Live data from Hacker News

Apple removes first-party firewall exemption in macOS 11.2 beta 2

twitter.com

341–350 of 354 posts

Re: Apple removes first-party firewall exemption in macOS 11.2 beta 2

#341
post #333

Earlier quoted context omitted.

They do neither.

They most definitely do, using their developer program. Look up Apple vs Epic for a case where they weaponized this.

You can run any software you want on macOS.

You can't publish any software you want on the App Store.

Re: Apple removes first-party firewall exemption in macOS 11.2 beta 2

#342

Earlier quoted context omitted.

I disabled IPv6 altogether, and Apple’s processes are still finding a way to resolve their real IPs after my DNS and /etc/hosts resolved their domains to 0.0.0.0. DNS should be enough, I shouldn’t have to black hole Apple’s entire /8 to stop macOS from phoning home when I’m not using the computer and no apps are running.

I suspect the number of macOS machines on networks with misconfigured DNS is far higher than the number of macOS machines whose admins want to prevent them from talking to Apple. So I’m glad they’re going to great lengths to preserve their ability to communicate with Apple even under adverse network conditions.

I appreciate giving people the benefit of the doubt, but this feels overly charitable to me. I doubt they’re worried about accidentally misconfigured /etc/hosts files.

Much more likely is that they were aware of outbound firewalls like Little Snitch and want to evade user attempts to block their software, as discussed in the main article here.

Re: Apple removes first-party firewall exemption in macOS 11.2 beta 2

#343
post #290

In Case You Didn't Know: Big Sur on M1 (and possibly on Intel) maintains a persistent, hardware-serial-number linked TLS connection to Apple (for APNS, just like on iOS) at all times when you are logged in, even if you don't use iCloud, App Store, iMessage, or FaceTime, and have all analytics turned off. There's no UI to disable this. This means that Apple has the coarse location track log (due to GeoIP of the client…

At least in the EU, it sounds like this should be in violation of the ePrivacy directive (aka the cookie law). There’s an open complaint [0] about the IDFA on the same basis... [0] https://noyb.eu/en/noyb-files-complaints-against-apples-trac...

That seems to be stretching it. The user is informed about the IDFA on setup (one can argue that that is a violation), so it’s not like “Apple’s operating system creates the IDFA without user’s knowledge or consent” because they do inform you.

Regardless, you can always reset it if you want. And “at” WWDC 2020 (half a year before this complaint), Apple made cross app tracking opt-in.[0]

I applaud the EU for leading the way in consumer protection, but every time I hear about it in regards to technology, it always feels heavy handed with the arguments being a stretch sometimes.

[0]: https://www.adexchanger.com/privacy/apple-wwdc-2020-a-versio...

Re: Apple removes first-party firewall exemption in macOS 11.2 beta 2

#344

Earlier quoted context omitted.

At least in the EU, it sounds like this should be in violation of the ePrivacy directive (aka the cookie law). There’s an open complaint [0] about the IDFA on the same basis... [0] https://noyb.eu/en/noyb-files-complaints-against-apples-trac...

That seems to be stretching it. The user is informed about the IDFA on setup (one can argue that that is a violation), so it’s not like “Apple’s operating system creates the IDFA without user’s knowledge or consent” because they do inform you. Regardless, you can always reset it if you want. And “at” WWDC 2020 (half a year before this complaint), Apple made cross app tracking opt-in.[0] I applaud the EU for leading t…

It not stretching. The ePrivacy directive requires that user _is offered the right to refuse such processing by the data controller_, so it also refers to Apple itself.

Re: Apple removes first-party firewall exemption in macOS 11.2 beta 2

#345
post #333

Earlier quoted context omitted.

They most definitely do, using their developer program. Look up Apple vs Epic for a case where they weaponized this.

You can run any software you want on macOS. You can't publish any software you want on the App Store.

https://developer.apple.com/documentation/xcode/notarizing_m...

> Beginning in macOS 10.14.5, software signed with a new Developer ID certificate and all new or updated kernel extensions must be notarized to run. Beginning in macOS 10.15, all software built after June 1, 2019, and distributed with Developer ID must be notarized

So, no. You need Apple's approval to be able to create software that can actually be ran by end-users even if you do not distribute using the App Store.

Re: Apple removes first-party firewall exemption in macOS 11.2 beta 2

#346
post #308

Earlier quoted context omitted.

