Live data from Hacker News

Apple's apps bypass firewalls like LittleSnitch and LuLu on macOS Big Sur

twitter.com

601–610 of 649 posts

Re: Apple's apps bypass firewalls like LittleSnitch and LuLu on macOS Big Sur

#601
post #162
post #80

Earlier quoted context omitted.

Wouldn't pi-hole be the 'resolver' the other end of the request, the party it's encrypted for? Sure, Apple (or whoever) could just bypass it and use something specific, but can already just use an IP, no DNS anyway?

My understanding is the concern would be that closed source applications would use a hardcoded DoH resolver and pinned certs to bypass any unwanted blocks of ads/telemetry which could only be resolved with decompilation and patching with varying degrees of difficulty.

Sure, but if you're worried about them using a specific DNS, aren't you already worried about them not using DNS; resolving `phonehome.evil.co` once per release and shipping the baked-in IP? Stops working if it can't reach that IP, 'xx needs to update', gets new IP?

Re: Apple's apps bypass firewalls like LittleSnitch and LuLu on macOS Big Sur

#602

Earlier quoted context omitted.

Kexts are used by Apple internally, so I'd be shocked if they were removed from the OS completely. Third party kexts may be deprecated, but as long as SIP can be disabled it will always be possible to load your own.

Apple could stop allowing you to load kexts they don’t sign, like they do on iOS.

It’s my understanding (and I imagine yours is better than mine) that at least at present, the macOS kernel is open source, which would mean that unless they forked it, disabling firmware security and SIP would mean that you could replace it with a compatible one compiled from open sources that skips such a check.

They can, of course, remove that option a number of ways: closed source kernel, disable the disablement of boot security (such as on iOS), et c.

Re: Apple's apps bypass firewalls like LittleSnitch and LuLu on macOS Big Sur

#603

Background: I've written my own kernel extension that works in similar manner to Little Snitch, but does a lot more, including SSL MITM and on-demand packet capture, that I've been using for more than 10 years now. It's a fact that Apple has continuously moved to lock down macOS in ways that are antithetical to folks that want full control over their operating system. To many of us that moved on from Linux on the des…

Little Snitch is the only thing keeping me on macOS.

How do we go about replicating this sort of per-process network visibility/permission on Linux?

Re: Apple's apps bypass firewalls like LittleSnitch and LuLu on macOS Big Sur

#604
post #424

Earlier quoted context omitted.

> Third, I set my recursive resolver to use the nextdns.io endpoint as its upstream source of DNS. Doesn't that relegate your recursive resolver to a stub? You could run pi-hole on fly.io for free if DoT/DoH is all you need: https://fly.io/blog/stuff-your-pi-hole-from-anywhere/ I run a public DoH resolver with 170+ blocklists on Cloudflare Workers. Might open source it soon.

Nice. Do you have any more info on that resolver of yours?

[deleted]

Re: Apple's apps bypass firewalls like LittleSnitch and LuLu on macOS Big Sur

#605
post #21

Apple seems to do all kinds of weird networking _stuff_. For instance, during wakeup, your T2 equipped Macbook will wait for a DNS response and then use said DNS response to synchronize time via NTP before letting the user use the keyboard. Probably checking timestamps on signatures for the keyboard firmware, or something stupid like that. This only happens if it happens to have a default route. Similarly, all macOS…

You actually just helped me diagnose a really annoying bug I've been having lately. When I wake up my Mac from sleep mode the keyboard and mouse are unresponsive for a up to a few minutes in some extreme cases, sometimes I even have to hard reboot. I found online that it was related to VPNs trying to restore their connection but I could never find the link between the keyboard and the VPN.

It was also compounded by the VPN setting I use to disable all traffic until it successfully reconnects. Meaning whether my computer works or not is dependent on my VPN providers reliability.

Now that I know Apple thinks I need an internet connection to wake up my laptop securely I'm quite pissed by this. Brand new $4k laptop is a paperweight if my VPN can't connect.

Re: Apple's apps bypass firewalls like LittleSnitch and LuLu on macOS Big Sur

#606
post #602

Earlier quoted context omitted.

Apple could stop allowing you to load kexts they don’t sign, like they do on iOS.

It’s my understanding (and I imagine yours is better than mine) that at least at present, the macOS kernel is open source, which would mean that unless they forked it, disabling firmware security and SIP would mean that you could replace it with a compatible one compiled from open sources that skips such a check. They can, of course, remove that option a number of ways: closed source kernel, disable the disablement o…

XNU is open source and I have personally used custom kernels, but if it got to that point I definitely don't think it would be worthwhile for Little Snitch to maintain their kernel extension.

I truly don't think it would get to that point though. And even if it does, that day could be years away. We're talking about maintaining an existing product, not starting a new one from scratch.

IMO, the more pertinent question is whether it's worth asking customers to disable SIP. Up until now, commercial Mac software—even software targeting advanced users—has seemingly wanted to avoid that at all costs, whether it's Flavours discontinuing their theming software or nVidia discontinuing their web drivers†.

---

† Note that I'm continually suspicious we don't have the whole story here, but the commonly-cited narrative is that Apple won't sign nVidia's drivers.

