Apple apps on Big Sur bypass some firewalls and VPNs
thenextweb.com
thenextweb.com
Traditional VPNs that cover the whole system and route traffic based on destination IP (such as OpenVPN in UTUN mode) use the Packet Tunnel Provider in Destination IP mode. To the best of my knowledge, global VPNs routing based on destination IP (ie. non per-app VPNs) still route traffic from all applications, including Apple ones.
See this for more details on the Packet Tunnel Provider: https://developer.apple.com/documentation/networkextension/n...
My testing was not a comprehensive assessment of macOS-compatible VPN services and my selection was biased towards breadth of implementations disregarding all other criteria. It would be inappropriate for me to recommend any of them as I did not assess for quality of app, support, billing, or privacy.
If it adds a default route to your routing table when you connect, it's fine. If it offers fancy per-app traffic rules, it's probably not fine.
In summary, for each VPN app, I connected to the VPN and then wiretapped my computer to see if it originated unencrypted network traffic to any Internet destination other than the VPN while operating a variety of core macOS services on the exclusion list, such as Software Update and App Store.
In each case, I was able to witness Apple traffic on the VPN network interface but not on the Ethernet interface below it.
For anyone testing Mullvad, please keep in mind that they make use of the macOS packet firewall layer in addition to the usual VPN network interface, which may complicate my testing procedure if followed stringently as there might not be Apple traffic on any interface, VPN or not, in that scenario. Mullvad context is in another post: https://news.ycombinator.com/item?id=25116863
APPENDIX: Note that, as far as I can determine, existing TCP connections were not reset onto the VPN when it was connected. Since I was inspecting all traffic, not just Apple traffic, I ended up having to restart Slack a couple of times just to get it to switch over to the VPNs. I would imagine this should be studied more closely, since it was a surprise to me.
Someone else who didn't realize that I'd left out the methodology could possibly interpret their question as confused/misplaced/etc. I definitely wondered about that at first, but I took the good faith approach:
https://news.ycombinator.com/newsguidelines.html
Please respond to the strongest plausible interpretation of what someone says, not a weaker one that's easier to criticize. Assume good faith.
If you or I think there should be recommendations of which specific VPNs properly route Mac app traffic, then you or I can do our own tests and post our own comments with those results and recommendations.
https://news.ycombinator.com/item?id=25118136
I'm definitely frustrated that so many people (in top-level comments on HN, especially) are taking for granted some random Internet post without verifying it, but that's no excuse for the missing methodology.
You can't claim that these apps were not meant to do the very thing they used to do until Apple made such operation effectively impossible.
I'm not denying that NEFilterDataProvider is an inferior solution for per-app firewalls like Little Snitch, compared to their previous kernel extension.
> Some Apple apps bypass some network extensions and VPN Apps. Maps for example can directly access the internet bypassing any NEFilterDataProvider or NEAppProxyProviders you have running
But then the article sloppily goes on to say:
> What Wardle found is that the Mac App Store on the latest macOS bypasses any firewall.
(emphasis mine)
It looks like a lot of people are under the assumption that enabling VPN means system wide.
More info on the purpose of per-app VPNs: https://support.apple.com/en-us/guide/deployment-reference-i...
- It's physically impossible for your devices to bypass the VPN.
- It also works with devices that have poor or non existent VPN support (e.g. Roku, smart TV, etc.).
- You only have to configure it once vs having to configure it on all your devices.
- You can easily and quickly toggle the VPN by switching to a Wifi that doesn't have VPN setup.
I've been using GL.iNet's travel routers for many years and can't recommend enough (no affiliation other than being a customer). Just ordered their new Beryl router[0].
Without that focus, web sites would have a lot of trouble identifying IP traffic routed over a personal VPN from any other traffic. I suppose they could just block entire clouds, for those who run VPN servers on AWS, Azure, et al. But that would cause a lot of other problems.
I just route all of my devices through a single node I run at one physical location that appears like a genuine client node. I've never seen anything blocking it.
Basically if the IP is from a datacenter - it's likely a VPN.
And for sites with a lot of traffic, you probably don't even need an external subscription, you can deduce the ranges yourself simply by checking for IP addresses that wind up having logged-in users from all over the world in a short time frame.
Pretty easy to do accurately with a short set of heuristics.
In a previous job at an online gambling company we found that a large percentage of fraudulent user accounts came from VPNs so ended up banning them at the geo lookup stage.
I feel like "quickly" and "easily" a little overstated. Then again, this is someone who is willing to install their a separate firmware on a router, so...
Yes, setting it up in the first place may be fairly involved.
I replaced my router recently and changed my strategy. Now the router is only a router (and firewall of course).
I have a raspi sitting next to it providing the wireguard vpn. This is easy to update and everything actually works better than in past. I attribute a large part of that to wireguard over openvpn, though...
Double it, OpenWRT functionality beats any production router firmware. Bought Linksys some time ago, now searching a cable to flash OpenWRT on it 'cause original firmware feels crazy dumb.
