Live data from Hacker News

Apple removes first-party firewall exemption in macOS 11.2 beta 2

twitter.com

171–180 of 354 posts

Re: Apple removes first-party firewall exemption in macOS 11.2 beta 2

#171
post #93
post #26

Earlier quoted context omitted.

There was a ContentFilterExclusionList key in the /System/Library/Frameworks/NetworkExtension.framework/Versions/Current/Resources/Info.plist file. macOS 11.2 beta 2 removed the ContentFilterExclusionList. Does that take 6 months?

Noticing the issue, discussing it, setting meetings to agree to revert, and handling all other higher priority stuff before an eminent GM release and the most pressing x.1 update release, can take more than 6 months. Not to mention that "removing the ContentFilterExclusionList" is a hacky fix suggestion. Doesn't mean it's the actual hollistic fix, and there weren't other under the hood changes for this issue.

> Not to mention that "removing the ContentFilterExclusionList" is a hacky fix suggestion.

You've got in backwards. The ContentFilterExclusionList was itself a hack. It never should have existed.

Some people are handwaving about a mysterious vague problem that calls for a ContentFilterExclusionList, but Little Snitch has existed for many many years on the Mac and has been able to block everything, including Apple services. There was no problem with that until Apple decided to exempt itself from getting blocked.

Re: Apple removes first-party firewall exemption in macOS 11.2 beta 2

#173
post #167

Earlier quoted context omitted.

The PRISM revelations in particular made me realise that we can really only rely on Linux for security, since Apple, MS, Amazon and all the big tech companies are onboard with cooperating with the NSA. If you've read the way eg the CIA installs snooping software on Macs and PC's, they hide the Mac version in your hidden EFI boot volume, even from the factory. It's enough to make you never trust them again.

Factory installed CIA snoop software on Macs is news to me, especially bearing in mind most of the factories are in Taiwan. Where can I find out more? Also if the spyware is installed in firmware at the factory, how is Linux going to help you?

> especially bearing in mind most of the factories are in Taiwan

Zyxel, Asus, and other manufacturers of networking devices (with backdoors of course) are also there.

https://arstechnica.com/information-technology/2021/01/hacke...

Re: Apple removes first-party firewall exemption in macOS 11.2 beta 2

#174
post #162
post #158

This firewall issue isn't the only privacy feature strip from Big Sur release. Unfortunately no big media care about other huge problem Apple introduced. My only hope they will also fix full disk encryption in this update. Since Big Sur broken installation of macOS on passphrase-encrypted disk partitions. I bought into M1 hype and now it's end up that you no longer able to have separate password for the disk encrypti…

Most users don’t want a separate password for disk encryption though, so I’m not sure it’s a huge problem?

Most users probably also didn't care about the first-party firewall exemptions. They could have asked people if they wanted a separate password for disk encryption (e.g. a small checkbox).

Re: Apple removes first-party firewall exemption in macOS 11.2 beta 2

#175
post #95
post #18

Earlier quoted context omitted.

> That's why Apple has the Developer and Public Beta releases for iOS/OSX so that external users can provide feedback. And on this occasion just like on many other they will take action if necessary. Except that Apple did not take action. Firewall developers such as Little Snitch did become aware of the issue during the beta releases and gave feedback to Apple, which Apple ignored and shipped it anyway to the public.…

Why do you think Apple should've solved this issue immediately? I'm sure you (and the other people in this thread) care a lot about the firewall exception, but from the perspective of Apple this must've been a non-critical issue at best. I don't understand why you assume Apple should've dropped everything and fixed this as soon as it was reported. And clearly, as opposed to what you say, they did take action - otherw…

> from the perspective of Apple this must've been a non-critical issue at best.

From the perspective of Apple, this wasn't even an issue at all. It "behaves as intended". https://twitter.com/david_ddw/status/1329017113709842437 So that's why Apple didn't fix it. You don't fix something that you don't think is broken.

Re: Apple removes first-party firewall exemption in macOS 11.2 beta 2

#176

Earlier quoted context omitted.

Why are they ignoring /etc/hosts if this is good behavior?

Why are you using /etc/hosts to modify the behavior of the Apple resolver system? That’s not how macOS directory services work, and Apple only appears to offers it as a legacy backwards-compat stub with no guarantee of support or effectiveness for modern anything. It’s no surprise that it’s not an effective solution for you.

[deleted]

Re: Apple removes first-party firewall exemption in macOS 11.2 beta 2

#177
post #161

Earlier quoted context omitted.

The PRISM revelations in particular made me realise that we can really only rely on Linux for security, since Apple, MS, Amazon and all the big tech companies are onboard with cooperating with the NSA. If you've read the way eg the CIA installs snooping software on Macs and PC's, they hide the Mac version in your hidden EFI boot volume, even from the factory. It's enough to make you never trust them again.

Security isn't the same as privacy. Linux desktop security is poor but its privacy can be okay.

If it's important for you and Linux security is not enough for you, consider using Qubes OS.

Re: Apple removes first-party firewall exemption in macOS 11.2 beta 2

#178
post #164

I am glad that the public backlash forced them to fix a deliberate BACKDOOR that they had introduced (by design) in the Network Extension Framework that macOS Big Sur now forces all the firewalls to use. (At least, they claim to have removed it). But it is hard to trust them again, and I would prefer to use a firewall that uses its own kernel extension to manage the network than using Apple's API again. (Obviously th…

While I agree that one should remain suspicious and be vocal about privacy violations and security issues, I find your attitude of continuing to attack Apple inappropriate. Apple competitors Google and Microsoft which control the great majority of OS installs both for mobile and desktop don't even pretend to care about privacy. I have collected over the years reports about dozens of underhanded tactics they use to ma…

> I find your attitude of continuing to attack Apple inappropriate.

I do so because I am an Apple user - this is being typed on a mac mini. I also own other Apple hardwares.

I also advocated for Apple hardware within my family & friends to switch from Android to Apple quite successfully (I am the IT guy in my circle). I did so because I would like to believe their commitment to privacy they have publicly stated. (Tim Cook being Gay adds to that trust because he understands that privacy is not just about hiding secrets but protecting ourselves from political persecutions by those who do not like some part of our identity - whether it be regional, gender, political, cultural, religious, sexual etc.).

It doesn't mean I trust them blindly or completely or will allow them to screw my customer rights (like right to repair, and OWN my device). Would you?

Re: Apple removes first-party firewall exemption in macOS 11.2 beta 2

#179
post #161

Earlier quoted context omitted.

Security isn't the same as privacy. Linux desktop security is poor but its privacy can be okay.

Why us it poor? (Genuinely asking).

No real push to use sandboxing or to limit access to personal information. Any app you install can do anything it wants with all of your data.

Re: Apple removes first-party firewall exemption in macOS 11.2 beta 2

#180

Earlier quoted context omitted.

Why are they ignoring /etc/hosts if this is good behavior?

Are you also writing :: domain.example Because the difference is gethostbynamev2 (the most likely function being used, or I suppose the Apple equivalent) looks up a ipv6 hostname before it looks up a ipv4 hostname, which means a "0.0.0.0 domain.example" entry won't override the result of ipv6 lookups. $ echo "0.0.0.0 cloudflare.com" | sudo tee -a /etc/hosts $ getent hosts cloudflare.com && getent ahosts cloudflare.co…

I disabled IPv6 altogether, and Apple’s processes are still finding a way to resolve their real IPs after my DNS and /etc/hosts resolved their domains to 0.0.0.0.

DNS should be enough, I shouldn’t have to black hole Apple’s entire /8 to stop macOS from phoning home when I’m not using the computer and no apps are running.

Post reply on HN