macOS 11’s hidden security improvements
blog.malwarebytes.com
blog.malwarebytes.com
Although I may be misremembering or may have been misled by an ambiguous message. https://support.apple.com/en-us/HT201222 lists it as being a security update but "This update has no published CVE entries." (emphasis mine) implying some nasty but embargoed security issue.
Today you have to run Linux to control your computer yourself.
On M1: Still in progress. Linux boots but the kinks have to be worked out. Not production quality yet.
Oh, cool! I have one of the last Macbook pros with an Intel chip, so it sounds like I'm probably in the "secure boot" category.
Does the trackpad work well?
To control your operating system. Your hardware will still have shit like IME and whatnot.
In capitalist America you freely choose to let a small number of corporations sell you computers which control you.
There's a big difference! (In theory, at least.)
I think it is likely that 11.5.2 fixes a large vulnerability and they will only disclose more information once most people have updated to 11.5.2. And/or they are still preparing updates for Mojave/Catalina.
I am the on the more technical side, making me the help desk for friends and family. For the vast majority of people, the safest and easiest thing to hand them is a chromebook. If they want more capability or better hardware, then they will step up into OS X or windows.
They don’t care about the UX until they have to care about the UX because it’s not working the way it was intended. Then they want to fix it back to the way it was (unhide icons or the task bar). They don’t grasp how computers should work, and while I’ve tried explaining, it just doesn’t take. So they remember how to get to email by clicking icons.
99% of people for casual use would just be confused if you dropped them into a command line. There’s a reason things weren’t as popular before we made advances like we have today.
So - for the vast majority of users - an upgrade is an annoyance and downtime that is there during the 10-30 minutes a day they may need the machine (not the 10-30 minutes they are taking a break from the machine). They don’t understand, and don’t care about, the security updates.
Apple and Microsoft and Samsung and Google have no obligation to you, an edge customer, to create a lot more opportunities to screw things up for the vast majority of users who would just get confused. They have no obligation to enable users to perform illegal activity on their hardware. And they can put whatever they want to in the user agreement for their hardware and software. Your option as a consumer is to not buy it. You can complain about it, but that ship has sailed, as the vast majority of users don’t even understand the complaint and the potential implication.
But no. If you want a UX that’s fully configurable and secure and has privacy protections in place and places emphasis on security over convenience, a private, cloud focused, company like Google or Microsoft or Apple is not the right tree to be barking up.
I would say this though - the machine you run it on matters. The hardware matters. Some hardware runs great, other hardware will give you problems. This is due to driver support either being good or bad, not Linux itself, but the distinction is meaningless for the user.
Use a thinkpad, with Pop OS, to get you started. It will just work.
Some more digging shows that Chrome started using a weaker version of CSM, TCSM (thread CSM I assume) two years ago in NaCl: https://source.chromium.org/chromium/_/chromium/native_clien...
Firefox of course uses TCSM too: https://hg.mozilla.org/mozilla-central/rev/cd1ccb74af7c And so does Safari: https://trac.webkit.org/changeset/244233/webkit
I hope this at least somewhat assuages the fears of people who prefer Firefox or Safari over Chrome.
And then on Apple Silicon Macs, entering 1TR is tied to the physical action of holding down the power button.
You're going to have to redo everything after every update, however.
On macOS, the launchd configuration seems to be hard-wired and protected by SIP; there's no easy way to disable random daemons for features like remote student device management - something that most users would not need or want. And as you note even if you disable the associated feature (e.g. in Preferences) its daemon can still run.
It's always annoying when you're not doing anything but your laptop heats up and turns on the fans because some stupid daemon has woken up and decided to re-scan the same files (such as game updates) for the 100th time.
Not to mention photoanalysisd, which burns large amounts of CPU for days/weeks and runs even if you disable the intrusive and obnoxious holiday events/memories features in Photos.
Does anyone else wonder what exactly it is analysing now, after the whole CSAM thing came to light?
All of this is local-only. (Which is why it has to run an expensive indexing process locally.)
This and many other daemons related to photos is very annoying. I have my photos stored on an external drive because the internal SSD isn’t large enough for that, and it’s a nightmare every time trying to eject the external drive. Even when nothing has changed in the photos library, these daemons will be busy scrubbing the disk and keeping it busy for hours or days. The only solution is to find each process (per user) and kill them.
Some people have dismissed OpenBSD's mitigations as overhyped (i.e. - things like W^X are not the main problem, linux has long caught up, etc).
But now we see Apple adding precisely some of these mitigations.
Where does this leave such architectural countermeasures? Are there real gains from investing in such low-level things? Are they irrelevant in an age where many laptops still have ports that give direct DMA access, users are not savvy and sandboxes incomplete?
macOS has enforced W^X in most cases for many years.
