5 ms·
>The big question though is why the company’s doing this. So far, it hasn’t said why Apple apps on Big Sur are exempt from firewalls and VPNs, but there are som
by gvv 6y ago
>The big question though is why the company’s doing this. So far, it hasn’t said why Apple apps on Big Sur are exempt from firewalls and VPNs, but there are some theories.
I'm also genuinely curious, what is the main benefit of doing this and if it's done by design.
- martin_a 6y agoThis is probably the first step of being able to fully enforce geo-blocking, censorship or other legal requirements on Mac OS users without any way around.
- logicchains 6y agoI'm not a network person, but couldn't this be relatively easily bypassed just by running the VPN on the router?
- httgp 6y agoYes, but this isn’t an option that is readily available to everyone.
- quyleanh 6y agoYes, you can. However with average user, config router with VPN, proxy is a bit complicated. Bypass firewalls and VPNs on macOS is still terrible by the way.
- totalZero 6y agoYou can't run the VPN on the router if you don't own the router, which means that you can't protect your device's traffic when you're on the go, using mobile hotspot, or connecting to an ISP-supplied gateway without additional hardware.
- logicchains 6y agoIf I have a second phone (e.g. Android( running a hotspot, and I enable a VPN on that phone, will the hotspot / shared internet also go through the VPN, or will the hotspot bypass it?
- totalZero 6y agoWith my device and mobile service provider, the hotspot traffic does not route through the VPN that is active on the Android handset.
- BlueTemplar 6y agoFrankly, a fixed "Internet" Service Provider that doesn't provide you with a router (and leaves you the possibility to use your own) and a /48 IPv6 prefix should have no legal right to call that service "Internet" (in a similar way that Internet neutrality has to be legally respected) : https://www.ripe.net/publications/docs/ripe-690 https://www.ripe.net/publications/docs/ripe-690 (Mobile cellular Internet seems to be harder, but is there any reason why user's cell-'modem' can't handle the routing of successive /64 connections ?)
- sligor 6y agoIt only works at home. Or you need to always have and take your "router-in-the-middle" wherever you go, this is a way more complicated solution
- flower-giraffe 6y agoIn the future I think the tech savvy will be doing exactly that - pinefone as a wireless hotspot with wireguard to a anonymised proxy.
- kukx 6y agoYou can always put a vpn before mac eg using some Cisco or Linux based. Although it is obviously more complicated and expensive.
- w0utert 6y agoIf this Apple firewall nonsense sticks I can see a market emerge for self-contained USB ethernet/wifi dongles that incorporate a built-in router/firewall with VPN functionality. You could build something like this yourself using an rPI or something similar, but my feeling is there could be a sizable market for a small & cheap off-the-shelf device you just plug in.
- minxomat 6y agoEvery router I have seen in the past decade has had at least basic VPN functionality built in (L2TP/PPTP).
- w0utert 6y agoYes, but it's only useful when connected to your home LAN where you have control over the router, and even then only if you know how to set it up. Edit: also not sure if the router I got from my ISP (which I don't use, but I guess 99% of their other customers do since it is non-trivial to replace without losing IPTV) would allow me to configure it as a VPN gateway. Pretty sure it won't considering they try to lock it down as much as possible.
- BlueTemplar 6y agoHow does it work with IPv6, where there is no (need for) LAN (unless maybe if you're a huge company) ?
- silon42 6y agoI'd do the reverse, block any internet access unless it's over a VPN gateway. Additionally, block anything by default that wasn't looked up over my DNS proxy and/or uses HTTPS without SNI...
- sundvor 6y ago... for your own safety.
- blueblisters 6y agoI wonder what enterprises with managed macbooks would think about this. Internet traffic has to be routed through the company firewall in some corporate networks and this restriction will likely cause the company to ditch Apple.
- martin_a 6y agoI already thought the same. Our IT department is probably happy to get rid of the two handful of Mac systems once they have "proof" that those are undermining the network security (when the people use them from mobile hotspots or at home).
- solarkraft 6y agoI have a feeling that Apple likes to give its apps special treatment just to remind everyone that they can (why that is however I don't know, maybe begging for regulation?). I wouldn't be surprised if there are still apple apps installed as system apps on iOS that could just come through the store or are using some special Apple-only API to do something trivial.
- unicornfinder 6y agoMy suspicion is because they decided there was a possibility of a malicious app trying to intercept / block the connections.
- LoathsLights 6y agoI'm not sure how it is on Mac, but on Windows if you've ever used an app that can block network connections, and limit other applications. What is to stop any other app on your computer doing the exact same thing. As far as I've understood any app has access to any other app and the whole environment is just a warzone of apps where you have to trust every app completely to be okay with running it.
- dawnerd 6y agoSo there’s solutions to this. They could show a notice asking the user what they would like to do. Something like “there’s a problem connecting to the internet: cancel | try without vpn”