Re: Apple's apps bypass firewalls like LittleSnitch and LuLu on macOS Big Sur

#607

I mean I already knew something was weird when I couldnt su into root and do... root things without a bios hack on a Mac. Thats just not how Unix works at all... The whole concept of root is you are root no exceptions.

You can't even remove their new bloated system-installed wallpapers (>2GB, with about 3 of them taking almost 300MB each) without rebooting into safe mode and following tons of steps. But they will sell you an SSD upgrade to help hold them for 3X the market price.

https://apple.stackexchange.com/questions/375519/how-to-dele...

Re: Apple's apps bypass firewalls like LittleSnitch and LuLu on macOS Big Sur

#608
post #468
post #233

Earlier quoted context omitted.

I find it interesting how the needs of legitimate security mesh so well with the industry desires to kill off general-purpose computing for the majority of users

As a general rule, you want to prevent software from bypassing a user's informed consent. Apple typically does this in one of two ways: 1. Have functionality only accessible through system frameworks, so that the OS can be responsible for prompting for informed consent and granting it to a process. This means that the system itself has to have functionality to prompt for that informed consent in a way that users can…

> A prime example would be rebooting into recovery mode to turn off system integrity protections via a terminal command.

I actually think the way Apple implemented this downright brilliant. As you say, it can't be done automatically, and it's definitely made to be a bit intimidating. At the same time, it's not difficult or onerous, that's a pretty hard balance to strike.

By contrast, when I try to install unsigned drivers in Windows, I feel as though Microsoft is fighting me, and I get annoyed basically every time. I've never had that feeling with SIP; when I get a new computer, I take off the training wheels I don't need, and move along.

Re: Apple's apps bypass firewalls like LittleSnitch and LuLu on macOS Big Sur

#609
post #597

Earlier quoted context omitted.

That quote—“Apple now theoretically has a centralized database of every Mac user who's ever used youtube-dl.”—is somewhat misleading. Apple doesn’t get script contents, it only gets a hash. Of course, if Apple really wanted, they could maintain a DB of hashed contents of every possible version of youtube-dl script, and do their best to match it up with what users execute. However, even that far-fetched scenario falls…

Why are scripts even getting notarization checks when scripts cannot be notarized??? We shouldn't need to tell a story about how it would be difficult for Apple to exploit data they have about us, because they simply shouldn't have this data about us. The whole "We can trust Apple with our data" line starts with a flawed assumption: that Apple should be allowed to collect data from us. False. And it's important to no…

> And let's never forget, Apple has been actively collaborating with authoritarian governments to shut down pro-democracy activism. That's not just a theoretical possibility, it actually happened.

I wonder why any time I see these claims, they’re never accompanied by anything resembling reliable evidence.

> The whole "We can trust Apple with our data" line starts with a flawed assumption: that Apple should be allowed to collect data from us.

Apple is free to do that, as a private entity in a free market; you on the other hand are free to vote with your wallet and your time by buying their devices and developing for their ecosystem (or not).

You’re entitled to not believe that the end goal (security) is not justified or achieved by the means (notarization, Gatekeeper, etc.), but somehow you are not making that argument.

Re: Apple's apps bypass firewalls like LittleSnitch and LuLu on macOS Big Sur

#610
post #597

Earlier quoted context omitted.

Why are scripts even getting notarization checks when scripts cannot be notarized??? We shouldn't need to tell a story about how it would be difficult for Apple to exploit data they have about us, because they simply shouldn't have this data about us. The whole "We can trust Apple with our data" line starts with a flawed assumption: that Apple should be allowed to collect data from us. False. And it's important to no…

> And let's never forget, Apple has been actively collaborating with authoritarian governments to shut down pro-democracy activism. That's not just a theoretical possibility, it actually happened. I wonder why any time I see these claims, they’re never accompanied by anything resembling reliable evidence. > The whole "We can trust Apple with our data" line starts with a flawed assumption: that Apple should be allowed…

> I wonder why any time I see these claims, they’re never accompanied by anything resembling reliable evidence.

Because the stories have been on all the news sites, it's common knowledge, and thus it would be superfluous to submit detailed documentation every time it's mentioned? I can't help it if you're not informed about politics and tech.

> you on the other hand are free to vote with your wallet and your time by buying their devices and developing for their ecosystem (or not).

People always say stuff like that, but do they really mean it? It feels like just empty rhetoric to shut down criticism of Apple, not an actual suggestion. I've been a professional Mac developer for over a dozen years, my software has been enjoyed by countless people, and I've also provided many tech insights enjoyed by many people, including this one under discussion, as well as the Google Chrome bug story that's been going around — that's me too! Are you seriously saying I should pack my bags and leave the Apple ecosystem forever and no longer write software for the Mac or write blog posts about it? Is that what you really want? Is that what people in general want, for me to leave the Mac? Don't say it unless you mean it, and are willing to drive away longtime Mac users and/or developers like me.

I hope you'll enjoy your "curated" criticism-less ecosystem with no actual developers who care about the Mac.

Post reply on HN