That's a very broad generalization. I use a https://pcengines.ch/ based router with openwrt and mullvad as my VPN and performance is very close to non-vpn traffic.
Sure, if you run your VPN on bad hardware you might get bad performance but that is not true for everyone.
And I have no idea why either, just like you said, passing bit around.
It's not true. There are bugs and vulnerabilities, some of them can be exploited remotely. OpenWRT is no exception here. Better than many maybe, but not invulnerable.
And please, let's stick to professional terminology and call these "VPNs" what they are - transparent L2/L3 proxies.
Also I don’t think your terminology is really all that helpful. These services are literally VPNs. Trying to make a distinction doesn’t really add anything when VPN is already an established well understood term. This just adds confusion when there are already L3 proxies.
So there are no true VPN apps in Big Sur at all? Or true firewalls?
Honestly, this is so hard to believe that it cannot be untrue. They are totally sick at Apple.
So yes, Apple is in the wrong.
Edit: The article headline is technically accurate (if a little clickbaity): "Apple apps on Big Sur bypass firewalls and VPNs". Yes the do! Not all firewalls. But they bypass some of the most popular ones, like Little Snitch.
* system-wide VPNs - apparently work as before
* software firewalls - some Apple apps not blocked
* per-app VPNs - These are designed to tunnel traffic of a specific app through e.g. a corporate VPN and frankly have no connection to the topic.
It doesn't render GPs point moot, though.
What, are they working with someone? Five eyes? China? Spain? The Soviet Block?
Honestly, this is either utter imbecility or straight ill-will. There are no greys here. At all. When you do a think like this either you are stupid or you DO know the risks and are OK.
Great: now people in Hong-Kong cannot use Big Sur because they should be afraid of the apps they are using.
Yes:
Apple canceled their plans to fully encrypt iCloud data after the FBI complained:
https://www.reuters.com/article/us-apple-fbi-icloud-exclusiv...
In the Vault 7 leaks, Little Snitch was something specifically mentioned as being difficult to circumvent. Now, the ability to bypass it is baked into the OS:
https://blog.obdev.at/little-snitch-on-vault-7/
They moved iCloud keys to Chinese servers so the CCP could continue their surveillance:
https://www.reuters.com/article/us-china-apple-icloud-insigh...
During the protests in Hong Kong, Apple took down apps that let people crowdsource tracking of police:
https://www.nytimes.com/2019/10/09/technology/apple-hong-kon...
Also very relevant that VPNs seem to be illegal in China.
And Apple forced the hand of Telegram to shut down the channels revealing the names of Belarus police.
How illegal are they currently? When I lived there, they were illegal too, but still everybody would use them. There was always a difference between "illegal by law" and "really illegal".
> while China does have data privacy laws, there are broad exceptions when authorities investigate criminal acts, which can include undermining communist values, “picking quarrels” online, or even using a virtual private network to browse the Internet privately.
https://blog.invisiblethings.org/papers/2015/x86_harmful.pdf
[0] https://support.apple.com/guide/security/uefi-firmware-overv...
> The primary use of the ME is audio and video copyright protection on Mac computers that have only Intel-based graphics.
I dont now why. this is has been apple's stated position for a long time and the primary reason they are moving to ARM for the Mac, to make them more iDevice like, meaning you do not own the computer, they do, and you can only use it in a manner they (Apple) allows and bless.
Apple has been moving away form the professional / hacker market for a long time, they want to sell to normal consumers and could give a shit less about the pro or hacker market.
Making apps is not super profitable, most apps don't make enough revenue to support even 1 full time developer.
If they turn the Mac into a toy computer that developers can't use then it will affect the app ecosystem.
Just like NeXT didn't care about UNIX other than having a checkmark on bullet point list for the companies looking out for UNIX workstations.
As for "you don't own your computer, they do", what it translates to is: "The OS places certain restrictions that work and make it safer for the large majority of users, but might not give full tinkering abilities to everybody". Which you never have (full tinkering ability) in a closed source OS, anyway.
While "we bypass firewalls for our domains" can be thought of in the same vein ("we think it's better and safer for most users to work this way, and leads to less head-scratching why X Apple service doesn't work etc"), it's not exactly the same.
Apple can go towards the "no tinkering direction, it's a device that just works", without disallowing preventing user firewalls from blocking Apple domains (provided of course the user understands that by blocking them they get no iCloud and other services).
>Apple has been moving away form the professional / hacker market for a long time, they want to sell to normal consumers and could give a shit less about the pro or hacker market.
On the other hand, the pro market (video, music, graphics, office, programming, writing, data analysis, etc) shouldn't have workflow issues with what Apple did, and the hacker market is small (and has never been a target market).
There is a HUGE difference between passive secure defaults, which a normal user will never change, and active blocks / overrides that can not be removed.
