Live data from Hacker News

Apple removes first-party firewall exemption in macOS 11.2 beta 2

twitter.com

301–310 of 354 posts

Re: Apple removes first-party firewall exemption in macOS 11.2 beta 2

#301
post #250

Earlier quoted context omitted.

True but it's a slightly different category as he wouldn't leave his system on but locked in a potential high risk scenario.

You mean he would shut down a MacBook every day after us? That’s blasphemy.

At least with 10.15 and earlier you can configure MacOS to hybernate after certain amount of time when it will ask for FDE password on wake up and load everything from the disk.

Re: Apple removes first-party firewall exemption in macOS 11.2 beta 2

#302
post #174
post #162

Earlier quoted context omitted.

Most users don’t want a separate password for disk encryption though, so I’m not sure it’s a huge problem?

Most users probably also didn't care about the first-party firewall exemptions. They could have asked people if they wanted a separate password for disk encryption (e.g. a small checkbox).

It is highly non-trivial to extract private key from Apple encryption chips, last time I heared the price is at least 100K USD, and probably much higher now. So unless one values own secrets that high, a short password could be OK.

Re: Apple removes first-party firewall exemption in macOS 11.2 beta 2

#303
post #225
post #207

Earlier quoted context omitted.

How do you know it's "by design"? By default macOS was always using this encryption scheme, but there was always possibility to have an optional FDE. Now this is broken and I can't even manage to get macOS installed when any encrypted partition is present since it's also cause installer to fail. I obviously find it being absolutely terrible "design" decision since there no way on earth anyone can count disk encryptio…

Apple Silicon Macs use per-file encryption tied to the credentials: https://support.apple.com/en-gb/guide/security/secf6276da8a/... Was carried over from iOS. A way to bypass it _should_ be possible, but will entail having the System volume of the volume group to have different properties than the Data part. Otherwise the OS will fail to load. (on Apple Silicon Macs, macOS is fully booted already when you input the p…

Does this mean that every user account has their own data volume or that every user account has their home folder encrypted on a per-file basis? Or neither?

What is the privacy implications of two users (both with administrator accounts) sharing an Apple Silicon Mac?

Re: Apple removes first-party firewall exemption in macOS 11.2 beta 2

#304
post #240

Earlier quoted context omitted.

> You've got in backwards. The ContentFilterExclusionList was itself a hack. It never should have existed. It might or might not be a hack, but that's orthogonal to the functionality or whether it uses a ContentFilterExclusionList. The fact that it wasn't there before, or that it is a misguided feature idea, doesn't mean it was done as a quick and dirty implementation or that it's hastily made feature done via cuttin…

> doesn't mean it was done as a quick and dirty implementation or that it's hastily made feature done via cutting corners. I wasn't implying that. The ContentFilterExclusionList was already present in the first WWDC beta and could have been there internally for many months prior, who knows. I was using "hack" more in the sense of bypassing a security system. I said "It never should have existed", which is not a comme…

>It's incredibly tiresome when HN commenters try to "Macsplain" to me.

Isn't it also tiresome when people on HN assume we know who they are from their handle, or that we are somehow obliged to have followed them outside HN, and remember/know who they are?

I might recognize pg, or patio11, or tptacek, and a few more, but not everybody. And most handles, I just glaze over, they are not the important part in the discussion. I'm pretty sure most of us on HN have dozens of HN handles that we don't otherwise know who they are, or even keep tabs on from one HN thread to another.

I wouldn't try to "Macpslain" if your comment didn't seem to me to imply that this is just some an isolated thing with ContentFilterExclusionList, that can just be reversed like that, or if it mentioned that this is part of an extensive change to how network filters / kernel extensions work (or rather, don't work anymore) in Big Sur.

Re: Apple removes first-party firewall exemption in macOS 11.2 beta 2

#305
post #236

Earlier quoted context omitted.

> True, but this just proves my point. It still doesn't take 6 months to fix this issue... if they wanted to fix it. Just because it was reported as an issue doesn't mean it was thought as a bug (or an issue to fix) by Apple. That's what they wanted to do. People coded it explicitly. > Deprioritizing it was a deliberate choice by Apple. Of course. Why wouldn't it be? > From my perspective, the explanation is simple:…

> What I'm saying is "why this took 6 months" doesn't make much sense as a question. Why wouldn't it? For the 2nd or 3rd time in this thread, I have to remind that I was replying to a comment saying this: "That's why Apple has the Developer and Public Beta releases for iOS/OSX so that external users can provide feedback. And on this occasion just like on many other they will take action if necessary." So, maybe you s…

>My point was that developers filed feedback about this issue during the betas, yet Apple did not address that feedback, and thus "That's why Apple has the Developer and Public Beta releases for iOS/OSX" is not a valid point in this context.

