Live data from Hacker News

Apple removes first-party firewall exemption in macOS 11.2 beta 2

twitter.com

241–250 of 354 posts

Re: Apple removes first-party firewall exemption in macOS 11.2 beta 2

#241
post #215
post #164

Earlier quoted context omitted.

While I agree that one should remain suspicious and be vocal about privacy violations and security issues, I find your attitude of continuing to attack Apple inappropriate. Apple competitors Google and Microsoft which control the great majority of OS installs both for mobile and desktop don't even pretend to care about privacy. I have collected over the years reports about dozens of underhanded tactics they use to ma…

The fact that their competitors are as bad or worse in this regard does not make Apple saints - and this has all the hallmarks of an intentional addition to position Apple apps differently from the others, which is a classic Apple move. Compromise in security and prviacy clearly has been deemed worth by someone at Apple before the stink was raised.

This kind of black and white thinking is very impractical and self-defeating, except maybe for RMS, to remind us what we should strive for.

For most of us, the real world decision is to either work with a company which is actively working on undermining privacy or with one which is trying to improve things.

Re: Apple removes first-party firewall exemption in macOS 11.2 beta 2

#242
post #211
post #26

Earlier quoted context omitted.

There was a ContentFilterExclusionList key in the /System/Library/Frameworks/NetworkExtension.framework/Versions/Current/Resources/Info.plist file. macOS 11.2 beta 2 removed the ContentFilterExclusionList. Does that take 6 months?

> Does that take 6 months? You're assuming that changing that list is the only thing they needed to do. Have you thought about why they felt they needed that list to begin with? Maybe because they wanted to quality control that all their core services could graceful handle being blocked by a firewall first? That is, the job wasn't changing the list. The job was probably quality control of everything potentially block…

> You're assuming that changing that list is the only thing they needed to do.

No, you're assuming that I'm making that assumption. Why would you assume that?

> Most MacOS users by far probably don't care.

It's frustrating that people keep ignoring the fact that I was directly replying to this comment: "That's why Apple has the Developer and Public Beta releases for iOS/OSX so that external users can provide feedback."

If feedback during the betas does not make Apple take action, then the comment I was replying to was wrong.

Your response seems a bit ironic, though, because public backlash is exactly what caused Apple to backtrack.

Re: Apple removes first-party firewall exemption in macOS 11.2 beta 2

#243
post #107

Earlier quoted context omitted.

> On recent M1 you can’t even have own OS without Apple permission That's not true. https://asahilinux.org/about/ , "Does Apple allow this? Don’t you need a jailbreak?"

It would be good news when it’s finished ( If it will be finished at all) but it is not the case so far. Also, from the same source: “ Will this make Apple Silicon Macs a fully open platform? No, Apple still controls the boot process ...” Without open firmware and bootloader ... well, is it really Own OS?

There are very few if not zero modern computers with completely open source firmware and boot loader. Including computers with open source as their primary selling point.

Re: Apple removes first-party firewall exemption in macOS 11.2 beta 2

#244
post #167

Earlier quoted context omitted.

The PRISM revelations in particular made me realise that we can really only rely on Linux for security, since Apple, MS, Amazon and all the big tech companies are onboard with cooperating with the NSA. If you've read the way eg the CIA installs snooping software on Macs and PC's, they hide the Mac version in your hidden EFI boot volume, even from the factory. It's enough to make you never trust them again.

Factory installed CIA snoop software on Macs is news to me, especially bearing in mind most of the factories are in Taiwan. Where can I find out more? Also if the spyware is installed in firmware at the factory, how is Linux going to help you?

Well I think it's mac specific software.

I learned about it from wikileaks. Eg https://wikileaks.org/ciav7p1/cms/space_2359301.html

Re: Apple removes first-party firewall exemption in macOS 11.2 beta 2

#245
post #69

Earlier quoted context omitted.

As much the community wants to think they are evil and want to purposefully violate trust, most often the easier explanation works very well. Its an oversight or a resourcing issue.

As much as I'd like to believe it was just an oversight, how do you accidentally have your services bypass the firewall? That feels like it would have to be a deliberate choice under the assumption that "our apps are signed by us, and the OS verifies that, so all traffic through these apps should be OK, right?" I don't mean this snarkily; it's a genuine question. I don't know how OSes work.