As for the two mitigations mentioned in the article:
NO_SMT seems to be equivalent to Linux's "core scheduling" feature, which landed recently [1]. This approach, involving disabling SMT (aka hyperthreading) for specific processes, is different from OpenBSD's more brute-force approach of disabling SMT systemwide; there are pros and cons to both approaches.
As for the other one, forcing VERW to be executed on every return from the kernel, both Linux and OpenBSD chose the brute-force approach of doing this for all processes by default; both added this feature in 2019 as part of the coordinated disclosure of the MDS vulnerability class. Apple is instead doing it on a per-thread basis. Again, pros and cons.
Almost all DMA-capable peripherals on Apple Silicon (including iDevices) are gated behind an IOMMU.
Also, do note that Apple silicon puts everything behind a DART (essentially an IOMMU). This is noted in the article:
> Device isolation was another M1-only feature, that uses the more powerful IOMMU of that platform to make sure hardware devices can only share memory with the operating system and not with each other. Cross-device memory sharing is a historical custom, based on a blind, unfounded trust in hardware.
Well, pledge and unveil work fine.
Might as well mention it here: crytex is how you get code on the Security Research Device, rather than SSV.
https://eclecticlight.co/2021/08/15/last-week-on-my-mac-trus
TFA seems to be confused about what Apple did with the M1, macOS has had W^X enabled across the board (for userland) on all supported 64b architectures since 10.5 (10.4 only had stack W^X).
> Letting multiple threads share invisible resources carries the risk of letting a malicious thread steal secrets from a “sibling” thread running on the same core—a risk that over the years has materialized into multiple attacks, like TLBleed, PortSmash, Fallout, ZombieLoad, RIDL. A straightforward mitigation for this entire family of attacks, past and future, is then to simply disable SMT, which is what NO_SMT does.
BAHAHA cperciva was right! It’s a decade later and people care now! Linus didn’t care at the time!
I’m on mobile otherwise I’d link to relevant refs, but it was an “I told you so” 10 years in the making. Maybe longer? When was cperciva’s cache stealing research?
https://news.ycombinator.com/item?id=16082909
cperciva's paper from 2005 (linked above):
Thanks. :)
> The problems introduced by caches have been further exacerbated by the current trend towards increased parallelism. On recent processors implementing simultaneous multithreading [18], such as Intel’s “Hyper- Threading” processors [11], access to the L1 cache is shared between two independent instruction streams
And here we are 16 years later, with NO_SMT. Neat.
Perhaps my emotional outburst wasn’t substantive, but boy was it satisfying. I’ll try to restrain such urges in the future, but somehow I doubt a 16 year “told ya so” will pop up again any time soon. It’s half as old as I am.
I wish I could remember Linus’ remark about cperciva’s attack being merely “theoretical.”
Linus: "[...] I'd be really surprised if somebody is actually able to get a real-world attack on a real-world pgp key usage or similar out of it (and as to the covert channel, nobody cares). It's a fairly interesting approach, but it's certainly neither new nor HT-specific, or necessarily seem all that worrying in real life. [...]"
introduce memfd_secret system call to create "secret" memory areas
v11: * Drop support for uncached mappings
https://lwn.net/ml/linux-kernel/20201124092556.12009-1-rppt@...
This doesn't concern most of the improvements mentioned in the article, those are purely technical improvements at a very low level. But the signed system volume for example (also mentioned), while a good idea, lacks a convenient way for the user to make changes to it. I'm not very happy leaving my security to a black box and just trusting the supplier implicitly. This is a supplier that introduced a "get root with blank password" bug and the "your password hint is your actual password" one. Sure, everyone makes mistakes, especially for that reason I'd want to have more access than they offer now.
macOS is becoming more and more like iOS, which is also way too closed in my opinion. More locks is always good but the user should have a key, not just the supplier.
The list of things to disable seems to grow every year. Even with Gatekeeper, CSR/SIP disabled I’ll still have issues opening applications which may (or may not) be fixed by taking it out of quarantine, changing the signature, etc
I mention this because I think that it’s good Apple lets you use some of the hardware you own with relatively little restriction if you so choose, but it is a lot less practical than the previous status quo and other systems. You definitely lose some functionality (on M1, I believe you lose at least iOS application support.) If we’re going to be frank about it with Android, I think it’s fair to be frank about it with macOS/M1.
I would guess things could be better if user choice was as much of a focus as vendor control.
I think you might be confused. You don't need to root or unlock the bootloader on an Android device to side load apps. Just download desired APK and accept the security prompt of installing from unknown sources. It's literally that easy.
(I used to root Android phones in the 4.x days, and then stopped, and then went back to iOS as I found myself doing progressively less and less with my phone.)
