Bypassing Firewalls in macOS Big Sur
twitter.com
twitter.com
https://tinyapps.org/blog/202010210700_whose_computer_is_it....
And a humorous guide on disabling protections like code signing and notarization:
https://www.naut.ca/blog/2020/11/13/forbidden-commands-to-li...
On the server, there’s a reason Amazon built Firecracker and Google built gVisor instead of just using the Linux sandboxing primitives. I think calling them “industrial grade” is pushing it when they’re rarely used as the first line of defense against code that is expected to be actively hostile.
If an application uses Gtk+3 or Qt5 then portals will be used automatically for Open/Save dialogs:
https://docs.flatpak.org/en/latest/sandbox-permissions.html#...
I agree with the thrust of you comment though, outside the webbrowser, proper sandboxing a barely used outside web browsers. However, I think the problem is as much social as technical. Every time Flatpak comes up, it mostly gets hostile reactions.
The situation is rather unfortunate. A lot of people believe that Linux is more secure than other operating systems, but in practice the Linux desktop is far less secure than e.g. macOS, iOS/iPadOS, or Android.
And no, you aren't safe because it is open source software. Sandboxing also protects against unknown vulnerabilities in open source software.
actually firecracker is not a sandbox. it's basically qemu/libvirt and a minimal implementation of devices. it's qemu-kvm with a http interface and way less devices.
the reason why they rewritten qemu-kvm is because qemu-kvm contains a lot of code that is not needed and is way more bug prone. and also loading a kernel is way faster in firecracker since they optimized the kernel loading code.
The reason is that Firecracker is a virtual machine, and Linux containers and sandboxing primitives are not meant to be used for virtual machines.
Pointing at Snap and Flatpak's "sandboxes" is disingenuous when they're notorious for having sandboxing as an after thought to app distribution.
When I say industrial grade, I mean that the sandboxing and isolation primitives that are used in industry are those that are either provided in the kernel, or are deployed as part of a standard Linux server deployment.
I point to snap and flatpak because outside of browsers they are AFAICT the only attempts to sandbox user applications on Linux. It would be disingenuous if there were some other apps or distribution channels doing a better job that I hadn’t mentioned, I’d love to hear of some.
My point: opting out should be much, much easier.
What could be easier?
Most consumers don't care about security, making it easy to disable just opens the floodgates of their systems.
EDIT: clarity
[1]: https://github.com/coreutils/coreutils/commit/34e3ea055721ec...
"How do I do X? Just run this as root." Sometimes slightly disguised, but more often not.
Fighting the OS you are running is an uphill battle that gets tiresome real quick.
Most users will say yes.
Technical ones at least can say no.
Easier than setting up bluetoooth.
@grishka Edit because I'm rate limited:
I've not seen anything that does executable validation for linux and actually works. Needs lots of kernel support. See the response from the old DigSig author: https://stackoverflow.com/questions/1732927/signed-executabl...
You can check binary signatures on disk (tripwire) but that is extremely tiresome to maintain and does not prevent straight loading of shellcode into memory.
More recently: https://lwn.net/Articles/733431/
Signed kernel modules is on its way though: https://www.kernel.org/doc/html/latest/admin-guide/module-si...
I guess that would be a place to start for implementing SIP...
/usr/bin/vim was installed by my package manager, but there's no guarentee the version I'm running matches the version that was installed. Now in debian there is a file which has a checksum of the version the package installed, but that's not checked on execution, nor is it itself signed (so the process that replaced vim could just as easilly replace the checksum, or the process that checks the checksum)
ChromeOS uses dm-verity to verify the root partition at runtime, similar to Mac OS's signed system volume.
I won't disable SIP and I'll avoid installing Google Chrome on my new Macs, if possible.
Given the choice between (a) a corporate OS that requires me to perform some amount of work to "turn off" some "features" the corporation has enabled and (b) a non-corporate OS that requires me to perform some amount of work to "turn on" the "features" that I want to use, I prefer (b).
Most of them won't even care about sending too much data to a company if that's the price to have the same device everyone else is using in their industry...
Came here to say that.
> Most of them won't even care about sending too much data to a company if that's the price to have the same device everyone else is using in their industry...
