This is one of those tough cases where software cuts both ways. Some people are smart, informed developers that install a trusted tool to monitor their traffic and have legitimate reasons to want to inspect Apple traffic. They're dismayed. Most people are the opposite and this move protects the most sensitive data from being easily scooped up or muddled in easily installed apps, or at least easily installed apps that…
Tech savvy users are not just the minority. They're also cheap. They've been conditioned by the FOSS movement to think all software should be free as-in-beer. (The people who started FOSS didn't say that, but that's what it's become.) They say they want free as-in-freedom, but since they are not willing to pay for it they don't exist. Those who pay set the agenda for everything. Developing a truly polished operating…
Apple's apps bypass firewalls like LittleSnitch and LuLu on macOS Big Sur
71–80 of 649 posts
Re: Apple's apps bypass firewalls like LittleSnitch and LuLu on macOS Big Sur
#72That’s annoying yet pretty predictable, at least we’ve still got https://pi-hole.net/ as an option until DNS encryption becomes widespread :/
Re: Apple's apps bypass firewalls like LittleSnitch and LuLu on macOS Big Sur
#73Earlier quoted context omitted.
Oh wow! This probably explains why every now and then when I wake my MacBook Pro from sleep it says no keyboard is connected! I thought I had some hardware problem on a basically brand new machine. Glad to hear it's only a stupid software problem!
If you're using Cisco Anyconnect, blame that for that particular keyboard issue.
Re: Apple's apps bypass firewalls like LittleSnitch and LuLu on macOS Big Sur
#74So? Users expect basic OS functionality (like the App Store, Maps, etc) to function. Do people really install Little Snitch (which I've used since 2005 or so) for blocking Apple's own apps?
Yes, Absolutely! My primary use case for Little Snitch is to block Apple "services" that I don't use or want.
I don't use iCloud at all. I don't want Apple phoning home unless I specifically, manually check for software updates.
Re: Apple's apps bypass firewalls like LittleSnitch and LuLu on macOS Big Sur
#75Earlier quoted context omitted.
Dont pray, just dont buy Apple Products
Boycotting is not an effective strategy for addressing oligopolies. You need actual strong anti-trust regulation.
Re: Apple's apps bypass firewalls like LittleSnitch and LuLu on macOS Big Sur
#76Apple seems to do all kinds of weird networking _stuff_. For instance, during wakeup, your T2 equipped Macbook will wait for a DNS response and then use said DNS response to synchronize time via NTP before letting the user use the keyboard. Probably checking timestamps on signatures for the keyboard firmware, or something stupid like that. This only happens if it happens to have a default route. Similarly, all macOS…
Re: Apple's apps bypass firewalls like LittleSnitch and LuLu on macOS Big Sur
#77Earlier quoted context omitted.
If you don’t trust Apple then you need something more than little snitch. Apple is responsible for both hardware and OS. What delta in security or trust is little snitch going to offer over Apple?
In this situation the question isn’t about whether or not Apple can be trusted. Apple has clearly betrayed users’ trust in this situation. People don’t install Little Snitch only to prevent nefarious third party activity. Some may want to know what traffic is going to and from their computers. Other may want to block all traffic for testing and/or research purposes. I can trust that Apple is not doing something nefar…
Apple hasn't weakened the security of their devices to provide a secret way in, in fact, they made their systems even more robust.
The question absolutely is whether Apple can be trusted. Little Snitch works for other apps, just not Apple's apps. The remaining slice of the pie you're arguing for is whether or not we can trust Apple.
So what delta in security and trust over Apple are we getting by asking for this change, and how much insecurity and brittleness are we inviting to all other users with our ineffective software based firewall?
Re: Apple's apps bypass firewalls like LittleSnitch and LuLu on macOS Big Sur
#78This is one of those tough cases where software cuts both ways. Some people are smart, informed developers that install a trusted tool to monitor their traffic and have legitimate reasons to want to inspect Apple traffic. They're dismayed. Most people are the opposite and this move protects the most sensitive data from being easily scooped up or muddled in easily installed apps, or at least easily installed apps that…
This is the false shortcut behind any attempt to weaken security. Security makes access harder, therefore let's weaken security to improve access.
The fact is that weakening security also makes malicious behavior easier and/or more likely. Changes like this are bad particularly because Apple users pay for a protected walled garden.
Re: Apple's apps bypass firewalls like LittleSnitch and LuLu on macOS Big Sur
#79Earlier quoted context omitted.
Having a default route does not mean the internet is reachable.
Probably why the other discussed function exists: > Similarly, all macOS machines will test a DHCP supplied default route before applying it by trying to reach something on the internet. So if you happen to have some firewall rules that block internet access, no default route will be applied until the internet check times out. So if the default route doesn't exist yet since it's still checking for internet, it would…
Re: Apple's apps bypass firewalls like LittleSnitch and LuLu on macOS Big Sur
#80Earlier quoted context omitted.
Not a pi-hole user, but what is the plan for pi-hole once encrypted dns is everywhere? Will it just be dead? I can’t really think of a way for it not to be.
DoT isn't a big problem for a pihole, but it doesn't look like things are going that way. DoH can only be blocked by a mitm proxy. You would have to take a pretty serious security hit to do something like that with a pihole.
Sure, Apple (or whoever) could just bypass it and use something specific, but can already just use an IP, no DNS anyway?