12 ms·
It also means Tor can no longer exist on the Mac. What a sad day for privacy.
by mantap 6y ago
It also means Tor can no longer exist on the Mac. What a sad day for privacy.
- pfortuny 6y agoTotally irresponsible. There is no way I can understand this policy. Impossible. What, are they working with someone? Five eyes? China? Spain? The Soviet Block? Honestly, this is either utter imbecility or straight ill-will. There are no greys here. At all. When you do a think like this either you are stupid or you DO know the risks and are OK. Great: now people in Hong-Kong cannot use Big Sur because they should be afraid of the apps they are using.
- BlueTemplar 6y agoRemember that we have no idea whether Windows and Intel processors with IME (and AMD processors since Ryzen ?) don't have built-in backdoors (And Macs have been using Intel exclusively for years now, haven't-they ?). So nothing very new here, really... https://blog.invisiblethings.org/papers/2015/x86_harmful.pdf https://blog.invisiblethings.org/papers/2015/x86_harmful.pdf
- tpush 6y agoApple disables most of Intel's ME [0]. [0] https://support.apple.com/guide/security/uefi-firmware-overview-seced055bcf6/web https://support.apple.com/guide/security/uefi-firmware-overv...
- BlueTemplar 6y agoInteresting... though they don't give a date. Was it 2006, 2017... a gradual process since 2006 ?
- chungus_khan 6y agoIt's still in use for DRM though apparently, and so long as it still runs, and so long as we still can't audit it, it isn't trustworthy from a strict privacy perspective.
- jaywalk 6y agoI don't believe the IME has anything to do with DRM. That would be TPM.
- chungus_khan 6y agoFrom the above linked Apple page: > The primary use of the ME is audio and video copyright protection on Mac computers that have only Intel-based graphics.
- syshum 6y ago>>There is no way I can understand this policy. I dont now why. this is has been apple's stated position for a long time and the primary reason they are moving to ARM for the Mac, to make them more iDevice like, meaning you do not own the computer, they do, and you can only use it in a manner they (Apple) allows and bless. Apple has been moving away form the professional / hacker market for a long time, they want to sell to normal consumers and could give a shit less about the pro or hacker market.
- coldtea 6y agoBesides the general hand waving that doesn't mean much ("make them more iDevice like", "you don't own your computer, they do") which doesn't say anything, the parent is talking about this particular decision. As for "you don't own your computer, they do", what it translates to is: "The OS places certain restrictions that work and make it safer for the large majority of users, but might not give full tinkering abilities to everybody". Which you never have (full tinkering ability) in a closed source OS, anyway. While "we bypass firewalls for our domains" can be thought of in the same vein ("we think it's better and safer for most users to work this way, and leads to less head-scratching why X Apple service doesn't work etc"), it's not exactly the same. Apple can go towards the "no tinkering direction, it's a device that just works", without disallowing preventing user firewalls from blocking Apple domains (provided of course the user understands that by blocking them they get no iCloud and other services). >Apple has been moving away form the professional / hacker market for a long time, they want to sell to normal consumers and could give a shit less about the pro or hacker market. On the other hand, the pro market (video, music, graphics, office, programming, writing, data analysis, etc) shouldn't have workflow issues with what Apple did, and the hacker market is small (and has never been a target market).
- syshum 6y agoI think a large amount of people will disagree that these OS restrictions work or make it safer, but that is really besides the point There is a HUGE difference between passive secure defaults, which a normal user will never change, and active blocks / overrides that can not be removed. An example of this is iphone vs android store policy, by default on Android you can not install untrusted APK's or other stores, however inside the phone there is a simply way to disable this block. This is an example of a passive secure default. Where on iPhone it is simply impossible to disable this block One OS (android) is respecting your ownership rights while protecting the normal users, the other (iOS) is asserting their ownership over the device. Surely you can see the difference it is clear that apple intends to bring this type of Active Ownership control to the Mac ARM platform, this is just the first step, a warning shot if you will, of what is to come
- claudeganon 6y ago> What, are they working with someone? Five eyes? China? Spain? The Soviet Block? Yes: Apple canceled their plans to fully encrypt iCloud data after the FBI complained: https://www.reuters.com/article/us-apple-fbi-icloud-exclusive/exclusive-apple-dropped-plan-for-encrypting-backups-after-fbi-complained-sources-idUSKBN1ZK1CT https://www.reuters.com/article/us-apple-fbi-icloud-exclusiv... In the Vault 7 leaks, Little Snitch was something specifically mentioned as being difficult to circumvent. Now, the ability to bypass it is baked into the OS: https://blog.obdev.at/little-snitch-on-vault-7/ https://blog.obdev.at/little-snitch-on-vault-7/ They moved iCloud keys to Chinese servers so the CCP could continue their surveillance: https://www.reuters.com/article/us-china-apple-icloud-insight-idUSKCN1G8060 https://www.reuters.com/article/us-china-apple-icloud-insigh... During the protests in Hong Kong, Apple took down apps that let people crowdsource tracking of police: https://www.nytimes.com/2019/10/09/technology/apple-hong-kong-app.html https://www.nytimes.com/2019/10/09/technology/apple-hong-kon...
- BlueTemplar 6y ago> Apple said it decided it was better to offer iCloud under the new system because discontinuing it would lead to a bad user experience and actually lead to less data privacy and security for its Chinese customers. Also very relevant that VPNs seem to be illegal in China. And Apple forced the hand of Telegram to shut down the channels revealing the names of Belarus police.
- wwwwwwwww 6y ago> Also very relevant that VPNs seem to be illegal in China. How illegal are they currently? When I lived there, they were illegal too, but still everybody would use them. There was always a difference between "illegal by law" and "really illegal".
- jacobush 6y agoThe judiciary is not independent, so it's a moot point anyways. VPN use will just be used as another signal that you are possibly an enemy of the state.
- templain 6y agoimagine believing that VPNs grant privacy
- jmnicolas 6y agoSpain? Since when are they on our watch list? :)
- michaelt 6y agoPerhaps pfortuny is expecting the Spanish Inquisition?
- deleted 6y ago[deleted]
- Mordisquitos 6y agoBeing somewhat aware of current affairs in Spain and having dealt with Spanish administrations' digital services and platforms in multiple different contexts, I would be honestly very surprised if they were able to unilaterally agree any kind of deep backdoor conspiracy with a large tech company–let alone effectively implement it.
- blub 6y agoWhat does Tor have to do with anything, I thought it was just a normal app which routes its connections by itself?
- pfortuny 6y agoThe thing is... You use tor because you think you can prevent ALL of the traffic from being visible (similar to a VPN). Now you cannot trust the kernel not to reveal anything to Apple.
- MagnumOpus 6y agoAnd by "reveal to Apple" he means "reveal to every bent cop who's listening in on the wire that you wanted to avoid by using a VPN"
- tpush 6y ago?? This was always possible and has nothing to do with Apple exempting their apps from the firewall and VPNs.
- pfortuny 6y agoNo: you can trust a kernel or you cannot. “all this traffic must go this way”... Kernel: I don’t care. There is no meaningful tor under those conditions.
- blub 6y agoLast time I checked Tor was managing its own encryption and routing without relying on any macOS VPN or firewall API. Several years ago it was making direct connections to various IPs and sending the encrypted information. It makes no sense for Tor to use those APIs since they're designed for other use cases.
- blub 6y agoTor browser only routes its own traffic through the Tor network. By the time that traffic hits the kernel it should already be encrypted.