I do, I truly do care. So much that I'm looking at open-source/Linux options, at least for my home projects. Doesn't look very bright on the video side, but DaVinci Resolve is at least available for Linux. Rawtherapee is getting there with local adjustments as we speak. Darktable has lots of power but terrible UX.
People today, even more so than in the 2000's, have multiple computers. Would it still be feasible to have a Mac used for {music, cinema, graphics} that is not connected to the internet. Certainly one would have other computers that were connected to the internet and moving files between computers on the local network, preferably via Ethernet, is much faster.
But the point of me telling personal stories is not to suggest anyone could/should do the same things; on the contrary, it is to illustrate that "one size does not fit all". Today's Apple chooses for the user, rather than letting the user choose.
While most of Linux's audience (and probably practically all of NetBSD's) is rather technically inclined and could possibly be expected to turn on the security features as they need them, most of Windows' and macOS's audience will very likely have no idea that there is even an option to do this.
Also, software companies would probably take the easy route and just assume that since those features aren't enable by default, most people don't enable them and develop their software in a way which could be incompatible with them.
So I think that for an OS like macOS, where most people flock "because it just works and has no viruses", strict defaults are a sane choice. Having people go through hoops and click through warning messages would probably also push companies to better design their software.
In the end, I think the best way is for such features to be the default setup. But those OSs need to have an "escape hatch" for someone who actually wants those features disabled and actually understands the risks of disabling them. While macOS does (for the moment) have this hatch, it looks maybe /too/ complex. But then I think the difficulty of the exercise is in setting the "correct" level of complexity for this operation.
So the right path for consumer OS is ‘sound opinions, easily changed’.
Even technical users are going to differ in the sets of opinions they hold and are qualified to hold. I care about which Python I have installed. The virtual memory manager? Not so much. Someone else might, though.
The list is really disappointing.
actually default on, is not a problem if it is easy to turn it off in that case. if apple would have had a button to turn it off, we would be fine.
I don't believe the defaults related to this issue are a problem; its the lack of transparency about this, coupled with it being difficult to change this. Probably every update you gotta fix that. That's akin to running a Hackintosh. And we all know macOS is moving towards iOS; not Hackintosh/PC.
A more common use case for this kind of choice is corporate laptops. They usually set up their own policy on the laptop before handing it to employees for good reason. Firewalls are especially necessary to avoid leaking confidential information.
Why don't I just run a closed-source OS in a VM? They are fussy. Having some weird graphics tablet driver problem or something can really kill the creative connection between me and my work, and if I'm coming down to the wire on a deadline, it can cost me a contract.
What about tools that work natively on Linux? They generally just don't work for professional design use. Whenever I say that, a billion people always jump in and say "Gimp and VivaDesigner and Natron and XYZ and PDQ" work fine for me," and to my astonishment, they always seem surprised that the same just isn't true in most (any?) professional workflows. Sure, with varying amounts (usually non-trivial) of extra effort I can cobble together a disparate set of tools that might sometimes yield similar results to professional design programs, but it's going to take significantly more work to produce possibly lower-quality results, and that's just not an option for a pro. If you were hiring someone to craft the image of your company in a crowded, competitive marketplace, would you pay them more to take longer and potentially end up with a suboptimal product just because they were only using OSS to do it?
A software developer could feasibly use something like windows notepad or pine to achieve the same results as an IDE, or even a more powerful text editor like SublimeText. For many non-professionals, people just editing a config file, or people making the occasional shell script, it does work fine. Better even, considering that the extra baggage of complex tools would actually slow them down rather than speed them up.
get 2 machines then. Who says you need to have a single machine for everything? Get a Mac for your design work, treat it like an appliance, and use Linux for everything else on another machine. Problem solved.
People email you assets/images for use in your production work: are you going to get that on your 'designer' machine or on your Linux box? Most likely the latter, now you have to transfer it over to the 'work' box. Not technically difficult, but a definite speed-bump in your workflow. Awkward.
Your online document-sharing/demos (say Dropbox, whatever): is that from the work box? the utility box? both? Again, not technically a train-smash, but... awkward. A discontinuity that you'll have to deal with multiple times a day, a detour in your flow.
I can see why many would consider it too much of a hassle.
