Live data from Hacker News

Apple's apps bypass firewalls like LittleSnitch and LuLu on macOS Big Sur

twitter.com

241–250 of 649 posts

Re: Apple's apps bypass firewalls like LittleSnitch and LuLu on macOS Big Sur

#241

"You don't need kernel extensions, we'll provide APIs for you! We won't abuse the power that gives us, promise!" ...and now Apple has altered the deal and we must pray they do not alter it further. Disgusting. Predictable, expected, unsurprising -- but still disgusting.

Don't bother to look to Microsoft Windows for a solution! For don't forget MS Windows has a 'dial-home-to-Microsoft' link that's hard coded within Windows itself. It bypasses the hosts file altogether, and if I recall correctly, it's been in Windows since XP. The only solution stop the 'talk-home' connection would be to find the destination IPs numbers and then key them into your external router for blocking.

Windows doesn't bypass 3rd party firewalls.

Re: Apple's apps bypass firewalls like LittleSnitch and LuLu on macOS Big Sur

#242
post #21

Apple seems to do all kinds of weird networking _stuff_. For instance, during wakeup, your T2 equipped Macbook will wait for a DNS response and then use said DNS response to synchronize time via NTP before letting the user use the keyboard. Probably checking timestamps on signatures for the keyboard firmware, or something stupid like that. This only happens if it happens to have a default route. Similarly, all macOS…

Apple touted the T2 chip as the bee's knees in security. Now, we have a vulnerability that cannot be defended against. However, Apple went all in on the security of this T2 chip so that you cannot replace the SSD (besides the method to manufacture). I appreciate the desire at making a device difficult for a bad actor to get to your data, but they epicly failed and ultimately only made an user-hostile device. Oh, and…

The new keyboard is no longer horrible beyond index. Unfortunately, it's merely adequate, which at least in my book is unacceptable for any $1k+ laptop, let alone $3k+.

Re: Apple's apps bypass firewalls like LittleSnitch and LuLu on macOS Big Sur

#243

Earlier quoted context omitted.

Desktop linux still kind of sucks because there aren't enough people writing desktop linux software which does not suck and not enough people paying for that. Also there are enough people in linux community who still hate/disapprove all the integration efforts (e.g. systemd). And the thing linux sucks the most is integration.

> Also there are enough people in linux community who still hate/disapprove all the integration efforts (e.g. systemd). This is a fair point, and I'm guilty of complaining about systemd myself. Having said that, I haven't seen any improvements in the Linux UI experience that could be explained by "systemd fixed that". Maybe network management??

There are A LOT of improvements (e.g. session management, dynamically spawned services, networking, bluetooth, thunderbolt) which were made possible by systemd, udev and dbus.

I'm not saying that UI/UX is good. It sucks. It does not improve that much over time. Also Canonical made things worse by rolling out snapd which is unreliable and hard to setup non-ubuntu distros (e.g. it tends to drop its state on Gentoo)

Re: Apple's apps bypass firewalls like LittleSnitch and LuLu on macOS Big Sur

#244

Background: I've written my own kernel extension that works in similar manner to Little Snitch, but does a lot more, including SSL MITM and on-demand packet capture, that I've been using for more than 10 years now. It's a fact that Apple has continuously moved to lock down macOS in ways that are antithetical to folks that want full control over their operating system. To many of us that moved on from Linux on the des…

hahaha. I also don’t plan to upgrade past Mojave. To me Catalina was a trainwreck and at this point I think I’m loosing a lot of trust I used to put in Apple. this is compounded by the fact that I love Little Snitch and it has basically exponentially improved my life when it comes not only to browsing the web but when using any app on mac.

I tried catalina and... why? why did they dumb down mail? This is like the beige apple box era all over again. lame decision after lame decision and everything turns to mud.

Re: Apple's apps bypass firewalls like LittleSnitch and LuLu on macOS Big Sur

#245

Earlier quoted context omitted.

Apple touted the T2 chip as the bee's knees in security. Now, we have a vulnerability that cannot be defended against. However, Apple went all in on the security of this T2 chip so that you cannot replace the SSD (besides the method to manufacture). I appreciate the desire at making a device difficult for a bad actor to get to your data, but they epicly failed and ultimately only made an user-hostile device. Oh, and…

Additionally charging on the left side ports makes the T2 chip overheat and crashes the machine on occasion.

