7 ms·
Threre are no indications that Apple is willing to compromise and allow application firewalls to block Apple softwares that Apple believes should be able to acc
by webmobdev 6y ago
Threre are no indications that Apple is willing to compromise and allow application firewalls to block Apple softwares that Apple believes should be able to access the internet, even if the user doesn't want it too.
It's a gross invasion of privacy, and a security risk.
(By the way, even in Lulu, some Apple system software - apsd, automount, helpd, mDNSResponder, mount_nfs, mount_url, ocspd, sntp, trustd - are whitelisted and cannot be blocked by the user even if they want to, and that's bit disappointing).
- pydry 6y agoDoes this mean Mac users are not really root on their own machines?
- terramex 6y agoUsers can develop and install custom kernel extensions (.kexts) that can access everything, but they first need to disable System Integrity Protection in recovery mode. Over the years Apple expanded their frameworks library to reduce need for custom .kexts, but they are still supported even on M1 Macs (as long as they are compiled for ARM64). So to answer you question - 'root' user on macOS is by default not a true root in unix sense, but can be trivially turned into one by booting computer in recovery mode and running single command in Terminal. Restart into recovery mode is required so that malicious applications cannot change it on their own, even if they would use unknown privilege escalation technique.
- filleduchaos 6y agoIt's honestly mind-boggling how many people whine and complain about macOS not "letting" them do this or that when they can turn off virtually every one of their gripes in about two minutes. The most egregious was someone complaining that /bin and other system folders are read-only [on systems under System Integrity Protection]. Surely anybody with a pressing desire to e.g. upgrade their bash install or any other thing that requires write access to those folders is also capable of figuring out how to turn off SIP?
- danieldk 6y agoIt's honestly mind-boggling how many people whine and complain about macOS not "letting" them do this or that when they can turn off virtually every one of their gripes in about two minutes. It it too much to ask to have the normal security protections that macOS provides and still being able to block Apple services with Little Snitch or Lulu or letting Apple services go through a VPN as well?
- deleted 6y ago[deleted]
- bergstromm466 6y ago> It it too much to ask to have the normal security protections that macOS provides and still being able to block Apple services with Little Snitch or Lulu or letting Apple services go through a VPN as well? This. Apple is making the use of many security functions black or white: either you allow complete control by Apple, or you have little to no protection at all. Instead they could easily allow the user to customize, and make a selection that works for them (which was the standard in older versions of OSX - pre-Big Sur [1]). The above defending of a giant faceless corporation, by @filleduchaos, is what is mind-boggling. This feature obviously helps protect some users (non tech-literate ones), but for many it means completely turning off many useful security features ('opting out' by turning off SIP) with a lack of any sort of granular control/customization, on a device they supposedly own. It's a shame this new capitalist encroachment on user privacy is met with such understanding. [1] https://news.ycombinator.com/item?id=25078034 https://news.ycombinator.com/item?id=25078034, https://sneak.berlin/20201112/your-computer-isnt-yours/ https://sneak.berlin/20201112/your-computer-isnt-yours/
- vezycash 6y ago>Apple is making the use of many security functions black or white: either you allow complete control by Apple, or you have little to no protection at all. In that respect, no Apple's no different from Facebook's "agree to share your data or take a hike" move with WhatsApp
- lovelyviking 6y agoWhat is point then to have such app all? if you can’t control _all_ connections then it appears useless. What is the proper solution? Something on router? Is there a way? Can Openwrt do the job of protecting privacy properly?
- noname120 6y ago“This solution is not completely perfect so it's absolutely worthless”.
- eternalban 6y ago"This lock doesn't really prevent unauthorized access to this room but you know, 'perfect is the enemy of good!'"
- SamBam 6y agoThat excessive. Installing a lock to which the building owner owns a key is still an improvement over not installing a lock at all. There's a difference between "All your connections are wide open, so any malicious or compromised software can connect to the web" and "Apple can connect to the web, so you have to decide whether to trust Apple." I mean, if you're on a mac and you don't trust Apple not to be secretly keylogging your passwords or something, I think a firewall isn't going to help you.
- eternalban 6y agoOh, the comment was only addressed to GP and a misused meme. It is -not- a comment on LuLu or the substantial and valuable contributions and efforts of the developer in question. Hats off to him. https://www.objective-see.com/ https://www.objective-see.com/
- hobs 6y agoAs the solution worked before and they purposefully broke it, your statement is just idiotic.
- vimy 6y agoIt’s one of their weirder decisions. You can’t claim to be privacy king while simultaneously doing something like this. Maybe this is caused by Apple departments being siloed. The privacy champions are in a different silo?
- blauditore 6y agoI have the impression that Apple's privacy marketing was just an opportunity grab because they noticed they were doing slightly better than competitors. The recent reveal of MacOS calling home and lack of any significant reaction is a strong indicator this was all just lip service.
