Live data from Hacker News

macOS 11’s hidden security improvements

blog.malwarebytes.com

141–150 of 152 posts

Re: macOS 11’s hidden security improvements

#141

Earlier quoted context omitted.

What's the state of running Linux on Mac hardware these days?

On Intel: Works pretty well. No longer a need to have special ISOs like Ubuntu used to have. You do have to turn off the "secure boot" on newer systems with T2 chip (using the startup security utility in recovery mode) On M1: Still in progress. Linux boots but the kinks have to be worked out. Not production quality yet.

>On Intel: Works pretty well.

Oh, cool! I have one of the last Macbook pros with an Intel chip, so it sounds like I'm probably in the "secure boot" category.

Does the trackpad work well?

Re: macOS 11’s hidden security improvements

#142
post #101

Earlier quoted context omitted.

Any middleware Linux/BSD router could detect suspicious traffic.

I don't think this is realistic any more. There's just too much noise, too many chatty processes, too much traffic. A while ago I tried to track the start of a single application, a new install of Firefox. IIRC the first start generated traffic to about a dozen endpoints. Also, macOS and Windows generate enormous amounts of traffic (others here have noted that). The amount of background traffic is simply overwhelming…

tcpdump on pflog0 and then use wireshark.

Re: macOS 11’s hidden security improvements

#143

Earlier quoted context omitted.

Obviously those two fall in the former.

So what mitigations are "fanciful junk" exactly, and was that actually known before or just poo-poo'd the way basically everything the openbsd folks introduce is?

Trapsled?

Re: macOS 11’s hidden security improvements

#144
post #118

Earlier quoted context omitted.

No way. Ask HN "new generation" to tell you, Apple and Microsoft are taking care of you to feel safe and protecting the children at the same time. Linux desktop sucks. It is broken. I found out that this "brokenness" is what I expect to have. To modify and optimize my UX.

It's not broken at all... At least not for me, being a user for several decades now. I use it at work while billing quite a lot of money so if it was breaking, I would have a massive problem. :) I would say this though - the machine you run it on matters. The hardware matters. Some hardware runs great, other hardware will give you problems. This is due to driver support either being good or bad, not Linux itself, but…

It is sarcasm. But obviously I communicated this poorly. Linux actually is more comfortable for development. macOS is broken by design. MacOS X in the old times was a dream to work on. But now with all "privacy" features from Apple - anything is a problem, and the quality of software from Cupertino is lowest ever.

Re: macOS 11’s hidden security improvements

#145

Earlier quoted context omitted.

On Intel: Works pretty well. No longer a need to have special ISOs like Ubuntu used to have. You do have to turn off the "secure boot" on newer systems with T2 chip (using the startup security utility in recovery mode) On M1: Still in progress. Linux boots but the kinks have to be worked out. Not production quality yet.

>On Intel: Works pretty well. Oh, cool! I have one of the last Macbook pros with an Intel chip, so it sounds like I'm probably in the "secure boot" category. Does the trackpad work well?

Good question, I haven't tried it on one that recent. But on my older ones it worked fine. Even gestures. Not as smooth as on macOS though.

Re: macOS 11’s hidden security improvements

#146

Earlier quoted context omitted.

You get that. And about a million tradeoffs in terms of usability. No thanks. Edit: To those downvoting. If you genueinly think running linux isn't a UIUX downgrade on macOS you are totally deluded. Its more open. Cool. It's also a UX nightmare.

Nah. It's great. You can view hidden files in the file manager without memorizing a keyboard shortcut or terminal command. Most Window managers don't rely on track pad gestures and so the mouse feels like a first class citizen. Window management in the big DEs is better than macOS. MacOS is a frustrating mess to me.

The vast majority of users (the U in UX) do not ever need to see a dotfile. In fact, you'd not want them anywhere near one.

Re: macOS 11’s hidden security improvements

#147
post #85

Earlier quoted context omitted.

You get that. And about a million tradeoffs in terms of usability. No thanks. Edit: To those downvoting. If you genueinly think running linux isn't a UIUX downgrade on macOS you are totally deluded. Its more open. Cool. It's also a UX nightmare.

I don't think anyone should downvote expressing an opinion, at least when it's done without toxicity like you did. Ok, that "delusion" remark was a bit toxic. But anyway. Here's my opinion: i3 is vastly superior to anything macos is offering in the desktop space in terms of usability. Sure, wrestling with minutae like proper font rendering and DPI settings is a huge pain, but a) some distros do those things for you a…

Fair, but it's not vastly superior for the majority of computer users, whose experience revolves entirely around the mouse. That's what I was getting at with macOS being better - generally, obviously not for every person.

Re: macOS 11’s hidden security improvements

#148

Earlier quoted context omitted.

You get that. And about a million tradeoffs in terms of usability. No thanks. Edit: To those downvoting. If you genueinly think running linux isn't a UIUX downgrade on macOS you are totally deluded. Its more open. Cool. It's also a UX nightmare.

> If you genueinly think running linux isn't a UIUX downgrade.... You've betrayed yourself with this statement. There isn't one Linux . I know this might just seem like more of the complexity non-Linux users want to avoid, however users are free to install whatever desktop environment or window manager they like. You could even opt for a desktop environment that resembles MacOS in most ways. I use MacOS in my profess…

This entire comment proves my point. To you - a developer / tech pro, you feel Linux has a better UX.

My point was generalised, and I think generally the average computer user is going to have a better UX on macOS than linux. If they can figure out how to even set up Linux of course.

Re: macOS 11’s hidden security improvements

#149
post #100
post #89

Earlier quoted context omitted.

Does anyone know for a way to disable this scanning by photoanalysisd? (Other than not having any photos.) my old laptop keeps chugging away at that process for tens of minutes after each wake.

Find the binary of the service and chmod -x it as root.

Be careful with this approach, I’ve run into a problem where this causes macOS to spam your system logs with errors.

Re: macOS 11’s hidden security improvements

#150

Earlier quoted context omitted.

Nah. It's great. You can view hidden files in the file manager without memorizing a keyboard shortcut or terminal command. Most Window managers don't rely on track pad gestures and so the mouse feels like a first class citizen. Window management in the big DEs is better than macOS. MacOS is a frustrating mess to me.

The vast majority of users (the U in UX) do not ever need to see a dotfile. In fact, you'd not want them anywhere near one.

So piss off the users that do? For a while there wasn't even the keyboard shortcut. Throw up a scary warning if you need to but I feel like it's a basic system function that should be included. Some how Windows manages to allow users to toggle hidden files through the GUI and I haven't heard of too many disasters because of it.

I would argue it's actually worse with the keyboard shortcut on OS X because it's completely possible for someone to trigger Cmd+Shift+. accidentally whereas in other OSs it's a clear toggled option in the GUI.

Post reply on HN