For example I would want to be able to just make an exception for some of the files I want to change.
The kind of control I'd want is allowing to add a signator for approved kernel extensions. So that I could add my own key and sign kernel extensions myself. Or trust another party to do this. Just like you can add your own keys to Secure Boot on a PC. The same with the app notarisation. Another feature that's essentially great, but fully under the control of Apple. For example, as a corporate admin it'd be great to be able to notarise which apps I'd allow our employees to use.
These security tools would be super powerful and useful if we would be allowed to configure them more.
https://support.apple.com/guide/mdm/kernel-extension-policy-...
All of these are now possible to configure in settings now and device encryption is on by default.
But this is just kernel extension stuff. We know users use some software (not with kernel or system extensions) that's not allowed in our environment. Zoom for example (people are allowed to use it in the browser only for contact with external parties but many people install the full thing anyway). Our security department has banned the full client because of the backdoor it introduced.
Right now we mark it as malware in our antivirus, but it would be great to be able to prevent it altogether.
The state of Linux Desktop has actually being getting worse, not better.
From a top with Ubuntu in the first 5 years, to the sad state we see now.
If there is any criticism that can be made, it’s that the amount of choice can be overwhelming - there are dozens of highly polished, functional distributions - but once you get past that there is no practical limit except the way that Microsoft products like Office are locked away (even this is improving, since you can use Office online).
1. Security. On Linux you can setup mandatory access control - i.e. AppArmor, SeLinux, and even if you don't want to fiddle with that, you can create mutliple users for multiple purposes to sandbox your data from untrusted apps. Running a program as another user is no problem on Linux - try it on Mac OS... (I did try it and it almost worked but things like select file dialog won't work, which makes it useless). By the way, Apple introduced some sandboxing capabilities in Catalina, but it's almost insulting because it only allows to restrict Desktop, Downloads and Trash directories, and not allowing the user to restrict other custom directories to certain apps only. And even for Desktop/Downloads it does not work reliably - i.e. I could not isolate a web browser from accessing desktop.
2. Privacy. I accidentally came upon article from a few years ago where it was revealed that Mac OS sends usage data to Apple or a third party on an unencrypted channel. Then there's the recent issue with client side scanning.
3. Desktop experience. This may be cosmetic but I don't like that Mac OS forces a slow 200ms fade animation when switching between desktops. You can't even switch back and forth too fast because the switching mechanism won't catch the hotkey if the slow fade animation is in progress.
The hardware is good though. Really hoping M1 on Linux will become a thing.
Reasons were the excellent jails system, the ports collection, the ZFS on root (though Ubuntu is starting to offer that) and the great documentation. I also don't like the scale of corporate involvement in Linux development. In the end that leads to companies trying to insert their own IP with a view to monetisation (like Ubuntu with Mir, Upstart, now snaps). It's also the most suitable for a desktop system of all the BSDs I think.
But it's not for everyone. For one the hardware support is limited. I didn't even bother trying to get the WiFi or bluetooth going (I run this on a pure desktop). For laptop use I'd use a flavour of Linux, though I'm not entirely sure which I'd use :) It also doesn't hold your hand as much as most Linux distros, though it's not nearly as barebones as arch either! I'd consider it something a bit in the middle like Manjaro. Overall I'm really happy with it though.
I still use Macs for work though and I administered them for a long time. It's always a struggle if you need to do something that Apple doesn't really want you to do. You may get it working, but there's a good chance it'll get broken in whatever minor patch that's coming along without warning :) Unfortunately in a business with less than 1% Macs you can't always do things the Apple way.
As a 20+ year Linux user and 10+ year paid Linux admin, BSD has really connected with me as a sysadmin. Besides the clean filesystem structure and updated docs, there's generally "one way to do something" (looking at you, Red Hat...) and surprisingly, the packages are more up to date than I'm used to in CentOS / Ubuntu Server, usually tracking the latest stable releases. For the core system, there appears to be no update churn as with Linux distros.
After I discovered the FreeBSD images for the Raspberry Pi, it scratched my tinkerer itch and now... yeah.
People joke about The Year of Linux on the Desktop, but I believe we've been there since ~2014, when Chromebooks started to really get good. Goes to show a full "desktop environment," as we know it, isn't always needed for a great experience.
https://www.reddit.com/r/linux/comments/54in5s/the_nsa_has_t...
A while ago I tried to track the start of a single application, a new install of Firefox. IIRC the first start generated traffic to about a dozen endpoints.
Also, macOS and Windows generate enormous amounts of traffic (others here have noted that).
The amount of background traffic is simply overwhelming. Perhaps security companies can make sense of it all, but it's far too much for most technical people.
