Running macOS in a Virtual Machine on Apple Silicon Macs
developer.apple.com
developer.apple.com
Or literally open the iPhoto Library folder and go rescuing your photos. There are all sort of thumbnail versions in there for performance, so you'll have to discover the folder hierarchy to find your originals, but they're there.
I came from Aperture into modern Photos after holding out as long as possible. As versions updated, Photos understood more and more Aperture metadata and edits.
With 10^6 photos, to get this to work I had to use old Aperture Library manager utilities to split those by album (by year for unclassified), then bring those split libs into Photos one at a time.
I brought each into its own Photos library to limit blast radius of import issues, and was able to isolate which image(s) caused faults.
After having an array of Photos libraries, I made a big enough store on a fast Mac that could stay online uninterrupted to act as my library host and iCloud Photos master.
I imported Photos to Photos, and let it sync. Able to use logs and narrow down and retry remaining from an import when issues. Eventually, all good.
There is a rate limit on syncing Photos to cloud. If Photos thinks you’re doing separate syncs, it can hit at 25K. So after that either just let it sit to catch up over the next week(s), or, if you are somehow certain of zero errors, keep cloud sync off until all Photos are imported and indexed locally then turn it on. Helping others with this, I’ve had to try both ways. All at once is best if no errors, as it doesn’t seem to rate limit the first batch.
https://support.apple.com/en-us/HT202299
Note, with 10^6 photos in iCloud Photos and multiple devices syncing, sometimes one or more usually older items lose sync or won’t sync from an iPhone. In my experiences, nothing fixes this, not even disable/enable iCloud Photos — until the next major version number iOS release, which seems to reindex or rebuild device Photos library.
I don't know, I haven't counted them in a long time. But probably tens of thousands of photos curated into hundreds of albums across a few dozen separate iPhoto libraries. It's over 20 years worth of work.
Even if I exported all the albums manually I would lose the captions.
Also, I don't want my photos in the cloud. I want them only on media in my direct physical control because I want to retain my Fourth Amendment rights.
It's especially bad with the crap programs on Windows that encoded videos and the like.
Since it is immutable, restarting the VM will clear all files back to a clean slate.
macOS has app sandboxing built-in, but it is not as good as a VM.
I’m curious why this isn’t a more popular setup? Running a browser in an isolated VM seems like it should be a best practice. Does anyone else run a similar setup?
The serial console is for setup/config of the host.
"Krypton" is the name of the isolated microVMs in Hyper-V, but they don't really document it at all.
I do a fair amount of upload/download of docs and images. And some of the "cookie pre-fills stuff for me" is useful. I know you can work around all that, but I'm lazy. I suspect more lazy people like me is the primary reason it's not popular.
Take it with a grain of salt though as they ship their own VM now too :) https://www.openbsd.org/faq/faq16.html
TLDR: P(non-root-vm-breakout-not-requiring-app-breakout) < P(app-breakout) and P(non-root-vm-breakout) < P(local-pe | system-service-exploit)
At least they run their own servers, instead of using a public cloud provider.
e.g. the most recent iOS 15.3.1 security update for iPhone 6S and later devices, https://support.apple.com/en-us/HT213093
> WebKit: Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited.
Downloads are a primary usage in the browse for me, and copy/paste is too.
Do you not find that this and the ‘control v’ versus ‘command v’ thing drives you mad?
How do these (relatively minor) things get solved? Key remapping might do the latter.
Downloads -> writable storage, e.g. network directory or local mutable disk.
Same can be down for the browser profile directory, if that doesn't weaken your local security goals.
And one that most people never deal with? At least from a browser exploit…
> WebKit: Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited.
IF the attacker gained persistent access, your only recourse is to wipe the phone and start over.
Browser VMs are not the only option. Regular OS wipe/install is another, e.g. rotate between two dedicated browsing devices with native performance. One indicator of a compromised device is a reduction in perceived performance.
HP SureClick or MS AppGuard Edge is another level of complexity: every network connection and browser tab is a separate stateless micro-VM whose output is dynamically composited into a single display, with optional analytics of traffic and malware within each isolated micro-VM.