That's iOS software, not Mac software, with the exception of info on some tools to install on a Mac to help hack iOS devices.

Yes that wasn't the precise link I apologise. They had details on the mac stuff too. If you look around. https://wikileaks.org/vault7/ https://www.pcworld.com/article/3184435/wikileaks-documents-...

Right so they have firmware malware and tools for infiltrating it into machines. That’s not a surprise. The extraordinary claim that I challenged was that this is being installed on Apple computers at the factories. So far as I can tel, there is no evidence for it.

This is like someone claiming it will rain next week and when asked how they know, they say they can prove it rained last week. That’s irrelevant. Yes I know they have firmware attacks. Where does the claim they are putting it on machines in the factory come from? How many times do I need to ask the same question?

Re: Apple removes first-party firewall exemption in macOS 11.2 beta 2

#347
post #345

Earlier quoted context omitted.

You can run any software you want on macOS. You can't publish any software you want on the App Store.

https://developer.apple.com/documentation/xcode/notarizing_m... > Beginning in macOS 10.14.5, software signed with a new Developer ID certificate and all new or updated kernel extensions must be notarized to run. Beginning in macOS 10.15, all software built after June 1, 2019, and distributed with Developer ID must be notarized So, no. You need Apple's approval to be able to create software that can actually be ran b…

First, that is "software signed with a new Developer ID". You can just not sign software and it does not need to be notarised.

Second, notarisation is not an "approval". It is a malware scan.

The only thing that requires notarisation, which, again, is not "approval", is kernel extensions.

Re: Apple removes first-party firewall exemption in macOS 11.2 beta 2

#348
post #346

Earlier quoted context omitted.

Yes that wasn't the precise link I apologise. They had details on the mac stuff too. If you look around. https://wikileaks.org/vault7/ https://www.pcworld.com/article/3184435/wikileaks-documents-...

Right so they have firmware malware and tools for infiltrating it into machines. That’s not a surprise. The extraordinary claim that I challenged was that this is being installed on Apple computers at the factories. So far as I can tel, there is no evidence for it. This is like someone claiming it will rain next week and when asked how they know, they say they can prove it rained last week. That’s irrelevant. Yes I k…

I might have mistaken it for the evidence that they installed hacking tools on factory fresh iPhones, not macs.

https://wikileaks.org/vault7/

>"NightSkies 1.2" a "beacon/loader/implant tool" for the Apple iPhone. Noteworthy is that NightSkies had reached 1.2 by 2008, and is expressly designed to be physically installed onto factory fresh iPhones. i.e the CIA has been infecting the iPhone supply chain of its targets since at least 2008.

Re: Apple removes first-party firewall exemption in macOS 11.2 beta 2

#350
post #346

Earlier quoted context omitted.

Right so they have firmware malware and tools for infiltrating it into machines. That’s not a surprise. The extraordinary claim that I challenged was that this is being installed on Apple computers at the factories. So far as I can tel, there is no evidence for it. This is like someone claiming it will rain next week and when asked how they know, they say they can prove it rained last week. That’s irrelevant. Yes I k…

I might have mistaken it for the evidence that they installed hacking tools on factory fresh iPhones, not macs. https://wikileaks.org/vault7/ >"NightSkies 1.2" a "beacon/loader/implant tool" for the Apple iPhone. Noteworthy is that NightSkies had reached 1.2 by 2008, and is expressly designed to be physically installed onto factory fresh iPhones. i.e the CIA has been infecting the iPhone supply chain of its targets s…

Factory fresh just means fresh from the factory, not necessarily in the factory. The attack targets phones in their manufactured state with the OS and vendor firmware installed. In other words it's not an attack that depends on end user software (Apps) being installed, or on user behaviour, or even on features of the mobile network.

By supply chain, when they say mail orders and other shipments, they just mean between the vendor and the customer. In this case the use of "supply chain" could be miss-understood, this is a post-factory attack which would be carried out in transit, probably at a US border.

We have seen that done before to shipments of devices such as computers and network gear that have been intercepted and hacked before delivery to a suspect, or a target organisation or country.

I don't think this can be reasonably construed as evidence for Apple conniving with the CIA. In fact I still don't think that would make any sense from a CIA perspective. The factories aren't even in the US. Apple employees aren't background checked or sworn agents, they're a potential security risk. Why involve them if you don't need to?

Post reply on HN