5 ms·
Apple apps do bypass NEFilterDataProvider (used by application firewalls like Little Snitch), and the per-app VPN mechanism (using NEAppProxyProvider). Thus, pe
by wizee 6y ago
Apple apps do bypass NEFilterDataProvider (used by application firewalls like Little Snitch), and the per-app VPN mechanism (using NEAppProxyProvider). Thus, per-app VPNs can't be applied to Apple applications, but per-app VPNs were never intended to globally intercept traffic. Claiming that Apple apps bypass (all) VPNs in Big Sur is deceptive - they only bypass per-app VPNs that were never intended to cover all system traffic in the first place.
Traditional VPNs that cover the whole system and route traffic based on destination IP (such as OpenVPN in UTUN mode) use the Packet Tunnel Provider in Destination IP mode. To the best of my knowledge, global VPNs routing based on destination IP (ie. non per-app VPNs) still route traffic from all applications, including Apple ones.
See this for more details on the Packet Tunnel Provider: https://developer.apple.com/documentation/networkextension/netunnelprovidermanager https://developer.apple.com/documentation/networkextension/n...
- lifty 6y agoWhat about firewalling? Do you know if there is a way to setup a system wide firewall that doesn’t exclude Apple processes?
- xenadu02 6y agoApple apps bypassing NEFilterDataProvider on macOS is a bug.
- wizee 6y agoThe PF (BSD Packet Filter) firewall built into Mac OS covers apple processes. However, I don't think its interfaces are sufficient to implement the functionality of Little Snitch. The new-ish NEFilterDataProvider API used by Little Snitch on Big Sur is neutered by allowing Apple apps to bypass it.
- floatingatoll 6y agoYou are correct. I tested several of the normal ‘whole-system’ VPNs on Big Sur last week when this misleading headline came out and Apple traffic was correctly routed over the VPN in each case. (Both the built-in macOS VPN client and third-party tuns such as Viscosity, etc.)
- xvector 6y agoCould you let us know which whole-system VPNs worked for you?
- floatingatoll 6y agoNo, sorry. My testing was not a comprehensive assessment of macOS-compatible VPN services and my selection was biased towards breadth of implementations disregarding all other criteria. It would be inappropriate for me to recommend any of them as I did not assess for quality of app, support, billing, or privacy. If it adds a default route to your routing table when you connect, it's fine. If it offers fancy per-app traffic rules, it's probably not fine.
- unethical_ban 6y agoYou made a conclusion statement on an experiment, then denied a request for information on your methods.
- artificial 6y agoThis situation reminds me heavily of the Simpsons. I can't stop thinking about this: "Aurora borealis this time of year?" https://www.youtube.com/watch?reload=9&v=Rj0Tj8dnrYw https://www.youtube.com/watch?reload=9&v=Rj0Tj8dnrYw
- floatingatoll 6y agoD'oh! (See elsethread.)
- grupthink 6y agoI feel the same. I'm confused as to why this was downvoted by HN. Could someone clue us in?
- snowwrestler 6y ago
- thdrdt 6y agoIf so many people are confused by this, aren't VPN settings per app not insecure by default? It looks like a lot of people are under the assumption that enabling VPN means system wide.
- wizee 6y agoPer-app VPNs have existed for some time, and their use case is different from system-wide VPNs. Typically, per-app VPNs are used when you want to grant specific applications access to resources on say a corporate VPN, without granting all applications access to the VPN. Per-app VPNs are also useful if you want to protect a specific app's communications through an encrypted tunnel without affecting the rest of the system. More info on the purpose of per-app VPNs: https://support.apple.com/en-us/guide/deployment-reference-ios/apdfbf6f529b/web https://support.apple.com/en-us/guide/deployment-reference-i...
- AlexandrB 6y agoThe problem is per-app firewalls used to be able to block all apps/traffic equally. Apple then deprecated/discouraged the KEXT mechanism these firewalls used in favour of NEFilterDataProvider which, as you described, is clearly an inferior solution. You can't claim that these apps were not meant to do the very thing they used to do until Apple made such operation effectively impossible.
- wizee 6y agoI'm talking about VPNs, not firewalls. This article (and people in general) are claiming that Apple applications bypass VPNs, and falsely implying that system-wide VPNs are no longer possible in Big Sur. NEAppProxyProvider was never meant for system-wide VPNs. NEPacketTunnelProvider, the system-wide VPN mechanism (when used in destination IP mode), continues to route system-wide VPN traffic, including that of Apple applications. I'm not denying that NEFilterDataProvider is an inferior solution for per-app firewalls like Little Snitch, compared to their previous kernel extension.
- AlexandrB 6y agoI think you're right, the article definitely oversteps its bounds and ends up claiming that Apple apps can bypass all VPNs and firewalls. The correct summary of the situation is probably the first tweet in the article: > Some Apple apps bypass some network extensions and VPN Apps. Maps for example can directly access the internet bypassing any NEFilterDataProvider or NEAppProxyProviders you have running But then the article sloppily goes on to say: > What Wardle found is that the Mac App Store on the latest macOS bypasses any firewall. (emphasis mine)
- dang 6y agoOk, we've added the quantifier 'some' to the title above.