Live data from Hacker News

Apple's apps bypass firewalls like LittleSnitch and LuLu on macOS Big Sur

twitter.com

551–560 of 649 posts

Re: Apple's apps bypass firewalls like LittleSnitch and LuLu on macOS Big Sur

#551

Earlier quoted context omitted.

Is it really a goal of most FOSS projects to attract the mainstream? IME some of the highest-quality and longest lived projects know who their users are and provide an extremely high quality product. I don't want to see Arch Linux, for example, to start prioritizing for attracting non-technical users who want it to "just work."

Well you should be thankful our predecessors took making things "just work" seriously enough to remove your need to boot using toggle switch sequences.

Oh come on! It is not because I spend most of my life inside a terminal that I don't prefer simple things over complicated ones.

Technical doesn't mean "unnecessarily complicated", it means "rich, expressive and built for users that are willing to spend some time to learn" (at least it should)

Re: Apple's apps bypass firewalls like LittleSnitch and LuLu on macOS Big Sur

#552
post #253
post #78

Earlier quoted context omitted.

> Is the world better or worse due to this change? This is the false shortcut behind any attempt to weaken security. Security makes access harder, therefore let's weaken security to improve access. The fact is that weakening security also makes malicious behavior easier and/or more likely. Changes like this are bad particularly because Apple users pay for a protected walled garden.

What this will do is allow apple to decide what goes in and out of the machine. It's pretty clear what they think - they allow basically any app to access the network on ios.

Local network access is a separate permission since iOS 14. I’m not sure whether that is for scanning or multicast only (e.g. finding devices such as Chromecast) or complete access to anything other that the gateway and dns servers.

Re: Apple's apps bypass firewalls like LittleSnitch and LuLu on macOS Big Sur

#553
post #512

Earlier quoted context omitted.

Yes I agree with your first part. There are real drawbacks. But it's like installing a custom HTTPS cert in your OS to inspect potential traffic that malware may use through, say, a Google Doc or Sheet. It's helpful to true professionals dealing with highly sensitive information, but it's ultimately a bigger source of compromise for the vast majority of software users. I don't think there is an easy answer here. That…

If they can circumvent system security for their own purposes (even though I’m sure it wasn’t planned to be that way), then they should be open to circumventing it for our country (by backdoor-ing their encryption), at least that is how I would imagine it will be referenced in the inevitable government lawsuit. What a major screw up Apple!

How dare the guy with over 40 years on the job think such things! (What, are there like under 500 of us left?) Downvote him into retirement!! (what’s that? He STILL isn’t old enough to use the senior menu at IHop? Omg he might know something about Apple he didn’t read on a blog post!)

Point being that people who actually need their reputation on here in order to maintain employment are fully suppressed, which means the commenters are following each other “in a circle” trying to maintain their popularity contest. Sadly, that means HackerNews is mainly for entertainment and judging popularity only. (I’m obviously here for the entertainment rofl)

Re: Apple's apps bypass firewalls like LittleSnitch and LuLu on macOS Big Sur

#554
post #172

Earlier quoted context omitted.

Jobs' Apple created technologies which have rooted deeply in POSIX standards and standard UNIX* conventions. If you knew UNIX(Linux/BSD/whatever), you can find the same data streams on the same places. OS was obscure but, predictable. Different but, familiar. It had kernel extensions, logs and devices. Nothing was extremely obfuscated. It was a UNIX device but, shinier . Now it feels like a glorified iOS box with mor…

I intend this with kindness: normally I don’t nitpick on grammar and punctuation, but you’ve got a repeated error here that’s easily corrected. Generally, you want to break your sentences with commas _before_ usage of “but”: “He wanted to buy a pen, but the store had run out.” If you’re a native speaker, the comma goes where you’d naturally have a brief pause in speech. If you’re not a native speaker, it may be helpf…

Hey, thanks for your comment. There are no hard feelings and I really appreciate that. I'm not a native speaker but, I try to write and talk as correctly as possible.

I used to put commas before, however some grammar checking tools like grammarly marked them as wrong, and I changed my ways.

Comma rules are complex in both in my native language and English and a good, definitive guide would be really helpful.

Thanks for your comment again.

Re: Apple's apps bypass firewalls like LittleSnitch and LuLu on macOS Big Sur

#555
post #493
post #400

Earlier quoted context omitted.

The decision is questionable, but you can always inspect traffic from the machine outside it, I would even say that's preferable in context of malware.

