11 ms·
Apple’s Private Relay can cause the system to ignore firewall rules
- EricE 4y agoUgh - I appreciat the spirit of what they are doing, but it’s yet another example of the best of intentions getting flattend by unintended second order effects. At least it’s still beta!
- legrande 4y agoWell I will be turning this off when it's out of beta and I'm prompted to use it. I already cloak my traffic with a self-hosted VPN+VPS box that I control. And using Mullvad combined with Private Relay would be redundant and overkill. Just turn it off if using a VPN client.
- lazyier 4y agoSeems annoying, but any application can work around any firewall rules pretty trivially provided they can get at least one type of connection out to the internet. TCP, UDP, DNS... anything. Just need that one connection and it can be turned into a tunnel. The private relay feature is worth being aware of, but it's irritating for users to deal with overzealous and clueless admins who think that locking down systems by disabling features like this can "increase security". It just ends up getting in the way of getting work done without any real benefit.
- ocdtrekkie 4y agoYou're ignoring that admins have often legal responsibilities and compliance requirements to manage and monitor their networks. It doesn't really matter how I feel about a given VPN service... if you want to be on my network you have to turn it off. (And yes, I often end up annoying myself by blocking stuff I myself would like to access at work. But that's my job.)
- tomjen3 4y agoSure and that is understandable, but it doesn't really do much. My personal phone is not on my employeers wifi but is still right next to me. There is nothing technical that they can do, short of a faraday cage for the building, to prevent me from going where ever I want on it. I feel like rules such as yours are a pre smartphone era thing, when I had to use the company laptop to get online away from home.
- ocdtrekkie 4y agoIt does a lot: You aren't exposing our network to security threats or legal liability. I don't care what you do with your phone on your own Internet connection. But if you want to connect it to my Wi-Fi then it has to follow my rules.
- msh 4y agoIf you don't control the endpoints you don't control the network.
- ocdtrekkie 4y agoIt depends. Obviously a lot of effort by certain monopolistic advertising companies have gone into ensuring the web platform is increasingly opaque and difficult to manage or monitor, but it's entirely in the purview of a network owner to disable or block anything that can't be inspected to satisfaction.
- msh 4y agoWell if you want to block everything that can't be inspected you will block a lot of common functionality. The question about if it's in the network owners purview to inspect depends on the network and traffic. It could also be illegal privacy violations.
- ocdtrekkie 4y ago
- 2Gkashmiri 4y agoyou comment "anything. Just need that one connection and it can be turned into a tunnel." this interests me because a few years ago i was subjected to a government imposed firewall https://thewire.in/government/kashmir-internet-whitelisted-websites https://thewire.in/government/kashmir-internet-whitelisted-w... and i tried my best to bypass this but i did not have the energy to fashion a touniquet of sorts. i did end up spinning up a free amazon vps because apparently "amazon website" was unblocked and that forced them to allow aws. i ended up simply using ssh -D to the ip of the vps. that worked for a while but it was not fun... the connection would drop frequently but otherwise it was a POC. my point is, when we are talking about a hostile adversary like your government that is out to get you, regular "vpn" does not work, in my case, i tried every darn thing but until i came up with my thing, i could not get access to regular internet so for the next time, what can i do?
- hhh 4y agoThis is my first thought of how to do my own VPN in a hostile environment, with the term VPN do you think of consumer VPNs? (Mullvad, Nord, etc.) When I moved to university, bandwidth was limited in the dormitory to 1mbps/user (in 2016…) This was unacceptable to me, but we had a private link (non-internet) to the campus with virtual desktop infrastructure that had no such limits :). ssh -D immediately gave me 500mbps download to my dorm room, and I guess this sort of thing is probably why I think of ssh -D and running on port 53 etc to evade this sort of thing. Public education in the US can function pretty well as a government out to get you in terms of digital freedom :)
- 2Gkashmiri 4y agoyeah, i even ended up using firefox foxyproxy addon because then i could either go all in on the proxy or whitelist style only few websites or blacklist with all websites and few open. that addon probably was the best thing in all of it because i was not pushing the entire OS through the tunnel. yeah, i guess for some time, cisco was called out by news outlets for helping the government impose the firewall which the company later denied but the damage was done by then so it didnt really matter, still, i think this just slipped from their minds, a random port, somethimes 80, 8080, 3400. it was fun (well considering the circumstances) with the added risk of incarceration if caught and many were unfortunately so yeah
- danamit 4y agoThe issue here is that an application is bypassing a kernel-level firewall, seems crazy to me that a Unix system is allowing that.
- dismantlethesun 4y agoApple seems to consider that they are the kernel and your machine is just a terminal that happens to run on their platform.
- jawngee 4y agoIt's also great for accessing stuff Vietnamese ISP's try so poorly to block.
- cosmiccatnap 4y agoThat is just how a VPN works in general, nothing special.
- pornel 4y agoEspecially rich coming from a VPN vendor, whose business happens to be threatened by Apple's relay.