I am programming on Ubuntu (C#, PHP, Javascript) with Jetbrains software. This works absolutely great.
For 3D work I use Blender.
But for graphical work I agree that there are still alternatives missing.
Figma is a very good alternative for Sketch. Scribus is a good alternative for Indesign. Krita is very good for concept art. But that's about it.
Inscape is a good alternative for Illustrator, but only if you work in RGB.
Gimp can do what Photoshop can but it will take you 3 times as long.
But for me the trade-offs work. I want to own my computer so I choose to work in Gimp instead of Photoshop. I also started to design websites directly with CSS. And I switched from 3DsMax to Blender (which isn't a trade-off anymore).
The choice is yours.
This time around I think that is possible, and economically solid, the move from Apple to ARM and closed walls of App Store to create conditions for real Linux Desktop Revolution.
As you can read in my comment I agree with you. For example working with text in Gimp is just horrible. And Inkscape is very good untill you need it for CMYK.
But this thread is about owning your PC. And then I think all those trade-offs can be overcome. Sometimes this means thinking in other directions. For example the choice to design in CSS instead of Photoshop.
I don't think you can say: 'I cannot get away from Apple'.
But you can say: 'I choose to stay at Apple because I think it is more convenient'.
The choice is yours.
Jokes aside you don't have to do it if you're scared, and if you want to try you can always switch back and forth between machines / OSs so you use the most suited environment according to the limits of context and the job you need to do.
Much like you can aim at 0% environment pollution by gradually removing excess stuff instead of going full off the grid, you don't have to do a radical move. Use the tools you need for the job, aiming at result production while keeping a liquid approach.
Depending on your skills, willpower, effort, and willingness to abandon uninventive corporations you can be faster and more efficient. You're just not feeling comfortable investing time and effort, which is a sacred choice.
Please consider that things have changed since 2019, VMs support of tablets and color grading tools are a breeze and using tools that your competitors are scared to use will make you innovative. Godspeed~
I am feeling pretty heavily smug that I got rid of my Apple kit earlier this year because I wasn't happy with the direction of the platform.
Thinkpad running Manjaro GNOME
Works fine, haven't looked back.
Have not found a good successor to Devonthink Pro though.
The T460p is a 2016/17 secondhand machine which cost USD235 which I then added a ram upgrade and a new 72Wh battery to. I don't miss the mbp at all and prefer the linux OS anyway.
It probably took me until this moment to realise I was largely falling for marketing in thinking only the best specs would do ...
Couldn't be happier.
I guess I need to get a Thinkpad running Linux for slowly finding replacments for my tools, and migrate not within weeks, but spreading my migration process over months.
My most essential tool is Emacs / Org and Lisp, Python plus the terminal with some shell scripting for automating all my workflows.
Yes, I will miss the smoothness that comes from very tight integration of hardware and services, but I absolutely hate the path that Apple is on, slowly taking all freedom from its users, until macOS is as closed as iOS. This is against every conviction I have as a citizen for whose freedom it is essential to have control over the machine that enables me to connect to the world and do my work. We are no toddlers, Apple does not need to put us in a walled garden, a promised land without any malware and danger (that‘s the promise, but in reality they want to control every aspect of their ecosystem, like an emperor that wants to tax every aspect of acting and movement in his land).
With org-mode I have dozens of files for managing my projects and tasks. And I can mix notes with tasks. This is a feature that makes it exceptional. When I was using Things3 I liked the tiny section beneath the task description where I could type some notes about the task. With orgmode I can write a full outline beneath the task description.
Emacs is extremely flexible as it can be extended with packages written in Lisp. There are packages that allow me to navigate to any outline node in my ~ 200 org files within a second (ivy + counsel + ripgrep-integration, also org-ql which allows me to query my org files).
Also, I write large amounts of text with org-mode (it’s an excellent outliner too; been previously using OmniOutline) and convert to markdown or any other format via pandoc.
Emacs, once mastered is an application framework that allows me automate any workflow for which I previously used AppleScript, DEVONthink, Python, Bash.
All of these were replaced with org-mode and Emacs (and likely some other Linux features for Alfred). Doom Emacs is a good framework to explore Emacs as it supports both vim and Emacs bindings (there’s also cua-mode).
