Live data from Hacker News

macOS 11’s hidden security improvements

blog.malwarebytes.com

101–110 of 152 posts

Re: macOS 11’s hidden security improvements

#101

Earlier quoted context omitted.

Back doors in the Linux kernel source code? No. Back doors in GNU/Linux distribution repositories? Maybe.

You don't think, with all the resources available to them, the intelligence community would spend just about whatever it took to sneak a vulnerability or two into the most-run piece of code on the planet? The core devs don't even have to be corrupted--there are 28 million lines of code in the kernel, you don't think a motivated adversary could sneak something past the gate keepers?

Any middleware Linux/BSD router could detect suspicious traffic.

Re: macOS 11’s hidden security improvements

#102
post #61

Earlier quoted context omitted.

This, a million times. Now that Mojave is starting to get dropped, Linux is exactly what the doctor ordered for me. I feel a lot safer in a system where I can check the locks instead of being told "the door's closed, you're fine."

Make no mistake, there are back doors into Linux as well.

Very difficult to do so as anyone can create (and distros do) a customized kernel and userland with severally different compiling options.

OpenSSL vs LibreSSL, Glibc vs Musl, X11 vs Arcan (or just the framebuffer/KMS), and so on.

Also, on exploits realize Linux and BSD run in devices very different from X86 right? NetBSD today runs even on Alpha, and 0days won't work with ease there.

Even more with the new RISC-V arches here.

Re: macOS 11’s hidden security improvements

#103

Earlier quoted context omitted.

On the other hand, Linux is getting better and better. And with the prevalence of web apps, the main obstacle to running non (MS | Apple) systems is getting smaller. With Linux, you can adjust the level of security you need and you keep the key. Security improvements appear also in BSDs, especially OpenBSD, but honestly I wouldn't recommend people used to macOS to switch to OpenBSD (yet).

You get that. And about a million tradeoffs in terms of usability. No thanks. Edit: To those downvoting. If you genueinly think running linux isn't a UIUX downgrade on macOS you are totally deluded. Its more open. Cool. It's also a UX nightmare.

> If you genueinly think running linux isn't a UIUX downgrade....

You've betrayed yourself with this statement. There isn't one Linux. I know this might just seem like more of the complexity non-Linux users want to avoid, however users are free to install whatever desktop environment or window manager they like. You could even opt for a desktop environment that resembles MacOS in most ways.

I use MacOS in my professional life, and Linux in my personal. My Linux PC has my own personalised setup built around the i3 window manager. I can say without question that I'm much faster and more productive on Linux than MacOS.

Re: macOS 11’s hidden security improvements

#104

Earlier quoted context omitted.

photoanalysisd Does anyone else wonder what exactly it is analysing now, after the whole CSAM thing came to light?

Apple's Photos app can search photos based on their contents (e.g. try typing "cat" into the Photos search box). It can also identify individual faces, and group photos based on who's in them. All of this is local-only. (Which is why it has to run an expensive indexing process locally.)

Cool tech, but so frustrating if it can't be toggled as an option. Reading this it's clear that I would be even more incompatible with macos now than when I left it years ago, just the lack of control.

Re: macOS 11’s hidden security improvements

#105
post #46

Earlier quoted context omitted.

It's the year of the Linux desktop!

It has been Linux desktop year for at least 15 years now. The state of Linux Desktop has actually being getting worse, not better. From a top with Ubuntu in the first 5 years, to the sad state we see now.

I understand that there are still some pain points for casual users. I first started using Linux on a daily basis in university in the mid 2000s. Back then, even distributions designed for casual users like Ubuntu had problems with everyday tasks like configuring multiple monitors. These days, I don't see any of those problems. I'm pretty confident I could give my parents a computer with Ubuntu 20 on it and they could probably figure out how to do their everyday tasks without any issues.

Re: macOS 11’s hidden security improvements

#106
post #61

Earlier quoted context omitted.

This, a million times. Now that Mojave is starting to get dropped, Linux is exactly what the doctor ordered for me. I feel a lot safer in a system where I can check the locks instead of being told "the door's closed, you're fine."

Make no mistake, there are back doors into Linux as well.

I'm a very privacy conscious Linux user. I'm not doing anything illegal, so I have no active concern about security. I'm not unrealistic. When it comes to my threat profiling, I don't expect my desktop to withstand attack by alphabet-soup US federal agencies. I just want to know that I have complete ownership of my hardware, and my data. I'm satisfied just knowing that a shadowy company like Google, or Apple, is not profiling me. If someone was going to be concerned with security from the government, Linux is still much more preferable than Windows, Android, or MacOS.

Re: macOS 11’s hidden security improvements

#107
post #52

Earlier quoted context omitted.

>The posture that the team has towards pushing those latter ones is what generally makes people unhappy. Well, pledge and unveil work fine.

Obviously those two fall in the former.

So what mitigations are "fanciful junk" exactly, and was that actually known before or just poo-poo'd the way basically everything the openbsd folks introduce is?

Re: macOS 11’s hidden security improvements

#108

Kinda sad to think future generations of Mac users won’t be able to write self modifying assembly. I feel like that’s a fun learning experience

That hasn't been a trivial option for a while, userland W^X (DEP) was implemented across the board >15 years ago.

TFA seems to be confused about what Apple did with the M1, macOS has had W^X enabled across the board (for userland) on all supported 64b architectures since 10.5 (10.4 only had stack W^X).

Re: macOS 11’s hidden security improvements

#109

Earlier quoted context omitted.

photoanalysisd Does anyone else wonder what exactly it is analysing now, after the whole CSAM thing came to light?

The CSAM thing "came to light"? They announced it publicly and proudly, before it was even implemented! There's no reason to think they are hiding anything.

The code for this was found in iOS 14.3, just in an inactivated state.

Re: macOS 11’s hidden security improvements

#110
post #97

Earlier quoted context omitted.

Youtube’s release notes: “Fixed bugs, improved performance, took the afternoon off”.

This is valid for all google aps.

Fixed bugs, improved performance, took the afternoon off, ~project got cancelled~, ~team~ got restructured, the intern.
Post reply on HN