An example of this is iphone vs android store policy, by default on Android you can not install untrusted APK's or other stores, however inside the phone there is a simply way to disable this block. This is an example of a passive secure default. Where on iPhone it is simply impossible to disable this block
One OS (android) is respecting your ownership rights while protecting the normal users, the other (iOS) is asserting their ownership over the device.
Surely you can see the difference
it is clear that apple intends to bring this type of Active Ownership control to the Mac ARM platform, this is just the first step, a warning shot if you will, of what is to come
Yes. That's why I think while this change is OK as a default, it's problematic to not be overridable -- and even if it was just a default it should be communicated clearly as a change, so those affected (e.g. people relying on VPN under some regime) know about them.
Those people are not the typical user case, but it's an important consideration still.
>An example of this is iphone vs android store policy, by default on Android you can not install untrusted APK's or other stores, however inside the phone there is a simply way to disable this block. This is an example of a passive secure default. Where on iPhone it is simply impossible to disable this block
One problem with this duality is that people will disable the block, and then complain plus have their info/data and those of others compromised etc, when they install malware at the first BS prompt that tells them to do so (to get some cool new game or some pirated stuff).
That is, it's not just those "knowing what they do" that will bypass those kind of defaults....
Apple chose to go with the "Most people don't know what they're doing, and if we allow it they will do it anyway", which is a defensible position. You use their OS knowing that they do that.
But this change now, was not the same kind or communicated as well.
>it is clear that apple intends to bring this type of Active Ownership control to the Mac ARM platform, this is just the first step, a warning shot if you will, of what is to come
If "what is to come" is a machine that "just works", has no malware, but has to get its software from the App Store and/or notarized by Apple, I'm fine with it. And hundreds of millions will probably also be.
Apple was never about tinkerers and customizations, they were always about cohesive, all-in-one, curated -- and that's ever since the Apple II.
It's not their fault that people who don't like this model feel like they have to still stay with Apple.
It's not 1999 anymore. Those days if they broke into your computer or if you got a virus you would lose some useless files and a few hours/day to reinstall your Windows. Nowadays you can lose a lot, and with working from home etc becoming more the norm, even more so...
It is also revisionist history to say "Apple was never about tinkerers and customizations", Apple was born out of the "tinkers" market, and did infact become popular pre-iphone days due to this hacker mentality, to deny this is to deny actual history
Further your comment it it "not being 1999" anymore and if your system becomes infected to the point wher you need to "reinstall windows" you lose alot simply because you are working from home..
I fail to see the connection, today there are far better tools on both windows and make to backup and restore systems.
For windows with OneDrive unless you have a massive amount of custom apps to install it is litterally just logging in to any other win10 computer and connecting your OneDrive to that computer and you have all you files
If you do not want to use Cloud services, Free Agents like Veeam for Windows empower users to backup and restore a complete computer is just a few minutes.
Also to claim mac is "Virus free" is moronic, and implies a level of security that is not really warranted, Mac like Linux is security through obscurity, Windows still has a 90+% market share, so of course threat actors will target windows more. Apple Mac is not target simply because there is not enough people to justify the investment.
As Mac's have become more popular, the number of threats have increased, and has shown Apple is not this secure enclave simply because they are Apple, they are secure simply because no one cares enough to target the platform,
Go read the feature list of Copland to see how much "tinkers" market they cared about.
I was there in the pre-iPhone days, and Apple was never about the "hacker mentality".
In the early days (and up to now) it was all about "computers for the rest of us" (as the slogan famously said, which is also what the 1984 ad was about -- freeing computing from being a serious/enterprise/business affair, not about hacking ideal - the target was IBM and the PC).
During the Jobs-ousted era (Scully etc), it was mostly about selling expensive boxes to vertical markets (printing, design, and so on).
Their first popular post-Jobs products were the all-in-one iMac, the powerbooks, and of course, the iPod. And they always insisted on the vertical integration (they make the hardware and OS/basic software) - with the brief pre-Jobs exception of the Mac-clones, which nearly killed the company.
>I fail to see the connection, today there are far better tools on both windows and make to backup and restore systems.
It's not about backing up and restoring, it's about third parties getting access to your documents, data, personal pics and videos, account passwords, files, etc -- which today are a much larger and more important part of your life and business than it ever was.
>Also to claim mac is "Virus free" is moronic, and implies a level of security that is not really warranted
I didn't claim it, but now that you said, I will: Mac is, if not virus free, effectively virus free, and can be even more so. There has not been any major outbreak for the Mac (tons for Windows). The biggest outbreaks were confined to sub-10% of users, and were invariably trojans, not viruses (users had to actively run them).
>Mac like Linux is security through obscurity, Windows still has a 90+% market share, so of course threat actors will target windows more. Apple Mac is not target simply because there is not enough people to justify the investment.
That's an old fable that doesn't hold. In the 90s, when the Mac (Mac OS then, pre-OS X) had 2% to Windows 98%, it still had tons of viruses.
