4 ms·
Can't speak for other OSes but OS X constantly phones home to Cupertino, sometimes not even using encryption, thus leaking data when you're booked into a public
by blumentopf 12y ago
Can't speak for other OSes but OS X constantly phones home to Cupertino, sometimes not even using encryption, thus leaking data when you're booked into a public Wifi.
I literally spent weeks last year grepping the entire Mavericks base installation for hardcoded URLs, domain names and IP addresses and setting up entries in /etc/hosts and NAT rules to hardwire that stuff to 127.0.0.1. I also had to disable lots of LaunchServices/Agents to get the OS to shut up. Can put this up on Github if there is interest. It's only for Mavericks though, couldn't be bothered to upgrade to Yosemite as long as there are security updates for Mavericks.
Oh and another thing a lot of people don't know: The OS stores Wifi passwords in EFI boot variables. This is used for Internet Recovery. So if your device is stolen or just lent to someone else, consider your Wifi passwords compromised, regardless if the disk was encrypted.
- heyalexej 12y agoI'd certainly be interested.
- Osmium 12y ago> Oh and another thing a lot of people don't know: The OS stores Wifi passwords in EFI boot variables. This is used for Internet Recovery. So if your device is stolen or just lent to someone else, consider your Wifi passwords compromised, regardless if the disk was encrypted. I can't speak for if this is true or not, but I literally yesterday ran Internet Recovery and it didn't remember my wifi password. I had to re-enter it myself. Little Snitch is a good reverse-firewall which might be preferable to messing around with /etc/hosts for many, especially since it offers active protection.
- blumentopf 12y agoRetrieving wifi passwords from NVRAM: /usr/libexec/airportd readNVRAM Alternatively: nvram 36C28AB5-6566-4C50-9EBD-CBB920F83843:current-network nvram 36C28AB5-6566-4C50-9EBD-CBB920F83843:preferred-networks nvram 36C28AB5-6566-4C50-9EBD-CBB920F83843:preferred-count
- rimantas 12y agoLeaking what data?
- wz1000 12y ago> I literally spent weeks last year grepping the entire Mavericks base installation for hardcoded URLs, domain names and IP addresses and setting up entries in /etc/hosts and NAT rules to hardwire that stuff to 127.0.0.1 I don't know how OSX works, but can't there still be addressed you missed that are hiding in the proprietary code? Also, if you are this worried about security, wouldn't you be better off just using a free OS?
- allannienhuis 12y agoApple locks in IOS developers to OSX - I'm not aware of any practical way of building IOS apps and submitting them to the app store without running OSX. That doesn't mean you need to use it as your regular personal use OS, but if you're spending your days writing IOS apps you don't have any other choice.
- ganeshkrishnan 12y agoAs an Android dev who was forced to create my app for IOS because a huge chunk of users are on IOS, the whole process of developing for IOS gave me brain cancer. XCode (like itunes) is a worthless piece of garbage. It's unfucking unbelievable how little this "IDE" accomplishes. And uploading to app store (with certificates, provisioning profiles, launch images, icons etc) sucked all the brain juice out of me. The error messages are even much more cryptic than Windows 95. Why on earth is this piece of locked up abomination so popular? Why are we crying about freedom from government so much and then rushing to buy this crapware?
- tajen 12y agoI dropped Ubuntu after three sequential bad quality upgrades (blocking bugs, lost configuration for upgraded packages, Unity). I won't use Windows because the command line isn't unix-style. Remains Mac OS X. Never had a single day of administration. What we need is open-source with a budget...
- api 12y agoBecause for the end user it offers a clean high-quality user experience with minimal friction. That is more powerful than anything else. It's more powerful than cost or freedom, and the developers can suck it. Microsoft was always shit for developers too, but it gave users what they want and users pay.
- nubela 12y agoCan you share that blacklist with us?
- rrggrr 12y agoWould you consider uploading your configs to Github or posting them on a blog. I'm sure the community would be grateful for it, at least I would.
- alimoeeny 12y agoI think using little snitch or similar would be the better way to go. Since I imagine not every url is hard coded as plain text and there are updates all the time, and changes and caches .... But I definitely agree, OS X phones home (and other places) all the time. Everytime my phone rings my mac tries to connect to some apple server. ...
- danieleggert 12y agoOn OS X 10.10 there are no WiFi credentials in the EFI boot variables.