Live data from Hacker News

Bypassing Firewalls in macOS Big Sur

twitter.com

31–40 of 251 posts

Re: Bypassing Firewalls in macOS Big Sur

#31
post #27

Earlier quoted context omitted.

Why? As long as you're not getting the ARM ones, you can stick on 10.15 - which is something many will do anyway for at least a year until Apple irons out the worst bugs of BS. Only thing I'm still pissed about 10.15 is that Wine still can't run 32-bit apps.

You can stay on an older version for a little while, maybe a year at most until it stops getting patches. Then you get to make the choice of using an OS that's vulnerable to exploits and an OS with a gigantic backdoor in it.

> You can stay on an older version for a little while, maybe a year at most until it stops getting patches.

Catalina should be supported for two more years:

https://computing.cs.cmu.edu/desktop/os-lifecycle

https://www.csun.edu/it/supported-operating-systems

https://www.reddit.com/r/sysadmin/comments/imdzv4/endoflife_...

Re: Bypassing Firewalls in macOS Big Sur

#32
post #28

This seems so negligent it's difficult for me to believe this was a mistake. Perhaps it could be argued that Apple doesn't want applications blocking the network traffic of trusted applications because there is limited upside to doing so and doing so may restrict core functionality such as system updates, etc. But surely the most reasonable explanation here is that Apple wants a back door to guarantee they can monito…

No, that is not the most reasonable expectation. Fails both Occam's Razor and the laugh test.

To believe this, one has to believe that a $2 trillion company did this on purpose, knowing it would be revealed within hours and that it would take a major hit on the very reputation for user privacy and security that they have spent years building.

There are a lot of better explanations available than "Apple decided user security can fuck off and that clumsily collaborating with the bad guys in trivially-detectable ways was a way better plan".

Re: Bypassing Firewalls in macOS Big Sur

#33
post #7

How to disable this feature: https://tinyapps.org/blog/202010210700_whose_computer_is_it.... And a humorous guide on disabling protections like code signing and notarization: https://www.naut.ca/blog/2020/11/13/forbidden-commands-to-li...

I’m not sure it’s sensible to call these “protections” - they’re closer to security theater.

Re: Bypassing Firewalls in macOS Big Sur

#34

Well, this basically confirms my decision to not purchase a macbook for my next laptop.

Why? As long as you're not getting the ARM ones, you can stick on 10.15 - which is something many will do anyway for at least a year until Apple irons out the worst bugs of BS. Only thing I'm still pissed about 10.15 is that Wine still can't run 32-bit apps.

I'm still running 10.14 here, for that very reason (32-bit apps.)

Re: Bypassing Firewalls in macOS Big Sur

#35
post #32
post #28

This seems so negligent it's difficult for me to believe this was a mistake. Perhaps it could be argued that Apple doesn't want applications blocking the network traffic of trusted applications because there is limited upside to doing so and doing so may restrict core functionality such as system updates, etc. But surely the most reasonable explanation here is that Apple wants a back door to guarantee they can monito…

No, that is not the most reasonable expectation. Fails both Occam's Razor and the laugh test. To believe this, one has to believe that a $2 trillion company did this on purpose, knowing it would be revealed within hours and that it would take a major hit on the very reputation for user privacy and security that they have spent years building. There are a lot of better explanations available than "Apple decided user s…

https://news.ycombinator.com/item?id=25096990

Re: Bypassing Firewalls in macOS Big Sur

#36
post #13

This whole release cycle is just one gigantic facepalm after another. I am feeling pretty heavily smug that I got rid of my Apple kit earlier this year because I wasn't happy with the direction of the platform.

What did you move to?

I did the same about a year ago.

Thinkpad running Manjaro GNOME

Works fine, haven't looked back.

Re: Bypassing Firewalls in macOS Big Sur

#37
post #7

How to disable this feature: https://tinyapps.org/blog/202010210700_whose_computer_is_it.... And a humorous guide on disabling protections like code signing and notarization: https://www.naut.ca/blog/2020/11/13/forbidden-commands-to-li...

I’m not sure it’s sensible to call these “protections” - they’re closer to security theater.

Can you give an example of what you consider proper protections?

Re: Bypassing Firewalls in macOS Big Sur

#38

"You can’t have a back door in the software because you can’t have a back door that’s only for the good guys." — Tim Cook

Does it look like the software part of Apple has been consistently grappled with controversial decisions?

I heard Apple has been very secretive in its development. Maybe it works for hardware, but software is an area where collaboration across teams are very important, isolated bubble breeds incompetence and politics.

Re: Bypassing Firewalls in macOS Big Sur

#39
post #31
post #27

Earlier quoted context omitted.

You can stay on an older version for a little while, maybe a year at most until it stops getting patches. Then you get to make the choice of using an OS that's vulnerable to exploits and an OS with a gigantic backdoor in it.

> You can stay on an older version for a little while, maybe a year at most until it stops getting patches. Catalina should be supported for two more years: https://computing.cs.cmu.edu/desktop/os-lifecycle https://www.csun.edu/it/supported-operating-systems https://www.reddit.com/r/sysadmin/comments/imdzv4/endoflife_...

Ah excuse me for that. 2 years of additional lifespan is still painfully short for a deprecated OS. Even free OSes like Ubuntu LTS get more years of support than versions of macOS (Ubuntu LTS release cycle of 2 years minus 5 years of support = 3 years of additional support after deprecation).

Re: Bypassing Firewalls in macOS Big Sur

#40
Of course when this possibility was raised 25 days ago on HN [1] there was a swarm of apologists who figured the superior Apple services needed no firewall interception (and just 2 days ago we learned that hell yes, they do!) and that this was all by design and impervious to abuse by other apps.

Turns out, no, macOS is still written by the same old skeleton crew at Apple and they still introduce trivial problems in most things they do.

1: https://news.ycombinator.com/item?id=24839086

Post reply on HN