24 ms·
Apple apps on Big Sur bypass some firewalls and VPNs
- gvv 6y ago>The big question though is why the company’s doing this. So far, it hasn’t said why Apple apps on Big Sur are exempt from firewalls and VPNs, but there are some theories. I'm also genuinely curious, what is the main benefit of doing this and if it's done by design.
- martin_a 6y agoThis is probably the first step of being able to fully enforce geo-blocking, censorship or other legal requirements on Mac OS users without any way around.
- logicchains 6y agoI'm not a network person, but couldn't this be relatively easily bypassed just by running the VPN on the router?
- httgp 6y agoYes, but this isn’t an option that is readily available to everyone.
- quyleanh 6y agoYes, you can. However with average user, config router with VPN, proxy is a bit complicated. Bypass firewalls and VPNs on macOS is still terrible by the way.
- totalZero 6y agoYou can't run the VPN on the router if you don't own the router, which means that you can't protect your device's traffic when you're on the go, using mobile hotspot, or connecting to an ISP-supplied gateway without additional hardware.
- logicchains 6y agoIf I have a second phone (e.g. Android( running a hotspot, and I enable a VPN on that phone, will the hotspot / shared internet also go through the VPN, or will the hotspot bypass it?
- totalZero 6y agoWith my device and mobile service provider, the hotspot traffic does not route through the VPN that is active on the Android handset.
- BlueTemplar 6y agoFrankly, a fixed "Internet" Service Provider that doesn't provide you with a router (and leaves you the possibility to use your own) and a /48 IPv6 prefix should have no legal right to call that service "Internet" (in a similar way that Internet neutrality has to be legally respected) : https://www.ripe.net/publications/docs/ripe-690 https://www.ripe.net/publications/docs/ripe-690 (Mobile cellular Internet seems to be harder, but is there any reason why user's cell-'modem' can't handle the routing of successive /64 connections ?)
- sligor 6y agoIt only works at home. Or you need to always have and take your "router-in-the-middle" wherever you go, this is a way more complicated solution
- flower-giraffe 6y agoIn the future I think the tech savvy will be doing exactly that - pinefone as a wireless hotspot with wireguard to a anonymised proxy.
- kukx 6y agoYou can always put a vpn before mac eg using some Cisco or Linux based. Although it is obviously more complicated and expensive.
- w0utert 6y agoIf this Apple firewall nonsense sticks I can see a market emerge for self-contained USB ethernet/wifi dongles that incorporate a built-in router/firewall with VPN functionality. You could build something like this yourself using an rPI or something similar, but my feeling is there could be a sizable market for a small & cheap off-the-shelf device you just plug in.
- minxomat 6y agoEvery router I have seen in the past decade has had at least basic VPN functionality built in (L2TP/PPTP).
- w0utert 6y agoYes, but it's only useful when connected to your home LAN where you have control over the router, and even then only if you know how to set it up. Edit: also not sure if the router I got from my ISP (which I don't use, but I guess 99% of their other customers do since it is non-trivial to replace without losing IPTV) would allow me to configure it as a VPN gateway. Pretty sure it won't considering they try to lock it down as much as possible.
- BlueTemplar 6y agoHow does it work with IPv6, where there is no (need for) LAN (unless maybe if you're a huge company) ?
- silon42 6y agoI'd do the reverse, block any internet access unless it's over a VPN gateway. Additionally, block anything by default that wasn't looked up over my DNS proxy and/or uses HTTPS without SNI...
- sundvor 6y ago... for your own safety.
- blueblisters 6y agoI wonder what enterprises with managed macbooks would think about this. Internet traffic has to be routed through the company firewall in some corporate networks and this restriction will likely cause the company to ditch Apple.
- martin_a 6y agoI already thought the same. Our IT department is probably happy to get rid of the two handful of Mac systems once they have "proof" that those are undermining the network security (when the people use them from mobile hotspots or at home).
- solarkraft 6y agoI have a feeling that Apple likes to give its apps special treatment just to remind everyone that they can (why that is however I don't know, maybe begging for regulation?). I wouldn't be surprised if there are still apple apps installed as system apps on iOS that could just come through the store or are using some special Apple-only API to do something trivial.
