Live data from Hacker News

Apple removes first-party firewall exemption in macOS 11.2 beta 2

twitter.com

351–354 of 354 posts

Re: Apple removes first-party firewall exemption in macOS 11.2 beta 2

#351
post #290

In Case You Didn't Know: Big Sur on M1 (and possibly on Intel) maintains a persistent, hardware-serial-number linked TLS connection to Apple (for APNS, just like on iOS) at all times when you are logged in, even if you don't use iCloud, App Store, iMessage, or FaceTime, and have all analytics turned off. There's no UI to disable this. This means that Apple has the coarse location track log (due to GeoIP of the client…

Well anyone can do the same and you’d be none the wiser.

Unless of course you go on and install LittleSnitch or the Windows equivalent, which is something I’m not sure even the all of the HN does bother to do anymore.

And then you’re left off with trusting Microsoft or intel or AMD with their unaudited management engines running on-cpu with DMA access, oh and whatever is running in the EFI firmware...

It’s (did)trust all the way down

Re: Apple removes first-party firewall exemption in macOS 11.2 beta 2

#352
post #350

Earlier quoted context omitted.

I might have mistaken it for the evidence that they installed hacking tools on factory fresh iPhones, not macs. https://wikileaks.org/vault7/ >"NightSkies 1.2" a "beacon/loader/implant tool" for the Apple iPhone. Noteworthy is that NightSkies had reached 1.2 by 2008, and is expressly designed to be physically installed onto factory fresh iPhones. i.e the CIA has been infecting the iPhone supply chain of its targets s…

Factory fresh just means fresh from the factory, not necessarily in the factory. The attack targets phones in their manufactured state with the OS and vendor firmware installed. In other words it's not an attack that depends on end user software (Apps) being installed, or on user behaviour, or even on features of the mobile network. By supply chain, when they say mail orders and other shipments, they just mean betwee…

Alright then they probably aren't infected straight from the factory. However Apple is definitely collaborating with NSA as are other major US tech companies.

Re: Apple removes first-party firewall exemption in macOS 11.2 beta 2

#353
post #345

Earlier quoted context omitted.

https://developer.apple.com/documentation/xcode/notarizing_m... > Beginning in macOS 10.14.5, software signed with a new Developer ID certificate and all new or updated kernel extensions must be notarized to run. Beginning in macOS 10.15, all software built after June 1, 2019, and distributed with Developer ID must be notarized So, no. You need Apple's approval to be able to create software that can actually be ran b…

First, that is "software signed with a new Developer ID". You can just not sign software and it does not need to be notarised. Second, notarisation is not an "approval". It is a malware scan. The only thing that requires notarisation, which, again, is not "approval", is kernel extensions.

How can you notarize your software when apple has suspended your developer account? Would you not say that notarization requires you to have a developer account, which requires Apple's approval?

Re: Apple removes first-party firewall exemption in macOS 11.2 beta 2

#354
post #213

Earlier quoted context omitted.

> I find your attitude of continuing to attack Apple inappropriate. I do so because I am an Apple user - this is being typed on a mac mini. I also own other Apple hardwares. I also advocated for Apple hardware within my family & friends to switch from Android to Apple quite successfully (I am the IT guy in my circle). I did so because I would like to believe their commitment to privacy they have publicly stated. (Tim…

Your CV or Apple credentials are not relevant. If one considers privacy important, as you seem to, then they should engage with companies which at least try to behave in a privacy-friendly way instead of typing backdoor in all caps several times and painting those companies in a bad light while not recognizing any of their contributions to improving the privacy of their customers. And here are those contributions spe…

> Your CV or Apple credentials are not relevant.

Maybe not to you. It should be for Apple, if they actually care about their users / customers.

> Apple is the only company preventing Google from having the private information of all smartphone users ...

No, it isn't. There are other worthy contenders to both ios and Android, like Sailfish OS. (In fact, using a Sailfish OS mobile phone actually protects my data from both Apple and Google - it's a double win for me).

And unlike you, my idea of privacy isn't trusting one corporate over another, but ensuring that no corporate has access to my personal data itself in the first place - I absolutely do not want Apple to have access to any of my data. (And whether you like it or not, until Apple does precisely that, I will keep criticising it).

Post reply on HN