Live data from Hacker News

Apple's apps bypass firewalls like LittleSnitch and LuLu on macOS Big Sur

twitter.com

511–520 of 649 posts

Re: Apple's apps bypass firewalls like LittleSnitch and LuLu on macOS Big Sur

#511
post #39
post #21

Apple seems to do all kinds of weird networking _stuff_. For instance, during wakeup, your T2 equipped Macbook will wait for a DNS response and then use said DNS response to synchronize time via NTP before letting the user use the keyboard. Probably checking timestamps on signatures for the keyboard firmware, or something stupid like that. This only happens if it happens to have a default route. Similarly, all macOS…

> wait for a DNS response and then use said DNS response to synchronize time via NTP before letting the user use the keyboard ... and what if your network is down? You can't even use your keyboard?

That is exactly what happens if you use VPN clients.

The machine is basically frozen at login until some timeout hits.

Re: Apple's apps bypass firewalls like LittleSnitch and LuLu on macOS Big Sur

#512
post #18

Earlier quoted context omitted.

I'd argue this opens up a giant attack surface where malicious software will try to route its command and control communication through a protected service. Do we really want to trust that Apple will keep all 50+ of these privileged services fully protected? I think it makes the "world" slightly worse in that it will be harder to discover malware. Little snitch has a small user base, but it's been used to identify ma…

Yes I agree with your first part. There are real drawbacks. But it's like installing a custom HTTPS cert in your OS to inspect potential traffic that malware may use through, say, a Google Doc or Sheet. It's helpful to true professionals dealing with highly sensitive information, but it's ultimately a bigger source of compromise for the vast majority of software users. I don't think there is an easy answer here. That…

If they can circumvent system security for their own purposes (even though I’m sure it wasn’t planned to be that way), then they should be open to circumventing it for our country (by backdoor-ing their encryption), at least that is how I would imagine it will be referenced in the inevitable government lawsuit. What a major screw up Apple!

Re: Apple's apps bypass firewalls like LittleSnitch and LuLu on macOS Big Sur

#514

Earlier quoted context omitted.

> One of the value props was the inability to reset and resell if it were lost or stolen. It's sure one of those nice to have features, but there's no good reason why it has to be mandatory like it is. All in all, having a device purposefully retain some information when you factory reset it is user-hostile. The "lost or stolen" argument also hardly holds for desktop computers like Mac Pro or Mac Mini or iMac, yet th…

It seems like this is a feature designed to shrink the "used" market for Apple products -- and not a user benefiting feature.

But one of the things about Apple products that makes people okay with the exorbitant pricing is the resale value. I thought Apple themselves realized this?

Re: Apple's apps bypass firewalls like LittleSnitch and LuLu on macOS Big Sur

#515

Earlier quoted context omitted.

Linux on the desktop and Linux on the laptop (heh) has definitely improved. It _sometimes_ needs a little tweaking to get it right, but KDE/Plasma also happens to offer that level of "tweakability" that should satisfy almost all semi-mainstream users (at least anyone coming from Windows or Mac). Compared to my first Linux laptop (a Sony Vaio circa 2000), my current XPS 13 works as well as any Mac laptop I have ever o…

I try the major DEs every few years to see if they fit me, most recently trying the newest KDE and GNOME versions in a VM about a month ago. Both have improved for sure, but they still have a long way to go… GNOME actually came closest but its customizability level is even lower than that of macOS, even factoring in extensions. Both suffer from a laundry list of minor annoyances that snowball into something that's ha…

I would suggest looking into MATE or XFCE if you haven't, or even a tiling window manager like i3.

Re: Apple's apps bypass firewalls like LittleSnitch and LuLu on macOS Big Sur

#516

Earlier quoted context omitted.

> any backdoors Apple builds for its own apps Apple hasn't weakened the security of their devices to provide a secret way in, in fact, they made their systems even more robust. The question absolutely is whether Apple can be trusted. Little Snitch works for other apps, just not Apple's apps. The remaining slice of the pie you're arguing for is whether or not we can trust Apple. So what delta in security and trust ove…

Bottom line is that Apple made software like Little Snitch switch away from kexts and then built in behavior that was unexpected, which would not have been possible for them to do while Little Snitch was based on kexts. Whether this is malicious, not malicious, secure, insecure etc. is irrelevant to whether this is an untrustworthy action. It’s not what one would reasonably expect and is therefore a betrayal of users…

>is therefore a betrayal of users’ trust.

I would disagree with that statement. The user bought an Apple computer so they clearly trust Apple already. If anything, the new frameworks make the system more secure which strengthens that trust for users. The only people really affected by this change are users who want granular control over everything whether it comes from Apple or not.

Re: Apple's apps bypass firewalls like LittleSnitch and LuLu on macOS Big Sur

#517

Earlier quoted context omitted.

The linux desktop experience is still quite in a state. I will likely do the same and suffer Linux, but I think many will go back to windows as WSL continues to improve. Apple is going to lose developers.

Try Linux Mint with xfce. Really nice out of the box.

Or MATE on an older laptop. Linux Mint is great!

Re: Apple's apps bypass firewalls like LittleSnitch and LuLu on macOS Big Sur

#518

Earlier quoted context omitted.

As is usual, this is something Stallman had touched upon years ago[1]. [1] https://www.gnu.org/philosophy/can-you-trust.en.html

I've been respecting RMS' argument year by year

I find this article[1] linked by RMS is prescient as well, for something published in 2003.

[1] https://www.cl.cam.ac.uk/~rja14/tcpa-faq.html

Re: Apple's apps bypass firewalls like LittleSnitch and LuLu on macOS Big Sur

#519
post #18

Earlier quoted context omitted.

I'd argue this opens up a giant attack surface where malicious software will try to route its command and control communication through a protected service. Do we really want to trust that Apple will keep all 50+ of these privileged services fully protected? I think it makes the "world" slightly worse in that it will be harder to discover malware. Little snitch has a small user base, but it's been used to identify ma…

Yes I agree with your first part. There are real drawbacks. But it's like installing a custom HTTPS cert in your OS to inspect potential traffic that malware may use through, say, a Google Doc or Sheet. It's helpful to true professionals dealing with highly sensitive information, but it's ultimately a bigger source of compromise for the vast majority of software users. I don't think there is an easy answer here. That…

I helped a friend of mine with her OS X laptop. She had installed something bad and it installed MITM proxy and its own CA and other things to totally own and inspect all of her web browser traffic including SSL. So these features that we find powerful and informative also do have a dark side for more novice users.

Re: Apple's apps bypass firewalls like LittleSnitch and LuLu on macOS Big Sur

#520
post #207

Earlier quoted context omitted.

Not a pi-hole user, but what is the plan for pi-hole once encrypted dns is everywhere? Will it just be dead? I can’t really think of a way for it not to be.

You use your pi-hole as your encrypted DNS provider?

> Not a pi-hole user
Post reply on HN