Well, if you actually like to tinker from time to time just for tinkering's sake, this is a great approach I inadvertently took.
My daily driver for 7 years had been a late 2013 mbp, which still works and is plenty powerful for most of what I do. Then during the shelter in place period I installed a Arch on my desktop (which normally runs Windows for Photoshop, etc) just to experiment a little with ZFS on Linux, etc. Then I started using it more and more and now I rarely use my mac again. (note that I'm not new to linux, had been using it both on the desktop and the server for a very long time and my work laptop runs linux).
However, unlike you, I don't use many Apple-only tools mostly just Things and Bear. I haven't found replacements for those, but as they never were a critical part of what I do, it wasn't that big of a deal to just drop them.
iA Writer is available on Windows and Android.
I use it heavily for:
* snippets (mostly for terminal so Termius might be an option but I also use it for non-terminal things)
* clipboard history (are there up to par alternatives?)
* workflows - mostly launching various websites, like Jira tickets with "<board> <ticket #>" or "c suponer" to conjugate Spanish verbs), but also for launching various shell scripts (like changing nameservers with "ns <provider>"), or keyboard shortcuts for playing specific sounds (for fun)
> I guess I need to get a Thinkpad running Linux for slowly finding replacments for my tools, and migrate not within weeks, but spreading my migration process over months.
I'm in the same boat. I've been eyeballing a Tuxedo Pulse 14, but have been thinking of getting a regular PC keyboard in the meantime for the Mac and play around with Linux in Virtualbox.
Edit: Found this, seems like there's hope: https://medium.com/curiouscaloo/macos-to-ubuntu-part1-alfred...
There are also Linux "commodity" laptops from Linux-focused companies now. E.g.,
To believe this, one has to believe that a $2 trillion company did this on purpose, knowing it would be revealed within hours and that it would take a major hit on the very reputation for user privacy and security that they have spent years building.
There are a lot of better explanations available than "Apple decided user security can fuck off and that clumsily collaborating with the bad guys in trivially-detectable ways was a way better plan".
I guess I just don't understand how this wasn't flagged as a concern when the feature was being worked on? How is it possible that Apple's engineering team built a backdoor like this without it raising serious security concerns? And if concerns were raised why was this not adequately pen tested prior to release?
I'm not sure what's worse from a reputational perspective... A company that prides itself on privacy but can't get something as basic as a firewall right, or a company that knows how to write secure software but occasionally puts backdoors in them for intelligence agencies?
This seems a little rudely dismissive. GP's skepticism sounds totally reasonable and healthy to me.
The malevolent act on their best interest which is often predictable and limited. The incompetent simply give away data to every random badguy under the sun.
I mean, it is the result of deliberate architecture and design changes to security and networking on macOS.
I believe Win10 was the first to do something like this --- it ignores the hosts files and firewall for certain hardcoded domain names and IPs.
[1] https://www.badllama.com/content/portable-raspberry-pi-firew...
If you want to block something use a firewall.
I see a lot of iCloud and Software update stuff in there.
Nothing malicious from first glance.
And I am sure the 30% cut and $100 annual fee has nothing to do with the decision either. Apple only cares about customers, not money. /s
Apple - "we want to keep it simple to our users"
Google - "AI doesn't have any control over data we've collected"
Facebook - "Every company is spying on their users"
Amazon - "we control mere 10% of global economy"
Salesforce - "you can ‘easily’ export your data from our completely proprietary platform"
Yep. And when Apple does it, HN will celebrate. There's a certain type of person who's terrified by independence and freedom and who craves the comforting safety of rules and control. macOS will be the OS for that kind of person.
Apple has all but guaranteed that my current Mac will be my last. I have been using Macs since the Mac IIx, and my first Mac laptop was the Powerbook 190.
The only reason that I have my Mid 2018 Macbook Pro, is that I bought it in Budapest after my previous machine died, and the reseller Apple store was the only one that stocked English keycaps for the keyboard (they did have to unbox and change the keycaps).
My technology choices are starting to feel frustratingly niche. I am using Apple over Linux because I tired of having to mess around with the systems constantly to get things working. ItJustWorks™ is a powerful driver.
