Live data from Hacker News

Apple's apps bypass firewalls like LittleSnitch and LuLu on macOS Big Sur

twitter.com

71–80 of 649 posts

Re: Apple's apps bypass firewalls like LittleSnitch and LuLu on macOS Big Sur

#71
post #33
post #6

This is one of those tough cases where software cuts both ways. Some people are smart, informed developers that install a trusted tool to monitor their traffic and have legitimate reasons to want to inspect Apple traffic. They're dismayed. Most people are the opposite and this move protects the most sensitive data from being easily scooped up or muddled in easily installed apps, or at least easily installed apps that…

Tech savvy users are not just the minority. They're also cheap. They've been conditioned by the FOSS movement to think all software should be free as-in-beer. (The people who started FOSS didn't say that, but that's what it's become.) They say they want free as-in-freedom, but since they are not willing to pay for it they don't exist. Those who pay set the agenda for everything. Developing a truly polished operating…

I'm happy to pay for good FOSS and open hardware and I'm paying. Also I'm trying to avoid any proprietary and especially cloud-connected things. You are generalizing too much, there are enough people who are happy to pay for trustworthy software and hardware. Just noone cares.

Re: Apple's apps bypass firewalls like LittleSnitch and LuLu on macOS Big Sur

#72

That’s annoying yet pretty predictable, at least we’ve still got https://pi-hole.net/ as an option until DNS encryption becomes widespread :/

I don't see how pi-hole get affected by DNS via https, unless you are leaving out the part about computers, tablets, and phones using hard-coded DNS servers that use DNS via https. This is a trend, but a very small one right now.

Re: Apple's apps bypass firewalls like LittleSnitch and LuLu on macOS Big Sur

#73
post #45

Earlier quoted context omitted.

Oh wow! This probably explains why every now and then when I wake my MacBook Pro from sleep it says no keyboard is connected! I thought I had some hardware problem on a basically brand new machine. Glad to hear it's only a stupid software problem!

If you're using Cisco Anyconnect, blame that for that particular keyboard issue.

It's any VPN software that is always-on.

Re: Apple's apps bypass firewalls like LittleSnitch and LuLu on macOS Big Sur

#74
post #11

So? Users expect basic OS functionality (like the App Store, Maps, etc) to function. Do people really install Little Snitch (which I've used since 2005 or so) for blocking Apple's own apps?

> Do people really install Little Snitch (which I've used since 2005 or so) for blocking Apple's own apps?

Yes, Absolutely! My primary use case for Little Snitch is to block Apple "services" that I don't use or want.

I don't use iCloud at all. I don't want Apple phoning home unless I specifically, manually check for software updates.

Re: Apple's apps bypass firewalls like LittleSnitch and LuLu on macOS Big Sur

#75
post #28

Earlier quoted context omitted.

Dont pray, just dont buy Apple Products

Boycotting is not an effective strategy for addressing oligopolies. You need actual strong anti-trust regulation.

Hear hear. All "just use an alternative" does is temporarily shift the problem. And then tomorrow an article appears highlighting Windows 10's invasive telemetry and people say "yeah just use macOS".

Re: Apple's apps bypass firewalls like LittleSnitch and LuLu on macOS Big Sur

#76
post #21

Apple seems to do all kinds of weird networking _stuff_. For instance, during wakeup, your T2 equipped Macbook will wait for a DNS response and then use said DNS response to synchronize time via NTP before letting the user use the keyboard. Probably checking timestamps on signatures for the keyboard firmware, or something stupid like that. This only happens if it happens to have a default route. Similarly, all macOS…

Unrelated but has anyone often had Chrome going on cpu usage rampage and unresponsive fairly frequency on 'wakeup from sleep'? It's almost certain to happen if the chrome has been updated and waiting to be restarted.

Re: Apple's apps bypass firewalls like LittleSnitch and LuLu on macOS Big Sur

#77

Earlier quoted context omitted.

If you don’t trust Apple then you need something more than little snitch. Apple is responsible for both hardware and OS. What delta in security or trust is little snitch going to offer over Apple?

In this situation the question isn’t about whether or not Apple can be trusted. Apple has clearly betrayed users’ trust in this situation. People don’t install Little Snitch only to prevent nefarious third party activity. Some may want to know what traffic is going to and from their computers. Other may want to block all traffic for testing and/or research purposes. I can trust that Apple is not doing something nefar…

> any backdoors Apple builds for its own apps

Apple hasn't weakened the security of their devices to provide a secret way in, in fact, they made their systems even more robust.

The question absolutely is whether Apple can be trusted. Little Snitch works for other apps, just not Apple's apps. The remaining slice of the pie you're arguing for is whether or not we can trust Apple.

So what delta in security and trust over Apple are we getting by asking for this change, and how much insecurity and brittleness are we inviting to all other users with our ineffective software based firewall?

Re: Apple's apps bypass firewalls like LittleSnitch and LuLu on macOS Big Sur

#78
post #6

This is one of those tough cases where software cuts both ways. Some people are smart, informed developers that install a trusted tool to monitor their traffic and have legitimate reasons to want to inspect Apple traffic. They're dismayed. Most people are the opposite and this move protects the most sensitive data from being easily scooped up or muddled in easily installed apps, or at least easily installed apps that…

> Is the world better or worse due to this change?

This is the false shortcut behind any attempt to weaken security. Security makes access harder, therefore let's weaken security to improve access.

The fact is that weakening security also makes malicious behavior easier and/or more likely. Changes like this are bad particularly because Apple users pay for a protected walled garden.

Re: Apple's apps bypass firewalls like LittleSnitch and LuLu on macOS Big Sur

#79
post #68
post #48

Earlier quoted context omitted.

Having a default route does not mean the internet is reachable.

Probably why the other discussed function exists: > Similarly, all macOS machines will test a DHCP supplied default route before applying it by trying to reach something on the internet. So if you happen to have some firewall rules that block internet access, no default route will be applied until the internet check times out. So if the default route doesn't exist yet since it's still checking for internet, it would…

The default route verification is separate from the keyboard issue. I don't know exactly what is going on here, but in the above post what I mean by the system applying a default route is that the route isn't propagated to the system configration's dynamic store and whatever macOS uses for netlink, i.e. the route doesn't show up in `route monitor` until the check finishes. However, I do believe it would still be used at some level, either on the T2 or in the kernel to do the NTP stuff.

Re: Apple's apps bypass firewalls like LittleSnitch and LuLu on macOS Big Sur

#80

Earlier quoted context omitted.

Not a pi-hole user, but what is the plan for pi-hole once encrypted dns is everywhere? Will it just be dead? I can’t really think of a way for it not to be.

DoT isn't a big problem for a pihole, but it doesn't look like things are going that way. DoH can only be blocked by a mitm proxy. You would have to take a pretty serious security hit to do something like that with a pihole.

Wouldn't pi-hole be the 'resolver' the other end of the request, the party it's encrypted for?

Sure, Apple (or whoever) could just bypass it and use something specific, but can already just use an IP, no DNS anyway?

Post reply on HN