Live data from Hacker News

Apple's apps bypass firewalls like LittleSnitch and LuLu on macOS Big Sur

twitter.com

291–300 of 649 posts

Re: Apple's apps bypass firewalls like LittleSnitch and LuLu on macOS Big Sur

#291
post #250

Earlier quoted context omitted.

Hmm is this also why I can't use my bluetooth mouse at the login screen?

Would certain go a long way to explain why waking my MBP up after going AFK involves an affair that requires me to undock it from my vertical stand, entering password, and awkwardly trying to place it back into the stand, reconnecting peripherals while slapping the BT keyboard endlessly so it doesn't go back to sleep after login. Quite annoying.

> reconnecting peripherals while slapping the BT keyboard endlessly so it doesn't go back to sleep after login.

https://www.cru-inc.com/products/wiebetech/mouse_jiggler_mj-...

Re: Apple's apps bypass firewalls like LittleSnitch and LuLu on macOS Big Sur

#292

Hasn't this always been a bit of an issue? Apps with root privileges have been able to get around Little Snitch for as long as I can recall. Some software relies specifically on that ability.

...no, I don't think they could. Is there an example you're thinking of? Up until recently, Little Snitch monitored network traffic in kernel space.

Off the top of my head, I think it was Photoshop or something else along those lines (it's been a few years). It installed itself a little helper tool that ran as root which could talk to the licensing servers without tripping Little Snitch.

I don't run Little Snitch any more, so it may no longer work that way. Some software (games seem to be an egregiously bad offender) insists on communicating with seemlingly random IP addresses and not using DNS to resolve them, and it's hard to run any kind of filtering software or parental controls such as Screen Time successfully. I make do with outbound filtering at my router.

Re: Apple's apps bypass firewalls like LittleSnitch and LuLu on macOS Big Sur

#293

Earlier quoted context omitted.

Apple touted the T2 chip as the bee's knees in security. Now, we have a vulnerability that cannot be defended against. However, Apple went all in on the security of this T2 chip so that you cannot replace the SSD (besides the method to manufacture). I appreciate the desire at making a device difficult for a bad actor to get to your data, but they epicly failed and ultimately only made an user-hostile device. Oh, and…

Additionally charging on the left side ports makes the T2 chip overheat and crashes the machine on occasion.

REALLY?

Okay, I'm going to test this.

I noticed odd hangings and cpu hitting high temps on a MBP 2018' w/ dell usb C dock on left side, meanwhile right side is fine but I had to reboot randomly and sometimes it will just crash.

And this is a MBP on a laptop stand.

Re: Apple's apps bypass firewalls like LittleSnitch and LuLu on macOS Big Sur

#294

Earlier quoted context omitted.

to me it's plainly wrong for a comma. but I also don't like to color outside the box. perhaps an ellipses would've been ok.

Don't worry, your instincts are correct. The only time a comma should follow a conjunction is if there is an interrupting phrase that breaks up the sentence. Example: "He's a nice guy but, to be honest, he smells like a hippopotamus."

I learn so much from grammar folks. :D

Re: Apple's apps bypass firewalls like LittleSnitch and LuLu on macOS Big Sur

#295

Earlier quoted context omitted.

Linux on the desktop and Linux on the laptop (heh) has definitely improved. It _sometimes_ needs a little tweaking to get it right, but KDE/Plasma also happens to offer that level of "tweakability" that should satisfy almost all semi-mainstream users (at least anyone coming from Windows or Mac). Compared to my first Linux laptop (a Sony Vaio circa 2000), my current XPS 13 works as well as any Mac laptop I have ever o…

I try the major DEs every few years to see if they fit me, most recently trying the newest KDE and GNOME versions in a VM about a month ago. Both have improved for sure, but they still have a long way to go… GNOME actually came closest but its customizability level is even lower than that of macOS, even factoring in extensions. Both suffer from a laundry list of minor annoyances that snowball into something that's ha…

elementary OS’s Pantheon seems to be the closest DE to macOS’s Aqua

Re: Apple's apps bypass firewalls like LittleSnitch and LuLu on macOS Big Sur

#296

Earlier quoted context omitted.

