Live data from Hacker News

Bypassing Firewalls in macOS Big Sur

twitter.com

181–190 of 251 posts

Re: Bypassing Firewalls in macOS Big Sur

#181
post #178

On my system: % cd /System/Library/Frameworks/ % cd NetworkExtension.framework/ % cd Versions/A/Resources/ % ls -l Info.plist -rw-r--r-- 1 root wheel 8.9K Jan 1 2020 Info.plist ⇒ I think this requires root. That, IMO, would make it less of an issue (maybe even a good thing, given the complaints people have about Apple not giving them control over their hardware)

It's totally irrelevant if this requires root or not, since the issue is about endpoint firewalls not being able to see this traffic/filter it. A normal non-apple root process doesn't have this privilege, going by the described exploit.

IMO, this issue is not about the existence of the feature, but about non-Apple software being able to take advantage of it. For that requiring root, IMO, is relevant.

Re: Bypassing Firewalls in macOS Big Sur

#182

This is a deal breaker for me. Little Snitch is absolutely 100% essential for privacy. I’m staying on MacOS Catalina until they pry it off my cold dead hands.

I'm still on Mojave and thinking about staying there.

If the 16inch came with Mojave that would be my safe place too. Killing 32bit apps and now bypssing firewalls. They really are a selfish engineering group.

Re: Bypassing Firewalls in macOS Big Sur

#183
post #32
post #28

This seems so negligent it's difficult for me to believe this was a mistake. Perhaps it could be argued that Apple doesn't want applications blocking the network traffic of trusted applications because there is limited upside to doing so and doing so may restrict core functionality such as system updates, etc. But surely the most reasonable explanation here is that Apple wants a back door to guarantee they can monito…

No, that is not the most reasonable expectation. Fails both Occam's Razor and the laugh test. To believe this, one has to believe that a $2 trillion company did this on purpose, knowing it would be revealed within hours and that it would take a major hit on the very reputation for user privacy and security that they have spent years building. There are a lot of better explanations available than "Apple decided user s…

Ultimately, there's little difference between incompetence and malevolence when acting in this level. Incompetence might actually be slightly worse.

The malevolent act on their best interest which is often predictable and limited. The incompetent simply give away data to every random badguy under the sun.

Re: Bypassing Firewalls in macOS Big Sur

#185
post #7

How to disable this feature: https://tinyapps.org/blog/202010210700_whose_computer_is_it.... And a humorous guide on disabling protections like code signing and notarization: https://www.naut.ca/blog/2020/11/13/forbidden-commands-to-li...

The issue is defaults. Personally, I prefer using an open source alternative OS where generally everything is disbled by default. (NetBSD is best exemple I have found.) Commercial OS like the ones created by Apple, Microsoft, Google, etc. have default settings that are opinionated, i.e., some users might not wish to choose these settings. This puts a burden on the user to disable or work around them somehow. Apple iO…

It seems to me that the issue with this approach is that those commercial OSs have to deal with a way more diverse audience than NetBSD and even Linux.

While most of Linux's audience (and probably practically all of NetBSD's) is rather technically inclined and could possibly be expected to turn on the security features as they need them, most of Windows' and macOS's audience will very likely have no idea that there is even an option to do this.

Also, software companies would probably take the easy route and just assume that since those features aren't enable by default, most people don't enable them and develop their software in a way which could be incompatible with them.

So I think that for an OS like macOS, where most people flock "because it just works and has no viruses", strict defaults are a sane choice. Having people go through hoops and click through warning messages would probably also push companies to better design their software.

In the end, I think the best way is for such features to be the default setup. But those OSs need to have an "escape hatch" for someone who actually wants those features disabled and actually understands the risks of disabling them. While macOS does (for the moment) have this hatch, it looks maybe /too/ complex. But then I think the difficulty of the exercise is in setting the "correct" level of complexity for this operation.

Re: Bypassing Firewalls in macOS Big Sur

#186
post #7

How to disable this feature: https://tinyapps.org/blog/202010210700_whose_computer_is_it.... And a humorous guide on disabling protections like code signing and notarization: https://www.naut.ca/blog/2020/11/13/forbidden-commands-to-li...

The issue is defaults. Personally, I prefer using an open source alternative OS where generally everything is disbled by default. (NetBSD is best exemple I have found.) Commercial OS like the ones created by Apple, Microsoft, Google, etc. have default settings that are opinionated, i.e., some users might not wish to choose these settings. This puts a burden on the user to disable or work around them somehow. Apple iO…

99% of users need opinionated settings as they are not qualified to have opinions on them.

So the right path for consumer OS is ‘sound opinions, easily changed’.

Re: Bypassing Firewalls in macOS Big Sur

#187
post #132
post #96

Earlier quoted context omitted.

disable sideloading and enforce a Mac App Store only policy on macOS People have been repeating that for years, since the Mac App Store was announced. It’s not in Apple’s interest to do it. There is a ton of software, open source in particular, that Apple benefits tremendously by. It costs Apple nothing to maintain the status quo. Going Mac App Store only would drive tons of developers off the platform and do absolut…

Apple developers would stay on the platform, regardless. The GNU/Linux developers that have been giving money to Apple for a shinny UNIX, might go to Windows with WSL, which I doubt unless we are speaking about the crowd that only cares about POSIX and keeps calling that "Linux". The GNU/Linux developers that have been giving money to Apple for a shiny UNIX instead of sponsoring OEMs, now they finally learn how Apple…

In this context it can be a "power" move to push away developers who are unwilling to agree to further closing of the platform. As a result Apple will have only "the faithful ones" and will avoid reactions like recent Unreal fiasco ( in this case the faithful one is Unity). And as I see its working perfectly, most of tech you-tubers are in the bag by default, most of the designers and creative users are lazy (and technically challenged), corporate users, semi pros and regular iPhone crowd are already locked in and don't care. The only thing is someone to start legislative reaction, but this is hard and Apple has all the money. So this is the new norm. Machiavellian move with global impact:)

Re: Bypassing Firewalls in macOS Big Sur

#188

This is a deal breaker for me. Little Snitch is absolutely 100% essential for privacy. I’m staying on MacOS Catalina until they pry it off my cold dead hands.

My exact reaction:) I can run on Catalina at least for 5 years and move to full Gento Linux after this.

Re: Bypassing Firewalls in macOS Big Sur

#189
post #7

How to disable this feature: https://tinyapps.org/blog/202010210700_whose_computer_is_it.... And a humorous guide on disabling protections like code signing and notarization: https://www.naut.ca/blog/2020/11/13/forbidden-commands-to-li...

The issue is defaults. Personally, I prefer using an open source alternative OS where generally everything is disbled by default. (NetBSD is best exemple I have found.) Commercial OS like the ones created by Apple, Microsoft, Google, etc. have default settings that are opinionated, i.e., some users might not wish to choose these settings. This puts a burden on the user to disable or work around them somehow. Apple iO…

These are almost unchangeable defaults, it’s not like Apple is setting a desktop background and you can just click and change it.

The list is really disappointing.

Re: Bypassing Firewalls in macOS Big Sur

#190
post #48

Earlier quoted context omitted.

Why _should_ you have to disable this feature? Sigh. My point: opting out should be much, much easier.

First boot: “Do you wish Apple to receive ... for your security?” Most users will say yes. Technical ones at least can say no. Easier than setting up bluetoooth.

Actually the OS asks these questions already.
Post reply on HN