I run my own OpenBSD firewall and I've long since given up trying to understand what my Macbooks are doing.
The beauty of OpenBSD itself is that it starts very few daemons, and all source code is available. So it's easy for me to understand what my firewall is doing.
user@catalina ~ % ps aux |wc -l
542
vs openbsd_user$ ps aux |wc -l
42OpenSSL vs LibreSSL, Glibc vs Musl, X11 vs Arcan (or just the framebuffer/KMS), and so on.
Also, on exploits realize Linux and BSD run in devices very different from X86 right? NetBSD today runs even on Alpha, and 0days won't work with ease there.
Even more with the new RISC-V arches here.
Edit: To those downvoting. If you genueinly think running linux isn't a UIUX downgrade on macOS you are totally deluded. Its more open. Cool. It's also a UX nightmare.
"keyboard shortcut": Command-Shift-period
"terminal command": defaults write com.apple.finder AppleShowAllFiles yes
I would argue it's actually worse with the keyboard shortcut on OS X because it's completely possible for someone to trigger Cmd+Shift+. accidentally whereas in other OSs it's a clear toggled option in the GUI.
If you want something more Mac-like, Gnome is a thing of course but it's too opinionated like Mac for me.
It wasn't ten minutes, and there were way too many configuration options that I couldn't fix (like the terrible trackpad scrolling) despite best efforts that it wasn't worth it, and too many that I didn't want to bother. The point is that out of the box, the UX of the Linux UIs has historically and still does suck compared to tools that have a UX focus, and that's a deal breaker for a lot of people that I know.
Here's my opinion: i3 is vastly superior to anything macos is offering in the desktop space in terms of usability. Sure, wrestling with minutae like proper font rendering and DPI settings is a huge pain, but a) some distros do those things for you and b) if you're not a serial distro hopper / manic reinstaller, those things don't have to be done too often.
I genuinely think it's an UX upgrade. And I've been using macs almost exclusively for 5 years now.
The bad things of Linux are still bad: subsystems get replaced all the time (often with just minimal technical justification), and the replacements are usually (if you compare them to Macs) alpha quality for a long time. And the integration is lacking. Notable contemporary examples: oss/alsa/pulseaudio/jack/pipewire and x11/wayland. This is something I truly don't miss when using macs. Almost everything else I do miss.
I have many gripes with Linux, but not about UX. I use preemptive kernels on the desktop for example, because the vanilla kernel is geared towards more general usage, which practically speaking means servers. Sometimes I need to spend more time when installing some new piece of hardware (and sometimes I don't, it works automatically).
One of the biggest advantages for me personally is that I can diagnose occasional problem myself, down to a single character in the source code if I want/need. I know what is running on my system and why, and if I want, I can remove it. (Or, I can make it very hard to remove.) I know what is getting in and out, and I can block it if I want, without any built-in exceptions for the vendor. When you come to think of it, this should be the default for all systems, but we're heading in the opposite direction.
What's still missing with this setup is a shortcut for easily moving a window to another desktop. Any clues how to achieve that?
And finally there's the irritating MacOS UX "feature", that selecting an application with cmd-tab doesn't switch to the desktop where it is, or doesn't unminimize it if it's minimized.
You've betrayed yourself with this statement. There isn't one Linux. I know this might just seem like more of the complexity non-Linux users want to avoid, however users are free to install whatever desktop environment or window manager they like. You could even opt for a desktop environment that resembles MacOS in most ways.
I use MacOS in my professional life, and Linux in my personal. My Linux PC has my own personalised setup built around the i3 window manager. I can say without question that I'm much faster and more productive on Linux than MacOS.
Even tiling window managers don't really have any problems. They provide a very niche UX, which is almost entirely keyboard driven. There's not a single general application I can think of designed for use with this kind of window manager. Still, you get a pretty consistent user experience for the most part.
My point was generalised, and I think generally the average computer user is going to have a better UX on macOS than linux. If they can figure out how to even set up Linux of course.
That's the definition of backdoors.
The password hint bug, for example, was “only listening to Apple” in the narrow sense that the OS wouldn’t let you run your own implementation of password hints or login. But it’s not a backdoor.
There are plenty of built-in features that aren’t configurable, which is fine and good. Because most people have no idea what those things do, most of the rest shouldn’t touch them, and leaving them as configurable or editable opens up a whole class of malware.
MacOS has no convenient way to know if changes are made by the user or malware. It is a feature, not a bug, for most users. Why would you need to change system volume anyway?
So if you have the application firewall on, opening ports in pf won't help.
I'm kinda surprised pf is still in there to be honest. I know some security solutions like McAfee Firewall use it under the hood. But they could do similar things with network extensions. I have expected them to drop it for years now.