Well, to that I agree.

Re: Apple removes first-party firewall exemption in macOS 11.2 beta 2

#306
post #240

Earlier quoted context omitted.

> doesn't mean it was done as a quick and dirty implementation or that it's hastily made feature done via cutting corners. I wasn't implying that. The ContentFilterExclusionList was already present in the first WWDC beta and could have been there internally for many months prior, who knows. I was using "hack" more in the sense of bypassing a security system. I said "It never should have existed", which is not a comme…

> It's incredibly tiresome when HN commenters try to "Macsplain" to me. Isn't it also tiresome when people on HN assume we know who they are from their handle, or that we are somehow obliged to have followed them outside HN, and remember/know who they are? I might recognize pg, or patio11, or tptacek, and a few more, but not everybody. And most handles, I just glaze over, they are not the important part in the discus…

> Isn't it also tiresome when people on HN assume we know who they are from their handle

No, I don't expect people to know who I am. However, I do expect people to avoid assuming that I'm ignorant of the subject at hand. This ought to be the default approach you have toward anyone.

In this same thread, I was referred to as "My sweet summer child", as if I didn't understand software development at all. This shouldn't happen, regardless of whether you know me or not. https://news.ycombinator.com/item?id=25771925

Re: Apple removes first-party firewall exemption in macOS 11.2 beta 2

#307
post #280
post #278

Earlier quoted context omitted.

This definitely is a feature. You can use sandboxing if you want to. See kernel namespaces (used by Docker), Ubuntu's snaps, etc. But breaking almost all software by default just because some incompetent users keep choosing to install malware is not a great strategy.

It isn't the dichotomy you set it up to be. macOS solved this without "breaking almost all software by default" using per-app, per-directory permissions for the file system, over and above the decades-old POSIX file modes model. You're making excuses for the lack of security innovation on Linux workstations. They've fallen behind.

To be frank, Mac is not a model I would want to follow.

I am the sysadmin and owner of my machine, not Apple or some other organization. They have no business telling me what software I can and can't run, or what files that software can access.

Re: Apple removes first-party firewall exemption in macOS 11.2 beta 2

#308
post #167

Earlier quoted context omitted.

Factory installed CIA snoop software on Macs is news to me, especially bearing in mind most of the factories are in Taiwan. Where can I find out more? Also if the spyware is installed in firmware at the factory, how is Linux going to help you?

Well I think it's mac specific software. I learned about it from wikileaks. Eg https://wikileaks.org/ciav7p1/cms/space_2359301.html

That's iOS software, not Mac software, with the exception of info on some tools to install on a Mac to help hack iOS devices.

Re: Apple removes first-party firewall exemption in macOS 11.2 beta 2

#309
post #297
post #288

Earlier quoted context omitted.

I don't think it's inaccurate; the IC pays the data providers (presumably for implementation/overhead) for receiving the FAA702 (PRISM/FISA) data. Which data is picked by the US government, and no warrant is required. Apple provided data on 30,000+ users to the US government without a warrant in 2019, per their own transparency report. If they received money for the program, they are indeed "selling user data to [the…

A reimbursement for effort/overhead is not the same as selling for profit. Again, there *really are companies who sell consumer data to law enforcement for profit*, so it's important to use the correct language and make the appropriate distinction. Do I like that Apple does that? No. Do I think the actual policy conversation is best served by accuracy in language? Yes.

You're just playing word games. Apple gave user information to the US government in return for money. That's selling.

Nitpicking about whether they made a profit has no bearing on the statement “Apple selling user data to US government”.

Re: Apple removes first-party firewall exemption in macOS 11.2 beta 2

#310
post #279

Earlier quoted context omitted.

When Apple launched iOS 6, it was the first operating system to include per-app privacy controls around access to things like microphone, camera, photos, etc. Controls we consider fundamental today. It did not mention it a single time in any of its PR or marketing at all. The first reference you find to it will be from Apple blogs who were surprised to stumble upon it in the iOS 6 beta. It took Android two more years…

This comment has no basis of truth. https://www.youtube.com/watch?v=39iKLwlUqBo Jobs @ D8 People are quick to forget because back then everyone (including HN) was praising Google for everything under the sun.

In that video, Steve mentions the fact that iOS had location permission prompts before iOS 6 – is that what you are referring to as incorrect? Because that is a good catch, permission prompts were present at least as early as iOS 4.2:

https://developer.apple.com/documentation/corelocation/clloc...

EDIT: Oh, I see, if you are referring to the PR or marketing portion, I think it is certainly clear that Apple had a pro-privacy stance, but that did not make its way into the company's _consumer_ marketing:

https://web.archive.org/web/20120718122643/http://www.apple....

Post reply on HN