Live data from Hacker News

Apple's apps bypass firewalls like LittleSnitch and LuLu on macOS Big Sur

twitter.com

461–470 of 649 posts

Re: Apple's apps bypass firewalls like LittleSnitch and LuLu on macOS Big Sur

#461
post #6

This is one of those tough cases where software cuts both ways. Some people are smart, informed developers that install a trusted tool to monitor their traffic and have legitimate reasons to want to inspect Apple traffic. They're dismayed. Most people are the opposite and this move protects the most sensitive data from being easily scooped up or muddled in easily installed apps, or at least easily installed apps that…

How is this good?

Either Apple doesn't trust Little Snitch and shouldn't let it interfere with any apps, or Apple does trust Little Snitch and shouldn't block it at all. There's no reason to implement this halfway.

Re: Apple's apps bypass firewalls like LittleSnitch and LuLu on macOS Big Sur

#462
post #13

Earlier quoted context omitted.

If I install Little Snitch, it's because I trust Little Snitch to be responsible for my computer's network traffic, over and above anyone else. I recognize that this won't necessarily apply to all users or all apps, but there needs to be a way for the user to designate trust. Apple services and traffic should not get special treatment.

They provide the OS. If you don't trust them, then you shouldn't trust anything running on top of it either...

Their software could have bugs, or be compromised.

Re: Apple's apps bypass firewalls like LittleSnitch and LuLu on macOS Big Sur

#463
post #32

That totally breaks my use case for Little Snitch: working tethered. When I tether my laptop it thinks it has free reign with the bandwidth and all of the little background processes can kill my data in a few minutes. With a firewall, I can grant access to only the processes that I need to get my work done. Now, I guess I have to run some external firewall between my laptop and my phone. ... or better yet, abandon Ap…

[deleted]

Re: Apple's apps bypass firewalls like LittleSnitch and LuLu on macOS Big Sur

#464
post #32

That totally breaks my use case for Little Snitch: working tethered. When I tether my laptop it thinks it has free reign with the bandwidth and all of the little background processes can kill my data in a few minutes. With a firewall, I can grant access to only the processes that I need to get my work done. Now, I guess I have to run some external firewall between my laptop and my phone. ... or better yet, abandon Ap…

I use Trip Mode for that ( https://tripmode.ch/ ). Though, it's not unlikely it'll have the same issues described in the OP, it does seem to block Apple stuff on Mojave.

I had replied to parent as well, but then saw your note. So I deleted, and pasting my agreement here:

> free reign with the bandwidth and all of the little background processes can kill my data in a few minutes

New: TripMode 3, made for macOS 11 Big Sur. Easily control your Mac's data usage on slow or expensive networks.

Drastically optimize your Mac’s data usage by automatically blocking unwanted background updates. Keep control with the new live monitor and data usage reports. Reveal domains where your apps send your data to. Now with a redesigned, easier than ever UI.

https://tripmode.ch

Re: Apple's apps bypass firewalls like LittleSnitch and LuLu on macOS Big Sur

#465
post #426
post #410

Earlier quoted context omitted.

Can you recommend a portable wifi firewall? Based on Raspberry Pi, perhaps?

saw the GL.iNet+GL-MT300N-V2 recently - have not bought it yet, maybe it's time if it's good

Ah, nice. I've been looking for something with which I can sniff my phone's activity, and that provides all of the keywords. And $20 ain't bad neither.

Re: Apple's apps bypass firewalls like LittleSnitch and LuLu on macOS Big Sur

#466
post #167

Earlier quoted context omitted.

I think the threat model here is that someone might've swapped out your keyboard to one that's spying on you, whilst you're out at a conference enjoying the more social aspects of such gatherings. At the same time, if you were to not be connected to a network, this kind of verification wouldn't do anything.

I don't believe this is ever the case. What happens if you legitimately installed a new keyboard? Will Apple just... prevent you from using it?