TLS makes this difficult today and SNI encryption will make this next to impossible without installing a custom ca certificate and doing MITM. Even that isn't helpful when you are using a laptop that may not always be on the network where you have deployed a device for inspection. Better to be able to inspect or block on the device by application.

I would be astonished if Apple doesn't at least experiment with key pinning for the services it has decided to "protect" in this way.

If pinning is used then you can't interfere by interposing a middlebox, the connection would just fail. I guess it's possible Apple would find corporate pushback is too strong, but maybe not.

Don't use things you don't trust. If you trust Apple's proprietary software at least you are getting exactly what you signed up for. Apple gets to do whatever they want, which you apparently trust them to do. Will they accidentally let in bad guys? Maybe. You signed up for that too.

Re: Apple's apps bypass firewalls like LittleSnitch and LuLu on macOS Big Sur

#556
post #502
post #13

Earlier quoted context omitted.

They provide the OS. If you don't trust them, then you shouldn't trust anything running on top of it either...

That's the exactly the thing - they are, indeed, chasing me off. When this Mac dies, I'll be replacing it with something running Debian. It is too bad - the Mac hit this sweet-spot where it was pretty much my perfect machine for several years - a kickass Unix workstation in a decently built laptop, with a decent GUI, with access to consumer apps, too. It was great while it lasted. Thing is, this is a reasonable thing…

I really thought about this yesterday, and the one program i really miss on linux would be Little Snitch. I need a good application firewall on linux.

Re: Apple's apps bypass firewalls like LittleSnitch and LuLu on macOS Big Sur

#557
post #21

Apple seems to do all kinds of weird networking _stuff_. For instance, during wakeup, your T2 equipped Macbook will wait for a DNS response and then use said DNS response to synchronize time via NTP before letting the user use the keyboard. Probably checking timestamps on signatures for the keyboard firmware, or something stupid like that. This only happens if it happens to have a default route. Similarly, all macOS…

> For instance, during wakeup, your T2 equipped Macbook will wait for a DNS response and then use said DNS response to synchronize time via NTP before letting the user use the keyboard.

Aha so this is why I need to put my MacBook back to sleep after waking on a spotty WiFi connection or when it was previously connected to vpn which timed out during sleep!

Re: Apple's apps bypass firewalls like LittleSnitch and LuLu on macOS Big Sur

#558
post #13

Earlier quoted context omitted.

If I install Little Snitch, it's because I trust Little Snitch to be responsible for my computer's network traffic, over and above anyone else. I recognize that this won't necessarily apply to all users or all apps, but there needs to be a way for the user to designate trust. Apple services and traffic should not get special treatment.

They provide the OS. If you don't trust them, then you shouldn't trust anything running on top of it either...

Well, that's not the whole story: consider another example, the various parts of Safari. Apple wrote that, Apple wrote the whole OS…should they have access to a kernel task port? Shouldn't I trust them to not do bad things? Of course I do, since I use the browser–but I am glad that those are split into separate processes and sandboxed, because an exploit in any of those instantly turns this access into a confused deputy problem. A confused deputy is trustworthy–but they're confused.

Adding exceptions means adding more points of failure, more complexities in code, more opportunities for attackers to bypass restrictions placed on them but not on OS services. Not only that, but you get the upside of having a unified model for Apple and your app developers "for free"–the latter which is of critical importance to Apple in particular, since they have had years of trouble in this area.

Re: Apple's apps bypass firewalls like LittleSnitch and LuLu on macOS Big Sur

#559
post #416

Earlier quoted context omitted.

Another reason why I'm going to stick with Linux for the foreseeable future. I just wish the font rendering situation on Linux was better though. Text (in browsers) just looks so bad on Linux compared to both Windows and mac.

No, it's fine, just needs a bit of tweaking: https://aswinmohan.me/posts/better-fonts-on-linux/

Thank you!

Re: Apple's apps bypass firewalls like LittleSnitch and LuLu on macOS Big Sur

#560
post #468
post #233

Earlier quoted context omitted.

I find it interesting how the needs of legitimate security mesh so well with the industry desires to kill off general-purpose computing for the majority of users

As a general rule, you want to prevent software from bypassing a user's informed consent. Apple typically does this in one of two ways: 1. Have functionality only accessible through system frameworks, so that the OS can be responsible for prompting for informed consent and granting it to a process. This means that the system itself has to have functionality to prompt for that informed consent in a way that users can…

Unfortunately, Apple often does 1 far more often than 2, whether it be because 2 is harder, or has a worse experience, or what have you. And Apple exempting themselves is really option 3 for themselves.
Post reply on HN