14 ms·
Warning: DNS encryption in Little Snitch 6.1 may occasionally fail
- skrrtww 2y agoThe title sort of implies this is intentional or privileged to Apple, while it rather seems more like just a bug. I also wish people would post the FB numbers and the details of their report when they say they've reported things like this.
- pkulak 2y agoYeah, if it was intentional, it would probably be a hard-coded, encrypted URL. Some devices are starting to do that to get around ad blocking.
- hiatus 2y agoGood thing you can still see the domain over the network if you control the network.
- lukevp 2y agoYou can’t control anything if they do DNS over HTTPS to a hardcoded IP they control and cert pin so you can’t MITM the connection, can you?
- userbinator 2y agoThat's what a firewall is for.
- Wingy 2y agoIf the pinned cert is stored on some kind of ROM chip you could probably rewrite it to replace it with your own cert.
- hiatus 2y agoYou can at the very least block traffic to the hardcoded IP.
- pkulak 2y agoSure, but then DNS breaks on the device and it's useless. Might as well just hit it with a hammer.
- Reptur 2y agoDevil's advocate would say: They could do this and make it look like a bug that never gets fixed in order to avoid backlash. How it gets achieved is flexible if the goal is met.
- kergonath 2y agoWhy would they be afraid of backlash on such an obscure, technical feature? They never were in the past and are expected to take controversial technical decisions by now. And by “now”, I mean in the last 30-odd years.
- asplake 2y ago> Update 2024-09-17, 7:10 p.m. > After further investigation, we found that this bug has already existed at least since macOS 14.5 Sonoma (maybe even earlier, but we currently don’t have access to an older 14.x system for testing).
- mattl 2y agoWhich is pretty wild too, considering they're selling the product and the new OS came out yesterday.
- taspeotis 2y agoDid they test it ever worked with getaddrinfo? Or did they just see it worked once with CFNetwork and called it a day and then later publish a blog post saying it’s broken?
- TheJoeMan 2y agoIt's ridiculous us developers still have to jump through hoops to save around older versions of the OS for testing. There is 0 technical reason why Apple can't let us downgrade.
- luxuryballs 2y agoyeah it feels like they decided bank accounts flush with cash were a better investment than legacy system support
- thewileyone 2y agoNewsflash, they've always thought this way.
- luxuryballs 2y agoyep
- dishsoap 2y agoCan someone fill me in on this? What hoops have to be jumped through? The last time I used macs, there were no issues downloading and installing older OS versions, but I have not used them recently.
- hypeatei 2y ago> After further investigation, we found that this bug has already existed at least since macOS 14.5 Sonoma Isn't this an inherent risk when attempting to do network stuff in userspace? You're at a very high level so hoping that lower level things comply seems risky if DNS encryption is critical to your use case.
- newaccount74 2y agoApple removed support for kernel extensions, and instead added a bunch of APIs that allow to do network filtering etc in user space. Unfortunately, some of their networking code just bypasses those network filter extensions (probably because of bugs) -- this is not the first time the developers of Little Snitch publicized a bug like this.
- xyst 2y agoIf I recall, Apple deprecated use of certain network apis for third party developers. But Apple’s own apps (App Store) do not have these same restrictions. Thus, when trying to filter network traffic via app firewall via new APIs. It would fail since App Store uses legacy APIs. Maybe part of this old bug (that I thought was fixed)
- newaccount74 2y agogetaddrinfo() is not a legacy API, it's a standard cross platform API for doing DNS lookups.
- indrora 2y agoSpecifically defined by POSIX: https://pubs.opengroup.org/onlinepubs/9699919799/functions/getaddrinfo.html https://pubs.opengroup.org/onlinepubs/9699919799/functions/g...
- trillic 2y agoIt's POSIX which Apple generally abides by except for timer_create. macOS is historically officially a UNIX, which would require getaddrinfo.
- keyboardcaper 2y agoFunny how that goes: macOS is POSIX certified but no other desktop BSD or Linux is.
- spookie 2y agoBecause it's an expensive and lengthy process. And every version would need to be re-certified.
- ajross 2y agoThere have been POSIX-certified Linux variants. But the open source projects you use don't bother (for obvious reasons) and commercial derivatives like Android and ChromeOS don't need it. Similarly Window NT was POSIX-certified way back in the day yet its descendants aren't, even though they implement the same API set (via very different technology).
- bradgessler 2y agoI’ve had issues using the Resolv library in Ruby when I’m connecting to the internet via a tethered iPhone. Never ran into that until Sequoia. I wonder if that’s related? TBH I’m too lazy to dig in and find out. Has anybody else run into this issue?
- unluckier 2y agoSee: https://waclaw.blog/macos-firewall-blocking-web-browsing-after-upgrading-to-sequoia/ https://waclaw.blog/macos-firewall-blocking-web-browsing-aft... If disabling the firewall (for testing) solves this problem, this is likely your issue.
- elashri 2y agoI maybe imagining but I feel like deja vu that there will be a problem with DNS that would affect Little snitch., Mullvad and others with new releases of iOS and Mac. If true I would really question what apple is doing during their months long developer and beta testing.
