Live data from Hacker News

Apple's apps bypass firewalls like LittleSnitch and LuLu on macOS Big Sur

twitter.com

481–490 of 649 posts

Re: Apple's apps bypass firewalls like LittleSnitch and LuLu on macOS Big Sur

#481
post #278
post #233

Earlier quoted context omitted.

I find it interesting how the needs of legitimate security mesh so well with the industry desires to kill off general-purpose computing for the majority of users

I mean the irony is when it comes to browsers you see the general tone of HN shift to the opposite opinion when it comes to features like, RTC, USB, Bluetooth, Filesystem Access. These are all features that give users more power but it's (apparently) easier to see the downsides and how these features can and are used maliciously. Now put yourself in the Apple's position where "an iOS app" or a "mac App" is about as t…

> Can you imagine if websites could control your firewall?

Oh, they can. Cross-site scripting and request-forgery attacks aren't dead yet thanks to widespread terrible security practices :)

Re: Apple's apps bypass firewalls like LittleSnitch and LuLu on macOS Big Sur

#482
post #18
post #6

This is one of those tough cases where software cuts both ways. Some people are smart, informed developers that install a trusted tool to monitor their traffic and have legitimate reasons to want to inspect Apple traffic. They're dismayed. Most people are the opposite and this move protects the most sensitive data from being easily scooped up or muddled in easily installed apps, or at least easily installed apps that…

I'd argue this opens up a giant attack surface where malicious software will try to route its command and control communication through a protected service. Do we really want to trust that Apple will keep all 50+ of these privileged services fully protected? I think it makes the "world" slightly worse in that it will be harder to discover malware. Little snitch has a small user base, but it's been used to identify ma…

I think this is the case where you can have traffic monitoring set-up on your home router or any other network gateway available. It will be slightly more troublesome, but not impossible.

Re: Apple's apps bypass firewalls like LittleSnitch and LuLu on macOS Big Sur

#483

Earlier quoted context omitted.

Apple's authoritarian control-freak mentality has been around since the original Macintosh of the 80s. It was only a coincidence that moving to x86 opened up some freedom. Now it's just moving in the same direction Apple always was.

I'm not entirely sure what's leading you to this conclusion. The original Macintosh had no privileges system and let apps write to random bits of memory. It was quite problematic for multitasking, in fact.

The original Macintosh had no privileges system and let apps write to random bits of memory

Neither did the PCs of the time, but the difference becomes obvious when you actually try to write an app: PC magazines were filled with BASIC and Asm listings (to be entered with DEBUG), both of which could be immediately used on an IBM PC with DOS, whereas to even start creating --- or for that matter, modifying --- software for the Macintosh was pretty much a non-starter for everyone who didn't want to actually invest plenty of $$$ in it.

Documentation on the system details is barely available (there's Inside Macintosh, but that pales in comparison to the IBM PC Technical Reference series --- the latter including full BIOS source code and schematics, even for the monitor and hard drive), and of course the PC was far more expandable. Apple wanted the whole stack locked down from the beginning.

Re: Apple's apps bypass firewalls like LittleSnitch and LuLu on macOS Big Sur

#484
post #438

Earlier quoted context omitted.

I can't speak about 5 years ago, but I was using Little Snitch with VMWare last year, and it worked. I had to specifically allow the VMWare process.

Guest traffic was visible when the VM was in NAT mode, but when switched to Bridged mode traffic went straight through with LS unaware. I suppose LS was only sniffing the standard adapters, though this could have been improved since.

I was only trialing VMWare before, so unfortunately I can't test this anymore.

Re: Apple's apps bypass firewalls like LittleSnitch and LuLu on macOS Big Sur

#485
post #479

Earlier quoted context omitted.

> Further, to avoid replay attacks it must include the current time in the message it signs. Use a counter...?

I'm not trying to defend Apple here, just explain the mechanism to the parent.

Oh, okay. You said "must" so I was wondering if there was another important factor.

Re: Apple's apps bypass firewalls like LittleSnitch and LuLu on macOS Big Sur

#486
post #421
post #412

Earlier quoted context omitted.

>hiding URLs does protect users from phishing Real question: how? I would expect it to be the opposite, a perfect phishing site will have the wrong URL.

Because it's not really "hiding the URL" despite what all the outrage bloggers tried to make it seem. It's by default (i.e. until you tap/click it) hiding the parts of the URL that the site controls. So paypal.amazon.citibank.scamsite.biz/secure/login/trustus will just show scamsite.biz.

[deleted]

Re: Apple's apps bypass firewalls like LittleSnitch and LuLu on macOS Big Sur

#487
post #484

Earlier quoted context omitted.

Guest traffic was visible when the VM was in NAT mode, but when switched to Bridged mode traffic went straight through with LS unaware. I suppose LS was only sniffing the standard adapters, though this could have been improved since.

I was only trialing VMWare before, so unfortunately I can't test this anymore.

Heads up that VMWare Fusion has a free version on Mac as of this month. :)

Re: Apple's apps bypass firewalls like LittleSnitch and LuLu on macOS Big Sur

#488
post #421
post #412

Earlier quoted context omitted.

>hiding URLs does protect users from phishing Real question: how? I would expect it to be the opposite, a perfect phishing site will have the wrong URL.

Because it's not really "hiding the URL" despite what all the outrage bloggers tried to make it seem. It's by default (i.e. until you tap/click it) hiding the parts of the URL that the site controls. So paypal.amazon.citibank.scamsite.biz/secure/login/trustus will just show scamsite.biz.

My first instinct was to distrust the hide-until-click URL bar also, but you've illustrated clearly why it's a reasonable default. It mitigates the effect of malicious websites playing URL games, and allows the browser to more accurately convey to the user where they really are.

Re: Apple's apps bypass firewalls like LittleSnitch and LuLu on macOS Big Sur

#489
post #438

Earlier quoted context omitted.

I can't speak about 5 years ago, but I was using Little Snitch with VMWare last year, and it worked. I had to specifically allow the VMWare process.

Guest traffic was visible when the VM was in NAT mode, but when switched to Bridged mode traffic went straight through with LS unaware. I suppose LS was only sniffing the standard adapters, though this could have been improved since.

That's likely because VMWare Workstation's bridge mode likely injects into the networking stack at the same point that Little Snitch does.

Re: Apple's apps bypass firewalls like LittleSnitch and LuLu on macOS Big Sur

#490
post #421
post #412

Earlier quoted context omitted.

>hiding URLs does protect users from phishing Real question: how? I would expect it to be the opposite, a perfect phishing site will have the wrong URL.

Because it's not really "hiding the URL" despite what all the outrage bloggers tried to make it seem. It's by default (i.e. until you tap/click it) hiding the parts of the URL that the site controls. So paypal.amazon.citibank.scamsite.biz/secure/login/trustus will just show scamsite.biz.

To drive your point home, paypal.amazon.citibank.scamsite.biz/secure/login/trustus will likely have a perfectly valid certificate, along with the trusted green closed-lock before the URL, implying that the site is "secure".
Post reply on HN