- VWWHFSfQ 4y agoSeems like a valid complaint to me. Apple is giving themselves privileges to end-around potential competitors on their platforms. Although this is not new.
- jeffbee 4y agoThis isn't something Apple has sneakily reserved for itself. Any process the user authorizes can access PF_NDRV sockets which bypass firewall rules. It's a documented feature of Darwin.
- VWWHFSfQ 4y agoI fail to see the difference. apple authorized themselves to bypass firewall rules without the users input
- howinteresting 4y agoPersonally I trust Mullvad a million times more than Apple. Mullvad is one of the few vendors which have earned my trust. Meanwhile, Apple caved into pressure from the FBI to keep iCloud message backups unencrypted.
- treesknees 4y agoThe article is referring to the Private Relay connection itself (the "VPN" connection. In quotes because it's not a real VPN) bypassing the firewall, which is not typical. Apple took some heat for doing this to their other apps when Big Sur was first released [1]. Mullvad is installing a rule to essentially disallow any non-VPN'd traffic to prevent leaks. But iCloud Private Relay is not being stopped by that rule. [1] https://arstechnica.com/gadgets/2020/11/apple-lets-some-big-sur-network-traffic-bypass-firewalls/ https://arstechnica.com/gadgets/2020/11/apple-lets-some-big-...
- egberts1 4y agoThat’s why you always carry your personal pocket-cellular WiFi modem with custom firewall settings. Then turn on Airport mode on your cellphone. Sign on to your WiFi. IP address Privacy, pretty much assured (assuming you have your own backend WireGuard and remote VPS-based gateway. )
- VWWHFSfQ 4y agosounds like a lot of punishment just so you can use an iphone. maybe try a different device
- actionfromafar 4y agoYeah... like a laptop with OpenBSD? Otherwise it sounds like sound advice for any device if you have the threat profile to warrant it.
- VWWHFSfQ 4y agoSeems like a lot of theater to me. If you really have that kind of risk profile then you're not running your exit on your own vps. That will singularly identify you and there's no plausible deniability. And you're leaking way more PII in a typical web request over your VPN than than just an IP. I appreciate that people are interested in this stuff and want to do it, but it sounds pointless really.
- egberts1 4y agoO_o. Who ever said about running your own exit node on your own VPS? We got other ways to established an exit node. Is an entrance node, this VPS. But it is heady and pointless … for a small fry.
- 3np 4y agoGot any models you have tried and used?
- 4y ago
- jeroenhd 4y agoI doubt this is a leak, it very much sounds like Apple is using QUIC to connect home and make the API work. Not respecting the system firewall does seem like a flaw, but Apple has had a history of bypassing attempts at filtering network traffic. Firewalls have been blocked from working and Apple services have been made unblockable in later APIs. I'm not surprised in the slightest that Apple also bypasses your VPN to call home. I don't know if this is a problem, though. If you buy Apple, you let Apple make the decisions for you, that's how the entire ecosystem is designed. You must trust Apple unconditionally and accept traffic sent home to adhere to their privacy settings, or you should not run macOS at all. Try to run Windows or Linux on it if you've bought your computer for the hardware quality, though the M1 makes that nearly impossible without sacrificing user experience.
- noasaservice 4y agoThat sounds like treacherous computing. And I've argued before, that this smells like a rental with the name of a "sale". A computer does what its owner whats it to do. And when Apple or another company is directing its actions, tells me that what I have is a rental. Either relinquish control, or put it on the market with the real name. It's not a sale.
- hn_version_0023 4y agoI agree with this take 110% As an aside, I’d also like to subscribe to “No as a service”.
- olliej 4y agoDude, literally the article says: data gets sent to private relay if you have it enabled. You can stop it from being sent by not turning it on. What is apple meant to do? Just not provide the service at all? Because private relay is vastly superior to a VPN for web content, which is what matters to most users?
- eptcyka 4y ago
- N0RMAN 4y agoDoes disabling Private Relay[1] on a DNS-level prevent this? [1] https://developer.apple.com/support/prepare-your-network-for-icloud-private-relay/ https://developer.apple.com/support/prepare-your-network-for...
- xvector 4y agoYes, but just keep the feature off in the OS. Why go through these ridiculous workarounds?
- 0xdeadb00f 4y agoCompletely tangential but I had no idea (what I assume to be remnants of) FreeBSD's pf firewall is included, and works, in standard MacOS.
- toast0 4y agoIIRC, ipfw is there too, but maybe a little less supported, not sure about FreeBSD's third firewall (ipfilter). As with most of the stuff pulled from FreeBSD, it was pulled around the year 2000, usually with no updates from upstream, and often with few updates from Apple. Pf's synproxy doesn't really work on macos, and is unlikely to get fixed.
- jeffbee 4y agoSystem VPN is a privileged process and it's quite possible that it uses raw networking, for efficiency or other implementation reasons. You'd also see that any Linux process with CAP_NET_RAW "ignores" iptables. It's good to keep in mind the inherent limitations of in-system software firewalls.