Before 2019 if you use the factory standard keyboard Apple will just prevent you from using it (butterfly).

Re: Apple's apps bypass firewalls like LittleSnitch and LuLu on macOS Big Sur

#467
post #21

Apple seems to do all kinds of weird networking _stuff_. For instance, during wakeup, your T2 equipped Macbook will wait for a DNS response and then use said DNS response to synchronize time via NTP before letting the user use the keyboard. Probably checking timestamps on signatures for the keyboard firmware, or something stupid like that. This only happens if it happens to have a default route. Similarly, all macOS…

The keyboard thing is new to me, wow that sucks. The other one sounds like a workaround for captive portals. I think there is some documentation on that wrt Safari and the built in networking, but it was mostly a workaround needed to deal with wifi hotspots that intercept dns until you pay/subscribe, and it causes safari to look hung - so they had to make it clear it wasn’t their browser hanging since it couldn’t mak…

Cool, can you reference some docs or any communication from Apple re the captive portal workarounds?

It feels rather heavy handed as there are ways other systems have worked around this that don't hijack routes.

Re: Apple's apps bypass firewalls like LittleSnitch and LuLu on macOS Big Sur

#468
post #233

Earlier quoted context omitted.

You could (and perhaps would) make the same argument about Intel (for providing the processor) or Broadcom (for providing the wifi chip) or Comcast (for providing internet service). And it's true, all of these parties have the ability to use their positions for nefarious purposes. However, I would like to limit that potential as much as possible, partly by creating a stigma against practices that remove control from…

I find it interesting how the needs of legitimate security mesh so well with the industry desires to kill off general-purpose computing for the majority of users

As a general rule, you want to prevent software from bypassing a user's informed consent. Apple typically does this in one of two ways:

1. Have functionality only accessible through system frameworks, so that the OS can be responsible for prompting for informed consent and granting it to a process. This means that the system itself has to have functionality to prompt for that informed consent in a way that users can understand.

2. Require processes which an application cannot script that are technically complicated enough that users might realize they are pulling off the warranty-voiding stickers. A prime example would be rebooting into recovery mode to turn off system integrity protections via a terminal command.

Both of these wind up getting gated in priority, but such is the priority of their system - limiting the ability of arbitrary software to act as an unrestricted agent of the user so that user security and privacy (as well as device operation like battery life and radio reception) can be protected.

Re: Apple's apps bypass firewalls like LittleSnitch and LuLu on macOS Big Sur

#469
post #6

This is one of those tough cases where software cuts both ways. Some people are smart, informed developers that install a trusted tool to monitor their traffic and have legitimate reasons to want to inspect Apple traffic. They're dismayed. Most people are the opposite and this move protects the most sensitive data from being easily scooped up or muddled in easily installed apps, or at least easily installed apps that…

Why doesn't each individual user have the final say over whether she wants to accept the change or not? There is no option presented to the user:

   [ ] Do not trust Apple, trust only me
You say "Some people are smart, informed developers" but in this case, it appears Apple is treating every user as the same.

I am not a "developer" (nor am I particularly "smart") and yet I monitor traffic to/from computers I own. Maybe some incorrect assumptions are being made about so-called "users". I find it perplexing that any company should be able to prevent me from monitoring traffic to/from computers I own. I own the computers, I pay for the bandwidth. I do not buy Apple computers for the Apple software.

Re: Apple's apps bypass firewalls like LittleSnitch and LuLu on macOS Big Sur

#470
post #334

Earlier quoted context omitted.

Eventually I don't think little snitch will even have apis to access stuff like that in the kernel as a kext as macos updates continue on.

Kexts are used by Apple internally, so I'd be shocked if they were removed from the OS completely. Third party kexts may be deprecated, but as long as SIP can be disabled it will always be possible to load your own.

The networking subsystem that the kernel exposes could be removed however, replaced with one which is neither stable nor publicly documented.
Post reply on HN