Live data from Hacker News

Apple's apps bypass firewalls like LittleSnitch and LuLu on macOS Big Sur

twitter.com

631–640 of 649 posts

Re: Apple's apps bypass firewalls like LittleSnitch and LuLu on macOS Big Sur

#631

Earlier quoted context omitted.

Yes I agree with your first part. There are real drawbacks. But it's like installing a custom HTTPS cert in your OS to inspect potential traffic that malware may use through, say, a Google Doc or Sheet. It's helpful to true professionals dealing with highly sensitive information, but it's ultimately a bigger source of compromise for the vast majority of software users. I don't think there is an easy answer here. That…

I helped a friend of mine with her OS X laptop. She had installed something bad and it installed MITM proxy and its own CA and other things to totally own and inspect all of her web browser traffic including SSL. So these features that we find powerful and informative also do have a dark side for more novice users.

I’m trying to think of a powerful tool that is not dangerous. Still thinking

Re: Apple's apps bypass firewalls like LittleSnitch and LuLu on macOS Big Sur

#632

Everyone seems to assume this is true, but are people also confirming this? I installed LittleSnitch recently on Big Sur and I’m constantly getting pop up’s for all of Apple’s internal daemons etc. While I haven’t tried the App Store specifically, I’m wondering if the person didn’t understand how things were configured and was allowing certain traffic thru. I can’t imagine there’s really some big conspiracy here.

Confirmed. Someone also found the strings in the network stack, which are tested against the app's bundle identifier to provide these wholes. It's ridiculous.

Do you have a reference? As noted, this seems to contradict what Objective Development is saying.

Objective (sic) proof that Objective Development is lying would certainly be a big deal, and a very good reason not to trust Little Snitch.

Re: Apple's apps bypass firewalls like LittleSnitch and LuLu on macOS Big Sur

#633
post #502

Earlier quoted context omitted.

That's the exactly the thing - they are, indeed, chasing me off. When this Mac dies, I'll be replacing it with something running Debian. It is too bad - the Mac hit this sweet-spot where it was pretty much my perfect machine for several years - a kickass Unix workstation in a decently built laptop, with a decent GUI, with access to consumer apps, too. It was great while it lasted. Thing is, this is a reasonable thing…

I really thought about this yesterday, and the one program i really miss on linux would be Little Snitch. I need a good application firewall on linux.

We are working on an alternative for both Linux and Windows: https://safing.io/portmaster/

Not only is it an application firewall, but also gives you DNS filtering (ie. Pi-Hole basics) and DNS-over-TLS.

If you check it out, we'd love to hear some feedback! (Full UI revamp incoming)

Re: Apple's apps bypass firewalls like LittleSnitch and LuLu on macOS Big Sur

#634

Earlier quoted context omitted.

I really thought about this yesterday, and the one program i really miss on linux would be Little Snitch. I need a good application firewall on linux.

Sounds like a business opportunity...

We're on it: https://safing.io/portmaster/

Re: Apple's apps bypass firewalls like LittleSnitch and LuLu on macOS Big Sur

#635
post #610

Earlier quoted context omitted.

> And let's never forget, Apple has been actively collaborating with authoritarian governments to shut down pro-democracy activism. That's not just a theoretical possibility, it actually happened. I wonder why any time I see these claims, they’re never accompanied by anything resembling reliable evidence. > The whole "We can trust Apple with our data" line starts with a flawed assumption: that Apple should be allowed…

> I wonder why any time I see these claims, they’re never accompanied by anything resembling reliable evidence. Because the stories have been on all the news sites, it's common knowledge, and thus it would be superfluous to submit detailed documentation every time it's mentioned? I can't help it if you're not informed about politics and tech. > you on the other hand are free to vote with your wallet and your time by…

> Because the stories have been on all the news sites, it's common knowledge, and thus it would be superfluous to submit detailed documentation every time it's mentioned?

Those are the claims, yet every time I dig deeper I see how from “actively collaborating with authoritarian governments to shut down pro-democracy activism” they are reduced to “complying with local laws” within a single brief conversation.

Sure, in some countries the latter is a superset of the former. In such countries, violation of ethical norms could be required in some situations to comply with local law. However, it doesn’t mean that any instance of the latter always requires the former, nor that Apple had ever faced this choice, nor that if put in this situation Apple would agree to actually do the former as opposed to exiting the market (which, exiting, I suspect is a scenario CCP would very much prefer to avoid).

I will roughly delineate the difference based on two concrete example situations:

1) Complying with the requirement to store encryption keys for Chinese user data on Chinese servers = complying with local laws.