- olliej 4y agoI’m unsure how a VPN and private relay would be expected to operate concurrently? What happens if you enable two VPNs concurrently today? Private relay and VPNs serve significantly different purposes - private relay is very clearly http[s] focused to the extent that I recall it doesn’t cover most traffic?
- ec109685 4y agoPrivate Relay turns itself off when a VPN is enabled.
- tedmiston 4y ago> Private Relay turns itself off when a VPN is enabled. I tested this on iOS and Private Relay does not turn itself off when a VPN is enabled.
- lxgr 4y agoIt does for me as well. Does your VPN possibly not offer a default route?
- olliej 4y agoThanks! If the apple documentation says it does, that would seem like an obvious bug, but I'm curious whether the apple docs do say that, or there's a general assumption of that being the case? Oh, as I think of it, did you test the UI switch position or network traffic? I could believe the following behaviors: * UI switch turns off, private relay continues to carry traffic * UI switch stays on, private relay continues to carry traffic * UI switch stays on, private relay does actually turn off All seem like entirely plausible bug behaviors, and it would be nice to know which it was (UI off + iCPR on would seem to most overtly be a bug)
- tedmiston 4y ago> What happens if you enable two VPNs concurrently today? I don't believe it's possible to have more than one VPN configuration be enabled simultaneously.
- smegsicle 4y agomeanwhile does everything on wsl2 still bypass windows firewall?
- ec109685 4y agoThe headline implies that normal user traffic bypasses the firewall. When in fact, it's only apple system traffic. Still not great, but way less bad than if the VPN was actually bypassed for all traffic: "It is worth noting that Private Relay (mostly) disables itself as soon as any firewall rule is added to PF (the system firewall on macOS devices). The Mullvad VPN app does add firewall rules. Once you connect the Mullvad app, Private Relay announces that it has disabled itself. We see no correlation between user traffic and the leaking packets. We believe they are just some heartbeat signal calling home to Apple. We do not know what information is transmitted to Apple, but since the destination is Apple servers, it is a strong signal to your local network and ISP that you might be a macOS user."
- gigel82 4y agoIt's not the first time Apple allowed certain applications bypass the firewall / VPN (see https://www.macworld.co.uk/news/apples-own-programs-bypass-firewalls-vpns-in-big-sur-3798193/ https://www.macworld.co.uk/news/apples-own-programs-bypass-f... ). It is very bad indeed; not even Microsoft dares to do this in Windows (you can still very much block any network request from any part of the system via firewalls or DNS ad-blockers).
- adamomada 4y agoI’ve been using little snitch for a decade+ and as far as I remember it was the only time, and was probably a mistake by Apple. From your link: > Objective Development, the developers of Little Snitch, also writes about the discovery - and that they take it for granted that Apple will correct it. (Update, 14 January 2021: Apple indeed appears to have removed the whitelist exemption in macOS Big Sur 11.2 beta 2.)
- ridgered4 4y agoIs that true? I thought I recall reading the Windows firewall resets itself and that come call homes use hard coded IPs.
- tedmiston 4y ago> It is worth noting that Private Relay (mostly) disables itself as soon as any firewall rule is added to PF (the system firewall on macOS devices). Unclear if that's the case on iOS though.
- Vladimof 4y agoApple being marketed as a privacy company makes me laugh... about once a month.
- NaturalPhallacy 4y agoI mean they went up against the mainstream media and the FBI when they tried to demand the FBI demanded they make an insecure version of iOS for them, that would have enabled unlocking all iphones in existence. The headlines said "apple is refusing to unlock a terrorist's iPhone, but if you did your homework, it was actually the aboe first sentence that was happening. That's pretty pro privacy. I assume Google has already done this for them, perhaps without even being asked.
- Vladimof 4y ago> NaturalPhallacy - they tried to demand the FBI demanded they make an insecure version of iOS for them, that would have enabled unlocking all iphones in existence. Google's and Apple's policies are basically the same when it comes to sharing data with the government... they both comply with secret laws (thanks Snowden).
- m463 4y agoI believe apple did the same thing decades ago with security ("windows is insecure, macos is secure", "we don't get viruses", etc) Over time they got better in this respect. Maybe they will offer real privacy someday. I would love a real firewall and little snitch on ios.
- jmbwell 4y agoIn what situation would you want private relay on, but block traffic to Apple?
- JustABurner188 4y agoPrivate relay seems to be fraught with privacy and security issues. I was able to use private relay to bypass IP based restrictions to all sites using one of the CDNs that private relay uses.
- JustABurner188 4y agoPosting this on a burner account for obvious reasons but I was able to bypass Cloudflare’s IP based restrictions using Apple’s iCloud relay when my connection was being relayed through one of their POPs. As far as I can tell the issue is fixed now but I’m unsure if they ever notified customers. The product seems to be fraught with security issues for Apple customers and others.
- a-dub 4y agoit's probably just out of band housekeeping for the private relay link. > We do not know what information is transmitted to Apple, but since the destination is Apple servers, it is a strong signal to your local network and ISP that you might be a macOS user. isn't this trivially evident with all your traffic being tunneled back to apple as well?