Before, I was trying to figure out how mac's would ever be used anywhere near something classified or secret for a company.
Before, I was trying to figure out how mac's would ever be used anywhere near something classified or secret for a company.
That they purposefully added in the first place to let only Apple apps bypass third-party firewalls?
- pro/dev users who act as their trend setters (see recent backpedals on keyboards and Mac Pro form factor)
- people hacking stuff where it’s popular enough they want more influence on the UX (bootcamp)
"Some system processes bypassing NetworkExtensions in macOS is a bug, in case you were wondering."
Reply[2] by David Dudok de Wit, developer of TripMode:
"Glad to see it's being reconsidered as a bug, because Apple told us it 'behaves as designed' (FB7740671 + FB7665551). And why is there an exclusion list in the first place? I'd love to know more and see this documented."
Reply[3] by Russ:
"Can't get too specific but I promise it's really mundane/boring software development stuff... like two features that interact in an unintended way kind of boring."
Comment[4] on Russ's original tweet by Sérgio Silva:
"Yes. A bug with its own configuration file /System/Library/Frameworks/NetworkExtension.framework/Resources/Info.plist ContentFilterExclusionList"
[1] https://web.archive.org/web/20201118140434/https://twitter.c...
[2] https://twitter.com/david_ddw/status/1329017113709842437
[3] https://twitter.com/xenadu02/status/1329030446269620224
[4] https://twitter.com/sergiojdsilva/status/1328991480657162242
Every family has that one computer geek who everyone asks for advice, which ultimately influences purchase decisions.
Relying on a personal firewall on the device itself seems ill-fated. Maybe it could be considered an additional layer of security, but I've yet to work at a place where a personal firewall is part of the security concept, no matter which OS. It's either firewalls at the gateway, maybe additional ones for certain departments, or mandatory proxy servers if you're stuck in the 90s.
Clearly if your kernel or userspace are compromised that's not much use, and that's where external controls kick in.
You can't determine (absent some custom network and protocols) which piece of software was responsible for a given packet once you leave the device though, so that's the (current) best place to do that - if you want to impose policies controlling the hosts and protocols an application can use, you will want to implement this on-device, then firewall for the superset of all of those at the network level.
In essence it's about raising the number of independent failures required to result in a compromise. If you imagine the application firewall on the device has its policies managed rather than selected by the user, it starts to make more sense.
> In essence it's about raising the number of independent failures required to result in a compromise.
Sure, it doesn't hurt, minus maybe the case that a vulnerability in that firewall itself is used.
> If you imagine the application firewall on the device has its policies managed rather than selected by the user, it starts to make more sense.
That's a requirement I guess. You don't want accountants and HR people handling popups by a firewall app. :-)
> Install personal firewall software or equivalent functionality on any portable computing devices (including company and/or employee-owned) that connect to the Internet when outside the network (for example, laptops used by employees), and which are also used to access the CDE.
The most common place this would come up would be with SREs/Devs that have access to prod (and thus the "Cardholder Data Environment") from their laptops. It can also apply to business users that have access to certain admin dashboards in some organisations.
Microsoft provides the sources and special builds for sensitive environments.
They work with governments worldwide and open their source code to get certified.
As far as I understand it never was Apple's priority.