11 ms·
I am glad that the public backlash forced them to fix a deliberate BACKDOOR that they had introduced (by design) in the Network Extension Framework that macOS B
by webmobdev 6y ago
I am glad that the public backlash forced them to fix a deliberate BACKDOOR that they had introduced (by design) in the Network Extension Framework that macOS Big Sur now forces all the firewalls to use. (At least, they claim to have removed it). But it is hard to trust them again, and I would prefer to use a firewall that uses its own kernel extension to manage the network than using Apple's API again. (Obviously that's going to be really hard with the changes they have made to the OS).
I know many Apple's fan see this as a positive move.
But let's not ignore the pattern of privacy violations and user data collections due to deliberate design and the "apology" and "changes" that follow once CAUGHT. A few of these that immediately come to mind are:
- Apple selling user data to US government: https://www.theguardian.com/world/2013/jun/06/us-tech-giants-nsa-data https://www.theguardian.com/world/2013/jun/06/us-tech-giants...
- Apple iPhone 11 tracks user location even when location services are explicitly turned off by user (another BACKDOOR): https://www.silicon.co.uk/mobility/smartphones/apple-iphone-collects-location-data-321509?cmpredirect https://www.silicon.co.uk/mobility/smartphones/apple-iphone-...
- Apple macOS tracks every app that you use: https://sneak.berlin/20201112/your-computer-isnt-yours/ https://sneak.berlin/20201112/your-computer-isnt-yours/
- Apple introduces BACKDOOR in its API to allow Apple apps to bypass application firewalls: https://www.patreon.com/posts/hooray-no-more-46179028 https://www.patreon.com/posts/hooray-no-more-46179028
(For those who want to diss me for the above, realise that Apple's new found love for privacy doesn't mean shit without such public scrutiny and discussions. And if you want it to last, remain suspicious and VOCAL on any such possible violations.)
- conistonwater 6y agoWhy do you call it a deliberate backdoor when the Apple developers (see elsewhere in this thread) have said this was a bug?
- kristofferR 6y agoYou don't create a whitelist system literally called ContentFilterExclusionList by accident.
- zaphirplane 6y agoA backdoor has some malicious connotations to me. Having security profiles controlled by a list seems a thing Without spending a lot of time sshd has allowLists (AllowGroups) and match directives Sudo also has per group config As a user on any operating system what you can and can’t do is controlled by a list Perhaps the issue is the list isn’t user controlled ? Perhaps the issue falls into the “I own and control my device” vs “we sell you a safe, foot gun safe, easy to use device (in their opinion)”
- jakubp 6y agoIf they claim "here's the API you can use to control network access" but can then put arbitrary apps to work around that, that's the definition of backdoor access to the device.
- zaphirplane 6y agoI’m not supporting their approach. Why can’t this be thought of as a control API with a built in allow list ? Where the list is hidden by obscurity
- yarcob 6y agoA "back door" is any kind of mechanism that was added by the vendor to circumvent security mechanisms. Back doors are typically not disclosed to the user, and can't be turned off. So for example an automatic software update mechanism isn't a back door, as the user is aware of it and can typically turn it off if they are concerned about security. An undisclosed mechanism that allows Apple apps to circumvent firewalls does very much fit the description of a back door. Intent doesn't matter with regards to back doors. Most back doors are not made with malicious intent, or at least the vendors usually claim that they only had good intentions for the back door. (Eg. see the recent reports where a router manufacturer had a secret password that they claimed was only used for software updates) The danger about back doors is that malicious software can use the back doors to circumvent the security measures, just like Patrick Wardle demonstrated that it was possible to use Apple's content filter exclusion to circumvent firewalls.
- felipelemos 6y agoHow a 'ContentFilterExclusionList' creation can be a bug? Somebody hit the wrong keys by mistake and nobody noticed during the pull request review?
- jansan 6y agoEntirely possible if an infinite number of monkeys type along on an infinite number of keyboards. https://en.wikipedia.org/wiki/Infinite_monkey_theorem https://en.wikipedia.org/wiki/Infinite_monkey_theorem
- _underfl0w_ 6y agoIncidentally, probably an apt depiction of Apple's development process :P
- Lammy 6y ago"Hanlon's razor" is a gift to the malicious. I've stopped believing in it entirely.
- stretchcat 6y agoAgreed. Nearly every kid discovers the 'it was an accident' lie/excuse. And I don't think adults ever forget it.