What if you have a model with ports only on the left-hand side? Does it crash it as well?

Re: Apple's apps bypass firewalls like LittleSnitch and LuLu on macOS Big Sur

#246
post #6

This is one of those tough cases where software cuts both ways. Some people are smart, informed developers that install a trusted tool to monitor their traffic and have legitimate reasons to want to inspect Apple traffic. They're dismayed. Most people are the opposite and this move protects the most sensitive data from being easily scooped up or muddled in easily installed apps, or at least easily installed apps that…

Have you used little snitch? It very clearly allows all apple traffic by default, and if you modify something that would affect it, you get a huge popup explaining what will happen and have to click on a red button to confirm.

Re: Apple's apps bypass firewalls like LittleSnitch and LuLu on macOS Big Sur

#247

Earlier quoted context omitted.

Not a pi-hole user, but what is the plan for pi-hole once encrypted dns is everywhere? Will it just be dead? I can’t really think of a way for it not to be.

DoT isn't a big problem for a pihole, but it doesn't look like things are going that way. DoH can only be blocked by a mitm proxy. You would have to take a pretty serious security hit to do something like that with a pihole.

Whitelisting would make it much more difficult for wildcat DoH. On the gripping hand, whitelisting is extremely annoying and tends to block more work-related-and-useful than software that is actually malicious.

Re: Apple's apps bypass firewalls like LittleSnitch and LuLu on macOS Big Sur

#248
post #172

Earlier quoted context omitted.

Jobs' Apple created technologies which have rooted deeply in POSIX standards and standard UNIX* conventions. If you knew UNIX(Linux/BSD/whatever), you can find the same data streams on the same places. OS was obscure but, predictable. Different but, familiar. It had kernel extensions, logs and devices. Nothing was extremely obfuscated. It was a UNIX device but, shinier . Now it feels like a glorified iOS box with mor…

I intend this with kindness: normally I don’t nitpick on grammar and punctuation, but you’ve got a repeated error here that’s easily corrected. Generally, you want to break your sentences with commas _before_ usage of “but”: “He wanted to buy a pen, but the store had run out.” If you’re a native speaker, the comma goes where you’d naturally have a brief pause in speech. If you’re not a native speaker, it may be helpf…

If you’re a native speaker, the comma goes where you’d naturally have a brief pause in speech.

Some speech styles use pause after "but". You can hear it from news reporters and on tv shows in general, when actors read partial sentences from paper or screen. It is not exclusive to english, and it is a common mistake to use punctuation with respect to own/technical intonations and delays instead of correct ones.

"X but, Y" likely means "X, but... Y" here, i.e. the first pause is much less pronounced than the second.

Re: Apple's apps bypass firewalls like LittleSnitch and LuLu on macOS Big Sur

#249
post #219

Earlier quoted context omitted.

So what if that is their reasoning? Freedom also means the freedom to make mistakes. We don't set a standard of "absolute safety" in many other (arguably more important) areas of our lives, so why do it here?

Because a computer is an appliance for most people, with it working, and it being secure, being an absolutely critical feature. I believe still have the option to disable SIP and make as many mistakes as you want. [1] 1. https://developer.apple.com/documentation/macos-release-note... > Workaround: During development, you can temporarily disable System Integrity Protection to allow these deprecated kernel extensions t…

The fact that you can still disable SIP is a good point and I hope that's always possible. The direction Apple is going thought suggests that an iPad-like experience is the eventual goal.

Re: Apple's apps bypass firewalls like LittleSnitch and LuLu on macOS Big Sur

#250
post #21

Apple seems to do all kinds of weird networking _stuff_. For instance, during wakeup, your T2 equipped Macbook will wait for a DNS response and then use said DNS response to synchronize time via NTP before letting the user use the keyboard. Probably checking timestamps on signatures for the keyboard firmware, or something stupid like that. This only happens if it happens to have a default route. Similarly, all macOS…

Hmm is this also why I can't use my bluetooth mouse at the login screen?

Would certain go a long way to explain why waking my MBP up after going AFK involves an affair that requires me to undock it from my vertical stand, entering password, and awkwardly trying to place it back into the stand, reconnecting peripherals while slapping the BT keyboard endlessly so it doesn't go back to sleep after login.

Quite annoying.

Post reply on HN