- webmobdev 6y agoSpot-on - it is just a lip-service, and initiated after Jolla launched its Sailfish OS phone. Jolla was started by a bunch of ex-Nokia engineers who were working on the next-gen mobile OS, before Microsoft scuttled it. The Jolla phone outsold the iPhones in some countries in Europe when it was launched ( https://www.gsmarena.com/jolla_outsells_iphone_5c_and_iphone_5s_at_finnish_carrier_dna-news-7464.php https://www.gsmarena.com/jolla_outsells_iphone_5c_and_iphone... ). Unfortunately, they couldn't maintain their momentum and had to get out of the business of making phones. (They still make their mobile OS, and you can buy a license for it and install it on some Sony phones). At that time, Apple even had an ad-network for apps, and had got embroiled in the PRISM scandal (Apple, and other American corporate were selling their users data to US government agencies - https://www.theguardian.com/world/2013/jun/06/us-tech-giants-nsa-data https://www.theguardian.com/world/2013/jun/06/us-tech-giants... ). Jolla was marketed with a focus on privacy. To counter the bad publicity and the threat from a potential startup, they partly shut-down their ad-network ( https://appleinsider.com/articles/16/01/15/apple-to-shut-down-iad-app-network-on-june-30 https://appleinsider.com/articles/16/01/15/apple-to-shut-dow... ) and started marketing their new found love for privacy. But from the get-go, it was never about user privacy - their goal was to ensure that the users data remained siloed within their eco-system, and their competitors couldn't get access to it. They also used the "privacy" angel as an excuse to further close down their devices, and make it incompatible with anything not approved by them. (Note that it was due to their ad-network and because Apple wants access to users data that iPhones / iPad don't give you the ability to control what app can or cannot connect to the internet. This is still the case, except if you are on cellular data; if you are on Wifi though, an app cannot be blocked. While all the new labeling "transparency" feature and telling the user what data an app will gather from you is good, the feature that would really benefit every one better is the ability to block apps from connecting to the internet itself in the first place!).
- miles 6y ago> some Apple system software ... are whitelisted and cannot be blocked by the user even if they want to There are currently 3 ways I know of to block them: 1. Exclusions Blaster https://www.vallumfirewall.com/eblaster/ https://www.vallumfirewall.com/eblaster/ 2. Enabling Little Snitch 4.6 kext under Big Sur https://www.obdev.at/support/littlesnitch/245913651253917 https://www.obdev.at/support/littlesnitch/245913651253917 3. Convoluted hack: https://tinyapps.org/blog/202010210700_whose_computer_is_it.html https://tinyapps.org/blog/202010210700_whose_computer_is_it....
- Wowfunhappy 6y agoOh neat, they're still maintaining Little Snitch 4 for Big Sur for people who want a kext and don't mind approving it. They say "that option could go away at any time", but that would require Apple to make SIP mandatory, and I still don't see that happening. There may come a time, however, where you need to actually disable part of SIP.
- FabHK 6y agoCould you enlighten me what the gross invasion of privacy and the security risk is for the majority of users that do not hack their machine in a way that prevents those connections? I'm aware of Gatekeeper checking developer certificates upon opening apps over an unencrypted connection (so far; Apple is fixing that), but not sure where the gross privacy invasion or security risk is (in particular compared to existing alternatives, not some platonic ideal). Here, FWIW, is what Apple says about Gatekeeper and Notarization. I'd be eager to hear any evidence that this is incorrect. > Gatekeeper performs online checks to verify if an app contains known malware and whether the developer’s signing certificate is revoked. We have never combined data from these checks with information about Apple users or their devices. We do not use data from these checks to learn what individual users are launching or running on their devices. > Notarization checks if the app contains known malware using an encrypted connection that is resilient to server failures. > These security checks have never included the user’s Apple ID or the identity of their device. To further protect privacy, we have stopped logging IP addresses associated with Developer ID certificate checks, and we will ensure that any collected IP addresses are removed from logs. > In addition, over the the next year we will introduce several changes to our security checks: * A new encrypted protocol for Developer ID certificate revocation checks * Strong protections against server failure * A new preference for users to opt out of these security protections https://support.apple.com/en-us/HT202491 https://support.apple.com/en-us/HT202491
- webmobdev 6y ago> Could you enlighten me what the gross invasion of privacy and the security risk is for the majority of users The same reasons that people use application firewalls on their system - Access to our personal data by Apple - intentionally or "accidently". Malware may be able to hijack Apple whitelisted softwares to do their mischief. (And please don't reply by saying we can "trust" Apple with our data - I don't, and if I have paid for a computer I consider it mine, not Apple's to meddle with it as they please). As for the Gatekeeper incident, the only comment I have to add is that I really don't care about Apple's "apology" after they have been caught ...
- acdha 6y ago