Live data from Hacker News

Apple removes first-party firewall exemption in macOS 11.2 beta 2

twitter.com

201–210 of 354 posts

Re: Apple removes first-party firewall exemption in macOS 11.2 beta 2

#201
post #162
post #158

This firewall issue isn't the only privacy feature strip from Big Sur release. Unfortunately no big media care about other huge problem Apple introduced. My only hope they will also fix full disk encryption in this update. Since Big Sur broken installation of macOS on passphrase-encrypted disk partitions. I bought into M1 hype and now it's end up that you no longer able to have separate password for the disk encrypti…

Most users don’t want a separate password for disk encryption though, so I’m not sure it’s a huge problem?

IMO that's a big problem. They are completely different risk categories. My FDE password is absurdly long and complicated, since I never want someone who gains physical access to get all my data, but my Linux user account password isn't as long since it's main purpose is to stop someone from getting passed my lock screen if I was to leave my system unattended.

Re: Apple removes first-party firewall exemption in macOS 11.2 beta 2

#202

Earlier quoted context omitted.

Why do you want to upgrade though? What's Mojave lacking that Catalina has?

The latest XCode that supports deploying to iOS 14 devices, unfortunately.

Ah ok. Yeah, that makes sense.

Re: Apple removes first-party firewall exemption in macOS 11.2 beta 2

#203

Earlier quoted context omitted.

> Why do you call it a deliberate backdoor when the Apple developers (see elsewhere in this thread) have said this was a bug? They're lying.

Why would they lie and not just shut the hell up? It makes no sense.

Sometimes people talk, even when they should shut the hell up. (The Apple developer has since deleted his tweet).

Re: Apple removes first-party firewall exemption in macOS 11.2 beta 2

#204

Earlier quoted context omitted.

Why do you call it a deliberate backdoor when the Apple developers (see elsewhere in this thread) have said this was a bug?

How a 'ContentFilterExclusionList' creation can be a bug? Somebody hit the wrong keys by mistake and nobody noticed during the pull request review?

Entirely possible if an infinite number of monkeys type along on an infinite number of keyboards.

https://en.wikipedia.org/wiki/Infinite_monkey_theorem

Re: Apple removes first-party firewall exemption in macOS 11.2 beta 2

#205

Earlier quoted context omitted.

Why us it poor? (Genuinely asking).

No real push to use sandboxing or to limit access to personal information. Any app you install can do anything it wants with all of your data.

I know, it's amazing, isn't it? Just think of the amazing possibilities this new "general-purpose computing" could unlock!

Re: Apple removes first-party firewall exemption in macOS 11.2 beta 2

#206
post #145

Earlier quoted context omitted.

Apple has no love for privacy nor ever had. They are in a market position where their main competitors - Google primarily, Microsoft and Amazon - are highly dependent on revenue streams extracted by monetizing personal information. Apple is in a position to cut that stream without affecting its bottom line, so it does it and claims privacy as a core value. I won't look a gift horse in the mouth, but I have no doubt t…

Isn't "it's in our financial interests right now" about as much "love" as you'll get for anything by a corporation? Saying "Apple has no love for privacy, they're only doing it because it sells" sounds moot to me, every company only does things because they sell.

In common speech, "love" is expected to last eternal, not just to the end of the quarter. I'm not really a romantic, but using the word "love" in a corporate context defiles it.

Re: Apple removes first-party firewall exemption in macOS 11.2 beta 2

#207
post #193
post #158

This firewall issue isn't the only privacy feature strip from Big Sur release. Unfortunately no big media care about other huge problem Apple introduced. My only hope they will also fix full disk encryption in this update. Since Big Sur broken installation of macOS on passphrase-encrypted disk partitions. I bought into M1 hype and now it's end up that you no longer able to have separate password for the disk encrypti…

On the M1, that's by design. If you install macOS on an external volume it doesn't have that behaviour. On the internal disk, it's there because they carried over the iOS infrastructure, where your login password is the FDE one. macOS also now boots before asking for your password, like iOS. (the OS volume itself isn't encrypted and is read-only, the data volume is encrypted with your password)

How do you know it's "by design"? By default macOS was always using this encryption scheme, but there was always possibility to have an optional FDE. Now this is broken and I can't even manage to get macOS installed when any encrypted partition is present since it's also cause installer to fail.

I obviously find it being absolutely terrible "design" decision since there no way on earth anyone can count disk encryption key that is unlockable by user password or faceid secure.

PS: If someone have any idea how having separate boot password can be hacked aroud I'll really appreciate the advice.

Re: Apple removes first-party firewall exemption in macOS 11.2 beta 2

#208

An Apple employee tweeted after the news with 11.0 that this was a bug so I'm not surprised, but happy to see it fixed!

Adding entire feature without justification (ContentFilterExclusionList) is not a bug. Calling it a bug is misleading.

The feature could be a workaround for a bug. That is, one of their internal services didn't handle being blocked well, and instead of fixing that service they just added that feature as a temporary workaround to make sure the new firewall functionality didn't break any important/core features of MacOS

I'm not saying this is what happened, but without actually knowing what happened we can't assume the intention was to exclude everything in this list forever either.

Re: Apple removes first-party firewall exemption in macOS 11.2 beta 2

#209
post #162

Earlier quoted context omitted.

Most users don’t want a separate password for disk encryption though, so I’m not sure it’s a huge problem?

IMO that's a big problem. They are completely different risk categories. My FDE password is absurdly long and complicated, since I never want someone who gains physical access to get all my data, but my Linux user account password isn't as long since it's main purpose is to stop someone from getting passed my lock screen if I was to leave my system unattended.

Both are 'physical access'.

If one does not power down your system, your FDE is unlocked. So they only need your Linux user account password to get access to the data on your disk.

FDE only protects your data when it's locked. Normally this is when your system is shut down.

Re: Apple removes first-party firewall exemption in macOS 11.2 beta 2

#210
post #187
post #156

Earlier quoted context omitted.

ironically, most of these companies are out of China because they don't want to comply with Chinese laws. Not apple https://applecensorship.com/

> ironically, most of these companies are out of China Of the three companies named: - Google's user-facing services (search, email, app store, docs, ...) are blocked, but Google Ads (which are censored) and Android (which comes without any content that would require censorship) are still sold. - Microsoft: I'm not aware of any of their products being unavailable. Windows is the dominant desktop operating system in C…

Worse than this, and to the point of this post - you can’t offer comms service in China unless it has a way to be snooped by government. So some comm services like Skype have to offer a separate app, just for China, which affects all messages sent and received by users of this version of the app, even if it comes from a regular app.

I was telling my friends who moved from China and kept their iPhones, to just buy a new one... just in case...

Post reply on HN