3 ms·
> Honestly this seems entirely reasonable I want to agree with your optimistic view of this, but I can't, because I don't think reason was used in making the d
by ayyy 6y ago
> Honestly this seems entirely reasonable
I want to agree with your optimistic view of this, but I can't, because I don't think reason was used in making the decision.
I think the reality is probably closer to this:
Product: "so we can't let users block our own apps. it might break things in weird ways and also they implicitly trust us already because we make their OS".
Engineers on the application firewall team: "ok cool, we'll disable users from blocking Apple apps".
Any freedom you're enjoying with PF isn't there because Apple decided it was a good idea. It's there because Apple decided to build on BSD.
I'm actually surprised MacOS even has PF (apparently since 2015, enhanced from other BSD implementations). I did a minimal amount of searching and found this now-relevant gem: https://manjusri.ucsc.edu/2015/03/10/PF-on-Mac-OS-X/ https://manjusri.ucsc.edu/2015/03/10/PF-on-Mac-OS-X/
> If two firewalls, Application Firewall & PF, are both running, you may wonder whose rules take precedence. Let’s find out.
> ...
> So one can conclude that PF rules are applied first, then the rules for Application Firewall.
- lilyball 6y ago> Any freedom you're enjoying with PF isn't there because Apple decided it was a good idea. It's there because Apple decided to build on BSD. It’s there because Apple decided it was a good idea. If they didn’t think it was a good idea, they wouldn’t have included it. Your next sentence even implies this when it admits that Apple’s inclusion of PF is only a few years old. > I'm actually surprised MacOS even has PF (apparently since 2015, enhanced from other BSD implementations).
- ayyy 6y agoIt's not like PF was billed as a hot new feature of the OS. I believe it's a happy accident that we got PF, and I won't be shocked if it goes away in the future. Especially now that it's been publicly documented that it can block Apple apps.
- derbOac 6y agoThe fact that all of this still has had to be deduced ad hoc in some reverse engineering-type paradigm also should give anyone pause. The fact packet filtering works is better than if it didn't but that's almost besides the point. The problem is Apple deliberately obfuscating important security details from the user. It's literally asserting privilege of itself over the user/device owner in an essential way, if not entirely through filtering protocol than through informing about the protocol.