Live data from Hacker News

Apple removes first-party firewall exemption in macOS 11.2 beta 2

twitter.com

331–340 of 354 posts

Re: Apple removes first-party firewall exemption in macOS 11.2 beta 2

#331
post #290

In Case You Didn't Know: Big Sur on M1 (and possibly on Intel) maintains a persistent, hardware-serial-number linked TLS connection to Apple (for APNS, just like on iOS) at all times when you are logged in, even if you don't use iCloud, App Store, iMessage, or FaceTime, and have all analytics turned off. There's no UI to disable this. This means that Apple has the coarse location track log (due to GeoIP of the client…

How do you know that apple is logging GeoIPs and performing this association with appleIDs? Or are you just saying it’s possible to do so?

Apple has to log client IPs on these systems to prevent abuse, to stop people doing things like scraping every public key for every iMessage user and then publishing the diffs.

IP to ISP/Location mapping is just a lookup table, and can be done at any time now or in the future.

Re: Apple removes first-party firewall exemption in macOS 11.2 beta 2

#332
post #325
post #321

Earlier quoted context omitted.

With a datetime and IP, you can geoIP any time in the future. It's a single ETL operation. So you treat it like they do, one way or another.

This assumes they don’t scrub it before storing it, which we know they do for some services , and we have no information about others. We can’t in fact treat it like they do. We can only treat it like they might be able to .

Anyone monitoring the traffic outside of Apple can do it, as well. IIRC TLS client certificate information is not encrypted on the wire, but I'd need to review modern TLS protocol negotiation to confirm. This would allow anyone monitoring Apple's upstream, passively, to perform this same location logging that Apple does.

Apple knows this, so shipping systems that leak information in this way is tacit acceptance of the military spying going on on the networks to which Apple's servers are connected.

Re: Apple removes first-party firewall exemption in macOS 11.2 beta 2

#333
post #307

Earlier quoted context omitted.

To be frank, Mac is not a model I would want to follow. I am the sysadmin and owner of my machine, not Apple or some other organization. They have no business telling me what software I can and can't run, or what files that software can access.

They do neither.

They most definitely do, using their developer program. Look up Apple vs Epic for a case where they weaponized this.

Re: Apple removes first-party firewall exemption in macOS 11.2 beta 2

#334
post #271

Earlier quoted context omitted.

If that is your idea of Own OS I am happy for you.

You're changing the subject. The discussion is about your implication that one "can’t even have own OS without Apple permission", and that is simply not true.

Am I? Then what ‘closing bootloader’ is if not their form of giving permissions? If I understood correctly they would not “help” with specs and we do not know what bootloader capable of. Why? if their goal to keep it open? Let’s see the tendency.

They have put a complete control over IOS devices since the beginning of IOS, including the apps that were not allowed at all. Since then they are trying to bring this into a ‘personal computer’ domain as it seems.

they started slowly but steady to put more and more control over Mac apps,

then they started limiting root access,

Now the bootloader ...

So where they are going ? As I see it the tendency is to close MacOS completely just as IOS unless they face a strong resistance, then they go for ‘as much as they can get’ or ‘as much as they can get away with’ strategy, feeding some ‘calming pills’ on the way that some perhaps are happy to swallow. They have changed things from, “of course it is not our business what you boot” , to “of course, we may allow unsigned kernels .... for now” (if it’s true at all, we still need to see this in reality) Yes it is not as strong as “we will not allow at all”, but for sure it’s their permission now. You may say, oh it’s just as before. No , it’s not, they have taken some of the existing freedom and intend to take more next year possibly. And who knows what their bootloader does? What if it would be controlled remotely ? What if to load some “unsigned kernels” which are called just kernels by the way, they would still require some online check? Who knows? What of the above is not true or incorrect?

Re: Apple removes first-party firewall exemption in macOS 11.2 beta 2

#335
post #332
post #325

Earlier quoted context omitted.

This assumes they don’t scrub it before storing it, which we know they do for some services , and we have no information about others. We can’t in fact treat it like they do. We can only treat it like they might be able to .

Anyone monitoring the traffic outside of Apple can do it, as well. IIRC TLS client certificate information is not encrypted on the wire, but I'd need to review modern TLS protocol negotiation to confirm. This would allow anyone monitoring Apple's upstream, passively, to perform this same location logging that Apple does. Apple knows this, so shipping systems that leak information in this way is tacit acceptance of th…

“Anyone monitoring the traffic outside of Apple can do it, as well”

Well this is true of every single connection made by every single app on every single device, for every upstream.

That means everyone is tacitly accepting the military spying going on on the networks to which their servers are connected.

That’s not actually an unreasonable position as far as I’m concerned, and you previous comments about this being true unless Tor is embedded have some validity. I say some because I’m unconvinced that Tor is quite ready to handle all traffic yet.

What is unreasonable is your focus on Apple.

By excluding the fact that your complaints are a general problem with TCP/IP and apply to essentially any service, you don’t seem to be doing a great job of informing people about the reality of the problem.

It’s also worth noting that if your position has now moved to how the tracking could be being done by someone monitoring Apple’s network rather than Apple themselves, you are tacitly acknowledging that your claim that Apple is keeping records of your location are just speculation.

Re: Apple removes first-party firewall exemption in macOS 11.2 beta 2

#336
post #329
post #324

Earlier quoted context omitted.

