Live data from Hacker News

Bypassing Firewalls in macOS Big Sur

twitter.com

221–230 of 251 posts

Re: Bypassing Firewalls in macOS Big Sur

#221

Earlier quoted context omitted.

Interesting thanks, what would be the Linux equivalent of SIP?

SIP relies on entitlements, which rely on code signing. I'm not sure code signing is at all a thing on Linux.

Package signing is definitely a thing on Linux.

Re: Bypassing Firewalls in macOS Big Sur

#222

Ugh. I'd love to switch to Linux, but as a designer, I'm stuck. It's not a lack of understanding of how it works— Before I was a designer I was a developer, worked in IT for a while, worked in upper-level support for a while, and Linux was my primary personal and professional OS from the late 90s to like 2010. Why don't I just run a closed-source OS in a VM? They are fussy. Having some weird graphics tablet driver pr…

I agree that Gimp et al are terrible, but why not use Figma? It’s a great design tool, and thanks to it being browser-based you can use it on any platform, including Linux.

Re: Bypassing Firewalls in macOS Big Sur

#225
Trying to understand this as someone who is not sophisticated about security issues. It SOUNDS like, if you have a Big Sur machine that runs no software other than Apple's and software downloaded from App Store, this isn't an issue.

The problem is if you install non-App Store software. Most people don't need to do that, but of course, the types of users who frequently Hacker News frequently will. So they run the risk of installing, and using, malicious software.

I myself do install non-App Store software sometimes. Prior to Big Sur, I could use Little Snitch and be sure I knew what servers it was communicating with. With Big Sur, I can't.

Does that sum up the problem?

Re: Bypassing Firewalls in macOS Big Sur

#226

Trying to understand this as someone who is not sophisticated about security issues. It SOUNDS like, if you have a Big Sur machine that runs no software other than Apple's and software downloaded from App Store, this isn't an issue. The problem is if you install non-App Store software. Most people don't need to do that, but of course, the types of users who frequently Hacker News frequently will. So they run the risk…

Pretty much any file you could open on your computer can be used to install malware (given the right conditions). It’s not limited to applications. And that malware can now hijack these services that bypass firewalls, VPNs, etc undetected.

Re: Bypassing Firewalls in macOS Big Sur

#227

Trying to understand this as someone who is not sophisticated about security issues. It SOUNDS like, if you have a Big Sur machine that runs no software other than Apple's and software downloaded from App Store, this isn't an issue. The problem is if you install non-App Store software. Most people don't need to do that, but of course, the types of users who frequently Hacker News frequently will. So they run the risk…

Pretty much any file you could open on your computer can be used to install malware (given the right conditions). It’s not limited to applications. And that malware can now hijack these services that bypass firewalls, VPNs, etc undetected.

Thank you. I am not sophisticated about these things so let me ask a follow-up. By "open" a file, most end users think of documents that are opened by applications... either from the App Store or from Apple.

I think you are thinking about things like shell scripts, binary executables that run in the terminal which being an official Mac "Application", etc. Is that right?

Re: Bypassing Firewalls in macOS Big Sur

#228
post #72

This reminds me of the old saying that it's impossible to work within an infected system to clean it --- and now that corporations have been "infecting" systems with such telemetry/spyware by default, that's even more true. I believe Win10 was the first to do something like this --- it ignores the hosts files and firewall for certain hardcoded domain names and IPs.

https://en.wikipedia.org/wiki/Hosts_(file) If you want to block something use a firewall.

Even an external firewall can't easily block everything. Just send telemetry over port 443 to an AWS server and most can't block it. You can't trust a device that need an outgoing firewall.

Re: Bypassing Firewalls in macOS Big Sur

#229

Earlier quoted context omitted.

Pretty much any file you could open on your computer can be used to install malware (given the right conditions). It’s not limited to applications. And that malware can now hijack these services that bypass firewalls, VPNs, etc undetected.

Thank you. I am not sophisticated about these things so let me ask a follow-up. By "open" a file, most end users think of documents that are opened by applications... either from the App Store or from Apple. I think you are thinking about things like shell scripts, binary executables that run in the terminal which being an official Mac "Application", etc. Is that right?

Malware can be embedded in just about anything. PDFs and other documents are a common vector. While scripts and executables are obviously a greater risk, it’s pretty easy to mask malware as those files as well.

Re: Bypassing Firewalls in macOS Big Sur

#230

You play with fire you will get burned. Same thing will happen with an encryption backdoor like the EU is now thinking of forcing down our throats...

Saying "the EU wants to backdoor encryption" is like saying "the USA wants to backdoor encryption" when one working group is talking about it. "The EU" doesn't want backdoors in encryption just like American politicians don't all agree with trump's Twitter mania.
Post reply on HN