I try the major DEs every few years to see if they fit me, most recently trying the newest KDE and GNOME versions in a VM about a month ago. Both have improved for sure, but they still have a long way to go… GNOME actually came closest but its customizability level is even lower than that of macOS, even factoring in extensions. Both suffer from a laundry list of minor annoyances that snowball into something that's ha…

Same experience. I tried, but Linux just isn’t ready to be used as a general OS right now. I’ve dug through message boards and bug reports, and a lot of the features that MacOS has will never be implemented. I’m taking about features released 13+ years ago on OS X 10.4.

> a lot of the features that MacOS has will never be implemented

Care to name any? Other times I’ve heard things like this on HN I’ve been able to locate them.

Re: Apple's apps bypass firewalls like LittleSnitch and LuLu on macOS Big Sur

#297

Earlier quoted context omitted.

Not a pi-hole user, but what is the plan for pi-hole once encrypted dns is everywhere? Will it just be dead? I can’t really think of a way for it not to be.

DoT isn't a big problem for a pihole, but it doesn't look like things are going that way. DoH can only be blocked by a mitm proxy. You would have to take a pretty serious security hit to do something like that with a pihole.

[deleted]

Re: Apple's apps bypass firewalls like LittleSnitch and LuLu on macOS Big Sur

#298
post #13

Earlier quoted context omitted.

If I install Little Snitch, it's because I trust Little Snitch to be responsible for my computer's network traffic, over and above anyone else. I recognize that this won't necessarily apply to all users or all apps, but there needs to be a way for the user to designate trust. Apple services and traffic should not get special treatment.

They provide the OS. If you don't trust them, then you shouldn't trust anything running on top of it either...

I trust my friend Mike to drive me to the pub. I don't trust Mike to be the executor of my will.

Re: Apple's apps bypass firewalls like LittleSnitch and LuLu on macOS Big Sur

#299
post #21

Apple seems to do all kinds of weird networking _stuff_. For instance, during wakeup, your T2 equipped Macbook will wait for a DNS response and then use said DNS response to synchronize time via NTP before letting the user use the keyboard. Probably checking timestamps on signatures for the keyboard firmware, or something stupid like that. This only happens if it happens to have a default route. Similarly, all macOS…

Apple touted the T2 chip as the bee's knees in security. Now, we have a vulnerability that cannot be defended against. However, Apple went all in on the security of this T2 chip so that you cannot replace the SSD (besides the method to manufacture). I appreciate the desire at making a device difficult for a bad actor to get to your data, but they epicly failed and ultimately only made an user-hostile device. Oh, and…

> I appreciate the desire at making a device difficult for a bad actor to get to your data

That's what FileVault is for. I don't understand what's the problem T2 is trying to solve by its existence. Being able to use something else to read the data from a drive you pulled out of your computer, after decrypting it with your password, is a feature, not a bug. T2 is a regression, not an improvement in security. You can't call it a security product if you keep the master key, which Apple does.

Re: Apple's apps bypass firewalls like LittleSnitch and LuLu on macOS Big Sur

#300
post #219

Earlier quoted context omitted.

Because a computer is an appliance for most people, with it working, and it being secure, being an absolutely critical feature. I believe still have the option to disable SIP and make as many mistakes as you want. [1] 1. https://developer.apple.com/documentation/macos-release-note... > Workaround: During development, you can temporarily disable System Integrity Protection to allow these deprecated kernel extensions t…

The fact that you can still disable SIP is a good point and I hope that's always possible. The direction Apple is going thought suggests that an iPad-like experience is the eventual goal.

The requirement of a developer account, or some entitlement, to get full access would really be unfortunate.
Post reply on HN