Live data from Hacker News

Apple's apps bypass firewalls like LittleSnitch and LuLu on macOS Big Sur

twitter.com

201–210 of 649 posts

Re: Apple's apps bypass firewalls like LittleSnitch and LuLu on macOS Big Sur

#201

"You don't need kernel extensions, we'll provide APIs for you! We won't abuse the power that gives us, promise!" ...and now Apple has altered the deal and we must pray they do not alter it further. Disgusting. Predictable, expected, unsurprising -- but still disgusting.

Tim Cook's Apple Inc is really a nightmare. Sure we have sleek shiny laptops and devices that are amazingly powerful but at what cost? I still haven't found a trackpad as good as MagicTrackpad sadly otherwise I'd ditch the MacBook Pro. To be fair to Apple though, it's their OS, they can do what they want and we agree every time we update MacOS or iOS. It's crazy to me that we basically only have 3 phone device choice…

New XPS 15 has great trackpad and is a good alternative. Its not any cheaper than MBP though. https://www.youtube.com/watch?v=WCM8FZlFTas

Re: Apple's apps bypass firewalls like LittleSnitch and LuLu on macOS Big Sur

#202

"You don't need kernel extensions, we'll provide APIs for you! We won't abuse the power that gives us, promise!" ...and now Apple has altered the deal and we must pray they do not alter it further. Disgusting. Predictable, expected, unsurprising -- but still disgusting.

Tim Cook's Apple Inc is really a nightmare. Sure we have sleek shiny laptops and devices that are amazingly powerful but at what cost? I still haven't found a trackpad as good as MagicTrackpad sadly otherwise I'd ditch the MacBook Pro. To be fair to Apple though, it's their OS, they can do what they want and we agree every time we update MacOS or iOS. It's crazy to me that we basically only have 3 phone device choice…

The talos raptor has a power9 cpu. The Ampere is powered by arm. There is an upcoming risc-v based pc by SiFive

That is at least 3 niche entries in addition to the 2 mainstream choices.

Intel wants really badly to be a 3rd player in the GPU space and its integrated graphics are already good enough if you aren't gaming although I have doubts about their upcoming dedicated GPU.

The Linux desktop space is nicer in the keyboard centric simple environments space or at least ditch gnome and switch to KDE running on an distro that actually stays up to date.

The challenge is not mostly using such an environment its setting it up in the first place.

Looks like every category has 3-5 options.

Re: Apple's apps bypass firewalls like LittleSnitch and LuLu on macOS Big Sur

#203

Earlier quoted context omitted.

Desktop linux still kind of sucks because there aren't enough people writing desktop linux software which does not suck and not enough people paying for that. Also there are enough people in linux community who still hate/disapprove all the integration efforts (e.g. systemd). And the thing linux sucks the most is integration.

> Also there are enough people in linux community who still hate/disapprove all the integration efforts (e.g. systemd). This is a fair point, and I'm guilty of complaining about systemd myself. Having said that, I haven't seen any improvements in the Linux UI experience that could be explained by "systemd fixed that". Maybe network management??

The biggest thing is probably systemd user services and session management with logind. Having your entire user session under a process supervisor that can anything can hook into is good for stability since your "desktop" now has a much more control of what's actually running. They days of logout just failing because your compositor can't kill all the things are pretty much gone. Logind is far far from perfect but it's a breath of fresh air compared to ConsoleKit and it unifies the concept of a session so that GUI/VNC/SSH are all the same kind of thing.

Re: Apple's apps bypass firewalls like LittleSnitch and LuLu on macOS Big Sur

#204
post #170
post #148

Earlier quoted context omitted.

No you wouldn't. It's not about the trackpad hardware (Apple sells a separate Bluetooth trackpad after all), but it's about the software.

What about the software makes it good? Ive never used a macbook so have zero experience with it.

See also: https://news.ycombinator.com/item?id=24700537

Re: Apple's apps bypass firewalls like LittleSnitch and LuLu on macOS Big Sur

#205
post #167

Earlier quoted context omitted.

