Live data from Hacker News

Apple's apps bypass firewalls like LittleSnitch and LuLu on macOS Big Sur

twitter.com

571–580 of 649 posts

Re: Apple's apps bypass firewalls like LittleSnitch and LuLu on macOS Big Sur

#571
post #493
post #400

Earlier quoted context omitted.

The decision is questionable, but you can always inspect traffic from the machine outside it, I would even say that's preferable in context of malware.

TLS makes this difficult today and SNI encryption will make this next to impossible without installing a custom ca certificate and doing MITM. Even that isn't helpful when you are using a laptop that may not always be on the network where you have deployed a device for inspection. Better to be able to inspect or block on the device by application.

When we are talking about malware that's irrelevant. And if we are talking about inspecting Apple's traffic, I don't think you should trust things you see on their hardware running their operating system.

Re: Apple's apps bypass firewalls like LittleSnitch and LuLu on macOS Big Sur

#572
post #52

Earlier quoted context omitted.

> They say they want free as-in-freedom, but since they are not willing to pay for it they don't exist. Only paying users matter. Citation needed. If you look at app store pricing models the opposite seems true. If I were going to take a random guess I would say that tech savvy users use open source software to avoid anti-consumer bullshit more than anything else.

If enough people said to Apple "hey, this stuff is not acceptable and we won't pay for it" and then they actually did follow through, Apple would stop. My point is that the vast majority of people don't say that, only a very tiny minority. The vast majority of people want convenience, not control. They want their stuff to "just work" because even if they do have the technical knowledge they don't have the time to scr…

> If enough people said to Apple "hey, this stuff is not acceptable and we won't pay for it" and then they actually did follow through, Apple would stop.

“The market will price this out” doesn’t actually work because it assumes that 1. Apple’s product strategy is done to match market desires perfectly and 2. The decision to buy is solely predicated on this particular thing. The first is false because nobody can do that and the second is because people buy Apple products for other reasons than just that. I personally know many people (although this sample is of course unbiased) that buy Apple devices for a number of reasons (they work well, they look nice, they have good support) but hate that they can’t do thing on them. But their purchase decision doesn’t reflect their opinions on this particular issue.

Re: Apple's apps bypass firewalls like LittleSnitch and LuLu on macOS Big Sur

#573

Background: I've written my own kernel extension that works in similar manner to Little Snitch, but does a lot more, including SSL MITM and on-demand packet capture, that I've been using for more than 10 years now. It's a fact that Apple has continuously moved to lock down macOS in ways that are antithetical to folks that want full control over their operating system. To many of us that moved on from Linux on the des…

I switched back to linux two years ago for exactly the same reason.

It was painful at first, but it's worth it. The only things I still miss are the visual feedback in the UI (lots of little stuff) and the feel of the trackpad.

But the customizability has more than made up for that in productivity. Like being able to edit the source code for the window manager.

Re: Apple's apps bypass firewalls like LittleSnitch and LuLu on macOS Big Sur

#574
post #66

Earlier quoted context omitted.

> but is it really that hard to document these behaviors? I imagine it is, given the bureaucracy of a big company. Apple's documentation has long been really dreadful, mostly nonexistent and where it does exist, usually incomplete and even wrong. I've assumed it was because the code itself is developed by isolated groups while the documentation presumably has to touch all sorts of people (publishing, translation, lan…

> Apple's documentation has long been really dreadful Developer docs for most of their libraries are usually just the method name in a large font and the parameter types and that's it.

Online documentation. For some reason the qualification is necessary because their header files have a bunch of information that whatever script or tool that generates the webpages doesn’t catch.

Re: Apple's apps bypass firewalls like LittleSnitch and LuLu on macOS Big Sur

#575
post #18

Earlier quoted context omitted.

I'd argue this opens up a giant attack surface where malicious software will try to route its command and control communication through a protected service. Do we really want to trust that Apple will keep all 50+ of these privileged services fully protected? I think it makes the "world" slightly worse in that it will be harder to discover malware. Little snitch has a small user base, but it's been used to identify ma…

> Do we really want to trust that Apple will keep all 50+ of these privileged services fully protected? No.[1] That's what people need to start understanding. Even if you decide to trust that someone will attempt to act in your best interests (you really shouldn't, see Google's extinct "do no evil" mantra), you can't trust anyone to do so perfectly. All this aspirational goodwill that fans express on behalf of their…

I actually agree with your point, but what?!?! It takes some serious punch drinking to have ever gone along with that "hee-hee we can do such creeper things but we don't because we're ethically superior" shtick. Anyone who has ever signed on to work for Google has made an obvious decision of wallet/status over ethics. Yet the implication in your post seems to be "if google went cheese, anyone could". I disagree strongly.

