Live data from Hacker News

Apple's apps bypass firewalls like LittleSnitch and LuLu on macOS Big Sur

twitter.com

391–400 of 649 posts

Re: Apple's apps bypass firewalls like LittleSnitch and LuLu on macOS Big Sur

#391

Earlier quoted context omitted.

> any backdoors Apple builds for its own apps Apple hasn't weakened the security of their devices to provide a secret way in, in fact, they made their systems even more robust. The question absolutely is whether Apple can be trusted. Little Snitch works for other apps, just not Apple's apps. The remaining slice of the pie you're arguing for is whether or not we can trust Apple. So what delta in security and trust ove…

> Apple hasn't weakened the security of their devices to provide a secret way in, in fact, they made their systems even more robust. I'd consider poking a hole in firewalls to be providing "a secret way in", particularly in the context of Little Snitch. This isn't some antivirus bloatware that comes preinstalled, or a firewall imposed by corporate networks. The entire pitch of Little Snitch is that it enables you , t…

ANY firewall inherently trusts the OS of the device it's running. They have to in order to function. The firewall sits on top of the OS, not underneath it. Even on Linux if you're running ipfw, the traffic first goes through the OS and then to your firewall.

Re: Apple's apps bypass firewalls like LittleSnitch and LuLu on macOS Big Sur

#392

Earlier quoted context omitted.

What's the alternative for the typical user? Windows has its own problems, and let's face it: market forces on this sort of thing or any other practices by the two of them have not driven people to use desktop Linux instead. For most people, there's simply no reasonable option to switch to that would avoid these things or employ market forces to get these companies to change their ways.

Depends on what the typical user does. I would guess a lot of people would be fine with a Chrome Book.

The barrier isn't usability or functionality for most use cases. The barrier is getting it on the computer and supporting it. We don't have the retail & support infrastructure in place for it to be a practical option. If a non-technical person has Linux on their computer, it's probably because some technical relative put it there, and has made themselves the support person for it as well. You can't walk into a Best Buy and walk out with an Ubuntu laptop. The is an effort & technical knowledge barrier to it, and that's what I mean when I say it's not currently a practical option for a typical user.

Re: Apple's apps bypass firewalls like LittleSnitch and LuLu on macOS Big Sur

#393
post #104

Earlier quoted context omitted.

What's the alternative for the typical user? Windows has its own problems, and let's face it: market forces on this sort of thing or any other practices by the two of them have not driven people to use desktop Linux instead. For most people, there's simply no reasonable option to switch to that would avoid these things or employ market forces to get these companies to change their ways.

I'm not a "typical" user so i dont care.

Then you have provided a solution that is not generalizable. Which is fine, but not particularly useful to this conversation.

Re: Apple's apps bypass firewalls like LittleSnitch and LuLu on macOS Big Sur

#394

For anyone that wants to switch to Linux and retain similar functionality as this firewall app, there is this: https://github.com/gustavo-iniguez-goya/opensnitch

There is another - and I'd argue better - alternative for Linux and Windows:

Portmaster by Safing https://safing.io/portmaster/

Not only is it an application firewall, but also gives you DNS filtering (ie. Pi-Hole basics) and DNS-over-TLS.

Full Disclosure: I'm one of the founders.

Re: Apple's apps bypass firewalls like LittleSnitch and LuLu on macOS Big Sur

#395

Earlier quoted context omitted.

Additionally charging on the left side ports makes the T2 chip overheat and crashes the machine on occasion.

REALLY? Okay, I'm going to test this. I noticed odd hangings and cpu hitting high temps on a MBP 2018' w/ dell usb C dock on left side, meanwhile right side is fine but I had to reboot randomly and sometimes it will just crash. And this is a MBP on a laptop stand.

Yes it was with specific models, but it's got nothing to do with the T2 chip. https://apple.stackexchange.com/questions/363337/how-to-find...

Re: Apple's apps bypass firewalls like LittleSnitch and LuLu on macOS Big Sur

#396
post #3

A great example of why you need defense in depth. Ideally you'd be running the local firewall on your box, as well as an external firewall. That being said, this is not ok behavior on Apple's part. There shouldn't be a way for traffic to go around the firewall like this, even if it is just Apple apps. Because as Apple well knows, once you make a backdoor, someone will figure out a way to exploit it.

If you're on a laptop, you won't necessarily always be able to filter on the router level.

Of course not, which is why this still isn't very cool. If you're super paranoid you can always carry around a small router or a pi to attach to the wifi and be your external router though.

Re: Apple's apps bypass firewalls like LittleSnitch and LuLu on macOS Big Sur

#398
post #312

Earlier quoted context omitted.

Where are these weird anti-FOSS statements being bred from? > Those who pay set the agenda for everything. And this different from non FOSS software how? > Developing a truly polished operating system with a whole ecosystem of services is far, far beyond what volunteers and hobbyists can achieve. As someone who uses Linux as my primary workstation I disagree. My coworkers that use Mac or Windows seem to have about th…

I crap on FOSS a bit because I like it and wish it got more traction in the mainstream. I intend it as constructive criticism. I've been a FOSS user and sometimes contributor since 1994 when I installed Linux with floppy disks, and have consistently watched FOSS lose the mainstream because they don't grasp the critical importance of UI/UX. I want to write "it has to just work" on a sledgehammer and bash people about…

Is it really a goal of most FOSS projects to attract the mainstream? IME some of the highest-quality and longest lived projects know who their users are and provide an extremely high quality product.

I don't want to see Arch Linux, for example, to start prioritizing for attracting non-technical users who want it to "just work."

Re: Apple's apps bypass firewalls like LittleSnitch and LuLu on macOS Big Sur

#399
post #324

Earlier quoted context omitted.

Linux on the desktop and Linux on the laptop (heh) has definitely improved. It _sometimes_ needs a little tweaking to get it right, but KDE/Plasma also happens to offer that level of "tweakability" that should satisfy almost all semi-mainstream users (at least anyone coming from Windows or Mac). Compared to my first Linux laptop (a Sony Vaio circa 2000), my current XPS 13 works as well as any Mac laptop I have ever o…

Is there a 'little snitch' for desktop linux with the speed of it's UI in setting networking rules?

We are working on an alternative for both Linux and Windows: https://safing.io/portmaster/

Not only is it an application firewall, but also gives you DNS filtering (ie. Pi-Hole basics) and DNS-over-TLS.

Not sure what you mean with "the speed of it's UI ..." though.

Re: Apple's apps bypass firewalls like LittleSnitch and LuLu on macOS Big Sur

#400
post #18
post #6

This is one of those tough cases where software cuts both ways. Some people are smart, informed developers that install a trusted tool to monitor their traffic and have legitimate reasons to want to inspect Apple traffic. They're dismayed. Most people are the opposite and this move protects the most sensitive data from being easily scooped up or muddled in easily installed apps, or at least easily installed apps that…

I'd argue this opens up a giant attack surface where malicious software will try to route its command and control communication through a protected service. Do we really want to trust that Apple will keep all 50+ of these privileged services fully protected? I think it makes the "world" slightly worse in that it will be harder to discover malware. Little snitch has a small user base, but it's been used to identify ma…

The decision is questionable, but you can always inspect traffic from the machine outside it, I would even say that's preferable in context of malware.
Post reply on HN