Live data from Hacker News

Apple's apps bypass firewalls like LittleSnitch and LuLu on macOS Big Sur

twitter.com

401–410 of 649 posts

Re: Apple's apps bypass firewalls like LittleSnitch and LuLu on macOS Big Sur

#401
post #6

This is one of those tough cases where software cuts both ways. Some people are smart, informed developers that install a trusted tool to monitor their traffic and have legitimate reasons to want to inspect Apple traffic. They're dismayed. Most people are the opposite and this move protects the most sensitive data from being easily scooped up or muddled in easily installed apps, or at least easily installed apps that…

> I trust Apple, but I don't like trusting trust.

Trust relies on faith or evidence, the overwhelming circumstantial evidence is that Apple can not be trusted with anything other than their commercial interests.

You can not trust Apple with anything else, therefore you must have faith.

Re: Apple's apps bypass firewalls like LittleSnitch and LuLu on macOS Big Sur

#402
post #286
post #254

Earlier quoted context omitted.

Huh? When I’m out socializing there’s no spying to do. But as soon as I get back I will just log in and the spying begins. I’m so accustomed to flaky peripherals with Apple products I wouldn’t even be alarmed at the behavior.

I think you misunderstand. The idea is that if your keyboard is replaced with a keyboard that has modified (hacked) firmware, your computer will refuse to let you use it. To do this, it must obtain a cryptographic attestation from the keyboard firmware, proving that it has not been modified. Further, to avoid replay attacks it must include the current time in the message it signs. NTP is used by macOS to determine th…

What happens if you have networking turned off or your WiFi isn't configured for the local network?

Re: Apple's apps bypass firewalls like LittleSnitch and LuLu on macOS Big Sur

#403

Earlier quoted context omitted.

I try the major DEs every few years to see if they fit me, most recently trying the newest KDE and GNOME versions in a VM about a month ago. Both have improved for sure, but they still have a long way to go… GNOME actually came closest but its customizability level is even lower than that of macOS, even factoring in extensions. Both suffer from a laundry list of minor annoyances that snowball into something that's ha…

Tried PopOS from System76 recently? It's IMHO the current best user experience of Gnome.

I have, in fact I had it installed directly on one of my towers a few months ago to make sure that no weird VM shenanigans were futzing things up.

It was one of the smoother GNOME distros, and its installer was far more competent than Ubuntu's (mainly, it didn't screw with the boot partitions of every drive in the system like Ubuntu's installer did). Ultimately though, GNOME itself is flawed in its approach to a few things.

Re: Apple's apps bypass firewalls like LittleSnitch and LuLu on macOS Big Sur

#404

Background: I've written my own kernel extension that works in similar manner to Little Snitch, but does a lot more, including SSL MITM and on-demand packet capture, that I've been using for more than 10 years now. It's a fact that Apple has continuously moved to lock down macOS in ways that are antithetical to folks that want full control over their operating system. To many of us that moved on from Linux on the des…

> I've written my own kernel extension that works in similar manner to Little Snitch, but does a lot more, including SSL MITM and on-demand packet capture, that I've been using for more than 10 years now. I'd be interested to read more about this, and maybe even use your kext. I'm currently MITM'ing all of my SSL traffic[1] for a different, esoteric reason: I insist on using a 7-year-old version of macOS, and it does…

> I'd be interested to read more about this

Yeah, me too!

Re: Apple's apps bypass firewalls like LittleSnitch and LuLu on macOS Big Sur

#405
post #13

Earlier quoted context omitted.

If I install Little Snitch, it's because I trust Little Snitch to be responsible for my computer's network traffic, over and above anyone else. I recognize that this won't necessarily apply to all users or all apps, but there needs to be a way for the user to designate trust. Apple services and traffic should not get special treatment.

They provide the OS. If you don't trust them, then you shouldn't trust anything running on top of it either...

> If you don't trust them, then you shouldn't trust anything running on top of it either...

You start with trust, if you attempt to verify that trust by examining behaviour and discover a covert side channel surely you can no longer trust.

Re: Apple's apps bypass firewalls like LittleSnitch and LuLu on macOS Big Sur

#406
post #193

Earlier quoted context omitted.