And of course iOS has 0 or no viruses and malware, whereas Android has a ton, and there are not only close (30-40% to 60%) but also richer people on the iOS phone side to justify resources. It's just more secure, for various reasons (and no side-loading is one):
https://www.pandasecurity.com/en/mediacenter/mobile-security....
Wait what?? Are you serious? Please tell me you are not serious
Man are you in an Apple PR bubble if you believe that, iOS most certainly has been impacted by viruses, malware and vulnerabilities
>>That's an old fable that doesn't hold. In the 90s, when the Mac (Mac OS then, pre-OS X) had 2% to Windows 98%, it still had tons of viruses
I am not sure what you are attempting to say here? your implying Mac OS had a ton of viruses, if so I am not sure why you said "still had tons of viruses"
If you are talking about win 98 having viruses this does not refute my statement at all, as in Win98 days, as today then and now Windows was the vast majority (90+%) of computers.
Well, since you're outside the PR bubble, I'll be eagerly awaiting for your examples of viruses in iOS devices. I'll be patient.
Spyware you'll find a few (they exist in any system when you can't trust the developer 100% -- even Facebook app functions as malware, in the sense that it got data it shouldn't), that are stopped when found out, exactly due to developer certificates. No malware in the wild (virus, trojans, etc) infecting iOS devices, due to no sideloading and sandboxing.
While at it, also refute the "50 to 1" Android to iOS malware ratio as given in the post -- and that's from an antivirus vendor:
https://www.pandasecurity.com/en/mediacenter/mobile-security...
You're serious and I'm not after all. And you're also outside the bubble, so you'll have access to plenty of material...
There are various third party add-ons for various systems that do try to funnel "ALL" traffic through Tor in various ways. ORBot for Android tries to act like a VPN for the phone. Outboard hardware like the Pi-hole will try to put everything on a subnet through Tor. Tor-centric OSes like Whonix and TAILS put all of their traffic through Tor. You can hack something up to do it on vanilla Linux.
... but so far as I know, there has never been anything that tried to do it on MacOS. Maybe I just don't know about some weird hack that's available, but even if there is one, it's not part of Tor proper.
It's also not something anybody should ever have relied on anyway, because trying to "act like a VPN", on a general-purpose OS that's not cooperating, is prone to be leaky regardless of the OS. As long as programs running in an OS can find out the system's "real" IP address, they can leak it, so if you're serious about containing non-cooperative programs, you need to deprive them of that information.
The Tor Browser doesn't do any that. It just sends the traffic from the browser app itself over Tor using SOCKS, and Apple has not broken that here.
What Apple is doing is obnoxious and unacceptable and yet another reason never, ever to use an Apple product for anything... but it has zero impact on Tor.
Imagine you open Tor in your mac, Apple will send a request with Date, Time, Computer, ISP, City, State and Application Hash through the open internet for everyone that listens.
That by itself is not very interesting but if you combine that with all the other data hoarding that happens it can trace back to you.
For the Tor Browser, the developer ID used with OCSP is:
The Tor Project, Inc (MADPSAYN6T)
That's certainly enough to tell Apple you are running Tor Browser, Tor itself, or something else from the Tor project!Also that's only OCSP which runs often. Gatekeeper also runs, though only the first time each new executable is run. Gatekeeper does tell Apple the hash of the application. That will show up each time you run it after updating to a new version.
The stuff about street address etc is wrong, but not completely wrong. Because the request is sent when you open the application, as a side effect it reveals your approximate location (to anyone third-party eavesdroppers not just Apple) and an accurate timestamp, of the moment when you opened Tor.
Of course anyone eavesdropping nearby can detect the Tor traffic itself. However, only on the paths used to the Tor exit node. Separate from the Tor traffic, Apple and any routers along the path to Apple (e.g. "great firewall") can identify devices running Tor from far away, even if they don't have direct evidence of Tor traffic from those devices. I think it quite likely that CCP (among others) will be logging these OCSP requests at the great firewall already.
Here's a "cleared up" version of the story from https://www.theverge.com/2020/11/16/21569316/apple-mac-ocsp-... :
> the data sent to Apple’s OCSP server contains information relating to an app’s developer but not the app itself. It adds that Apple’s Gatekeeper service can send the hash of an executable, but that this is separate to OCSP and happens over an encrypted connection. Apple’s own support page notes that Gatekeeper uses “an encrypted connection that is resilient to server failures.”
> In its updated support document, Apple makes clear that security checks it makes when authenticating software do not include a user’s Apple ID or device identity. The company also says it’s stopped logging IP addresses associated with the Developer ID certificate checks. “We have never combined data from these checks with information about Apple users or their devices,” writes the iPhone-maker. “We do not use data from these checks to learn what individual users are launching or running on their devices.”
It doesn’t send a text string of the developer ID. It sends the thumbprint for the certificate. That’s still some information that could be used indirectly to determine some apps that may be running, but you’d have to at least collect a mapping database by sampling common apps.