As for "I'm not important enough to be a target", some humans are on education or career paths to change that calculation. Some adversaries may see value in early access to up-and-coming targets. As the cost of targeting falls, the bar for "important enough" also falls.
That doesn't work because of the hilariously wide performance swings induced by antivirus software overhead. :(
IMHO the tab-isolation model you describe is the solution for the top-level comment - something something Firecracker...
Just want to highlight this point, as this is important and probably not given enough conscious thought.
Sure, there are e.g. certain high security businesses or certain high risk individuals that should consider higher security options (or in some cases regulation therefore). That it's certain conditions is precisely why it isn't for the vast majority though, if it were you wouldn't need to specify corner cases.
Security is about judging how to stay as far up the curve as you can without it costing you more than you'd realistically lose to do so. It is not about closing every conceivable hole in your attack surface to achieve minimal risk.
I'd also add there is a counter to the always increasing cost/reward ratio of targeting: the always decreasing amount of complexity of implementing the security mitigations for the "next level" of security. In a decade browsing via VM may be commonplace for the average user (though probably more persistently for that use case) and not require a thought to use. That doesn't make it any different for today but it points out there is more than "threats have increased" that can change what's a reasonable place to be on the security curve.
Who said "everyone" or "one day"? It's bad today, especially for those who assume they are not affected, even though they have never done forensics to test that assumption.
An example: most software incorporates other software as dependencies. As a developer, if a downstream consumer of your software is regulated, your software business could be regulated as a dependency. This also applies to open-source projects. If your software becomes regulated, then the dev/build environment for that software may be regulated. The details are being worked out now, this is not some distant future. https://fossa.com/blog/cybersecurity-executive-order-softwar...
The time will come when more endpoint devices will not be able to connect to sensitive services, because of missing security properties of the endpoint. The definition of sensitive services could be regulated, e.g. CI/CD system. As a software developer, that could mean your dev workstation (including browser configuration) cannot be used to change/publish code without clearing a security bar. https://docs.microsoft.com/en-us/security/compass/privileged...
> there is more than "threats have increased" that can change what's a reasonable place to be on the security curve.
Yes, there is also "damages have increased", so more stakeholders have an interest in consensus definitions and enforcement of reasonable, in specific contexts.
We're a couple layers deep now but the question that started the chain was:
> I’m curious why this isn’t a more popular setup?
If we're no longer talking about that but saying general security implementations and requirements will be tighter at some point in the future then sure, full agree. If we're talking about VM based browsing and why people aren't using it today then I'm not sure how any of this applies outside a tiny fraction of a percentage of machines browsed from.
Qubes is super cool. It's just a pity that it also imposes a bit too many constraints (especially related to USB keyboard... For security reasons) and performance penalties to make it a realistic alternative for me
But if you're that careful, what is the VM really doing for you, and why the hell are you even exposing yourself that much? Just use Lynx or something.
The real solution is this: Install Firefox, install noscript to nuke all javascript, install ublock too, and get a password manager. Selectively allow any webpage interactivity, as necessary. The world isn't a Tom Clancy novel so you don't actually need to do anything more than this to be very secure and on top of almost all active threats.
Ultimately to achieve what we all actually want (strong isolation guarantees that would prevent a full browser exploit from both A) your SSH keys from getting stolen and B) also your gmail spool from being attacked, and let's be honest, B is the worst case scenario) requires a rethinking of the fundamental software stack from OS to user-visible applications. No amount of Browsers-in-a-VM are a substitute.
Obviously I'm not saying 2FA isn't good, and doesn't mitigate some clearly related attacks like raw credential theft (whether or not the browser is exploited, obviously.) My position is just that browsers-in-VMs is a mostly roundabout threat model whose actual benefits (such as some semblance of filesystem isolation) can be achieved other ways. The things these approaches can not fix are otherwise systematic issues that require major redesigns to achieve.
What other ways would you recommend for filesystem isolation better than simply immutable VM running a web browser?
Maybe I'm missing something, but I'd love to know why this doesn't make good sense. Each VM is isolated from the others and also from the host OS.
Yes running a VM won’t protect against this threat.
Running a VM will pretty much eliminate that 0-day from infecting the host OS, where it could become a persistent threat and have access to a range of sensitive data.