I think the threat model here is that someone might've swapped out your keyboard to one that's spying on you, whilst you're out at a conference enjoying the more social aspects of such gatherings. At the same time, if you were to not be connected to a network, this kind of verification wouldn't do anything.

I don't believe this is ever the case. What happens if you legitimately installed a new keyboard? Will Apple just... prevent you from using it?

I have a 2017 MBP. There are several keycaps that that are no longer physically connected to the key, so if I tilt the laptop 4 or 5 keys fall off. I have been dealing with it by using an external Apple keyboard (with added benefit of having 10-key and full sized arrow keys). Since it's on a desktop in this config, I have it set to never sleep so luckily I have not seen this unwakeable fuck up.

Re: Apple's apps bypass firewalls like LittleSnitch and LuLu on macOS Big Sur

#206
post #37

I trust Apple a lot more than I trust Google or Facebook, but this clamping down of the Mac without options for power users while officially stating that the Mac will remain a Mac is alarming and distasteful on the part of Apple. With the transition to Apple’s own chips looming, it seems like the days of “a Mac is a personal computer and not an app console like an iPhone or iPad” will be over by the middle of this de…

Maybe you should review that trust. Apple of 2020 is very different from what they were in 2010 and before

Re: Apple's apps bypass firewalls like LittleSnitch and LuLu on macOS Big Sur

#207

That’s annoying yet pretty predictable, at least we’ve still got https://pi-hole.net/ as an option until DNS encryption becomes widespread :/

Not a pi-hole user, but what is the plan for pi-hole once encrypted dns is everywhere? Will it just be dead? I can’t really think of a way for it not to be.

You use your pi-hole as your encrypted DNS provider?

Re: Apple's apps bypass firewalls like LittleSnitch and LuLu on macOS Big Sur

#208

"You don't need kernel extensions, we'll provide APIs for you! We won't abuse the power that gives us, promise!" ...and now Apple has altered the deal and we must pray they do not alter it further. Disgusting. Predictable, expected, unsurprising -- but still disgusting.

Tim Cook's Apple Inc is really a nightmare. Sure we have sleek shiny laptops and devices that are amazingly powerful but at what cost? I still haven't found a trackpad as good as MagicTrackpad sadly otherwise I'd ditch the MacBook Pro. To be fair to Apple though, it's their OS, they can do what they want and we agree every time we update MacOS or iOS. It's crazy to me that we basically only have 3 phone device choice…

don't upgrade and/or don't continue with apple.

Alternatively firewall your machine, but apple keeps allowing itself workarounds, like find my where "offline" machines aren't so offline.

And then 5G has all kinds of inter-machine connectivity.

Re: Apple's apps bypass firewalls like LittleSnitch and LuLu on macOS Big Sur

#209
post #28

Earlier quoted context omitted.

Dont pray, just dont buy Apple Products

Boycotting is not an effective strategy for addressing oligopolies. You need actual strong anti-trust regulation.

You need everything at the same time. You also should promote Linux among your friends.

Re: Apple's apps bypass firewalls like LittleSnitch and LuLu on macOS Big Sur

#210
post #165
post #127

Earlier quoted context omitted.

any access? On Windows, you can write a driver that would run in kernel mode, but critical sections can't be modified[1]. I'd imagine there's something similar for mac. [1] https://en.wikipedia.org/wiki/Kernel_Patch_Protection

KPP is not considered a security boundary. That means, in Windows security jargon, that it's a feature that helps security. But not something that you or anyone else should consider a fail proof solution, or even something that would result in a patch if breached.

If patching the kernel to intercept network requests is sufficiently hard enough that you're forced to use their "approved" way of intercepting network requests, then it's very easy for them to sneak requests through. Even if patching the kernel wasn't an issue, it still turns into a game of whack a mole because apple can sneak as many changes as they want with each macos release. It heavily favors apple, not the developers of such firewalls.
Post reply on HN