Most importantly, it doesn’t even try to explain what OSCP is. This is critical in order to understand the purpose. Without that, and with the other false or misleading info, it looks like this literally exists for the purpose of tracking your every move and what apps you use. But that isn’t what it is at all. It’s a good faith malware protection feature that has some potentially unwanted side effects that have privacy implications, and even those implications are substantially less than what is claimed.
There are legitimate privacy concerns with OSCP but I feel that it’s important to represent the situation accurately. This is an off the shelf revocation checking protocol that was implemented to the spec. We should pressure them to improve it (which sounds like it already happened, a very positive sign) but it’s unhelpful to paint them as villains over it for following a standard and not even keeping any of the data that is sent back.
You’re correct that the notarization check has a hash, but that’s not what he was talking about. Also, that’s sent once and encrypted I believe.
There is no meaningful tor under those conditions.
It makes no sense for Tor to use those APIs since they're designed for other use cases.
Not sure how well any of that works though. I'm not touching Big Sur or the new macs with a 10' pole until all the software that I rely on is updated to not require kexts 100% (including Little Snitch full support) and Apple silicon has virtualization support so I can run Docker.
I'm really glad I just upgraded to the latest intel mbp a few months ago.
How can I know that the option to edit the whitelist won‘t be removed as fast as the default entries were added to the whitelist?
1: https://tinyapps.org/blog/202010210700_whose_computer_is_it....
https://mrmacintosh.com/google-chrome-keystone-is-modifying-...
At least there seems to be a way to try and fight it.
What a mess, man...
So you can't support the free market and not allow big companies to exist at the same time.
Instead I think it would be honest to say that we don't want free markets, because they have inherent issues that are detrimental to people. At the same time we don't want planned markets which have historically failed as well.
Instead there must either be a better paradigm or a sweet spot in between (e.g. a well regulated somewhat free market).
That's a non sequitur. A lot of "normal businesses" became big.
In any case, Apple didn't become big because they found a "loophole". They were on the brink of bunrupcty and become big because they put out product after product that people liked: the first iMac, the iPod, the iPhone, and the iPad.
And they didn't even compete on cheaper prices, undercuttting the competition by throwing VC money (a trick Amazon did): they did it while selling only on the higher end of the market, and charging the same or more than their PC/mobile competitors.
Oh, and for the most part they didn't even do it though marketing either. Their ad budget was laughable and less than half to 1/5th compared to competitors for the first 15 years. Heck, Samsung used double to triple Apple's ad budget, and Google used 1/2 Apple's budget on just a single phone product.
https://qz.com/103266/google-is-about-to-spend-half-of-apple...
The idealized market models are models. It doesn't work like that in real life.
Example: McDonald's. They have all the competition in the world. Restaurants are one of the closest markets to idealized perfect competition there is. But McDonald's still makes plenty of money. Because as close as restaurants are to the ideal, the ideal doesn't actually happen in real life.
Coca Cola, Nike, Toyota, Starbucks. These are all multi-billion dollar companies with nothing even resembling a monopoly.
Most large corporations become large not purely on market forces but because of Regulatory capture where by they slam the door on competing businesses by passing "consumer friendly" regulations that is in reality more focused on preventing new comers to the market
Why do you think Facebook is soo hell bent on getting regluations from the government on social media, because they know they will be one of the "stakeholders" that will help write them thus ensuring their market dominance
Why do you think Amazon is now in favor of National Sales Tax regulations, because now that they have to pay sales tax in all 50 states is favors them to have 1 regulation vs 3000
Why do you think Walmart now favors raising the minimum wage, because social and economic pressure has forced them to raise their own wages so they want to ensure all companies have to pay the same wages they are
Point to any large company that is in a position of market dominance and I will show the government regulations that allow them to operate in that way
hell the very basis of the corporation is a fictitious entity created by government to limit liability, the laws around those corporations (especially public corporations) are government regulations written by large corporations for their benefit, That is not a free market at all
> Why do you think Facebook is soo hell bent on getting regluations from the government on social media
What truly threatens these corporations isn't regulation, in fact I'd wager they're counting on it. The real threat is the next Instagram that walks through the door that doesn't sell to FB. Basically, the biggest threat to FB is the fact that people don't really care about FB, they just want something to look at on their phones. It's totally in FB's best interest then to make it more difficult for competition to invent new ways to look for people to look at their phones.
Banking and finance in general is probably the best example. It's so difficult to start a bank these days that your best bet is to acquire a failing one.
However, on this point:
> Point to any large company that is in a position of market dominance and I will show the government regulations that allow them to operate in that way
I don't really see how Apple falls under this category? I can see it for Amazon, Netflix, Walmart, Google, Facebook, etc... but what about Apple?
This Duopoly is largely supported because of FCC Regulations and carrier restrictions it is very hard to get access to Wireless frequencies and ever harder to do that nation wide, given this it is hard to deploy a mobile device in the US.