This is not security theatre. You just have incomplete threat modelling here.
https://www.securityweek.com/chrome-sandbox-escape-vulnerabi...
Web browser sandbox escape just by viewing a HTML page. Not common, but it happens.
[1] https://nakedsecurity.sophos.com/2020/06/12/facebook-paid-fo...
Security is about risk management and levels of protection. Saying locking your door is useless because someone might drive a car through is not going to help anything.
My employer requires a certain unpopular remote access client suite that installs unnecessary background services running as root. The reliance on a certain unstable audio streaming plugin for skype calls makes everything harder to work on a VM.
Performance is acceptable, even for videos and the like. I'm sure it's considerably slower, but it works for me. I also see adding a bit of a speed bump that mentally distances the web from my main computing environment as a benefit.
edit: in addition to native virtualization, as noted below
- Hardware accelerated virtualization using Hypervisor.framework and QEMU
- Boot macOS guests with Virtualization.framework on macOS 12+
So, it does use Virtualization.framework for macOS guests.
https://wiki.qemu.org/ChangeLog/6.2#Arm
>On macOS hosts with Apple Silicon CPUs we now support the 'hvf' accelerator for running AArch64 guests
(macOS 11.3+ Only) Bridged networking and shared networking support.
Fusion and Parallels are expensive (and I personally don’t love the interface anyway), and I’ve found UTM a pain to setup. I’d like to just take an Ubuntu ISO (or macOS image) choose a disk size and be on with it. Preferably with support for snapshots, but not required.
I spent a while searching for projects but most are no more than (not actively maintained) proof of concepts.
Do note that the framework for Linux asks for a kernel+disk rather than an ISO. I don’t support it at the moment (the project is macOS-focused) but it wouldn’t be too hard to add support for.
Maybe it's a loss leader product now, get individuals into it so that they will ask for it at work.
However... my personal opinion of Workstation has taken a nosedive. I've experienced quite a number of really ridiculous bugs, and it appears that the firing of all of the competent maintainers and replacing them with Chinese developers has not done the product quality any favours. Looks like it's been in "cash cow maintenance mode" for almost a decade at this point.
Example from last week at work: When I fire up my Linux VMs on Windows 10 Enterprise, I get a black screen. The workaround: enable a nonexistent floppy drive. When the system boots the "floppy drive not present" dialogue box somehow stops the screen blanking out and it works until the virtualised OS power saving turns off the screen. At which point it's dead until you power it down and repeat the floppy trick. There's some really basic bug here, and it's been around for several years. Reported and unaddressed.
Same with quite a few other issues I've reported. EFI bugs preventing FreeBSD booting. Segfaults when using the PC beeper on Linux. Really stupid stuff that any basic emulation should be handling.
The QA on these products seems to have just gone, and I really resent paying a significant amount of money for bug-ridden poorly-tested software.
With Fusion I've seen the same issues that Workstation has for the most part, since other than the UI the codebase is mostly shared. If they want to be able to compete with the OS-provided and free alternatives, they need to up their game and make their product worth paying money for. Right now, it seems like you pay through the nose for something that has a handful of features nothing else offers, but overall is a worse experience.
Why? I've had some issues with booting before, but in general UTM is the simple QEMU front-end for macOS for me, a lot like Boxes for Gnome.
https://developer.apple.com/documentation/virtualization/run...
I was watching the github actions launch issue around macOS to see how they would handle the licensing issue[1]. In the end GH/MS didn't comment due to some "NDA" -- would be easy to state if they went the license route so...
[0]: https://github.com/actions/virtual-environments/issues/1814
[1]: https://github.com/actions/virtual-environments/issues/2604
I could imagine them slicing those machines using virtualization, licenses permitting (apparently the 24 hour requirement is from Apple's license agreement.)
I had a version of this working months ago but it was pretty useless without iCloud or my developer account.
I guess I should test it.
Or is my setup not what you’re describing?
If the macOS you run in an M1 virtual machine is the same macOS, then why is the same not true? And I suppose I wonder whether the officially-supported ESXi-virtualizing-macOS has iCloud support, and how that works.
I’m giving it 8GB of ram and 6 cores/12 threads. VM is running on pcie ssd. Speed is good.
