Live data from Hacker News

Apple removes first-party firewall exemption in macOS 11.2 beta 2

twitter.com

131–140 of 354 posts

Re: Apple removes first-party firewall exemption in macOS 11.2 beta 2

#131

Does anyone know how this impacts little snitch?

It impacts all application firewalls on macOS - Lulu, Little Snitch, HandsOff, TripMode, RadioSilence etc - equally. Meaning, they can all now block the apps that Apple had exempted, in future versions of macOS Big Sur.

Re: Apple removes first-party firewall exemption in macOS 11.2 beta 2

#132
post #18

Earlier quoted context omitted.

> That's why Apple has the Developer and Public Beta releases for iOS/OSX so that external users can provide feedback. And on this occasion just like on many other they will take action if necessary. Except that Apple did not take action. Firewall developers such as Little Snitch did become aware of the issue during the beta releases and gave feedback to Apple, which Apple ignored and shipped it anyway to the public.…

> Except that Apple did not take action. Look, I don't mean to criticise. But how do you know that Apple didn't start working on a fix when they were told about it? Apple doesn't exactly say when they start working on a fix for something, or else we would have known earlier.

It's not up to customers to assume the good intentions of a large organization. Apple has internal decisions and processes that result in them not communicating in a timely manner. Whatever fallout from that is on them.

Re: Apple removes first-party firewall exemption in macOS 11.2 beta 2

#133

I am glad that the public backlash forced them to fix a deliberate BACKDOOR that they had introduced (by design) in the Network Extension Framework that macOS Big Sur now forces all the firewalls to use. (At least, they claim to have removed it). But it is hard to trust them again, and I would prefer to use a firewall that uses its own kernel extension to manage the network than using Apple's API again. (Obviously th…

Why do you call it a deliberate backdoor when the Apple developers (see elsewhere in this thread) have said this was a bug?

"Hanlon's razor" is a gift to the malicious. I've stopped believing in it entirely.

Re: Apple removes first-party firewall exemption in macOS 11.2 beta 2

#134
post #84

Earlier quoted context omitted.

Tweet[1] by Apple developer Russ Bishop: "Some system processes bypassing NetworkExtensions in macOS is a bug, in case you were wondering." Reply[2] by David Dudok de Wit, developer of TripMode: "Glad to see it's being reconsidered as a bug, because Apple told us it 'behaves as designed' (FB7740671 + FB7665551). And why is there an exclusion list in the first place? I'd love to know more and see this documented." Rep…

The tweet by the Apple developer has been deleted - hope he didn't lose job, and at worst only earned a reprimand. (Nobody with experience would call it a bug, when it was clearly a deliberate design decision).

Twitter indicates that he is still employed.

Re: Apple removes first-party firewall exemption in macOS 11.2 beta 2

#135
post #107

Earlier quoted context omitted.

I find it amazing that recently on a presumably ‘hacker’ forum opinions showing a ‘freedom software’ perspective get a bully response in form of simply downvoting and shutting up the person. I urge the admins to stop this practice. I wish to hear such points of view and consider things from such perspective. It is very logical to assume that once you have no direct access to the sources of software, that software cou…

> On recent M1 you can’t even have own OS without Apple permission That's not true. https://asahilinux.org/about/ , "Does Apple allow this? Don’t you need a jailbreak?"

And Apple released a build today which provides the kmutil options for it, too :)

Re: Apple removes first-party firewall exemption in macOS 11.2 beta 2

#136
post #133

Earlier quoted context omitted.

Why do you call it a deliberate backdoor when the Apple developers (see elsewhere in this thread) have said this was a bug?

"Hanlon's razor" is a gift to the malicious. I've stopped believing in it entirely.

Agreed. Nearly every kid discovers the 'it was an accident' lie/excuse. And I don't think adults ever forget it.

Re: Apple removes first-party firewall exemption in macOS 11.2 beta 2

#137
post #3

Nice to see that Apple isn't so big that it doesn't think it has to listen to reasonable/rational public feedback that it is making poor decisions. Now, if they could empower lower levels to make these decisions before the issues blow up in the wider world context, all the better.

Curious why you phrased Apple listening to their customers in such a negative way. Maybe from pessimism bias? I observe a lot of HN commenters don't vibe with how Apple controls & develops their ecosystem. Yet, instead of go elsewhere, complaining and acting like being oh so very special enough to know how things should be done is preferred; while expecting a major company to just cater to their personal whims. I'm u…

>have no faith in Apple's competition at making anything better than Apple currently has.

110% this.

Other laptops are awful hardware. Including the Dell XPS line and the new thinkpads.

Re: Apple removes first-party firewall exemption in macOS 11.2 beta 2

#138

This is really responsible of them! Before, I was trying to figure out how mac's would ever be used anywhere near something classified or secret for a company.

> Before, I was trying to figure out how mac's would ever be used anywhere near something classified or secret for a company. Relying on a personal firewall on the device itself seems ill-fated. Maybe it could be considered an additional layer of security, but I've yet to work at a place where a personal firewall is part of the security concept, no matter which OS. It's either firewalls at the gateway, maybe addition…

An application firewall on the device serves a different purpose to that running off-device, namely the ability to filter traffic based on the origin (or destination) application.

Clearly if your kernel or userspace are compromised that's not much use, and that's where external controls kick in.

You can't determine (absent some custom network and protocols) which piece of software was responsible for a given packet once you leave the device though, so that's the (current) best place to do that - if you want to impose policies controlling the hosts and protocols an application can use, you will want to implement this on-device, then firewall for the superset of all of those at the network level.

In essence it's about raising the number of independent failures required to result in a compromise. If you imagine the application firewall on the device has its policies managed rather than selected by the user, it starts to make more sense.

Re: Apple removes first-party firewall exemption in macOS 11.2 beta 2

#139
post #90

Earlier quoted context omitted.

Just search for example "apple backpedals" and it's pretty clear that Apple is not immune to the effects of publicity (like all companies)

I cited a pretty huge example (bootcamp) where there was no media pressure at all. There was definitely tech pressure, but the media had no dog in the fight.

Finding an example of Apple changing something for a reason other than media coverage is hardly evidence of media coverage never swaying Apple.

Re: Apple removes first-party firewall exemption in macOS 11.2 beta 2

#140

An Apple employee tweeted after the news with 11.0 that this was a bug so I'm not surprised, but happy to see it fixed!

Adding entire feature without justification (ContentFilterExclusionList) is not a bug.

Calling it a bug is misleading.

Post reply on HN