If I'm being honest with myself, it's also a question of access to paid apps. If I list all the apps I use on a daily basis, a bunch of them are Mac only, and an even smaller set run on Linux (even if they have a Windows version as well).
The most obvious reason is that it would utterly destroy the Mac among influencer communities and developers.
But perhaps the most underrated reason is that Apple already has a managed computing platform in the iPad. Rather than the Mac becoming more locked down, I expect the iPad will become ever-more desktop-like and take over more and more market share from traditional computers.
I’d contend that an iMac-like desktop iPad is a more likely future product than a fully locked down Mac.
People have been repeating that for years, since the Mac App Store was announced. It’s not in Apple’s interest to do it. There is a ton of software, open source in particular, that Apple benefits tremendously by. It costs Apple nothing to maintain the status quo.
Going Mac App Store only would drive tons of developers off the platform and do absolutely nothing to increase sales on the Store anyway. It would be widely panned as a ham-fisted move.
The GNU/Linux developers that have been giving money to Apple for a shinny UNIX, might go to Windows with WSL, which I doubt unless we are speaking about the crowd that only cares about POSIX and keeps calling that "Linux".
The GNU/Linux developers that have been giving money to Apple for a shiny UNIX instead of sponsoring OEMs, now they finally learn how Apple has always been, including before the days of almost getting to close shop.
That crowd can turn on to their Pandora, GPX, Arduino, Raspberry, whatever SOC is going trendy.
As for Unreal I wish they learn their lesson, or be honest and create a lawsuit against Sony, Nintendo and Microsoft.
I think an argument can be construed that (one of) Apple's interests is to control what and how users can do on Apple devices. iOS-like lockdown seems entirely in line with that.
> Going Mac App Store only would drive tons of developers off the platform and do absolutely nothing to increase sales on the Store anyway.
And others would fill in the gap. The Store sales would inevitably have to go up – it would become the only way to get software on the device. Not like every user would immediately drop the Mac. I can imagine a non-trivial fraction of users wouldn't even notice that something has changed.
It wouldn't happen right next year, or in one go, but the more I think, the more I am growing convinced that it's sneaking up.
> It would be widely panned as a ham-fisted move.
If it doesn't affect the bottom line, it doesn't really matter. They got away with 4 years of perhaps the worst laptop keyboard of the decade; are getting away with inflicting the TouchBar price tag on tens of thousands of users(1), making devices unserviceable, and even with the matter in question.
Given Apple's size and user base, I'm afraid that outside of straight-up illegal activity, there's little Apple can't get away with. Especially if the janky move is factored into small, cruddy steps.
(1) I realize it's a lame point, but it annoys me personally
This has the dual-benefit of protecting casual users, and allowing power-users flexibility with any binaries that aren't sandboxed. From what I understand of your example, you used the bundled python installation to make the connection, the python binary is not sandboxed and is not affected by AppProxyProvider. This will be the case with any other binaries as well -- ping, ssh, etc...
The relevant documentation is at: https://developer.apple.com/documentation/networkextension/a...
Specifically the section I've highlighted here: https://share.getcloudapp.com/Z4uyONmJ
You can install notarized software, though.
:c
The government has its work cut out.
This however is something that Microsoft has absolutely dreamed about doing, but never had the power to actually make it happen. Apple wants to have the same power on the desktop that they have on iOS - no code not blessed (and taxed) by Apple run. This is what Apple wants, total control of everything executed by the cpu.
You can get a lot more done today without Microsoft than you could 20 years ago, but it is very hard to not have an accessible copy of Word if you interact with lawyers (where formatting and change tracking matters, and mostly compatible like libreoffice or google docs is not sufficient.
Also, if you take remote tests for school (which was almost mandatory for some, and now for almost all), many places require you install some windows only rootkit so they could claim to have monitored you.
My children’s remote school mostly works without any MS stuff, but every now and then it doesn’t and I have to fire up a VM.
Monopoly is still there, even if it is not as tight as it once was.
Same thing will happen with an encryption backdoor like the EU is now thinking of forcing down our throats...
I heard Apple has been very secretive in its development. Maybe it works for hardware, but software is an area where collaboration across teams are very important, isolated bubble breeds incompetence and politics.
