Earlier quoted context omitted.
Interesting thanks, what would be the Linux equivalent of SIP?
SIP relies on entitlements, which rely on code signing. I'm not sure code signing is at all a thing on Linux.
Bypassing Firewalls in macOS Big Sur
221–230 of 251 posts
Re: Bypassing Firewalls in macOS Big Sur
#222Ugh. I'd love to switch to Linux, but as a designer, I'm stuck. It's not a lack of understanding of how it works— Before I was a designer I was a developer, worked in IT for a while, worked in upper-level support for a while, and Linux was my primary personal and professional OS from the late 90s to like 2010. Why don't I just run a closed-source OS in a VM? They are fussy. Having some weird graphics tablet driver pr…
Re: Bypassing Firewalls in macOS Big Sur
#223Re: Bypassing Firewalls in macOS Big Sur
#224Re: Bypassing Firewalls in macOS Big Sur
#225The problem is if you install non-App Store software. Most people don't need to do that, but of course, the types of users who frequently Hacker News frequently will. So they run the risk of installing, and using, malicious software.
I myself do install non-App Store software sometimes. Prior to Big Sur, I could use Little Snitch and be sure I knew what servers it was communicating with. With Big Sur, I can't.
Does that sum up the problem?
Re: Bypassing Firewalls in macOS Big Sur
#226Trying to understand this as someone who is not sophisticated about security issues. It SOUNDS like, if you have a Big Sur machine that runs no software other than Apple's and software downloaded from App Store, this isn't an issue. The problem is if you install non-App Store software. Most people don't need to do that, but of course, the types of users who frequently Hacker News frequently will. So they run the risk…
Re: Bypassing Firewalls in macOS Big Sur
#227Trying to understand this as someone who is not sophisticated about security issues. It SOUNDS like, if you have a Big Sur machine that runs no software other than Apple's and software downloaded from App Store, this isn't an issue. The problem is if you install non-App Store software. Most people don't need to do that, but of course, the types of users who frequently Hacker News frequently will. So they run the risk…
Pretty much any file you could open on your computer can be used to install malware (given the right conditions). It’s not limited to applications. And that malware can now hijack these services that bypass firewalls, VPNs, etc undetected.
I think you are thinking about things like shell scripts, binary executables that run in the terminal which being an official Mac "Application", etc. Is that right?
Re: Bypassing Firewalls in macOS Big Sur
#228This reminds me of the old saying that it's impossible to work within an infected system to clean it --- and now that corporations have been "infecting" systems with such telemetry/spyware by default, that's even more true. I believe Win10 was the first to do something like this --- it ignores the hosts files and firewall for certain hardcoded domain names and IPs.
https://en.wikipedia.org/wiki/Hosts_(file) If you want to block something use a firewall.
Re: Bypassing Firewalls in macOS Big Sur
#229Earlier quoted context omitted.
Pretty much any file you could open on your computer can be used to install malware (given the right conditions). It’s not limited to applications. And that malware can now hijack these services that bypass firewalls, VPNs, etc undetected.
Thank you. I am not sophisticated about these things so let me ask a follow-up. By "open" a file, most end users think of documents that are opened by applications... either from the App Store or from Apple. I think you are thinking about things like shell scripts, binary executables that run in the terminal which being an official Mac "Application", etc. Is that right?
Re: Bypassing Firewalls in macOS Big Sur
#230You play with fire you will get burned. Same thing will happen with an encryption backdoor like the EU is now thinking of forcing down our throats...