- unicornfinder 6y agoMy suspicion is because they decided there was a possibility of a malicious app trying to intercept / block the connections.
- LoathsLights 6y agoI'm not sure how it is on Mac, but on Windows if you've ever used an app that can block network connections, and limit other applications. What is to stop any other app on your computer doing the exact same thing. As far as I've understood any app has access to any other app and the whole environment is just a warzone of apps where you have to trust every app completely to be okay with running it.
- dawnerd 6y agoSo there’s solutions to this. They could show a notice asking the user what they would like to do. Something like “there’s a problem connecting to the internet: cancel | try without vpn”
- ramtatatam 6y agoOn Linux I can configure programs to use VPN link or not to use it so I guess it would also be the case with Mac? I would expect apps not to bypass default route settings, not being Mac user I can only guess default route can be set there, but would OS somehow provide alternative routes if it detects default route is VPN?
- steerablesafe 6y agoOn Linux you can also have network namespaces. It wouldn't surprise me if Mac OS had a similar capability and their apps ran on a different network namespace than the one configurable by the user.
- lsiebert 6y agoNah, they require programs to use their api, and then whitelist their own programs from the api. you can use the following in the terminal the see the list of whitelisted programs: cat /System/Library/Frameworks/NetworkExtension.framework/Versions/A/Resources/Info.plist
- heavyset_go 6y agoLinux offers virtual TUN/TAP[1] devices that encrypt all traffic that is routed through them, along with proxying at the application-level that allows you to tell, say Firefox, to use your VPN. Linux also lets you create VPN connections for individual apps if you use network namespacing. Before Wireguard, I used use network namespaces with OpenVPN[2] to create individual tunnels for different apps, and it worked nicely. [1] https://en.wikipedia.org/wiki/TUN/TAP https://en.wikipedia.org/wiki/TUN/TAP [2] https://github.com/pekman/openvpn-netns https://github.com/pekman/openvpn-netns
- djrogers 6y agoRegular VPN clients that manipulate the default route still work like they always have, this particular issue is related to per-app VPNs, which are not nearly as common, and would generally not be used to redirect OS-native traffic anyway.
- wilt 6y agoThis type of crap is why I stopped using windows and macos. I don't want my security to be compromised because of some idiot in a suit making a bad call.
- dewey 6y agoSometimes these companies have a lot of resources to harden other parts of the system though so it'll always be a trade-off.
- totalZero 6y agoTrue, but that line of thinking assumes they will harden those things in favor of the customer/user. The article suggests that Apple may be exempting its own apps from user-defined network traffic protection measures in order to clamp down on geographical licensing loopholes, or to keep its app traffic out of VPN servers. Either case would be to the benefit of Apple and the detriment of the customer/user IMO.
- eeZah7Ux 6y agoNo, not at all, when compared to Linux.
- intricatedetail 6y agoI disabled all telemetry in Windows and use Glasswire to check what's up, but planning to add RPI with some extra traffic monitoring. Frankly this is untenable. Users shouldn't have to go to such lengths to protect their privacy. Apple and Microsoft need to be held accountable and ordered to delete all personal data harvested to which they cannot provide legitimate reason to have it.
- deleted 6y ago[deleted]
- izacus 6y agoWhat does Google's software have to do with an Apple issue? Is this a form of whataboutism or what's the actual point?
- mnahkies 6y agoI think their point is regardless of whether it's Apple, Google, Microsoft, etc the end user has increasingly little control over their devices. The only way to fix this in the long run is open platforms
- anaganisk 6y agoIt obviously states singling out apple in this not the way forward.
- gcbirzan 6y agoIt works for me, with block connections without VPN on android 10 (android one). Do you have a source for that?
- woahAcademia 6y agoRemember this when their ads touting privacy/security inevitability are presented to you. Apple marketing is disgusting.