What is it about Adobe software that makes it only work on Windows or macOS? Both of their graphics engines are totally different, so what makes it so difficult for Linux compatibility? It's the only software package that keeps me beholden to Apple (I'll never run Windows of my own decision).

I have an aging MacBook Air (works great for 99% of the things I want to do), an aging iPad Pro, and an iPhone XR. I probably am in the market to replace them in that order. I just bought my son a Lenovo laptop because he needed Windows. I'm dismayed at where Apple is going, so I'm considering a Dell Linux laptop as my daily driver. I need to do some video editing, so for a while I'll use my son's laptop, and possibl…

I'm in the same boat, just more from a Photography standpoint. Oldest Mac I own is a 2012 MBP and I really do not see any appeal in any of the newer machines. I built myself fairly high end Mini ITX Windows machine for a fraction of what a comparable Mac would cost. Only downside is having a somewhat bigger PC on my desk.

For video editing I was very surprised at how quickly I picked up / understood the Free version of Davinci Resolve after looking for a Final Cut replacement for my gaming PC.

Re: Apple's apps bypass firewalls like LittleSnitch and LuLu on macOS Big Sur

#408

Earlier quoted context omitted.

I installed GNU/Linux for my relatives and it's been working fine for years. So I would say GNU/Linux is a perfect alternative for typical users.

The key thing there is that you installed the OS. You're saying there's little difficulty in using the OS, but that isn't what I mean when I say it's not a practical option. The core problem is that the average person doesn't know how and wouldn't be comfortable taking that step, even if it's pretty easy once you know how. You have also made yourself their support person. They can't bring their computer to Best Buy o…

https://news.ycombinator.com/item?id=24840166

Re: Apple's apps bypass firewalls like LittleSnitch and LuLu on macOS Big Sur

#409
post #13

Earlier quoted context omitted.

If I install Little Snitch, it's because I trust Little Snitch to be responsible for my computer's network traffic, over and above anyone else. I recognize that this won't necessarily apply to all users or all apps, but there needs to be a way for the user to designate trust. Apple services and traffic should not get special treatment.

They provide the OS. If you don't trust them, then you shouldn't trust anything running on top of it either...

It's not about trust that they aren't doing something malicious, it's about trusting them to provide the level of attention and work required to keep something very secure.

A kernel and the core OS capabilities are a high security domain and I expect Apple to be extremely careful and put a lot of attention into making it secure. Desktop applications are a different domain where security is not quite at the same level and Apple will not and can not provide the same level of security for all of them that it can and does provide for the base OS.

As a simple example, compare Safari and the OS. The domains in which they operate make it extremely hard, if not impossible, for Safari to have the same level of security as the OS and kernel because the use case of Safari opens it to far more attack vectors.

Does anyone believe that exempting all Safari traffic from firewalls would be a good idea? If not, then why should we accept that it's a good idea for some arbitrarily set of other Apple applications?

The issue here is simple, it's the same as it always is with Apple. There's a choice to do the thing that's slightly more complex and requires users to provide even a minimal amount of input that they might have to think about ("An application is attempting to change the traffic flow required by X service, if you allow this it may cause problems with this service. Yes/No?"), but instead they opt for "Users must trust us implicitly and entirely in everything we do", which is their go-to solution. It all comes back to control, does Apple control the user, or the the user control their software? Apple has built their empire around the former, so while we can't expect the latter without if being forced on them, that doesn't mean we shouldn't.

Re: Apple's apps bypass firewalls like LittleSnitch and LuLu on macOS Big Sur

#410
post #400
post #18

Earlier quoted context omitted.

I'd argue this opens up a giant attack surface where malicious software will try to route its command and control communication through a protected service. Do we really want to trust that Apple will keep all 50+ of these privileged services fully protected? I think it makes the "world" slightly worse in that it will be harder to discover malware. Little snitch has a small user base, but it's been used to identify ma…

The decision is questionable, but you can always inspect traffic from the machine outside it, I would even say that's preferable in context of malware.

Can you recommend a portable wifi firewall? Based on Raspberry Pi, perhaps?
Post reply on HN