The person that found the phone only poked around after he was confused when it went bricked a few hours later (remotely done by Apple). Then they actually tried to get it back to Apple, and got blown off. That's when they contacted Gizmodo. I think Apple was pissed that Gizmodo paid $5,000 to get it from the finder and didn't return it immediately to Apple without question or inspection.
Only thing I'm still pissed about 10.15 is that Wine still can't run 32-bit apps.
Catalina should be supported for two more years:
https://computing.cs.cmu.edu/desktop/os-lifecycle
https://www.csun.edu/it/supported-operating-systems
https://www.reddit.com/r/sysadmin/comments/imdzv4/endoflife_...
Guess I won't be upgrading from Catalina for a long time.
I wonder why they still thought it was a great idea to go ahead.
My pessimistic view of today's techworld tells me to follow the money on this and that I might not be able to block in-system ads in some future.
Turns out, no, macOS is still written by the same old skeleton crew at Apple and they still introduce trivial problems in most things they do.
https://www.reuters.com/article/us-apple-fbi-icloud-exclusiv...
(I hate the term “all but”. I find it often hard to tell what people actually want to say when using it.)
I didn't understand this reference. Who is the "same old skeleton crew"?
[0] https://en.m.wiktionary.org/wiki/skeleton_crew#:~:text=skele....
I try to forget those in between years of of System 7 / OS8 / OS9. They all gave me deep scars through countless hours spent troubleshooting extension conflicts. All while seeing the unhelpful, literal bomb icon dozens of times in a row [0]. The windows BSOD was bad, but at least it never mocked you about the OS blowing up.
[0]https://www.versionmuseum.com/images/operating-systems/class...
More details: In theory, extension troubleshooting should have been easy. 1) Boot with them off. If it boots, it's the extensions. 2) Turn half off. If it boots, you know it's the other half. 3) Repeat step #2 with the remaining extensions until you find the offending one.
Except it wasn't always a single one. It could be a problem that only occurred when a combination were active. So you'd go through the much higher # of combinations of turning certain groups on together... the first 5 & third 5 extensions, etc... Sometimes even that wouldn't work, and you'd be stuck opening programs you knew used certain extensions to force them into activity. Eventually, if you were lucky, you'd find the one corrupt extension and reinstall it. But if all else failed, you backed up the data with all extensions disabled, blew out the OS with a clean install and reinstall all the programs & restore the backup.
[$] for me
We need to nuke the Apple bullshit from MacOS Catalina and convert it into people’s operating system. Ethics be damned.
The previous discussion was about how Big Sur has some built-in exceptions for Apple software.
The current discussion is about the discovery that these built-in exceptions can also be abused by non-Apple software, rendering the firewall completely ineffective.
This is impossible to read on a phone.
You have a VPN active - I'm actually saying go here not there. Because the default connection might be unsafe, limited, etc.
Now, since I have to spend money on multiple dongles, etc that might justify me to buy a pi-hole for a home connection. Get around that Apple
Apple is allowing apps to specifically their own DNS over HTTPs. This DOH setting will not be transparent to the user and will be per application. So imagine a world where each app can bypass your system network settings .... already here
The problem is if you install non-App Store software. Most people don't need to do that, but of course, the types of users who frequently Hacker News frequently will. So they run the risk of installing, and using, malicious software.
I myself do install non-App Store software sometimes. Prior to Big Sur, I could use Little Snitch and be sure I knew what servers it was communicating with. With Big Sur, I can't.
Does that sum up the problem?
I think you are thinking about things like shell scripts, binary executables that run in the terminal which being an official Mac "Application", etc. Is that right?
Just trying to make sure I'm understanding.
Apparently Patrick Wardle describes a security hole, which uses the NetworkExtension framework to make it as if his code is Apple code, and thus ignores the firewall rules. My guess is, that it'll get patched and that will be that.
If you think about it, blocking OS stuff makes less sense. You're already trusting the OS to a great degree.
(I can understand the need for most people to control the OS to a great degree, but personally I don't feel that need for macOS, which is my workhorse.)
You should be able to deny/allow connections for any app, including 1st party apps.
This isn’t only an issue of trust. There are apps made to meter your connection (e.g. when you’re using your phone as a Personal Hotspot), where you’d like to see how much bw your 1st party apps are using, and have the option to block them.