- totalZero 6y agoYou're not kidding. From https://www.apple.com/privacy/ https://www.apple.com/privacy/ : Privacy is a fundamental human right. At Apple, it’s also one of our core values. Your devices are important to so many parts of your life. What you share from those experiences, and who you share it with, should be up to you. We design Apple products to protect your privacy and give you control over your information. It’s not always easy. But that’s the kind of innovation we believe in.
- deepstack 6y agoBig companies are disgusting in general!
- deleted 6y ago[deleted]
- blub 6y agoI'm glad that people are putting pressure on Apple to fix this and hope that they do. That being said, I think many comments here are out of touch. We're talking about a specialized security feature which is not easily available on other platforms is only used by a minority of users and still works for most programs. What exactly are your threat models that this is causing a problem for you? Are you sure that you can even use a mainstream OS if you need to block all outbound connections? If I had to have complete control over my outbound connections, I would use a hardware/software solution sitting between the computer and router. Secondly, is this really bypassing VPNs or only the new firewall API? e.g. is it bypassing WireGuard?
- kjaftaedi 6y ago>What exactly are your threat models that this is causing a problem for you? If I connect to a public wifi hotspot and use a VPN, I used to be under the general assumption that my network traffic would be sent through my network tunnel and not be accessible to other users of the same hotspot.
- tait 6y agoAgreed! One of the points of having a VPN is to be able to run software without every single middle man on the network knowing what you are running. For example, say someone hypothetically wanted to post a comment on twitter that, again, hypothetically, was politically inconvenient for some authority figure. The fact they launched twitter at about the time that comment was posted might be something they would prefer to not have reported on the internet at all, and certainly not without encryption. Generally, this falls into the general category of "I may disagree with what you say, but I will fight for your right to say it".
- srg0 6y ago> without every single middle man on the network knowing what you are running with a different chain of middle men, ftfy.
- blub 6y ago
- ReptileMan 6y agopocket router with DDWRT running and open vpn is my solution lately.
- m000 6y agoThat's actually a viable solution for Apple laptops. You're already carrying half a dozen adapters and dongles. One more wouldn't break your back.
- intricatedetail 6y agoApple could detect the VPN and brick the laptop.
- intricatedetail 6y agoBig Sur(veillance). This should be illegal.
- deleted 6y ago[deleted]
- pfortuny 6y agoSo, there is no software way to prevent this? This is as crazy as it gets, and totally unbelievable. So there are no true VPN apps in Big Sur at all? Or true firewalls? Honestly, this is so hard to believe that it cannot be untrue. They are totally sick at Apple.
- deepstack 6y agoApple is the new MS!
- deepstack 6y agoBy this I just mean it is general observation in company when they become large. If we are to support free market. Big companies are not be allowed to exist, it just encourage mon/dup/oli gopoly and hinter economic optimisation.
- EGreg 6y agoAND it is Big Brother in its “1984” ad. “We will prevail!” Ironic, isn’t it PS: Why don’t the people here combine forces and capital to create a video and privately registered website like apple1984.com (I think trademarks can be used for criticism, otherwise just use 1984 plus something) and actually run this ad to shame apple on various social media and youtube? DoubleTwist did. https://www.dmlp.org/legal-guide/using-trademarks-others https://www.dmlp.org/legal-guide/using-trademarks-others
- carlmr 6y agoOne of the issues I see with this is that the free market encourages companies to try to become a monopoly/oligopoly, because it's the only way to sustain profits in the normal idealized market models. So you can't support the free market and not allow big companies to exist at the same time. Instead I think it would be honest to say that we don't want free markets, because they have inherent issues that are detrimental to people. At the same time we don't want planned markets which have historically failed as well. Instead there must either be a better paradigm or a sweet spot in between (e.g. a well regulated somewhat free market).
- albeva 6y agoso much for their much hyped Safety and Security and Privacy ... Hypocrites. The whole Industry.
- acd10j 6y agoIt is possible that they are doing it on instructions of Chinese government under threat of ban. So every iphone even with vpn could be tracked.
- jazzabeanie 6y agoCould it be so that they can serve the app with the local authority’s backdoor?
- mantap 6y agoWe are getting towards the point where we will have to boot up into a full screen Linux VM because the outer operating system is too laden with crap like this (and secure boot).