- unluckier 2y agoSequoia also breaks an application's ability to use DNS (or presumably anything UDP-based) if the macOS firewall is enabled, and an app is listed as "Block incoming connections". https://waclaw.blog/macos-firewall-blocking-web-browsing-after-upgrading-to-sequoia/ https://waclaw.blog/macos-firewall-blocking-web-browsing-aft...
- OptionOfT 2y agoHonestly, I'm fine with that. Applications themselves should not be resolving DNS outside of what I set in settings. The reasons applications do this is to prevent users from blocking telemetry etc. It's my computer, I should have final say on what goes out.
- Spivak 2y agoYep, I wish they would go the full way and block socket access entirely so your own outgoing traffic is always introspectable even with cert pinning. It would make it blatantly obvious when apps try shady shit.
- newaccount74 2y agoShady shit? Not every network request is a call to an HTTP REST API. Blocking socket APIs would break every app that supports other protocols. Goodbye file transfer apps, VPN apps, file sync apps, database tools, SSH clients, remote desktop clients, audio and video conferencing apps, etc.
- mzs 2y agothe (complicated) rules: man 5 resolver also try with a domain that exists
- Legion 2y agoI always love the announcements of, "Bug found in new OS release! EDIT: Actually it's been there for a while!"
- lapcat 2y agoDupe: https://news.ycombinator.com/item?id=41568128 https://news.ycombinator.com/item?id=41568128
- kelnos 2y agoIt's a little weird to me that getaddrinfo() is considered a "low-level legacy API". Maybe things are drastically different on macOS, but getaddrinfo() is the way to resolve names on Linux and I suspect the *BSDs. Sure, I expect most macOS apps will use something in Foundation or some other NetworkKit-type framework to do DNS queries, but it's odd to me that the code there wouldn't then call down to getaddrinfo() or the like to do the dirty work. I guess GAI is blocking, so presumably there's some other low-level non-blocking call?
- unethical_ban 2y agoI'll pile on, as someone who has never developed for Apple systems: What APIs are supposed to be used for DNS resolution? * Host file * Configured DNS server * App-specific DNS server if it exists What "API" is there? Why doesn't an app doing system-wide DNS modifictions just modify the settings for default resolver?
- threeseed 2y ago> This library wraps around the dnssd framework and the c-ares C library with Swift-friendly APIs and data structures. https://github.com/apple/swift-async-dns-resolver https://github.com/apple/swift-async-dns-resolver
- josephcsible 2y agoIt feels like Embrace, Extend, Extinguish to claim that a portable API is "legacy" and that its replacement is Apple-only.
- deleted 2y ago[deleted]
- deleted 2y ago[deleted]
- virtue3 2y ago
- whalesalad 2y ago[flagged]
- Avamander 2y agoDeploying DNS encryption on macOS is in general really tedious. Applying it as a system or user profile has different results. Switching between providers or temporarily disabling DNS encryption is painful. I also still haven't figured out how to get SSID-based switching to work, does it even?
- Reason077 2y ago> "To protect (DNS lookups) from prying eyes, Little Snitch 6 offers a new feature: DNS encryption." Browsers such as Firefox have offered this directly for a while. Of course, that only covers DNS lookups made from the web browser, but it doesn't rely on OS-level hooks that (at least in Apple's case) can break.
- Mainsail 2y agoWhat am I missing here? Reading the article, it appears that Firefox is the browser that seems to be bypassing.
- Reason077 2y agoThey're using Little Snitch as an OS-level DNS proxy, which should intercept all DNS requests from any app and encrypt them. But, depending on what API the app uses for its DNS lookups, some DNS requests do not go via the proxy. Presumably Firefox, in its default configuration with DNS encryption set to OFF ("Use your default DNS resolver"), uses one the affected APIs.
- Mainsail 2y agoAh, that makes sense. Ty.
- jedisct1 2y agoThe standard way to use dnscrypt-proxy is to set the resolver to 127.0.0.1. Does Little Snitch do things differently?
- system7rocks 2y agoHmm. I use NextDNS for this feature. I think. May have to do some testing to see whether or not it is operational at all.
- tankenmate 2y agoI use routedns [0] as my local stub resolver so that I can pick and choose which requests go to where and also what transport they use. It can also blocklist, re-write, cache, load balance, and/or handle fall back requests; so it give you lots of control. I use a stub listener on localhost:53 for local requests and then forward them via UDP QUIC (TLS 0-RTT) requests to Cloudflare (1.1.1.1) with caching for most requests. Fast and reasonably secure. [0] https://github.com/folbricht/routedns https://github.com/folbricht/routedns
- ggm 2y ago"Mac OSX has complex paths into name-to-address translation and a single entrypoint is not well enforced." this is not "bypass encryption" this is "uses a range of ABI/API bindings in code which don't expose well into a single control point"
- deleted 2y ago[deleted]
- pkilgore 2y agoMy read of this is that it shouldn't affect pi.hole given the system's default nameserver would still received by DDNS and thus be the pi.hole? Or do these requests go somewhere that's hard-coded?