He’s just saying it’s possible to do so. This claim that Apple are tracking your location because they use TCP/IP to receive connections, has been made many times now. Nobody has so far presented evidence that Apple does in fact geolocate people or even that they persistently store IP address information related to user accounts. I don’t know for sure that they do not, but I do know that they are aware that keeping I…

There are ways to communicate over the internet that don't disclose the source IP of the client doing the connecting. Tor also uses TCP/IP, so your oversimplification of my post is... not accurate. > Nobody has so far presented evidence that Apple does in fact geolocate people or even that they persistently store IP address information related to user accounts. We're talking about IP address logs related to hardware…

If you are saying that by using Tor, origin information can be hidden, I’d say that’s true.

So for everything not using such a method, what I said is true, which is almost everything.

If you said “Apple should use Tor for everything so that eavesdroppers cannot deduce people’s locations via GeoIP” that would be a fair statement.

Sayid “Apple keeps records of your location history”, is speculation which you have never substantiated, despite repeated challenges.

However what I said still holds despite this small exception.

IP address logs certainly can be changed before storage.

Re: Apple removes first-party firewall exemption in macOS 11.2 beta 2

#337
post #330
post #328

Earlier quoted context omitted.

Well the iCloud backups not being encrypted yet is a serious problem. Weirdly, this isn’t news - anonymous sources have said before that it was due to FBI pressure. But this doesn’t have anything to do with Apple logging locations. If sneak’s claim was correct, there would be nothing we could do about it. If we’re talking about iCloud backups, at the very least you can turn those off and do them locally. I’m pretty s…

Apple had at least a partial implementation of e2e backup that was resilient to users losing their passwords, via something like friends-and-family secret sharing to perform data recovery. The implementation was scrapped. There are ways of solving these problems, throwing up hands and saying "it can't be done anyway" is silly. Apple has done a lot of things that couldn't be done: a computer without a floppy or serial…

“it can't be done anyway”

Nobody is saying this.

Also I agree with you - e2e secret sharing is possible, although hard for users with just one device - I.e. a lot of people.

And yes, Apple has solved a lot of fucking hard problems, slowly, and incrementally.

Just because they haven’t done it yet doesn’t mean they won’t.

You have no evidence at all that any of this is because “Apple Serves at the pleasure of US military intelligence”.

You keep making claims that are pure speculation as if they are true.

I actually agree with keeping pressure up on Apple to implement E2E backups.

I guess you don’t think that’s ever going to be possible though.

Re: Apple removes first-party firewall exemption in macOS 11.2 beta 2

#338
post #145

Earlier quoted context omitted.

Apple has no love for privacy nor ever had. They are in a market position where their main competitors - Google primarily, Microsoft and Amazon - are highly dependent on revenue streams extracted by monetizing personal information. Apple is in a position to cut that stream without affecting its bottom line, so it does it and claims privacy as a core value. I won't look a gift horse in the mouth, but I have no doubt t…

When Apple launched iOS 6, it was the first operating system to include per-app privacy controls around access to things like microphone, camera, photos, etc. Controls we consider fundamental today. It did not mention it a single time in any of its PR or marketing at all. The first reference you find to it will be from Apple blogs who were surprised to stumble upon it in the iOS 6 beta. It took Android two more years…

Android had permission system before iOS implement it, but it was just a prompt for list of permissions at install time so not much worth like current one.

Re: Apple removes first-party firewall exemption in macOS 11.2 beta 2

#339
post #247
post #207

Earlier quoted context omitted.

How do you know it's "by design"? By default macOS was always using this encryption scheme, but there was always possibility to have an optional FDE. Now this is broken and I can't even manage to get macOS installed when any encrypted partition is present since it's also cause installer to fail. I obviously find it being absolutely terrible "design" decision since there no way on earth anyone can count disk encryptio…

Why is that so important? Your disk encryption key is certainly stored in memory for the duration of your session (which on Macs might as well be forever since they don’t need to shutdown), so anyone with your user password can gain access either way.

It is important because M1 is iOS-derived hardware and unlikely to keep disk encryption keys in memory that you or anyone can freely dump. And hardware attacks against TPM are both costly and hard to perform.

Also in case of travel or emergency it's much easier to just power it off. At the same time there is tons of ways how someone can steal your day-to-day lock screen password.

Re: Apple removes first-party firewall exemption in macOS 11.2 beta 2

#340

Earlier quoted context omitted.

Are you also writing :: domain.example Because the difference is gethostbynamev2 (the most likely function being used, or I suppose the Apple equivalent) looks up a ipv6 hostname before it looks up a ipv4 hostname, which means a "0.0.0.0 domain.example" entry won't override the result of ipv6 lookups. $ echo "0.0.0.0 cloudflare.com" | sudo tee -a /etc/hosts $ getent hosts cloudflare.com && getent ahosts cloudflare.co…

I disabled IPv6 altogether, and Apple’s processes are still finding a way to resolve their real IPs after my DNS and /etc/hosts resolved their domains to 0.0.0.0. DNS should be enough, I shouldn’t have to black hole Apple’s entire /8 to stop macOS from phoning home when I’m not using the computer and no apps are running.

I suspect the number of macOS machines on networks with misconfigured DNS is far higher than the number of macOS machines whose admins want to prevent them from talking to Apple. So I’m glad they’re going to great lengths to preserve their ability to communicate with Apple even under adverse network conditions.
Post reply on HN