- jmnicolas 6y agoShouldn't it be the opposite: have a Linux hypervisor that controls the network and a MacOS VM (or Windows for that matter)? A bit like what QubeOS does.
- mantap 6y agoThe new ARM Macs have "secure boot". I don't know how it will work exactly but I assume it's something that stops you from booting a different operating system. If not, I'm sure that's in the pipeline.
- zepto 6y agoWhy not just use Linux?
- xvector 6y agoWhy hasn’t Apple responded to this? What the hell?
- sqldba 6y agoIt hasn’t gotten a strong enough backlash. They commented on all the *gates and even the ocsp issue which reached mainstream media. But this is so low level (normal people don’t know or care about firewalls except it’s running, or understand why it’s bad for Apple to bypass it) that it won’t become big enough to get that kind of press and response. Once it’s exploited and has a pretty name, maybe.
- heavyset_go 6y agoThey spent millions of dollars plastering all sorts of media with ads about how much Apple loves privacy, and they figure that they can hire a few people to write articles explaining how it is actually good that Apple gets to decide what traffic should and shouldn't go through your VPN[1]. [1] https://news.ycombinator.com/item?id=25095438 https://news.ycombinator.com/item?id=25095438
- dirtiest-thing 6y agoLet me see... hu... Interesting example of fragmented pressure-group politics, not ? More generally... a few days ago, I watched TV (the old linear one... ^^) and sure there were some ads, mainly about food, caring (clothing, hygiene, room) and somehow 'imagecare' (cellphones and magically 'digital identity') ...um (to keep it short)... so let me ask, were all of the polarizing only serving as a use to sell something like "Inseldenken"? (-;
- ratsimihah 6y agoI see a bright future for Linux.
- supermatt 6y agoThis is another example of apples platform treating apple apps "preferentially" - one of the points raised in the ongoing appstore complaint. I can understand why they think they can do this - they create the OS, so you implicitly "trust" them - but that position doesn't mean you shouldn't be able to grant others that same trust, IMHO.
- intricatedetail 6y agoApple should be divided into separate independent companies. One for silicon, one for computers, one for phones and gadgets, one for screens, one for OS, one for app store and so on.
- zepto 6y agoIf your goal is to destroy them and return us to Microsoft era stagnation, then sure.
- intricatedetail 6y agoMicrosoft, Google, Amazon, Facebook and so on need to be split and also ordered to delete all personal data that they don't have legitimate need for.
- zepto 6y agoPerhaps so. It would be interesting to know how you would frame a law that defined ‘legitimate need’ doe data?
- olalonde 6y agoIf you're serious about using a VPN, I strongly recommend getting an OpenWRT capable router and setting up your VPN there. Some benefits: - It's physically impossible for your devices to bypass the VPN. - It also works with devices that have poor or non existent VPN support (e.g. Roku, smart TV, etc.). - You only have to configure it once vs having to configure it on all your devices. - You can easily and quickly toggle the VPN by switching to a Wifi that doesn't have VPN setup. I've been using GL.iNet's travel routers for many years and can't recommend enough (no affiliation other than being a customer). Just ordered their new Beryl router[0]. [0] https://www.gl-inet.com/products/gl-mt1300/ https://www.gl-inet.com/products/gl-mt1300/
- intricatedetail 6y agoI've tried this approach but often i would find traffic going down - especially YT and occassionaly router would crash. Frankly it's like 5 years old now. Are there any modern routers easily handling VPN?
- economusty 6y agoLinksys LRT224 has been great for me, I run a permanent VPN to my aws resources.
- zokier 6y agoI don't think age is factor here, routers shouldn't "crash" just because you push some bits through it, 5 years old or not.
- heavyset_go 6y agoThey are often not actively cooled and not build for high CPU usage and the heat that generates.
- gjsman-1000 6y agoExcept, what’s crazy is that they do. I have an ISP-provided Xyzel C1100 modem, and sometimes it does just randomly crash and take about a minute to reload if we’re doing to much. I’d buy a good DSL modem, but it happens just under the threshold where I’d buy a $100 modem to fix it.
