Live data from Hacker News

Apple removes first-party firewall exemption in macOS 11.2 beta 2

twitter.com

311–320 of 354 posts

Re: Apple removes first-party firewall exemption in macOS 11.2 beta 2

#311
post #225

Earlier quoted context omitted.

Apple Silicon Macs use per-file encryption tied to the credentials: https://support.apple.com/en-gb/guide/security/secf6276da8a/... Was carried over from iOS. A way to bypass it _should_ be possible, but will entail having the System volume of the volume group to have different properties than the Data part. Otherwise the OS will fail to load. (on Apple Silicon Macs, macOS is fully booted already when you input the p…

Does this mean that every user account has their own data volume or that every user account has their home folder encrypted on a per-file basis? Or neither? What is the privacy implications of two users (both with administrator accounts) sharing an Apple Silicon Mac?

One data volume per OS install.

Both users have access to all the data in that case. It got carried over from iOS which didn't have multi-user support.

(and this is by-design, protection granularity is the volume)

Re: Apple removes first-party firewall exemption in macOS 11.2 beta 2

#312
post #255

Earlier quoted context omitted.

When Apple launched iOS 6, it was the first operating system to include per-app privacy controls around access to things like microphone, camera, photos, etc. Controls we consider fundamental today. It did not mention it a single time in any of its PR or marketing at all. The first reference you find to it will be from Apple blogs who were surprised to stumble upon it in the iOS 6 beta. It took Android two more years…

The first except for Blackberry. Before IOS or Android even existed Blackberry had granular per app permissions. I don't disagree with your argument though, of the modern mobile OSs Apple moved to towards the per-app model before everyone else. I just find it interesting when Apple or Android gets coverage/credit for a feature that has long existed but was forgotten or ignored.

I did not know this, thanks for teaching me something new! It goes at least back to BlackBerry OS 4, running on the BlackBerry Pearl, released in 2008 (but likely further back):

> You can set permissions that control how third-party applications on your BlackBerry device interact with the other applications on your device. For example, you ca control whether third-party applications can access data or the Internet, make calls, or use Bluetooth® connections.

https://www.t-mobile.com/support/public-files/images/legacy/...

Re: Apple removes first-party firewall exemption in macOS 11.2 beta 2

#313
post #307
post #280

Earlier quoted context omitted.

It isn't the dichotomy you set it up to be. macOS solved this without "breaking almost all software by default" using per-app, per-directory permissions for the file system, over and above the decades-old POSIX file modes model. You're making excuses for the lack of security innovation on Linux workstations. They've fallen behind.

To be frank, Mac is not a model I would want to follow. I am the sysadmin and owner of my machine, not Apple or some other organization. They have no business telling me what software I can and can't run, or what files that software can access.

They do neither.

Re: Apple removes first-party firewall exemption in macOS 11.2 beta 2

#314

Earlier quoted context omitted.

If you’re curious about more of the history (now, almost a decade ago), this was the scandal that likely motivated the above: https://www.theverge.com/2012/2/7/2782947/path-ios-app-user-... Congresspeople sent letters to app developers as a result (not even Apple, ha). iOS 6 was then seeded to the public four months after that article. But! It actually goes earlier than this. Apple started phasing out access to devic…

If it was seeded 4 months after the article, it had absolutely nothing to do with the article.

Yes, that makes sense, development timelines for these features are often far longer than we imagine.

Re: Apple removes first-party firewall exemption in macOS 11.2 beta 2

#315

Earlier quoted context omitted.

Which monitors are you using?

Two Asus 27GN950-B's ( https://www.lg.com/us/monitors/lg-27gn950-b-gaming-monitor ) connected by USB-C to DP. I have heard about the issue on a few other forums with other monitors. The only one I haven't heard about in either direction is the ProDisplay XDR.

Err, LG, not Asus...