Apple then relies upon Copyright and Contract law both of which are favorable to large companies not consumers to ensure their market dominance by making it impossible to create interoperability between their ecosystem and others.
Then you have the various Tax and general business regulations that favor all Large companies, some of which in general prohibit smaller companies from growing.
Ironic, isn’t it
PS: Why don’t the people here combine forces and capital to create a video and privately registered website like apple1984.com (I think trademarks can be used for criticism, otherwise just use 1984 plus something) and actually run this ad to shame apple on various social media and youtube? DoubleTwist did.
VPN work just fine for me. Some Apple apps mat bypass the VPN, but I don’t see a reason those apps would need to connect to the company intranet in the first place.
Nevermind that your VPN might have the purpose of bypassing shitty, insecure public wifi.
Nevermind you may not be trusting your local/national internet infrastructure.
Apple knows best. Trust them.
/s
Routing traffic onto the public Internet through a 3rd party adds absolutely nothing to security. You shouldn’t trust the Internet in any case.
If you use it to ‘bypass shitty security’ and then all you’re doing is trick yourself into a false sense of security. VPN services like that are complete and total bullshit.
The major non-corporate-drone use of VPNs is to confuse the site you're communicating with about where you are, not to conceal the content of the traffic.
There are many other uses, and more things in Heaven and Earth, Horatio, than are dreamt of in your philosophy.
So basically to commit fraud when using streaming services. Can you think of a legitimate use case ?
This is beyond irresponsible. Apple knows there's going to be bugs in their code. Doing it anyway is completely hypocritical to their own privacy-focused marketing.
Such an application is extremely annoying for normal users.
Deleted comment
The article suggests that Apple may be exempting its own apps from user-defined network traffic protection measures in order to clamp down on geographical licensing loopholes, or to keep its app traffic out of VPN servers. Either case would be to the benefit of Apple and the detriment of the customer/user IMO.
I'm also genuinely curious, what is the main benefit of doing this and if it's done by design.
https://www.ripe.net/publications/docs/ripe-690
(Mobile cellular Internet seems to be harder, but is there any reason why user's cell-'modem' can't handle the routing of successive /64 connections ?)
Edit: also not sure if the router I got from my ISP (which I don't use, but I guess 99% of their other customers do since it is non-trivial to replace without losing IPTV) would allow me to configure it as a VPN gateway. Pretty sure it won't considering they try to lock it down as much as possible.
Additionally, block anything by default that wasn't looked up over my DNS proxy and/or uses HTTPS without SNI...
I wouldn't be surprised if there are still apple apps installed as system apps on iOS that could just come through the store or are using some special Apple-only API to do something trivial.
I can understand why they think they can do this - they create the OS, so you implicitly "trust" them - but that position doesn't mean you shouldn't be able to grant others that same trust, IMHO.
That said, I am curious which laptop brands today are most compatible with Linux. I've heard good things about Lenovo and Dell XPS. As for which flavor of Linux, I have my eyes on Arch...
Why just not buy preinstalled Linux? https://puri.sm/products/
Furthermore- Dell's WD19TB dock works on most kernels (and all newer XPS models) as well. I'm talking power, USB, network, and 3 2k@60 (or 1 4k@144 & 1 1080@60) displays all on a single cable. The future we were promised 4 years ago is finally here.
I bought a system 76 which comes with Linux (Ubuntu or Popos). I’m using pop and things work (jet brains, bitwig, I compiled unreal engine..).
Those machines are rebranded clevos (so they say) but I know drivers will work. Build quality is decent but the machine has lasted. It’s been good and pretty much maintenance free. The os updates frequently.
My only complaint is the machine has 2 video cards and will only drive externals with the nvidia one. Switching requires a reboot. The battery life isn’t great when driving the nvidia card. Maybe the new ones fixed this (onyx pro)
(btw, I admit that some of this has to do with a general lack of support for Linux by software and hardware companies, but there's only one side of this Linux distros can work on and that is making it a more pleasant environment for end users and most Linux users seem to sneer at that thought)
In my past experiences a big frustration was configuring/debugging some random thing and ending up with a solution that - given 12 months of time - i needed to tweak and cannot remember what i did. Or worse, i upgrade software and something breaks. I identified that this effort was wasted if i couldn't roll back easily, or incrementally document my steps through the OS.
To tackle this i chose to go with NixOS. It's got a lot of rough edges, but a few days of dedicated learning time was enough to make me feel mostly productive. I still have a lot of hanging questions, but with NixOS + Flakes + Home Manager i have a system that i feel confident about stability and my ability to roll back as needed. This softens the blow for me personally of needing to figure stuff out that i otherwise wouldn't of had to on OSX.
Since my focus is building a beast PC (that i don't want to pay Apple for) i might still use Mac Laptops, and as a bonus my Nix setup can still be applied on Apple. From NixPkgs to Home Manager dotfiles i plan on using my setup on both Mac and NixOS.