- lxgr 6y agoBesides the privacy/security implications, this seems like it would also break these apps for all network topologies that only grant internet access through a VPN. Some universities used to (and probably still do) provide internet access over unencrypted Wi-Fi networks, with the VPN gateway as the only reachable host.
- dd82 6y agoits not a bug, its a feature!
- baq 6y agoStallman, for all his faults, predicted exactly this and fought an uphill battle to prevent it. If only there was money in GPL software to make it competitive on the desktop, not just usable. It's something that would have to happen out of taxpayer's purse, I'm afraid.
- chrisfinazzo 6y agoYet, those who tried to follow this ethos quickly discovered that the GPL requirements forced them to open up more than they wanted, including most things that made their products unique. If you can't have meaningful competitive advantage or differentiation, it's kind of hard to make money.
- Hizonner 6y agoNo, it's hard to make ridiculously out-of-proportion amounts of money, create artificial concentration, and deliver extended exponential growth of individual enterprises. And of course it's hard to even make a living when all your competitors are allowed "differentiation" and you're not. Which is what happens when a government sails in and starts granting monopolies. Copyright is an artificial monopoly. Patents are artificial monopolies. There are a bunch of weird people out there who call themselves "libertarians", but somehow favor the government creating such restrictions on people's liberty. They're confused and should be ignored. Trade secrets are perhaps slightly less artificial, but they are clearly destructive in an enormous number of ways. If, as lawgiver, one were to totally eliminate all imaginary property and outlaw commercial secrets, one could arrange a society where a lot of people could make a very nice living. It might be harder to become a tycoon. Which would be all to the good.
- zepto 6y agoI largely agree with you - we need to get past the notion of IP, but it’s a long where from where we currently are, and for all the problems with the current system, there are going to be problems with dismantling the IP regime. What is the first step?
- 6y ago
- lprd 6y agoI'm getting more and more incentive to just drop macOS and start using Linux as my daily driver. Apple has absolutely no excuse for this, and I hope they correct it. That said, I am curious which laptop brands today are most compatible with Linux. I've heard good things about Lenovo and Dell XPS. As for which flavor of Linux, I have my eyes on Arch...
- claudeganon 6y agoThinkpads: https://wiki.archlinux.org/index.php/Laptop/Lenovo https://wiki.archlinux.org/index.php/Laptop/Lenovo
- adkadskhj 6y agoAny thoughts on Purism or System76? I like the Thinkpads but i'm tempted to go Purism or System76 purely to support them.. but i don't want to do it at the cost of being dissatisfied with a lesser product.
- claudeganon 6y agoI haven’t used either. I’ve heard a fair amount of complaints about the build quality on System76s.
- vladvasiliu 6y agoCan't speak for all their models, but I've had success with HP. My work laptop is a ProBook 430 G5 and everything except for the fingerprint sensor works great. The G4 also worked well but I only tried it for a short period. I've only tried Arch, but I suppose Ubuntu should work too.
- acomjean 6y agoI looked into this a couple years ago for notebooks. Dell and Lenovo are pretty popular choices. Dell will pre install and I think Lenovo does now. I think desktops are easier to do your own install. I bought a system 76 which comes with Linux (Ubuntu or Popos). I’m using pop and things work (jet brains, bitwig, I compiled unreal engine..). Those machines are rebranded clevos (so they say) but I know drivers will work. Build quality is decent but the machine has lasted. It’s been good and pretty much maintenance free. The os updates frequently. My only complaint is the machine has 2 video cards and will only drive externals with the nvidia one. Switching requires a reboot. The battery life isn’t great when driving the nvidia card. Maybe the new ones fixed this (onyx pro)
- fbelzile 6y agoWell, this is great news for malware developers (including intelligence agencies)! Apple might as well just have said: "Here, malware developers, focus your efforts on these few apps. The payout when you find an exploitable vulnerability is fully unmonitored, unfettered access to the network (by default) to do as you please." This is beyond irresponsible. Apple knows there's going to be bugs in their code. Doing it anyway is completely hypocritical to their own privacy-focused marketing.
