Live data from Hacker News

Apple's apps bypass firewalls like LittleSnitch and LuLu on macOS Big Sur

twitter.com

41–50 of 649 posts

Re: Apple's apps bypass firewalls like LittleSnitch and LuLu on macOS Big Sur

#41
post #39
post #21

Apple seems to do all kinds of weird networking _stuff_. For instance, during wakeup, your T2 equipped Macbook will wait for a DNS response and then use said DNS response to synchronize time via NTP before letting the user use the keyboard. Probably checking timestamps on signatures for the keyboard firmware, or something stupid like that. This only happens if it happens to have a default route. Similarly, all macOS…

> wait for a DNS response and then use said DNS response to synchronize time via NTP before letting the user use the keyboard ... and what if your network is down? You can't even use your keyboard?

I should've clarified - it only does this if there is a default route. Funnily enough, whilst the firewalls in the original twitter post would possibly fail to catch this traffic, PF will block it just fine.

Re: Apple's apps bypass firewalls like LittleSnitch and LuLu on macOS Big Sur

#42
Background: I've written my own kernel extension that works in similar manner to Little Snitch, but does a lot more, including SSL MITM and on-demand packet capture, that I've been using for more than 10 years now.

It's a fact that Apple has continuously moved to lock down macOS in ways that are antithetical to folks that want full control over their operating system. To many of us that moved on from Linux on the desktop, the combination of a stable/uniform/attractive desktop environment with a Unix core that had great developer documentation -no longer the case!- and nicely-designed APIs was too much to resist. Unfortunately, the push towards consumers and Apple's increasingly one-sided my-way-or-the-highway approach (fueled by security concerns that to me are completely irrelevant, if not a huge annoyance and waste of time) means that a lot of us oldschool Unix hackers were left out in the cold.

I don't plan to upgrade past Mojave and at some point in the future I will move back to Linux.

Re: Apple's apps bypass firewalls like LittleSnitch and LuLu on macOS Big Sur

#43

"You don't need kernel extensions, we'll provide APIs for you! We won't abuse the power that gives us, promise!" ...and now Apple has altered the deal and we must pray they do not alter it further. Disgusting. Predictable, expected, unsurprising -- but still disgusting.

Apple have never made such claim. In fact, if you read their ToS, it discloses all the information you're classifying as "disgusting".

Re: Apple's apps bypass firewalls like LittleSnitch and LuLu on macOS Big Sur

#44
post #33
post #6

This is one of those tough cases where software cuts both ways. Some people are smart, informed developers that install a trusted tool to monitor their traffic and have legitimate reasons to want to inspect Apple traffic. They're dismayed. Most people are the opposite and this move protects the most sensitive data from being easily scooped up or muddled in easily installed apps, or at least easily installed apps that…

Tech savvy users are not just the minority. They're also cheap. They've been conditioned by the FOSS movement to think all software should be free as-in-beer. (The people who started FOSS didn't say that, but that's what it's become.) They say they want free as-in-freedom, but since they are not willing to pay for it they don't exist. Those who pay set the agenda for everything. Developing a truly polished operating…

> They say they want free as-in-freedom, but since they are not willing to pay for it they don't exist. Only paying users matter.

Citation needed. If you look at app store pricing models the opposite seems true. If I were going to take a random guess I would say that tech savvy users use open source software to avoid anti-consumer bullshit more than anything else.

Re: Apple's apps bypass firewalls like LittleSnitch and LuLu on macOS Big Sur

#45
post #21

Apple seems to do all kinds of weird networking _stuff_. For instance, during wakeup, your T2 equipped Macbook will wait for a DNS response and then use said DNS response to synchronize time via NTP before letting the user use the keyboard. Probably checking timestamps on signatures for the keyboard firmware, or something stupid like that. This only happens if it happens to have a default route. Similarly, all macOS…

Oh wow! This probably explains why every now and then when I wake my MacBook Pro from sleep it says no keyboard is connected! I thought I had some hardware problem on a basically brand new machine. Glad to hear it's only a stupid software problem!

If you're using Cisco Anyconnect, blame that for that particular keyboard issue.

Re: Apple's apps bypass firewalls like LittleSnitch and LuLu on macOS Big Sur

#46
post #12
post #9

The solution is simple, just look at the tricks these apps are using and use them to implement malware.

I bet they have feature flags that are signed and validated by Apple. You wouldn’t be able to run your app without their approval (which they won’t give).

Yep. I think people need to get past the idea that they own their iPhone or Mac. Apple does, they just let you use it.

Re: Apple's apps bypass firewalls like LittleSnitch and LuLu on macOS Big Sur

#47
post #21

Apple seems to do all kinds of weird networking _stuff_. For instance, during wakeup, your T2 equipped Macbook will wait for a DNS response and then use said DNS response to synchronize time via NTP before letting the user use the keyboard. Probably checking timestamps on signatures for the keyboard firmware, or something stupid like that. This only happens if it happens to have a default route. Similarly, all macOS…

Holy cow, you just explained a load of weird keyboard behavior I was seeing after waking from sleep.

Re: Apple's apps bypass firewalls like LittleSnitch and LuLu on macOS Big Sur

#48
post #41
post #39

Earlier quoted context omitted.

> wait for a DNS response and then use said DNS response to synchronize time via NTP before letting the user use the keyboard ... and what if your network is down? You can't even use your keyboard?

I should've clarified - it only does this if there is a default route. Funnily enough, whilst the firewalls in the original twitter post would possibly fail to catch this traffic, PF will block it just fine.

Having a default route does not mean the internet is reachable.

Re: Apple's apps bypass firewalls like LittleSnitch and LuLu on macOS Big Sur

#49
post #28

"You don't need kernel extensions, we'll provide APIs for you! We won't abuse the power that gives us, promise!" ...and now Apple has altered the deal and we must pray they do not alter it further. Disgusting. Predictable, expected, unsurprising -- but still disgusting.

Dont pray, just dont buy Apple Products

The alternative is what? System76 makes a decent laptop but they don’t have a repair center in every major city. I buy Apple computers because of the hardware support and integration with iPhone.

Speaking of iPhone, the open options are at best abysmal for privacy (at least orders of magnitudes worse than Apple) and at worst part of planned obsolescence that creates e-waste much faster than Apple devices.

Fun fact, at least for now, you can still buy a Mac and boot Linux. Probably not true once Apple silicon hits but that’s a sad day for anyone who liked boot camp.

Re: Apple's apps bypass firewalls like LittleSnitch and LuLu on macOS Big Sur

#50
post #21

Apple seems to do all kinds of weird networking _stuff_. For instance, during wakeup, your T2 equipped Macbook will wait for a DNS response and then use said DNS response to synchronize time via NTP before letting the user use the keyboard. Probably checking timestamps on signatures for the keyboard firmware, or something stupid like that. This only happens if it happens to have a default route. Similarly, all macOS…

[deleted]
Post reply on HN