Live data from Hacker News

macOS 11’s hidden security improvements

blog.malwarebytes.com

131–140 of 152 posts

Re: macOS 11’s hidden security improvements

#131
post #113
post #66

Earlier quoted context omitted.

Except, those quickly disappeared. That's the essence of the joke that was mentioned. Each year was called the year of the Linux Desktop, but it never happened.

I meant the 'year' had come and gone, 20 years ago.

Gotcha! Thank you.

Re: macOS 11’s hidden security improvements

#132
post #46

Earlier quoted context omitted.

It's the year of the Linux desktop!

It has been Linux desktop year for at least 15 years now. The state of Linux Desktop has actually being getting worse, not better. From a top with Ubuntu in the first 5 years, to the sad state we see now.

For a developer / power user Linux Desktop is years ahead of Mac OS. I recently bought a Macbook for testing and given how shiny it is, I had the thought to consider using it as a daily computer, but I could not switch because of the obstacles below and I continue being a happy Linux user:

1. Security. On Linux you can setup mandatory access control - i.e. AppArmor, SeLinux, and even if you don't want to fiddle with that, you can create mutliple users for multiple purposes to sandbox your data from untrusted apps. Running a program as another user is no problem on Linux - try it on Mac OS... (I did try it and it almost worked but things like select file dialog won't work, which makes it useless). By the way, Apple introduced some sandboxing capabilities in Catalina, but it's almost insulting because it only allows to restrict Desktop, Downloads and Trash directories, and not allowing the user to restrict other custom directories to certain apps only. And even for Desktop/Downloads it does not work reliably - i.e. I could not isolate a web browser from accessing desktop.

2. Privacy. I accidentally came upon article from a few years ago where it was revealed that Mac OS sends usage data to Apple or a third party on an unencrypted channel. Then there's the recent issue with client side scanning.

3. Desktop experience. This may be cosmetic but I don't like that Mac OS forces a slow 200ms fade animation when switching between desktops. You can't even switch back and forth too fast because the switching mechanism won't catch the hotkey if the slow fade animation is in progress.

The hardware is good though. Really hoping M1 on Linux will become a thing.

Re: macOS 11’s hidden security improvements

#133
post #96

Earlier quoted context omitted.

Both Microsoft and Apple are treating users like they don't care now. And probably 99.99999% of the users don't. Today you have to run Linux to control your computer yourself.

In soviet russia the computer controls you. It's funny to see Apple with 1984 ad and Microsoft which said that GPL is communistic apply the same tactics as the KGB and Soviet politburo. I think that people never learn because they are so happy to embrace the future.

In Soviet Russia the government force computer to control you.

In capitalist America you freely choose to let a small number of corporations sell you computers which control you.

There's a big difference! (In theory, at least.)

Re: macOS 11’s hidden security improvements

#134

Earlier quoted context omitted.

Apple's Photos app can search photos based on their contents (e.g. try typing "cat" into the Photos search box). It can also identify individual faces, and group photos based on who's in them. All of this is local-only. (Which is why it has to run an expensive indexing process locally.)

Cool tech, but so frustrating if it can't be toggled as an option. Reading this it's clear that I would be even more incompatible with macos now than when I left it years ago, just the lack of control.

It can be.

Re: macOS 11’s hidden security improvements

#135

Earlier quoted context omitted.

photoanalysisd Does anyone else wonder what exactly it is analysing now, after the whole CSAM thing came to light?

Apple's Photos app can search photos based on their contents (e.g. try typing "cat" into the Photos search box). It can also identify individual faces, and group photos based on who's in them. All of this is local-only. (Which is why it has to run an expensive indexing process locally.)

I have my photos on Synology NAS, and it does the same thing - except it manages doing it much more efficiently, while using a much weaker Atom CPU.

Re: macOS 11’s hidden security improvements

#136
post #69

Earlier quoted context omitted.

Not with SIP engaged.

Why is it not possible to disable SIP, make the desired changes, compute a new seal, then enable SIP again?

I kind of bailed on macOS prior to Big Sur, so I'm not sure—but I think you can do that. Authenticated-root would need to be kept turned off, but that's a separate thing.

You're going to have to redo everything after every update, however.

Re: macOS 11’s hidden security improvements

#137
post #92
post #69

Earlier quoted context omitted.

Why is it not possible to disable SIP, make the desired changes, compute a new seal, then enable SIP again?

Because if you can do it, any rootkit will be able to do it too.

No it can't. You'd have to disable SIP temporarily in the first place, and a rootkit can't boot a recovery environment while SIP is engaged.

And then on Apple Silicon Macs, entering 1TR is tied to the physical action of holding down the power button.

Re: macOS 11’s hidden security improvements

#138

Earlier quoted context omitted.

photoanalysisd Does anyone else wonder what exactly it is analysing now, after the whole CSAM thing came to light?

Apple's Photos app can search photos based on their contents (e.g. try typing "cat" into the Photos search box). It can also identify individual faces, and group photos based on who's in them. All of this is local-only. (Which is why it has to run an expensive indexing process locally.)

photoanalysisd was responsible for making my Mac feel slow at least 80% of the time I started to notice it chug. Apple should really limit the processes CPU time so that it doesn't randomly spin up my fans.

Re: macOS 11’s hidden security improvements

#139
post #61

Earlier quoted context omitted.

This, a million times. Now that Mojave is starting to get dropped, Linux is exactly what the doctor ordered for me. I feel a lot safer in a system where I can check the locks instead of being told "the door's closed, you're fine."

Make no mistake, there are back doors into Linux as well.

You could avoid looking like a clown by adding some URLs to relevant sources to your post.

Re: macOS 11’s hidden security improvements

#140
post #85

Earlier quoted context omitted.

You get that. And about a million tradeoffs in terms of usability. No thanks. Edit: To those downvoting. If you genueinly think running linux isn't a UIUX downgrade on macOS you are totally deluded. Its more open. Cool. It's also a UX nightmare.

I don't think anyone should downvote expressing an opinion, at least when it's done without toxicity like you did. Ok, that "delusion" remark was a bit toxic. But anyway. Here's my opinion: i3 is vastly superior to anything macos is offering in the desktop space in terms of usability. Sure, wrestling with minutae like proper font rendering and DPI settings is a huge pain, but a) some distros do those things for you a…

To me Mac OS has a nicer looking UI, but i3 has better UX. For instance, the animations on Mac OS are annyoing. There is nothing good about adding a delay to basic operations. On i3, I can switch between workspaces in an instant, on Mac OS, I have to wait for a stupid 200ms animation to finish - and that is after already fiddling in system settings to disable fancy animation effects (the default was slide-in, ugh).
Post reply on HN