- blub 6y agoThis is irrelevant news for malware developers. How many people do you think are running Little Snitch? I'd be surprised if it's more than several tens of thousands out of tens (hundreds?) of millions of machines. Such an application is extremely annoying for normal users.
- amelius 6y ago"Apple appliances are not allowed in this building. You can leave them in the bin next to the umbrellas. Thank you."
- lmilcin 6y agoYou need to understand, when buying this kind of device, it is not yours. It may be convenient, shiny and powerful, but somebody else decides what it does and that means you are not in control. The hardware may be outstanding and the OS could have been top choice for me if only I knew it is my machine. As it is not the case, I will be sticking to Linux laptop for good and bad.
- zepto 6y agoIt is yours. However, every other point you make here is accurate.
- lmilcin 6y agoIt is mine in name only. It is like a private bedroom where somebody else can come at any moment and inspect any aspect of my life and I can't stop him and sometimes I can't even know he is inspecting me at the moment.
- zepto 6y agoWell that’s obviously a total exaggeration. Yes, there is some information leakage, but nothing like ‘inspecting any aspect of your life’. But more to the point, you own the computer. You chose the operating system. If you don’t like what it does, buy something else. You can sell the one you don’t like, because it is yours. It’s as simple as that.
- wizee 6y agoApple apps do bypass NEFilterDataProvider (used by application firewalls like Little Snitch), and the per-app VPN mechanism (using NEAppProxyProvider). Thus, per-app VPNs can't be applied to Apple applications, but per-app VPNs were never intended to globally intercept traffic. Claiming that Apple apps bypass (all) VPNs in Big Sur is deceptive - they only bypass per-app VPNs that were never intended to cover all system traffic in the first place. Traditional VPNs that cover the whole system and route traffic based on destination IP (such as OpenVPN in UTUN mode) use the Packet Tunnel Provider in Destination IP mode. To the best of my knowledge, global VPNs routing based on destination IP (ie. non per-app VPNs) still route traffic from all applications, including Apple ones. See this for more details on the Packet Tunnel Provider: https://developer.apple.com/documentation/networkextension/netunnelprovidermanager https://developer.apple.com/documentation/networkextension/n...
- lifty 6y agoWhat about firewalling? Do you know if there is a way to setup a system wide firewall that doesn’t exclude Apple processes?
- xenadu02 6y agoApple apps bypassing NEFilterDataProvider on macOS is a bug.
- wizee 6y agoThe PF (BSD Packet Filter) firewall built into Mac OS covers apple processes. However, I don't think its interfaces are sufficient to implement the functionality of Little Snitch. The new-ish NEFilterDataProvider API used by Little Snitch on Big Sur is neutered by allowing Apple apps to bypass it.
- floatingatoll 6y agoYou are correct. I tested several of the normal ‘whole-system’ VPNs on Big Sur last week when this misleading headline came out and Apple traffic was correctly routed over the VPN in each case. (Both the built-in macOS VPN client and third-party tuns such as Viscosity, etc.)
- xbar 6y agoColor me depressed. I was hopeful to switch to Apple silicon. This architectural decision alone is enough to make Big Sur and its successors a permanent non-starter.
- Zetaphor 6y agoSerious question, what does Apple offer that brings people back to them after an event like this, or the last one, or the one before that? You can't customize the OS, the software for the platform is available on Windows and Linux, and the hardware is overpriced and underpowered, and then there's stuff like this where Apple decides how you should use _your_ computer. I sincerely do not understand why anyone would ever purchase an Apple computer, and yet here we are, again. Especially confusing to me is how many of my fellow web developer peers I see choosing Apple devices over literally any other laptop with Windows or Linux which will run circles around a Macbook of the same price range.
- Jackim 6y agoThis hasn't always been the case, but high-quality hardware and long battery life have been big attractors for me. I've never used a trackpad on a non-Mac laptop that has been comparable to Macbooks.
- stryker7001 6y agoDoes this really matter to anyone except a select few people? Thats the issue I see here over and over. Missing the forest for the trees. No solution is perfect, but there's a feeling of exceptionalism that permeates this website.