Also i am wondering if you cant just change dns to block it either pihole, nextdns or even just change hosts file.
What does seem weird to me, is that they didn't implement a low data mode into macOS, like they do with iOS.
I'm sure there are advantages to system processes avoiding the firewall (inept admins unable to block updates for example) but does that outweigh the downsides?
% cd /System/Library/Frameworks/
% cd NetworkExtension.framework/
% cd Versions/A/Resources/
% ls -l Info.plist
-rw-r--r-- 1 root wheel 8.9K Jan 1 2020 Info.plist
⇒ I think this requires root. That, IMO, would make it less of an issue (maybe even a good thing, given the complaints people have about Apple not giving them control over their hardware)A normal non-apple root process doesn't have this privilege, going by the described exploit.
I can hack ipf in a similar way, adding an ACCEPT rule...
Nothing to see here, move along...
I love this though, finally the GNU/Linux crowd that has been giving money to Apple for convinience, instead of sponsoring Linux OEMs gets the message.
With sponsoring Linux OEMs instead we'd still have more of the same beige boxes, no new major architecture like ARM on the desktop, a Windows-2005 state of desktop environments (Linux DEs and Windows have both not just copied but dragged behind OSX/macOS changes ever since Aqua, like adding compositors, expose view, and so on, instead of coming up with their own ideas, GNOME/KDE advertise and redo on every new release stuff that was already in Windows in 2002), and so on.
I buy into Apple ecosystem for what it is, the progression of NeXTSTEP ideas (whose I came in touch with during my thesis), where UNIX compatibility was only used to bring stuff into the platform and have a place at the 90's workstation wars.
That is what Apple platforms are all about, an alternative OS design, where UNIX compatibility is good figuration, but will never get a main actor role.
By sponsoring GNU/Linux OEMs I mean paying companies like Tuxedo, Asus, Elementary, System76,..., just don't pay someone else to develop on their OS expecting to improve GNU/Linux ecosystem.
WSL is going to be the same, Microsoft just discovered that there is this crowd that cares more about POSIX tools, keeps calling them "Linux", but what they really want is anything that seems like UNIX, so out of the ashes from Project Astoria and Drawbriges, WSL got born and advertised to the masses unhappy with "GNU/Linux" on macOS.
As for the lack of creativity you point out, I fully agree with you, GNU/Linux desktop experience feels like those guys that buy a Fiat Spider and then stick a Ferrari logo into it.
Yeah, could not put it better.
The sad thing is there are tons of things they could do to differentiate from macOS/Windows and build something better, but the only thing they do is "copying the same" + "more customization" but with lesser production values (due to less resources, more fragmentation, more customization meaning less coherence, no unified vision(s), etc).
Fucsia is the only alternative OS project (real in the sense with money and a player behind it, there are tons of academic toy OSes that ultimately wont matter), trying to do something at the 2020-level, but knowing the attencion span, lack of vision, and culture of Google it wont go anywhere, or just end up as a ho-hum replacement for Android.
There's lots of resistance, cargo cult, and ceremony, at the Linux distro level, and some things need a big player with lots of resources to push them. Canonical is not that big, and doesn't really do that well anyway (even assuming it's interested). And because Linux is mostly hardcore devs and enthusiasts, it's difficult to sell them any major change to the way things have always been.
One idea for example that sounded like a move forward is something like GoboLinux fs structure. But of course that will get ridiculed by most Linux greybeards because it's not like things have always been. Some for something like NixOS. And that's just of the FHS layer -- imagine the resistance to changes to more classic layers (e.g. the hate something like systemd still gets).
Apple can change things more easily because they can do it end to end, and millions of consumers don't expect things to stay like NextSTEP forever, or care about strict POSIX adherence), but they still get all the hate on HN for many moves.
And of course nobody appreciates the hard work of moving e.g. 500,000,000 devices or more (iOS + macOS) to a new filesystem you have developed in the span of 5 or so years - but they notice all the baby issues that pop up (while similar issues to e.g. fs changes in Linux distros, with all the fragmentation, and "DIY" go unnoticed, or pinned to the user as responsible who switched from ext4 to something else etc.).