Live data from Hacker News

Apple removes first-party firewall exemption in macOS 11.2 beta 2

twitter.com

231–240 of 354 posts

Re: Apple removes first-party firewall exemption in macOS 11.2 beta 2

#231
post #184

Earlier quoted context omitted.

OK, so some Taiwanese network device manufacturers have poor default account practices, news at 11:00. I'm not seeing the CIA connection. Devices like this are used by the government and military contractors as well, and as you can see such vulnerabilities are trivial to detect so you can't count on the opposition finding out about it and using it. This one was picked up days after the firmware release. The smoking g…

> poor default account practices Understatement of the year. Secret account is exactly what people call "a backdoor".

[deleted]

Re: Apple removes first-party firewall exemption in macOS 11.2 beta 2

#232

Earlier quoted context omitted.

Isn't "it's in our financial interests right now" about as much "love" as you'll get for anything by a corporation? Saying "Apple has no love for privacy, they're only doing it because it sells" sounds moot to me, every company only does things because they sell.

Companies are made up of and run by people and the decisions made by those people are not necessarily solely profit-driven. That doesn't mean that making money is not important to these people; of course it is. But it's not the only factor.

Corporations are owned by shareholders, aren't they the ones who ultimately make decisions?

Re: Apple removes first-party firewall exemption in macOS 11.2 beta 2

#233
post #145

I am glad that the public backlash forced them to fix a deliberate BACKDOOR that they had introduced (by design) in the Network Extension Framework that macOS Big Sur now forces all the firewalls to use. (At least, they claim to have removed it). But it is hard to trust them again, and I would prefer to use a firewall that uses its own kernel extension to manage the network than using Apple's API again. (Obviously th…

Apple has no love for privacy nor ever had. They are in a market position where their main competitors - Google primarily, Microsoft and Amazon - are highly dependent on revenue streams extracted by monetizing personal information. Apple is in a position to cut that stream without affecting its bottom line, so it does it and claims privacy as a core value. I won't look a gift horse in the mouth, but I have no doubt t…

> Apple is in a position to cut that stream without affecting its bottom line, so it does it and claims privacy as a core value.

Well, the GP has a quite damming list showing that it doesn't. It's only empty marketing.

Re: Apple removes first-party firewall exemption in macOS 11.2 beta 2

#234
post #226
post #187

Earlier quoted context omitted.

> ironically, most of these companies are out of China Of the three companies named: - Google's user-facing services (search, email, app store, docs, ...) are blocked, but Google Ads (which are censored) and Android (which comes without any content that would require censorship) are still sold. - Microsoft: I'm not aware of any of their products being unavailable. Windows is the dominant desktop operating system in C…

Google doesn't certify devices in the Chinese market which run Android. Android is open source. Devices made for the domestic Chinese market run versions of Android created by the manufacturers and lack Google apps and services.

The majority of Android phones manufactured in China are not intended for the domestic market but are exported, and do come with Google apps and services, which Google licenses to the manufacturers.

Re: Apple removes first-party firewall exemption in macOS 11.2 beta 2

#235

I am glad that the public backlash forced them to fix a deliberate BACKDOOR that they had introduced (by design) in the Network Extension Framework that macOS Big Sur now forces all the firewalls to use. (At least, they claim to have removed it). But it is hard to trust them again, and I would prefer to use a firewall that uses its own kernel extension to manage the network than using Apple's API again. (Obviously th…

Keep in mind, pf still worked as intended. With caveats that macOS doesn't work properly if all traffic is dropped, imposing 30 second timeouts before publishing a default route to the routing table, among other things throwing a hissy fit. But, at least on macOS, there has always been a way to block all traffic.

Re: Apple removes first-party firewall exemption in macOS 11.2 beta 2

#236
post #168

Earlier quoted context omitted.

> The ones they consider less important are put in a backlog. True, but this just proves my point. It still doesn't take 6 months to fix this issue... if they wanted to fix it. Deprioritizing it was a deliberate choice by Apple. The reason the exclusion list shipped to the public in Big Sur wasn't technical, the reason is that Apple's priorities are messed up. From my perspective, the explanation is simple: ContentFi…

> True, but this just proves my point. It still doesn't take 6 months to fix this issue... if they wanted to fix it. Just because it was reported as an issue doesn't mean it was thought as a bug (or an issue to fix) by Apple. That's what they wanted to do. People coded it explicitly. > Deprioritizing it was a deliberate choice by Apple. Of course. Why wouldn't it be? > From my perspective, the explanation is simple:…

> What I'm saying is "why this took 6 months" doesn't make much sense as a question. Why wouldn't it?

For the 2nd or 3rd time in this thread, I have to remind that I was replying to a comment saying this: "That's why Apple has the Developer and Public Beta releases for iOS/OSX so that external users can provide feedback. And on this occasion just like on many other they will take action if necessary." So, maybe you should argue with that comment instead of with me?