Re: Apple removes first-party firewall exemption in macOS 11.2 beta 2

#316
post #290

In Case You Didn't Know: Big Sur on M1 (and possibly on Intel) maintains a persistent, hardware-serial-number linked TLS connection to Apple (for APNS, just like on iOS) at all times when you are logged in, even if you don't use iCloud, App Store, iMessage, or FaceTime, and have all analytics turned off. There's no UI to disable this. This means that Apple has the coarse location track log (due to GeoIP of the client…

At least in the EU, it sounds like this should be in violation of the ePrivacy directive (aka the cookie law).

There’s an open complaint [0] about the IDFA on the same basis...

[0] https://noyb.eu/en/noyb-files-complaints-against-apples-trac...

Re: Apple removes first-party firewall exemption in macOS 11.2 beta 2

#317

Earlier quoted context omitted.

When Apple launched iOS 6, it was the first operating system to include per-app privacy controls around access to things like microphone, camera, photos, etc. Controls we consider fundamental today. It did not mention it a single time in any of its PR or marketing at all. The first reference you find to it will be from Apple blogs who were surprised to stumble upon it in the iOS 6 beta. It took Android two more years…

That's not true at all. Even early Nokia (Symbian) or Blackberry phones had fine grained permission prompts. As did early Android, actually, but they were deemed to annoying for users. Apple does deserve credit for leading and influencing Android in this regard, but neither the concept nor the implementation is new.

Do you have a link to the Android thing? I'd be curious to learn more. I always thought early Android had transparency (showing what an app uses) but no control over changing it.

Re: Apple removes first-party firewall exemption in macOS 11.2 beta 2

#318

This is really responsible of them! Before, I was trying to figure out how mac's would ever be used anywhere near something classified or secret for a company.

> Before, I was trying to figure out how mac's would ever be used anywhere near something classified or secret for a company. Relying on a personal firewall on the device itself seems ill-fated. Maybe it could be considered an additional layer of security, but I've yet to work at a place where a personal firewall is part of the security concept, no matter which OS. It's either firewalls at the gateway, maybe addition…

I mostly agree with your assessment of their usefulness, but any organisation that handles credit cards likely has to use personal firewalls. Requirement 1.4 of the DSS:

> Install personal firewall software or equivalent functionality on any portable computing devices (including company and/or employee-owned) that connect to the Internet when outside the network (for example, laptops used by employees), and which are also used to access the CDE.

The most common place this would come up would be with SREs/Devs that have access to prod (and thus the "Cardholder Data Environment") from their laptops. It can also apply to business users that have access to certain admin dashboards in some organisations.

Re: Apple removes first-party firewall exemption in macOS 11.2 beta 2

#319

Earlier quoted context omitted.

I am not suggesting it is perfect, but that it may be a little hyperbolic to say any os you load on a Mac is not it's 'own OS' because it relies on closed bootloaders/firmware. If that is the case, then what does every other computer run? Is Linus's own operating system not his own because he loads it on an Intel or AMD processor?

We will know the answer to that question once we study thoroughly all versions of microcode those processors have/ had. Alto had how much? 128k ? and some big part of it was for display memory? And it was a full OS. Just imagine what you can have in firmware/bootloader now days. Is it that hard to imagine for everybody?

But, again, as of today the situation on Intel is no different.

That doesn’t mean it’s okay, but, well, I guess I would be interested to know what computer you’re using. :)

Re: Apple removes first-party firewall exemption in macOS 11.2 beta 2

#320
post #308

Earlier quoted context omitted.

Well I think it's mac specific software. I learned about it from wikileaks. Eg https://wikileaks.org/ciav7p1/cms/space_2359301.html

That's iOS software, not Mac software, with the exception of info on some tools to install on a Mac to help hack iOS devices.

Yes that wasn't the precise link I apologise. They had details on the mac stuff too. If you look around. https://wikileaks.org/vault7/

https://www.pcworld.com/article/3184435/wikileaks-documents-...

Post reply on HN