I switched fully ~4 weeks ago, and my only real complaints are (as a Linux Desktop beginner):
1. X11 seems awful. Notably i have one 4k Monitor and two 1080p Monitors and .. it's annoying to setup. I'm using XFCE because it was notably faster than KDE and especially GNOME, and so i set XFCE to 2x Window Scaling but that scales all 3 monitors. So i have to use xrandr to tweak the scalings, and that has been a chore. Lots of experimentation for a janky experience, but i've got it working good enough for me. Wayland will hopefully improve this, but that's a long ways out it seems.
2. Basic features like scaling seem hit or miss. On KDE i recall it working pretty well with all my normal windows. On XFCE if i set 2x Scaling, Spotify and Zoom don't recognize the scaling. Resulting in very small text. I'm willing to overlook a lot of the Mac "pretty" - but i really wish Desktop Environments would perfect the basics.
3. Discoverability on Linux (any distro, imo) is .. bad. We all know the trend of immediately going to Google for everything if you're unfamiliar with the toolset or the domain, but i feel like there's got to be a better way to navigate a OS from both CLI and UI. Linux has the same discoverability problem that Windows has, it's just easier to Google things.. and that feels bad. For a hacker friendly OS i think we could do better here. NixOS, while equally terrible on this front, strikes me as something uniquely fit to be discoverable - given that nearly the entire experience is immutably configured.
All in all, so far i'm quite happy with my switch and looking forward to buying a Zen3 to build a new workstation. Hope this summary of my month long journey is of use to someone lol. It's far from over.
As for ‘happening out of the taxpayer’s purse’ - currently those who spend the money from the taxpayers purse in almost all jurisdictions are seeking to outlaw or seriously curtail encryption that they cannot break.
If you want to accelerate and make permanent the loss of control, get the government involved.
What we need is to build the infrastructure that would allow for decentralized trust of software and to make it as easy to use as an App Store.
If you can't have meaningful competitive advantage or differentiation, it's kind of hard to make money.
Which is what happens when a government sails in and starts granting monopolies.
Copyright is an artificial monopoly. Patents are artificial monopolies. There are a bunch of weird people out there who call themselves "libertarians", but somehow favor the government creating such restrictions on people's liberty. They're confused and should be ignored.
Trade secrets are perhaps slightly less artificial, but they are clearly destructive in an enormous number of ways.
If, as lawgiver, one were to totally eliminate all imaginary property and outlaw commercial secrets, one could arrange a society where a lot of people could make a very nice living. It might be harder to become a tycoon. Which would be all to the good.
What is the first step?
Go watch "The Internet's Own Boy", Aaron Swartz's biopic, which describes the arguments for and against copyright/patents, you'll learn something. No question, the system is flawed, but not irredeemably so.
I still think it is valuable to be able to say (as copyright does) 'I made this thing, deserve to be paid if others use it, and can control to an extent how it gets used.' Ditto for patents - 'What I made is my original idea or is an improvement based on the work of those who came before me.'
If, as I understand your argument, you are in favor of the libertarian view which advocates that the government create no law which protects these constructs, you also deserve to be ignored.
Both have been innefective at promoting innovation through disincentivising trade secrets. The most precious knowledge is not released and copyrighted and patented. It is still kept a secret. If they were effective we would be living in a world dominated by shared source instead of binary blobs and obfuscation.
Without copyright and patents, trade secrets are the main protection mechanism but at the same time reverse engineering is not restricted in any way.
That being said, I think many comments here are out of touch. We're talking about a specialized security feature which is not easily available on other platforms is only used by a minority of users and still works for most programs.
What exactly are your threat models that this is causing a problem for you? Are you sure that you can even use a mainstream OS if you need to block all outbound connections? If I had to have complete control over my outbound connections, I would use a hardware/software solution sitting between the computer and router.
Secondly, is this really bypassing VPNs or only the new firewall API? e.g. is it bypassing WireGuard?
If I connect to a public wifi hotspot and use a VPN, I used to be under the general assumption that my network traffic would be sent through my network tunnel and not be accessible to other users of the same hotspot.
One of the points of having a VPN is to be able to run software without every single middle man on the network knowing what you are running.
For example, say someone hypothetically wanted to post a comment on twitter that, again, hypothetically, was politically inconvenient for some authority figure.
The fact they launched twitter at about the time that comment was posted might be something they would prefer to not have reported on the internet at all, and certainly not without encryption.
Generally, this falls into the general category of "I may disagree with what you say, but I will fight for your right to say it".
with a different chain of middle men, ftfy.
Some VPNs were using kexts before Big Sur, some weren't. Wireguard for example is a normal AppStore app which integrates with the OS VPN support. It would suck to be confirmed that it's leaking traffic.
For what it's worth, a VPN will not protect you from threats on a hostile network.
