Live data from Hacker News

Apple removes first-party firewall exemption in macOS 11.2 beta 2

twitter.com

91–100 of 354 posts

Re: Apple removes first-party firewall exemption in macOS 11.2 beta 2

#91
post #63
post #42

Earlier quoted context omitted.

> Does that take 6 months? If this one change is in a pool with tens of thousands of other possible changes, and it also has to go through one or more QA cycles? Sure, why not 6 months?

> Sure, why not 6 months? Because the first WWDC preview version of Big Sur was released to developers on June 22, 2020, and Big Sur was released to the public on November 12, 2020, so Apple needs to be able to fix issues identified during the beta period much quicker than in 6 months.

Apple doesn't have to "fix issues identified during the beta period" much quicker than the release date.

No OS does, including FOSS distros / OSes.

Apple just has to fix "the most important issues" with the most bang for the buck identified during the beta period before release.

Which they do.

The ones they consider less important are put in a backlog.

You can find "issues identified during beta releases" still open and unfixed for all OSes, some even going 10 years back, long after the release was out...

Re: Apple removes first-party firewall exemption in macOS 11.2 beta 2

#93
post #26

Earlier quoted context omitted.

> Except that Apple did not take action. Look, I don't mean to criticise. But how do you know that Apple didn't start working on a fix when they were told about it? Apple doesn't exactly say when they start working on a fix for something, or else we would have known earlier.

There was a ContentFilterExclusionList key in the /System/Library/Frameworks/NetworkExtension.framework/Versions/Current/Resources/Info.plist file. macOS 11.2 beta 2 removed the ContentFilterExclusionList. Does that take 6 months?

Noticing the issue, discussing it, setting meetings to agree to revert, and handling all other higher priority stuff before an eminent GM release and the most pressing x.1 update release, can take more than 6 months.

Not to mention that "removing the ContentFilterExclusionList" is a hacky fix suggestion. Doesn't mean it's the actual hollistic fix, and there weren't other under the hood changes for this issue.

Re: Apple removes first-party firewall exemption in macOS 11.2 beta 2

#94

This is really responsible of them! Before, I was trying to figure out how mac's would ever be used anywhere near something classified or secret for a company.

It would be responsible of them if they had done it in a situation where they weren't pressured into the decision by media outlets.

Nah, it's not media outlets Apple is scared of, it's the front page of Hacker News...

Re: Apple removes first-party firewall exemption in macOS 11.2 beta 2

#95
post #18

Earlier quoted context omitted.

Having worked at Apple and other big companies it's almost always Engineers and PMs making these decisions. It's not like Tim Cook or Craig Federighi is running around demanding people add Apple apps to a firewall exclusion list. They have much bigger things to worry about. It's just that as an engineer you are often in a bubble and can't foresee every implication of your decision. That's why Apple has the Developer…

> That's why Apple has the Developer and Public Beta releases for iOS/OSX so that external users can provide feedback. And on this occasion just like on many other they will take action if necessary. Except that Apple did not take action. Firewall developers such as Little Snitch did become aware of the issue during the beta releases and gave feedback to Apple, which Apple ignored and shipped it anyway to the public.…

Why do you think Apple should've solved this issue immediately? I'm sure you (and the other people in this thread) care a lot about the firewall exception, but from the perspective of Apple this must've been a non-critical issue at best. I don't understand why you assume Apple should've dropped everything and fixed this as soon as it was reported. And clearly, as opposed to what you say, they did take action - otherwise they'd never have removed it.

Re: Apple removes first-party firewall exemption in macOS 11.2 beta 2

#96
post #75

Earlier quoted context omitted.

There's no link because the tweet was deleted soon afterward. The tweet seems to have been very ill-advised. I don't know how anyone can describe this as a "bug", because as the linked article describes, there's an explicit "ContentFilterExclusionList" in the Info.plist file with a list of the specific Apple services excluded. That's not by accident, it's by design.

bug was in the design. (or in decision leading to design)

I don't think I'd call it a bug. It's a poor decision. I can easily believe that it wasn't a decision made with malicious intent; the culture at Apple seems (at least from the outside, judging by results) to encourage an "it's okay to give our own software special exceptions" mentality.

Re: Apple removes first-party firewall exemption in macOS 11.2 beta 2

#97
post #65
post #60

Earlier quoted context omitted.

The firewall is just the tip of the iceberg. Microsoft provides the sources and special builds for sensitive environments. They work with governments worldwide and open their source code to get certified. As far as I understand it never was Apple's priority.

You're commending Micro$oft for sharing source code? Please! They both are completely irresponsible and push proprietary malware. Anything less than freely usable/sharable software is inadequate.

I find it amazing that recently on a presumably ‘hacker’ forum opinions showing a ‘freedom software’ perspective get a bully response in form of simply downvoting and shutting up the person. I urge the admins to stop this practice. I wish to hear such points of view and consider things from such perspective.

It is very logical to assume that once you have no direct access to the sources of software, that software could do things that malware does. Yet this obviously logical reminder get downvoted like it is irrational or off topic.

It is on topic, it is rational, it is a good reminder and we see Microsoft and Apple consistently disrespect a right of a person to control own _Personal_ computer(PC). On recent M1 you can’t even have own OS without Apple permission, which makes it useless brick for me. Do some people still understand what ‘personal’ means ?

Re: Apple removes first-party firewall exemption in macOS 11.2 beta 2

#99
post #75

Earlier quoted context omitted.

There's no link because the tweet was deleted soon afterward. The tweet seems to have been very ill-advised. I don't know how anyone can describe this as a "bug", because as the linked article describes, there's an explicit "ContentFilterExclusionList" in the Info.plist file with a list of the specific Apple services excluded. That's not by accident, it's by design.

bug was in the design. (or in decision leading to design)

A bug is unintentional, through error or coincidence of unforeseen circumstances.

Coding a feature and providing a configuration file thereto is not a bug.

Re: Apple removes first-party firewall exemption in macOS 11.2 beta 2

#100
post #69

Earlier quoted context omitted.

As much the community wants to think they are evil and want to purposefully violate trust, most often the easier explanation works very well. Its an oversight or a resourcing issue.

As much as I'd like to believe it was just an oversight, how do you accidentally have your services bypass the firewall? That feels like it would have to be a deliberate choice under the assumption that "our apps are signed by us, and the OS verifies that, so all traffic through these apps should be OK, right?" I don't mean this snarkily; it's a genuine question. I don't know how OSes work.

Perhaps they wanted a bypass as system recovery option, or preference, not on by default.
Post reply on HN