Live data from Hacker News

Apple's apps bypass firewalls like LittleSnitch and LuLu on macOS Big Sur

twitter.com

541–550 of 649 posts

Re: Apple's apps bypass firewalls like LittleSnitch and LuLu on macOS Big Sur

#541
post #13

Earlier quoted context omitted.

If I install Little Snitch, it's because I trust Little Snitch to be responsible for my computer's network traffic, over and above anyone else. I recognize that this won't necessarily apply to all users or all apps, but there needs to be a way for the user to designate trust. Apple services and traffic should not get special treatment.

They provide the OS. If you don't trust them, then you shouldn't trust anything running on top of it either...

Microsoft makes an OS too. And to use it I have to spend an enormous amount of time turning off all its daemons that phone home, harvest my personal information, show me ads, and force updates on me.

So no, I don't trust OS providers. I tolerate them and defend myself against them.

Re: Apple's apps bypass firewalls like LittleSnitch and LuLu on macOS Big Sur

#542
post #502
post #13

Earlier quoted context omitted.

They provide the OS. If you don't trust them, then you shouldn't trust anything running on top of it either...

That's the exactly the thing - they are, indeed, chasing me off. When this Mac dies, I'll be replacing it with something running Debian. It is too bad - the Mac hit this sweet-spot where it was pretty much my perfect machine for several years - a kickass Unix workstation in a decently built laptop, with a decent GUI, with access to consumer apps, too. It was great while it lasted. Thing is, this is a reasonable thing…

I disagree that it's reasonableness except in the short term. We're seeing a change in developers' opinions; my friends in video production were getting ready to ditch Apple due to their "professional" software and hardware products getting worse both in relative (hardware) and absolute (software) terms. Part of the Apple cachet is that these are professional tools; how long is their reputation going to hold up if those professionals leave the platform?

It's a touch of hubris to think that we are and will continue to be taste makers, certainly. Maybe Apple won't get burned by alienating this crowd. But it seems a risky strategy for dubious return.

Re: Apple's apps bypass firewalls like LittleSnitch and LuLu on macOS Big Sur

#543
Does anyone know how this actually works, technically?

Are these apps using some kind of special API? (If yes, what's to stop other people's apps using that API?)

Is it because they are signed with some kind of special entitlement?

Is it due to some combination of both? (Maybe you have to use some magic API, but you need to be signed with some magic entitlement to be allowed to use it?)

Re: Apple's apps bypass firewalls like LittleSnitch and LuLu on macOS Big Sur

#544

Earlier quoted context omitted.

Same experience. I tried, but Linux just isn’t ready to be used as a general OS right now. I’ve dug through message boards and bug reports, and a lot of the features that MacOS has will never be implemented. I’m taking about features released 13+ years ago on OS X 10.4.

> a lot of the features that MacOS has will never be implemented Care to name any? Other times I’ve heard things like this on HN I’ve been able to locate them.

A big one I will sorely miss as I transition to Linux (and it's the only one I can think of right now), is the ability to rename and move around files while they are open!

OK here's another, very related: the ability to have apps remember their open files when you quit and re-open them.

These are significant productivity boosters, and I will miss them. It's definitely a trade-off, but now Apple has tipped the scales too much in favour of Linux...for me.

Re: Apple's apps bypass firewalls like LittleSnitch and LuLu on macOS Big Sur

#545
post #361
post #6

This is one of those tough cases where software cuts both ways. Some people are smart, informed developers that install a trusted tool to monitor their traffic and have legitimate reasons to want to inspect Apple traffic. They're dismayed. Most people are the opposite and this move protects the most sensitive data from being easily scooped up or muddled in easily installed apps, or at least easily installed apps that…

Who cares about the world.. I just want full access to the system I paid for. This should always remain an option.

Depending on your definition of "full access", you probably haven't truly had that for decades—on any broadly available computing system at least.

Re: Apple's apps bypass firewalls like LittleSnitch and LuLu on macOS Big Sur

#546
post #374

Earlier quoted context omitted.