No gpu is in my server so it’s using a basic VNC connection. If you add a gpu and pass it through the desktop experience would be much better. However I only needed to do this to do initial setup.
The cool thing about my setup is that it uses a docker container called macinabox which handles the initial Vm configuration and macOS installation, estuary automating the “hackintosh” process.
A few years back I built the vm infrastructure for a CI/CD platform for iOS and macOS app developers. It wasn’t easy to do this in a technically and legally well supported manner.
Why is Apple supporting this use case?
"The OS X EULA does allow for OS X to be virtualized on Apple hardware as both host and guest. This is why (as you note) VMware Workstation does not support OS X virtualization, but Fusion, ESXi, and vSphere do. All versions of VMware's apps check to ensure that you are running on Apple hardware and you are running a supported OS (as not all versions of OS X allow virtualization)."
I am trying to get Snow Leopard+Rosetta virtualized under Mac OS 10.10 Yosemite, as well as get Mac OS 10.8 Lion to run under Snow Leopard ( software requirements, and supporting PowerMac application, Freehand ).
Its a total complete uphill battle, that apple does not want to happen:
"You are completely correct that the EULAs are unclear about the question of running 3+ OS X VMs on a single OS X host. This is a legal question, and not a technical one. For that matter, so is the limitation about which versions of OS X can be virtualized (ex: 10.6 virtualization requires the Server edition, and all VMware applications block you from virtualizing the Standard edition)."
So, it actually is true, and there is proof in VMWare's documentation.
Shall I quote that too?
It’s true that “once upon a time” it wasn’t supported, but those days are long past.
I had someone bring in a Franklin Ace Apple II clone. There are Apple ][ emulators too. Not just for nostalgia, but for applications that are no longer supported or being developed.
I can run DOS on a Core II duo after 40 years.
My point is Apple emulation is only profitable when selling hardware, don't even think its nifty, when its dumped like old fish.
Interesting -- any more documentation around this to take a look at?
It's a bit of a hassle, but I got mine to work in less than an hour. Apparently there's now mitigation that could require you to call Apple support, but I never ran into that when I was on Mojave.
There are also several macOS cloud service providers - including Amazon/AWS, which even has M1 instances.
I expect the secret that makes it easy and license-compliant is running on Apple hardware (presumably Mac mini.)
What about AWS, Macstadium, etc.?
It's required to run iMovie to try to resurrect an old project
VMWare for a long time doesn't support it, but not sure what capabilities Qemu has for GPUs emulation?
Parallels has exceeded my every expectation and seems to be full of “It just works!” Presently running an instance of macOS 10.8 (Mountain Lion) in Parallels 17, but I don’t know if it offers GPU support.
Maybe check using a trial version?
Looking at the examples - quite verbose!
let virtualMachineConfiguration = VZVirtualMachineConfiguration()
virtualMachineConfiguration.platform = createMacPlaform()
virtualMachineConfiguration.bootLoader = MacOSVirtualMachineConfigurationHelper.createBootLoader()
Why not "VMConfigHelper.createBootLoader()" over "MacOSVirtualMachineConfigurationHelper.createBootLoader()" ?I personally quite like it, but it can be jarring for people coming from other languages.
- i or idx is often preferred over index
- fn or fun is often used where function is a reserved word
That said, I’m also cognitively sensitive to column width. I’m not “80 columns or fight”, but I definitely find longer lines of code challenging to follow. As such I prefer to balance verbosity by deferring to the context (lexical scope, imported module name/hierarchy, file name/path, general contextual assumptions that you’d already need to be effective in the codebase).
I find both extremes jarring, and there’s usually an opportunity to optimize for both local understanding and reading without reaching those extremes (of course at the expense of keystrokes/autocomplete pitfalls, but once you’ve embraced verbosity at any level that’s assumed).
I thought Parallels would be using the MacOS virtualization framework? If not, it will be interesting to compare how other systems perform.
Well, the very first time a Mac sees an app, there are special GateKeeper error codes that are never repeated... so if you are unfortunate enough to not know this and test your app on all the Macs you have in your possession, and still can't identify the bug, it was most likely error coded at the very first run time...
To which the solution is make a VM or do all the un-niceties of removing the special security from the Mac, safe boots and all.