“ A virtual private network (VPN) is a form of network tunnel where a VPN client uses the public Internet to create a connection to a VPN server and then passes private network traffic over that connection. If you want to build a VPN client that implements a flow-oriented, custom VPN protocol—one that works with the data passing through a TCP connection rather than the packets used to transport that data—create an app proxy provider app extension. When the system starts a VPN configuration that uses your app proxy provider, it launches your app extension, instantiates your app proxy provider subclass within that app extension, and starts forwarding flows to your provider. Each flow represents either a TCP connection or a conversation over UDP. Your provider is expected to open a tunnel to a VPN server and forward each flow over that tunnel. Similarly, if your provider receives flow data from the tunnel, it should pass that back to the system via the appropriate flow. App proxy providers are one form of per-app VPN, the other being a Packet Tunnel Provider in source application mode. App proxy providers are supported in iOS on managed devices only, and in macOS for Mac App Store apps only.” https://developer.apple.com/documentation/networkextension/a...
More explanation here: https://twitter.com/lorisscandurra/status/132793682910295244...
I'm confused by this statement. We are talking about being able to implement firewalls and VPNs which can filter/redirect all outgoing connections. These are both abilities easily available on Windows and Linux.
To be fair I haven't looked at the state of Linux app firewalls in years, maybe there's something better available, but *tables is not it.
I've used two products in the past, NetLimiter and ZoneAlarm. Back then NL was just getting some basic firewall features, since its main feature was throttling the connection per app. I used ZA as a free product, but now I see they have a paid version. Last time I checked a couple of years ago I also found GlassWire, but I didn't purchase it because it kept being detected as infected by VirusTotal and the dev didn't have a clue what was wrong.
Frankly I don't know how trustworthy any of these apps are - this is a big problem with security software on Windows - you don't know if the anti-malware is going to behave like malware.
root access is irrelevant here.
If my app has root access, you can't force me to do anything.
I would like my computer to not connect to anyone or anything when it's powered on if I'm not running interactive apps that I specifically wish to use the network.
It's sort of like the bad old days with linux distros coming with like 47 listening services enabled by default. It took a while before they realized that defaulting things to "off" was the best move.
I encourage you to look at the pcaps coming out of a fresh macOS install with everything turned off: App Store, iCloud, analytics, FaceTime, iMessage. You'd be surprised how much it's doing when it's sitting there "doing nothing".
Apple has only been doing this for 3 major OS releases, or about two years.
On Windows you can run WPD[1] and turn it off, and also firewall the hosts it communicates with using the OS's built-in firewall.
Big Sur won't let you block Apple apps now.
[1]: https://wpd.app/
Such firewalls are used for protection against asshole developers which want to collect analytics without asking for confirmation. Apple are one of the assholes and LS can only be an interim solution against the OS developer. This was bound to happen... and I guess only a HW solution will help now.
Will it catch everything? No, obviously. Will it catch enough things to make it worth running? I guess that depends on your threat model, but many think it's worth it.
A bit like what QubeOS does.
Some universities used to (and probably still do) provide internet access over unencrypted Wi-Fi networks, with the VPN gateway as the only reachable host.
You can't customize the OS, the software for the platform is available on Windows and Linux, and the hardware is overpriced and underpowered, and then there's stuff like this where Apple decides how you should use _your_ computer. I sincerely do not understand why anyone would ever purchase an Apple computer, and yet here we are, again.
Especially confusing to me is how many of my fellow web developer peers I see choosing Apple devices over literally any other laptop with Windows or Linux which will run circles around a Macbook of the same price range.
Hypocrites. The whole Industry.
They commented on all the *gates and even the ocsp issue which reached mainstream media.
But this is so low level (normal people don’t know or care about firewalls except it’s running, or understand why it’s bad for Apple to bypass it) that it won’t become big enough to get that kind of press and response.
Once it’s exploited and has a pretty name, maybe.
I was hopeful to switch to Apple silicon.
This architectural decision alone is enough to make Big Sur and its successors a permanent non-starter.
Linux also lets you create VPN connections for individual apps if you use network namespacing. Before Wireguard, I used use network namespaces with OpenVPN[2] to create individual tunnels for different apps, and it worked nicely.
you can use the following in the terminal the see the list of whitelisted programs:
cat /System/Library/Frameworks/NetworkExtension.framework/Versions/A/Resources/Info.plist
Apple marketing is disgusting.
From https://www.apple.com/privacy/ :
Privacy is a fundamental human right. At Apple, it’s also one of our core values. Your devices are important to so many parts of your life. What you share from those experiences, and who you share it with, should be up to you. We design Apple products to protect your privacy and give you control over your information. It’s not always easy. But that’s the kind of innovation we believe in.
The hardware may be outstanding and the OS could have been top choice for me if only I knew it is my machine. As it is not the case, I will be sticking to Linux laptop for good and bad.
However, every other point you make here is accurate.
Yes, there is some information leakage, but nothing like ‘inspecting any aspect of your life’.
But more to the point, you own the computer. You chose the operating system. If you don’t like what it does, buy something else. You can sell the one you don’t like, because it is yours.
It’s as simple as that.