Live data from Hacker News

Apple removes first-party firewall exemption in macOS 11.2 beta 2

twitter.com

181–190 of 354 posts

Re: Apple removes first-party firewall exemption in macOS 11.2 beta 2

#181
post #147

Earlier quoted context omitted.

A backdoor has some malicious connotations to me. Having security profiles controlled by a list seems a thing Without spending a lot of time sshd has allowLists (AllowGroups) and match directives Sudo also has per group config As a user on any operating system what you can and can’t do is controlled by a list Perhaps the issue is the list isn’t user controlled ? Perhaps the issue falls into the “I own and control my…

If they claim "here's the API you can use to control network access" but can then put arbitrary apps to work around that, that's the definition of backdoor access to the device.

I’m not supporting their approach. Why can’t this be thought of as a control API with a built in allow list ? Where the list is hidden by obscurity

Re: Apple removes first-party firewall exemption in macOS 11.2 beta 2

#182

Earlier quoted context omitted.

Why do you call it a deliberate backdoor when the Apple developers (see elsewhere in this thread) have said this was a bug?

> Why do you call it a deliberate backdoor when the Apple developers (see elsewhere in this thread) have said this was a bug? They're lying.

Every year the same actually.

Re: Apple removes first-party firewall exemption in macOS 11.2 beta 2

#183
post #162
post #158

This firewall issue isn't the only privacy feature strip from Big Sur release. Unfortunately no big media care about other huge problem Apple introduced. My only hope they will also fix full disk encryption in this update. Since Big Sur broken installation of macOS on passphrase-encrypted disk partitions. I bought into M1 hype and now it's end up that you no longer able to have separate password for the disk encrypti…

Most users don’t want a separate password for disk encryption though, so I’m not sure it’s a huge problem?

It's about choice and control over your data - an educated user knows that with hardware encryption, it is very difficult to retrieve data if the hardware fails. There's also the trust factor where you would prefer to have the keys, rather than trust some device.

(E.g. Some Western Digital drives have problems with their hardware encryption and made the data on it irretrievable for many - https://github.com/andlabs/reallymine/issues/53 . More here - https://carltonbale.com/western-digital-mybook-drive-lock-en...).

What is being questioned and criticized is the removal of this choice. Especially when a product claims a commitment to privacy.

Re: Apple removes first-party firewall exemption in macOS 11.2 beta 2

#184
post #167

Earlier quoted context omitted.

Factory installed CIA snoop software on Macs is news to me, especially bearing in mind most of the factories are in Taiwan. Where can I find out more? Also if the spyware is installed in firmware at the factory, how is Linux going to help you?

> especially bearing in mind most of the factories are in Taiwan Zyxel, Asus, and other manufacturers of networking devices (with backdoors of course) are also there. https://arstechnica.com/information-technology/2021/01/hacke...

OK, so some Taiwanese network device manufacturers have poor default account practices, news at 11:00. I'm not seeing the CIA connection.

Devices like this are used by the government and military contractors as well, and as you can see such vulnerabilities are trivial to detect so you can't count on the opposition finding out about it and using it. This one was picked up days after the firmware release. The smoking gun would be government and military admins secretly being advised by the CIA to close these security loopholes, so the government is protected but everyone else isn't. IMHO that would get Snowdened almost immediately. There's no way they'd keep a lid on that, there would just be too many people involved.

As with a lot of this conspiracy theory stuff, it only makes sense if you don't think about it too much. Once you actually start thinking through the consequences and practicalities, it doesn't hold together.

Re: Apple removes first-party firewall exemption in macOS 11.2 beta 2

#185

Earlier quoted context omitted.

As much as I'd like to believe it was just an oversight, how do you accidentally have your services bypass the firewall? That feels like it would have to be a deliberate choice under the assumption that "our apps are signed by us, and the OS verifies that, so all traffic through these apps should be OK, right?" I don't mean this snarkily; it's a genuine question. I don't know how OSes work.

Perhaps they wanted a bypass as system recovery option, or preference, not on by default.

They already have a "system recovery mode" where no such firewalls run, and only select system tools are available. There's also "safe mode".