Re: Apple's apps bypass firewalls like LittleSnitch and LuLu on macOS Big Sur

#577

Earlier quoted context omitted.

> a lot of the features that MacOS has will never be implemented Care to name any? Other times I’ve heard things like this on HN I’ve been able to locate them.

A big one I will sorely miss as I transition to Linux (and it's the only one I can think of right now), is the ability to rename and move around files while they are open! OK here's another, very related: the ability to have apps remember their open files when you quit and re-open them. These are significant productivity boosters, and I will miss them. It's definitely a trade-off, but now Apple has tipped the scales…

Both of those things work under Linux for me. I guess it depends on the apps?

Re: Apple's apps bypass firewalls like LittleSnitch and LuLu on macOS Big Sur

#578

Earlier quoted context omitted.

https://news.ycombinator.com/item?id=24840166

None of those options are viable for mass market adoption right now. They are niche operations that are practically invisible to anyone outside of the industry. I didn't say you can't buy Linux pre-installed, I said you can't go into a big-box store like Best Buy to do so, and that there's no significant consumer support infrastructure. There's also the strong possibility that at least some of these places won't exis…

> It uses its own flavor of Linux, meaning support options are extremely limited.

The difference between PureOS and Debian is practically non-existent.

> System76's website is itself half-broken, with 500 errors

OK, it proves that the company is about to die. We of course never see those errors on big websites /s

>If tomorrow a million Apple users said "Enough! LittleSnitch is the straw that breaks the camel's back!" and decided they wanted to shop for a desktop linux system, the market couldn't handle it.

Although it is true, the good news is that such thing just cannot happen. This is not how the market changes. The change is always smooth enough that the companies can adjust. And I am sure Purism and System76 are able to given reasonable time.

> I'm saying that it is not a mass-market option right now for users frustrated with Windows/OS X.

Many (most?) frustrated users on MacOS are those who can use the options I listed. If they understand the problems like the one in the title, they definitely can order a laptop online. Probably also true with Windows. Such changes typically start with geeks anyway (AFAIK geeks switched to MacOS first).

> You cannot point to niche operations and claim it to be a viable mass-market option.

I did not claim that. I suggest that those complaining about users restrictions should go to Linux. Typical users do not complain about such things.

> I didn't say you can't buy Linux pre-installed, I said you can't go into a big-box store like Best Buy to do so, and that there's no significant consumer support infrastructure.

Now you have a point and I actually do not really understand, why I cannot just enter a big shop and ask for a Linux laptop. I actually tried to ask tens of times and they always say there are no. Sounds like a conspiracy by the big labels to me.

Re: Apple's apps bypass firewalls like LittleSnitch and LuLu on macOS Big Sur

#579
post #18

Earlier quoted context omitted.

I'd argue this opens up a giant attack surface where malicious software will try to route its command and control communication through a protected service. Do we really want to trust that Apple will keep all 50+ of these privileged services fully protected? I think it makes the "world" slightly worse in that it will be harder to discover malware. Little snitch has a small user base, but it's been used to identify ma…

Yes I agree with your first part. There are real drawbacks. But it's like installing a custom HTTPS cert in your OS to inspect potential traffic that malware may use through, say, a Google Doc or Sheet. It's helpful to true professionals dealing with highly sensitive information, but it's ultimately a bigger source of compromise for the vast majority of software users. I don't think there is an easy answer here. That…

Why not just give additional permission levels? I don't really get why so many permission models on what software can do are effectively "admin mode" or "user mode". Why can't you get a very strong warning when software tries to snoop on traffic, but you can still do it? Or maybe you have to go into settings and allow it or something like that.

When you rent space in a building, do you get access to every single apartment/office space in the building? No. You get access to specifically what you rented and the front door. The maintenance people for the building will have access to the front door and other maintenance areas, but won't have access to your space. We can clearly conceptualize models like that. We even have something like this on phones.

Re: Apple's apps bypass firewalls like LittleSnitch and LuLu on macOS Big Sur

#580
post #6

This is one of those tough cases where software cuts both ways. Some people are smart, informed developers that install a trusted tool to monitor their traffic and have legitimate reasons to want to inspect Apple traffic. They're dismayed. Most people are the opposite and this move protects the most sensitive data from being easily scooped up or muddled in easily installed apps, or at least easily installed apps that…

Trusting corporations (or any entity free from limitations and background checks) seldom bring the expected results.
Post reply on HN