My point was that developers filed feedback about this issue during the betas, yet Apple did not address that feedback, and thus "That's why Apple has the Developer and Public Beta releases for iOS/OSX" is not a valid point in this context.

Re: Apple removes first-party firewall exemption in macOS 11.2 beta 2

#237
post #193
post #158

This firewall issue isn't the only privacy feature strip from Big Sur release. Unfortunately no big media care about other huge problem Apple introduced. My only hope they will also fix full disk encryption in this update. Since Big Sur broken installation of macOS on passphrase-encrypted disk partitions. I bought into M1 hype and now it's end up that you no longer able to have separate password for the disk encrypti…

On the M1, that's by design. If you install macOS on an external volume it doesn't have that behaviour. On the internal disk, it's there because they carried over the iOS infrastructure, where your login password is the FDE one. macOS also now boots before asking for your password, like iOS. (the OS volume itself isn't encrypted and is read-only, the data volume is encrypted with your password)

> (the OS volume itself isn't encrypted and is read-only, the data volume is encrypted with your password)

Wait, WHAT? Can someone with an M1 encrypted volume Mac check this directory and see if you see thumbnails?

> $TMPDIR/../C/com.apple.QuickLook.thumbnailcache/

A full writeup of this is at the link [1]. This has been a well-known thing in computer forensics for many years, which is why *full* disk encryption is so important.

[1]: https://objective-see.com/blog/blog_0x30.html

Re: Apple removes first-party firewall exemption in macOS 11.2 beta 2

#238

Earlier quoted context omitted.

By choosing which markets you operate in and which products you develop you have a fair bit of influence which things are in your "financial interest". E.g. creating a company with a business model which benefits from taxing CO2 emissions (Tesla) is morally great. Whereas having a business model which benefits from cheap oil (VW) is less so. Product decisions (electric vs. fuel engines) have a large effect on your lo…

If Apple knew it could make more money in say for example, arms dealing, wouldn't it be obliged to pivot to serve the shareholders? I guess it's somewhat democratic as shareholders could vote against it for moral reasons

No. Not all corporate actions have to be aligned to maximal profit extraction.

Re: Apple removes first-party firewall exemption in macOS 11.2 beta 2

#239
post #145

Earlier quoted context omitted.

Apple has no love for privacy nor ever had. They are in a market position where their main competitors - Google primarily, Microsoft and Amazon - are highly dependent on revenue streams extracted by monetizing personal information. Apple is in a position to cut that stream without affecting its bottom line, so it does it and claims privacy as a core value. I won't look a gift horse in the mouth, but I have no doubt t…

Having been a programmer through the 90's, and watched Microsoft (and Oracle, et. al.) through their most malfeasant years, I'm very cautious about giving companies the benefit of the doubt. However, the fact that Apple is leaving hundreds of billions of dollars on the table by NOT monetizing their aggregated user data does seem to indicate that their will is strong here, and that "they" mean what "they" say about pr…

Or it wouldn’t really be that much more. How do you come up with hundreds of billions of dollars? Who are the buyers?

Re: Apple removes first-party firewall exemption in macOS 11.2 beta 2

#240
post #171

Earlier quoted context omitted.

> Not to mention that "removing the ContentFilterExclusionList" is a hacky fix suggestion. You've got in backwards. The ContentFilterExclusionList was itself a hack. It never should have existed. Some people are handwaving about a mysterious vague problem that calls for a ContentFilterExclusionList, but Little Snitch has existed for many many years on the Mac and has been able to block everything , including Apple se…

> You've got in backwards. The ContentFilterExclusionList was itself a hack. It never should have existed. It might or might not be a hack, but that's orthogonal to the functionality or whether it uses a ContentFilterExclusionList. The fact that it wasn't there before, or that it is a misguided feature idea, doesn't mean it was done as a quick and dirty implementation or that it's hastily made feature done via cuttin…

> doesn't mean it was done as a quick and dirty implementation or that it's hastily made feature done via cutting corners.

I wasn't implying that. The ContentFilterExclusionList was already present in the first WWDC beta and could have been there internally for many months prior, who knows. I was using "hack" more in the sense of bypassing a security system. I said "It never should have existed", which is not a comment on the quality of the design of the thing that did exist.

> People forget this is not just a single feature, but part of a change to how network filtering is done (not through a third party kernel extension anymore), accompanied with new APIs.

I'm not "people". I'm well aware and haven't forgotten. I've been a professional Mac developer for 15 years. I've used the Network Extension API myself. You may remember me from such news stories as the Mac OCSP appocalypse. https://techcrunch.com/2020/11/15/apple-responds-to-gatekeep... It's incredibly tiresome when HN commenters try to "Macsplain" to me.

Post reply on HN