- tpmoney 2y agoNo this appears to be if an application registers a DNS resolver proxy on the local system, getaddrinfo doesn't use the proxy, and presumably just hits whatever the network interface's configured DNS server is.
- zjp 2y agoAm I susceptible to this if I redirect all DNS traffic on my network to a pihole, which is the only device I let make external DNS requests?
- rapatel0 2y agoIf pihole is using DNS encryption for upstream lookups, the this would only affect you on your local network. In other words, it would be unencrypted to the pihole but encrypted when going out to the internet.
- sleepybrett 2y agomacos may bypass LITTLE SNITCH'S encrypted dns proxy, more like it.
- PaulDavisThe1st 2y agoCan some ELI5 why you'd use a proxy rather than reset the server name?
- spr-alex 2y agoPlugging https://www.supernetworks.org/ https://www.supernetworks.org/ -- when on wifi/vpn all DNS will go up over DNS over HTTPS as plaintext DNS is DNAT'd to CoreDNS which is by default configured to use DoH.
- gsich 2y agoWhy is a DNS proxy needed? My assumption is that you configure DoT or DoH (which I interpret as DNS encryption) somewhere in the settings of the OS.
- OJFord 2y agoI was confused at the Little Snitch mention, and then reading further it just seems like a LS bug, that it only works in certain cases. Well, seems this is the LS blog, so only confusion is why this is portrayed as a macOS bug? I'm not saying it's wrong, it's their domain not mine after all, it just doesn't seem to be justified in TFA?
- kccqzy 2y agoIf the OS allows the registration of a DNS proxy, and some calls bypass the proxy, it's squarely an OS bug.
- jesprenj 2y agoDoesn't getaddrinfo respect /etc/resolv.conf? So LittleSnitch should install itself there if it wants to be used by getaddrinfo. Besides, apps can always make direct lookups to a resolver of their choice, bypassing any resolver hints of the operating system.
- kccqzy 2y agoThe /etc/resolv.conf system is woefully inadequate. It doesn't have a concept of per-interface customization so you can't customize according to the currently active network interface. It doesn't distinguish between DNS configuration delivered by the network administrator (which can and should be changed remotely) versus set by the computer administrator. It doesn't work very well with VPNs where a specific DNS server is used for resolving addresses on that VPN.
- rob 2y agoIt wasn't.
- gigatexal 2y agoI wonder if this affects iOS, too
- jesse_faden 2y agoI would believe so. I have a custom DNS profile setup that redirects a few domains to a server I run. The server has custom SSL certs issued by a private CA. I the certificate installed on iOS as a trusted root certificate. Everytime I'm connected to my home WiFi I would randomly get `peer closed connection in SSL handshake (104: Connection reset by peer)`. I have absolutely no clue why it does this and this issue goes away when I'm connected on mobile data. Now I'm guessing that it is bypassing the DNS profile and resolving it using my ISPs DNS or some other way.
- gigatexal 2y agoOh this is not good. I hope the vpn providers chime in, the MullVads and ExpressVPNs etc
- gigatexal 2y agoNvm. Turns out it was a bug in littlesnitch.
- zimpenfish 2y ago> I would believe so. It won't, it was specifically a bug in Little Snitch (which doesn't currently run on iOS, I believe.) "The problem discussed here turned out to be specific to Little Snitch 6.1 and not a general issue in macOS. It has already been fixed in Little Snitch 6.1.1."
- jms703 2y agoI wonder how little snitch sets the dns encryption up. In macOS, you need to setup encrypted dns via a profile System (Settings => General => VPN, DNS & Device Management) and then in the browser. However, I think terminal and appstore still use whatever server is obtained via DHCP and is not encrypted.
- Jemm 2y agoApple ignoring standards again.
- zimpenfish 2y ago> UPDATE: Spoke too soon… The problem discussed here turned out to be specific to Little Snitch 6.1 and not a general issue in macOS. Not really.
- huugoo 2y ago[dead]
- dwighttk 2y ago>UPDATE: Spoke too soon… The problem discussed here turned out to be specific to Little Snitch 6.1 and not a general issue in macOS. It will be fixed in an update of Little Snitch later today.
- leeter 2y agoDang can we get an update to the title to reflect this?
- DrammBA 2y agoI see people tagging him as @dang, not sure if there's some backend logic to notify him but here goes nothing. New title from source: Warning: DNS encryption in Little Snitch 6.1 may occasionally fail
- squigz 2y agoThere isn't. > @dang is a no-op. The only way to get reliable message delivery is to email hn@ycombinator.com https://news.ycombinator.com/item?id=36526450 https://news.ycombinator.com/item?id=36526450
- dang 2y agoI put "[fixed]" in there temporarily but if that's not accurate we can change it again.
- theonealtair 2y agoThis is why I firewall egress port 53 at the router level.
- egberts1 2y agoThe battle of DNS resolving ownership rages on: who has the rights to set the DNS nameservers/resolver. As a long-time DNS security researcher, the ultimate and final end means would be to mirror the root servers, but I assert, for now, popping in your own `resolv.conf` should suffice, … again, for now. https://tailscale.com/blog/sisyphean-dns-client-linux https://tailscale.com/blog/sisyphean-dns-client-linux