- webmobdev 6y ago(That tweet has been deleted by the Apple developer). Before macOS Big Sur / Catalina, many of these application firewalls - Lulu, Little Snitch, HandsOff, TripMode, RadioSilence etc. - all used their own kernel extensions to effectively monitor and block any processes from connecting to the internet. Firewalls are system security softwares. And naturally Apple would prefer to oversee and have this in-built in their OS. Apple also wants to discourage kernel extensions on macOS (they have some good reasons - a poorly designed kernel extension can make the OS unstable; but mostly its about feature control with Apple). So they informed all such firewall app developers that their individual kernel extensions will no longer be allowed, and Apple had instead created an OS API specifically for their use case. (They described the features it would have and invited them to give their feedback). And so all application firewalls were forced to update their apps and use this OS API. But this API had an undisclosed, in-built list of Apple approved applications that no firewall was allowed to block. Someone created that list. Someone added that list in the system, and coded the API to specifically give them special privileges to bypass any application firewalls. Bugs are accidental. Backdoors like these are intentional. (You can however take exception to the usage of "Backdoor" here - perhaps from Apple's perspective it was a good design decision as many of these services go wacko, and sometimes even freeze your system, when they aren't allowed to do what they are coded to, like do some operation over the internet. I've often seen CPU spikes and slowdowns when you block some of these services.)
- raverbashing 6y agoI agree, this is 90% likely malicious. The non-malicious usage I can imagine is that for debugging the firewall you don't want to lock your other services out of it in case something goes wrong (or as you said, for reliability issues)
- webmobdev 6y agoMy fear is that Apple will now make the design decision to make these services more unreliable if blocked. Like I experienced, others too have noticed similar behaviour: > It’s worth noting that Big Sur and its predecessors are built to assume that they can talk to Apple at any time, but when we don’t allow it, a few unwanted side effects pop up. For example, the keyboard sometimes takes longer to wake up from sleep mode. Or, in certain situations, the Mullvad app takes longer to detect that the computer is online. - https://mullvad.net/en/blog/2020/11/16/big-no-big-sur-mullvad-disallows-apple-apps-bypass-firewall/ https://mullvad.net/en/blog/2020/11/16/big-no-big-sur-mullva... (Ofcourse, as a developer, I can sympathize with the Apple developers - when you design a product to use the internet, you don't really think hard about all kinds of use cases where internet access is deliberately denied).
- pstrateman 6y ago> Why do you call it a deliberate backdoor when the Apple developers (see elsewhere in this thread) have said this was a bug? They're lying.
- rorykoehler 6y agoIt's always a bug. Fool me once....
- jarym 6y agoPerhaps they meant it was a bug in management because the code was very much intentional
- xxs 6y ago> have said this was a bug They can say whatever they like, it's another story they've got no credibility. It was quite obvious it was very much a deliberate action (just look at the naming, itself)
- yholio 6y agoApple has no love for privacy nor ever had. They are in a market position where their main competitors - Google primarily, Microsoft and Amazon - are highly dependent on revenue streams extracted by monetizing personal information. Apple is in a position to cut that stream without affecting its bottom line, so it does it and claims privacy as a core value. I won't look a gift horse in the mouth, but I have no doubt that the tables could switch at any time.
- confiq 6y agoironically, most of these companies are out of China because they don't want to comply with Chinese laws. Not apple https://applecensorship.com/ https://applecensorship.com/
- simonh 6y ago"Brain test game was deleted from the Chinese App Store". These are just changes to the app catalog, what reason do we have to believe that a bunch of brain training apps being dropped or withdrawn is evidence of censorship? Has any of this been verified with the App publishers?
- yorwba 6y ago> ironically, most of these companies are out of China Of the three companies named: - Google's user-facing services (search, email, app store, docs, ...) are blocked, but Google Ads (which are censored) and Android (which comes without any content that would require censorship) are still sold. - Microsoft: I'm not aware of any of their products being unavailable. Windows is the dominant desktop operating system in China, and I'd be surprised if the app store wasn't censored. Bing search results are definitely censored (they tell you so at the bottom of the page). - Amazon isn't selling much that could run afoul of censorship, except possibly books (remember when Amazon used to be an online bookstore?) but in China their market is mostly targeted at the niche of high-end imported goods. (Note the country-of-origin indicators on https://www.amazon.cn/ https://www.amazon.cn/ )
- yalok 6y ago
- Synaesthesia 6y agoThe PRISM revelations in particular made me realise that we can really only rely on Linux for security, since Apple, MS, Amazon and all the big tech companies are onboard with cooperating with the NSA. If you've read the way eg the CIA installs snooping software on Macs and PC's, they hide the Mac version in your hidden EFI boot volume, even from the factory. It's enough to make you never trust them again.
- neolog 6y agoSecurity isn't the same as privacy. Linux desktop security is poor but its privacy can be okay.
- mcdevilkiller 6y agoWhy us it poor? (Genuinely asking).
- user-the-name 6y agoNo real push to use sandboxing or to limit access to personal information. Any app you install can do anything it wants with all of your data.
- fsflover 6y agoCan't you run apps on behalf of restricted users?