2) Providing personally identifiable information about individual Apple users at request of CCP, or helping CCP representatives hack into Apple devices = collaborating to shut down activism.

If you have any evidence of anything along the lines of (2), I’m all ears (as I’m sure is any tech journalist worth their salt).

> Are you seriously saying I should pack my bags and leave the Apple ecosystem forever and no longer write software for the Mac or write blog posts about it?

I’ll level with you here. I’m not a professional Apple developer making a living from selling my software to end-users, but I dabble, and I am very deep in Apple’s hardware and software, preferring them to any other alternative in the market. It would be an extreme lifestyle change, but if I had reasons to believe that Apple had indeed collaborated with CCP to shut down activism, due to my personal views I would have to exit Apple’s ecosystem and start hacking on a PinePhone or something.

That said, if a country like China doesn’t want its citizens’ data encryption keys to live on servers in a country like the USA, I don’t believe that’s outrageous; if you’re an activist, you’ll be aware of that and make arrangements. There’s a line, but this does not cross that line as far as I’m concerned.

Re: Apple's apps bypass firewalls like LittleSnitch and LuLu on macOS Big Sur

#636
post #374

Earlier quoted context omitted.

Is the crack in hardware or software? Any links on it? I thought the iPhones at least could not be reset by thieves?

Every device up to the iphone X has been cracked btw so the factory reset protection can be bypassed.

Can you provide some links?

Re: Apple's apps bypass firewalls like LittleSnitch and LuLu on macOS Big Sur

#637
post #312

Earlier quoted context omitted.

Where are these weird anti-FOSS statements being bred from? > Those who pay set the agenda for everything. And this different from non FOSS software how? > Developing a truly polished operating system with a whole ecosystem of services is far, far beyond what volunteers and hobbyists can achieve. As someone who uses Linux as my primary workstation I disagree. My coworkers that use Mac or Windows seem to have about th…

I crap on FOSS a bit because I like it and wish it got more traction in the mainstream. I intend it as constructive criticism. I've been a FOSS user and sometimes contributor since 1994 when I installed Linux with floppy disks, and have consistently watched FOSS lose the mainstream because they don't grasp the critical importance of UI/UX. I want to write "it has to just work" on a sledgehammer and bash people about…

Sorry then. I had read something anti-foss the other day (probably on Reddit) which seemed to have a hidden agenda behind it like in the old days. As far as having a “it just works” experience- sticking with the Lenovo and Dell professional lines has worked out pretty well for me.

Re: Apple's apps bypass firewalls like LittleSnitch and LuLu on macOS Big Sur

#638

Earlier quoted context omitted.

I think this is the case where you can have traffic monitoring set-up on your home router or any other network gateway available. It will be slightly more troublesome, but not impossible.

That doesn't work with HTTPS, obviously. And with DNS-over-HTTPS, DNS-over-TLS and encrypted SNI, that makes it all the more harder.

It would work with HTTPS if you can set your software to accept a self-signed root cert. That's a significant if, however.

Re: Apple's apps bypass firewalls like LittleSnitch and LuLu on macOS Big Sur

#639

Earlier quoted context omitted.

>is therefore a betrayal of users’ trust. I would disagree with that statement. The user bought an Apple computer so they clearly trust Apple already. If anything, the new frameworks make the system more secure which strengthens that trust for users. The only people really affected by this change are users who want granular control over everything whether it comes from Apple or not.

>The user bought an Apple computer so they clearly trust Apple This is false, maybe I bought X because it was the least shitty choice.

That's fine but you bought it. When it comes down to it, America and capitalism run on the premise that you vote with your dollar. You voted with your dollar regardless of the mental gymnastics you did or didn't do to make that decision.

Re: Apple's apps bypass firewalls like LittleSnitch and LuLu on macOS Big Sur

#640
post #32

That totally breaks my use case for Little Snitch: working tethered. When I tether my laptop it thinks it has free reign with the bandwidth and all of the little background processes can kill my data in a few minutes. With a firewall, I can grant access to only the processes that I need to get my work done. Now, I guess I have to run some external firewall between my laptop and my phone. ... or better yet, abandon Ap…

Last year Apple introduced 2 flags on the network: “constrained” (the Low Data Mode toggle) and “expensive” (most cellular and personal hotspots). These are intended to let the app make intelligent decisions about what network requests to do. For example, “expensive” networks should disable background or speculative fetches and only fetch what the user asked for.

Presumably Apple apps that bypass the network filter are making use of these flags already, to avoid unnecessary network traffic.

Post reply on HN