DNS, /etc/hosts, and even IPv4 blackholing by attempting to send their phone-home packets through IPv6. Then if you block that as well your computer constantly freezes.

That's an odd one. If my Mac is offline it works just fine. Perhaps your filtering/firewalling isn't complete so it gets partial connections and then times out on the rest? If you do that in large quantities, any OS will start to show trouble.

Timing out packets instead of denying them could certainly be an issue (I run across this a lot with internet being down while the router and internal DNS is still up).

But your claim that “any OS will start to show trouble” is not how it’s supposed to work, nor how it used to work before 24/7 connections, nor even how it should work assuming you’re ok with phone-home daemons.

Post reply on HN