Re: Apple removes first-party firewall exemption in macOS 11.2 beta 2

#186

I am glad that the public backlash forced them to fix a deliberate BACKDOOR that they had introduced (by design) in the Network Extension Framework that macOS Big Sur now forces all the firewalls to use. (At least, they claim to have removed it). But it is hard to trust them again, and I would prefer to use a firewall that uses its own kernel extension to manage the network than using Apple's API again. (Obviously th…

Why do you call it a deliberate backdoor when the Apple developers (see elsewhere in this thread) have said this was a bug?

> have said this was a bug

They can say whatever they like, it's another story they've got no credibility. It was quite obvious it was very much a deliberate action (just look at the naming, itself)

Re: Apple removes first-party firewall exemption in macOS 11.2 beta 2

#187
post #156
post #145

Earlier quoted context omitted.

Apple has no love for privacy nor ever had. They are in a market position where their main competitors - Google primarily, Microsoft and Amazon - are highly dependent on revenue streams extracted by monetizing personal information. Apple is in a position to cut that stream without affecting its bottom line, so it does it and claims privacy as a core value. I won't look a gift horse in the mouth, but I have no doubt t…

ironically, most of these companies are out of China because they don't want to comply with Chinese laws. Not apple https://applecensorship.com/

> ironically, most of these companies are out of China

Of the three companies named:

- Google's user-facing services (search, email, app store, docs, ...) are blocked, but Google Ads (which are censored) and Android (which comes without any content that would require censorship) are still sold.

- Microsoft: I'm not aware of any of their products being unavailable. Windows is the dominant desktop operating system in China, and I'd be surprised if the app store wasn't censored. Bing search results are definitely censored (they tell you so at the bottom of the page).

- Amazon isn't selling much that could run afoul of censorship, except possibly books (remember when Amazon used to be an online bookstore?) but in China their market is mostly targeted at the niche of high-end imported goods. (Note the country-of-origin indicators on https://www.amazon.cn/ )

Re: Apple removes first-party firewall exemption in macOS 11.2 beta 2

#188
post #145

I am glad that the public backlash forced them to fix a deliberate BACKDOOR that they had introduced (by design) in the Network Extension Framework that macOS Big Sur now forces all the firewalls to use. (At least, they claim to have removed it). But it is hard to trust them again, and I would prefer to use a firewall that uses its own kernel extension to manage the network than using Apple's API again. (Obviously th…

Apple has no love for privacy nor ever had. They are in a market position where their main competitors - Google primarily, Microsoft and Amazon - are highly dependent on revenue streams extracted by monetizing personal information. Apple is in a position to cut that stream without affecting its bottom line, so it does it and claims privacy as a core value. I won't look a gift horse in the mouth, but I have no doubt t…

Isn't "it's in our financial interests right now" about as much "love" as you'll get for anything by a corporation? Saying "Apple has no love for privacy, they're only doing it because it sells" sounds moot to me, every company only does things because they sell.

Re: Apple removes first-party firewall exemption in macOS 11.2 beta 2

#189
post #145

Earlier quoted context omitted.

Apple has no love for privacy nor ever had. They are in a market position where their main competitors - Google primarily, Microsoft and Amazon - are highly dependent on revenue streams extracted by monetizing personal information. Apple is in a position to cut that stream without affecting its bottom line, so it does it and claims privacy as a core value. I won't look a gift horse in the mouth, but I have no doubt t…

Isn't "it's in our financial interests right now" about as much "love" as you'll get for anything by a corporation? Saying "Apple has no love for privacy, they're only doing it because it sells" sounds moot to me, every company only does things because they sell.

By choosing which markets you operate in and which products you develop you have a fair bit of influence which things are in your "financial interest".

E.g. creating a company with a business model which benefits from taxing CO2 emissions (Tesla) is morally great. Whereas having a business model which benefits from cheap oil (VW) is less so. Product decisions (electric vs. fuel engines) have a large effect on your long-term financial interests.

Re: Apple removes first-party firewall exemption in macOS 11.2 beta 2

#190

Earlier quoted context omitted.

For my 32 bit binaries, the easiest way to use them is to run the Windows version, because that OS has better backwards compatability. It's possible to get a Mojave VM up and running but it was nontrivial when I gave it a shot

If I'm not mistaken, WINE is now capable of running 32-bit Windows binaries on 64-bit-only macOS as well, so that may also be an option particularly for more simple apps.

I don't think Wine can, but Crossover definitely can.
Post reply on HN