My guess is that this started small (“we shouldn’t let firewalls block security updates or Find My Mac”) and once that mechanism was there people kept adding other things to it thinking about support (security filters are notorious for people blocking things without understanding the implications and then file big reports) but not the users who would be upset about not being able to block those services.

Re: Apple removes first-party firewall exemption in macOS 11.2 beta 2

#246
post #145

I am glad that the public backlash forced them to fix a deliberate BACKDOOR that they had introduced (by design) in the Network Extension Framework that macOS Big Sur now forces all the firewalls to use. (At least, they claim to have removed it). But it is hard to trust them again, and I would prefer to use a firewall that uses its own kernel extension to manage the network than using Apple's API again. (Obviously th…

Apple has no love for privacy nor ever had. They are in a market position where their main competitors - Google primarily, Microsoft and Amazon - are highly dependent on revenue streams extracted by monetizing personal information. Apple is in a position to cut that stream without affecting its bottom line, so it does it and claims privacy as a core value. I won't look a gift horse in the mouth, but I have no doubt t…

When Apple launched iOS 6, it was the first operating system to include per-app privacy controls around access to things like microphone, camera, photos, etc. Controls we consider fundamental today. It did not mention it a single time in any of its PR or marketing at all. The first reference you find to it will be from Apple blogs who were surprised to stumble upon it in the iOS 6 beta. It took Android two more years to launch a similar feature.

Yes, Apple is doubling down on its competitive advantage here. But to claim it does not and never cared for privacy is just ignoring the facts and the history. It moved the industry forward.

Re: Apple removes first-party firewall exemption in macOS 11.2 beta 2

#247
post #207
post #193

Earlier quoted context omitted.

On the M1, that's by design. If you install macOS on an external volume it doesn't have that behaviour. On the internal disk, it's there because they carried over the iOS infrastructure, where your login password is the FDE one. macOS also now boots before asking for your password, like iOS. (the OS volume itself isn't encrypted and is read-only, the data volume is encrypted with your password)

How do you know it's "by design"? By default macOS was always using this encryption scheme, but there was always possibility to have an optional FDE. Now this is broken and I can't even manage to get macOS installed when any encrypted partition is present since it's also cause installer to fail. I obviously find it being absolutely terrible "design" decision since there no way on earth anyone can count disk encryptio…

Why is that so important? Your disk encryption key is certainly stored in memory for the duration of your session (which on Macs might as well be forever since they don’t need to shutdown), so anyone with your user password can gain access either way.

Re: Apple removes first-party firewall exemption in macOS 11.2 beta 2

#248

This is really responsible of them! Before, I was trying to figure out how mac's would ever be used anywhere near something classified or secret for a company.

It would be responsible of them if they had done it in a situation where they weren't pressured into the decision by media outlets.

The amount of people reading about firewalls in the latest OS release surely does not qualify as “media pressure” on any kind of scale.

Re: Apple removes first-party firewall exemption in macOS 11.2 beta 2

#249

I am glad that the public backlash forced them to fix a deliberate BACKDOOR that they had introduced (by design) in the Network Extension Framework that macOS Big Sur now forces all the firewalls to use. (At least, they claim to have removed it). But it is hard to trust them again, and I would prefer to use a firewall that uses its own kernel extension to manage the network than using Apple's API again. (Obviously th…

It’s inaccurate to say “Apple selling user data to US government”. That’s not what the article claims (the word “sell” doesn’t even appear in the text), and there are in fact many consumer data brokers who really do sell data to law enforcement.

Re: Apple removes first-party firewall exemption in macOS 11.2 beta 2

#250

Earlier quoted context omitted.

Both are 'physical access'. If one does not power down your system, your FDE is unlocked. So they only need your Linux user account password to get access to the data on your disk. FDE only protects your data when it's locked. Normally this is when your system is shut down.

True but it's a slightly different category as he wouldn't leave his system on but locked in a potential high risk scenario.

You mean he would shut down a MacBook every day after us? That’s blasphemy.
Post reply on HN