- vaduz 6y agoVia CLI you can, but GUI apps connect to your X server session, and then the fun begins - any application you allow to connect can essentially capture your keyboard, mouse, clipboard and a ton of other fun things,as there is no sandboxing applied between them. It's inherent in the design of the X protocol. There are solutions that are intended to force the sandboxing by opening a new Xserver for every application, e.g. Firejail [0], but that comes with another set of interoperability problems. Wayland was supposed to address some of these concerns, but it will only do so for applications that natively talk wayland protocol, not the ones that connect through x-protocol via xwayland [0] https://firejail.wordpress.com/ https://firejail.wordpress.com/
- lern_too_spel 6y agoYour first link was debunked the day it was printed. https://mobile.twitter.com/search?q=Greenwald%20direct%20access https://mobile.twitter.com/search?q=Greenwald%20direct%20acc...
- blub 6y agoWhile I agree that one should remain suspicious and be vocal about privacy violations and security issues, I find your attitude of continuing to attack Apple inappropriate. Apple competitors Google and Microsoft which control the great majority of OS installs both for mobile and desktop don't even pretend to care about privacy. I have collected over the years reports about dozens of underhanded tactics they use to manipulate users into sharing data, when they're not downright forcing them to do it. Currently Google is showing in the EU a modal pop-up asking users to accept to be tracked or fuck off to a labyrinth of "See more" and "Other options" which are obviously violating the GDPR. They got fined five times already for GDPR violations. Microsoft have told their non-enterprise customers to bugger off and learn to live with telemetry. They're actively working around people blocking telemetry and they're being investigated for these practices. How about a thank you that at least someone at Apple listens to their customers?
- webmobdev 6y ago> I find your attitude of continuing to attack Apple inappropriate. I do so because I am an Apple user - this is being typed on a mac mini. I also own other Apple hardwares. I also advocated for Apple hardware within my family & friends to switch from Android to Apple quite successfully (I am the IT guy in my circle). I did so because I would like to believe their commitment to privacy they have publicly stated. (Tim Cook being Gay adds to that trust because he understands that privacy is not just about hiding secrets but protecting ourselves from political persecutions by those who do not like some part of our identity - whether it be regional, gender, political, cultural, religious, sexual etc.). It doesn't mean I trust them blindly or completely or will allow them to screw my customer rights (like right to repair, and OWN my device). Would you?
- blub 6y agoYour CV or Apple credentials are not relevant. If one considers privacy important, as you seem to, then they should engage with companies which at least try to behave in a privacy-friendly way instead of typing backdoor in all caps several times and painting those companies in a bad light while not recognizing any of their contributions to improving the privacy of their customers. And here are those contributions spelled out for you: Apple is the only company preventing Google from having the private information of all smartphone users on the planet on their servers.
- eptcyka 6y agoKeep in mind, pf still worked as intended. With caveats that macOS doesn't work properly if all traffic is dropped, imposing 30 second timeouts before publishing a default route to the routing table, among other things throwing a hissy fit. But, at least on macOS, there has always been a way to block all traffic.
- nr2x 6y agoIt’s inaccurate to say “Apple selling user data to US government”. That’s not what the article claims (the word “sell” doesn’t even appear in the text), and there are in fact many consumer data brokers who really do sell data to law enforcement.
- sneak 6y agoI don't think it's inaccurate; the IC pays the data providers (presumably for implementation/overhead) for receiving the FAA702 (PRISM/FISA) data. Which data is picked by the US government, and no warrant is required. Apple provided data on 30,000+ users to the US government without a warrant in 2019, per their own transparency report. If they received money for the program, they are indeed "selling user data to [the] US government".
- nr2x 6y agoA reimbursement for effort/overhead is not the same as selling for profit. Again, there *really are companies who sell consumer data to law enforcement for profit*, so it's important to use the correct language and make the appropriate distinction. Do I like that Apple does that? No. Do I think the actual policy conversation is best served by accuracy in language? Yes.
- dahfizz 6y agoYou're just playing word games. Apple gave user information to the US government in return for money. That's selling. Nitpicking about whether they made a profit has no bearing on the statement “Apple selling user data to US government”.
- nbzso 6y agoI will not assume anything. When they roll official update and people do proper testing (Wireshark etc), may be I will update. But for me the romantic days of "trust us we care for users privacy" are over. Period. I read Apple actions, not intents. And reading actions for me is: "Mac OS is a valuable part of vertical integration map of Apple services". When I buy something - I own something. If idea of ownership is problematic for Apple they must state it openly and rename all the hardware store buttons from "Buy" to "Rent".
- sneak 6y ago> I am glad that the public backlash Due in no small part to HN. If it weren't for this community, the word would not have spread as far as it did to pressure them to make this change. Thanks to all of you and everyone at HN who works hard to keep this place as awesome as it is.
- dang 6y ago"Please don't use uppercase for emphasis. If you want to emphasize a word or phrase, put asterisks around it and it will get italicized." https://news.ycombinator.com/newsguidelines.html https://news.ycombinator.com/newsguidelines.html.