One of the value props was the inability to reset and resell if it were lost or stolen. Now that it’s cracked there is more of an incentive to not try and find the owner. As for actual data security you are probably right

Is the crack in hardware or software? Any links on it? I thought the iPhones at least could not be reset by thieves?

Every device up to the iphone X has been cracked btw so the factory reset protection can be bypassed.

Re: Apple's apps bypass firewalls like LittleSnitch and LuLu on macOS Big Sur

#547
post #226

Earlier quoted context omitted.

T2 is a nightmare for people who want to reinstall. I reinstalled a machine for someone and it was a mess of 2fa and other nonsense.

Yeah if you want to wipe a laptop, make sure you unlink your user account first. It's Apple's theft protection, same as with their phones. It'll want to see a successful login with the Apple ID.

This is the worst. So many people seem to forget their apple ID password but remember their screen unlock password. I saw a case recently where someone had an attacker get access to their apple account as well as everything else. I was able to do a fresh install of their windows laptop but I was unable to reset the persons iphone because the attacker had changed the apple id password.

I have also seen many android devices bricked by the same anti theft protections.

Re: Apple's apps bypass firewalls like LittleSnitch and LuLu on macOS Big Sur

#548
post #424

Earlier quoted context omitted.

> Third, I set my recursive resolver to use the nextdns.io endpoint as its upstream source of DNS. Doesn't that relegate your recursive resolver to a stub? You could run pi-hole on fly.io for free if DoT/DoH is all you need: https://fly.io/blog/stuff-your-pi-hole-from-anywhere/ I run a public DoH resolver with 170+ blocklists on Cloudflare Workers. Might open source it soon.

Nice. Do you have any more info on that resolver of yours?

[deleted]

Re: Apple's apps bypass firewalls like LittleSnitch and LuLu on macOS Big Sur

#549

Earlier quoted context omitted.

One of the value props was the inability to reset and resell if it were lost or stolen. Now that it’s cracked there is more of an incentive to not try and find the owner. As for actual data security you are probably right

> One of the value props was the inability to reset and resell if it were lost or stolen. It's sure one of those nice to have features, but there's no good reason why it has to be mandatory like it is. All in all, having a device purposefully retain some information when you factory reset it is user-hostile. The "lost or stolen" argument also hardly holds for desktop computers like Mac Pro or Mac Mini or iMac, yet th…

> The "lost or stolen" argument also hardly holds for desktop computers

Why ? People's houses get broken into all the time.

And probably 99.999% of laptops never leave a person's house.

Re: Apple's apps bypass firewalls like LittleSnitch and LuLu on macOS Big Sur

#550

Earlier quoted context omitted.

Bottom line is that Apple made software like Little Snitch switch away from kexts and then built in behavior that was unexpected, which would not have been possible for them to do while Little Snitch was based on kexts. Whether this is malicious, not malicious, secure, insecure etc. is irrelevant to whether this is an untrustworthy action. It’s not what one would reasonably expect and is therefore a betrayal of users…

>is therefore a betrayal of users’ trust. I would disagree with that statement. The user bought an Apple computer so they clearly trust Apple already. If anything, the new frameworks make the system more secure which strengthens that trust for users. The only people really affected by this change are users who want granular control over everything whether it comes from Apple or not.

This conflating of purchasing with trusting is harmful. It's an ongoing trend I've seen with large tech companies, with arguments of the form "You accept a tiny X, therefore your rejection of the giant Y is invalid."

We buy things from companies we don't implicitly trust all the time, because we can isolate and verify those things.

I don't always trust the supermarket to sell me non-moldy produce, but I can look at the produce and see whether it's moldy.

I don't trust oil companies not to destroy the environment, but if they sell me bad fuel it will be very clear.

I don't trust OS makers, but I can run firewalls and network sniffers to verify that the OS is behaving reasonably, and isolate it when it isn't. Until I can't.

Post reply on HN